Subject: CVS commit: pkgsrc
From: Quentin Garnier
Date: 2006-04-14 15:47:30
Message id: 20060414134730.2C1982DA27@cvs.netbsd.org

Log Message:
PHP4/5 security changes...  They're not critical issues;  secunia classes
them between "not critical" and "less critical".

Fix CVE-2006-0996, CVE-2006-1494, CVE-2006-1608, CVE-2006-1490.

See:
    http://secunia.com/advisories/19383/
    http://secunia.com/advisories/19599/

Patches were extracted from CVS.  I had to translate the one for
CVE-2006-1608 on php4 because it has not made its way to the php4.4 branch
(I don't know why;  I can confirm it fixes the issue).

While here, add PATCHDIR to the list of variables php5's Makefile.php
defines.  That way, ap-php gets patched too...

Files:
RevisionActionfile
1.29modifypkgsrc/lang/php5/Makefile
1.18modifypkgsrc/lang/php5/Makefile.php
1.15modifypkgsrc/lang/php5/distinfo
1.9modifypkgsrc/www/ap-php/Makefile
1.63modifypkgsrc/www/php4/Makefile
1.52modifypkgsrc/www/php4/distinfo