Subject: CVS commit: pkgsrc/lang
From: Takahiro Kambe
Date: 2024-06-07 15:54:25
Message id: 20240607135425.ECAD5FC74@cvs.NetBSD.org

Log Message:
lang/php81: update to 8.1.29

pkgsrc change:

Instead of patch configure, patch m4 files and use autoconf to generate
configure.

PHP 8.1.29 (2024-06-06)

- CGI:
  . Fixed bug GHSA-3qgc-jrrr-25jv (Bypass of CVE-2012-1823, Argument Injection
    in PHP-CGI). (CVE-2024-4577) (nielsdos)

- Filter:
  . Fixed bug GHSA-w8qr-v226-r27w (Filter bypass in filter_var FILTER_VALIDATE_URL).
    (CVE-2024-5458) (nielsdos)

- OpenSSL:
  . The openssl_private_decrypt function in PHP, when using PKCS1 padding
    (OPENSSL_PKCS1_PADDING, which is the default), is vulnerable to the Marvin Attack
    unless it is used with an OpenSSL version that includes the changes from \ 
this pull
    request: https://github.com/openssl/openssl/pull/13817 \ 
(rsa_pkcs1_implicit_rejection).
    These changes are part of OpenSSL 3.2 and have also been backported to stable
    versions of various Linux distributions, as well as to the PHP builds \ 
provided for
    Windows since the previous release. All distributors and builders should \ 
ensure that
    this version is used to prevent PHP from being vulnerable. (CVE-2024-2408)

- Standard:
  . Fixed bug GHSA-9fcc-425m-g385 (Bypass of CVE-2024-1874).
    (CVE-2024-5585) (nielsdos)

Files:
RevisionActionfile
1.22modifypkgsrc/lang/php81/Makefile
1.33modifypkgsrc/lang/php81/distinfo
1.1addpkgsrc/lang/php81/patches/patch-build_php.m4
1.1addpkgsrc/lang/php81/patches/patch-sapi_apache2handler_config.m4
1.2removepkgsrc/lang/php81/patches/patch-configure