Fwd: [elinks-dev] [Bug][Security] elinks doesn't verify server certificate

2017-03-10 Thread Edd Barrett
Hi, The following email appeared in my inbox from the elinks-dev list (I can't link you to it because it seems all the elinks archives have either disappeared or are out of date). I've verified that elinks is not checking the validity of certificates by hitting https://www.pcwebshop.co.uk/ in bot

Re: Fwd: [elinks-dev] [Bug][Security] elinks doesn't verify server certificate

2017-03-10 Thread Edd Barrett
On Fri, Mar 10, 2017 at 10:54:29AM +, Edd Barrett wrote: > Index: Makefile > === > RCS file: /home/edd/cvsync/ports/www/elinks/Makefile,v > retrieving revision 1.37 > diff -u -p -r1.37 Makefile > --- Makefile 30 Jan 2017 10:06:55

UPDATE: net/lftp

2017-03-10 Thread Rafael Sadowski
Hi All! Here's an update to lftp 4.7.7. Best regards, Rafael Index: Makefile === RCS file: /cvs/ports/net/lftp/Makefile,v retrieving revision 1.113 diff -u -p -u -p -r1.113 Makefile --- Makefile16 Feb 2017 10:56:00 - 1

[wip] mosh-1.3.0-rc2

2017-03-10 Thread Jeremie Courreges-Anglas
Upstream published an RC. Among other things, mosh now uses pledge(2). The client seems to still work fine against an old (1.2.4) mosh-server, but I haven't done much tests. Feedback welcome. Index: Makefile === RCS file: /d/cvs/p

[wip] ratpoison-1.4.9-rc2

2017-03-10 Thread Jeremie Courreges-Anglas
So I published ratpoison-1.4.9-rc2 yesterday. The big change is Xrandr support instead of Xinerama (at last...). I don't have a timeline for the 1.4.9 release, but if I get enough reports (multiple screen setups anyone?) maybe this could be shipped with the 6.1 release. Index: Makefile ===

Re: NEW: www/p5-CGI-Fast 2.12

2017-03-10 Thread Jeremie Courreges-Anglas
Mikolaj Kucharski writes: > Hi, > > This Perl module is needed for gitweb.cgi from git package to work > over FastCGI. My gitweb stopped to work after recent upgrade to the > latest snapshot and attached port makes it work again. Have you tried to track down this gitweb "regression"? Anyway, yo

new: security/botan2

2017-03-10 Thread Alexander Bluhm
Hi I would like to add a new port for the crypto library botan 2. We already have the botan 1.10 in ports, but they are not API compatible. So I think it it best to put it under security/botan2. Note that all internal paths do not conflict with the existing security/botan. Comment: crypto and T

UPDATE: Openmdns-0.7

2017-03-10 Thread Gonzalo L. Rodriguez
Hello, Update for Openmdns 0.7: https://github.com/haesbaert/mdnsd OK? Comments? Cheers.- -- Sending from my toaster. Index: Makefile === RCS file: /cvs/ports/net/openmdns/Makefile,v retrieving revision 1.16 diff -u -p -r1.16 Mak

Re: new: security/botan2

2017-03-10 Thread Rafael Sadowski
On Fri Mar 10, 2017 at 08:01:06PM +0100, Alexander Bluhm wrote: > Hi > > I would like to add a new port for the crypto library botan 2. We > already have the botan 1.10 in ports, but they are not API compatible. > So I think it it best to put it under security/botan2. Note that > all internal pa

UPDATE: security/botan

2017-03-10 Thread Rafael Sadowski
Hi All, please find below a simple diff to update botan to the last stable version. CVE fixes between 1.10.10 and 1.10.15 - Resolve infinite loop in modular square root algorithm. CVE-2016-2194 - Use constant time modular inverse algorithm to avoid possible side channel attack against ECDSA (C

Re: NEW: www/p5-CGI-Fast 2.12

2017-03-10 Thread Mikolaj Kucharski
On Fri, Mar 10, 2017 at 07:27:19PM +0100, Jeremie Courreges-Anglas wrote: > Mikolaj Kucharski writes: > > > Hi, > > > > This Perl module is needed for gitweb.cgi from git package to work > > over FastCGI. My gitweb stopped to work after recent upgrade to the > > latest snapshot and attached port