pkgsrc-Changes-HG archive

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]

[pkgsrc/trunk]: pkgsrc/security Update to version 2.2.7



details:   https://anonhg.NetBSD.org/pkgsrc/rev/d9f94a7f13c6
branches:  trunk
changeset: 511887:d9f94a7f13c6
user:      salo <salo%pkgsrc.org@localhost>
date:      Tue Apr 25 12:45:57 2006 +0000

description:
Update to version 2.2.7

Approved by <frueauf>

Changes:
- make it work as binary packages,
- remove useless MESSAGE files,
- add nmap.nasl plugin, not included by default upstream,
- make the installation a bit more sane and easier to configure.

2.2.7:
======

Nessus 2.2.7 contains several fixes for bugs which have been found
during the 3.x developement process and have been backported to this
branch. It also slightly extends the NASL language by adding support for
arrays of arrays. We will use this feature in some key plugins (SMB in
particular) within 6 months, so you should definitely upgrade to 2.2.7
or 3.0.x.

nessus-libraries:
- Fixed a NULL pointer dereferencement in the BPF server (this mostly
  affects OpenBSD and FreeBSD < 5)
- The 'service' functions now only deal with the services file provided
- with Nessus (instead of using a mix of /etc/services and others)

libnasl:
- Fixed off-by-one bugs in insstr() and str_replace() which would
  sometimes prevent these two functions from properly dealing with the
  last character of a string
- Fixed tcp_ping() which was too aggressive and may therefore sometimes
  miss a live host
- Fixed a bug in send() which would not properly validate the value of the
  'length' variable
- Now handle arrays of arrays
- Fixed open_priv_sock_tcp() which would report a successful connection
  when timing out

nessusd:
- Properly install the file 'nessus-services' in $prefix/var/nessus/
- Bigger buffer when receiving preferences from the client (to avoid a
  possible truncation of the plugin list in the future)
- Fixed a bug in the preferences parser which would cause nessusd to die
  on startup when processing a malformed preference file

nessus client:
- Fixed an unlikely but potential segmentation fault when viewing the
  report in the GUI
- Erase the credentials from memory after having used them (thanks to
  Sumiut Siddhart for noticing this)

plugins:
- Fixed several bugs in find_services.c which would not properly set the
  key Transport/SSL or which may read some data beyond its buffer
- Fixed a bad #if/#endif clause in nessus_tcp_scanner.c which prevented it
  from recomputing the RTT, hence negatively impacting the performance
- nmap.nasl has been removed from the main distribution (to use nmap from
  within Nessus read http://www.nessus.org/documentation/?doc=nmap-usage)

diffstat:

 security/libnasl/Makefile             |   5 +++--
 security/libnasl/PLIST                |   4 +++-
 security/libnasl/buildlink3.mk        |   7 +++----
 security/libnasl/distinfo             |   9 +++++----
 security/libnasl/patches/patch-ab     |  15 +++++++++++++++
 security/nessus-core/MESSAGE          |  19 +++++--------------
 security/nessus-core/Makefile         |  30 ++++++++++++++++++++++++++----
 security/nessus-core/PLIST            |  11 +++--------
 security/nessus-core/buildlink3.mk    |   6 +++---
 security/nessus-core/distinfo         |   9 +++++----
 security/nessus-core/files/nessusd.sh |   4 ++--
 security/nessus-core/patches/patch-ab |  14 ++++++++++++++
 security/nessus-libraries/Makefile    |   6 +++---
 security/nessus-libraries/distinfo    |   8 ++++----
 security/nessus-plugins/MESSAGE       |   9 ---------
 security/nessus-plugins/Makefile      |  13 +++++++++----
 security/nessus-plugins/distinfo      |  11 +++++++----
 security/nessus/MESSAGE               |   7 -------
 security/nessus/Makefile              |   3 +--
 security/nessus/Makefile.common       |   4 ++--
 20 files changed, 113 insertions(+), 81 deletions(-)

diffs (truncated from 410 to 300 lines):

diff -r a706baf18e1e -r d9f94a7f13c6 security/libnasl/Makefile
--- a/security/libnasl/Makefile Tue Apr 25 12:29:25 2006 +0000
+++ b/security/libnasl/Makefile Tue Apr 25 12:45:57 2006 +0000
@@ -1,4 +1,4 @@
-# $NetBSD: Makefile,v 1.17 2005/12/05 23:55:18 rillig Exp $
+# $NetBSD: Makefile,v 1.18 2006/04/25 12:45:57 salo Exp $
 
 .include       "../../security/nessus/Makefile.common"
 
@@ -6,7 +6,8 @@
 
 COMMENT=       Nessus Attack Scripting Language library
 
-WRKSRC=                        ${WRKDIR}/libnasl
+WRKSRC=                ${WRKDIR}/libnasl
+
 GNU_CONFIGURE=         yes
 CONFIGURE_ARGS+=       --localstatedir=${VARBASE:Q}
 
diff -r a706baf18e1e -r d9f94a7f13c6 security/libnasl/PLIST
--- a/security/libnasl/PLIST    Tue Apr 25 12:29:25 2006 +0000
+++ b/security/libnasl/PLIST    Tue Apr 25 12:45:57 2006 +0000
@@ -1,7 +1,9 @@
-@comment $NetBSD: PLIST,v 1.12 2004/09/22 08:09:52 jlam Exp $
+@comment $NetBSD: PLIST,v 1.13 2006/04/25 12:45:57 salo Exp $
 bin/nasl
 bin/nasl-config
 include/nessus/nasl.h
 lib/libnasl.la
 man/man1/nasl-config.1
 man/man1/nasl.1
+share/examples/libnasl/nessus_org.pem
+@dirrm share/examples/libnasl
diff -r a706baf18e1e -r d9f94a7f13c6 security/libnasl/buildlink3.mk
--- a/security/libnasl/buildlink3.mk    Tue Apr 25 12:29:25 2006 +0000
+++ b/security/libnasl/buildlink3.mk    Tue Apr 25 12:45:57 2006 +0000
@@ -1,5 +1,4 @@
-# $NetBSD: buildlink3.mk,v 1.7 2006/04/12 10:27:33 rillig Exp $
-# XXX  BUILDLINK_DEPMETHOD.libnasl?=   build
+# $NetBSD: buildlink3.mk,v 1.8 2006/04/25 12:45:57 salo Exp $
 
 BUILDLINK_DEPTH:=      ${BUILDLINK_DEPTH}+
 LIBNASL_BUILDLINK3_MK:=        ${LIBNASL_BUILDLINK3_MK}+
@@ -12,8 +11,8 @@
 BUILDLINK_PACKAGES+=   libnasl
 
 .if !empty(LIBNASL_BUILDLINK3_MK:M+)
-BUILDLINK_API_DEPENDS.libnasl+=        libnasl>=2.2.3
-BUILDLINK_ABI_DEPENDS.libnasl?=        libnasl>=2.2.3
+BUILDLINK_API_DEPENDS.libnasl+=        libnasl>=2.2.7
+BUILDLINK_ABI_DEPENDS.libnasl?=        libnasl>=2.2.7
 BUILDLINK_PKGSRCDIR.libnasl?=  ../../security/libnasl
 .endif # LIBNASL_BUILDLINK3_MK
 
diff -r a706baf18e1e -r d9f94a7f13c6 security/libnasl/distinfo
--- a/security/libnasl/distinfo Tue Apr 25 12:29:25 2006 +0000
+++ b/security/libnasl/distinfo Tue Apr 25 12:45:57 2006 +0000
@@ -1,6 +1,7 @@
-$NetBSD: distinfo,v 1.20 2006/01/29 17:05:54 adam Exp $
+$NetBSD: distinfo,v 1.21 2006/04/25 12:45:57 salo Exp $
 
-SHA1 (libnasl-2.2.6.tar.gz) = 323475d7c11b045abd93f8adad3e7ca7ca05ed0a
-RMD160 (libnasl-2.2.6.tar.gz) = 0c179b3a7d87fe61c8729c4e854b83ab2839031f
-Size (libnasl-2.2.6.tar.gz) = 364643 bytes
+SHA1 (libnasl-2.2.7.tar.gz) = d2d0c5b8ce6e63e08069173b414fa6588837cb46
+RMD160 (libnasl-2.2.7.tar.gz) = 281c6ea87e8eba25152f6f81bdf7186b2ceb9e43
+Size (libnasl-2.2.7.tar.gz) = 364755 bytes
 SHA1 (patch-aa) = dd13fb7ddaf21f313e392e76138bbb66c7bdfbcb
+SHA1 (patch-ab) = 8a8b99ce00f298eae8a18741d966a1ee70cbba1c
diff -r a706baf18e1e -r d9f94a7f13c6 security/libnasl/patches/patch-ab
--- /dev/null   Thu Jan 01 00:00:00 1970 +0000
+++ b/security/libnasl/patches/patch-ab Tue Apr 25 12:45:57 2006 +0000
@@ -0,0 +1,15 @@
+$NetBSD: patch-ab,v 1.1 2006/04/25 12:45:57 salo Exp $
+
+--- Makefile.orig      2004-07-28 20:07:09.000000000 +0200
++++ Makefile   2006-04-10 13:22:16.000000000 +0200
+@@ -17,8 +17,8 @@
+       $(INSTALL) -c -m 0644 doc/nasl-config.1 $(DESTDIR)${mandir}/man1
+       $(INSTALL) -c -m 0644 doc/nasl.1 $(DESTDIR)${mandir}/man1
+       $(INSTALL) -c -m 0644 doc/nasl-config.1 $(DESTDIR)${mandir}/man1
+-      test -d $(DESTDIR)${localstatedir}/nessus || $(INSTALL_DIR) -m 755 $(DESTDIR)${localstatedir}/nessus
+-      $(INSTALL) -c -m 0644 doc/nessus_org.pem $(DESTDIR)${localstatedir}/nessus/nessus_org.pem
++      $(BSD_INSTALL_DATA_DIR) $(DESTDIR)${prefix}/share/examples/libnasl
++      $(BSD_INSTALL_DATA) doc/nessus_org.pem $(DESTDIR)${prefix}/share/examples/libnasl
+ 
+ 
+       @echo
diff -r a706baf18e1e -r d9f94a7f13c6 security/nessus-core/MESSAGE
--- a/security/nessus-core/MESSAGE      Tue Apr 25 12:29:25 2006 +0000
+++ b/security/nessus-core/MESSAGE      Tue Apr 25 12:45:57 2006 +0000
@@ -1,19 +1,10 @@
 ===========================================================================
-$NetBSD: MESSAGE,v 1.7 2004/10/11 22:14:51 reed Exp $
-
-Nessus may have placed some files in /var/nessus, ${PREFIX}/etc/nessus,
-${PREFIX}/com/nessus and ${PREFIX}/lib/nessus/reports. If you do not need
-these files any more, be sure to remove them:
+$NetBSD: MESSAGE,v 1.8 2006/04/25 12:45:57 salo Exp $
 
-       rm -fr ${VARBASE}/nessus
-       rm -fr ${PREFIX}/etc/nessus
-       rm -fr ${PREFIX}/lib/nessus/reports
-       rm -fr ${PREFIX}/com/nessus
-
-Before you can start scanning, you need to create one or more user-accounts
-using "nessus-adduser", generate key using "nessus-mkcert" then start the
-nessus daemon, nessusd, and use the "nessus" GUI program to direct the
-daemon.
+Before you can start scanning, you need to create one or more user accounts
+using "nessus-adduser", generate key (and configuration file, if you lack
+one) using "nessus-mkcert" then start the nessus daemon, "nessusd", and use
+the "nessus" GUI program to manage the daemon.
 
 If you want to start nessusd automatically on system boot, please copy
 ${PREFIX}/${RCD_SCRIPTS_EXAMPLEDIR}/nessusd to /etc/rc.d and set
diff -r a706baf18e1e -r d9f94a7f13c6 security/nessus-core/Makefile
--- a/security/nessus-core/Makefile     Tue Apr 25 12:29:25 2006 +0000
+++ b/security/nessus-core/Makefile     Tue Apr 25 12:45:57 2006 +0000
@@ -1,21 +1,43 @@
-# $NetBSD: Makefile,v 1.29 2006/04/17 13:46:10 wiz Exp $
+# $NetBSD: Makefile,v 1.30 2006/04/25 12:45:57 salo Exp $
 
 .include       "../../security/nessus/Makefile.common"
 
 DISTNAME=      nessus-core-${VERS}
-PKGREVISION=   2
 
 COMMENT=       Core module of the Nessus Network Security Scanner
 
 WRKSRC=                ${WRKDIR}/nessus-core
+
 GNU_CONFIGURE=         yes
-CONFIGURE_ARGS+=       --enable-gtk --with-x --localstatedir=${VARBASE:Q}
+CONFIGURE_ARGS+=       --enable-gtk
+CONFIGURE_ARGS+=       --with-x
+CONFIGURE_ARGS+=       --localstatedir=${VARBASE:Q}
+CONFIGURE_ARGS+=       --sharedstatedir=${PKG_SYSCONFBASE:Q}
 CONFIGURE_ENV+=                ac_cv_path_GTKCONFIG="pkg-config gtk+-2.0" \
                        ac_cv_path_GLIBCONFIG="pkg-config glib-2.0"
 
 RCD_SCRIPTS=   nessusd
-PLIST_SUBST+=  VARBASE=${VARBASE:Q}
+
+PKG_SYSCONFSUBDIR?=    nessus
+
+OWN_DIRS_PERMS+=       ${VARBASE}/nessus ${ROOT_USER} ${ROOT_GROUP} 0700
+OWN_DIRS_PERMS+=       ${PKG_SYSCONFDIR} ${ROOT_USER} ${ROOT_GROUP} 0700
+
+OWN_DIRS+=     ${PREFIX}/lib/nessus            \
+               ${PREFIX}/lib/nessus/reports    \
+               ${PREFIX}/lib/nessus/plugins
+
+MAKE_DIRS+=    ${VARBASE}/nessus/jobs          \
+               ${VARBASE}/nessus/logs          \
+               ${VARBASE}/nessus/tmp           \
+               ${VARBASE}/nessus/users
+
+CONF_FILES+=   ${BUILDLINK_PREFIX.libnasl}/share/examples/libnasl/nessus_org.pem \
+               ${VARBASE}/nessus/nessus_org.pem
+CONF_FILES+=   ${PREFIX}/share/examples/nessus/nessus-services \
+               ${VARBASE}/nessus/nessus-services
 
 .include "../../security/libnasl/buildlink3.mk"
 .include "../../x11/gtk2/buildlink3.mk"
+
 .include "../../mk/bsd.pkg.mk"
diff -r a706baf18e1e -r d9f94a7f13c6 security/nessus-core/PLIST
--- a/security/nessus-core/PLIST        Tue Apr 25 12:29:25 2006 +0000
+++ b/security/nessus-core/PLIST        Tue Apr 25 12:45:57 2006 +0000
@@ -1,4 +1,4 @@
-@comment $NetBSD: PLIST,v 1.15 2005/05/02 20:34:05 reed Exp $
+@comment $NetBSD: PLIST,v 1.16 2006/04/25 12:45:57 salo Exp $
 bin/nessus
 bin/nessus-fetch
 bin/nessus-mkcert-client
@@ -26,10 +26,5 @@
 sbin/nessus-rmuser
 sbin/nessusd
 share/examples/rc.d/nessusd
-@exec ${MKDIR} %D/lib/nessus/reports
-@unexec ${RMDIR} %D/lib/nessus/reports 2>/dev/null || ${TRUE}
-@unexec ${RMDIR} %D/lib/nessus 2>/dev/null || ${TRUE}
-@exec ${MKDIR} %D/etc/nessus
-@unexec ${RMDIR} %D/etc/nessus 2>/dev/null || ${TRUE}
-@exec ${MKDIR} ${VARBASE}/nessus
-@unexec ${RMDIR} ${VARBASE}/nessus 2>/dev/null || ${TRUE}
+share/examples/nessus/nessus-services
+@dirrm share/examples/nessus
diff -r a706baf18e1e -r d9f94a7f13c6 security/nessus-core/buildlink3.mk
--- a/security/nessus-core/buildlink3.mk        Tue Apr 25 12:29:25 2006 +0000
+++ b/security/nessus-core/buildlink3.mk        Tue Apr 25 12:45:57 2006 +0000
@@ -1,4 +1,4 @@
-# $NetBSD: buildlink3.mk,v 1.9 2006/04/17 13:46:10 wiz Exp $
+# $NetBSD: buildlink3.mk,v 1.10 2006/04/25 12:45:57 salo Exp $
 
 BUILDLINK_DEPTH:=              ${BUILDLINK_DEPTH}+
 NESSUS_CORE_BUILDLINK3_MK:=    ${NESSUS_CORE_BUILDLINK3_MK}+
@@ -11,8 +11,8 @@
 BUILDLINK_PACKAGES+=   nessus-core
 
 .if !empty(NESSUS_CORE_BUILDLINK3_MK:M+)
-BUILDLINK_API_DEPENDS.nessus-core+=            nessus-core>=2.2.3
-BUILDLINK_ABI_DEPENDS.nessus-core?=    nessus-core>=2.2.6nb2
+BUILDLINK_API_DEPENDS.nessus-core+=    nessus-core>=2.2.7
+BUILDLINK_ABI_DEPENDS.nessus-core?=    nessus-core>=2.2.7
 BUILDLINK_PKGSRCDIR.nessus-core?=      ../../security/nessus-core
 .endif # NESSUS_CORE_BUILDLINK3_MK
 
diff -r a706baf18e1e -r d9f94a7f13c6 security/nessus-core/distinfo
--- a/security/nessus-core/distinfo     Tue Apr 25 12:29:25 2006 +0000
+++ b/security/nessus-core/distinfo     Tue Apr 25 12:45:57 2006 +0000
@@ -1,6 +1,7 @@
-$NetBSD: distinfo,v 1.20 2006/01/29 17:05:54 adam Exp $
+$NetBSD: distinfo,v 1.21 2006/04/25 12:45:57 salo Exp $
 
-SHA1 (nessus-core-2.2.6.tar.gz) = 878434bbbae4f0edf9cc1c90315e2ee0524eb2e3
-RMD160 (nessus-core-2.2.6.tar.gz) = 2ddd5f2b70a1d4432bb0126d1cac710105e9291f
-Size (nessus-core-2.2.6.tar.gz) = 683530 bytes
+SHA1 (nessus-core-2.2.7.tar.gz) = c261eeb14e0594467f0e1da04a42679f4658c1f4
+RMD160 (nessus-core-2.2.7.tar.gz) = 672bc31cc8283e3248831bb8564c6531d4b55eed
+Size (nessus-core-2.2.7.tar.gz) = 673852 bytes
 SHA1 (patch-aa) = ec63c0c606016033d15289c0ab3cbbc5bf74e64c
+SHA1 (patch-ab) = 9fce5a88d2d9574cd0912fd55ae2a833942e0e22
diff -r a706baf18e1e -r d9f94a7f13c6 security/nessus-core/files/nessusd.sh
--- a/security/nessus-core/files/nessusd.sh     Tue Apr 25 12:29:25 2006 +0000
+++ b/security/nessus-core/files/nessusd.sh     Tue Apr 25 12:45:57 2006 +0000
@@ -1,6 +1,6 @@
 #!/bin/sh
 #
-# $NetBSD: nessusd.sh,v 1.1 2003/06/09 17:01:26 frueauf Exp $
+# $NetBSD: nessusd.sh,v 1.2 2006/04/25 12:45:57 salo Exp $
 #
 
 # PROVIDE: nessusd
@@ -21,7 +21,7 @@
 nessusd_setup()
 {
        echo "Dump of nessusd setup."
-       @PREFIX@/sbin/nessusd -d
+       ${command} -d
 }
 
 load_rc_config $name
diff -r a706baf18e1e -r d9f94a7f13c6 security/nessus-core/patches/patch-ab
--- /dev/null   Thu Jan 01 00:00:00 1970 +0000
+++ b/security/nessus-core/patches/patch-ab     Tue Apr 25 12:45:57 2006 +0000
@@ -0,0 +1,14 @@
+$NetBSD: patch-ab,v 1.3 2006/04/25 12:45:57 salo Exp $
+
+--- Makefile.orig      2006-01-15 16:37:55.000000000 +0100
++++ Makefile   2006-04-10 13:49:33.000000000 +0200
+@@ -38,7 +38,8 @@
+       test -d $(DESTDIR)${NESSUSD_STATEDIR}/tmp || $(INSTALL_DIR) -m 755 $(DESTDIR)${NESSUSD_STATEDIR}/tmp
+       test -d $(DESTDIR)${NESSUSD_STATEDIR}/jobs  || $(INSTALL_DIR) -m 755 $(DESTDIR)${NESSUSD_STATEDIR}/jobs
+       test -d $(DESTDIR)${NESSUSD_LOGDIR} || $(INSTALL_DIR) -m 755 $(DESTDIR)${NESSUSD_LOGDIR}
+-      $(INSTALL) -c -m 0444 nessus-services $(DESTDIR)${NESSUSD_STATEDIR}/
++      $(BSD_INSTALL_DATA_DIR) $(DESTDIR)${prefix}/share/examples/nessus
++      $(BSD_INSTALL_DATA) nessus-services $(DESTDIR)${prefix}/share/examples/nessus
+       $(INSTALL) -c -m 0444 include/config.h $(DESTDIR)${includedir}/nessus
+       $(INSTALL) -c -m 0444 include/ntcompat.h $(DESTDIR)${includedir}/nessus
+       $(INSTALL) -c -m 0444 include/includes.h $(DESTDIR)${includedir}/nessus
diff -r a706baf18e1e -r d9f94a7f13c6 security/nessus-libraries/Makefile
--- a/security/nessus-libraries/Makefile        Tue Apr 25 12:29:25 2006 +0000
+++ b/security/nessus-libraries/Makefile        Tue Apr 25 12:45:57 2006 +0000
@@ -1,13 +1,13 @@
-# $NetBSD: Makefile,v 1.25 2005/12/05 23:55:18 rillig Exp $
+# $NetBSD: Makefile,v 1.26 2006/04/25 12:45:57 salo Exp $
 
 .include       "../../security/nessus/Makefile.common"
 
 DISTNAME=      nessus-libraries-${VERS}
 COMMENT=       Libs required by the Nessus Network security scanner
 
-BUILD_DEPENDS+=        bison-[0-9]*:../../devel/bison
+WRKSRC=                ${WRKDIR}/nessus-libraries
 
-WRKSRC=                ${WRKDIR}/nessus-libraries
+USE_TOOLS+=            bison
 USE_LIBTOOL=           yes
 GNU_CONFIGURE=         yes
 CONFIGURE_ARGS+=       --enable-zlib=${BUILDLINK_PREFIX.zlib}/lib \
diff -r a706baf18e1e -r d9f94a7f13c6 security/nessus-libraries/distinfo
--- a/security/nessus-libraries/distinfo        Tue Apr 25 12:29:25 2006 +0000
+++ b/security/nessus-libraries/distinfo        Tue Apr 25 12:45:57 2006 +0000
@@ -1,8 +1,8 @@
-$NetBSD: distinfo,v 1.23 2006/01/29 17:05:54 adam Exp $
+$NetBSD: distinfo,v 1.24 2006/04/25 12:45:57 salo Exp $
 
-SHA1 (nessus-libraries-2.2.6.tar.gz) = 7552cb5c48ace2e38537d8b58a1c7968172399cc
-RMD160 (nessus-libraries-2.2.6.tar.gz) = 6fd4b60515fa17657a015a3a31d380ee5d2c23ba
-Size (nessus-libraries-2.2.6.tar.gz) = 426911 bytes
+SHA1 (nessus-libraries-2.2.7.tar.gz) = 2723edc97fe02cf0c14004c89487c570df7f0e7c
+RMD160 (nessus-libraries-2.2.7.tar.gz) = 08f0602635cd9ca5f2bc4513067c0c5251249a97
+Size (nessus-libraries-2.2.7.tar.gz) = 426429 bytes
 SHA1 (patch-aa) = c525abf1ccfe4c3921609b91e335fa19b0bcab87
 SHA1 (patch-ab) = 982846ca823fb9f83b2d670f61f78b3b61f6d704
 SHA1 (patch-ac) = ec174bd6ddb7303f53a5e474451ad0f306575682
diff -r a706baf18e1e -r d9f94a7f13c6 security/nessus-plugins/MESSAGE
--- a/security/nessus-plugins/MESSAGE   Tue Apr 25 12:29:25 2006 +0000



Home | Main Index | Thread Index | Old Index