Subject: CVS commit: [pkgsrc-2008Q4] pkgsrc/lang/php5
From: Matthias Scheler
Date: 2009-03-15 20:21:22
Message id: 20090315192122.87A38175D0@cvs.netbsd.org

Log Message:
Pullup ticket #2721 - requested by adrianp
php5: security update

Revisions pulled up:
- lang/php5/MESSAGE.suhosin			1.1 via patch
- lang/php5/Makefile				1.71 via patch
- lang/php5/Makefile.common			1.35
- lang/php5/Makefile.php			1.33-1.34
- lang/php5/PLIST				1.21
- lang/php5/distinfo				1.61-1.62
- lang/php5/patches/patch-an			patch
- lang/php5/patches/patch-ar			patch
- lang/php5/patches/patch-as			delete
---
Module Name:	pkgsrc
Committed By:	adrianp
Date:		Mon Mar  2 22:52:17 UTC 2009

Modified Files:
	pkgsrc/lang/php5: Makefile Makefile.common Makefile.php PLIST distinfo
Removed Files:
	pkgsrc/lang/php5/patches: patch-as

Log Message:
The PHP development team would like to announce the immediate availability of \ 
PHP 5.2.9. This release focuses on improving the stability of the PHP 5.2.x \ 
branch with over 50 bug fixes, several of which are security related. All users \ 
of PHP are encouraged to upgrade to this release.

Security Enhancements and Fixes in PHP 5.2.9:

    * Fixed security issue in imagerotate(), background colour isn't validated \ 
correctly with a non truecolour image. Reported by Hamid Ebadi, APA Laboratory \ 
(Fixes CVE-2008-5498). (Scott)
    * Fixed a crash on extract in zip when files or directories entry names \ 
contain a relative path. (Pierre)
    * Fixed explode() behavior with empty string to respect negative limit. (Shire)
    * Fixed a segfault when malformed string is passed to json_decode(). (Scott)

Key enhancements in PHP 5.2.9 include:

    * Added optional sorting type flag parameter to array_unique(). Default is \ 
SORT_REGULAR. (Andrei)
    * Fixed bug #45996 (libxml2 2.7 causes breakage with character data in \ 
xml_parse()). (Rob)
    * A number of fixes in the mbstring extension (Moriyoshi)
    * Fixed bug #44336 (Improve pcre UTF-8 string matching performance). (frode \ 
at coretrek dot com, Nuno)
    * Fixed bug #46699 (xml_parse crash when parser is namespace aware). (Rob)
    * Fixed bug #46748 (Segfault when an SSL error has more than one error). (Scott)
    * Fixed bug #46889 (Memory leak in strtotime()). (Derick)
    * Fixed bug #47049 (SoapClient::__soapCall causes a segmentation fault). (Dmitry)
    * Fixed bug #47165 (Possible memory corruption when passing return value by \ 
reference). (Dmitry)
    * Fixed bug #47282 (FILTER_VALIDATE_EMAIL is marking valid email addresses \ 
as invalid). (Ilia)
    * Fixed bug #47422 (modulus operator returns incorrect results on 64 bit \ 
linux). (Matt)
    * Over 50 bug fixes.
---
Module Name:	pkgsrc
Committed By:	adrianp
Date:		Thu Mar  5 23:22:24 UTC 2009

Modified Files:
	pkgsrc/lang/php5: Makefile.php distinfo

Log Message:
Add back suhosin patch as a new one for 5.2.9 is out

Files:
RevisionActionfile
1.69.2.1modifypkgsrc/lang/php5/Makefile
1.33.2.1modifypkgsrc/lang/php5/Makefile.common
1.29.6.1modifypkgsrc/lang/php5/Makefile.php
1.19.2.1modifypkgsrc/lang/php5/PLIST
1.56.2.3modifypkgsrc/lang/php5/distinfo
1.6.2.1modifypkgsrc/lang/php5/patches/patch-an
1.1.2.2addpkgsrc/lang/php5/MESSAGE.suhosin
1.4.12.1addpkgsrc/lang/php5/patches/patch-ar
1.3.20.1removepkgsrc/lang/php5/patches/patch-as