Up to [cvs.NetBSD.org] / pkgsrc / lang / php56
Request diff between arbitrary revisions
Default branch: MAIN
Revision 1.31 / (download) - annotate - [select for diffs], Wed Nov 23 16:18:50 2022 UTC (2 months, 1 week ago) by adam
Branch: MAIN
CVS Tags: pkgsrc-2022Q4-base,
pkgsrc-2022Q4,
HEAD
Changes since 1.30: +2 -2
lines
Diff to previous 1.30 (colored)
massive revision bump after textproc/icu update
Revision 1.29.4.1 / (download) - annotate - [select for diffs], Mon Nov 7 17:37:05 2022 UTC (2 months, 4 weeks ago) by bsiegert
Branch: pkgsrc-2022Q3
Changes since 1.29: +5 -5
lines
Diff to previous 1.29 (colored) next main 1.30 (colored)
Pullup ticket #6701 - requested by taca lang/php74: security fix Revisions pulled up: - lang/php/phpversion.mk 1.380 - lang/php56/Makefile 1.30 - lang/php74/Makefile 1.17 - lang/php74/distinfo 1.39 - lang/php80/Makefile 1.10 - lang/php81/Makefile 1.8 --- Module Name: pkgsrc Committed By: taca Date: Sun Oct 30 10:50:01 UTC 2022 Modified Files: pkgsrc/lang/php56: Makefile pkgsrc/lang/php74: Makefile pkgsrc/lang/php80: Makefile pkgsrc/lang/php81: Makefile Log Message: lang/php: post-install clean up Do not manually install executable files and manual. These are already done by php's Makefile from some time ago. --- Module Name: pkgsrc Committed By: taca Date: Fri Nov 4 00:40:58 UTC 2022 Modified Files: pkgsrc/lang/php: phpversion.mk pkgsrc/lang/php74: distinfo Log Message: lang/php74: update to 7.4.33 7.4.33 (2022-11-03) - GD: . Fixed bug #81739: OOB read due to insufficient input validation in imageloadfont(). (CVE-2022-31630) (cmb) - Hash: . Fixed bug #81738: buffer overflow in hash_update() on long parameter. (CVE-2022-37454) (nicky at mouha dot be)
Revision 1.30 / (download) - annotate - [select for diffs], Sun Oct 30 10:50:01 2022 UTC (3 months, 1 week ago) by taca
Branch: MAIN
Changes since 1.29: +5 -5
lines
Diff to previous 1.29 (colored)
lang/php: post-install clean up Do not manually install executable files and manual. These are already done by php's Makefile from some time ago.
Revision 1.29 / (download) - annotate - [select for diffs], Mon Apr 18 19:09:56 2022 UTC (9 months, 2 weeks ago) by adam
Branch: MAIN
CVS Tags: pkgsrc-2022Q3-base,
pkgsrc-2022Q2-base,
pkgsrc-2022Q2
Branch point for: pkgsrc-2022Q3
Changes since 1.28: +2 -2
lines
Diff to previous 1.28 (colored)
revbump for textproc/icu update
Revision 1.28 / (download) - annotate - [select for diffs], Wed Dec 8 16:02:17 2021 UTC (13 months, 4 weeks ago) by adam
Branch: MAIN
CVS Tags: pkgsrc-2022Q1-base,
pkgsrc-2022Q1,
pkgsrc-2021Q4-base,
pkgsrc-2021Q4
Changes since 1.27: +2 -2
lines
Diff to previous 1.27 (colored)
revbump for icu and libffi
Revision 1.27 / (download) - annotate - [select for diffs], Wed Apr 21 11:40:27 2021 UTC (21 months, 2 weeks ago) by adam
Branch: MAIN
CVS Tags: pkgsrc-2021Q3-base,
pkgsrc-2021Q3,
pkgsrc-2021Q2-base,
pkgsrc-2021Q2
Changes since 1.26: +2 -2
lines
Diff to previous 1.26 (colored)
revbump for textproc/icu
Revision 1.26 / (download) - annotate - [select for diffs], Thu Nov 5 09:06:58 2020 UTC (2 years, 3 months ago) by ryoon
Branch: MAIN
CVS Tags: pkgsrc-2021Q1-base,
pkgsrc-2021Q1,
pkgsrc-2020Q4-base,
pkgsrc-2020Q4
Changes since 1.25: +2 -2
lines
Diff to previous 1.25 (colored)
*: Recursive revbump from textproc/icu-68.1
Revision 1.25 / (download) - annotate - [select for diffs], Tue Jun 2 08:22:46 2020 UTC (2 years, 8 months ago) by adam
Branch: MAIN
CVS Tags: pkgsrc-2020Q3-base,
pkgsrc-2020Q3,
pkgsrc-2020Q2-base,
pkgsrc-2020Q2
Changes since 1.24: +2 -2
lines
Diff to previous 1.24 (colored)
Revbump for icu
Revision 1.24 / (download) - annotate - [select for diffs], Sat Jan 18 21:49:42 2020 UTC (3 years ago) by jperkin
Branch: MAIN
CVS Tags: pkgsrc-2020Q1-base,
pkgsrc-2020Q1
Changes since 1.23: +2 -2
lines
Diff to previous 1.23 (colored)
*: Recursive revision bump for openssl 1.1.1.
Revision 1.23 / (download) - annotate - [select for diffs], Wed Jul 3 07:30:50 2019 UTC (3 years, 7 months ago) by nia
Branch: MAIN
CVS Tags: pkgsrc-2019Q4-base,
pkgsrc-2019Q4,
pkgsrc-2019Q3-base,
pkgsrc-2019Q3
Changes since 1.22: +2 -2
lines
Diff to previous 1.22 (colored)
Use https for php.net.
Revision 1.22 / (download) - annotate - [select for diffs], Thu May 23 19:23:03 2019 UTC (3 years, 8 months ago) by rillig
Branch: MAIN
CVS Tags: pkgsrc-2019Q2-base,
pkgsrc-2019Q2
Changes since 1.21: +3 -3
lines
Diff to previous 1.21 (colored)
all: replace SUBST_SED with the simpler SUBST_VARS pkglint -Wall -r --only "substitution command" -F With manual review and indentation fixes since pkglint doesn't get that part correct in every case.
Revision 1.21 / (download) - annotate - [select for diffs], Sun Mar 31 20:48:40 2019 UTC (3 years, 10 months ago) by wiz
Branch: MAIN
Changes since 1.20: +2 -1
lines
Diff to previous 1.20 (colored)
php56: bump PKGREVISION for openssl 1.1 patch
Revision 1.19.2.1 / (download) - annotate - [select for diffs], Sat Jan 19 21:57:11 2019 UTC (4 years ago) by bsiegert
Branch: pkgsrc-2018Q4
Changes since 1.19: +1 -2
lines
Diff to previous 1.19 (colored) next main 1.20 (colored)
Pullup ticket #5899 - requested by taca lang/php56: security fix Revisions pulled up: - lang/php/phpversion.mk 1.245 - lang/php56/Makefile 1.20 - lang/php56/distinfo 1.54 --- Module Name: pkgsrc Committed By: taca Date: Sat Jan 12 15:01:34 UTC 2019 Modified Files: pkgsrc/lang/php: phpversion.mk pkgsrc/lang/php56: Makefile distinfo Log Message: lang/php56: udate to 5.6.40 10 Jan 2019, PHP 5.6.40 - GD: . Fixed bug #77269 (efree() on uninitialized Heap data in imagescale leads to use-after-free). (cmb) . Fixed bug #77270 (imagecolormatch Out Of Bounds Write on Heap). (cmb) - Mbstring: . Fixed bug #77370 (Buffer overflow on mb regex functions - fetch_token). (Stas) . Fixed bug #77371 (heap buffer overflow in mb regex functions - compile_string_node). (Stas) . Fixed bug #77381 (heap buffer overflow in multibyte match_at). (Stas) . Fixed bug #77382 (heap buffer overflow due to incorrect length in expand_case_fold_string). (Stas) . Fixed bug #77385 (buffer overflow in fetch_token). (Stas) . Fixed bug #77394 (Buffer overflow in multibyte case folding - unicode). (Stas) . Fixed bug #77418 (Heap overflow in utf32be_mbc_to_code). (Stas) - Phar: . Fixed bug #77247 (heap buffer overflow in phar_detect_phar_fname_ext). (Stas) - Xmlrpc: . Fixed bug #77242 (heap out of bounds read in xmlrpc_decode()). (cmb) . Fixed bug #77380 (Global out of bounds read in xmlrpc base64 code). (Stas)
Revision 1.20 / (download) - annotate - [select for diffs], Sat Jan 12 15:01:34 2019 UTC (4 years ago) by taca
Branch: MAIN
CVS Tags: pkgsrc-2019Q1-base,
pkgsrc-2019Q1
Changes since 1.19: +1 -2
lines
Diff to previous 1.19 (colored)
lang/php56: udate to 5.6.40 10 Jan 2019, PHP 5.6.40 - GD: . Fixed bug #77269 (efree() on uninitialized Heap data in imagescale leads to use-after-free). (cmb) . Fixed bug #77270 (imagecolormatch Out Of Bounds Write on Heap). (cmb) - Mbstring: . Fixed bug #77370 (Buffer overflow on mb regex functions - fetch_token). (Stas) . Fixed bug #77371 (heap buffer overflow in mb regex functions - compile_string_node). (Stas) . Fixed bug #77381 (heap buffer overflow in multibyte match_at). (Stas) . Fixed bug #77382 (heap buffer overflow due to incorrect length in expand_case_fold_string). (Stas) . Fixed bug #77385 (buffer overflow in fetch_token). (Stas) . Fixed bug #77394 (Buffer overflow in multibyte case folding - unicode). (Stas) . Fixed bug #77418 (Heap overflow in utf32be_mbc_to_code). (Stas) - Phar: . Fixed bug #77247 (heap buffer overflow in phar_detect_phar_fname_ext). (Stas) - Xmlrpc: . Fixed bug #77242 (heap out of bounds read in xmlrpc_decode()). (cmb) . Fixed bug #77380 (Global out of bounds read in xmlrpc base64 code). (Stas)
Revision 1.19 / (download) - annotate - [select for diffs], Sun Dec 9 12:20:44 2018 UTC (4 years, 1 month ago) by taca
Branch: MAIN
CVS Tags: pkgsrc-2018Q4-base
Branch point for: pkgsrc-2018Q4
Changes since 1.18: +2 -1
lines
Diff to previous 1.18 (colored)
Bump PKGREVISION for separation of php-sqlite3 package from lang/php?? base packages.
Revision 1.15.2.1 / (download) - annotate - [select for diffs], Sat Mar 3 09:23:30 2018 UTC (4 years, 11 months ago) by spz
Branch: pkgsrc-2017Q4
Changes since 1.15: +1 -7
lines
Diff to previous 1.15 (colored) next main 1.16 (colored)
Pullup ticket #5715 - requested by taca lang/php56: security update Revisions pulled up: - lang/php56/DESCR 1.3 - lang/php56/MESSAGE 1.2 - lang/php56/Makefile 1.16 - lang/php56/distinfo 1.45-1.46 - lang/php56/patches/patch-configure 1.4 ------------------------------------------------------------------- Module Name: pkgsrc Committed By: jperkin Date: Tue Jan 16 11:28:09 UTC 2018 Modified Files: pkgsrc/lang/php56: Makefile distinfo pkgsrc/lang/php56/patches: patch-configure Log Message: php56: Convert libgcc fix to a patch to mirror php7*. To generate a diff of this commit: cvs rdiff -u -r1.15 -r1.16 pkgsrc/lang/php56/Makefile cvs rdiff -u -r1.44 -r1.45 pkgsrc/lang/php56/distinfo cvs rdiff -u -r1.3 -r1.4 pkgsrc/lang/php56/patches/patch-configure ------------------------------------------------------------------- Module Name: pkgsrc Committed By: jdolecek Date: Sun Feb 4 11:35:39 UTC 2018 Modified Files: pkgsrc/lang/php56: DESCR MESSAGE pkgsrc/lang/php70: DESCR MESSAGE Log Message: note a planned End of Life for support of PHP 5.6.x and PHP 7.0.x Those releases will stop getting official support on Dec 31 2018 and Dec 3 2018 respectively, and they should be removed from pkgsrc by then. To generate a diff of this commit: cvs rdiff -u -r1.2 -r1.3 pkgsrc/lang/php56/DESCR cvs rdiff -u -r1.1 -r1.2 pkgsrc/lang/php56/MESSAGE ------------------------------------------------------------------- Module Name: pkgsrc Committed By: taca Date: Fri Mar 2 02:13:44 UTC 2018 Modified Files: pkgsrc/lang/php: phpversion.mk pkgsrc/lang/php56: distinfo Log Message: lang/php56: update to 5.6.34 01 Mar 2018, PHP 5.6.34 - Standard: . Fixed bug #75981 (stack-buffer-overflow while parsing HTTP response). (Stas) To generate a diff of this commit: cvs rdiff -u -r1.45 -r1.46 pkgsrc/lang/php56/distinfo
Revision 1.18 / (download) - annotate - [select for diffs], Fri Feb 23 15:26:15 2018 UTC (4 years, 11 months ago) by wiz
Branch: MAIN
CVS Tags: pkgsrc-2018Q3-base,
pkgsrc-2018Q3,
pkgsrc-2018Q2-base,
pkgsrc-2018Q2,
pkgsrc-2018Q1-base,
pkgsrc-2018Q1
Changes since 1.17: +1 -5
lines
Diff to previous 1.17 (colored)
lang/*: remove BROKEN markers for known openssl-1.1 breakage Requested by joerg.
Revision 1.17 / (download) - annotate - [select for diffs], Tue Feb 20 06:42:20 2018 UTC (4 years, 11 months ago) by wiz
Branch: MAIN
Changes since 1.16: +5 -1
lines
Diff to previous 1.16 (colored)
php56: mark as broken on NetBSD-current due to openssl-1.1
Revision 1.16 / (download) - annotate - [select for diffs], Tue Jan 16 11:28:09 2018 UTC (5 years ago) by jperkin
Branch: MAIN
Changes since 1.15: +1 -7
lines
Diff to previous 1.15 (colored)
php56: Convert libgcc fix to a patch to mirror php7*.
Revision 1.14.4.1 / (download) - annotate - [select for diffs], Tue Oct 31 18:13:26 2017 UTC (5 years, 3 months ago) by spz
Branch: pkgsrc-2017Q3
Changes since 1.14: +1 -5
lines
Diff to previous 1.14 (colored) next main 1.15 (colored)
Pullup ticket #5613 - requested by taca lang/php56: security update Revisions pulled up: - lang/php56/Makefile 1.15 - lang/php56/distinfo 1.43 - lang/php/phpversion.mk patch ------------------------------------------------------------------- Module Name: pkgsrc Committed By: taca Date: Fri Oct 27 08:45:06 UTC 2017 Modified Files: pkgsrc/lang/php: phpversion.mk pkgsrc/lang/php56: Makefile distinfo Log Message: lang/php56: Update to 5.6.32 * pkgsrc change: remove post-extract which is not required any more. * including securiy fixes. 26 Sep 2017, PHP 5.6.32 - Date: . Fixed bug #75055 (Out-Of-Bounds Read in timelib_meridian()). (Derick) - mcrypt: . Fixed bug #72535 (arcfour encryption stream filter crashes php). (Leigh) - PCRE: . Fixed bug #75207 (applied upstream patch for CVE-2016-1283). (Anatol) To generate a diff of this commit: cvs rdiff -u -r1.14 -r1.15 pkgsrc/lang/php56/Makefile cvs rdiff -u -r1.42 -r1.43 pkgsrc/lang/php56/distinfo
Revision 1.15 / (download) - annotate - [select for diffs], Fri Oct 27 08:45:06 2017 UTC (5 years, 3 months ago) by taca
Branch: MAIN
CVS Tags: pkgsrc-2017Q4-base
Branch point for: pkgsrc-2017Q4
Changes since 1.14: +1 -5
lines
Diff to previous 1.14 (colored)
lang/php56: Update to 5.6.32 * pkgsrc change: remove post-extract which is not required any more. * including securiy fixes. 26 Sep 2017, PHP 5.6.32 - Date: . Fixed bug #75055 (Out-Of-Bounds Read in timelib_meridian()). (Derick) - mcrypt: . Fixed bug #72535 (arcfour encryption stream filter crashes php). (Leigh) - PCRE: . Fixed bug #75207 (applied upstream patch for CVE-2016-1283). (Anatol)
Revision 1.13.2.1 / (download) - annotate - [select for diffs], Sat Jul 15 19:23:43 2017 UTC (5 years, 6 months ago) by bsiegert
Branch: pkgsrc-2017Q2
Changes since 1.13: +1 -2
lines
Diff to previous 1.13 (colored) next main 1.14 (colored)
Pullup ticket #5509 - requested by taca lang/php56: security fix Revisions pulled up: - lang/php/phpversion.mk 1.184 - lang/php56/Makefile 1.14 - lang/php56/distinfo 1.42 --- Module Name: pkgsrc Committed By: taca Date: Fri Jul 7 03:13:48 UTC 2017 Modified Files: pkgsrc/lang/php: phpversion.mk pkgsrc/lang/php56: Makefile distinfo Log Message: Update php56 to 5.6.31. 06 Jul 2017, PHP 5.6.31 - Core: . Fixed bug #73807 (Performance problem with processing post request over 2000000 chars). (Nikita) . Fixed bug #74111 (Heap buffer overread (READ: 1) finish_nested_data from unserialize). (Nikita) . Fixed bug #74603 (PHP INI Parsing Stack Buffer Overflow Vulnerability). (Stas) . Fixed bug #74819 (wddx_deserialize() heap out-of-bound read via php_parse_date()). (Derick) - GD: . Fixed bug #74435 (Buffer over-read into uninitialized memory). (cmb) - mbstring: . Add oniguruma upstream fix (CVE-2017-9224, CVE-2017-9226, CVE-2017-9227, CVE-2017-9228, CVE-2017-9229) (Remi, Mamoru TASAKA) - OpenSSL: . Fixed bug #74651 (negative-size-param (-1) in memcpy in zif_openssl_seal()). (Stas) - PCRE: . Fixed bug #74087 (Segmentation fault in PHP7.1.1(compiled using the bundled PCRE library)). (Stas) - WDDX: . Fixed bug #74145 (wddx parsing empty boolean tag leads to SIGSEGV). (Stas)
Revision 1.14 / (download) - annotate - [select for diffs], Fri Jul 7 03:13:48 2017 UTC (5 years, 7 months ago) by taca
Branch: MAIN
CVS Tags: pkgsrc-2017Q3-base
Branch point for: pkgsrc-2017Q3
Changes since 1.13: +1 -2
lines
Diff to previous 1.13 (colored)
Update php56 to 5.6.31. 06 Jul 2017, PHP 5.6.31 - Core: . Fixed bug #73807 (Performance problem with processing post request over 2000000 chars). (Nikita) . Fixed bug #74111 (Heap buffer overread (READ: 1) finish_nested_data from unserialize). (Nikita) . Fixed bug #74603 (PHP INI Parsing Stack Buffer Overflow Vulnerability). (Stas) . Fixed bug #74819 (wddx_deserialize() heap out-of-bound read via php_parse_date()). (Derick) - GD: . Fixed bug #74435 (Buffer over-read into uninitialized memory). (cmb) - mbstring: . Add oniguruma upstream fix (CVE-2017-9224, CVE-2017-9226, CVE-2017-9227, CVE-2017-9228, CVE-2017-9229) (Remi, Mamoru TASAKA) - OpenSSL: . Fixed bug #74651 (negative-size-param (-1) in memcpy in zif_openssl_seal()). (Stas) - PCRE: . Fixed bug #74087 (Segmentation fault in PHP7.1.1(compiled using the bundled PCRE library)). (Stas) - WDDX: . Fixed bug #74145 (wddx parsing empty boolean tag leads to SIGSEGV). (Stas)
Revision 1.12.8.1 / (download) - annotate - [select for diffs], Wed Apr 12 18:22:19 2017 UTC (5 years, 9 months ago) by bsiegert
Branch: pkgsrc-2017Q1
Changes since 1.12: +2 -1
lines
Diff to previous 1.12 (colored) next main 1.13 (colored)
Pullup ticket #5243 - requested by sevan lang/php56: build fix lang/php70: build fix lang/php71: build fix Revisions pulled up: - lang/php56/Makefile 1.13 - lang/php56/Makefile.php 1.2 - lang/php56/PLIST 1.3 - lang/php56/distinfo 1.41 - lang/php56/patches/patch-ext_xsl_php__xsl.h 1.1 - lang/php70/Makefile 1.6 - lang/php70/Makefile.php 1.3 - lang/php70/PLIST 1.3 - lang/php70/distinfo 1.31 - lang/php70/patches/patch-ext_xsl_php__xsl.h 1.1 - lang/php71/Makefile 1.9 - lang/php71/Makefile.php 1.2 - lang/php71/PLIST 1.3 - lang/php71/distinfo 1.17 - lang/php71/patches/patch-ext_xsl_php__xsl.h 1.1 - textproc/Makefile 1.918 - textproc/php-dom/DESCR deleted - textproc/php-dom/Makefile deleted --- Module Name: pkgsrc Committed By: fhajny Date: Wed Apr 5 12:28:59 UTC 2017 Modified Files: pkgsrc/lang/php56: Makefile Makefile.php PLIST distinfo pkgsrc/lang/php70: Makefile Makefile.php PLIST distinfo pkgsrc/lang/php71: Makefile Makefile.php PLIST distinfo Added Files: pkgsrc/lang/php56/patches: patch-ext_xsl_php__xsl.h pkgsrc/lang/php70/patches: patch-ext_xsl_php__xsl.h pkgsrc/lang/php71/patches: patch-ext_xsl_php__xsl.h Log Message: Build the dom extension embedded. This enables full functionality in xmlreader and fixes joyent/pkgsrc/issues/477. Bump PKREVISION. --- Module Name: pkgsrc Committed By: fhajny Date: Wed Apr 5 12:34:47 UTC 2017 Modified Files: pkgsrc/textproc: Makefile Removed Files: pkgsrc/textproc/php-dom: DESCR Makefile Log Message: Remove textproc/php-dom, the module is now built into the resp. PHP packages.
Revision 1.13 / (download) - annotate - [select for diffs], Wed Apr 5 12:28:59 2017 UTC (5 years, 10 months ago) by fhajny
Branch: MAIN
CVS Tags: pkgsrc-2017Q2-base
Branch point for: pkgsrc-2017Q2
Changes since 1.12: +2 -1
lines
Diff to previous 1.12 (colored)
Build the dom extension embedded. This enables full functionality in xmlreader and fixes joyent/pkgsrc/issues/477. Bump PKREVISION.
Revision 1.11.2.1 / (download) - annotate - [select for diffs], Tue Jun 28 19:37:34 2016 UTC (6 years, 7 months ago) by bsiegert
Branch: pkgsrc-2016Q1
Changes since 1.11: +2 -2
lines
Diff to previous 1.11 (colored) next main 1.12 (colored)
Pullup ticket #5051 - requested by taca lang/php56: security fix Revisions pulled up: - lang/php/phpversion.mk 1.140 - lang/php56/Makefile 1.12 - lang/php56/distinfo 1.28 --- Module Name: pkgsrc Committed By: taca Date: Fri Jun 24 15:25:21 UTC 2016 Modified Files: pkgsrc/lang/php: phpversion.mk pkgsrc/lang/php56: Makefile distinfo Log Message: Update php56 to 5.6.23 (PHP 5.6.23), including security fixes. pkgsrc change: remove confiugre from SUBST_FILES.path. 23 Jun 2016, PHP 5.6.23 - Core: . Fixed bug #72275 (Integer Overflow in json_encode()/json_decode()/ json_utf8_to_utf16()). (Stas) . Fixed bug #72400 (Integer Overflow in addcslashes/addslashes). (Stas) . Fixed bug #72403 (Integer Overflow in Length of String-typed ZVAL). (Stas) - GD: . Fixed bug #72298 (pass2_no_dither out-of-bounds access). (Stas) . Fixed bug #72337 (invalid dimensions can lead to crash) (Pierre) . Fixed bug #72339 (Integer Overflow in _gd2GetHeader() resulting in heap overflow). (Pierre) . Fixed bug #72407 (NULL Pointer Dereference at _gdScaleVert). (Stas) . Fixed bug #72446 (Integer Overflow in gdImagePaletteToTrueColor() resulting in heap overflow). (Pierre) - Intl: . Fixed bug #70484 (selectordinal doesn't work with named parameters). (Anatol) - mbstring: . Fixed bug #72402 (_php_mb_regex_ereg_replace_exec - double free). (Stas) - mcrypt: . Fixed bug #72455 (Heap Overflow due to integer overflows). (Stas) - Phar: . Fixed bug #72321 (invalid free in phar_extract_file()). (hji at dyntopia dot com) - SPL: . Fixed bug #72262 (int/size_t confusion in SplFileObject::fread). (Stas) . Fixed bug #72433 (Use After Free Vulnerability in PHP's GC algorithm and unserialize). (Dmitry) - OpenSSL: . Fixed bug #72140 (segfault after calling ERR_free_strings()). (Jakub Zelenka) - WDDX: . Fixed bug #72340 (Double Free Courruption in wddx_deserialize). (Stas) - zip: . Fixed bug #72434 (ZipArchive class Use After Free Vulnerability in PHP's GC algorithm and unserialize). (Dmitry)
Revision 1.12 / (download) - annotate - [select for diffs], Fri Jun 24 15:25:21 2016 UTC (6 years, 7 months ago) by taca
Branch: MAIN
CVS Tags: pkgsrc-2017Q1-base,
pkgsrc-2016Q4-base,
pkgsrc-2016Q4,
pkgsrc-2016Q3-base,
pkgsrc-2016Q3,
pkgsrc-2016Q2-base,
pkgsrc-2016Q2
Branch point for: pkgsrc-2017Q1
Changes since 1.11: +2 -2
lines
Diff to previous 1.11 (colored)
Update php56 to 5.6.23 (PHP 5.6.23), including security fixes. pkgsrc change: remove confiugre from SUBST_FILES.path. 23 Jun 2016, PHP 5.6.23 - Core: . Fixed bug #72275 (Integer Overflow in json_encode()/json_decode()/ json_utf8_to_utf16()). (Stas) . Fixed bug #72400 (Integer Overflow in addcslashes/addslashes). (Stas) . Fixed bug #72403 (Integer Overflow in Length of String-typed ZVAL). (Stas) - GD: . Fixed bug #72298 (pass2_no_dither out-of-bounds access). (Stas) . Fixed bug #72337 (invalid dimensions can lead to crash) (Pierre) . Fixed bug #72339 (Integer Overflow in _gd2GetHeader() resulting in heap overflow). (Pierre) . Fixed bug #72407 (NULL Pointer Dereference at _gdScaleVert). (Stas) . Fixed bug #72446 (Integer Overflow in gdImagePaletteToTrueColor() resulting in heap overflow). (Pierre) - Intl: . Fixed bug #70484 (selectordinal doesn't work with named parameters). (Anatol) - mbstring: . Fixed bug #72402 (_php_mb_regex_ereg_replace_exec - double free). (Stas) - mcrypt: . Fixed bug #72455 (Heap Overflow due to integer overflows). (Stas) - Phar: . Fixed bug #72321 (invalid free in phar_extract_file()). (hji at dyntopia dot com) - SPL: . Fixed bug #72262 (int/size_t confusion in SplFileObject::fread). (Stas) . Fixed bug #72433 (Use After Free Vulnerability in PHP's GC algorithm and unserialize). (Dmitry) - OpenSSL: . Fixed bug #72140 (segfault after calling ERR_free_strings()). (Jakub Zelenka) - WDDX: . Fixed bug #72340 (Double Free Courruption in wddx_deserialize). (Stas) - zip: . Fixed bug #72434 (ZipArchive class Use After Free Vulnerability in PHP's GC algorithm and unserialize). (Dmitry)
Revision 1.11 / (download) - annotate - [select for diffs], Sat Apr 2 09:00:25 2016 UTC (6 years, 10 months ago) by taca
Branch: MAIN
CVS Tags: pkgsrc-2016Q1-base
Branch point for: pkgsrc-2016Q1
Changes since 1.10: +1 -2
lines
Diff to previous 1.10 (colored)
Update php56 to 5.6.20, including security fix. Add add an patch to fix memory leak noted from Zafer Aydo¾»įn via private mail. 31 Mar 2016, PHP 5.6.20 - CLI Server: . Fixed bug #69953 (Support MKCALENDAR request method). (Christoph) - Core: . Fixed bug #71596 (Segmentation fault on ZTS with date function (setlocale)). (Anatol) - Curl: . Fixed bug #71694 (Support constant CURLM_ADDED_ALREADY). (mpyw) - Date: . Fixed bug #71635 (DatePeriod::getEndDate segfault). (Thomas Punt) - Fileinfo: . Fixed bug #71527 (Buffer over-write in finfo_open with malformed magic file). (Anatol) - Mbstring: . Fixed bug #71906 (AddressSanitizer: negative-size-param (-1) in mbfl_strcut). (Stas) - ODBC: . Fixed bug #47803, #69526 (Executing prepared statements is succesfull only for the first two statements). (einavitamar at gmail dot com, Anatol) . Fixed bug #71860 (Invalid memory write in phar on filename with \0 in name). (Stas) - PDO_DBlib: . Bug #54648 (PDO::MSSQL forces format of datetime fields). (steven dot lambeth at gmx dot de, Anatol) - Phar: . Fixed bug #71625 (Crash in php7.dll with bad phar filename). (Anatol) . Fixed bug #71504 (Parsing of tar file with duplicate filenames causes memory leak). (Jos Elstgeest) - SNMP: . Fixed bug #71704 (php_snmp_error() Format String Vulnerability). (andrew at jmpesp dot org) - Standard . Fixed bug #71798 (Integer Overflow in php_raw_url_encode). (taoguangchen at icloud dot com, Stas)
Revision 1.10 / (download) - annotate - [select for diffs], Sat Mar 5 11:28:43 2016 UTC (6 years, 11 months ago) by jperkin
Branch: MAIN
Changes since 1.9: +2 -1
lines
Diff to previous 1.9 (colored)
Bump PKGREVISION for security/openssl ABI bump.
Revision 1.9 / (download) - annotate - [select for diffs], Tue Oct 27 09:08:20 2015 UTC (7 years, 3 months ago) by jperkin
Branch: MAIN
CVS Tags: pkgsrc-2015Q4-base,
pkgsrc-2015Q4
Changes since 1.8: +7 -1
lines
Diff to previous 1.8 (colored)
Pass --disable-libgcc when using SunOS/clang, clang doesn't support the test and will handle libgcc itself as appropriate.
Revision 1.8 / (download) - annotate - [select for diffs], Mon Sep 7 12:02:05 2015 UTC (7 years, 5 months ago) by jperkin
Branch: MAIN
CVS Tags: pkgsrc-2015Q3-base,
pkgsrc-2015Q3
Changes since 1.7: +1 -6
lines
Diff to previous 1.7 (colored)
Now that _STRIPFLAG_INSTALL is disabled by default on Darwin, remove manual settings of INSTALL_UNSTRIPPED=yes for Darwin in individual packages.
Revision 1.6.2.1 / (download) - annotate - [select for diffs], Tue Jul 14 22:14:30 2015 UTC (7 years, 6 months ago) by tron
Branch: pkgsrc-2015Q2
Changes since 1.6: +1 -2
lines
Diff to previous 1.6 (colored) next main 1.7 (colored)
Pullup ticket #4774 - requested by taca lang/php56: security update Revisions pulled up: - lang/php/phpversion.mk 1.105 - lang/php56/Makefile 1.7 - lang/php56/distinfo 1.13 - lang/php56/patches/patch-ext_spl_spl__heap.c deleted --- Module Name: pkgsrc Committed By: taca Date: Sat Jul 11 00:31:01 UTC 2015 Modified Files: pkgsrc/lang/php: phpversion.mk pkgsrc/lang/php56: Makefile distinfo Removed Files: pkgsrc/lang/php56/patches: patch-ext_spl_spl__heap.c Log Message: Update php56 to 5.6.11. 10 Jul 2015, PHP 5.6.11 - Core: . Fixed bug #69768 (escapeshell*() doesn't cater to !). (cmb) . Fixed bug #69703 (Use __builtin_clzl on PowerPC). (dja at axtens dot net, Kalle) . Fixed bug #69732 (can induce segmentation fault with basic php code). (Dmitry) . Fixed bug #69642 (Windows 10 reported as Windows 8). (Christian Wenz, Anatol Belski) . Fixed bug #69551 (parse_ini_file() and parse_ini_string() segmentation fault). (Christoph M. Becker) . Fixed bug #69781 (phpinfo() reports Professional Editions of Windows 7/8/8.1/10 as "Business"). (Christian Wenz) . Fixed bug #69740 (finally in generator (yield) swallows exception in iteration). (Nikita) . Fixed bug #69835 (phpinfo() does not report many Windows SKUs). (Christian Wenz) . Fixed bug #69892 (Different arrays compare indentical due to integer key truncation). (Nikita) . Fixed bug #69874 (Can't set empty additional_headers for mail()), regression from fix to bug #68776. (Yasuo) - GD: . Fixed bug #61221 (imagegammacorrect function loses alpha channel). (cmb) - GMP: . Fixed bug #69803 (gmp_random_range() modifies second parameter if GMP number). (Nikita) - PCRE: . Fixed Bug #53823 (preg_replace: * qualifier on unicode replace garbles the string). (cmb) . Fixed bug #69864 (Segfault in preg_replace_callback) (cmb, ab) - PDO_pgsql: . Fixed bug #69752 (PDOStatement::execute() leaks memory with DML Statements when closeCuror() is u). (Philip Hofstetter) . Fixed bug #69362 (PDO-pgsql fails to connect if password contains a leading single quote). (Matteo) . Fixed bug #69344 (PDO PgSQL Incorrect binding numeric array with gaps). (Matteo) - SimpleXML: . Refactored the fix for bug #66084 (simplexml_load_string() mangles empty node name). (Christoph Michael Becker) - SPL: . Fixed bug #69737 (Segfault when SplMinHeap::compare produces fatal error). (Stas) . Fixed bug #67805 (SplFileObject setMaxLineLength). (Willian Gustavo Veiga). . Fixed bug #69970 (Use-after-free vulnerability in spl_recursive_it_move_forward_ex()). (Laruence) - Sqlite3: . Fixed bug #69972 (Use-after-free vulnerability in sqlite3SafetyCheckSickOrOk()). (Laruence)
Revision 1.7 / (download) - annotate - [select for diffs], Sat Jul 11 00:31:01 2015 UTC (7 years, 6 months ago) by taca
Branch: MAIN
Changes since 1.6: +1 -2
lines
Diff to previous 1.6 (colored)
Update php56 to 5.6.11. 10 Jul 2015, PHP 5.6.11 - Core: . Fixed bug #69768 (escapeshell*() doesn't cater to !). (cmb) . Fixed bug #69703 (Use __builtin_clzl on PowerPC). (dja at axtens dot net, Kalle) . Fixed bug #69732 (can induce segmentation fault with basic php code). (Dmitry) . Fixed bug #69642 (Windows 10 reported as Windows 8). (Christian Wenz, Anatol Belski) . Fixed bug #69551 (parse_ini_file() and parse_ini_string() segmentation fault). (Christoph M. Becker) . Fixed bug #69781 (phpinfo() reports Professional Editions of Windows 7/8/8.1/10 as "Business"). (Christian Wenz) . Fixed bug #69740 (finally in generator (yield) swallows exception in iteration). (Nikita) . Fixed bug #69835 (phpinfo() does not report many Windows SKUs). (Christian Wenz) . Fixed bug #69892 (Different arrays compare indentical due to integer key truncation). (Nikita) . Fixed bug #69874 (Can't set empty additional_headers for mail()), regression from fix to bug #68776. (Yasuo) - GD: . Fixed bug #61221 (imagegammacorrect function loses alpha channel). (cmb) - GMP: . Fixed bug #69803 (gmp_random_range() modifies second parameter if GMP number). (Nikita) - PCRE: . Fixed Bug #53823 (preg_replace: * qualifier on unicode replace garbles the string). (cmb) . Fixed bug #69864 (Segfault in preg_replace_callback) (cmb, ab) - PDO_pgsql: . Fixed bug #69752 (PDOStatement::execute() leaks memory with DML Statements when closeCuror() is u). (Philip Hofstetter) . Fixed bug #69362 (PDO-pgsql fails to connect if password contains a leading single quote). (Matteo) . Fixed bug #69344 (PDO PgSQL Incorrect binding numeric array with gaps). (Matteo) - SimpleXML: . Refactored the fix for bug #66084 (simplexml_load_string() mangles empty node name). (Christoph Michael Becker) - SPL: . Fixed bug #69737 (Segfault when SplMinHeap::compare produces fatal error). (Stas) . Fixed bug #67805 (SplFileObject setMaxLineLength). (Willian Gustavo Veiga). . Fixed bug #69970 (Use-after-free vulnerability in spl_recursive_it_move_forward_ex()). (Laruence) - Sqlite3: . Fixed bug #69972 (Use-after-free vulnerability in sqlite3SafetyCheckSickOrOk()). (Laruence)
Revision 1.6 / (download) - annotate - [select for diffs], Sun Jun 28 15:35:33 2015 UTC (7 years, 7 months ago) by taca
Branch: MAIN
CVS Tags: pkgsrc-2015Q2-base
Branch point for: pkgsrc-2015Q2
Changes since 1.5: +2 -1
lines
Diff to previous 1.5 (colored)
Add fix to https://bugs.php.net/bug.php?id=69737. Bump PKGREVISION.
Revision 1.5 / (download) - annotate - [select for diffs], Mon Mar 16 00:26:31 2015 UTC (7 years, 10 months ago) by taca
Branch: MAIN
CVS Tags: pkgsrc-2015Q1-base,
pkgsrc-2015Q1
Changes since 1.4: +2 -2
lines
Diff to previous 1.4 (colored)
Fix problem by PHP_BASE_VERS related changes.
Revision 1.1.2.2 / (download) - annotate - [select for diffs], Wed Mar 4 18:52:36 2015 UTC (7 years, 11 months ago) by tron
Branch: pkgsrc-2014Q4
Changes since 1.1.2.1: +0 -1
lines
Diff to previous 1.1.2.1 (colored) to branchpoint 1.1 (colored) next main 1.2 (colored)
Pullup ticket #4633 - requested by taca lang/php56: security update Revisions pulled up: - lang/php/phpversion.mk 1.88 - lang/php56/Makefile 1.4 - lang/php56/PLIST 1.2 - lang/php56/distinfo 1.6 - lang/php56/patches/patch-ext_date_php_date.c deleted - lang/php56/patches/patch-ext_date_tests_bug68942.phpt deleted - lang/php56/patches/patch-ext_date_tests_bug68942_2.phpt deleted --- Module Name: pkgsrc Committed By: taca Date: Fri Feb 20 01:17:50 UTC 2015 Modified Files: pkgsrc/lang/php: phpversion.mk pkgsrc/lang/php56: Makefile PLIST distinfo Removed Files: pkgsrc/lang/php56/patches: patch-ext_date_php_date.c patch-ext_date_tests_bug68942.phpt patch-ext_date_tests_bug68942_2.phpt Log Message: Update php56 to 5.6.6 (PHP 5.6.6). 19 Feb 2015, PHP 5.6.6 - Core: . Removed support for multi-line headers, as the are deprecated by RFC 7230. (Stas) . Fixed bug #67068 (getClosure returns somethings that's not a closure). (Danack at basereality dot com) . Fixed bug #68942 (Use after free vulnerability in unserialize() with DateTimeZone). (CVE-2015-0273) (Stas) . Fixed bug #68925 (Mitigation for CVE-2015-0235 ćąGHOST: glibc gethostbyname buffer overflow). (Stas) . Fixed Bug #67988 (htmlspecialchars() does not respect default_charset specified by ini_set) (Yasuo) . Added NULL byte protection to exec, system and passthru. (Yasuo) - Dba: . Fixed bug #68711 (useless comparisons). (bugreports at internot dot info) - Enchant: . Fixed bug #68552 (heap buffer overflow in enchant_broker_request_dict()). (Antony) - Fileinfo: . Fixed bug #68827 (Double free with disabled ZMM). (Joshua Rogers) . Fixed bug #67647 (Bundled libmagic 5.17 does not detect quicktime files correctly). (Anatol) . Fixed bug #68731 (finfo_buffer doesn't extract the correct mime with some gifs). (Anatol) - FPM: . Fixed bug #66479 (Wrong response to FCGI_GET_VALUES). (Frank Stolle) . Fixed bug #68571 (core dump when webserver close the socket). (redfoxli069 at gmail dot com, Laruence) - JSON: . Fixed bug #50224 (json_encode() does not always encode a float as a float) by adding JSON_PRESERVE_ZERO_FRACTION. (Juan Basso) - LIBXML: . Fixed bug #64938 (libxml_disable_entity_loader setting is shared between threads). (Martin Jansen) - Mysqli: . Fixed bug #68114 (linker error on some OS X machines with fixed width decimal support) (Keyur Govande) . Fixed bug #68657 (Reading 4 byte floats with Mysqli and libmysqlclient has rounding errors) (Keyur Govande) - Opcache: . Fixed bug with try blocks being removed when extended_info opcode generation is turned on. (Laruence) - PDO_mysql: . Fixed bug #68750 (PDOMysql with mysqlnd does not allow the usage of named pipes). (steffenb198 at aol dot com) - Phar: . Fixed bug #68901 (use after free). (bugreports at internot dot info) - Pgsql: . Fixed Bug #65199 (pg_copy_from() modifies input array variable) (Yasuo) - Session: . Fixed bug #68941 (mod_files.sh is a bash-script) (bugzilla at ii.nl, Yasuo) . Fixed Bug #66623 (no EINTR check on flock) (Yasuo) . Fixed bug #68063 (Empty session IDs do still start sessions) (Yasuo) - Sqlite3: . Fixed bug #68260 (SQLite3Result::fetchArray declares wrong required_num_args). (Julien) - Standard: . Fixed bug #65272 (flock() out parameter not set correctly in windows). (Daniel Lowrey) . Fixed bug #69033 (Request may get env. variables from previous requests if PHP works as FastCGI). (Anatol) - Streams: . Fixed bug which caused call after final close on streams filter. (Bob)
Revision 1.4 / (download) - annotate - [select for diffs], Fri Feb 20 01:17:49 2015 UTC (7 years, 11 months ago) by taca
Branch: MAIN
Changes since 1.3: +1 -2
lines
Diff to previous 1.3 (colored)
Update php56 to 5.6.6 (PHP 5.6.6). 19 Feb 2015, PHP 5.6.6 - Core: . Removed support for multi-line headers, as the are deprecated by RFC 7230. (Stas) . Fixed bug #67068 (getClosure returns somethings that's not a closure). (Danack at basereality dot com) . Fixed bug #68942 (Use after free vulnerability in unserialize() with DateTimeZone). (CVE-2015-0273) (Stas) . Fixed bug #68925 (Mitigation for CVE-2015-0235 GHOST: glibc gethostbyname buffer overflow). (Stas) . Fixed Bug #67988 (htmlspecialchars() does not respect default_charset specified by ini_set) (Yasuo) . Added NULL byte protection to exec, system and passthru. (Yasuo) - Dba: . Fixed bug #68711 (useless comparisons). (bugreports at internot dot info) - Enchant: . Fixed bug #68552 (heap buffer overflow in enchant_broker_request_dict()). (Antony) - Fileinfo: . Fixed bug #68827 (Double free with disabled ZMM). (Joshua Rogers) . Fixed bug #67647 (Bundled libmagic 5.17 does not detect quicktime files correctly). (Anatol) . Fixed bug #68731 (finfo_buffer doesn't extract the correct mime with some gifs). (Anatol) - FPM: . Fixed bug #66479 (Wrong response to FCGI_GET_VALUES). (Frank Stolle) . Fixed bug #68571 (core dump when webserver close the socket). (redfoxli069 at gmail dot com, Laruence) - JSON: . Fixed bug #50224 (json_encode() does not always encode a float as a float) by adding JSON_PRESERVE_ZERO_FRACTION. (Juan Basso) - LIBXML: . Fixed bug #64938 (libxml_disable_entity_loader setting is shared between threads). (Martin Jansen) - Mysqli: . Fixed bug #68114 (linker error on some OS X machines with fixed width decimal support) (Keyur Govande) . Fixed bug #68657 (Reading 4 byte floats with Mysqli and libmysqlclient has rounding errors) (Keyur Govande) - Opcache: . Fixed bug with try blocks being removed when extended_info opcode generation is turned on. (Laruence) - PDO_mysql: . Fixed bug #68750 (PDOMysql with mysqlnd does not allow the usage of named pipes). (steffenb198 at aol dot com) - Phar: . Fixed bug #68901 (use after free). (bugreports at internot dot info) - Pgsql: . Fixed Bug #65199 (pg_copy_from() modifies input array variable) (Yasuo) - Session: . Fixed bug #68941 (mod_files.sh is a bash-script) (bugzilla at ii.nl, Yasuo) . Fixed Bug #66623 (no EINTR check on flock) (Yasuo) . Fixed bug #68063 (Empty session IDs do still start sessions) (Yasuo) - Sqlite3: . Fixed bug #68260 (SQLite3Result::fetchArray declares wrong required_num_args). (Julien) - Standard: . Fixed bug #65272 (flock() out parameter not set correctly in windows). (Daniel Lowrey) . Fixed bug #69033 (Request may get env. variables from previous requests if PHP works as FastCGI). (Anatol) - Streams: . Fixed bug which caused call after final close on streams filter. (Bob)
Revision 1.1.2.1 / (download) - annotate - [select for diffs], Thu Feb 19 19:18:59 2015 UTC (7 years, 11 months ago) by tron
Branch: pkgsrc-2014Q4
Changes since 1.1: +1 -0
lines
Diff to previous 1.1 (colored)
Pullup ticket #4618 - requested by sevan lang/php56: security patch Revisions pulled up: - lang/php56/Makefile 1.3 - lang/php56/distinfo 1.5 - lang/php56/patches/patch-ext_date_php_date.c 1.1 - lang/php56/patches/patch-ext_date_tests_bug68942.phpt 1.1 - lang/php56/patches/patch-ext_date_tests_bug68942_2.phpt 1.1 --- Module Name: pkgsrc Committed By: sevan Date: Thu Feb 19 00:23:20 UTC 2015 Modified Files: pkgsrc/lang/php56: Makefile distinfo Added Files: pkgsrc/lang/php56/patches: patch-ext_date_php_date.c patch-ext_date_tests_bug68942.phpt patch-ext_date_tests_bug68942_2.phpt Log Message: Fix CVE-2015-0273 php: #68942 Use after free vulnerability in unserialize() with DateTimeZone Reviewed by wiz@
Revision 1.3 / (download) - annotate - [select for diffs], Thu Feb 19 00:23:20 2015 UTC (7 years, 11 months ago) by sevan
Branch: MAIN
Changes since 1.2: +2 -1
lines
Diff to previous 1.2 (colored)
Fix CVE-2015-0273 php: #68942 Use after free vulnerability in unserialize() with DateTimeZone Reviewed by wiz@
Revision 1.2 / (download) - annotate - [select for diffs], Mon Feb 2 10:54:19 2015 UTC (8 years ago) by sevan
Branch: MAIN
Changes since 1.1: +7 -1
lines
Diff to previous 1.1 (colored)
As per previous PHP release, apply the necessary flags to sqlite so that it builds correctly on Darwin prior to v9. ok wiz@
Revision 1.1 / (download) - annotate - [select for diffs], Mon Nov 24 15:37:08 2014 UTC (8 years, 2 months ago) by taca
Branch: MAIN
CVS Tags: pkgsrc-2014Q4-base
Branch point for: pkgsrc-2014Q4
Add php56, PHP version 5.6.3. THe main features of PHP 5.6: * Constant scalar expressions. * Variadic functions and argument unpacking using the ... operator. * Exponentiation using the ** operator. * Function and constant importing with the use keyword. * phpdbg as an interactive integrated debugger SAPI. * php://input is now reusable, and $HTTP_RAW_POST_DATA is deprecated. * GMP objects now support operator overloading. * File uploads larger than 2 gigabytes in size are now accepted. Please refer for difference from oldre release:http://php.net/migration56.