Path to this page:
Subject: CVS commit: pkgsrc/www/php-sugarcrm
From: Takahiro Kambe
Date: 2014-07-02 11:13:02
Message id: 20140702091302.DA4A096@cvs.netbsd.org
Log Message:
Update php-sugarcrm to 6.5.17, security release.
Quote from http://www.providentcrm.com/news/sugarcrm-6-5-17-patch-list/.
1. Module scanner now blocks two additional functions:
simplexml_load_file and simplexml_load_string
2. JS Security Fix in Emails -- changing AJAX call from GET to POST.
3. XML Handling -- Additional error handling and libxml_disable_entity_loader
is now set to true.
4. Users module -- Additional checking on un-authorised access to other users
profile, plus Bugfix for password field.
Files: