Subject: CVS commit: pkgsrc/security/php-suhosin
From: Takahiro Kambe
Date: 2012-01-20 04:23:34
Message id: 20120120032334.C6098175DD@cvs.netbsd.org

Log Message:
Update php-suhosin package to 0.9.33 to fix security problem.

                         SektionEins GmbH
                        www.sektioneins.de

                     -= Security  Advisory =-

     Advisory: Suhosin PHP Extension Transparent Cookie Encryption Stack
Buffer Overflow
 Release Date: 2012/01/19
Last Modified: 2012/01/19
       Author: Stefan Esser [stefan.esser[at]sektioneins.de]

  Application: Suhosin Extension <= 0.9.32.1
     Severity: A possible stack buffer overflow in Suhosin extension's
               transparent cookie encryption that can only be triggered
               in an uncommon and weakened Suhosin configuration can lead
               to arbitrary remote code execution, if the FORTIFY_SOURCE
               compile option was not used when Suhosin was compiled.
         Risk: Medium
Vendor Status: Suhosin Extension 0.9.33 was released which fixes this
vulnerability
    Reference: http://www.suhosin.org/
               https://github.com/stefanesser/suhosin

Files:
RevisionActionfile
1.5modifypkgsrc/security/php-suhosin/Makefile
1.4modifypkgsrc/security/php-suhosin/distinfo