Path to this page:
Subject: CVS commit: [pkgsrc-2014Q3] pkgsrc/lang
From: Matthias Scheler
Date: 2014-12-21 11:26:39
Message id: 20141221102639.C196098@cvs.netbsd.org
Log Message:
Pullup ticket #4577 - requested by taca
lang/php54: security update
Revisions pulled up:
- lang/php/phpversion.mk 1.79
- lang/php54/distinfo 1.50
---
Module Name: pkgsrc
Committed By: taca
Date: Fri Dec 19 16:08:35 UTC 2014
Modified Files:
pkgsrc/lang/php: phpversion.mk
pkgsrc/lang/php54: distinfo
Log Message:
Update php54 to 5.4.36, including security fix.
18 Dec 2014 PHP 5.4.36
- Core:
. Upgraded crypt_blowfish to version 1.3. (Leigh)
. Fixed bug #68545 (NULL pointer dereference in unserialize.c). (Anatol)
. Fixed bug #68594 (Use after free vulnerability in unserialize()).
(CVE-2014-8142) (Stefan Esser)
13 Nov 2014 PHP 5.4.35
- Core:
. Fixed bug #68365 (zend_mm_heap corrupted after memory overflow in
zend_hash_copy). (Dmitry)
- Fileinfo:
. Fixed bug #68283 (fileinfo: out-of-bounds read in elf note headers).
(CVE-2014-3710) (Remi)
- GMP:
. Fixed bug #63595 (GMP memory management conflicts with other libraries
using GMP). (Remi)
- PDO_pgsql:
. Fixed bug #66584 (Segmentation fault on statement deallocation) (Matteo)
Files: