pkgsrc-Changes-HG archive

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]

[pkgsrc/trunk]: pkgsrc/lang/php5 Fix for CVE-2006-3011



details:   https://anonhg.NetBSD.org/pkgsrc/rev/93212088b084
branches:  trunk
changeset: 516311:93212088b084
user:      adrianp <adrianp%pkgsrc.org@localhost>
date:      Tue Jul 18 21:57:30 2006 +0000

description:
Fix for CVE-2006-3011
Bump to nb2

diffstat:

 lang/php5/Makefile         |   4 ++--
 lang/php5/distinfo         |   3 ++-
 lang/php5/patches/patch-av |  15 +++++++++++++++
 3 files changed, 19 insertions(+), 3 deletions(-)

diffs (46 lines):

diff -r d4b91800a40a -r 93212088b084 lang/php5/Makefile
--- a/lang/php5/Makefile        Tue Jul 18 21:39:39 2006 +0000
+++ b/lang/php5/Makefile        Tue Jul 18 21:57:30 2006 +0000
@@ -1,7 +1,7 @@
-# $NetBSD: Makefile,v 1.37 2006/07/08 00:53:09 minskim Exp $
+# $NetBSD: Makefile,v 1.38 2006/07/18 21:57:30 adrianp Exp $
 
 PKGNAME=               php-${PHP_BASE_VERS}
-PKGREVISION=           1
+PKGREVISION=           2
 CATEGORIES=            lang
 
 HOMEPAGE=              http://www.php.net/
diff -r d4b91800a40a -r 93212088b084 lang/php5/distinfo
--- a/lang/php5/distinfo        Tue Jul 18 21:39:39 2006 +0000
+++ b/lang/php5/distinfo        Tue Jul 18 21:57:30 2006 +0000
@@ -1,4 +1,4 @@
-$NetBSD: distinfo,v 1.24 2006/07/08 00:53:09 minskim Exp $
+$NetBSD: distinfo,v 1.25 2006/07/18 21:57:30 adrianp Exp $
 
 SHA1 (php-5.1.4nb1/php-5.1.4.tar.bz2) = 83d4c5a4a3e8f3bcb0da841edd8d55893dbf5394
 RMD160 (php-5.1.4nb1/php-5.1.4.tar.bz2) = d4ab11884a3a899f21eef777767a553cf81584ce
@@ -11,3 +11,4 @@
 SHA1 (patch-as) = 217c06efe5912570fab64f205d0b4faa07cda063
 SHA1 (patch-at) = d1dd8decd0e5528e9166bd313bc382e3e138a82f
 SHA1 (patch-au) = 90264101db6c2f000c30d1f513392acec781202b
+SHA1 (patch-av) = a6cfc9b508d6e6e8fe2523a1b8a2480b6c767014
diff -r d4b91800a40a -r 93212088b084 lang/php5/patches/patch-av
--- /dev/null   Thu Jan 01 00:00:00 1970 +0000
+++ b/lang/php5/patches/patch-av        Tue Jul 18 21:57:30 2006 +0000
@@ -0,0 +1,15 @@
+$NetBSD: patch-av,v 1.1 2006/07/18 21:57:30 adrianp Exp $
+
+# This is CVE-2006-3011
+
+--- ext/standard/basic_functions.c.orig        2006-04-03 14:46:11.000000000 +0100
++++ ext/standard/basic_functions.c
+@@ -2034,7 +2034,7 @@ PHPAPI int _php_error_log(int opt_err, c
+                       break;
+ 
+               case 3:         /*save to a file */
+-                      stream = php_stream_open_wrapper(opt, "a", IGNORE_URL | ENFORCE_SAFE_MODE | REPORT_ERRORS, NULL);
++                      stream = php_stream_open_wrapper(opt, "a", IGNORE_URL_WIN | ENFORCE_SAFE_MODE | REPORT_ERRORS, NULL);
+                       if (!stream)
+                               return FAILURE;
+                       php_stream_write(stream, message, strlen(message));



Home | Main Index | Thread Index | Old Index