Path to this page:
Subject: CVS commit: pkgsrc/www/typo3_47
From: Takahiro Kambe
Date: 2013-12-10 16:20:03
Message id: 20131210152003.9869E96@cvs.netbsd.org
Log Message:
Update typo3_47 package to 4.7.17 (TYPO3 4.7.17).
- Fix multiple vulnerabilities in TYPO3 CMS:
http://typo3.org/teams/security/security-bulletins/typo3-core/typo3-core-sa-2013-004/
- Enable PHP_VERSIONS_ACCEPTED which was accidently commented out by previous
commit.
2013-12-10 9e378dd [RELEASE] Release of TYPO3 4.7.17 (TYPO3 \
Release Team)
2013-12-10 efa9e0b #45043 [SECURITY] Prevent editor controlled hmac \
content (Franz G. Jahn)
2013-12-10 d207548 #42772 [SECURITY] XSS in colorpicker wizard (Anja \
Leichsenring)
2013-12-10 92712d6 #31206 [SECURITY] XSS in header link of all \
content elements (Anja Leichsenring)
2013-12-10 573f720 #20811 [SECURITY] XSS vulnerability in extension \
manager (Marcus Krause)
2013-12-10 b7eac59 #41714 [SECURITY] Information Disclosure in \
Wizards (Anja Leichsenring)
2013-12-10 319a06c #54099 [SECURITY] Fix open redirection in openid \
extension (Anja Leichsenring)
2013-12-10 834afa5 #48187 [SECURITY] feuser_adminLib.inc allows to \
set arbitrary fields (Steffen Ritter)
2013-12-10 aa08f14 #36768 [SECURITY] XSS in be_layout wizard (Anja \
Leichsenring)
2013-12-10 f3b5a6a #54074 [SECURITY] Remove possible XSS from \
ActionController Error output (Anja Leichsenring)
2013-12-10 0bc4fc4 #54073 [SECURITY] Unsafe unserialize of GET \
parameter in Add-Wizard (Marcus Krause)
2013-12-02 c400e94 #54124 [BUGFIX] ClientUtility does not detect \
Internet Explorer 11 (Stefan Neufeind)
2013-12-02 124a913 #54120 Revert "[BUGFIX] Object passed to \
date()" (Markus Klein)
2013-12-01 3f2e971 Revert "[BUGFIX] Distinguish \
unassigend columns and colPos 0" (Steffen Ritter)
2013-11-29 a7dbbbf #42651 [BUGFIX] ext:adodb Restrict connection \
wizard to admins (Christian Kuhn)
2013-11-26 542bd7d #25157,#45550 [BUGFIX] Distinguish unassigend columns and \
colPos 0 (Philipp Gampe)
Files: