OpenBSD/ports QHTDwUKdevel/libelf Makefile, editors/neovim Makefile

   editors/neovim: backport arbitrary code execution fix to 6.4-stable.

   Source command doesn't check for the sandbox.
   https://github.com/neovim/neovim/pull/10082

   Detailed description:
   https://github.com/numirias/security/blob/master/doc/2019-06-04_ace-vim-neovim.md

   I also had to add another MASTER_SITE to libelf to get this to build.
   Seems they have re-rolled their distfile at some point.

   Reads OK, sthen@
VersionDeltaFile
1.13.4.1+3-2devel/libelf/Makefile
1.11.2.1+2-2editors/neovim/Makefile
1.1.4.1+1-1editors/neovim/patches/patch-src_nvim_getchar_c
+6-53 files

OpenBSD/ports K3CeZO7www/nextcloud Makefile

   Force the PHP version to 7.1 which is the minimum required by
   Nextcloud, spotted by matthieu@ by the hard way.

   Discussed with sthen@

   OK sthen@
VersionDeltaFile
1.25.2.10+3-1www/nextcloud/Makefile
+3-11 files

OpenBSD/ports h5MzDA5sysutils/firmware/intel Makefile distinfo, sysutils/firmware/intel/pkg PLIST

   MFC new intel microcode
VersionDeltaFile
1.9.2.1+9-10sysutils/firmware/intel/Makefile
1.6.2.1+11-2sysutils/firmware/intel/pkg/PLIST
1.6.2.1+2-2sysutils/firmware/intel/distinfo
+22-143 files

OpenBSD/ports e89JOynsysutils/firmware Makefile.inc

   MFC make MASTER_SITES conditional on !GH_ACCOUNT
VersionDeltaFile
1.4.6.1+3-1sysutils/firmware/Makefile.inc
+3-11 files

OpenBSD/ports XqR41aTnet/samba Makefile distinfo

   SECURITY update to samba-4.8.12

   Fixes:
   o  CVE-2018-16860 (Samba AD DC S4U2Self/S4U2Proxy unkeyed checksum)

   Release notes:
   https://www.samba.org/samba/history/samba-4.8.12.html
VersionDeltaFile
1.260.2.4+4-4net/samba/Makefile
1.71.2.4+2-2net/samba/distinfo
+6-62 files

OpenBSD/ports 8EBdKR5www/nextcloud distinfo Makefile, www/nextcloud/pkg PLIST

   Update for Nextcloud to 16.0.0:

   https://nextcloud.com/changelog/

   Fart cloud all the things!

   OK stsp@
VersionDeltaFile
1.18.2.7+856-748www/nextcloud/pkg/PLIST
1.16.2.7+2-2www/nextcloud/distinfo
1.25.2.9+2-2www/nextcloud/Makefile
+860-7523 files

OpenBSD/ports O96uWVQwww/nextcloud Makefile distinfo, www/nextcloud/pkg PLIST

   Update for Nextcloud to 15.0.7:

   https://nextcloud.com/changelog/

   OK kirby@
VersionDeltaFile
1.18.2.6+20-28www/nextcloud/pkg/PLIST
1.25.2.8+2-3www/nextcloud/Makefile
1.16.2.6+2-2www/nextcloud/distinfo
+24-333 files

OpenBSD/ports tM0eMNmnet/samba Makefile distinfo, net/samba/patches patch-source3_wscript

   SECURITY update to samba-4.8.11

   Fixes:
   - CVE-2019-3880 (Save registry file outside share as unprivileged user)

   Release notes:
     https://www.samba.org/samba/history/samba-4.8.11.html

   6.4 tests by Ian McWilliam
VersionDeltaFile
1.260.2.3+17-12net/samba/Makefile
1.45.2.1+6-10net/samba/pkg/PLIST-main
1.4.8.1+11-1net/samba/pkg/PLIST-ldb
1.71.2.3+2-2net/samba/distinfo
1.7.2.1+2-2net/samba/patches/patch-source3_wscript
1.3.4.1+2-1net/samba/pkg/samba_ad_dc.rc
+40-281 files not shown
+41-297 files

OpenBSD/ports yT7x2tnwww/apache-httpd Makefile, www/apache-httpd/patches patch-modules_ssl_ssl_private_h patch-modules_ssl_ssl_engine_init_c

   move apache-httpd in -stable back to MODSSL_USE_OPENSSL_PRE_1_1_API codepaths,
   in the 2.4.35->37 timeframe they switched to newer-API codepaths which seem to
   be working in -current but fall over easily on 6.4/-stable, at least with the
   event mpm.

   problem reported by Frank Groeneveld.
VersionDeltaFile
1.5.4.2+17-2www/apache-httpd/patches/patch-modules_ssl_ssl_private_h
1.12.2.2+10-1www/apache-httpd/patches/patch-modules_ssl_ssl_engine_init_c
1.90.2.3+2-2www/apache-httpd/Makefile
+29-53 files

OpenBSD/ports B5XA0Wjlang/php/7.1/patches patch-php_ini-development, lang/php/7.2 Makefile

   MFC security updates to PHP 7.1.28 and 7.2.17.
   (6.4 also shipped with 5.6 and 7.0 branches which are now EoL).
VersionDeltaFile
1.1.2.2+5-5lang/php/7.2/patches/patch-acinclude_m4
1.1.2.2+2-2lang/php/7.2/patches/patch-aclocal_m4
1.1.2.2+2-2lang/php/7.2/patches/patch-php_ini-development
1.2.2.3+2-2lang/php/7.2/patches/patch-sapi_fpm_fpm_fpm_children_c
1.1.2.2+2-2lang/php/7.1/patches/patch-php_ini-development
1.1.2.3+2-2lang/php/7.2/Makefile
+15-153 files not shown
+21-219 files

OpenBSD/ports uWflrsswww/apache-httpd Makefile, www/apache-httpd/patches patch-modules_filters_mod_reqtimeout_c

   MFC: backport Apache httpd fix affecting file uploads, they were broken in 2.4.39
   unless the admin specifies an explicit RequestReadTimeout.

   https://bz.apache.org/bugzilla/show_bug.cgi?id=63325
   https://svn.apache.org/viewvc?view=revision&revision=1857129
VersionDeltaFile
1.90.2.2+2-1www/apache-httpd/Makefile
1.1.2.1+1-1www/apache-httpd/patches/patch-modules_filters_mod_reqtimeout_c
+3-22 files

OpenBSD/ports Aa5QCl9www/apache-httpd distinfo Makefile, www/apache-httpd/patches patch-modules_ssl_ssl_engine_init_c patch-configure

   update -stable to apache httpd 2.4.39 - important security fixes
   https://httpd.apache.org/security/vulnerabilities_24.html#2.4.39
VersionDeltaFile
1.19.2.1+228-227www/apache-httpd/pkg/PLIST-main
1.12.2.1+9-10www/apache-httpd/patches/patch-modules_ssl_ssl_engine_init_c
1.17.2.1+3-3www/apache-httpd/patches/patch-configure
1.5.4.1+2-2www/apache-httpd/patches/patch-modules_ssl_ssl_private_h
1.29.2.1+2-2www/apache-httpd/distinfo
1.90.2.1+2-2www/apache-httpd/Makefile
+246-2466 files

OpenBSD/ports kl64RO1mail/dovecot Makefile distinfo

   update -stable to Dovecot 2.2.36.3, from Brad
VersionDeltaFile
1.268.2.2+2-2mail/dovecot/Makefile
1.137.2.2+2-2mail/dovecot/distinfo
+4-42 files

OpenBSD/ports 4OIw0Jesecurity/clamav Makefile distinfo, security/clamav/patches patch-libclamav_Makefile_in patch-clamd_Makefile_in

   update clamav in -stable to 0.100.3
   https://blog.clamav.net/2019/03/clamav-01012-and-01003-patches-have.html

   CVE-2019-1785 CVE-2019-1786 CVE-2019-1787 CVE-2019-1788 CVE-2019-1789
   CVE-2019-1798
VersionDeltaFile
1.31.2.1+2-2security/clamav/patches/patch-libclamav_Makefile_in
1.121.2.1+2-2security/clamav/Makefile
1.62.2.1+2-2security/clamav/distinfo
1.24.2.1+2-2security/clamav/patches/patch-clamd_Makefile_in
1.21.2.1+2-2security/clamav/patches/patch-database_Makefile_in
1.11.2.1+2-2security/clamav/patches/patch-unit_tests_Makefile_in
+12-126 files

OpenBSD/ports PLdLZH5www/firefox-esr Makefile distinfo

   MFC:Update to firefox-esr 60.6.1.

   Fixes https://www.mozilla.org/en-US/security/advisories/mfsa2019-10/
   6.4-stable packages will be available tmrw late, still building.
VersionDeltaFile
1.84.2.7+2-2www/firefox-esr/Makefile
1.60.2.7+2-2www/firefox-esr/distinfo
+4-42 files

OpenBSD/ports kF8ZoSGwww/firefox-esr Makefile distinfo

   MFC: Update to firefox-esr 60.6.0.

   See https://www.mozilla.org/en-US/firefox/60.6.0/releasenotes/
   Fixes https://www.mozilla.org/en-US/security/advisories/mfsa2019-08/

   6.4-stable packages at the usual spot.
VersionDeltaFile
1.84.2.6+2-2www/firefox-esr/Makefile
1.60.2.6+2-2www/firefox-esr/distinfo
+4-42 files

OpenBSD/ports beJbXmblang/ruby/2.4 Makefile distinfo, lang/ruby/2.4/pkg PLIST-ri_docs

   Use upstream patch to fix the following vulnerabilities in rubygems:

   CVE-2019-8320: Delete directory using symlink when decompressing tar
   CVE-2019-8321: Escape sequence injection vulnerability in verbose
   CVE-2019-8322: Escape sequence injection vulnerability in gem owner
   CVE-2019-8323: Escape sequence injection vulnerability in API response handling
   CVE-2019-8324: Installing a malicious gem may lead to arbitrary code execution
   CVE-2019-8325: Escape sequence injection vulnerability in errors
VersionDeltaFile
1.11.2.2+5-1lang/ruby/2.4/Makefile
1.5.2.2+2-2lang/ruby/2.4/pkg/PLIST-ri_docs
1.7.2.2+2-0lang/ruby/2.4/distinfo
+9-33 files

OpenBSD/ports ifNNi0mlang/ruby/2.5 distinfo Makefile, lang/ruby/2.5/pkg PLIST-ri_docs

   Update to ruby 2.5.5

   Fixes the following vulnerabilities in rubygems:

   CVE-2019-8320: Delete directory using symlink when decompressing tar
   CVE-2019-8321: Escape sequence injection vulnerability in verbose
   CVE-2019-8322: Escape sequence injection vulnerability in gem owner
   CVE-2019-8323: Escape sequence injection vulnerability in API response handling
   CVE-2019-8324: Installing a malicious gem may lead to arbitrary code execution
   CVE-2019-8325: Escape sequence injection vulnerability in errors
VersionDeltaFile
1.2.2.2+2-3lang/ruby/2.5/pkg/PLIST-ri_docs
1.3.2.2+2-2lang/ruby/2.5/distinfo
1.4.2.2+2-2lang/ruby/2.5/Makefile
+6-73 files

OpenBSD/ports VuDEcfFwww/nextcloud Makefile, www/nextcloud/pkg README

   Fix typo on my previous commit spotted by aja@

   Also we want unify the variables
VersionDeltaFile
1.8.2.3+5-5www/nextcloud/pkg/README
1.25.2.7+2-2www/nextcloud/Makefile
+7-72 files

OpenBSD/ports RksclsUwww/nextcloud Makefile, www/nextcloud/pkg README

   List alphabetically and removes the duplicates lines from Bruno Flueckiger

   Thanks!
VersionDeltaFile
1.8.2.2+12-16www/nextcloud/pkg/README
1.25.2.6+2-1www/nextcloud/Makefile
+14-172 files

OpenBSD/ports soTg3EElang/php/7.2 Makefile distinfo, lang/php/7.2/patches patch-php_ini-development patch-php_ini-production

   update -stable to php-7.2.16
VersionDeltaFile
1.1.2.1+6-6lang/php/7.2/patches/patch-php_ini-development
1.1.2.1+5-5lang/php/7.2/patches/patch-php_ini-production
1.1.2.1+3-3lang/php/7.2/patches/patch-acinclude_m4
1.1.2.1+2-2lang/php/7.2/patches/patch-aclocal_m4
1.1.2.2+2-2lang/php/7.2/Makefile
1.1.2.2+2-2lang/php/7.2/distinfo
+20-201 files not shown
+21-217 files

OpenBSD/ports fG7NuFolang/php/7.1 Makefile distinfo, lang/php/7.1/patches patch-acinclude_m4 patch-aclocal_m4

   update -stable to php-7.1.27
VersionDeltaFile
1.1.2.1+3-3lang/php/7.1/patches/patch-acinclude_m4
1.1.2.1+2-2lang/php/7.1/patches/patch-aclocal_m4
1.1.2.2+2-2lang/php/7.1/Makefile
1.1.2.2+2-2lang/php/7.1/distinfo
1.1.2.1+2-2lang/php/7.1/patches/patch-php_ini-development
+11-115 files

OpenBSD/ports SgF4a0Iwww/nextcloud distinfo Makefile, www/nextcloud/pkg PLIST

   Update for Nextcloud to 15.0.5

   https://nextcloud.com/changelog/
VersionDeltaFile
1.18.2.5+27-66www/nextcloud/pkg/PLIST
1.16.2.5+2-2www/nextcloud/distinfo
1.25.2.5+2-2www/nextcloud/Makefile
+31-703 files

OpenBSD/ports tTBprT6net/wireshark Makefile distinfo

   update to wireshark-2.6.7 in -stable
VersionDeltaFile
1.77.2.3+10-10net/wireshark/Makefile
1.37.2.3+2-2net/wireshark/distinfo
+12-122 files

OpenBSD/ports ULMlXSZdatabases/mariadb Makefile, databases/mariadb/patches patch-scripts_mysql_install_db_sh

   Fix the mysql_install_db script. From Brad.
VersionDeltaFile
1.10.2.2+10-1databases/mariadb/patches/patch-scripts_mysql_install_db_sh
1.65.2.3+2-1databases/mariadb/Makefile
+12-22 files

OpenBSD/ports ITXju6Onet/tor Makefile distinfo, net/tor/patches patch-configure_ac

   SECURITY update to 0.3.4.11.

   Tested and ok stsp@
VersionDeltaFile
1.120.2.2+2-2net/tor/Makefile
1.98.2.2+2-2net/tor/distinfo
1.6.2.1+2-2net/tor/patches/patch-configure_ac
+6-63 files

OpenBSD/ports CfO7Bz7comms/conserver Makefile, comms/conserver/patches patch-console_console_c

   MFC conserver console(1) fix
VersionDeltaFile
1.6.12.1+17-13comms/conserver/pkg/DESCR
1.7.2.1+13-1comms/conserver/patches/patch-console_console_c
1.63.2.2+2-2comms/conserver/Makefile
+32-163 files

OpenBSD/ports LsNlzrJcomms/conserver Makefile, comms/conserver/patches patch-conserver_main_c

   MFC conserver fixes;
   - rc.d: where possible only attempt to signal the master not childs
   - FLAVOR=net: unbreak, :@SECLEVEL=0 is invalid
VersionDeltaFile
1.10.2.1+19-1comms/conserver/pkg/conserver.rc
1.2.2.1+12-2comms/conserver/patches/patch-conserver_main_c
1.63.2.1+2-2comms/conserver/Makefile
+33-53 files

OpenBSD/ports eXm8D4mmail/dovecot Makefile distinfo, mail/dovecot-pigeonhole distinfo Makefile

   Update -stable to Dovecot 2.2.36.1 for CVE-2019-3814 and the
   bug fixes in Dovecot and Dovecot-pigeonhole 0.4.24.1.
   From Brad.
VersionDeltaFile
1.268.2.1+2-3mail/dovecot/Makefile
1.30.2.1+2-2mail/dovecot-pigeonhole/distinfo
1.59.2.1+2-2mail/dovecot-pigeonhole/Makefile
1.137.2.1+2-2mail/dovecot/distinfo
+8-94 files

OpenBSD/ports XeMJJ8Zwww/firefox-esr Makefile distinfo

   MFC: Bugfix update to firefox-esr 60.5.2.

   See https://www.mozilla.org/en-US/firefox/60.5.2/releasenotes/
   Fixes crashes when reading Reuters news, cf https://bugzilla.mozilla.org/1505844
VersionDeltaFile
1.84.2.5+2-2www/firefox-esr/Makefile
1.60.2.5+2-2www/firefox-esr/distinfo
+4-42 files