Subject: CVS commit: [pkgsrc-2006Q2] pkgsrc/www/php4
To: None <pkgsrc-changes@NetBSD.org>
From: Lubomir Sedlacik <salo@netbsd.org>
List: pkgsrc-changes
Date: 08/24/2006 22:45:09
Module Name:	pkgsrc
Committed By:	salo
Date:		Thu Aug 24 22:45:09 UTC 2006

Modified Files:
	pkgsrc/www/php4 [pkgsrc-2006Q2]: Makefile.common distinfo
Removed Files:
	pkgsrc/www/php4/patches [pkgsrc-2006Q2]: patch-aw

Log Message:
Pullup ticket 1807 - requested by adrianp
security update for php4

Revisions pulled up:
- pkgsrc/www/php4/Makefile.common			1.54
- pkgsrc/www/php4/distinfo				1.57
- pkgsrc/www/php4/patches/patch-aw			removed

   Module Name:		pkgsrc
   Committed By:	adrianp
   Date:		Sun Aug 20 09:44:59 UTC 2006

   Modified Files:
   	pkgsrc/www/php4: Makefile.common distinfo
   Removed Files:
   	pkgsrc/www/php4/patches: patch-aw

   Log Message:
   PHP 4.4.4 Release Announcement

   This release address a series of locally exploitable security problems
   discovered since PHP 4.4.3. All PHP users are encouraged to upgrade to this
   release as soon as possible.

   This release provides the following security fixes:

   * Added missing safe_mode/open_basedir checks inside the error_log(),
     file_exists(), imap_open() and imap_reopen() functions.
   * Fixed overflows inside str_repeat() and wordwrap() functions on 64bit
   * systems.
   * Fixed possible open_basedir/safe_mode bypass in cURL extension.
   * Fixed overflow in GD extension on invalid GIF images.
   * Fixed a buffer overflow inside sscanf() function.
   * Fixed memory_limit restriction on 64 bit system.


To generate a diff of this commit:
cvs rdiff -r1.52.4.1 -r1.52.4.2 pkgsrc/www/php4/Makefile.common
cvs rdiff -r1.54.2.2 -r1.54.2.3 pkgsrc/www/php4/distinfo
cvs rdiff -r1.1.2.1 -r0 pkgsrc/www/php4/patches/patch-aw

Please note that diffs are not public domain; they are subject to the
copyright notices on the relevant files.