Subject: CVS commit: pkgsrc/mail/sympa
From: Manuel Bouyer
Date: 2008-12-20 20:02:12
Message id: 20081220190212.DF00C175D0@cvs.netbsd.org

Log Message:
Update sympa to 5.4.4. Bug fixes (including SQL injestion and privilege
escalation vulnerabilities) and updated translations:
    * Sympa was not fully compliant to the RFC 2616, leading for example
      to possible unwanted list deletion by administrators using prefetching
      tools. This was fixed by replacing all the threatening GET requests
      by POST requests;
    * Use of sprint() function for creating SQL queries lead to possible
      SQL injection through cookie manipulation;
    * The use of files in /tmp lead to vulnerabilities.

Files:
RevisionActionfile
1.38modifypkgsrc/mail/sympa/Makefile
1.7modifypkgsrc/mail/sympa/PLIST
1.11modifypkgsrc/mail/sympa/distinfo