Received: from mail.netbsd.org (mail.netbsd.org [204.152.190.11]) by www.NetBSD.org (Postfix) with ESMTP id 55D1C63B87A for ; Fri, 17 Dec 2010 01:19:26 +0000 (UTC) Received: by mail.netbsd.org (Postfix, from userid 605) id 2782D19D52B; Fri, 17 Dec 2010 01:19:26 +0000 (UTC) Received: from cvs.netbsd.org (cvs.NetBSD.org [IPv6:2001:4f8:3:7:2e0:81ff:fe30:95bd]) by mail.netbsd.org (Postfix) with ESMTP id 4C86719D4CC for ; Fri, 17 Dec 2010 01:19:17 +0000 (UTC) Received: by cvs.netbsd.org (Postfix, from userid 500) id BF532175DD; Fri, 17 Dec 2010 01:19:17 +0000 (UTC) MIME-Version: 1.0 Content-Disposition: inline Content-Transfer-Encoding: 8bit Content-Type: text/plain; charset="US-ASCII" Date: Fri, 17 Dec 2010 01:19:17 +0000 From: "Greg Troxel" Subject: CVS commit: pkgsrc/www/gitweb To: pkgsrc-changes@NetBSD.org Reply-To: gdt@netbsd.org X-Mailer: log_accum Message-Id: <20101217011917.BF532175DD@cvs.netbsd.org> Sender: pkgsrc-changes-owner@NetBSD.org List-Id: pkgsrc-changes.NetBSD.org Precedence: bulk Module Name: pkgsrc Committed By: gdt Date: Fri Dec 17 01:19:17 UTC 2010 Modified Files: pkgsrc/www/gitweb: Makefile distinfo Log Message: Update to 1.7.3.4. Most importantly: commit 3017ed62f47ce14a959e2d315c434d4980cf4243 Author: Jakub Narebski Date: Wed Dec 15 00:34:01 2010 +0100 gitweb: Introduce esc_attr to escape attributes of HTML elements It is needed only to escape attributes of handcrafted HTML elements, and not those generated using CGI.pm subroutines / methods for HTML generation. While at it, add esc_url and esc_html where needed, and prefer to use CGI.pm HTML generating methods than handcrafted HTML code. Most of those are probably unnecessary (could be exploited only by person with write access to gitweb config, or at least access to the repository). This fixes CVE-2010-3906 Reported-by: Emanuele Gentili Helped-by: John 'Warthog9' Hawley Helped-by: Jonathan Nieder Signed-off-by: Jakub Narebski Signed-off-by: Junio C Hamano and lesser changes: 3017ed6 gitweb: Introduce esc_attr to escape attributes of HTML elements d48b284 perl: bump the required Perl version to 5.8 from 5.6.[21] d8a9480 gitweb: Don't die_error in git_tag after already printing headers 22e5e58 Typos in code comments, an error message, documentation 497d9c3 gitweb: clarify search results page when no matching commit found 0b45010 gitweb: Fix typo in run() subroutine 7f425db gitweb: allow configurations that change with each request 61bf126 gitweb: move highlight config out of guess_file_syntax() 109988f gitweb: fix esc_url 869d588 gitweb: Move evaluate_gitweb_config out of run_request 7064994 gitweb/Makefile: fix typo in gitweb.min.css rule 5ed2ec1 gitweb: Return or exit after done serving request ad709ea gitweb: Fix typo in hash key name in %opts in git_header_html 45aa989 gitweb: Run in FastCGI mode if gitweb script has .fcgi extension 18d0532 gitweb: Move static files into seperate subdirectory 04794fd gitweb: Use @diff_opts while using format-patch a0446e7 gitweb: Add support for FastCGI, using CGI::Fast c2394fe gitweb: Put all per-connection code in run() subroutine 592ea41 gitweb: Refactor syntax highlighting support b331fe5 gitweb: Syntax highlighting support 152d943 gitweb: Create install target for gitweb in Makefile 8515392 gitweb: Improve installation instructions in gitweb/INSTALL ee1d8ee gitweb: Silence 'Variable VAR may be unavailable' warnings efb2d0c gitweb: Move generating page title to separate subroutine 7a59745 gitweb: Add custom error handler using die_error c42b00c gitweb: Use nonlocal jump instead of 'exit' in die_error 377bee3 gitweb: href(..., -path_info => 0|1) 8de096b gitweb: simplify gitweb.min.* generation and clean-up rules e391859 gitweb: update INSTALL to use shorter make target a8ab675 gitweb: add documentation to INSTALL regarding gitweb.js bb4bbf7 Gitweb: add autoconfigure support for minifiers 0e6ce21 Gitweb: add support for minifying gitweb.css 890a13a Sync with 1.7.0.4 7a49c25 gitweb: git_get_project_config requires only $git_dir, not also $projec 9be3614 gitweb: Fix project-specific feature override behavior 964ad92 gitweb multiple project roots documentation 1df4876 gitweb: Protect escaping functions against calling on undef 453541f gitweb: esc_html (short) error message in die_error e6e592d gitweb: Die if there are parsing errors in config file 57017b3 gitweb: Simplify (and fix) chop_str aa14013 gitweb: Add optional extra parameter to die_error, for extended explanaion 1ee4b4e gitweb: add a "string" variant of print_sort_th 0cf207f gitweb: add a "string" variant of print_local_time 24d4afc gitweb: Check that $site_header etc. are defined before using them 62331ef gitweb: Makefile improvements b62a1a9 gitweb: Load checking b2c2e4c gitweb.js: Workaround for IE8 bug To generate a diff of this commit: cvs rdiff -u -r1.8 -r1.9 pkgsrc/www/gitweb/Makefile cvs rdiff -u -r1.3 -r1.4 pkgsrc/www/gitweb/distinfo Please note that diffs are not public domain; they are subject to the copyright notices on the relevant files.