Path to this page:
Subject: CVS commit: pkgsrc/www/typo3_60
From: Takahiro Kambe
Date: 2013-12-10 16:21:30
Message id: 20131210152130.20FF996@cvs.netbsd.org
Log Message:
Update typo3_60 package to 6.0.12 (TYPO3 6.0.12).
- Fix multiple vulnerabilities in TYPO3 CMS:
http://typo3.org/teams/security/security-bulletins/typo3-core/typo3-core-sa-2013-004/
2013-12-10 55ea17b [RELEASE] Release of TYPO3 6.0.12 (TYPO3 \
Release Team)
2013-12-10 c703d1d #31206 [SECURITY] XSS in header link of all \
content elements (Anja Leichsenring)
2013-12-10 0f1e28b #42772 [SECURITY] XSS in colorpicker wizard \
(Marcus Krause)
2013-12-10 1cbe889 #45043 [SECURITY] Prevent editor controlled hmac \
content (Franz G. Jahn)
2013-12-10 79f6850 #48691 [SECURITY] XSS in backend user \
adminstration (Marc Bastian Heinrichs)
2013-12-10 b22cbce #41714 [SECURITY] Information Disclosure in \
Wizards (Helmut Hummel)
2013-12-10 e4134ae #54099 [SECURITY] Fix open redirection in openid \
extension (Helmut Hummel)
2013-12-10 2fb0277 #48187 [SECURITY] feuser_adminLib.inc allows to \
set arbitrary fields (Anja Leichsenring)
2013-12-10 bd6095f #36768 [SECURITY] XSS in be_layout wizard (Anja \
Leichsenring)
2013-12-10 872cf3d #47086 [SECURITY] XSS in beuser VH (Anja Leichsenring)
2013-12-10 cb55c53 #54074 [SECURITY] Remove possible XSS from \
ActionController Error output (Anja Leichsenring)
2013-12-10 578cc80 #54073 [SECURITY] Unsafe unserialize of GET \
parameter in Add-Wizard (Steffen Ritter)
2013-12-02 9757d0c #54124 [BUGFIX] ClientUtility does not detect \
Internet Explorer 11 (Stefan Neufeind)
2013-12-02 5bf7430 #54117 [BUGFIX] Add missing namespacing for \
calling GeneralUtility (Stefan Neufeind)
2013-11-29 30e1f41 #42651 [BUGFIX] ext:adodb Restrict connection \
wizard to admins (Christian Kuhn)
Files: