Link [ pkgsrc | NetBSD | pkgsrc git mirror | PR fulltext-search | netbsd commit viewer ]


   
        usage: [branch:branch] [user:user] [path[@revision]] keyword [... [-excludekeyword [...]]] (e.g. branch:MAIN pkgtools/pkg)




switch to index mode

recent branches: MAIN (22m)  pkgsrc-2024Q1 (9d)  pkgsrc-2023Q4 (56d)  pkgsrc-2023Q2 (89d)  pkgsrc-2023Q3 (168d) 

2024-05-27 10:53:10 UTC Now

2018-08-17 17:39:36 UTC pkgsrc-2018Q2 commitmail json YAML

Pullup ticket #5800 - requested by taca
lang/php56: security fix

Revisions pulled up:
- lang/php/phpversion.mk                                        1.225
- lang/php56/Makefile.php                                      1.5
- lang/php56/distinfo                                          1.49-1.50
- lang/php56/patches/patch-disable-filter-url                  1.1

---
  Module Name: pkgsrc
  Committed By: manu
  Date: Wed Jul 18 07:33:12 UTC 2018

  Modified Files:
  pkgsrc/lang/php56: Makefile.php distinfo
  pkgsrc/lang/php70: Makefile.php distinfo
  pkgsrc/lang/php71: Makefile.php distinfo
  pkgsrc/lang/php72: Makefile.php distinfo
  Added Files:
  pkgsrc/lang/php56/patches: patch-disable-filter-url
  pkgsrc/lang/php70/patches: patch-disable-filter-url
  pkgsrc/lang/php71/patches: patch-disable-filter-url
  pkgsrc/lang/php72/patches: patch-disable-filter-url

  Log Message:
  Add pkgsrc build option disable-filter-url to disable php://filter URL

  php://filter URL is a feature documented here:
  http://php.net/manual/en/wrappers.php.php

  Unfortunately, it allows remote control of include() behavior
  beyond what many developpers expected, enabling easy dump of
  PHP source files. The administrator may want to disable the
  feature for security sake, and this option makes that possible.

---
  Module Name: pkgsrc
  Committed By: taca
  Date: Fri Jul 20 13:28:48 UTC 2018

  Modified Files:
  pkgsrc/lang/php: phpversion.mk
  pkgsrc/lang/php56: distinfo

  Log Message:
  lang/php56: update to 5.6.37

  19 Jul 2018, PHP 5.6.37

  - Exif:
    . Fixed bug #76423 (Int Overflow lead to Heap OverFlow in
      exif_thumbnail_extract of exif.c). (Stas)
    . Fixed bug #76557 (heap-buffer-overflow (READ of size 48) while reading exif
      data). (Stas)

  - Win32:
    . Fixed bug #76459 (windows linkinfo lacks openbasedir check). (Anatol)

(bsiegert)