pkgsrc-Changes-HG archive
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]
[pkgsrc/pkgsrc-2019Q2]: pkgsrc/mail/squirrelmail Pullup ticket #6012 - reques...
details: https://anonhg.NetBSD.org/pkgsrc/rev/fb521b21867e
branches: pkgsrc-2019Q2
changeset: 338418:fb521b21867e
user: bsiegert <bsiegert%pkgsrc.org@localhost>
date: Fri Aug 09 12:38:43 2019 +0000
description:
Pullup ticket #6012 - requested by taca
mail/squirrelmail: security fix
Revisions pulled up:
- mail/squirrelmail/Makefile 1.137
- mail/squirrelmail/PLIST 1.42
- mail/squirrelmail/distinfo 1.71
---
Module Name: pkgsrc
Committed By: taca
Date: Wed Jul 24 03:49:35 UTC 2019
Modified Files:
pkgsrc/mail/squirrelmail: Makefile PLIST distinfo
Log Message:
mail/squirrelmail: update to 1.4.23pre14832
Update squirrelmail to 1.4.23pre14832.
- Changed anti-CSRF security token lifetime to be session-based.
- Added favicon and ability for admins to use their own by setting
$head_tag_extra in config_local.php (see documented comments in,
for example, src/webmail.php)
- Altered hook types "do_hook_function" and "concat_hook_function"
such that the ultimate hook return value (in its current state,
as computed (or not) by the plugins that have executed previously)
is both globalized and passed as an additional argument to each
plugin. This allows plugins to cooperate better and not overwrite
each other's return values.
- Updated SVG handling, closing several related vulnerabilities
(#2831) [CVE-2018-14950] [CVE-2018-14951] [CVE-2018-14952]
[CVE-2018-14953] [CVE-2018-14954] [CVE-2018-14955]
- Added IMAP ID command (RFC2971), sent after every login - use
by setting $imap_id_command_args in config/config_local.php
(see notes in functions/imap_general.php for more details)
- Fixed PHP7 warnings (#2847)
- Added handling for RCDATA and RAWTEXT elements in HTML sanitizer
[CVE-2019-12970]
diffstat:
mail/squirrelmail/Makefile | 7 +++----
mail/squirrelmail/PLIST | 3 ++-
mail/squirrelmail/distinfo | 10 +++++-----
3 files changed, 10 insertions(+), 10 deletions(-)
diffs (53 lines):
diff -r f6a561fbf7c9 -r fb521b21867e mail/squirrelmail/Makefile
--- a/mail/squirrelmail/Makefile Tue Jul 23 13:06:23 2019 +0000
+++ b/mail/squirrelmail/Makefile Fri Aug 09 12:38:43 2019 +0000
@@ -1,11 +1,10 @@
-# $NetBSD: Makefile,v 1.136 2019/05/23 19:23:08 rillig Exp $
+# $NetBSD: Makefile,v 1.136.2.1 2019/08/09 12:38:43 bsiegert Exp $
-DISTNAME= squirrelmail-webmail-1.4.23pre14764
+DISTNAME= squirrelmail-webmail-1.4.23pre14832
PKGNAME= ${DISTNAME:S/-webmail//}
-PKGREVISION= 1
CATEGORIES= mail www
MASTER_SITES= ${MASTER_SITE_LOCAL}
-EXTRACT_SUFX= .tar.bz2
+EXTRACT_SUFX= .tar.xz
MAINTAINER= taca%NetBSD.org@localhost
HOMEPAGE= http://www.squirrelmail.org/
diff -r f6a561fbf7c9 -r fb521b21867e mail/squirrelmail/PLIST
--- a/mail/squirrelmail/PLIST Tue Jul 23 13:06:23 2019 +0000
+++ b/mail/squirrelmail/PLIST Fri Aug 09 12:38:43 2019 +0000
@@ -1,4 +1,4 @@
-@comment $NetBSD: PLIST,v 1.41 2017/06/21 15:07:03 taca Exp $
+@comment $NetBSD: PLIST,v 1.41.20.1 2019/08/09 12:38:43 bsiegert Exp $
man/man8/squirrelmail-conf.pl.8
share/examples/squirrelmail/data/.htaccess
share/examples/squirrelmail/data/index.php
@@ -95,6 +95,7 @@
share/squirrelmail/doc/security.txt
share/squirrelmail/doc/translating.txt
share/squirrelmail/doc/translating_help.txt
+share/squirrelmail/favicon.ico
share/squirrelmail/functions/.htaccess
share/squirrelmail/functions/abook_database.php
share/squirrelmail/functions/abook_ldap_server.php
diff -r f6a561fbf7c9 -r fb521b21867e mail/squirrelmail/distinfo
--- a/mail/squirrelmail/distinfo Tue Jul 23 13:06:23 2019 +0000
+++ b/mail/squirrelmail/distinfo Fri Aug 09 12:38:43 2019 +0000
@@ -1,9 +1,9 @@
-$NetBSD: distinfo,v 1.70 2018/04/30 07:56:55 taca Exp $
+$NetBSD: distinfo,v 1.70.10.1 2019/08/09 12:38:43 bsiegert Exp $
-SHA1 (squirrelmail-webmail-1.4.23pre14764.tar.bz2) = 9fd0ddfd393be97373d5b839143285527c3cb9c4
-RMD160 (squirrelmail-webmail-1.4.23pre14764.tar.bz2) = 8b40681f8fa0cc9e25282d1215e6b88c2566c73b
-SHA512 (squirrelmail-webmail-1.4.23pre14764.tar.bz2) = 391d305184d88f4797ffb2203134bebfcd9327de063510155bc295f8edb1609dc2ea6e0f5e6d6f75e92e7fbfd938804aa0f155857c3c82c6a9f72f21b7ebf5a3
-Size (squirrelmail-webmail-1.4.23pre14764.tar.bz2) = 562786 bytes
+SHA1 (squirrelmail-webmail-1.4.23pre14832.tar.xz) = 32c38a24766fb5d0364253fdab36501923d7d9cd
+RMD160 (squirrelmail-webmail-1.4.23pre14832.tar.xz) = 689831ce73482384ce90b1ccfc84f81b29ad17eb
+SHA512 (squirrelmail-webmail-1.4.23pre14832.tar.xz) = b8a380f5bb72d2fdb2793edaf10410f3a3cdd8e3f7a44a4d3775be22cb202f29b2ee7c574f33986cfcb2d066dc6085b9b8092340f526e2c3dc8be1b39ccd8d12
+Size (squirrelmail-webmail-1.4.23pre14832.tar.xz) = 519160 bytes
SHA1 (patch-aa) = 4ba7ea0a85308816b9dc77c0af3c927359ed1275
SHA1 (patch-ab) = 30bf68c730f20e817fbe81d18bc2a95899ee3fd0
SHA1 (patch-ai) = e1a23673bf19bbbd88b00fb6bab3d6d1c8c11575
Home |
Main Index |
Thread Index |
Old Index