Subject: CVS commit: [pkgsrc-2021Q2] pkgsrc/lang
From: Benny Siegert
Date: 2021-07-04 21:16:05
Message id: 20210704191606.08540FA90@cvs.NetBSD.org

Log Message:
Pullup ticket #6478 - requested by taca
lang/php74: security fix

Revisions pulled up:
- lang/php/phpversion.mk                                        1.331
- lang/php74/distinfo                                           1.25

---
   Module Name:	pkgsrc
   Committed By:	taca
   Date:		Fri Jul  2 17:28:28 UTC 2021

   Modified Files:
   	pkgsrc/lang/php: phpversion.mk
   	pkgsrc/lang/php74: distinfo

   Log Message:
   lang/php74: update to 7.4.21

   01 Jul 2021, PHP 7.4.21

   - Core:
     . Fixed bug #81068 (Double free in realpath_cache_clean()). (Dimitry Andric)
     . Fixed bug #76359 (open_basedir bypass through adding ".."). (cmb)
     . Fixed bug #81090 (Typed property performance degradation with .= operator).
       (Nikita)
     . Fixed bug #81070 (Integer underflow in memory limit comparison).
       (Peter van Dommelen)
     . Fixed bug #81122 (SSRF bypass in FILTER_VALIDATE_URL).
       (CVE-2021-21705) (cmb)

   - Bzip2:
     . Fixed bug #81092 (fflush before stream_filter_remove corrupts stream).
       (cmb)

   - OpenSSL:
     . Fixed bug #76694 (native Windows cert verification uses CN as sever name).
       (cmb)

   - PDO_Firebird:
     . Fixed bug #76448 (Stack buffer overflow in firebird_info_cb).
       (CVE-2021-21704) (cmb)
     . Fixed bug #76449 (SIGSEGV in firebird_handle_doer).
       (CVE-2021-21704) (cmb)
     . Fixed bug #76450 (SIGSEGV in firebird_stmt_execute).
       (CVE-2021-21704) (cmb)
     . Fixed bug #76452 (Crash while parsing blob data in firebird_fetch_blob).
       (CVE-2021-21704) (cmb)

   - Standard:
     . Fixed bug #81048 (phpinfo(INFO_VARIABLES) "Array to string \ 
conversion").
       (cmb)

Files:
RevisionActionfile
1.24.2.1modifypkgsrc/lang/php74/distinfo