Wed Aug 8 18:39:22 2012 UTC ()
Pullup ticket #3889 - requested by tron
databases/phpmyadmin: security update

Revisions pulled up:
- databases/phpmyadmin/Makefile                                 1.102-1.103
- databases/phpmyadmin/PLIST                                    1.28
- databases/phpmyadmin/distinfo                                 1.62-1.63
- databases/phpmyadmin/patches/patch-libraries_header_http.inc.php deleted

-------------------------------------------------------------------
   Module Name:	pkgsrc
   Committed By:	tron
   Date:		Sun Jul 15 13:02:32 UTC 2012

   Modified Files:
   	pkgsrc/databases/phpmyadmin: Makefile PLIST distinfo
   Removed Files:
   	pkgsrc/databases/phpmyadmin/patches:
   	    patch-libraries_header_http.inc.php

   Log Message:
   Update "phpmyadmin" package to version 3.5.2. Changes since 3.5.1:
   - bug #3521416 [interface] JS error when editing index
   - bug #3521313 [core] Call to undefined function __()
   - bug #3521016 [edit] NOW() function incorrectly selected
   - bug [GUI] Invalid HTML code on transformation_overview.php
   - bug #3522930 [browse] Missing validation in Ajax mode
   - bug Fix popup message on build SQL of import
   - bug #3523499 [core] Make X-WebKit-CSP work better
   - replace Highcharts with jqplot for query profiling, zoom search
   - bug #3531584 [interface] No form validation in change password dialog
   - bug #3531585 [interface] Broken password validation in copy user form
   - bug #3531586 [unterface] Add user form prints JSON when user presses enter
   - bug #3534121 [config] duplicate line in config.sample.inc.php
   - bug #3534311 [interface] Grid editing incorrectly parses ENUM/SET values
   - bug #3510196 [core] More clever URL rewriting with ForceSSL

   To generate a diff of this commit:
   cvs rdiff -u -r1.101 -r1.102 pkgsrc/databases/phpmyadmin/Makefile
   cvs rdiff -u -r1.27 -r1.28 pkgsrc/databases/phpmyadmin/PLIST
   cvs rdiff -u -r1.61 -r1.62 pkgsrc/databases/phpmyadmin/distinfo
   cvs rdiff -u -r1.1 -r0 \
       pkgsrc/databases/phpmyadmin/patches/patch-libraries_header_http.inc.php

-------------------------------------------------------------------
   Module Name:	pkgsrc
   Committed By:	tron
   Date:		Wed Aug  8 07:17:00 UTC 2012

   Modified Files:
   	pkgsrc/databases/phpmyadmin: Makefile distinfo

   Log Message:
   Update "phpmyadmin" package to version 3.5.2.1. Changes since 3.5.2:
   - [security] Fixed local path disclosure vulnerability, see PMASA-2012-3

   To generate a diff of this commit:
   cvs rdiff -u -r1.102 -r1.103 pkgsrc/databases/phpmyadmin/Makefile
   cvs rdiff -u -r1.62 -r1.63 pkgsrc/databases/phpmyadmin/distinfo


(spz)
diff -r1.101 -r1.101.2.1 pkgsrc/databases/phpmyadmin/Makefile
diff -r1.27 -r1.27.2.1 pkgsrc/databases/phpmyadmin/PLIST
diff -r1.61 -r1.61.2.1 pkgsrc/databases/phpmyadmin/distinfo
diff -r1.1 -r0 pkgsrc/databases/phpmyadmin/patches/patch-libraries_header_http.inc.php

cvs diff -r1.101 -r1.101.2.1 pkgsrc/databases/phpmyadmin/Makefile (expand / switch to unified diff)

--- pkgsrc/databases/phpmyadmin/Makefile 2012/05/06 09:03:48 1.101
+++ pkgsrc/databases/phpmyadmin/Makefile 2012/08/08 18:39:21 1.101.2.1
@@ -1,14 +1,14 @@ @@ -1,14 +1,14 @@
1# $NetBSD: Makefile,v 1.101 2012/05/06 09:03:48 tron Exp $ 1# $NetBSD: Makefile,v 1.101.2.1 2012/08/08 18:39:21 spz Exp $
2 2
3DISTNAME= phpMyAdmin-${DIST_VERSION}-all-languages 3DISTNAME= phpMyAdmin-${DIST_VERSION}-all-languages
4PKGNAME= phpmyadmin-${DIST_VERSION:S/-//} 4PKGNAME= phpmyadmin-${DIST_VERSION:S/-//}
5CATEGORIES= databases www 5CATEGORIES= databases www
6MASTER_SITES= ${MASTER_SITE_SOURCEFORGE:=phpmyadmin/} 6MASTER_SITES= ${MASTER_SITE_SOURCEFORGE:=phpmyadmin/}
7EXTRACT_SUFX= .tar.xz 7EXTRACT_SUFX= .tar.xz
8 8
9OWNER= tron@NetBSD.org 9OWNER= tron@NetBSD.org
10HOMEPAGE= http://www.phpmyadmin.net/ 10HOMEPAGE= http://www.phpmyadmin.net/
11COMMENT= Set of PHP-scripts to adminstrate MySQL over the WWW 11COMMENT= Set of PHP-scripts to adminstrate MySQL over the WWW
12LICENSE= gnu-gpl-v2 12LICENSE= gnu-gpl-v2
13 13
14DEPENDS+= ${PHP_PKG_PREFIX}-bz2>=5.2.0:../../archivers/php-bz2 14DEPENDS+= ${PHP_PKG_PREFIX}-bz2>=5.2.0:../../archivers/php-bz2
@@ -18,27 +18,27 @@ DEPENDS+= ${PHP_PKG_PREFIX}-gettext>=5.2 @@ -18,27 +18,27 @@ DEPENDS+= ${PHP_PKG_PREFIX}-gettext>=5.2
18DEPENDS+= ${PHP_PKG_PREFIX}-mysql{,i}>=5.2.0:../../databases/php-mysql 18DEPENDS+= ${PHP_PKG_PREFIX}-mysql{,i}>=5.2.0:../../databases/php-mysql
19DEPENDS+= ${PHP_PKG_PREFIX}-gd>=5.2.0:../../graphics/php-gd 19DEPENDS+= ${PHP_PKG_PREFIX}-gd>=5.2.0:../../graphics/php-gd
20DEPENDS+= ${PHP_PKG_PREFIX}-mcrypt>=5.2.0:../../security/php-mcrypt 20DEPENDS+= ${PHP_PKG_PREFIX}-mcrypt>=5.2.0:../../security/php-mcrypt
21DEPENDS+= ${PHP_PKG_PREFIX}-json>=5.2.0:../../textproc/php-json 21DEPENDS+= ${PHP_PKG_PREFIX}-json>=5.2.0:../../textproc/php-json
22 22
23PKG_DESTDIR_SUPPORT= user-destdir 23PKG_DESTDIR_SUPPORT= user-destdir
24 24
25FILES_SUBST+= CONF_INC_PHP=${CONF_INC_PHP:Q} PMCONFFILE=${PMCONFFILE:Q} 25FILES_SUBST+= CONF_INC_PHP=${CONF_INC_PHP:Q} PMCONFFILE=${PMCONFFILE:Q}
26PLIST_SUBST+= DIST_VERSION=${DIST_VERSION:Q} 26PLIST_SUBST+= DIST_VERSION=${DIST_VERSION:Q}
27MESSAGE_SUBST+= CONF_INC_PHP=${CONF_INC_PHP} PMCONFFILE=${PMCONFFILE:Q} \ 27MESSAGE_SUBST+= CONF_INC_PHP=${CONF_INC_PHP} PMCONFFILE=${PMCONFFILE:Q} \
28 EXDIR=${EXDIR:Q} 28 EXDIR=${EXDIR:Q}
29 29
30CONF_INC_PHP= ${PREFIX}/share/phpmyadmin/config.inc.php 30CONF_INC_PHP= ${PREFIX}/share/phpmyadmin/config.inc.php
31DIST_VERSION= 3.5.1 31DIST_VERSION= 3.5.2.1
32DOC_FILES= ChangeLog Documentation.txt LICENSE README \ 32DOC_FILES= ChangeLog Documentation.txt LICENSE README \
33 RELEASE-DATE-${DIST_VERSION} 33 RELEASE-DATE-${DIST_VERSION}
34 34
35APACHE_USER?= www 35APACHE_USER?= www
36APACHE_GROUP?= www 36APACHE_GROUP?= www
37PKG_GROUPS= ${APACHE_GROUP} 37PKG_GROUPS= ${APACHE_GROUP}
38PKG_USERS= ${APACHE_USER}:${APACHE_GROUP} 38PKG_USERS= ${APACHE_USER}:${APACHE_GROUP}
39BUILD_DEFS+= APACHE_USER APACHE_GROUP 39BUILD_DEFS+= APACHE_USER APACHE_GROUP
40 40
41PKG_USERS_VARS+= APACHE_USER 41PKG_USERS_VARS+= APACHE_USER
42PKG_GROUPS_VARS+= APACHE_GROUP 42PKG_GROUPS_VARS+= APACHE_GROUP
43 43
44EXDIR= ${PREFIX}/share/examples/phpmyadmin 44EXDIR= ${PREFIX}/share/examples/phpmyadmin

cvs diff -r1.27 -r1.27.2.1 pkgsrc/databases/phpmyadmin/PLIST (expand / switch to unified diff)

--- pkgsrc/databases/phpmyadmin/PLIST 2012/05/06 09:01:10 1.27
+++ pkgsrc/databases/phpmyadmin/PLIST 2012/08/08 18:39:21 1.27.2.1
@@ -1,19 +1,19 @@ @@ -1,19 +1,19 @@
1@comment $NetBSD: PLIST,v 1.27 2012/05/06 09:01:10 tron Exp $ 1@comment $NetBSD: PLIST,v 1.27.2.1 2012/08/08 18:39:21 spz Exp $
2share/doc/phpmyadmin/ChangeLog 2share/doc/phpmyadmin/ChangeLog
3share/doc/phpmyadmin/Documentation.txt 3share/doc/phpmyadmin/Documentation.txt
4share/doc/phpmyadmin/LICENSE 4share/doc/phpmyadmin/LICENSE
5share/doc/phpmyadmin/README 5share/doc/phpmyadmin/README
6share/doc/phpmyadmin/RELEASE-DATE-3.5.1 6share/doc/phpmyadmin/RELEASE-DATE-${DIST_VERSION}
7share/examples/phpmyadmin/apache.conf 7share/examples/phpmyadmin/apache.conf
8share/examples/phpmyadmin/config.inc.php 8share/examples/phpmyadmin/config.inc.php
9share/phpmyadmin/Documentation.html 9share/phpmyadmin/Documentation.html
10share/phpmyadmin/Documentation.txt 10share/phpmyadmin/Documentation.txt
11share/phpmyadmin/browse_foreigners.php 11share/phpmyadmin/browse_foreigners.php
12share/phpmyadmin/bs_disp_as_mime_type.php 12share/phpmyadmin/bs_disp_as_mime_type.php
13share/phpmyadmin/bs_play_media.php 13share/phpmyadmin/bs_play_media.php
14share/phpmyadmin/changelog.php 14share/phpmyadmin/changelog.php
15share/phpmyadmin/chk_rel.php 15share/phpmyadmin/chk_rel.php
16share/phpmyadmin/db_create.php 16share/phpmyadmin/db_create.php
17share/phpmyadmin/db_datadict.php 17share/phpmyadmin/db_datadict.php
18share/phpmyadmin/db_events.php 18share/phpmyadmin/db_events.php
19share/phpmyadmin/db_export.php 19share/phpmyadmin/db_export.php
@@ -151,27 +151,27 @@ share/phpmyadmin/js/rte/triggers.js @@ -151,27 +151,27 @@ share/phpmyadmin/js/rte/triggers.js
151share/phpmyadmin/js/server_plugins.js 151share/phpmyadmin/js/server_plugins.js
152share/phpmyadmin/js/server_privileges.js 152share/phpmyadmin/js/server_privileges.js
153share/phpmyadmin/js/server_status.js 153share/phpmyadmin/js/server_status.js
154share/phpmyadmin/js/server_status_monitor.js 154share/phpmyadmin/js/server_status_monitor.js
155share/phpmyadmin/js/server_synchronize.js 155share/phpmyadmin/js/server_synchronize.js
156share/phpmyadmin/js/server_variables.js 156share/phpmyadmin/js/server_variables.js
157share/phpmyadmin/js/sql.js 157share/phpmyadmin/js/sql.js
158share/phpmyadmin/js/tbl_change.js 158share/phpmyadmin/js/tbl_change.js
159share/phpmyadmin/js/tbl_chart.js 159share/phpmyadmin/js/tbl_chart.js
160share/phpmyadmin/js/tbl_gis_visualization.js 160share/phpmyadmin/js/tbl_gis_visualization.js
161share/phpmyadmin/js/tbl_relation.js 161share/phpmyadmin/js/tbl_relation.js
162share/phpmyadmin/js/tbl_select.js 162share/phpmyadmin/js/tbl_select.js
163share/phpmyadmin/js/tbl_structure.js 163share/phpmyadmin/js/tbl_structure.js
164share/phpmyadmin/js/tbl_zoom_plot.js 164share/phpmyadmin/js/tbl_zoom_plot_jqplot.js
165share/phpmyadmin/js/update-location.js 165share/phpmyadmin/js/update-location.js
166share/phpmyadmin/libraries/Advisor.class.php 166share/phpmyadmin/libraries/Advisor.class.php
167share/phpmyadmin/libraries/Config.class.php 167share/phpmyadmin/libraries/Config.class.php
168share/phpmyadmin/libraries/Error.class.php 168share/phpmyadmin/libraries/Error.class.php
169share/phpmyadmin/libraries/Error_Handler.class.php 169share/phpmyadmin/libraries/Error_Handler.class.php
170share/phpmyadmin/libraries/File.class.php 170share/phpmyadmin/libraries/File.class.php
171share/phpmyadmin/libraries/Index.class.php 171share/phpmyadmin/libraries/Index.class.php
172share/phpmyadmin/libraries/List.class.php 172share/phpmyadmin/libraries/List.class.php
173share/phpmyadmin/libraries/List_Database.class.php 173share/phpmyadmin/libraries/List_Database.class.php
174share/phpmyadmin/libraries/Message.class.php 174share/phpmyadmin/libraries/Message.class.php
175share/phpmyadmin/libraries/PDF.class.php 175share/phpmyadmin/libraries/PDF.class.php
176share/phpmyadmin/libraries/PMA.php 176share/phpmyadmin/libraries/PMA.php
177share/phpmyadmin/libraries/Partition.class.php 177share/phpmyadmin/libraries/Partition.class.php

cvs diff -r1.61 -r1.61.2.1 pkgsrc/databases/phpmyadmin/distinfo (expand / switch to unified diff)

--- pkgsrc/databases/phpmyadmin/distinfo 2012/05/06 09:01:10 1.61
+++ pkgsrc/databases/phpmyadmin/distinfo 2012/08/08 18:39:21 1.61.2.1
@@ -1,6 +1,5 @@ @@ -1,6 +1,5 @@
1$NetBSD: distinfo,v 1.61 2012/05/06 09:01:10 tron Exp $ 1$NetBSD: distinfo,v 1.61.2.1 2012/08/08 18:39:21 spz Exp $
2 2
3SHA1 (phpMyAdmin-3.5.1-all-languages.tar.xz) = f61c477e0ed394a10c10c3c1f8e73d1449432b1b 3SHA1 (phpMyAdmin-3.5.2.1-all-languages.tar.xz) = 353f6749c048c8b5199c2d81b828bec4fddbb0b6
4RMD160 (phpMyAdmin-3.5.1-all-languages.tar.xz) = a2ebd6ca3e70a5c0f8b4cefa03e508ee0c4fd910 4RMD160 (phpMyAdmin-3.5.2.1-all-languages.tar.xz) = 3200d260f8a6ea028d9cdf4679af398bc8939896
5Size (phpMyAdmin-3.5.1-all-languages.tar.xz) = 3590204 bytes 5Size (phpMyAdmin-3.5.2.1-all-languages.tar.xz) = 3654120 bytes
6SHA1 (patch-libraries_header_http.inc.php) = 523b2d961d1591291c85b9e381a20f59ce332aa1 

File Deleted: pkgsrc/databases/phpmyadmin/patches/Attic/patch-libraries_header_http.inc.php