Subject: CVS commit: [pkgsrc-2019Q3] pkgsrc/lang
From: Benny Siegert
Date: 2019-10-25 13:59:45
Message id: 20191025115945.2E4D2FA89@cvs.NetBSD.org

Log Message:
Pullup ticket #6076 - requested by taca
lang/php73: security fix

Revisions pulled up:
- lang/php/phpversion.mk                                        1.270,1.272
- lang/php73/Makefile                                           1.6
- lang/php73/Makefile.php                                       1.2
- lang/php73/distinfo                                           1.12-1.13

---
   Module Name:    pkgsrc
   Committed By:   taca
   Date:           Wed Oct  2 14:08:05 UTC 2019

   Modified Files:
           pkgsrc/lang/php: phpversion.mk
           pkgsrc/lang/php73: Makefile Makefile.php distinfo

   Log Message:
   lang/php73: update to 7.3.10

   Update lang/php73 to 7.3.10.

   pkgsrc changes

   * Clean two pkglint's warnings.

   26 Sep 2019, PHP 7.3.10

   - Core:
     . Fixed bug #78220 (Can't access OneDrive folder). (cmb, ab)
     . Fixed bug #77922 (Double release of doc comment on inherited shadow
       property). (Nikita)
     . Fixed bug #78441 (Parse error due to heredoc identifier followed by digit).
       (cmb)
     . Fixed bug #77812 (Interactive mode does not support PHP 7.3-style heredoc).
       (cmb, Nikita)

   - FastCGI:
     . Fixed bug #78469 (FastCGI on_accept hook is not called when using named
       pipes on Windows). (Sergei Turchanov)

   - FPM:
     . Fixed bug #78334 (fpm log prefix message includes wrong stdout/stderr
       notation). (Tsuyoshi Sadakata)

   - Intl:
     . Ensure IDNA2003 rules are used with idn_to_ascii() and idn_to_utf8()
       when requested. (Sara)

   - MBString:
     . Fixed bug #78559 (Heap buffer overflow in mb_eregi). (cmb)

   - MySQLnd:
     . Fixed connect_attr issues and added the _server_host connection attribute.
       (Qianqian Bu)

   - ODBC:
     . Fixed bug #78473 (odbc_close() closes arbitrary resources). (cmb)

   - PDO_MySQL:
     . Fixed bug #41997 (SP call yields additional empty result set). (cmb)

   - sodium:
     . Fixed bug #78510 (Partially uninitialized buffer returned by
       sodium_crypto_generichash_init()). (Frank Denis, cmb)

---
   Module Name:    pkgsrc
   Committed By:   taca
   Date:           Fri Oct 25 02:57:04 UTC 2019

   Modified Files:
           pkgsrc/lang/php: phpversion.mk
           pkgsrc/lang/php73: distinfo

   Log Message:
   lang/php73: update to 7.3.11

   Update php73 to 7.3.11.

   24 Oct 2019, PHP 7.3.11

   - Core:
     . Fixed bug #78535 (auto_detect_line_endings value not parsed as bool).
       (bugreportuser)
     . Fixed bug #78620 (Out of memory error). (cmb, Nikita)

   - Exif :
     . Fixed bug #78442 ('Illegal component' on exif_read_data since PHP7)
           (Kalle)

   - FPM:
     . Fixed bug #78599 (env_path_info underflow in fpm_main.c can lead to RCE).
       (CVE-2019-11043) (Jakub Zelenka)
     . Fixed bug #78413 (request_terminate_timeout does not take effect after
       fastcgi_finish_request). (Sergei Turchanov)

   - MBString:
     . Fixed bug #78633 (Heap buffer overflow (read) in mb_eregi). (cmb)
     . Fixed bug #78579 (mb_decode_numericentity: args number inconsistency).
       (cmb)
     . Fixed bug #78609 (mb_check_encoding() no longer supports stringable
       objects). (cmb)

   - MySQLi:
     . Fixed bug #76809 (SSL settings aren't respected when persistent connections
       are used). (fabiomsouto)

   - Mysqlnd:
     . Fixed bug #78525 (Memory leak in pdo when reusing native prepared
       statements). (Nikita)

   - PCRE:
     . Fixed bug #78272 (calling preg_match() before pcntl_fork() will freeze
       child process). (Nikita)

   - PDO_MySQL:
     . Fixed bug #78623 (Regression caused by "SP call yields additional empty
       result set"). (cmb)

   - Session:
     . Fixed bug #78624 (session_gc return value for user defined session
       handlers). (bshaffer)

   - Standard:
     . Fixed bug #76342 (file_get_contents waits twice specified timeout).
       (Thomas Calvet)
     . Fixed bug #78612 (strtr leaks memory when integer keys are used and the
       subject string shorter). (Nikita)
     . Fixed bug #76859 (stream_get_line skips data if used with data-generating
       filter). (kkopachev)

   - Zip:
     . Fixed bug #78641 (addGlob can modify given remove_path value). (cmb)

Files:
RevisionActionfile
1.5.2.1modifypkgsrc/lang/php73/Makefile
1.1.8.1modifypkgsrc/lang/php73/Makefile.php
1.11.2.1modifypkgsrc/lang/php73/distinfo