Pullup ticket #2939 - requested by taca
authortron <tron>
Mon, 30 Nov 2009 23:10:20 +0000 (23:10 +0000)
committertron <tron>
Mon, 30 Nov 2009 23:10:20 +0000 (23:10 +0000)
commit314c62d8d4a93a2ab187f69f8dd882ba3f3f943a
tree09b92a4b82a5aceedfa2398883b757e72e768036
parent802fbc01efedc72e90a0e1572a0ec4c512c77485
Pullup ticket #2939 - requested by taca
php5: security patch

Revisions pulled up:
- lang/php5/Makefile 1.73-1.74
- lang/php5/distinfo 1.69-1.70
- lang/php5/patches/patch-ag 1.3
- lang/php5/patches/patch-ah 1.2
- lang/php5/patches/patch-ay 1.2
- lang/php5/patches/patch-az 1.1-1.2
- lang/php5/patches/patch-ba 1.1
- lang/php5/patches/patch-bb 1.1
- lang/php5/patches/patch-bc 1.1
- lang/php5/patches/patch-bd 1.1
---
Module Name: pkgsrc
Committed By: taca
Date: Thu Oct 22 14:49:06 UTC 2009

Modified Files:
pkgsrc/lang/php5: Makefile distinfo
Added Files:
pkgsrc/lang/php5/patches: patch-az

Log Message:
Add patch to check byte sequence more strictly in htmlspecialchars().

http://bugs.php.net/bug.php?id=49785

These are patch refrects r289411, r289554, r289565, r289567 and r289605
in PHP svn repositry.

Bump PKGREVISION.
---
Module Name: pkgsrc
Committed By: taca
Date: Mon Nov 30 06:14:08 UTC 2009

Modified Files:
pkgsrc/lang/php5: Makefile distinfo
pkgsrc/lang/php5/patches: patch-ag patch-ah patch-ay patch-az
Added Files:
pkgsrc/lang/php5/patches: patch-ba patch-bb patch-bc patch-bd

Log Message:
Add fixes for http://secunia.com/advisories/37412/ from PHP's repositry.

1. CVE-2009-3292 is already fixed in 5.2.11.

2. CVE-2009-3558

http://svn.php.net/viewvc?view=revision&revision=288934

3. CVE-2009-3557

http://svn.php.net/viewvc?view=revision&revision=288945
http://svn.php.net/viewvc?view=revision&revision=288971

4. CVE-2009-4017

http://svn.php.net/viewvc?view=revision&revision=289990
http://svn.php.net/viewvc?view=revision&revision=290820
http://svn.php.net/viewvc?view=revision&revision=290885

Other pkgsrc changes:

* Don't hardcord /usr/pkg in php.ini-dist and php.ini-recommended.
* Add comments to some of patch files.

Bump PKGREVISION.
lang/php5/Makefile
lang/php5/distinfo
lang/php5/patches/patch-ag
lang/php5/patches/patch-ah
lang/php5/patches/patch-ay
lang/php5/patches/patch-az [new file with mode: 0644]
lang/php5/patches/patch-ba [new file with mode: 0644]
lang/php5/patches/patch-bb [new file with mode: 0644]
lang/php5/patches/patch-bc [new file with mode: 0644]
lang/php5/patches/patch-bd [new file with mode: 0644]