Subject: CVS commit: pkgsrc/www
To: None <pkgsrc-changes@netbsd.org>
From: Johnny C. Lam <jlam@netbsd.org>
List: pkgsrc-changes
Date: 02/28/2002 17:07:18
Module Name:	pkgsrc
Committed By:	jlam
Date:		Thu Feb 28 15:07:18 UTC 2002

Modified Files:
	pkgsrc/www/ap-php3: Makefile
	pkgsrc/www/php3: Makefile distinfo
Added Files:
	pkgsrc/www/php3/patches: patch-ak

Log Message:
Update php3 and ap-php3 to 3.0.18nb1.  Changes from version 3.0.18 are
a security fix for a file-upload bug.

			<===> SECURITY NOTE <===>

Note that the buffer overflow fix is a major security fix.  Quoting from
the security advisory at:

        http://security.e-matters.de/advisories/012002.html

"PHP supports multipart/form-data POST requests (as described in RFC1867)
known as POST fileuploads. Unfourtunately there are several flaws in the
php_mime_split function that could be used by an attacker to execute
arbitrary code. During our research we found out that not only PHP4 but
also older versions from the PHP3 tree are vulnerable.


To generate a diff of this commit:
cvs rdiff -r1.9 -r1.10 pkgsrc/www/ap-php3/Makefile
cvs rdiff -r1.32 -r1.33 pkgsrc/www/php3/Makefile
cvs rdiff -r1.3 -r1.4 pkgsrc/www/php3/distinfo
cvs rdiff -r0 -r1.1 pkgsrc/www/php3/patches/patch-ak

Please note that diffs are not public domain; they are subject to the
copyright notices on the relevant files.