head 1.4; access; symbols pkgsrc-2026Q2:1.3.0.54 pkgsrc-2026Q2-base:1.3 pkgsrc-2026Q1:1.3.0.52 pkgsrc-2026Q1-base:1.3 pkgsrc-2025Q4:1.3.0.50 pkgsrc-2025Q4-base:1.3 pkgsrc-2025Q3:1.3.0.48 pkgsrc-2025Q3-base:1.3 pkgsrc-2025Q2:1.3.0.46 pkgsrc-2025Q2-base:1.3 pkgsrc-2025Q1:1.3.0.44 pkgsrc-2025Q1-base:1.3 pkgsrc-2024Q4:1.3.0.42 pkgsrc-2024Q4-base:1.3 pkgsrc-2024Q3:1.3.0.40 pkgsrc-2024Q3-base:1.3 pkgsrc-2024Q2:1.3.0.38 pkgsrc-2024Q2-base:1.3 pkgsrc-2024Q1:1.3.0.36 pkgsrc-2024Q1-base:1.3 pkgsrc-2023Q4:1.3.0.34 pkgsrc-2023Q4-base:1.3 pkgsrc-2023Q3:1.3.0.32 pkgsrc-2023Q3-base:1.3 pkgsrc-2023Q2:1.3.0.30 pkgsrc-2023Q2-base:1.3 pkgsrc-2023Q1:1.3.0.28 pkgsrc-2023Q1-base:1.3 pkgsrc-2022Q4:1.3.0.26 pkgsrc-2022Q4-base:1.3 pkgsrc-2022Q3:1.3.0.24 pkgsrc-2022Q3-base:1.3 pkgsrc-2022Q2:1.3.0.22 pkgsrc-2022Q2-base:1.3 pkgsrc-2022Q1:1.3.0.20 pkgsrc-2022Q1-base:1.3 pkgsrc-2021Q4:1.3.0.18 pkgsrc-2021Q4-base:1.3 pkgsrc-2021Q3:1.3.0.16 pkgsrc-2021Q3-base:1.3 pkgsrc-2021Q2:1.3.0.14 pkgsrc-2021Q2-base:1.3 pkgsrc-2021Q1:1.3.0.12 pkgsrc-2021Q1-base:1.3 pkgsrc-2020Q4:1.3.0.10 pkgsrc-2020Q4-base:1.3 pkgsrc-2020Q3:1.3.0.8 pkgsrc-2020Q3-base:1.3 pkgsrc-2020Q2:1.3.0.6 pkgsrc-2020Q2-base:1.3 pkgsrc-2020Q1:1.3.0.2 pkgsrc-2020Q1-base:1.3 pkgsrc-2019Q4:1.3.0.4 pkgsrc-2019Q4-base:1.3 pkgsrc-2019Q3:1.2.0.52 pkgsrc-2019Q3-base:1.2 pkgsrc-2019Q2:1.2.0.50 pkgsrc-2019Q2-base:1.2 pkgsrc-2019Q1:1.2.0.48 pkgsrc-2019Q1-base:1.2 pkgsrc-2018Q4:1.2.0.46 pkgsrc-2018Q4-base:1.2 pkgsrc-2018Q3:1.2.0.44 pkgsrc-2018Q3-base:1.2 pkgsrc-2018Q2:1.2.0.42 pkgsrc-2018Q2-base:1.2 pkgsrc-2018Q1:1.2.0.40 pkgsrc-2018Q1-base:1.2 pkgsrc-2017Q4:1.2.0.38 pkgsrc-2017Q4-base:1.2 pkgsrc-2017Q3:1.2.0.36 pkgsrc-2017Q3-base:1.2 pkgsrc-2017Q2:1.2.0.32 pkgsrc-2017Q2-base:1.2 pkgsrc-2017Q1:1.2.0.30 pkgsrc-2017Q1-base:1.2 pkgsrc-2016Q4:1.2.0.28 pkgsrc-2016Q4-base:1.2 pkgsrc-2016Q3:1.2.0.26 pkgsrc-2016Q3-base:1.2 pkgsrc-2016Q2:1.2.0.24 pkgsrc-2016Q2-base:1.2 pkgsrc-2016Q1:1.2.0.22 pkgsrc-2016Q1-base:1.2 pkgsrc-2015Q4:1.2.0.20 pkgsrc-2015Q4-base:1.2 pkgsrc-2015Q3:1.2.0.18 pkgsrc-2015Q3-base:1.2 pkgsrc-2015Q2:1.2.0.16 pkgsrc-2015Q2-base:1.2 pkgsrc-2015Q1:1.2.0.14 pkgsrc-2015Q1-base:1.2 pkgsrc-2014Q4:1.2.0.12 pkgsrc-2014Q4-base:1.2 pkgsrc-2014Q3:1.2.0.10 pkgsrc-2014Q3-base:1.2 pkgsrc-2014Q2:1.2.0.8 pkgsrc-2014Q2-base:1.2 pkgsrc-2014Q1:1.2.0.6 pkgsrc-2014Q1-base:1.2 pkgsrc-2013Q4:1.2.0.4 pkgsrc-2013Q4-base:1.2 pkgsrc-2013Q3:1.2.0.2 pkgsrc-2013Q3-base:1.2 pkgsrc-2013Q2:1.1.0.6 pkgsrc-2013Q2-base:1.1 pkgsrc-2013Q1:1.1.0.4 pkgsrc-2013Q1-base:1.1 pkgsrc-2012Q4:1.1.0.2 pkgsrc-2012Q4-base:1.1; locks; strict; comment @ * @; 1.4 date 2026.08.17.07.45.28; author wiz; state dead; branches; next 1.3; commitid KVLKXsntMhogMXRG; 1.3 date 2019.10.01.15.22.41; author ryoon; state Exp; branches; next 1.2; commitid xPB0EfzajhTw3bFB; 1.2 date 2013.08.07.11.06.39; author drochner; state Exp; branches; next 1.1; commitid HG1z67uc9xxOOv0x; 1.1 date 2012.11.01.19.32.44; author joerg; state Exp; branches 1.1.6.1; next ; 1.1.6.1 date 2013.08.21.19.40.13; author tron; state Exp; branches; next ; commitid OiXXKVNTb3M2em2x; desc @@ 1.4 log @putty: remove two patches Just tried - but not accepted by upstream. Code compiles without them. @ text @$NetBSD: patch-timing.c,v 1.3 2019/10/01 15:22:41 ryoon Exp $ --- timing.c.orig 2019-09-22 09:14:51.000000000 +0000 +++ timing.c @@@@ -60,19 +60,10 @@@@ static int compare_timers(void *av, void * Failing that, compare on the other two fields, just so that * we don't get unwanted equality. */ -#if defined(__LCC__) || defined(__clang__) - /* lcc won't let us compare function pointers. Legal, but annoying. */ - { - int c = memcmp(&a->fn, &b->fn, sizeof(a->fn)); - if (c) - return c; - } -#else - if (a->fn < b->fn) + if ((uintptr_t)a->fn < (uintptr_t)b->fn) return -1; - else if (a->fn > b->fn) + else if ((uintptr_t)a->fn > (uintptr_t)b->fn) return +1; -#endif if (a->ctx < b->ctx) return -1; @ 1.3 log @Update to 0.73 Changelog: Vulnerabilities fixed in this release include: - On Windows, the listening sockets used for local port forwarding were opened in a mode that did not prevent other processes from also listening on the same ports and stealing some of the incoming connections. - In the PuTTY terminal, bracketed paste mode was broken in 0.72, in a way that made the pasted data look like manual keyboard input. So any application relying on the bracketing sequences to protect against malicious clipboard contents would have been misled. - An SSH-1 server could trigger an access to freed memory by sending the SSH1_MSG_DISCONNECT message. Not known to be exploitable. Other bug fixes include: - Windows Plink no longer crashes on startup when it tries to tell you it's reusing an existing SSH connection. - Windows PuTTY now updates its terminal window size correctly if the screen resolution changes while it's maximised. - If you display the coloured error messages from gcc in the PuTTY terminal, there is no longer a missing character if a colour change happens exactly at the end of a line. - If you use the 'Clear Scrollback' menu option or escape sequence while text in the scrollback is selected, it no longer causes an assertion failure. @ text @d1 1 a1 1 $NetBSD: patch-timing.c,v 1.2 2013/08/07 11:06:39 drochner Exp $ @ 1.2 log @update to 0.63 This fixes a buffer overflow which was patched in pkgsrc (CVE-2013-4852), two other buffer overflows (CVE-2013-4206, CVE-2013-4207), and it clears private keys after use now (CVE-2013-4208). Other than that, there are mostly bug fixes from 0.62 and a few small features. @ text @d1 1 a1 1 $NetBSD$ d3 1 a3 1 --- timing.c.orig 2012-09-19 22:12:00.000000000 +0000 d12 3 a14 3 - int c = memcmp(&a->fn, &b->fn, sizeof(a->fn)); - if (c) - return c; d16 1 a16 1 -#else d19 1 a19 1 return -1; d22 1 a22 1 return +1; d26 1 a26 1 return -1; @ 1.1 log @Don't order function pointers directly. Don't use non-literals as format strings. Fix return type of intermediate used for return value of wcrtomb. @ text @d3 1 a3 1 --- timing.c.orig 2012-10-30 22:23:57.000000000 +0000 d5 1 a5 1 @@@@ -41,21 +41,10 @@@@ static int compare_timers(void *av, void d9 1 a9 1 -#ifdef __LCC__ d13 2 a14 4 - if (c < 0) - return -1; - else if (c > 0) - return +1; @ 1.1.6.1 log @Pullup ticket #4216 - requested by drochner security/putty: security update Revisions pulled up: - security/putty/Makefile 1.34-1.35 - security/putty/distinfo 1.14-1.15 - security/putty/patches/patch-CVE-2013-4852-1 deleted - security/putty/patches/patch-CVE-2013-4852-2 deleted - security/putty/patches/patch-import.c 1.2-1.3 - security/putty/patches/patch-terminal.c deleted - security/putty/patches/patch-timing.c 1.2 - security/putty/patches/patch-unix_gtkfont_c deleted - security/putty/patches/patch-unix_gtkwin.c 1.3 - security/putty/patches/patch-unix_uxnet.c 1.2 - security/putty/patches/patch-unix_uxucs.c 1.2 - security/putty/patches/patch-windows_window.c 1.2 --- Module Name: pkgsrc Committed By: drochner Date: Tue Aug 6 12:23:37 UTC 2013 Modified Files: pkgsrc/security/putty: Makefile distinfo pkgsrc/security/putty/patches: patch-import.c Added Files: pkgsrc/security/putty/patches: patch-CVE-2013-4852-1 patch-CVE-2013-4852-2 Log Message: add patch from upstream to fix possible heap overflow in SSH handshake due to integer overflow (CVE-2013-4852) bump PKGREV --- Module Name: pkgsrc Committed By: drochner Date: Wed Aug 7 11:06:39 UTC 2013 Modified Files: pkgsrc/security/putty: Makefile distinfo pkgsrc/security/putty/patches: patch-import.c patch-timing.c patch-unix_gtkwin.c patch-unix_uxnet.c patch-unix_uxucs.c patch-windows_window.c Removed Files: pkgsrc/security/putty/patches: patch-CVE-2013-4852-1 patch-CVE-2013-4852-2 patch-terminal.c patch-unix_gtkfont_c Log Message: update to 0.63 This fixes a buffer overflow which was patched in pkgsrc (CVE-2013-4852), two other buffer overflows (CVE-2013-4206, CVE-2013-4207), and it clears private keys after use now (CVE-2013-4208). Other than that, there are mostly bug fixes from 0.62 and a few small features. @ text @d3 1 a3 1 --- timing.c.orig 2012-09-19 22:12:00.000000000 +0000 d5 1 a5 1 @@@@ -60,19 +60,10 @@@@ static int compare_timers(void *av, void d9 1 a9 1 -#if defined(__LCC__) || defined(__clang__) d13 4 a16 2 - if (c) - return c; @