Path to this page:
Subject: CVS commit: [pkgsrc-2008Q2] pkgsrc/www/drupal
From: Tyler R. Retzlaff
Date: 2008-08-01 13:18:45
Message id: 20080801111845.B30BA175D0@cvs.netbsd.org
Log Message:
pullup ticket #2469 - requested by adrianp
drupal: update for security fix
revisions pulled up:
pkgsrc/www/drupal/Makefile 1.31
pkgsrc/www/drupal/distinfo 1.22
Module Name: pkgsrc
Committed By: adrianp
Date: Thu Jul 31 19:09:53 UTC 2008
Modified Files:
pkgsrc/www/drupal: Makefile distinfo
Log Message:
This release fixes a security vulnerability. Sites are urged to upgrade \
immediately after reading the security announcement:
* SA-2008-046 - Drupal core - Session fixation
In addition to this security vulnerability, the following bugs have been \
fixed in the 5.9 release:
* #281042 by schuyler1d. Render blocks before CSS and JS header generation.
* #232433 by Damien Tournoud. Use non-localized date for RSS.
* #281494 by beeradb. Code style.
* #252580 by Robert Douglass, Gerhard Killesreiter, flobruit: avoid \
division by zero, when all search weights are set to 0.
* #252921 by David_Rothstein and agentrickard: remove unused join, which \
caused column type compatibility problems with postgresql; improves postgresql \
compatibility.
* #128846 by takashi, chx, bdragon, wedge, salvis, Shiny: rewritten \
queries on PostreSQL need to have matching DISTINCT ON and ORDER BY expressions
* #280934. Make sure session is always regenerated.
Files: