Link [ pkgsrc | NetBSD | pkgsrc git mirror | PR fulltext-search | netbsd commit viewer ]


   
        usage: [branch:branch] [user:user] [path[@revision]] keyword [... [-excludekeyword [...]]] (e.g. branch:MAIN pkgtools/pkg)




switch to index mode

recent branches: MAIN (26m)  pkgsrc-2024Q1 (14d)  pkgsrc-2023Q4 (42d)  pkgsrc-2023Q2 (74d)  pkgsrc-2023Q3 (154d) 

2024-05-12 18:18:29 UTC Now

2013-12-25 16:32:32 UTC MAIN commitmail json YAML

Update mlterm to 3.3.2. (leaf package update, ok'ed wiz@)

pkgsrc changes:
- remove post-3.3.1 patches
- pull post-3.3.2 fixes for mlterm-fb from upstream:
  - 4d974f7: fix mlterm-fb scroll on >=8bpp framebuffers
  - 0b2987a: fix palette handling on 4bpp framebuffers

Changes from doc/en/ReleaseNote:

ver 3.3.2
* Support 4bpp framebuffer on NetBSD/luna68k.
* Desynchronize ssh negotiation on cygwin or mingw.
* "inner_border" option accepts "[horizontal border],[vertical border]" format value.
* Add "leftward_double_drawing" option which embolds medium fonts by drawing doubly at
  1 pixel leftward instead of rightward.
* Add vte_terminal_set_color_*_rgba() functions to libvte compatible library.
* Bug fixes:
  Fix memory leak when opening pty fails on win32gdi.
  Fix the bug which disabled to clear hidden input method window it if large
  value is specified for --border option.
  Fix the bug which disabled to paste UTF-8 string.
  Bitbucket pull request #1 (Thanks to Hayaki Saito san)
  Fix the bug which causes segfault in pasting text via win32 clipboard from x11
  applications over ssh x11 forwarding
  Fix segfault caused by zero column characters like 0x200e.

(tsutsui)

2013-12-25 14:59:10 UTC MAIN commitmail json YAML

2013-12-25 12:12:36 UTC MAIN commitmail json YAML

PR pkg/48479 Fix problem of:
ghostscript-cidfonts doesn't switch correctly ghostscript-agpl and -gpl
Thanks wiz@.

(mef)

2013-12-25 11:47:09 UTC MAIN commitmail json YAML

2013-12-25 11:04:28 UTC MAIN commitmail json YAML

Fix build with SunStudio C Compiler under Solaris 10.

(tron)

2013-12-25 02:26:48 UTC MAIN commitmail json YAML

Adjust PLIST only when following option is active.
  PKG_OPTIONS.ghostscript+=disable-compile-inits
No PKGREVISON++ (not packaged or binaries'd be the same before patch and after).
Discussed at thread starting
  http://mail-index.netbsd.org/pkgsrc-users/2013/12/23/msg019089.html

(mef)

2013-12-25 01:29:07 UTC MAIN commitmail json YAML

Corrected typo in COMMENT.

(rodent)

2013-12-24 15:29:44 UTC MAIN commitmail json YAML

Missing documentation update for the new default behaviour of "FETCH_USING".

(tron)

2013-12-24 15:21:38 UTC MAIN commitmail json YAML

Note update of the "xchat" package to version 2.8.8nb21.

(tron)

2013-12-24 15:21:24 UTC MAIN commitmail json YAML

Explicitely enable XFT support unless GTK+ was compiled without X11 support
under Mac OS X. This fixes the text output under Mac OS X if GTK+ was
actually compiled with X11 support.

(tron)

2013-12-24 15:00:44 UTC MAIN commitmail json YAML

>From https://github.com/erlang/otp/pull/46#issuecomment-21719585

"Since b29ecbd (OTP-10418, R15B03) Erlang does not compile anymore with
old versions of GCC that do not have atomic ops builtins on platforms
where there is no native ethread implementation (e.g. ARM): (...)

Please note however that I will be merging this branch as well,
which will mean that you have to explicitly tell configure that
you intend to use the fallback atomic operations though
--disable-native-ethr-impls or --disable-smp-require-native-atomics."

Translated: On NetBSD-5.1 (with gcc-4.1.3) the erlang package
didn't compile because of

>  ../include/internal/gcc/ethr_membar.h:49:4: error:
> #error "No __sync_val_compare_and_swap"

Adding the abovementioned option --disable-native-ethr-impls make the
Erlang runtime system use the original (now fallback) code. This should
maybe be an pkg option, but for now this has to do.

(is)

2013-12-24 11:22:42 UTC MAIN commitmail json YAML

Updated net/exabgp to 3.2.19

(pettai)

2013-12-24 11:21:55 UTC MAIN commitmail json YAML

ExaBGP Christmas release (version 3.2.19)
* Fix: bug when displaying EOR
* Fix: invalid check on next-hop for multi-line routes
* Fix: badly parsing command line for run option
* Fix: allow the creation of 'allow' flows
* Fix: bad JSON encoding for EOR
* Fix: API message encoding
* Improvement: allow digit:digit in extended communities
* Improvement: healtcheck.py, python 2.6 and community support

(pettai)

2013-12-24 05:57:44 UTC MAIN commitmail json YAML

To get a working compiler on SunOS, a number of hardcoded gcc/linker
related paths are replaced.
http://article.gmane.org/gmane.comp.compilers.llvm.devel/63317
ok'd by wiz@

(richard)

2013-12-24 03:26:56 UTC MAIN commitmail json YAML

Note update of devel/transifex-client package to 0.10.

(taca)

2013-12-24 03:26:19 UTC MAIN commitmail json YAML

Update transifex-client to 0.10.  This is a leaf package and a warning mail
would be sent from Transifex when using old transifex-client.

Here is some of changes from commit log.

* Use urllib3 for the API call; it allows to have proper SSL certificate
  verification (see CVE-2013-2073) as well as drop a lot of code.
* Add --psuedo option.

(taca)

2013-12-23 23:58:35 UTC MAIN commitmail json YAML

Add cups-filters to suggested new package list.

(gdt)

2013-12-23 11:57:07 UTC MAIN commitmail json YAML

2013-12-23 03:15:57 UTC MAIN commitmail json YAML

Updated comms/asterisk to 11.6.1

(jnemeth)

2013-12-23 02:51:57 UTC MAIN commitmail json YAML

fix a typo in last change.

(obache)

2013-12-23 01:34:03 UTC MAIN commitmail json YAML

Update to Asterisk 11.6.1: this is a security fix update to fix
AST-2013-006 and AST-2013-007, and a minor bug fix update.

pkgsrc change: disable SRTP on NetBSD as it doesn't link

---- 11.6.1 ----

The Asterisk Development Team has announced security releases for Certified
Asterisk 1.8.15, 11.2, and Asterisk 1.8, 10, and 11. The available security
releases are released as versions 1.8.15-cert4, 11.2-cert3, 1.8.24.1, 10.12.4,
10.12.4-digiumphones, and 11.6.1.

The release of these versions resolve the following issues:

* A buffer overflow when receiving odd length 16 bit messages in app_sms. An
  infinite loop could occur which would overwrite memory when a message is
  received into the unpacksms16() function and the length of the message is an
  odd number of bytes.

* Prevent permissions escalation in the Asterisk Manager Interface. Asterisk
  now marks certain individual dialplan functions as 'dangerous', which will
  inhibit their execution from external sources.

  A 'dangerous' function is one which results in a privilege escalation. For
  example, if one were to read the channel variable SHELL(rm -rf /) Bad
  Things(TM) could happen; even if the external source has only read
  permissions.

  Execution from external sources may be enabled by setting 'live_dangerously'
  to 'yes' in the [options] section of asterisk.conf. Although doing so is not
  recommended.

These issues and their resolutions are described in the security advisories.

For more information about the details of these vulnerabilities, please read
security advisories AST-2013-006 and AST-2013-007, which were
released at the same time as this announcement.

For a full list of changes in the current releases, please see the ChangeLogs:

http://downloads.asterisk.org/pub/telephony/asterisk/releases/ChangeLog-11.6.1

The security advisories are available at:

* http://downloads.asterisk.org/pub/security/AST-2013-006.pdf
* http://downloads.asterisk.org/pub/security/AST-2013-007.pdf

Thank you for your continued support of Asterisk!

----- 11.6.0 -----

The Asterisk Development Team has announced the release of Asterisk 11.6.0.

The release of Asterisk 11.6.0 resolves several issues reported by the
community and would have not been possible without your participation.
Thank you!

The following is a sample of the issues resolved in this release:

* --- Confbridge: empty conference not being torn down
  (Closes issue ASTERISK-21859. Reported by Chris Gentle)

* --- Let Queue wrap up time influence member availability
  (Closes issue ASTERISK-22189. Reported by Tony Lewis)

* --- Fix a longstanding issue with MFC-R2 configuration that
      prevented users
  (Closes issue ASTERISK-21117. Reported by Rafael Angulo)

* --- chan_iax2: Fix saving the wrong expiry time in astdb.
  (Closes issue ASTERISK-22504. Reported by Stefan Wachtler)

* --- Fix segfault for certain invalid WebSocket input.
  (Closes issue ASTERISK-21825. Reported by Alfred Farrugia)

For a full list of changes in this release, please see the ChangeLog:

http://downloads.asterisk.org/pub/telephony/asterisk/ChangeLog-11.6.0

Thank you for your continued support of Asterisk!

(jnemeth)

2013-12-22 21:32:36 UTC MAIN commitmail json YAML

Fix build on NetBSD-5* using a patch from John D. Baker in PR 48469.

(wiz)

2013-12-22 19:47:41 UTC MAIN commitmail json YAML

2013-12-22 15:29:20 UTC MAIN commitmail json YAML

fvwm no longer requires xpmroot, so remove xpmroot.

(dholland)

2013-12-22 15:23:48 UTC MAIN commitmail json YAML

+ bup-0.25 [wiz], calibre-1.16, coreutils-8.22, curl-7.34.0, enlightenment-0.18,
  glade-3.16.1, glproto-1.4.17, gob2-2.0.20, gupnp-0.20.9,
  hicolor-icon-theme-0.13, itstool-2.0.2, libgcrypt-1.6.0,
  libgdata-0.14.1, libzip-0.11.2 [wiz], meld-1.8.3, memcached-1.4.17,
  monit-5.6 [pkg/48465], pcre-8.34, php-tt-rss-1.11, png-1.6.8,
  py-anki2-2.0.20, py-chardet-2.2.1, py-django-1.6.1, py-sphinx-1.2,
  rainbowcrack-1.5, raptor2-2.0.12, ruby-tw-1.0.2 [pkg/48447],
  serf-1.3.3, surfraw-2.2.9, wine-devel-1.7.9 [wait until NetBSD
  gains OSS 4 [kern/46611] or bring OSS 3 support back],
  x264-devel-20131221, xcb-proto-1.10, xscreensaver-5.24,
  yabause-0.9.13.

(wiz)

2013-12-22 13:42:01 UTC MAIN commitmail json YAML

2013-12-22 12:26:35 UTC MAIN commitmail json YAML

belatedly add x11-links update.

(mrg)

2013-12-22 09:56:17 UTC MAIN commitmail json YAML

Note update of the "wireshark" package to version 1.10.5.

(tron)

2013-12-22 09:55:48 UTC MAIN commitmail json YAML

Update "wireshark" package to version 1.10.5. Changes since 1.10.4:
- The following bugs have been fixed:
  * Wireshark stops showing new packets but dumpcap keeps
    writing them to the temp file. (Bug 9571)
  * Wireshark 1.10.4 shuts down when promiscuous mode is
    unchecked. (Bug 9577)
  * Homeplug dissector bug: STATUS_ACCESS_VIOLATION: dissector
    accessed an invalid memory address. (Bug 9578)
- Updated Protocol Support
  GSM BSSMAP, GSM BSSMAP LE, GSM SMS, Homeplug, NAS-EPS, and SGSAP

(tron)

2013-12-21 19:46:25 UTC MAIN commitmail json YAML

Depend on php-iconv: updater for 1.9 complains:
"PHP support for iconv is required to handle multiple charsets."
Bump PKGREVISION.

(wiz)

2013-12-21 17:29:30 UTC MAIN commitmail json YAML

Update DEPENDS gem versions per tw.gemspec file.

Note both ruby-args_parser-0.2.0 and ruby-parallel-0.8.2 were updated
in September.

(tsutsui)

2013-12-21 16:21:20 UTC MAIN commitmail json YAML

2013-12-21 15:24:15 UTC MAIN commitmail json YAML

Update HOMEPAGE, comment out domain-grabbed MASTER_SITES.

(wiz)

2013-12-21 12:40:46 UTC MAIN commitmail json YAML

2013-12-21 12:21:47 UTC MAIN commitmail json YAML

The syntax of the Configure architecture table changed recently. Our
entries for NetbSD architectures without assembler routines and Interix
containing ::::::... need to be updated, else -fPIC ends up in the
object-to-build list of crypto/modes. The correct entry snippet is
stored in ${no_asm}.
make test has run successfully in pkgsrc-current and -2013Q3 on
Shark (arm, asm-less) as well as i386 (with asm routines).

(is)

2013-12-21 11:31:33 UTC MAIN commitmail json YAML

Remove -soname and avoid stripping on Darwin.  Fixes build.

(jperkin)

2013-12-21 11:15:08 UTC MAIN commitmail json YAML

Remove GNU ld options on Darwin too.

(jperkin)

2013-12-21 11:05:23 UTC MAIN commitmail json YAML

2013-12-21 10:51:52 UTC MAIN commitmail json YAML

Disable visibility on Darwin, fixes build.

(jperkin)

2013-12-21 10:42:29 UTC MAIN commitmail json YAML

2013-12-21 08:59:41 UTC MAIN commitmail json YAML

Use PKGPATH instead of PKGNAME for check current package, because later variable
may not be defined yet and broken with old bmake in netbsd5.

(obache)

2013-12-21 02:47:39 UTC MAIN commitmail json YAML

Note update of www/contao32 and www/contao32-example packages to 3.2.3.

(taca)

2013-12-21 02:46:25 UTC MAIN commitmail json YAML

Update contao32 (and contao32-example) to 3.2.3 during the freeze to
fix a few trivial (but nasty) problems of this almost leaf package:
approved by gdt@.

Version 3.2.3 (2013-12-20)
--------------------------

### Fixed
Correctly resize the mediaboxAdvanced in IE11 (see #6504).

### Fixed
Set the correct status header for cached files (see #6585).

### Fixed
Correctly set the empty value depending on the DB field (fixes #6550, #6544).

### Fixed
Prevent saving of detached models (see #6506).

### Fixed
Correctly determine the ACE editor's height (see #6578).

### Fixed
Always fall back to English if a language does not exist (see #6581).

### Fixed
Correctly display repeated events in the event list (see #6555).

### Fixed
Correctly show the available layout columns in the article module (see #6548).

### Fixed
Correctly show the "read more" link in the news list modules (see #6439).

### Updated
Updated html5shiv to version 3.7.0 (see #6543).

### Fixed
Support browsers with both mouse and touch support in the back end (see #6520).

### Fixed
Correctly handle multiple `RadioTable` widgets on the same page (see #6389).

### Fixed
Fixed two issues with the SQL cache (see #6507).

### Fixed
Do not require a redirect page for newsletter channels (see #6521).

### Fixed
Use the related field instead of `id` in the model query builder (see #6540).

(taca)

2013-12-20 22:42:38 UTC MAIN commitmail json YAML

Deal with different library path of ffmpeg010 to fix build.

(joerg)

2013-12-20 17:17:43 UTC MAIN commitmail json YAML

Update netpgpverify and libnetpgpverify to version 20131219

(agc)

2013-12-20 17:16:48 UTC MAIN commitmail json YAML

Update netpgpverify and libnetpgpverify to version 20131219

Fix a call to mp_radix_size to use a pointer to the BIGNUM, not the
address of the pointer, when accessing.  Fixes a problem observed in
other software when using the same code.  The problem was obscured
from the compiler because of the use of __UNCONST().  This makes the
BN_dec2bn() and BN_hex2bn() functions (in libnetpgpverify) work
properly.

OK: wiz

(agc)

2013-12-20 15:50:09 UTC MAIN commitmail json YAML

Note update of www/fengoffice package to 2.4.0.6.

(taca)

2013-12-20 15:49:34 UTC MAIN commitmail json YAML

Update fengoffice to 2.4.0.6.  (This is a leaf package and this update
contains security fix.)

Since 2.4.0.5
- bugfix: Don't send notification when add mail.

Since 2.4.0.4
- bugfix: Deprecated functions usage.
- bugfix: Emtpy trash can was using a deprecated function with performance issues.
- bugfix: Missing parameters in function invocation.

Since 2.4.0.3
- bugfix: can't delete template task, permission denied.

Since 2.4.0.2
- bugfix: langs customer_folder and project_folder.
- bugfix: can't add contacts from mail.
- bugfix: on activity widget move action don't display.
- bugfix: when create user, notifications break mysql transaction.

Since 2.4.0.1
- bugfix: cron process to emtpy trash can does not delete members asociated to contacts.

Since 2.4.0
- bugfix: tab order fix in quick add task;
- bugfix: issue when create a subtask from task view;

Since 2.4-rc
- fetaure: error message improved when upload limit is reached.
- bugfix: on gantt, names of the tasks were not displayed completely.
- bugfix: on gantt, the time estimation for tasks was not displayed correctly.
- bugfix: date custom properties default value does not use user's timezone.
- bugfix: on people widget add user combo is not ordered by name.
- bugfix: on activity widget dates have gmt errors.
- bugfix: general search allways search for empty string.
- bugfix: url files are not saved correctly when url is not absolute.
- bugfix: imap fetch fixed when last email does not exists in server.
- bugfix: only invite automatically the "filtered user" when adding a new event, not when editing an existing one.
- bugfix: variable member_deleted uninitialized in a cycle, maintains the value of previous iterations and fills the log warnings.
- bugfix: don't display group-mailer button if user doesn't have an email account.
- bugfix: allow mail rules for all incoming messages, useful for autoreplies.
- bugfix: the invitations of the events created on google calendar will have the same special ID of the event.

Since 2.4-beta
- feature: alert users if they have mails in the outbox
- feature: contact custom reports - added columns for address, phones, webpages and im.
- feature: display time estimation in time reports when grouping by tasks
- feature: config option to add default permissions to users when creating a member.
- system: upgrade Swift Mailer from version 4.0.6 to 5.0.1, this improves and solves some issues when sending emails with exchange servers
- bugfix: on user login when save timezone don't change the update_on value
- bugfix: solved an issue when editing a repetitive task and changing its previous repetition value
- bugfix: solved when editing a template task can't remove a dimension member
- bugfix: solved using repeating tasks when applying a template
- bugfix: on tasks and timeslots reports, if grouped by task it diplay milestones
- bugfix: allow the creation of templates in the root (View all)
- bugfix: Users are now shown by default in the People tab.
- bugfix: when printing the task list view, tasks now display their progress and estimation
- bugfix: on general search prevent multiple form submit.

Since 2.3.2.1
- feature: templates have been greatly improved: they have changed completely for good!
- feature: remember selection on total task execution time report
- feature: when sending an email, if a word containing attach is found and no attachment if found, it triggers an alert.
- feature: new user config option to set how many members are shown in breadcrumbs
- feature: update plugins after running upgrade from console.
- feature: add root permission when creating executive or superior users.
- feature: contact edit form has been improved

- bugfix: when uploading avatars, if it is .png and its size is smaller than 128x128 the image is not resized
- bugfix: when sending an mail, the sender is now subscribed to it
- bugfix: when adding a file from an email attachment, its now set to be created by the account owner
- bugfix: reporting pagination fixed
- bugfix: custom reports, csv and pdf export only exports the active page..now it exports everything!
- bugfix: don't collapse task group after performing an action to the task when group is expanded.
- bugfix: email parsing removes enters and some emails were not shown correctly
- bugfix: people widget in french used to cause a syntax error
- bugfix: don't classify email in account's member if conversation is already classified.
- bugfix: task filtering by user has been improved: it loads faster and more accurate
- bugfix: the users selectbox for assignees has been improved: it loads faster and more accurate
- bugfix: check for "can manage contacts" in system permissions if column exists
- bugfix: email parsing does not fetch addresses when they are separated by semicolon
- bugfix: tasks assigned to filter doesn't filter correctly when logged user is an internal collaborator and users can add objects without classifying them.
- bugfix: search result pagination issue
- bugfix: search results ordered by date again
- bugfix: add to searchable objects failed for some emails
- bugfix: custom properties migration fix
- bugfix: feng 1 to feng 2 upgrade improved
- bugfix: style fixes in administration tabs
- bugfix: checkbox in contact tab now is working properly. initially it does not show the users
- bugfix: google calendar sync issue for events with over 100 chars has been solved
- bugfix: contact csv export fixed: when no contact is selected => export all contact csv export fixed
- bugfix: some undefined variables have been defined
- bugfix: some translations that were missing were added
- security: remove xss from request parameters
- performance: search engine has been greatly improved
- other: the search button is disabled until returns the search result
- other: when upgrading to 2.4 the completed tasks from feng 1 will change to 100% in completed percentage

(taca)

2013-12-20 15:46:57 UTC MAIN commitmail json YAML

Updated devel/p5-Proc-Daemon to 0.14nb4

(wen)

2013-12-20 15:43:51 UTC MAIN commitmail json YAML

Fix CVE-2013-7135 (patch is from Debian)
Add LICENSE
Add missing BUILD_DEPENDS for test

Approved by: wiz@

(wen)

2013-12-20 15:35:50 UTC MAIN commitmail json YAML

Simplyfy using REPLACE_BASH instead of REPLACE_INTERPRETER and its
friends.

No functional change.

(taca)

2013-12-20 14:36:41 UTC MAIN commitmail json YAML

Updated lang/nodejs to 0.10.24

(fhajny)

2013-12-20 14:36:27 UTC MAIN commitmail json YAML

2013.12.18, Version 0.10.24 (Stable)
* uv: Upgrade to v0.10.21
* npm: upgrade to 1.3.21
* v8: backport fix for CVE-2013-{6639|6640}
* build: unix install node and dep library headers (Timothy J Fontaine)
* cluster, v8: fix --logfile=%p.log (Ben Noordhuis)
* module: only cache package main (Wyatt Preul)

(fhajny)

2013-12-20 10:03:35 UTC pkgsrc-2013Q3 commitmail json YAML

2013-12-20 08:45:44 UTC pkgsrc-2013Q3 commitmail json YAML

Pullup ticket #4277 - requested by is
graphics/gd: build fix for e.g. arm

Revisions pulled up:
- graphics/gd/distinfo                                          1.34-1.35
- graphics/gd/patches/patch-src_gd__bmp.c                      1.1-1.2

-------------------------------------------------------------------
  Module Name: pkgsrc
  Committed By: dholland
  Date: Mon Nov 11 20:38:16 UTC 2013

  Modified Files:
  pkgsrc/graphics/gd: distinfo
  Added Files:
  pkgsrc/graphics/gd/patches: patch-src_gd__bmp.c

  Log Message:
  Don't use ceill(); it isn't needed here and causes problems. See PR 48334.

  Technically this change should bump PKGREVISION (as it changes the
  binary package ever so slightly for platforms where the ceill() didn't
  cause a build failure) but I'm going to let it slide.

  To generate a diff of this commit:
  cvs rdiff -u -r1.33 -r1.34 pkgsrc/graphics/gd/distinfo
  cvs rdiff -u -r0 -r1.1 pkgsrc/graphics/gd/patches/patch-src_gd__bmp.c

-------------------------------------------------------------------
  Module Name: pkgsrc
  Committed By: dholland
  Date: Mon Nov 11 21:34:40 UTC 2013

  Modified Files:
  pkgsrc/graphics/gd: distinfo
  pkgsrc/graphics/gd/patches: patch-src_gd__bmp.c

  Log Message:
  Add upstream report URL per PR 48334.

  To generate a diff of this commit:
  cvs rdiff -u -r1.34 -r1.35 pkgsrc/graphics/gd/distinfo
  cvs rdiff -u -r1.1 -r1.2 pkgsrc/graphics/gd/patches/patch-src_gd__bmp.c

(spz)

2013-12-20 08:34:50 UTC pkgsrc-2013Q3 commitmail json YAML

Pullup ticket #4276 - requested by tron
net/wireshark: security update

Revisions pulled up:
- net/wireshark/DESCR                                          1.4
- net/wireshark/Makefile                                        1.112
- net/wireshark/distinfo                                        1.71
- net/wireshark/patches/patch-aa                                1.13
- net/wireshark/patches/patch-ab                                1.4
- net/wireshark/patches/patch-ac                                1.2

-------------------------------------------------------------------
  Module Name: pkgsrc
  Committed By: tron
  Date: Wed Dec 18 11:52:26 UTC 2013

  Modified Files:
  pkgsrc/net/wireshark: DESCR Makefile distinfo
  pkgsrc/net/wireshark/patches: patch-aa patch-ab patch-ac

  Log Message:
  Update "wireshark" package to version 1.10.4. Changes since version 1.10.3:
  - Bug Fixes
      The following vulnerabilities have been fixed.
        * wnpa-sec-2013-66
          The SIP dissector could go into an infinite loop.
          Discovered by Alain Botti. (Bug 9388)
          Versions affected: 1.10.0 to 1.10.3, 1.8.0 to 1.8.11
          CVE-2013-7112
        * wnpa-sec-2013-67
          The BSSGP dissector could crash. Discovered by Laurent
          Butti. (Bug 9488)
          Versions affected: 1.10.0 to 1.10.3
          CVE-2013-7113
        * wnpa-sec-2013-68
          The NTLMSSP v2 dissector could crash. Discovered by Garming
          Sam.
          Versions affected: 1.10.0 to 1.10.3, 1.8.0 to 1.8.11
          CVE-2013-7114
      The following bugs have been fixed:
        * "On-the-wire" packet lengths are limited to 65535 bytes.
          (Bug 8808, ws-buglink:9390)
        * Tx MCS set is not interpreted properly in WLAN beacon
          frame. (Bug 8894)
        * VoIP Graph Analysis window - some calls are black. (Bug
          8966)
        * Wireshark fails to decode single-line, multiple Contact:
          URIs in SIP responses. (Bug 9031)
        * epan/follow.c - Incorrect "bytes missing in capture file"
          in "check_fragments" due to an unsigned int wraparound?.
          (Bug 9112)
        * gsm_map doesn't decode MAPv3 reportSM-DeliveryStatus
          result. (Bug 9382)
        * Incorrect NFSv4 FATTR4_SECURITY_LABEL value. (Bug 9383)
        * Timestamp decoded for Gigamon trailer is not padded
          correctly. (Bug 9433)
        * SEL Fast Message Bug-fix for Signed 16-bit Integer Fast
          Meter Messages. (Bug 9435)
        * DNP3 Bug Fix for Analog Data Sign Bit Handling. (Bug
          9442)
        * GSM SMS User Data header fill bits are wrong when using a 7
          bits ASCII / IA5 encoding. (Bug 9478)
        * WCDMA RLC dissector cannot assemble PDUs with SNs skipped
          and wrap-arounded. (Bug 9505)
        * DTLS: fix buffer overflow in mac check. (Bug 9512)
        *  Correct data length in SCSI_DATA_IN packets (within
          iSCSI). (Bug 9521)
        * GSM SMS UDH EMS control expects 4 octets instead of 3 with
          OPTIONAL 4th. (Bug 9550)
        * Fix "decode as ..." for packet-time.c. (Bug 9563)
  - Updated Protocol Support
    ANSI IS-637-A, BSSGP, DNP3, DVB-BAT, DVB-CI, GSM MAP, GSM SMS,
    IEEE 802.11, iSCSI, NFSv4, NTLMSSP v2, RLC, SEL FM, SIP, and Time

  To generate a diff of this commit:
  cvs rdiff -u -r1.3 -r1.4 pkgsrc/net/wireshark/DESCR
  cvs rdiff -u -r1.111 -r1.112 pkgsrc/net/wireshark/Makefile
  cvs rdiff -u -r1.70 -r1.71 pkgsrc/net/wireshark/distinfo
  cvs rdiff -u -r1.12 -r1.13 pkgsrc/net/wireshark/patches/patch-aa
  cvs rdiff -u -r1.3 -r1.4 pkgsrc/net/wireshark/patches/patch-ab
  cvs rdiff -u -r1.1 -r1.2 pkgsrc/net/wireshark/patches/patch-ac

(spz)

2013-12-20 02:36:10 UTC MAIN commitmail json YAML

exactly check for the case MAKE_JOBS.
fixes for old bmake behavior in netbsd5 and missing MAKE_JOBS.

(obache)

2013-12-19 23:50:29 UTC MAIN commitmail json YAML

Improve support for HTTPS master site URLs:
As the default fetch program "tnftp" (in "pkgsrc" and all released
versions of NetBSD) doesn't support HTTPS prefer "fetch" (DragonFlyBSD,
FreeBSD and Minix) or Curl (CygWin, Linux, Mac OS X, Solaris) if available.

Change during pkgsrc-freeze approved by Greg Troxel and Thomas Klausner.

(tron)

2013-12-19 20:27:24 UTC MAIN commitmail json YAML

Use SPECIAL_PERMS on MirBSD, too. Fix build.

(bsiegert)

2013-12-19 14:29:07 UTC MAIN commitmail json YAML

Add a Platform/MirBSD.cmake file to fix the MirBSD build. The file is
installed along with other platform files, so I had to amend PLIST and
bump the PKGREVISION.

reviewed by wiz@, adam@

(bsiegert)

2013-12-19 09:34:28 UTC MAIN commitmail json YAML

Make KEYMAP_PATH match the directory keymaps are installed in. Hi prlw1!

(sborrill)

2013-12-19 04:15:52 UTC MAIN commitmail json YAML

remove qt5-ibus; no such directory

(jnemeth)

2013-12-18 23:48:22 UTC MAIN commitmail json YAML

Pick up maintainership.

(wiz)

2013-12-18 19:12:03 UTC MAIN commitmail json YAML

Configure looks for bison, and 'make' dies without a yacc, as the SunOS
bulk builds show. Add bison to USE_TOOLS.

(wiz)

2013-12-18 18:56:34 UTC MAIN commitmail json YAML

Updated security/gnupg to 1.4.16

(wiz)

2013-12-18 18:56:24 UTC MAIN commitmail json YAML

Update to 1.4.16:

Noteworthy changes in version 1.4.16 (2013-12-18)
-------------------------------------------------

* Fixed the RSA Key Extraction via Low-Bandwidth Acoustic
  Cryptanalysis attack as described by Genkin, Shamir, and Tromer.
  See <http://www.cs.tau.ac.il/~tromer/acoustic/>.  [CVE-2013-4576]

* Put only the major version number by default into armored output.

* Do not create a trustdb file if --trust-model=always is used.

* Print the keyid for key packets with --list-packets.

* Changed modular exponentiation algorithm to recover from a small
  performance loss due to a change in 1.4.14.

(wiz)

2013-12-18 18:51:03 UTC MAIN commitmail json YAML

Improve doc handling, from Niclas Rosenvik in PR 48454.
Really fixes packaging when doxygen already is installed.

No change by default, so no PKGREVISION++.

(wiz)

2013-12-18 17:55:15 UTC MAIN commitmail json YAML

2013-12-18 17:53:44 UTC MAIN commitmail json YAML

When using deprecated features, it helps to not disable them first.

(joerg)

2013-12-18 13:37:25 UTC MAIN commitmail json YAML

Apply the changes from setup2.py to setup3.py as well to fix the build
of the Python 3.x variant.

(joerg)

2013-12-18 11:52:49 UTC MAIN commitmail json YAML

Note update of the "wireshark" package to version 1.10.4.

(tron)

2013-12-18 11:52:26 UTC MAIN commitmail json YAML

Update "wireshark" package to version 1.10.4. Changes since version 1.10.3:
- Bug Fixes
  The following vulnerabilities have been fixed.
    * wnpa-sec-2013-66
      The SIP dissector could go into an infinite loop.
      Discovered by Alain Botti. (Bug 9388)
      Versions affected: 1.10.0 to 1.10.3, 1.8.0 to 1.8.11
      CVE-2013-7112
    * wnpa-sec-2013-67
      The BSSGP dissector could crash. Discovered by Laurent
      Butti. (Bug 9488)
      Versions affected: 1.10.0 to 1.10.3
      CVE-2013-7113
    * wnpa-sec-2013-68
      The NTLMSSP v2 dissector could crash. Discovered by Garming
      Sam.
      Versions affected: 1.10.0 to 1.10.3, 1.8.0 to 1.8.11
      CVE-2013-7114
  The following bugs have been fixed:
    * "On-the-wire" packet lengths are limited to 65535 bytes.
      (Bug 8808, ws-buglink:9390)
    * Tx MCS set is not interpreted properly in WLAN beacon
      frame. (Bug 8894)
    * VoIP Graph Analysis window - some calls are black. (Bug
      8966)
    * Wireshark fails to decode single-line, multiple Contact:
      URIs in SIP responses. (Bug 9031)
    * epan/follow.c - Incorrect "bytes missing in capture file"
      in "check_fragments" due to an unsigned int wraparound?.
      (Bug 9112)
    * gsm_map doesn't decode MAPv3 reportSM-DeliveryStatus
      result. (Bug 9382)
    * Incorrect NFSv4 FATTR4_SECURITY_LABEL value. (Bug 9383)
    * Timestamp decoded for Gigamon trailer is not padded
      correctly. (Bug 9433)
    * SEL Fast Message Bug-fix for Signed 16-bit Integer Fast
      Meter Messages. (Bug 9435)
    * DNP3 Bug Fix for Analog Data Sign Bit Handling. (Bug
      9442)
    * GSM SMS User Data header fill bits are wrong when using a 7
      bits ASCII / IA5 encoding. (Bug 9478)
    * WCDMA RLC dissector cannot assemble PDUs with SNs skipped
      and wrap-arounded. (Bug 9505)
    * DTLS: fix buffer overflow in mac check. (Bug 9512)
    *  Correct data length in SCSI_DATA_IN packets (within
      iSCSI). (Bug 9521)
    * GSM SMS UDH EMS control expects 4 octets instead of 3 with
      OPTIONAL 4th. (Bug 9550)
    * Fix "decode as ..." for packet-time.c. (Bug 9563)
- Updated Protocol Support
  ANSI IS-637-A, BSSGP, DNP3, DVB-BAT, DVB-CI, GSM MAP, GSM SMS,
  IEEE 802.11, iSCSI, NFSv4, NTLMSSP v2, RLC, SEL FM, SIP, and Time

(tron)

2013-12-18 10:02:55 UTC pkgsrc-2013Q3 commitmail json YAML

2013-12-18 10:02:40 UTC pkgsrc-2013Q3 commitmail json YAML

Pullup ticket #4275 - requested by taca
devel/ruby-i18n: security update

Revisions pulled up:
- devel/ruby-i18n/Makefile                                      1.9
- devel/ruby-i18n/PLIST                                        1.5
- devel/ruby-i18n/distinfo                                      1.8

---
  Module Name: pkgsrc
  Committed By: taca
  Date: Mon Dec 16 09:21:34 UTC 2013

  Modified Files:
  pkgsrc/devel/ruby-i18n: Makefile PLIST distinfo

  Log Message:
  Update ruby-i18n to 0.6.9.  This is security fix.

  * Add I18n::exists? method.
  * Add I18n.locale_available? method.
  * Delete unused files.
  * I18n::MissingTranslation exception escapes key names for its
    html_message, fixing CVE-2013-4492.
  * Use CGI.escapeHTML instead of CGI.escape_html for Ruby 1.8.7.
  * Fix an issue with setting I18n.config.enforce_available_locales.

(tron)

2013-12-18 02:31:32 UTC MAIN commitmail json YAML

Note PKGREVISION bump of teTeX-bin

(minskim)

2013-12-18 02:30:32 UTC MAIN commitmail json YAML

2013-12-17 23:23:38 UTC MAIN commitmail json YAML

Use a pointer to the void type, not a enum value that turns out to be 0.
Bump revision.

(joerg)

2013-12-17 23:22:36 UTC MAIN commitmail json YAML

2013-12-17 19:10:11 UTC MAIN commitmail json YAML

Maintainer mode was being activated in all cases, which is not
desirable; in particular on builds it enables -Werror which causes
the build to fail now.  from Debian by way of FreeBSD.

(markd)

2013-12-17 16:27:18 UTC MAIN commitmail json YAML

2013-12-17 15:05:23 UTC MAIN commitmail json YAML

Small fixes:
1.) Comment out "MASTER_SITES". The URL no longer works and all copies
    that Google can find are "pkgsrc" distfile mirrors.
2.) Fix various "pkglint" errors.

(tron)

2013-12-17 14:00:49 UTC MAIN commitmail json YAML

Updated mail/thunderbird17-l10n to 17.0.11

(ryoon)

2013-12-17 14:00:13 UTC MAIN commitmail json YAML

Update to 17.0.11

* Sync with thunderbird17-17.0.11

(ryoon)

2013-12-17 13:42:23 UTC MAIN commitmail json YAML

Updated mail/thunderbird17 to 17.0.11

(ryoon)

2013-12-17 13:41:41 UTC MAIN commitmail json YAML

Update to 17.0.11

* This package uses external NSS (devel/nss)

Changelog:
Fixed in Thunderbird ESR 17.0.11
MFSA 2013-103 Miscellaneous Network Security Services (NSS) vulnerabilities

(ryoon)

2013-12-17 13:27:12 UTC MAIN commitmail json YAML

Updated mail/thunderbird-l10n to 24.2.0

(ryoon)

2013-12-17 13:26:38 UTC MAIN commitmail json YAML

2013-12-17 13:25:45 UTC MAIN commitmail json YAML

Updated www/firefox24-l10n to 24.2.0

(ryoon)

2013-12-17 13:25:22 UTC MAIN commitmail json YAML

Update to 24.2.0

* Sync with firefox24-24.2.0

(ryoon)

2013-12-17 13:24:23 UTC MAIN commitmail json YAML

Updated www/firefox-l10n to 26.0

(ryoon)

2013-12-17 13:23:19 UTC MAIN commitmail json YAML

2013-12-17 13:10:31 UTC pkgsrc-2013Q3 commitmail json YAML

2013-12-17 13:10:12 UTC pkgsrc-2013Q3 commitmail json YAML

Pullup ticket #4274 - requested by taca
www/typo3_45: security update

Revisions pulled up:
- www/typo3_45/Makefile                                        1.28-1.29
- www/typo3_45/PLIST                                            1.13
- www/typo3_45/distinfo                                        1.23-1.24

---
  Module Name: pkgsrc
  Committed By: taca
  Date: Thu Dec  5 16:41:07 UTC 2013

  Modified Files:
  pkgsrc/www/typo3_45: Makefile distinfo

  Log Message:
  Update typo345 to 4.5.31 (TYPO3 4.5.31).

  2013-11-26  434ce71                  [RELEASE] Release of TYPO3 4.5.31 (TYPO3 Release Team)
  2013-11-19  396534e  #53758          [BUGFIX] Table cache_imagesizes is defined twice (Michiel Roos)
  2013-11-19  3f2ed1d  #53750          [BUGFIX] Scheduler extension sql file is invalid (Michiel Roos)
  2013-11-15  428baac  #17493          [BUGFIX] Fix broken edit icons on cType HTML (Stefan Neufeind)
  2013-11-11  6755f40  #37948          [BUGFIX] Correctly append additionalTreelistUpdateFields (Bart Dubelaar)
  2013-11-11  082facd  #31998          [BUGFIX] Faulty check for missing SMTP port (Stefan Neufeind)
  2013-11-09  c581f33  #29179          [BUGFIX] Escape title, extension, description of scheduler tasks (Stefan Neufeind)
  2013-11-09  7b08aa9  #53195          [BUGFIX] T3editor: Honour fileDenyPattern on saving included TS (Stefan Neufeind)
  2013-11-04  d372f5f  #38055          [BUGFIX] Remove declare(encoding=) (Josef Florian Glatz)
  2013-10-28  5ae438c  #53075          [BUGFIX] Cannot auto-load SC_* classes (Ernesto Baschny)
  2013-10-22  b5d6e9f  #50881          [TASK] Added missing core autoloaded files (Ernesto Baschny)
  2013-10-13  5b072ff  #52759          [BUGFIX] Object passed to date() (Philipp Gampe)
  2013-10-12  6371e46  #52104          [BUGFIX] Wrong calculation of maximum value for checkbox fields (Nicole Cordes)
  2013-10-12  78871e2  #37611          [BUGFIX] Select available page when changing WS (Thorsten Kahler)
  2013-10-11  ce02c01  #36573          [BUGFIX] Add workspace overlay for fetched records. (Anja Leichsenring)
  2013-10-11  d114ddb  #37065          [BUGFIX] Don't show duplicates in workspace preview (Timo Webler)
  2013-10-06  3289c39  #52045          [BUGFIX] EmConfUtility accesses non-arrays (Markus Klein)
  2013-09-27  cd1e12b  #52091,#51684  [BUGFIX] Check for string before using strlen (Markus Klein)
  2013-09-26  c8d2033  #34886          [BUGFIX] CF FileBackend unlimited lifetime support (Dominique Feyer)
  2013-09-18  ef6dc06                  [BUGFIX] Fix cropping of transparent gifs with im6. (Felix Bu
(tron)

2013-12-17 11:39:38 UTC MAIN commitmail json YAML

g-ir-scanner on Darwin doesn't like empty comments, fixes hang.

(jperkin)

2013-12-17 11:35:20 UTC MAIN commitmail json YAML

2013-12-17 07:07:22 UTC MAIN commitmail json YAML

One more file installed on FreeBSD.

(asau)

2013-12-17 07:02:07 UTC MAIN commitmail json YAML

One more file installed on FreeBSD (same as NetBSD).

(asau)

2013-12-17 06:48:08 UTC MAIN commitmail json YAML

POSIX shmem module is installed on FreeBSD.

(asau)

2013-12-17 06:45:40 UTC MAIN commitmail json YAML

2013-12-17 05:39:55 UTC MAIN commitmail json YAML

one update notice is enough

(jnemeth)

2013-12-17 05:37:53 UTC MAIN commitmail json YAML

Updated comms/asterisk10 to 10.12.4

(jnemeth)

2013-12-17 05:37:29 UTC MAIN commitmail json YAML

Updated comms/asterisk10 to 10.12.4

(jnemeth)

2013-12-17 05:37:10 UTC MAIN commitmail json YAML

Update to Asterisk 10.12.4:  this is a security fix update that fixes
AST-2013-006 and AST-2013-007.

The Asterisk Development Team has announced security releases for Certified
Asterisk 1.8.15, 11.2, and Asterisk 1.8, 10, and 11. The available security
releases are released as versions 1.8.15-cert4, 11.2-cert3, 1.8.24.1, 10.12.4,
10.12.4-digiumphones, and 11.6.1.

The release of these versions resolve the following issues:

* A buffer overflow when receiving odd length 16 bit messages in app_sms. An
  infinite loop could occur which would overwrite memory when a message is
  received into the unpacksms16() function and the length of the message is an
  odd number of bytes.

* Prevent permissions escalation in the Asterisk Manager Interface. Asterisk
  now marks certain individual dialplan functions as 'dangerous', which will
  inhibit their execution from external sources.

  A 'dangerous' function is one which results in a privilege escalation. For
  example, if one were to read the channel variable SHELL(rm -rf /) Bad
  Things(TM) could happen; even if the external source has only read
  permissions.

  Execution from external sources may be enabled by setting 'live_dangerously'
  to 'yes' in the [options] section of asterisk.conf. Although doing so is not
  recommended.

These issues and their resolutions are described in the security advisories.

For more information about the details of these vulnerabilities, please read
security advisories AST-2013-006 and AST-2013-007, which were
released at the same time as this announcement.

For a full list of changes in the current releases, please see the ChangeLogs:

http://downloads.asterisk.org/pub/telephony/asterisk/releases/ChangeLog-1.8.24.1

The security advisories are available at:

* http://downloads.asterisk.org/pub/security/AST-2013-006.pdf
* http://downloads.asterisk.org/pub/security/AST-2013-007.pdf

Thank you for your continued support of Asterisk!

(jnemeth)

2013-12-17 05:32:33 UTC MAIN commitmail json YAML

No separate library for dlopen on FreeBSD too.

(asau)

2013-12-17 02:29:28 UTC MAIN commitmail json YAML

Updated comms/asterisk18 to 1.8.24.1

(jnemeth)

2013-12-17 02:29:11 UTC MAIN commitmail json YAML

Update to Asterisk 1.8.24.1:  this is a security update that fixes
AST-2013-006 and AST-2013-007.

The Asterisk Development Team has announced security releases for Certified
Asterisk 1.8.15, 11.2, and Asterisk 1.8, 10, and 11. The available security
releases are released as versions 1.8.15-cert4, 11.2-cert3, 1.8.24.1, 10.12.4,
10.12.4-digiumphones, and 11.6.1.

The release of these versions resolve the following issues:

* A buffer overflow when receiving odd length 16 bit messages in app_sms. An
  infinite loop could occur which would overwrite memory when a message is
  received into the unpacksms16() function and the length of the message is an
  odd number of bytes.

* Prevent permissions escalation in the Asterisk Manager Interface. Asterisk
  now marks certain individual dialplan functions as 'dangerous', which will
  inhibit their execution from external sources.

  A 'dangerous' function is one which results in a privilege escalation. For
  example, if one were to read the channel variable SHELL(rm -rf /) Bad
  Things(TM) could happen; even if the external source has only read
  permissions.

  Execution from external sources may be enabled by setting 'live_dangerously'
  to 'yes' in the [options] section of asterisk.conf. Although doing so is not
  recommended.

These issues and their resolutions are described in the security advisories.

For more information about the details of these vulnerabilities, please read
security advisories AST-2013-006 and AST-2013-007, which were
released at the same time as this announcement.

For a full list of changes in the current releases, please see the ChangeLogs:

http://downloads.asterisk.org/pub/telephony/asterisk/releases/ChangeLog-1.8.24.1

The security advisories are available at:

* http://downloads.asterisk.org/pub/security/AST-2013-006.pdf
* http://downloads.asterisk.org/pub/security/AST-2013-007.pdf

Thank you for your continued support of Asterisk!

(jnemeth)

2013-12-17 01:46:39 UTC MAIN commitmail json YAML

Note update of tex-context{,-doc}

These were updated during freeze because tex-context-doc didn't build.

(minskim)

2013-12-17 01:43:29 UTC MAIN commitmail json YAML

2013-12-17 01:08:30 UTC MAIN commitmail json YAML

main DISTFILE must not be commented out.

(obache)

2013-12-16 19:51:14 UTC MAIN commitmail json YAML

No utmp.h on modern FreeBSD, use utmpx.h instead.

(asau)

2013-12-16 19:35:16 UTC MAIN commitmail json YAML

2013-12-16 19:00:03 UTC MAIN commitmail json YAML

2013-12-16 17:51:25 UTC pkgsrc-2013Q3 commitmail json YAML

Pullup tickets #4267, #4269, #4270, #4271, #4272 and #4273.

(tron)

2013-12-16 17:44:31 UTC pkgsrc-2013Q3 commitmail json YAML

Pullup ticket #4273 - requested by taca
net/samba: security update

Revisions pulled up:
- net/samba/Makefile                                            1.241
- net/samba/distinfo                                            1.96

---
  Module Name: pkgsrc
  Committed By: taca
  Date: Mon Dec  9 10:44:22 UTC 2013

  Modified Files:
  pkgsrc/net/samba: Makefile distinfo

  Log Message:
  Update samba to 3.6.22; Security fix for CVE-2012-6150.

  Changes since 3.6.21:
  ---------------------

  o  Jeremy Allison <jra@samba.org>
      * BUG 10185: CVE-2013-4408: Correctly check DCE-RPC fragment length field.

  o  Stefan Metzmacher <metze@samba.org>
      * BUG 10185: CVE-2013-4408: Correctly check DCE-RPC fragment length field.

  o  Noel Power <noel.power@suse.com>
      * BUGs 10300, 10306: CVE-2012-6150: Fail authentication if user isn't
        member of *any* require_membership_of specified groups.

  Changes since 3.6.20:
  ---------------------

  o  Jeremy Allison <jra@samba.org>
      * BUG 10139: Valid utf8 filenames cause "invalid conversion error"
        messages.
      * BUG 10167: s3-smb2 server: smb2 breaks "smb encryption = mandatory".
      * BUG 10187: Missing talloc_free can leak stackframe in error path.
      * BUG 10247: xattr: Fix listing EAs on *BSD for non-root users.

  o  Korobkin <korobkin+samba@gmail.com>
      * BUG 10118: Raise debug level for being unable to open a printer.

  o  Volker Lendecke <vl@samba.org>
      * BUG 10195: nsswitch: Fix short writes in winbind_write_sock.

  o  Arvid Requate <requate@univention.de>
      * BUG 10267: Fix Windows 8 printing via local printer drivers.

  o  Andreas Schneider <asn@cryptomilk.org>
      * BUG 10194: Make offline logon cache updating for cross child domain
        group membership.

(tron)

2013-12-16 17:35:05 UTC pkgsrc-2013Q3 commitmail json YAML

Pullup ticket #4272 - requested by taca
www/typo3_61: security update

Revisions pulled up:
- www/typo3_61/Makefile                                        1.2-1.3
- www/typo3_61/PLIST                                            1.2
- www/typo3_61/distinfo                                        1.2-1.3

---
  Module Name: pkgsrc
  Committed By: taca
  Date: Thu Dec  5 16:45:04 UTC 2013

  Modified Files:
  pkgsrc/www/typo3_61: Makefile PLIST distinfo

  Log Message:
  Update typo3_61 to 6.1.6 (TYPO3 6.1.6).

  2013-11-26  3f69433                  [RELEASE] Release of TYPO3 6.1.6 (TYPO3 Release Team)
  2013-11-26  3eda399  #53918          [BUGFIX] t3skin calls addIconSprite for each lang (Michiel Roos)
  2013-11-24  93ed8d2  #51650          [BUGFIX] TS: Allow "0" as strPad.padWith (Lars Peipmann)
  2013-11-24  aed6051  #15958          [BUGFIX] Reload list module on clickmenu action (Bernhard Kraft)
  2013-11-21  7042298  #53802          [BUGFIX] Fix moving/copying files and folders between storages (Frans Saris)
  2013-11-21  b78c694  #53844          [BUGFIX] Fix regression in ResourceCompressor (Markus Klein)
  2013-11-20  3d3de05  #53243          [BUGFIX] Filemtime / Filesize trigger warning (Tomita Militaru)
  2013-11-20  6c5d53d  #53458          [BUGFIX] Fluid paginate widget wrong number of links (Klaas Johan Kooistra)
  2013-11-20  52b751e                  Revert "[BUGFIX] Page module: Allow to paste in empty columns" (Markus Klein)
  2013-11-20  dbcaf93  #44002,#35980,  [BUGFIX] Page module: Allow to paste in empty columns (Bernhard Kraft)
  2013-11-19  023014c  #38766          [BUGFIX] l10n_mode for "pages" table and group fields. (Johannes Feustel)
  2013-11-19  9d97a70  #53773          [BUGFIX] Fix JS error in lang module (Markus Klein)
  2013-11-19  170f084  #53750          [BUGFIX] Scheduler extension sql file is invalid (Michiel Roos)
  2013-11-19  abcd5e9  #34544          [BUGFIX] fix javascript error "TBE_EDITOR not defined" in sys_action (Ralf Hettinger)
  2013-11-19  ba82fac  #51998          [BUGFIX] ExtDirect StateProvider should store all settings (Johannes Feustel)
  2013-11-19  571c8c9  #53746          [TASK] Optimization in AbstractViewHelper (Wouter Wolters)
  2013-11-18  33b0d1b  #53707          [BUGFIX] Rename hook in VariableFrontend.php (Nicole Cordes)
  2013-11-18  fbd9379  #53711          [BUGFIX] additionalAttributes for be.buttons.icon-VH misses hsc (Markus Klein)
  2013-11-18  fa87ad9  #53014          [BUGFIX] Check for query failures in admin methods (Thomas Maroschik)
  2013-11-15  7223b78                  Revert "[BUGFIX] EM: Fetch list as html, not as json" (Helmut Hummel)
  2013-11-14  62f7e87  #45724          [BUGFIX] FILES.folder does not work (Stefan Froemken)
  2013-11-14  c65640d  #51234          [BUGFIX] Move beuser property mappings to global scope (Philipp Gampe)
  2013-11-14  35a95b0  #17493          [BUGFIX] Fix broken edit icons on cType HTML (Stefan Neufeind)
  2013-11-13  fd66dfc  #25157,#45550  [BUGFIX] Distinguish unassigend columns and colPos 0 (Georg Ringer)
  2013-11-13  0641f4f  #51918          [BUGFIX] Native date and datetime values do not consider timezone (Oliver Hader)
  2013-11-12  9aa1fa2  #52926          [BUGFIX] Compressor resolves dots in filenames correctly (Christian Kuhn)
  2013-11-12  fa77640  #53115          [BUGFIX] T3editor: Make errors/exceptions show correctly (Stefan Neufeind)
  2013-11-12  259c64d  #22136          [BUGFIX] Fix menu popup for all IE versions (Alexander Opitz)
  2013-11-12  ffd8480  #52934          [BUGFIX] dataTables: Avoid sending cookie-data too often (Stefan Neufeind)
  2013-11-12  c3b0ebc  #53399          [BUGFIX] Wrong usage-text for cli_dispatch (Tomita Militaru)
  2013-11-12  dcdb7bb  #52904          [BUGFIX] Evaluator in JS fails with namespaces (Stefan Aebischer)
  2013-11-12  cf50919  #53538          [BUGFIX] Make be.buttons.icon-ViewHelper extensible (Stefan Neufeind)
  2013-11-11  fbb19b4  #52727          [TASK] Hard-coded labels in file collections (Tomita Militaru)
  2013-11-11  3dd29c3  #37948          [BUGFIX] Correctly append additionalTreelistUpdateFields (Bart Dubelaar)
  2013-11-11  a3153a3  #52488          [BUGFIX] Call to FlashMessageQueue::addMessage() method in extbase (Markus Klein)
  2013-11-11  b61f34f  #53423          [BUGFIX] EM: Fetch list as html, not as json (Stefan Neufeind)
  2013-11-10  093d7ac  #52173          [BUGFIX] Correct storage selection (follow-up) (Ernesto Baschny)
  2013-11-09  7015242  #53477          [TASK] Fix superfluous strlen() on constant strings (Steffen Ritter)
  2013-11-09  827bf21  #47040          [BUGFIX] Enable treeConfig overriding by Page TSconfig (Stefan Froemken)
  2013-11-09  0b03e72  #53195          [BUGFIX] T3editor: Honour fileDenyPattern on saving included TS (Stefan Neufeind)
  2013-11-08  6f1625f  #29179          [BUGFIX] Escape title, extension, description of scheduler tasks (Tomita Militaru)
  2013-10-23  d34bde3  #31572          [BUGFIX] Exception using cObject FORM in TypoScript (Andreas Bouche)
  2013-10-18  840a3a6  #35073          [BUGFIX] Enable BE search for multiple mountpoints (Georg Ringer)
  2013-10-17  775a077  #52931          [TASK] Exclude central Modernizr from concatenation (Stefan Neufeind)
  2013-10-17  0382419  #52570          [TASK] Tests for Persistence\Generic\Backend::getIdentifierByObject (Stefan Neufeind)
  2013-10-17  b78dc4e  #50548          [BUGFIX] Getting the identifier for a lazy object fails (Marc Bastian Heinrichs)
  2013-10-16  2f1fb3f  #52529          [BUGFIX] Suppress empty tag names in output of array2xml (Markus Hoelzle)
  2013-10-16  b218036  #52823          [BUGFIX] Preserve vendor name in refering request (Thomas Maroschik)
  2013-10-16  88cc508                  [BUGFIX] Follow-Up: Fatal error due to missing use statement (Sascha Egerer)
  2013-10-15  1761850  #52845          [BUGFIX] Moving folders fails (Oliver Hader)
  2013-10-15  be9b7c7  #50802          [BUGFIX] Only load folder contents if folder is initialised (Frans Saris)
  2013-10-15  ce693d8  #52824          [BUGFIX] Superfluous usage of ObjectManagerException (Oliver Hader)
  2013-10-15  8be996a  #51707          [FEATURE] Add getValidators to AbstractCompositeValidator (Stefan Froemken)
  2013-10-15  992e4ef  #52771          [BUGFIX] Use callback in preg_replace in RemoveXSS (Jigal van Hemert)
  2013-10-14  50942c2  #52773          [BUGFIX] Detect unix-styled absolute paths on Windows systems (Nicole Cordes)
  2013-10-13  2889f13  #52759          [BUGFIX] Object passed to date() (Xavier Perseguers)
  2013-10-12  f4f2756  #52731          [TASK] Use 6.1 branch in travis-integration for travis (Christian Kuhn)
  2013-10-12  d68c114  #52728          [BUGFIX] Use BackendUtility use statement (Anja Leichsenring)
  2013-10-12  33d4415  #52104          [BUGFIX] Wrong calculation of maximum value for checkbox fields (Nicole Cordes)
  2013-10-12  e3d02ef  #52715          [BUGFIX] Prevent empty newline below scheduler-task-name (Stefan Neufeind)
  2013-10-11  a3f8dfe  #52708          [BUGFIX] DataMapFactory::resolveTableName must remove leading backslashes (Alexander Schnitzler)
  2013-10-11  9b4462b  #50912          [BUGFIX] BackendUtility::viewOnClick() called with non-integer (Oliver Hader)
  2013-10-11  d910b2b  #51051          [BUGFIX] Clear_cache() must not consider page ids lower than 0 (Oliver Hader)
  2013-10-11  1483967  #37611          [BUGFIX] Select available page when changing WS (Thorsten Kahler)
  2013-10-11  f4e1b0e  #52636          [BUGFIX] Copy records to target page before origin page is deleted (Timo Webler)
  2013-10-11  ed4e368  #17551          [BUGFIX] Create workspace placeholder with processed field content (Sascha Egerer)
  2013-10-11  6f47aa5  #36573          [BUGFIX] Add workspace overlay for fetched records. (Timo Webler)
  2013-10-11  d6b57e8  #37209          [BUGFIX] WS preview shows pages changes from all WS (Thorsten Kahler)
  2013-10-11  fcad15e  #52530          [BUGFIX] Delete modified record in WS just deletes WS version (Sascha Egerer)
  2013-10-11  3ac3429  #37065          [BUGFIX] Don't show duplicates in workspace preview (Timo Webler)
  2013-10-10  394d12e  #52178          [BUGFIX] Cannot upload an extension as zip (Xavier Perseguers)
  2013-10-07  8f1afaf  #49538          [BUGFIX] Fields of type file_reference are not properly indexed (Martin Borer)
  2013-10-07  98625ae  #52546          [BUGFIX] Missing closing tag in ElementBrowser (Philipp Gampe)
  2013-10-05  dc5b2f1  #52469          [TASK] Use instanceof comparison instead of string comparison (Benjamin Serfhos)
  2013-09-30  6b2512a  #43540          [BUGFIX] TS is fetched from cache incorrectly sometimes (Dmitry Dulepov)
  2013-09-28  3a3edf1  #48809,#51730,  [BUGFIX] Fix wrong handling of php and TYPO3 dependencies (Susanne Moog)
  2013-09-28  9535891  #51329          [BUGFIX] Initialize extension name in command requests (Alexander Stehlik)
  2013-09-27  06723a0  #52045          [BUGFIX] EmConfUtility accesses non-arrays (Markus Klein)
  2013-09-27  219c381  #51588          [BUGFIX] Clear cached menu by tag (Zbigniew Jacko)
  2013-09-27  b41847a  #50437          [BUGFIX] Fix jumpToUrl()-Usage in Element Browser (Benjamin Pick)
  2013-09-26  6bdc8ad  #52091,#51684  [BUGFIX] Check for string before using strlen (Kilian Hann)
  2013-09-26  9be6739  #52266          [BUGFIX] groupFor-VH does not work with @lazy (Stefan Froemken)
  2013-09-26  d3bf620  #50913          [BUGFIX] Fix PHP warning trigged in getAuthInfoArray() (Christian Finkemeier)
  2013-09-26  993dd5d  #52316          [BUGFIX] Fatal in DefaultConfiguration (Christian Kuhn)
  2013-09-26  bb94fe0  #52305          [BUGFIX] Configure main extbase caches for unlimited entry lifetime (Christian Kuhn)
  2013-09-26  52ff400  #52295          [TASK] Use SimpleFileBackend for t3lib_l10n cache (Christian Kuhn)
  2013-09-25  f0fe1c4  #52226          [BUGFIX] EM does not link to docs.typo3.org (Xavier Perseguers)
  2013-09-25  db5fb24  #51116          [BUGFIX] Increase performance of exports for caches (Markus Klein)
  2013-09-25  28ee210  #52243          [BUGFIX] Remove duplicate exception code (Fabien Udriot)
  2013-09-24  3f53e6b  #52173          [BUGFIX] Correct storage selection (common prefixes) (Ernesto Baschny)
  2013-09-24  1d17a21  #52201          [BUGFIX] Fix broken Unit-test for #44825 (Wouter Wolters)
  2013-09-23  ae9b606  #44825          [BUGFIX] Fix page.headerData + USER_INT (Helmut Hummel)
  2013-09-20  7d08d29  #48912          [BUGFIX] Increase length of identifier field in sys_file (Nicole Cordes)
  2013-09-20  e0600ed  #52056          [BUGFIX] Wrong exception on renaming folder (Francois Suter)
  2013-09-19  9423c2c  #49328          [BUGFIX] Fix PHP warning when writing to Backend user log (Alexander Stehlik)
  2013-09-17  fd534b6  #45859          [BUGFIX] Faulty expand/collapse behavior in Element Browser (Oliver Hader)
  2013-09-17  ce68bcd  #19045          [BUGFIX] Fix cropping of transparent gifs with im6. (Stefan Neufeind)
  2013-09-17  fb5bbbf  #50907          [BUGFIX] Form Wizard: Adds mouse pointer to docheader icons (Ernesto Baschny)
  2013-09-13  0fe373b  #51981          [BUGFIX] Also consider JPEG files for IM/GM (Markus Klein)
  2013-09-12  b0c54dc  #51803          [TASK] Use a 401 header if login is not successful (Georg Ringer)
  2013-09-12  7169032  #47744          [BUGFIX] Replace SHOW DATABASE by query to schema (Alexander Opitz)
  2013-09-12  ddf74b0  #51891          [BUGFIX] Call to undefined method setTemplateFile (Wouter Wolters)

---
  Module Name: pkgsrc
  Committed By: taca
  Date: Tue Dec 10 15:22:20 UTC 2013

  Modified Files:
  pkgsrc/www/typo3_61: Makefile distinfo

  Log Message:
  Update typo3_61 package to 6.1.7 (TYPO3 6.1.7).

  - Fix multiple vulnerabilities in TYPO3 CMS:
  http://typo3.org/teams/security/security-bulletins/typo3-core/typo3-core-sa-2013-004/

  2013-12-10  afbadea                  [RELEASE] Release of TYPO3 6.1.7 (TYPO3 Release Team)
  2013-12-10  7481971  #31206          [SECURITY] XSS in header link of all content elements (Anja Leichsenring)
  2013-12-10  cb8db28  #42772          [SECURITY] XSS in colorpicker wizard (Marcus Krause)
  2013-12-10  2d29894  #45043          [SECURITY] Prevent editor controlled hmac content (Franz G. Jahn)
  2013-12-10  dca9c88  #48691          [SECURITY] XSS in backend user adminstration (Marc Bastian Heinrichs)
  2013-12-10  450e5d3  #41714          [SECURITY] Information Disclosure in Wizards (Helmut Hummel)
  2013-12-10  7e7f9e3  #54099          [SECURITY] Fix open redirection in openid extension (Helmut Hummel)
  2013-12-10  ad11945  #36768          [SECURITY] XSS in be_layout wizard (Anja Leichsenring)
  2013-12-10  18e0491  #47086          [SECURITY] XSS in beuser VH (Anja Leichsenring)
  2013-12-10  cbbeefd  #54074          [SECURITY] Remove possible XSS from ActionController Error output (Anja Leichsenring)
  2013-12-10  163947a  #54073          [SECURITY] Unsafe unserialize of GET parameter in Add-Wizard (Steffen Ritter)
  2013-12-02  d21a628  #54124          [BUGFIX] ClientUtility does not detect Internet Explorer 11 (Stefan Neufeind)
  2013-12-02  e538020  #54117          [BUGFIX] Add missing namespacing for calling GeneralUtility (Stefan Neufeind)
  2013-11-29  3a66a0e  #42651          [BUGFIX] ext:adodb Restrict connection wizard to admins (Christian Kuhn)

(tron)

2013-12-16 17:27:55 UTC pkgsrc-2013Q3 commitmail json YAML

Pullup ticket #4271 - requested by taca
www/typo3_60: security update

Revisions pulled up:
- www/typo3_60/MESSAGE                                          1.1
- www/typo3_60/Makefile                                        1.6-1.7
- www/typo3_60/PLIST                                            1.6
- www/typo3_60/distinfo                                        1.6-1.7

---
  Module Name: pkgsrc
  Committed By: taca
  Date: Thu Dec  5 16:44:04 UTC 2013

  Modified Files:
  pkgsrc/www/typo3_60: Makefile PLIST distinfo
  Added Files:
  pkgsrc/www/typo3_60: MESSAGE

  Log Message:
  Update typo60 to 6.0.11 (TYPO3 6.0.11).  Also add MESSAGE file.

  2013-11-26  5e5f1d2                  [RELEASE] Release of TYPO3 6.0.11 (TYPO3 Release Team)
  2013-11-26  762cb0a  #53918          [BUGFIX] t3skin calls addIconSprite for each lang (Michiel Roos)
  2013-11-24  96944c0  #15958          [BUGFIX] Reload list module on clickmenu action (Bernhard Kraft)
  2013-11-21  9e2a0a1  #53802          [BUGFIX] Fix moving/copying files and folders between storages (Frans Saris)
  2013-11-21  487903a  #53844          [BUGFIX] Fix regression in ResourceCompressor (Markus Klein)
  2013-11-20  aed68c8  #53243          [BUGFIX] Filemtime / Filesize trigger warning (Tomita Militaru)
  2013-11-20  2857828  #53458          [BUGFIX] Fluid paginate widget wrong number of links (Klaas Johan Kooistra)
  2013-11-19  3d6f5be  #53773          [BUGFIX] Fix JS error in lang module (Markus Klein)
  2013-11-19  ea58bd5  #53750          [BUGFIX] Scheduler extension sql file is invalid (Michiel Roos)
  2013-11-19  055e6a5  #34544          [BUGFIX] fix javascript error "TBE_EDITOR not defined" in sys_action (Ralf Hettinger)
  2013-11-19  6c6582a  #51998          [BUGFIX] ExtDirect StateProvider should store all settings (Johannes Feustel)
  2013-11-19  9a5858d  #53746          [TASK] Optimization in AbstractViewHelper (Wouter Wolters)
  2013-11-18  464a804  #53707          [BUGFIX] Rename hook in VariableFrontend.php (Nicole Cordes)
  2013-11-18  ad98c0a  #53711          [BUGFIX] additionalAttributes for be.buttons.icon-VH misses hsc (Markus Klein)
  2013-11-15  d33b4eb                  Revert "[BUGFIX] EM: Fetch list as html, not as json" (Helmut Hummel)
  2013-11-14  ecd873f  #45724          [BUGFIX] FILES.folder does not work (Stefan Froemken)
  2013-11-14  2fef8ad  #51234          [BUGFIX] Move beuser property mappings to global scope (Philipp Gampe)
  2013-11-14  c9c7551  #17493          [BUGFIX] Fix broken edit icons on cType HTML (Stefan Neufeind)
  2013-11-13  c372d65  #25157,#45550  [BUGFIX] Distinguish unassigend columns and colPos 0 (Georg Ringer)
  2013-11-13  e6b77d8  #51918          [BUGFIX] Native date and datetime values do not consider timezone (Oliver Hader)
  2013-11-12  0e4f15a  #52926          [BUGFIX] Compressor resolves dots in filenames correctly (Christian Kuhn)
  2013-11-12  6163c42  #53115          [BUGFIX] T3editor: Make errors/exceptions show correctly (Stefan Neufeind)
  2013-11-12  4435311  #22136          [BUGFIX] Fix menu popup for all IE versions (Alexander Opitz)
  2013-11-12  53a5a1a  #52934          [BUGFIX] dataTables: Avoid sending cookie-data too often (Stefan Neufeind)
  2013-11-12  94c4d70  #53399          [BUGFIX] Wrong usage-text for cli_dispatch (Tomita Militaru)
  2013-11-12  f113773  #52904          [BUGFIX] Evaluator in JS fails with namespaces (Stefan Aebischer)
  2013-11-12  9678fc6  #53538          [BUGFIX] Make be.buttons.icon-ViewHelper extensible (Stefan Neufeind)
  2013-11-11  e9bc5e1  #52727          [TASK] Hard-coded labels in file collections (Tomita Militaru)
  2013-11-11  bc9a847  #37948          [BUGFIX] Correctly append additionalTreelistUpdateFields (Bart Dubelaar)
  2013-11-11  a8f0d86  #53423          [BUGFIX] EM: Fetch list as html, not as json (Stefan Neufeind)
  2013-11-11  6f4ae27  #48809,#51730,  [BUGFIX] Fix wrong handling of php and TYPO3 dependencies (Susanne Moog)
  2013-11-10  907d5b1  #52173          [BUGFIX] Correct storage selection (follow-up) (Ernesto Baschny)
  2013-11-09  b7a6f48  #53477          [TASK] Fix superfluous strlen() on constant strings (Steffen Ritter)
  2013-11-09  58f1fa5  #47040          [BUGFIX] Enable treeConfig overriding by Page TSconfig (Stefan Froemken)
  2013-11-09  cb14179  #53195          [BUGFIX] T3editor: Honour fileDenyPattern on saving included TS (Stefan Neufeind)
  2013-11-08  c3773a4  #29179          [BUGFIX] Escape title, extension, description of scheduler tasks (Tomita Militaru)
  2013-10-23  648018e  #31572          [BUGFIX] Exception using cObject FORM in TypoScript (Andreas Bouche)
  2013-10-18  8c21be4  #35073          [BUGFIX] Enable BE search for multiple mountpoints (Georg Ringer)
  2013-10-17  fe876a8  #52931          [TASK] Exclude central Modernizr from concatenation (Stefan Neufeind)
  2013-10-16  04e4a4b  #52529          [BUGFIX] Suppress empty tag names in output of array2xml (Markus Hoelzle)
  2013-10-16  ac2b59e  #52823          [BUGFIX] Preserve vendor name in refering request (Thomas Maroschik)
  2013-10-15  693b575  #52845          [BUGFIX] Moving folders fails (Oliver Hader)
  2013-10-15  85d0653  #50802          [BUGFIX] Only load folder contents if folder is initialised (Frans Saris)
  2013-10-15  38958f0  #52824          [BUGFIX] Superfluous usage of ObjectManagerException (Oliver Hader)
  2013-10-15  4ba140a  #51707          [FEATURE] Add getValidators to AbstractCompositeValidator (Stefan Froemken)
  2013-10-15  1156074  #52771          [BUGFIX] Use callback in preg_replace in RemoveXSS (Jigal van Hemert)
  2013-10-14  c577f9e  #52773          [BUGFIX] Detect unix-styled absolute paths on Windows systems (Nicole Cordes)
  2013-10-13  6cc1f7a  #52759          [BUGFIX] Object passed to date() (Xavier Perseguers)
  2013-10-12  f272d54  #52731          [TASK] Use 6.1 branch in travis-integration for travis (Christian Kuhn)
  2013-10-12  6cbf164  #52728          [BUGFIX] Use BackendUtility use statement (Anja Leichsenring)
  2013-10-12  13c6602  #52104          [BUGFIX] Wrong calculation of maximum value for checkbox fields (Nicole Cordes)
  2013-10-12  23b8d11  #52715          [BUGFIX] Prevent empty newline below scheduler-task-name (Stefan Neufeind)
  2013-10-11  a909546  #52708          [BUGFIX] DataMapFactory::resolveTableName must remove leading backslashes (Alexander Schnitzler)
  2013-10-11  5faa4da  #50912          [BUGFIX] BackendUtility::viewOnClick() called with non-integer (Oliver Hader)
  2013-10-11  13c5bf9  #51051          [BUGFIX] Clear_cache() must not consider page ids lower than 0 (Oliver Hader)
  2013-10-11  17fe304  #37611          [BUGFIX] Select available page when changing WS (Thorsten Kahler)
  2013-10-11  e30b70b  #52636          [BUGFIX] Copy records to target page before origin page is deleted (Timo Webler)
  2013-10-11  db7d3e5  #17551          [BUGFIX] Create workspace placeholder with processed field content (Sascha Egerer)
  2013-10-11  660e030  #36573          [BUGFIX] Add workspace overlay for fetched records. (Timo Webler)
  2013-10-11  7c837df  #37209          [BUGFIX] WS preview shows pages changes from all WS (Thorsten Kahler)
  2013-10-11  5aeddac  #52530          [BUGFIX] Delete modified record in WS just deletes WS version (Sascha Egerer)
  2013-10-11  f561b99  #37065          [BUGFIX] Don't show duplicates in workspace preview (Timo Webler)
  2013-10-10  b4b0b0e  #52178          [BUGFIX] Cannot upload an extension as zip (Xavier Perseguers)
  2013-10-07  31e44bd  #46845          [BUGFIX] Fix namespace in FileMountRepositoryTest (Marc Bastian Heinrichs)
  2013-10-07  a7da230  #49538          [BUGFIX] Fields of type file_reference are not properly indexed (Martin Borer)
  2013-10-07  388c02d  #52546          [BUGFIX] Missing closing tag in ElementBrowser (Philipp Gampe)
  2013-10-06  30d93b4  #50756          [FEATURE] Backport ClassNamingUtility (Stefan Neufeind)
  2013-10-05  d6a8e68  #52469          [TASK] Use instanceof comparison instead of string comparison (Benjamin Serfhos)
  2013-09-30  8e1ea88  #43540          [BUGFIX] TS is fetched from cache incorrectly sometimes (Dmitry Dulepov)
  2013-09-28  a2532bb  #51329          [BUGFIX] Initialize extension name in command requests (Alexander Stehlik)
  2013-09-28  7144eb5  #52346          [BUGFIX] Incomplete backup in AbstractUserAuthenticationTest (Christian Kuhn)
  2013-09-27  9c200ea  #52091,#51684  [BUGFIX] Check for string before using strlen (Kilian Hann)
  2013-09-27  128d147  #52045          [BUGFIX] EmConfUtility accesses non-arrays (Markus Klein)
  2013-09-27  9fa9f15  #51588          [BUGFIX] Clear cached menu by tag (Zbigniew Jacko)
  2013-09-27  30af6a5  #50437          [BUGFIX] Fix jumpToUrl()-Usage in Element Browser (Benjamin Pick)
  2013-09-26  77c69e7  #52266          [BUGFIX] groupFor-VH does not work with @lazy (Stefan Froemken)
  2013-09-26  3f0cc99  #50913          [BUGFIX] Fix PHP warning trigged in getAuthInfoArray() (Christian Finkemeier)
  2013-09-26  919541b  #52316          [BUGFIX] Fatal in DefaultConfiguration (Christian Kuhn)
  2013-09-26  0deefa0  #52305          [BUGFIX] Configure main extbase caches for unlimited entry lifetime (Christian Kuhn)
  2013-09-26  d00db27  #52295          [TASK] Use SimpleFileBackend for t3lib_l10n cache (Christian Kuhn)
  2013-09-25  d01851c  #52226          [BUGFIX] EM does not link to docs.typo3.org (Xavier Perseguers)
  2013-09-25  68bb292  #51116          [BUGFIX] Increase performance of exports for caches (Markus Klein)
  2013-09-25  3f8cd14  #52243          [BUGFIX] Remove duplicate exception code (Fabien Udriot)
  2013-09-24  7151ce0  #52173          [BUGFIX] Correct storage selection (common prefixes) (Ernesto Baschny)
  2013-09-24  0a80fb6  #52201          [BUGFIX] Fix broken Unit-test for #44825 (Wouter Wolters)
  2013-09-23  be4627f  #44825          [BUGFIX] Fix page.headerData + USER_INT (Helmut Hummel)
  2013-09-20  580a576  #48912          [BUGFIX] Increase length of identifier field in sys_file (Nicole Cordes)
  2013-09-20  cb6bf25  #52056          [BUGFIX] Wrong exception on renaming folder (Francois Suter)
  2013-09-19  cdba66b  #49328          [BUGFIX] Fix PHP warning when writing to Backend user log (Alexander Stehlik)
  2013-09-17  23e6007  #45859          [BUGFIX] Faulty expand/collapse behavior in Element Browser (Oliver Hader)
  2013-09-17  c79315a  #19045          [BUGFIX] Fix cropping of transparent gifs with im6. (Stefan Neufeind)
  2013-09-17  aa4ab27  #50907          [BUGFIX] Form Wizard: Adds mouse pointer to docheader icons (Ernesto Baschny)
  2013-09-13  22ee660  #51981          [BUGFIX] Also consider JPEG files for IM/GM (Markus Klein)
  2013-09-12  40cb0a4  #51803          [TASK] Use a 401 header if login is not successful (Georg Ringer)
  2013-09-12  903046f  #51891          [BUGFIX] Call to undefined method setTemplateFile (Wouter Wolters)

---
  Module Name: pkgsrc
  Committed By: taca
  Date: Tue Dec 10 15:21:30 UTC 2013

  Modified Files:
  pkgsrc/www/typo3_60: Makefile distinfo

  Log Message:
  Update typo3_60 package to 6.0.12 (TYPO3 6.0.12).

  - Fix multiple vulnerabilities in TYPO3 CMS:
  http://typo3.org/teams/security/security-bulletins/typo3-core/typo3-core-sa-2013-004/

  2013-12-10  55ea17b                  [RELEASE] Release of TYPO3 6.0.12 (TYPO3 Release Team)
  2013-12-10  c703d1d  #31206          [SECURITY] XSS in header link of all content elements (Anja Leichsenring)
  2013-12-10  0f1e28b  #42772          [SECURITY] XSS in colorpicker wizard (Marcus Krause)
  2013-12-10  1cbe889  #45043          [SECURITY] Prevent editor controlled hmac content (Franz G. Jahn)
  2013-12-10  79f6850  #48691          [SECURITY] XSS in backend user adminstration (Marc Bastian Heinrichs)
  2013-12-10  b22cbce  #41714          [SECURITY] Information Disclosure in Wizards (Helmut Hummel)
  2013-12-10  e4134ae  #54099          [SECURITY] Fix open redirection in openid extension (Helmut Hummel)
  2013-12-10  2fb0277  #48187          [SECURITY] feuser_adminLib.inc allows to set arbitrary fields (Anja Leichsenring)
  2013-12-10  bd6095f  #36768          [SECURITY] XSS in be_layout wizard (Anja Leichsenring)
  2013-12-10  872cf3d  #47086          [SECURITY] XSS in beuser VH (Anja Leichsenring)
  2013-12-10  cb55c53  #54074          [SECURITY] Remove possible XSS from ActionController Error output (Anja Leichsenring)
  2013-12-10  578cc80  #54073          [SECURITY] Unsafe unserialize of GET parameter in Add-Wizard (Steffen Ritter)
  2013-12-02  9757d0c  #54124          [BUGFIX] ClientUtility does not detect Internet Explorer 11 (Stefan Neufeind)
  2013-12-02  5bf7430  #54117          [BUGFIX] Add missing namespacing for calling GeneralUtility (Stefan Neufeind)
  2013-11-29  30e1f41  #42651          [BUGFIX] ext:adodb Restrict connection wizard to admins (Christian Kuhn)

(tron)

2013-12-16 17:22:21 UTC pkgsrc-2013Q3 commitmail json YAML

Pullup ticket #4270 - requested by taca
www/typo3_47: security update

Revisions pulled up:
- www/typo3_47/MESSAGE                                          1.1
- www/typo3_47/Makefile                                        1.19-1.20
- www/typo3_47/PLIST                                            1.10
- www/typo3_47/distinfo                                        1.14-1.15

---
  Module Name: pkgsrc
  Committed By: taca
  Date: Thu Dec  5 16:42:21 UTC 2013

  Modified Files:
  pkgsrc/www/typo3_47: Makefile distinfo
  Added Files:
  pkgsrc/www/typo3_47: MESSAGE

  Log Message:
  Update typo347 to 4.7.16 (TYPO3 4.7.16).

  2013-11-26  95a730f                  [RELEASE] Release of TYPO3 4.7.16 (TYPO3 Release Team)
  2013-11-19  5975854  #53758          [BUGFIX] Table cache_imagesizes is defined twice (Michiel Roos)
  2013-11-19  7d0a241  #53750          [BUGFIX] Scheduler extension sql file is invalid (Michiel Roos)
  2013-11-11  90f4945  #31998          [BUGFIX] Faulty check for missing SMTP port (Stefan Neufeind)
  2013-11-11  f328884  #47040          [BUGFIX] Enable treeConfig overriding by Page TSconfig (Stefan Neufeind)
  2013-11-09  2c82f33  #29179          [BUGFIX] Escape title, extension, description of scheduler tasks (Stefan Neufeind)
  2013-11-09  d683693  #53195          [BUGFIX] T3editor: Honour fileDenyPattern on saving included TS (Stefan Neufeind)
  2013-10-28  37c4f0b  #53075          [BUGFIX] Cannot auto-load SC_* classes (Ernesto Baschny)
  2013-10-23  ceba809  #31572          [BUGFIX] Exception using cObject FORM in TypoScript (Andreas Bouche)
  2013-10-23  f8f155e  #43540          [BUGFIX] TS is fetched from cache incorrectly sometimes (Jigal van Hemert)
  2013-10-22  2ce69d2  #50881          [TASK] Added missing core autoloaded files (Ernesto Baschny)
  2013-10-13  d361b29  #52759          [BUGFIX] Object passed to date() (Philipp Gampe)
  2013-10-12  3699866  #52104          [BUGFIX] Wrong calculation of maximum value for checkbox fields (Nicole Cordes)
  2013-10-11  073dd57  #36573          [BUGFIX] Add workspace overlay for fetched records. (Anja Leichsenring)
  2013-10-06  f26f2f1  #52045          [BUGFIX] EmConfUtility accesses non-arrays (Markus Klein)
  2013-09-27  fda9783  #52091,#51684  [BUGFIX] Check for string before using strlen (Markus Klein)
  2013-09-26  9673d7e  #50913          [BUGFIX] Fix PHP warning trigged in getAuthInfoArray() (Christian Finkemeier)
  2013-09-26  e06f05a  #34886          [BUGFIX] CF FileBackend unlimited lifetime support (Dominique Feyer)

---
  Module Name: pkgsrc
  Committed By: taca
  Date: Tue Dec 10 15:20:03 UTC 2013

  Modified Files:
  pkgsrc/www/typo3_47: Makefile PLIST distinfo

  Log Message:
  Update typo3_47 package to 4.7.17 (TYPO3 4.7.17).

  - Fix multiple vulnerabilities in TYPO3 CMS:
  http://typo3.org/teams/security/security-bulletins/typo3-core/typo3-core-sa-2013-004/
  - Enable PHP_VERSIONS_ACCEPTED which was accidently commented out by previous
    commit.

  2013-12-10  9e378dd                  [RELEASE] Release of TYPO3 4.7.17 (TYPO3 Release Team)
  2013-12-10  efa9e0b  #45043          [SECURITY] Prevent editor controlled hmac content (Franz G. Jahn)
  2013-12-10  d207548  #42772          [SECURITY] XSS in colorpicker wizard (Anja Leichsenring)
  2013-12-10  92712d6  #31206          [SECURITY] XSS in header link of all content elements (Anja Leichsenring)
  2013-12-10  573f720  #20811          [SECURITY] XSS vulnerability in extension manager (Marcus Krause)
  2013-12-10  b7eac59  #41714          [SECURITY] Information Disclosure in Wizards (Anja Leichsenring)
  2013-12-10  319a06c  #54099          [SECURITY] Fix open redirection in openid extension (Anja Leichsenring)
  2013-12-10  834afa5  #48187          [SECURITY] feuser_adminLib.inc allows to set arbitrary fields (Steffen Ritter)
  2013-12-10  aa08f14  #36768          [SECURITY] XSS in be_layout wizard (Anja Leichsenring)
  2013-12-10  f3b5a6a  #54074          [SECURITY] Remove possible XSS from ActionController Error output (Anja Leichsenring)
  2013-12-10  0bc4fc4  #54073          [SECURITY] Unsafe unserialize of GET parameter in Add-Wizard (Marcus Krause)
  2013-12-02  c400e94  #54124          [BUGFIX] ClientUtility does not detect Internet Explorer 11 (Stefan Neufeind)
  2013-12-02  124a913  #54120          Revert "[BUGFIX] Object passed to date()" (Markus Klein)
  2013-12-01  3f2e971                  Revert "[BUGFIX] Distinguish unassigend columns and colPos 0" (Steffen Ritter)
  2013-11-29  a7dbbbf  #42651          [BUGFIX] ext:adodb Restrict connection wizard to admins (Christian Kuhn)
  2013-11-26  542bd7d  #25157,#45550  [BUGFIX] Distinguish unassigend columns and colPos 0 (Philipp Gampe)

(tron)

2013-12-16 17:05:48 UTC pkgsrc-2013Q3 commitmail json YAML

Pullup ticket #4269 - requested by taca
lang/php53: security update
lang/php54: security update
lang/php55: security update

Revisions pulled up:
- lang/php/phpversion.mk                                        1.46-1.52
- lang/php53/Makefile                                          1.44-1.45
- lang/php53/Makefile.php                                      1.38
- lang/php53/distinfo                                          1.69-1.70
- lang/php53/patches/patch-ext_date_lib_parse__iso__intervals.c 1.1
- lang/php53/patches/patch-ext_date_lib_parse__iso__intervals.re 1.1
- lang/php53/patches/patch-ext_openssl_openssl.c                deleted
- lang/php54/Makefile                                          1.15-1.16
- lang/php54/distinfo                                          1.28-1.31
- lang/php54/patches/patch-ext_date_lib_parse__iso__intervals.c 1.1
- lang/php54/patches/patch-ext_date_lib_parse__iso__intervals.re 1.1
- lang/php55/Makefile                                          1.6-1.7
- lang/php55/PLIST                                              1.2
- lang/php55/distinfo                                          1.7-1.12
- lang/php55/patches/patch-configure                            1.3
- lang/php55/patches/patch-ext_date_lib_parse__iso__intervals.c 1.1
- lang/php55/patches/patch-ext_date_lib_parse__iso__intervals.re 1.1
- lang/php55/patches/patch-ext_opcache_config.m4                1.1
- lang/php55/patches/patch-ext_sockets_sockaddr__conv.c        1.1
- lang/php55/patches/patch-sockaddr__conv.c                    deleted
- net/php-sockets/Makefile                                      1.12

---
  Module Name: pkgsrc
  Committed By: joerg
  Date: Tue Oct 15 14:43:51 UTC 2013

  Modified Files:
  pkgsrc/lang/php55: distinfo
  Added Files:
  pkgsrc/lang/php55/patches: patch-sockaddr__conv.c

  Log Message:
  Add patch that would fix the build of net/php-sockets for PHP 5.5, if I
  knew how to get it applied.

---
  Module Name: pkgsrc
  Committed By: taca
  Date: Tue Oct 15 15:46:37 UTC 2013

  Modified Files:
  pkgsrc/lang/php55: distinfo
  pkgsrc/net/php-sockets: Makefile
  Added Files:
  pkgsrc/lang/php55/patches: patch-ext_sockets_sockaddr__conv.c
  Removed Files:
  pkgsrc/lang/php55/patches: patch-sockaddr__conv.c

  Log Message:
  Fix php-socket with php55.

  - Use USE_PHP_EXT_PATCHES in net/php-sockets.
  - Make AI_V4MAPPED noop if platform dosen't have it.

  It is poor assumption that AI_V4MAPPED is always defined and V4 mapped
  address is always available.

---
  Module Name: pkgsrc
  Committed By: taca
  Date: Fri Oct 18 12:25:12 UTC 2013

  Modified Files:
  pkgsrc/lang/php: phpversion.mk
  pkgsrc/lang/php54: distinfo

  Log Message:
  Update php54 to 5.4.21 (PHP 5.4.21).

  17 Oct 2013, PHP 5.4.21

  - Core:
    . Fixed bug #65322 (compile time errors won't trigger auto loading). (Nikita)

  - CLI server:
    . Fixed bug #65633 (built-in server treat some http headers as
      case-sensitive). (Adam)

  - Datetime:
    . Fixed bug #64157 (DateTime::createFromFormat() reports confusing error
      message). (Boro Sitnikovski)

  - DBA extension:
    . Fixed bug #65708 (dba functions cast $key param to string in-place,
      bypassing copy on write). (Adam)

  - Filter:
    . Add RFC 6598 IPs to reserved addresses. (Sebastian Nohn)
    . Fixed bug #64441 (FILTER_VALIDATE_URL rejects fully qualified domain names).
      (Syra)

  - IMAP:
    . Fixed bug #65721 (configure script broken in 5.5.4 and 5.4.20 when enabling
      imap). (ryotakatsuki at gmail dot com)

  - Standard:
    . Fixed bug #61548 (content-type must appear at the end of headers for 201
      Location to work in http). (Mike)

  - Build system:
    . Fixed bug #62396 ('make test' crashes starting with 5.3.14 (missing
      gzencode())). (Mike)

---
  Module Name: pkgsrc
  Committed By: taca
  Date: Fri Oct 18 15:49:08 UTC 2013

  Modified Files:
  pkgsrc/lang/php: phpversion.mk
  pkgsrc/lang/php55: distinfo
  pkgsrc/lang/php55/patches: patch-configure
  Added Files:
  pkgsrc/lang/php55/patches: patch-ext_opcache_config.m4

  Log Message:
  Update php55 to 5.5.5.

  17 Oct 2013, PHP 5.5.5

  - Core:
    . Fixed bug #64979 (Wrong behavior of static variables in closure generators).
      (Nikita)
    . Fixed bug #65322 (compile time errors won't trigger auto loading). (Nikita)
    . Fixed bug #65821 (By-ref foreach on property access of string offset
      segfaults). (Nikita)

  - CLI server:
    . Fixed bug #65633 (built-in server treat some http headers as
      case-sensitive). (Adam)
    . Fixed bug #65818 (Segfault with built-in webserver and chunked transfer
      encoding). (Felipe)
    . Added application/pdf to PHP CLI Web Server mime types (Chris Jones)

  - Datetime:
    . Fixed bug #64157 (DateTime::createFromFormat() reports confusing error
      message). (Boro Sitnikovski)
    . Fixed bug #65502 (DateTimeImmutable::createFromFormat returns DateTime).
      (Boro Sitnikovski)
    . Fixed bug #65548 (Comparison for DateTimeImmutable doesn't work).
      (Boro Sitnikovski)

  - DBA extension:
    . Fixed bug #65708 (dba functions cast $key param to string in-place,
      bypassing copy on write). (Adam)

  - Filter:
    . Add RFC 6598 IPs to reserved addresses. (Sebastian Nohn)
    . Fixed bug #64441 (FILTER_VALIDATE_URL rejects fully qualified domain names).
      (Syra)

  - FTP:
    . Fixed bug #65667 (ftp_nb_continue produces segfault). (Philip Hofstetter)

  - GD
    . Ensure that the defined interpolation method is used with the generic
      scaling methods. (Pierre)

  - IMAP:
    . Fixed bug #65721 (configure script broken in 5.5.4 and 5.4.20 when enabling
      imap). (ryotakatsuki at gmail dot com)

  - OPcache:
    . Added support for GNU Hurd. (Svante Signell)
    . Added function opcache_compile_file() to load PHP scripts into cache
      without execution. (Julien)
    . Fixed bug #65845 (Error when Zend Opcache Optimizer is fully enabled).
      (Dmitry)
    . Fixed bug #65665 (Exception not properly caught when opcache enabled).
      (Laruence)
    . Fixed bug #65510 (5.5.2 crashes in _get_zval_ptr_ptr_var). (Dmitry)
    . Fixed issue #135 (segfault in interned strings if initial memory is too
      low). (Julien)

  - Sockets:
    . Fixed bug #65808 (the socket_connect() won't work with IPv6 address).
      (Mike)

  - SPL:
    . Fix bug #64782 (SplFileObject constructor make $context optional / give it
      a default value). (Nikita)

  - Standard:
    . Fixed bug #61548 (content-type must appear at the end of headers for 201
      Location to work in http). (Mike)

  - XMLReader:
    . Fixed bug #51936 (Crash with clone XMLReader). (Mike)
    . Fixed bug #64230 (XMLReader does not suppress errors). (Mike)

  - Build system:
    . Fixed bug #51076 (race condition in shtool's mkdir -p implementation).
      (Mike, Raphael Geissert)
    . Fixed bug #62396 ('make test' crashes starting with 5.3.14 (missing
      gzencode())). (Mike)

---
  Module Name: pkgsrc
  Committed By: taca
  Date: Fri Nov 15 16:33:14 UTC 2013

  Modified Files:
  pkgsrc/lang/php: phpversion.mk
  pkgsrc/lang/php55: PLIST distinfo

  Log Message:
  Update php55 package to 5.5.6.

  14 Nov 2013, PHP 5.5.6

  - Core:
    . Fixed bug #65947 (basename is no more working after fgetcsv in certain
      situation). (Laruence)
    . Improved performance of array_merge() and func_get_args() by eliminating
      useless copying. (Dmitry)
    . Fixed bug #65939 (Space before ";" breaks php.ini parsing).
      (brainstorm at nopcode dot org)
    . Fixed bug #65911 (scope resolution operator - strange behavior with $this).
      (Bob Weinand)
    . Fixed bug #65936 (dangling context pointer causes crash). (Tony)

  - FPM:
    . Changed default listen() backlog to 65535. (Tony)

  - MySQLi:
    . Fixed bug #66043 (Segfault calling bind_param() on mysqli). (Laruence)

  - OPcache
    . Increased limit for opcache.max_accelerated_files to 1,000,000. (Chris)
    . Fixed issue #115 (path issue when using phar). (Dmitry)
    . Fixed issue #149 (Phar mount points not working with OPcache enabled).
    (Dmitry)

  - ODBC
    . Fixed bug #65950 (Field name truncation if the field name is bigger than
      32 characters). (patch submitted by: michael dot y at zend dot com, Yasuo)

  - PDO:
    . Fixed bug #66033 (Segmentation Fault when constructor of PDO statement
      throws an exception). (Laruence)
    . Fixed bug 65946 (sql_parser permanently converts values bound to strings)

  - Standard:
    . Fixed bug #64760 (var_export() does not use full precision for floating-point
      numbers) (Yasuo)

---
  Module Name: pkgsrc
  Committed By: taca
  Date: Sat Nov 16 09:45:26 UTC 2013

  Modified Files:
  pkgsrc/lang/php: phpversion.mk
  pkgsrc/lang/php54: distinfo

  Log Message:
  Update php54 to 5.4.22.

  Version 5.4.22
  14-Nov-2013

  * Core:

      - Fixed bug #65911 (scope resolution operator - strange behavior with
        $this).

  CLI server:

      - Fixed bug #65818 (Segfault with built-in webserver and chunked transfer
        encoding).

  * Exif:

      - Fixed crash on unknown encoding.

  * FTP:

      - Fixed bug #65667 (ftp_nb_continue produces segfault).

  * ODBC:

      - Fixed bug #65950 (Field name truncation if the field name is bigger than
        32 characters).

  * Sockets:

      - Fixed bug #65808 (the socket_connect() won't work with IPv6 address).

  * Standard:

      - Fixed bug #64760 (var_export() does not use full precision for
        floating-point numbers).

  * XMLReader:

      - Fixed bug #51936 (Crash with clone XMLReader).
      - Fixed bug #64230 (XMLReader does not suppress errors).

---
  Module Name: pkgsrc
  Committed By: taca
  Date: Thu Dec  5 16:16:40 UTC 2013

  Modified Files:
  pkgsrc/lang/php53: Makefile distinfo
  Added Files:
  pkgsrc/lang/php53/patches: patch-ext_date_lib_parse__iso__intervals.c
      patch-ext_date_lib_parse__iso__intervals.re

  Log Message:
  Add fix for CVE-2013-6712, ext/date DoS vulnerability.

  Bump PKGREVISION.

---
  Module Name: pkgsrc
  Committed By: taca
  Date: Thu Dec  5 16:17:15 UTC 2013

  Modified Files:
  pkgsrc/lang/php54: Makefile distinfo
  Added Files:
  pkgsrc/lang/php54/patches: patch-ext_date_lib_parse__iso__intervals.c
      patch-ext_date_lib_parse__iso__intervals.re

  Log Message:
  Add fix for CVE-2013-6712, ext/date DoS vulnerability.

  Bump PKGREVISION.

---
  Module Name: pkgsrc
  Committed By: taca
  Date: Thu Dec  5 16:17:48 UTC 2013

  Modified Files:
  pkgsrc/lang/php55: Makefile distinfo
  Added Files:
  pkgsrc/lang/php55/patches: patch-ext_date_lib_parse__iso__intervals.c
      patch-ext_date_lib_parse__iso__intervals.re

  Log Message:
  Add fix for CVE-2013-6712, ext/date DoS vulnerability.

  Bump PKGREVISION.

---
  Module Name: pkgsrc
  Committed By: taca
  Date: Fri Dec 13 15:30:35 UTC 2013

  Modified Files:
  pkgsrc/lang/php: phpversion.mk
  pkgsrc/lang/php53: Makefile Makefile.php distinfo
  Removed Files:
  pkgsrc/lang/php53/patches: patch-ext_openssl_openssl.c

  Log Message:
  Update php53 to 5.3.28 (PHP 5.3.28).

  12 Dec 2013, PHP 5.3.28

  - Openssl:
    . Fixed handling null bytes in subjectAltName (CVE-2013-4073).
      (Christian Heimes)
    . Fixed memory corruption in openssl_x509_parse() (CVE-2013-6420).
      (Stefan Esser).

---
  Module Name: pkgsrc
  Committed By: taca
  Date: Fri Dec 13 15:32:21 UTC 2013

  Modified Files:
  pkgsrc/lang/php: phpversion.mk
  pkgsrc/lang/php54: Makefile distinfo

  Log Message:
  Update php54 to 5.4.23 (PHP 5.4.23).

  28 Nov 2013, PHP 5.4.23

  - Core:
    . Fixed bug #66094 (unregister_tick_function tries to cast a Closure to a
      string). (Laruence)
    . Fixed bug #65947 (basename is no more working after fgetcsv in certain
      situation). (Laruence)

  - JSON
    . Fixed whitespace part of bug #64874 ("json_decode handles whitespace and
      case-sensitivity incorrectly"). (Andrea Faulds)

  - MySQLi:
    . Fixed bug #66043 (Segfault calling bind_param() on mysqli). (Laruence)

  - mysqlnd:
    . Fixed bug #66124 (mysqli under mysqlnd loses precision when bind_param
      with 'i'). (Andrey)
    . Fixed bug #66141 (mysqlnd quote function is wrong with NO_BACKSLASH_ESCAPES
      after failed query). (Andrey)

  - OpenSSL:
    . Fixed memory corruption in openssl_x509_parse() (CVE-2013-6420).
      (Stefan Esser).

  - PDO
    . Fixed bug 65946 (sql_parser permanently converts values bound to strings)

---
  Module Name: pkgsrc
  Committed By: taca
  Date: Fri Dec 13 15:33:22 UTC 2013

  Modified Files:
  pkgsrc/lang/php: phpversion.mk
  pkgsrc/lang/php55: Makefile distinfo

  Log Message:
  Update php55 to 5.5.7 (PHP 5.5.7).

  12 Dec 2013, PHP 5.5.7

  - CLI server:
    . Added some MIME types to the CLI web server (Chris Jones)
    . Implemented FR #65917 (getallheaders() is not supported by the built-in web
      server) - also implements apache_response_headers() (Andrea Faulds)

  - Core:
    . Fixed bug #66094 (unregister_tick_function tries to cast a Closure to a
      string). (Laruence)

  - OPCache
    . Fixed bug #66176 (Invalid constant substitution). (Dmitry)
    . Fixed bug #65915 (Inconsistent results with require return value). (Dmitry)
    . Fixed bug #65559 (Opcache: cache not cleared if changes occur while
      running). (Dmitry)

  - OpenSSL:
    . Fixed memory corruption in openssl_x509_parse() (CVE-2013-6420).
      (Stefan Esser).

  - readline
    . Fixed Bug #65714 (PHP cli forces the tty to cooked mode). (Remi)

(tron)

2013-12-16 16:12:01 UTC pkgsrc-2013Q3 commitmail json YAML

Pullup ticket #4267 - requested by taca
textproc/icu: security patch

Revisions pulled up:
- textproc/icu/Makefile                                  patch
- textproc/icu/distinfo                                  patch
- textproc/icu/patches/patch-i18n_csrucode.cpp          patch

---
Apply patch to fix the security vulnerability reported in CVE-2013-2924.

(tron)

2013-12-16 15:31:05 UTC MAIN commitmail json YAML

2013-12-16 15:30:40 UTC MAIN commitmail json YAML

Updated textproc/grepcidr to 2.95 [apb 2013-12-16]

(apb)

2013-12-16 15:28:28 UTC MAIN commitmail json YAML

Update grepcidr to version 2.95.  It's now distributed as a tarball,
so we don't have to download each file individually; a bug in command
line argument parsing has been fixed, and an incorrect size has been fixed
in a malloc call.

(apb)

2013-12-16 14:17:16 UTC MAIN commitmail json YAML

Mark pkgsrc frozen.

(wiz)

2013-12-16 12:07:20 UTC MAIN commitmail json YAML

Add -lclucene-shared on Darwin.

(jperkin)

2013-12-16 11:59:56 UTC MAIN commitmail json YAML

Disable capabilities on FreeBSD, incompatible implementation.

(asau)

2013-12-16 10:43:10 UTC MAIN commitmail json YAML

Suggest placing pkgdb under prefix.

(asau)

2013-12-16 10:40:16 UTC MAIN commitmail json YAML

Actualise.
Don't insist on moving system tools.

(asau)

2013-12-16 09:53:44 UTC MAIN commitmail json YAML

2013-12-16 09:22:08 UTC MAIN commitmail json YAML

Note update of devel/ruby-i18n package to 0.6.9.

(taca)

2013-12-16 09:21:34 UTC MAIN commitmail json YAML

Update ruby-i18n to 0.6.9.  This is security fix.

* Add I18n::exists? method.
* Add I18n.locale_available? method.
* Delete unused files.
* I18n::MissingTranslation exception escapes key names for its
  html_message, fixing CVE-2013-4492.
* Use CGI.escapeHTML instead of CGI.escape_html for Ruby 1.8.7.
* Fix an issue with setting I18n.config.enforce_available_locales.

(taca)

2013-12-16 09:11:28 UTC MAIN commitmail json YAML

Put libboost_log_setup under PLIST.log.  Fixes Darwin/gcc.

(jperkin)

2013-12-16 08:45:18 UTC MAIN commitmail json YAML

restore enigmail checksums

(wiz)

2013-12-16 08:32:24 UTC MAIN commitmail json YAML

2013-12-16 06:50:06 UTC MAIN commitmail json YAML

2013-12-16 06:42:47 UTC MAIN commitmail json YAML

2013-12-16 06:42:21 UTC MAIN commitmail json YAML

Add chat/phone, which is like VMS phone, written by Jonathan C. Broome
in 1985 and fixed up by Christos "last week". (I've apparently been
sitting on this package since 20130101, so it was a year ago...)

XXX: this should probably grow an rc script for the master daemon, phoned.

(dholland)

2013-12-16 06:35:22 UTC MAIN commitmail json YAML

Force linking against libiconv for FreeBSD to fix build.

(asau)

2013-12-16 06:34:33 UTC MAIN commitmail json YAML

2013-12-16 06:33:06 UTC MAIN commitmail json YAML

Simplify packaging, add patch comment, and kill off the dynamic PLIST
generation.

PKGREVISION -> 1 to encourage rebuilding with proper PLIST support.

(dholland)

2013-12-16 06:24:13 UTC MAIN commitmail json YAML

Pull libiconv in for FreeBSD 9 to fix dependent packages.

(asau)

2013-12-16 06:23:09 UTC MAIN commitmail json YAML

Drop bootstrap binary from distfiles.
You can use your trusted bootstrap file as your basis.

(obache)

2013-12-16 05:47:43 UTC MAIN commitmail json YAML

Switch FETCH_USING to "fetch" by default on FreeBSD.
It exists by default and much functional support than "ftp" from net/tnftp.

(obache)

2013-12-16 05:15:18 UTC MAIN commitmail json YAML

Note PKGREVISION bump of tex-luatex

(minskim)

2013-12-16 05:12:24 UTC MAIN commitmail json YAML

Install a configuration file for tex-luatex

(minskim)

2013-12-16 03:11:58 UTC MAIN commitmail json YAML

Updated devel/xulrunner17 to 17.0.11
Updated www/firefox17 to 17.0.11

(ryoon)

2013-12-16 03:11:30 UTC MAIN commitmail json YAML

2013-12-16 03:10:12 UTC MAIN commitmail json YAML

Update to 17.0.11

* pkgsrc xulrunner17/firefox17 use external NSS

Changelog:
FIXED
Update ESR17 to NSS 3.14.5 RTM (see 936951)

(ryoon)

2013-12-16 02:22:45 UTC MAIN commitmail json YAML

Move SITES for bootstrap binary to be below after bootstrap binary kit name is
defined.

(obache)

2013-12-16 01:49:06 UTC MAIN commitmail json YAML

Remove "used by" lines for contao31/contao31-example.

(taca)

2013-12-16 01:48:27 UTC MAIN commitmail json YAML

Note remove of contao31 and contao31-example packages.

(taca)

2013-12-16 01:47:57 UTC MAIN commitmail json YAML

Remove contao31 and contao31-example.

(taca)

2013-12-16 01:47:29 UTC MAIN commitmail json YAML

2013-12-16 01:47:10 UTC MAIN commitmail json YAML

2013-12-16 01:03:02 UTC MAIN commitmail json YAML

Take MAINTAINERship; I more or less have been.

(gdt)

2013-12-15 22:25:51 UTC MAIN commitmail json YAML

Added net/exabgp version 3.2.18

(pettai)

2013-12-15 22:24:06 UTC MAIN commitmail json YAML

2013-12-15 22:22:44 UTC MAIN commitmail json YAML

Unlike BIRD or Quagga, ExaBGP was not designed to transform a general purpose
server into a router, but to allow engineers to control their BGP (rfc4271)
network easily. Think of it as Software Defined Networking for people with
"commodity" routers.

ExaBGP transform BGP (rfc4271) messages into friendly plain text or JSON
which can be easily manipulate by scripts.

It allows the creation of tools such as:
* advanced looking glass graphically display the routing of prefix
* high availability tool which automatically isolate broken services
* DDOS mitigation
* an anycasted server

(pettai)

2013-12-15 21:51:56 UTC MAIN commitmail json YAML

2013-12-15 21:50:34 UTC MAIN commitmail json YAML

Update go to 1.2.

Follow the example of OpenBSD ports and do not run the tests while building.
They are flaky under the Makefile harness for some reason.

(bsiegert)

2013-12-15 20:33:47 UTC MAIN commitmail json YAML

Fix the build on FreeBSD 9, FreeBSD uses sys/soundcard.h nowadays.

(asau)

2013-12-15 20:19:08 UTC MAIN commitmail json YAML

FreeBSD 9 doesn't have alloca.h, alloca() is declared in stdlib.h

(asau)

2013-12-15 20:14:16 UTC MAIN commitmail json YAML

2013-12-15 19:58:11 UTC MAIN commitmail json YAML

2013-12-15 19:51:57 UTC MAIN commitmail json YAML

2013-12-15 19:51:19 UTC MAIN commitmail json YAML

2013-12-15 19:50:19 UTC MAIN commitmail json YAML

2013-12-15 19:49:36 UTC MAIN commitmail json YAML

g_message is a function in GTK now, so use a different name.

(joerg)

2013-12-15 19:44:40 UTC MAIN commitmail json YAML

2013-12-15 19:44:02 UTC MAIN commitmail json YAML

2013-12-15 19:42:48 UTC MAIN commitmail json YAML

Needs libiconv to build on FreeBSD.
Bump revision as precaution.

(asau)

2013-12-15 19:42:46 UTC MAIN commitmail json YAML

Require qt4-tools to make cmake happy.

(joerg)

2013-12-15 19:42:04 UTC MAIN commitmail json YAML

2013-12-15 19:41:23 UTC MAIN commitmail json YAML

The Clang 3.4RCs started to use slightly more memory when compiling
Calculator.cpp, but it was enough to push it over 2GB. So disable
optimisation for now.

(joerg)

2013-12-15 19:40:03 UTC MAIN commitmail json YAML

Don't panic about unused functions.

(joerg)

2013-12-15 19:39:34 UTC MAIN commitmail json YAML

Don't try to optimize some files, clang will require up to 8GB of memory
for tracking all the jumps.

(joerg)

2013-12-15 19:38:33 UTC MAIN commitmail json YAML

2013-12-15 19:37:41 UTC MAIN commitmail json YAML

2013-12-15 19:36:37 UTC MAIN commitmail json YAML

Don't panic about unused functions.

(joerg)

2013-12-15 19:36:02 UTC MAIN commitmail json YAML

DIR is reserved for dirent.h, so use a different type name.

(joerg)

2013-12-15 18:45:19 UTC MAIN commitmail json YAML

Use uniform shared library names to avoid packaging list divergence.
This fixes package (and some its dependents) on FreeBSD at least.

(asau)

2013-12-15 18:35:41 UTC MAIN commitmail json YAML

Updated lang/polyml to 5.5.1

(asau)

2013-12-15 18:35:23 UTC MAIN commitmail json YAML

Update to Poly/ML 5.5.1
Contributed by Imre Vadasz on pkgsrc-users (slightly adapted).

Changes in Poly/ML Version 5.5.1

Major New Features and Changes

  * The intermediate code optimiser has been largely rewritten.
    The optimiser now detects various additional cases where a
    closures or tuples can be stored on the stack rather than
    requiring heap storage
  * The match compiler that processes a sequence of patterns in a
    case or fun-binding has been reworked. This now handles
    complex matches that used to result in a code blow-up
  * A"polyc" script has been added to aid compiling and linking
    ML code to produce a stand-alone binary. This is intended as
    an analogue of cc and gcc. The easiest way to build a binary
    is now to put the ML code into a file (foo.ML) with a
    function "main" that is the entry point to the code. Then run
    polyc -o foo foo.ML
    The script takes care of any libraries that may be required.
    It does require that the poly binary and libraries have been
    installed to the location that was specified in the configure
    script.
  * Set the default in the configure script not to build a shared
    library. This can be overidden with --enable-shared. The
    advantage of this is that binaries created from Poly/ML,
    including poly itself, do not require libpolyml at run-time.
  * Additions and changes to the command-line options when
    starting the ML top-level
      + The --eval option can be followed by a string which is
        compiled and executed before the top-level is entered
      + The --script option can be used to allow ML code to be
        run as a script (a "shell script") in Unix. It reads the
        file name given as the last option, skipping the first
        line if it begins #!. Implies -q option. Note: because of
        the way scripts pass their options if used this must be
        the only option. To use ML as a script put the ML code
        into a file, put
        #! /usr/local/bin/poly --script
        as the first line, modifying the path depending on where
        poly is installed, and set the file to have execute
        permission.
      + The -q option now sets the print depth to zero as well as
        suppressing the start-up message
      + The input prompt (> or #) is only produced if the input
        is a terminal. The -i option should be used to cause the
        prompt to be produced if, for example, the input is from
        a pipe.

Minor Additions and Changes

  * The -H option now sets the initial heap size rather than
    being a synonym for --minheap
  * Add large file support
  * When printing the fields a record print them in alphabetical
    order rather than the system order used in the compiler
  * Convert the representation of the statistics to use ASN1
    encoding. This is byte-order and word-length independent and
    allows 32-bit Poly/ML to read the statistics of 64-bit Poly/
    ML on the same machine and vice-versa.
  * Add a substructure Exception to the PolyML structure to hold
    all the functions related to exceptions.
  * The default for --gc-threads is now the number of independent
    physical processors. Hyperthreaded cores are counted as
    single cores rather than dual cores.
  * Improve the GC and allocation code for very large arrays
  * Improve handling of OS.Process.system in Cygwin
  * Improved versions of Word32 and Word64. These are used for
    SystemWord and LargeWord.

Bug Fixes

  * Fix Word32.fromLargeInt which could return values outside the
    range of Word32
  * Fix segfault in PolyML.stackTrace
  * Fix errors in conversion of string to real values
  * Fix segfault when a thread created in foreign code called an
    ML callback
  * Fix profiler which could often report UNKNOWN function
  * Fix bug with overlapped areas in ArraySlice.copy
  * Fix InternalError exception with ML code where a fixed record
    type could not be found
  * Fix bug with equality on BoolVector.vector
  * Raise the correct exception (Size) for negative lengths in
    canInput and inputN
  * Fix Real.fromInt with an argument that was an arbitrary
    precision number in the long form
  * Fix error in the timing information printed with
    PolyML.timing true in Windows.
  * Fix occasional problem with input/output as a result of the
    stream token being represented by an immutable value but then
    being checked for equality
  * Fix bug in X86-64 code-generator with literal constants that
    do not fit in 32-bits. It could result in an "InternalError:
    gen32s: invalid word" exception. Includes regression test.
  * Fix LargWord.fromInt which was wrong for large negative
    values
  * Fix bug in power-of-two function in code-generator. This
    caused an infinite loop with Word.* when multiplying by a
    constant with the highest bit set and not a power of two.
  * Fix bug in structure matching code
  * Use ELF_Rela relocation structures for all relocations in
    X86-64. Some systems e.g. Solaris require this.

(asau)

2013-12-15 14:33:41 UTC MAIN commitmail json YAML

Updated devel/p5-Set-IntSpan to 1.19

(wen)

2013-12-15 14:32:50 UTC MAIN commitmail json YAML

Update to 1.19
Add LICENSE

Upstream changes:
1.19  2014 Apr 09
        - unit test fix

1.18  2013 Apr 03
        - POD

1.17  2013 Apr 02
- no use integer
- optimize _copy_array

(wen)

2013-12-15 14:27:46 UTC MAIN commitmail json YAML

Updated devel/p5-Set-Array to 0.30

(wen)

2013-12-15 14:25:50 UTC MAIN commitmail json YAML

Update to 0.30

Upstream changes:
0.30  Wed Sep 18 09:21:00 2013
- No code changes.
- Add t/intersection.*.pl as part of the expanded discussion of methods such as intersection().
This code was developed in conjunction with Joern Behre, to help clear up confusion over
the issue of the uniqueness of items returned from various methods.
- Add an FAQ with an item discussing this issue.
- Expand the discussion of overloaded operators to recommend testing of the output of various methods
before production use, and that unique() may need to be called, since unique() is not called
automatically during a call to, say, intersection().
- Include docs for bag(), difference(), intersection(), is_equal() and not_equal() explicitly among
all other methods, besides their original mention under 'OVERLOADED (COMPARISON) OPERATORS'.
- Include docs for new() as well.

0.29  Wed Jul  3 16:20:00 2013
- No code changes.
- Rename CHANGES to Changes as per CPAN::Changes::SPEC.
- Recreate META.* files so they say licence is artistic_2 rather than artistic_1.
Build.PL and Makefile.PL already said artistic_2, but the META.* files didn't.
There is no reference to licences in the source of the module itself.
This was requested by Christopher Meng who packages stuff for Fedora.

0.28  Wed Dec 19 08:50:00 2012
- Extend fix for RT#81971 to add ^ in the regexps used in index() and rindex(), so they are now
/^\Q$value\E$/ and not just /\Q$value\E$/. This issue was also reported by Henrik Hald N魘蛭aard.
- Update docs for rindex() is say undef is returned - as with index() - if the value is not found.
- Extend t/rt.81971.t to check rindex() returns undef when searching for the suffix of a value.

0.27  Sat Dec 15 07:19:00 2012
- Fix RT#81971, kindly reported by Henrik Hald N魘蛭aard.
When special chars, as used in regexps, are set members, or used to find set members, they
must be quoted with \Q$value\E inside regexps.
This fix was applied to count(), delete(), exists(), index() and rindex().
- Add t/rt.81971.t to exercise the new code.
- While examining the code for this fix, I found a couple of other bugs: In index() and rindex(),
the value searched for was compared with each set member using this regexp, /$value/,
instead of this regexp, /$value$/. The missing, trailing, $ meant that the member could match just
the prefix of $value, rather than match the value exactly. So in those 2 methods the tests are now
/\Q$value\E$/. The other 3 methods mentioned above already used /$value$/.

(wen)

2013-12-15 14:21:29 UTC MAIN commitmail json YAML

Updated devel/nss to 3.15.3.1

(ryoon)

2013-12-15 14:21:01 UTC MAIN commitmail json YAML

Update to 3.15.3.1

Changelog:
New in NSS 3.15.3.1

New Functionality

No new major functionality is introduced in this release. This is
a patch release to revoke trust of a subordinate CA certificate
that was mis-used to generate a certificate used by a network
appliance.

Bugs fixed in NSS 3.15.3.1

    Bug 946351 - Misissued Google certificates from DCSSI

A complete list of all bugs resolved in this release can be obtained
at
https://bugzilla.mozilla.org/buglist.cgi?resolution=FIXED&classification=Components&query_format=advanced&target_milestone=3.15.3.1&product=NSS

Compatibility

NSS 3.15.3.1 shared libraries are backward compatible with all
older NSS 3.x shared libraries. A program linked with older NSS
3.x shared libraries will work with NSS 3.15.3.1 shared libraries
without recompiling or relinking. Furthermore, applications that
restrict their use of NSS APIs to the functions listed in NSS Public
Functions will remain compatible with future versions of the NSS
shared libraries.

(ryoon)

2013-12-15 14:13:37 UTC MAIN commitmail json YAML

Bump PKGREVISION

* Convert to use xulrunner24

(ryoon)

2013-12-15 14:08:42 UTC MAIN commitmail json YAML

Add xulrunner24

(ryoon)

2013-12-15 14:07:50 UTC MAIN commitmail json YAML

Added devel/xulrunner24 version 24.2.0

(ryoon)

2013-12-15 14:07:13 UTC MAIN commitmail json YAML

Import xulrunner24-24.2.0 as devel/xulrunner24.

XULRunner is a runtime environment for applications using the
XML User Interface Language, XUL. It is the successor of the "Gecko"
runtime environment.

This package tracks 24 extended support release.

(ryoon)

2013-12-15 14:06:21 UTC MAIN commitmail json YAML

Updated mail/thunderbird to 24.2.0

(ryoon)

2013-12-15 14:05:57 UTC MAIN commitmail json YAML

Update to 24.2.0

Changelog:
    FIXED
    Security fixes can be found here
    FIXED
    Fixed an issue where long messages with multiple signatures could end up unreadable (bug 929006)
    FIXED
    Fixed an issue where editing account settings was not possible in some non-standard configurations of local folder set-ups (bug 921371)

Fixed in Thunderbird 24.2
MFSA 2013-117 Mis-issued ANSSI/DCSSI certificate
MFSA 2013-116 JPEG information leak
MFSA 2013-115 GetElementIC typed array stubs can be generated outside observed typesets
MFSA 2013-114 Use-after-free in synthetic mouse movement
MFSA 2013-113 Trust settings for built-in roots ignored during EV certificate validation
MFSA 2013-111 Segmentation violation when replacing ordered list elements
MFSA 2013-109 Use-after-free during Table Editing
MFSA 2013-108 Use-after-free in event listeners
MFSA 2013-104 Miscellaneous memory safety hazards (rv:26.0 / rv:24.2)

(ryoon)

2013-12-15 14:02:59 UTC MAIN commitmail json YAML

Updated www/firefox24 to 24.2.0

(ryoon)

2013-12-15 14:02:25 UTC MAIN commitmail json YAML

Update to 24.2.0

* Fix PR pkg/48420: fix build on NetBSD with drace support
  Patches from richard@

Changelog:
Fixed in Firefox ESR 24.2
MFSA 2013-117 Mis-issued ANSSI/DCSSI certificate
MFSA 2013-116 JPEG information leak
MFSA 2013-115 GetElementIC typed array stubs can be generated outside observed typesets
MFSA 2013-114 Use-after-free in synthetic mouse movement
MFSA 2013-113 Trust settings for built-in roots ignored during EV certificate validation
MFSA 2013-111 Segmentation violation when replacing ordered list elements
MFSA 2013-109 Use-after-free during Table Editing
MFSA 2013-108 Use-after-free in event listeners
MFSA 2013-104 Miscellaneous memory safety hazards (rv:26.0 / rv:24.2)

(ryoon)

2013-12-15 13:55:39 UTC MAIN commitmail json YAML

2013-12-15 13:54:37 UTC MAIN commitmail json YAML

Update to 26.0

* Build outside WRKSRC, fix build

Changelog:
NEW
All Java plug-ins are defaulted to 'click to play'
NEW
Password manager now supports script-generated password fields
NEW
Updates can now be performed by Windows users without write permissions to Firefox install directory (requires Mozilla Maintenance Service)
NEW
Support for H.264 on Linux if the appropriate gstreamer plug-ins are installed
CHANGED
Support for MP3 decoding on Windows XP, completing MP3 support across Windows OS versions
CHANGED
CSP implementation now supports multiple policies, including the case of both an enforced and Report-Only policy, per the spec
DEVELOPER
Social API now supports Social Bookmarking for multiple providers through its SocialMarks functionality (see MDN docs)
DEVELOPER
Math.ToFloat32 takes a JS value and converts it to a Float32, whenever possible
DEVELOPER
There is no longer a prompt when websites use appcache
DEVELOPER
Support for the CSS image orientation property
DEVELOPER
New App Manager allows you to deploy and debug HTML5 webapps on Firefox OS phones and the Firefox OS Simulator
DEVELOPER
IndexedDB can now be used as a "optimistic" storage area so it doesn't require any prompts and data is stored in a pool with LRU eviction policy, in short temporary storage
FIXED
When displaying a standalone image, Firefox matches the EXIF orientation information contained within the JPEG image (298619)
FIXED
Text Rendering Issues on Windows 7 with Platform Update KB2670838 (MSIE 10 Prerequisite) or on Windows 8.1 (812695)
FIXED
Improved page load times due to no longer decoding images that aren't visible (847223)
FIXED
AudioToolbox MP3 backend for OSX (914479)
FIXED
Various security fixes

Fixed in Firefox 26
MFSA 2013-117 Mis-issued ANSSI/DCSSI certificate
MFSA 2013-116 JPEG information leak
MFSA 2013-115 GetElementIC typed array stubs can be generated outside observed typesets
MFSA 2013-114 Use-after-free in synthetic mouse movement
MFSA 2013-113 Trust settings for built-in roots ignored during EV certificate validation
MFSA 2013-112 Linux clipboard information disclosure though selection paste
MFSA 2013-111 Segmentation violation when replacing ordered list elements
MFSA 2013-110 Potential overflow in JavaScript binary search algorithms
MFSA 2013-109 Use-after-free during Table Editing
MFSA 2013-108 Use-after-free in event listeners
MFSA 2013-107 Sandbox restrictions not applied to nested object elements
MFSA 2013-106 Character encoding cross-origin XSS attack
MFSA 2013-105 Application Installation doorhanger persists on navigation
MFSA 2013-104 Miscellaneous memory safety hazards (rv:26.0 / rv:24.2)

(ryoon)

2013-12-15 13:50:51 UTC MAIN commitmail json YAML

Updated chat/p5-POE-Filter-IRCD to 2.44

(wen)

2013-12-15 13:49:44 UTC MAIN commitmail json YAML

Update to 2.44

Upstream changes:
-----------------------------------------
version 2.44 at 2013-06-10 13:21:56 +0000
-----------------------------------------

  Change: ae253101da7958777a572271f901e894ae20de05
  Author: Chris 'BinGOs' Williams <chris@bingosnet.co.uk>
  Date : 2013-06-10 14:21:56 +0000

    Convert the distribution to dzil

  Change: 2f3bfa5c4a97ca061c2f87d4f4706e0bb0376f43
  Author: Chris Williams <chris@bingosnet.co.uk>
  Date : 2013-06-10 06:08:52 +0000

    Merge pull request #1 from avenj/messagetags

    IRCv3.2 message tag support, tests for same.

  Change: 31a1c9aeab4120e626af130d73b0f1a58a77d46e
  Author: Jon Portnoy <avenj@cobaltirc.org>
  Date : 2013-06-07 13:03:16 +0000

    Add IRCv3.2 message tag support, tests for same.

(wen)