Subject: CVS commit: [pkgsrc-2014Q1] pkgsrc/www/typo3_60
From: Matthias Scheler
Date: 2014-05-28 21:15:23
Message id: 20140528191523.DB67896@cvs.netbsd.org

Log Message:
Pullup ticket #4420 - requested by taca
www/typo3_60: security update

Revisions pulled up:
- www/typo3_60/Makefile                                         1.8
- www/typo3_60/PLIST                                            1.7
- www/typo3_60/distinfo                                         1.8

---
   Module Name:	pkgsrc
   Committed By:	taca
   Date:		Tue May 27 13:50:48 UTC 2014

   Modified Files:
   	pkgsrc/www/typo3_60: Makefile PLIST distinfo

   Log Message:
   Update typo3_60 to 6.0.14 (TYPO3 6.0.14), contains several security fixes.

   2014-05-22  d1d252f                  [RELEASE] Release of TYPO3 6.0.14 (TYPO3 \ 
Release Team)
   2014-05-22  37273fb  #30377          [SECURITY] Add trusted HTTP_HOST \ 
configuration (Helmut Hummel)
   2014-05-22  edd27ad  #54111,#54113   [SECURITY] XSS in (old) extension \ 
manager information function (Nicole Cordes)
   2014-05-22  00f00b1  #48695          [SECURITY] XSS in new content element \ 
wizard (Marcus Krause)
   2014-05-22  6b7f3a8  #54109          [SECURITY] XSS in template tools on root \ 
page (Marc Bastian Heinrichs)
   2014-05-22  5935348  #57576          [SECURITY] XSS in Backend Layout Wizard \ 
(Helmut Hummel)
   2014-05-22  dda1739  #48693          [SECURITY] Encode URL for use in \ 
JavaScript (Jigal van Hemert)
   2014-05-22  5e00a13  #56458          [SECURITY] Fix insecure unserialize in \ 
colorpicker (Helmut Hummel)
   2014-05-22  0f29e1f  #54526          [SECURITY] Remove charts.swf to get rid \ 
of XSS vulnerability (Helmut Hummel)
   2014-05-21  e50f6a6  #54917          [BUGFIX] Indexer tries to insert NULL \ 
into DB (Markus Klein)
   2014-05-15  53c830f  #53079          [BUGFIX] FlashMessageService not \ 
available in TYPO3 6.0 (Oliver Hader)
   2014-05-14  459c34d  #58529          [BUGFIX] DependencyUtility does count() \ 
on an integer (Markus Klein)
   2014-04-25  bd704d5  #58180          [BUGFIX] Database query error for \ 
non-workspaces tables (Oliver Hader)
   2014-04-16  d1fc88d                  [TASK] Set TYPO3 version to 6.0.14-dev \ 
(TYPO3 Release Team)

   2014-04-16  be80735                  [RELEASE] Release of TYPO3 6.0.13 (TYPO3 \ 
Release Team)
   2014-04-15  d9e6546  #51768          [TASK] Updates prototype and \ 
scriptaculous, fixing IE9+ issues (Ernesto Baschny)
   2014-04-15  48f974e  #56580          [BUGFIX] SoftReferenceIndex typolink \ 
lacks support for title attributes (Marc Bastian Heinrichs)
   2014-04-15  9d1c880  #56991          [BUGFIX] Fix refindex for FlexForm \ 
fields type group file_reference (Marc Bastian Heinrichs)
   2014-04-15  75f6b1b  #56353,#56352   [BUGFIX] Fields of type group file are \ 
not properly indexed (Marc Bastian Heinrichs)
   2014-04-15  4e64a39  #57010          [BUGFIX] Add SoftIndex parser typolink \ 
to link in sys_file_reference (Marc Bastian Heinrichs)
   2014-04-04  72be9f3  #57656          [TASK] Integrate default README.txt \ 
(Oliver Hader)
   2014-04-04  de4e047  #57603          [SECURITY] Prevent XSS in scheduler form \ 
(Nicole Cordes)
   2014-03-31  03646f1  #57296          [BUGFIX] Test typeof TBE_EDITOR for \ 
object not function (Alexander Opitz)
   2014-03-24  87d3d40  #57238          [BUGFIX] Typo in Extbase localization \ 
file (Xavier Perseguers)
   2014-03-13  be10ede  #56855          [BUGFIX] Extbase tries to overlay \ 
pages_language_overlay records (Stanislas Rolland)
   2014-03-08  15b15c0  #43885          [BUGFIX] Temporary DB tree mount notice \ 
missing in ElementBrowser (Lorenz Ulrich)
   2014-03-05  99025c1  #46185          [BUGFIX] IdentityProperties were not set \ 
(Stefan Froemken)
   2014-03-03  69c103b  #56262          [BUGFIX] Double escape of title in \ 
indexed search (Markus Klein)
   2014-02-28  cf83948  #56378          [BUGFIX] Do not log with severity \ 
1320177676 (Christian Weiske)
   2014-02-28  432a7bd  #56421          [BUGFIX] @return for \ 
TYPO3\CMS\Sv\AuthenticationService::authUser (Christian Weiske)
   2014-02-28  1474e2c  #41413          [BUGFIX] URL-encoded title in link \ 
wizard (Helmut Hummel)
   2014-02-27  ab4ef14  #55966          [BUGFIX] Revert "[TASK] Use a 401 \ 
header if login is not successful" (Markus Klein)
   2014-02-25  95cb16e  #56184          [BUGFIX] Paginator in TER list not using \ 
ajax (Jigal van Hemert)
   2014-02-25  8c2179f  #23984          [BUGFIX] felogin reset password links \ 
not clickable (Jigal van Hemert)
   2014-02-21  9ebf4bb  #54724          [BUGFIX] Use count on storage after \ 
initialization of LazyObjectStorage (Marc Bastian Heinrichs)
   2014-02-21  4b44141  #49499          [BUGFIX] Fix possible language handling \ 
issue (Markus Klein)
   2014-02-20  568b9bf  #56135          [BUGFIX] DatabaseConnection::listQuery \ 
wrong usage of strpos() (Markus Klein)
   2014-02-19  40d97d5  #56067          [BUGFIX] Various static calls to \ 
non-static functions (Markus Klein)
   2014-02-18  e428692  #54304          [BUGFIX] Missing encoding in flexforms \ 
IRRE javascript (Alexey Gafiulov)
   2014-02-17  a335bcf  #52527          [BUGFIX] addToAllTCAtypes() doesn't add \ 
new field (Tomita Militaru)
   2014-02-17  88fd2df  #55998          [BUGFIX] Usage of undefined variables in \ 
ShortcutToolbarItem (Tim Lochmueller)
   2014-02-11  e2ebdfd  #53028          [BUGFIX] cache_clearAtMidnight conflicts \ 
with content start/endtime (Dmitry Dulepov)
   2014-02-10  e73b549                  [TASK] Execute lint in parallel (Helmut \ 
Hummel)
   2014-02-09  d2881f5  #53768,#28745   [BUGFIX] Allow to render the same TS \ 
object twice (Markus Klein)
   2014-02-09  228fbc5  #55821          [BUGFIX] Tests: Remove unstable \ 
GeneralUtilityTest::getUrl* (Christian Kuhn)
   2014-02-09  d9bf811  #18797          [BUGFIX] "New page" wizard \ 
discloses existence of pages outside DB mount (Nicole Cordes)
   2014-02-09  2a233ef  #53564          [TASK] Add possibility creating \ 
accessible mock for abstract classes (Marc Bastian Heinrichs)
   2014-02-08  33a058b  #16491          [BUGFIX] CSV-Download not working in IE \ 
and HTTPS backend (Wouter Wolters)
   2014-02-06  0fe2509  #55713          [BUGFIX] Missing namespace in \ 
ContentObjectRenderer (Markus Klein)
   2014-02-05  0004322  #54112          [BUGFIX] Set missing markers to empty \ 
string (Bernhard Kraft)
   2014-02-03  8623b17  #54371          [BUGFIX] Add stdWrap on value property \ 
of TEXT (Markus Klein)
   2014-02-03  e5a844d  #52048          [BUGFIX] Locker throws exception if \ 
semaphore can not be acquired (Markus Klein)
   2014-01-30  dc271e4  #55475          [BUGFIX] Regression in DataHandler \ 
(Wouter Wolters)
   2014-01-30  460da13  #41450          [BUGFIX] Handle empty tags in language \ 
pack index files (Alexander Stehlik)
   2014-01-29  3a84755  #55407          [BUGFIX] ClickMenu does not show \ 
destination-foldername (Stefan Neufeind)
   2014-01-28  e5df843  #55350          [BUGFIX] Invalid constant in the domain \ 
redirect function (Tim Lochmueller)
   2014-01-27  3b2cb07  #55366,#55377   [TASK] Change phpunit repository url for \ 
travis (Philipp Gampe)
   2014-01-24  72db639  #55093          [BUGFIX] Simulate time in TYPO3 admin \ 
panel broken (Peter Niederlag)
   2014-01-23  68057cf  #54849          [BUGFIX] CLI context cannot write to \ 
backend log (Oliver Hader)
   2014-01-16  c4703db  #53712          [BUGFIX] Create valid file reference \ 
index data (Alexander Stehlik)
   2014-01-16  42cd027  #50266          [BUGFIX] File browser fails on \ 
inexistent expandFolder (Mario Rimann)
   2014-01-15  f76c7ea  #34631          [BUGFIX] Show correct record title for \ 
be_groups and be_users (Markus Klein)
   2014-01-14  f3d324d  #53826          [BUGFIX] Folder tree in popup throws JS \ 
error (Aske Ertmann)
   2014-01-14  df52d4a  #53352          [BUGFIX] Add defaultTypoScript to \ 
hierachyInfo (Peter Niederlag)
   2014-01-09  d0c4276  #53862          [BUGFIX] isValidUrl() idna converts \ 
whole URI (Michiel Roos)
   2014-01-09  9f330b7  #52554          [TASK] Change list view delete icon if \ 
record is deleted in WS (Sascha Egerer)
   2014-01-09  ffc3f2b  #24877,#6708    [BUGFIX] Only create one keypair in \ 
rsaauth (Tom Ruether)
   2014-01-09  583a51b  #38767          [BUGFIX] use search word(s) for ordering \ 
search results (again) (Ralf Hettinger)
   2014-01-08  74be2df  #38766          [BUGFIX] l10n_mode for "pages" \ 
table and group fields. (Johannes Feustel)
   2014-01-08  d1e2110  #53727          [BUGFIX] Form Wizard saving destroys \ 
Radio Buttons (Markus Klein)
   2014-01-08  96ff927  #52133          [BUGFIX] Display relations' titles when \ 
TCA label field is type inline (Claus Due)
   2014-01-04  2c40d1b  #53662          [BUGFIX] Allow NULL values in INSERT \ 
queries (Alexander Stehlik)
   2014-01-04  dd187dd  #53682          [TASK] Optimize speed for instantiating \ 
class with arguments (Helmut Hummel)
   2013-12-23  c2211f5  #54115          [BUGFIX] ClassAliasMap, Tx_ VH namespace \ 
and closing tag throws Exception (Claus Due)
   2013-12-18  6be4de6  #54369          [TASK] Fix travis builds (Markus Klein)
   2013-12-18  e6bfc6e  #51752          [BUGFIX] ArrayIterator::seek() warning \ 
in ElementBrowser (Markus Klein)
   2013-12-18  1294fe7  #52059          [BUGFIX] felogin: Unknown modifier in \ 
regular expression (Wouter Wolters)
   2013-12-18  4f8c872  #47648          [BUGFIX] Remove \ 
ElementBrowser::isReadOnlyFolder (Markus Klein)
   2013-12-13  78b00f3  #54027          [BUGFIX] No double htmlspecialchars for \ 
filemount select (Alexander Stehlik)
   2013-12-12  28ca149  #53818          [BUGFIX] Cleanly unset cookies on login \ 
in cookie-check (Stefan Neufeind)

Files:
RevisionActionfile
1.7.4.1modifypkgsrc/www/typo3_60/Makefile
1.6.4.1modifypkgsrc/www/typo3_60/PLIST
1.7.4.1modifypkgsrc/www/typo3_60/distinfo