Subject: CVS commit: [pkgsrc-2019Q3] pkgsrc/lang
From: Benny Siegert
Date: 2019-10-25 13:10:21
Message id: 20191025111021.49615FA89@cvs.NetBSD.org

Log Message:
Pullup ticket #6075 - requested by taca
lang/php72: security fix

Revisions pulled up:
- lang/php/phpversion.mk                                        1.269,1.271
- lang/php72/Makefile                                           1.21
- lang/php72/Makefile.php                                       1.13
- lang/php72/distinfo                                           1.45-1.46

---
   Module Name:    pkgsrc
   Committed By:   taca
   Date:           Wed Oct  2 14:05:22 UTC 2019

   Modified Files:
           pkgsrc/lang/php: phpversion.mk
           pkgsrc/lang/php72: Makefile Makefile.php distinfo

   Log Message:
   lang/php72: update to 7.2.23

   Update lang/php72 to 7.2.23.

   pkgsrc changes

   * Clean two pkglint's warnings.

   26 Sep 2019, PHP 7.2.23

   - Core:
     . Fixed bug #78220 (Can't access OneDrive folder). (cmb, ab)
     . Fixed bug #78412 (Generator incorrectly reports non-releasable $this as GC
       child). (Nikita)

   - FastCGI:
     . Fixed bug #78469 (FastCGI on_accept hook is not called when using named
       pipes on Windows). (Sergei Turchanov)

   - MySQLnd:
     . Fixed connect_attr issues and added the _server_host connection attribute.
       (Qianqian Bu)

   - ODBC:
     . Fixed bug #78473 (odbc_close() closes arbitrary resources). (cmb)

   - PDO_MySQL:
     . Fixed bug #41997 (SP call yields additional empty result set). (cmb)

   - sodium:
     . Fixed bug #78510 (Partially uninitialized buffer returned by
       sodium_crypto_generichash_init()). (Frank Denis, cmb)

   - SPL:
     . Fixed bug #72884 (SplObject isCloneable() returns true but errs on clone).
       (Chu Zhaowei)

---
   Module Name:    pkgsrc
   Committed By:   taca
   Date:           Fri Oct 25 02:51:18 UTC 2019

   Modified Files:
           pkgsrc/lang/php: phpversion.mk
           pkgsrc/lang/php72: distinfo

   Log Message:
   lang/php72: update to 7.2.24

   Update php72 to 7.2.24.

   24 Oct 2019, PHP 7.2.24

   - Core:
     . Fixed bug #78535 (auto_detect_line_endings value not parsed as bool).
       (bugreportuser)
     . Fixed bug #78620 (Out of memory error). (cmb, Nikita)

   - Exif:
     . Fixed bug #78442 ('Illegal component' on exif_read_data since PHP7)
           (Kalle)

   - FPM:
     . Fixed bug #78599 (env_path_info underflow in fpm_main.c can lead to RCE).
       (CVE-2019-11043) (Jakub Zelenka)

   - MBString:
     . Fixed bug #78579 (mb_decode_numericentity: args number inconsistency).
       (cmb)
     . Fixed bug #78609 (mb_check_encoding() no longer supports stringable
       objects). (cmb)

   - MySQLi:
     . Fixed bug #76809 (SSL settings aren't respected when persistent connections
       are used). (fabiomsouto)

   - PDO_MySQL:
     . Fixed bug #78623 (Regression caused by "SP call yields additional empty
       result set"). (cmb)

   - Session:
     . Fixed bug #78624 (session_gc return value for user defined session
       handlers). (bshaffer)

   - Standard:
     . Fixed bug #76342 (file_get_contents waits twice specified timeout).
       (Thomas Calvet)
     . Fixed bug #78612 (strtr leaks memory when integer keys are used and the
       subject string shorter). (Nikita)
     . Fixed bug #76859 (stream_get_line skips data if used with data-generating
       filter). (kkopachev)

   - Zip:
     . Fixed bug #78641 (addGlob can modify given remove_path value). (cmb)

Files:
RevisionActionfile
1.20.2.1modifypkgsrc/lang/php72/Makefile
1.12.8.1modifypkgsrc/lang/php72/Makefile.php
1.44.2.1modifypkgsrc/lang/php72/distinfo