Path to this page:
Subject: CVS commit: pkgsrc/www/typo3_45
From: Takahiro Kambe
Date: 2013-12-10 16:18:33
Message id: 20131210151833.B019396@cvs.netbsd.org
Log Message:
Update typo3_45 package to 4.5.32 (TYPO3 4.5.32).
- Fix multiple vulnerabilities in TYPO3 CMS:
http://typo3.org/teams/security/security-bulletins/typo3-core/typo3-core-sa-2013-004/
- Enable PHP_VERSIONS_ACCEPTED which was accidently commented out by previous
commit.
2013-12-10 1956962 [RELEASE] Release of TYPO3 4.5.32 (TYPO3 \
Release Team)
2013-12-10 60576d1 #31206 [SECURITY] XSS in header link of all \
content elements (Anja Leichsenring)
2013-12-10 77dc1c4 #42772 [SECURITY] XSS in colorpicker wizard (Anja \
Leichsenring)
2013-12-10 52d3bff #45043 [SECURITY] Prevent editor controlled hmac \
content (Franz G. Jahn)
2013-12-10 cae8739 #20811 [SECURITY] XSS vulnerability in extension \
manager (Marcus Krause)
2013-12-10 ba92f0a #41714 [SECURITY] Information Disclosure in \
Wizards (Anja Leichsenring)
2013-12-10 63ff910 #54099 [SECURITY] Fix open redirection in openid \
extension (Anja Leichsenring)
2013-12-10 c4d1336 #48187 [SECURITY] feuser_adminLib.inc allows to \
set arbitrary fields (Steffen Ritter)
2013-12-10 5342284 #36768 [SECURITY] XSS in be_layout wizard (Anja \
Leichsenring)
2013-12-10 b360a1a #54074 [SECURITY] Remove possible XSS from \
ActionController Error output (Anja Leichsenring)
2013-12-10 78ee538 #54073 [SECURITY] Unsafe unserialize of GET \
parameter in Add-Wizard (Marcus Krause)
2013-12-08 5aa4ab2 #54282 [BUGFIX] Fix failing test (Anja Leichsenring)
2013-12-08 6add221 #54280 [BUGFIX] Fix failing test (Anja Leichsenring)
2013-12-02 0c3fa95 #54124 [BUGFIX] ClientUtility does not detect \
Internet Explorer 11 (Stefan Neufeind)
2013-12-02 d353ab0 #54120 Revert "[BUGFIX] Object passed to \
date()" (Markus Klein)
2013-11-29 309e93a #42651 [BUGFIX] ext:adodb Restrict connection \
wizard to admins (Christian Kuhn)
2013-11-26 1d95cad #25157,#45550 [BUGFIX] Distinguish unassigend columns and \
colPos 0 (Philipp Gampe)
Files: