Commits on Mar 22, 2014
  1. pullup 4350

    spz committed Mar 22, 2014
  2. Pullup ticket #4350 - requested by tron

    spz committed Mar 22, 2014
    graphics/freetype2: build fix
    Revisions pulled up:
    - graphics/freetype2/                              1.44
       Module Name:	pkgsrc
       Committed By:	jperkin
       Date:		Wed Mar 19 10:16:33 UTC 2014
       Modified Files:
       Log Message:
       Move bzip2 and zlib buildlink3 out of the png PKG_OPTION check, they are
       unconditional dependencies.
       To generate a diff of this commit:
       cvs rdiff -u -r1.43 -r1.44 pkgsrc/graphics/freetype2/
Commits on Mar 21, 2014
  1. pullup 4349

    spz committed Mar 21, 2014
  2. Pullup ticket #4349 - requested by tron

    spz committed Mar 21, 2014
    www/apache24: security update
    Revisions pulled up:
    - www/apache24/Makefile                                         1.26
    - www/apache24/PLIST                                            1.15
    - www/apache24/distinfo                                         1.13
       Module Name:	pkgsrc
       Committed By:	adam
       Date:		Tue Mar 18 20:09:08 UTC 2014
       Modified Files:
       	pkgsrc/www/apache24: Makefile PLIST distinfo
       Log Message:
       Changes 2.4.9:
       *) mod_ssl: Work around a bug in some older versions of OpenSSL that
          would cause a crash in SSL_get_certificate for servers where the
          certificate hadn't been sent.
       *) mod_lua: Add a fixups hook that checks if the original request is intend=
          for LuaMapHandler. This fixes a bug where FallbackResource invalidates t=
          LuaMapHandler directive in certain cases by changing the URI before the =
          handler code executes
       Changes 2.4.8:
       *) SECURITY: CVE-2014-0098 (
          Clean up cookie logging with fewer redundant string parsing passes.
          Log only cookies with a value assignment. Prevents segfaults when
          logging truncated cookies.
       *) SECURITY: CVE-2013-6438 (
          mod_dav: Keep track of length of cdata properly when removing
          leading spaces. Eliminates a potential denial of service from
          specifically crafted DAV WRITE requests
       *) core: Support named groups and backreferences within the LocationMatch,
          DirectoryMatch, FilesMatch and ProxyMatch directives. (Requires
          non-ancient PCRE library)
       *) core: draft-ietf-httpbis-p1-messaging-23 corrections regarding
          TE/CL conflicts.
       *) mod_dir: Add DirectoryCheckHandler to allow a 2.2-like behavior, skipping
          execution when a handler is already set.
       *) mod_ssl: Do not perform SNI / Host header comparison in case of a
          forward proxy request.
       *) mod_ssl: Remove the hardcoded algorithm-type dependency for the
          SSLCertificateFile and SSLCertificateKeyFile directives, to enable
          future algorithm agility, and deprecate the SSLCertificateChainFile
          directive (obsoleted by SSLCertificateFile).
       *) mod_rewrite: Add RewriteOptions InheritDown, InheritDownBefore,
          and IgnoreInherit to allow RewriteRules to be pushed from parent scopes
          to child scopes without explicitly configuring each child scope.
       *) prefork: Fix long delays when doing a graceful restart.
       *) FreeBSD: Disable IPv4-mapped listening sockets by default for versions
          5+ instead of just for FreeBSD 5.
       *) mod_proxy_wstunnel: Avoid busy loop on client errors, drop message
          IDs 02445, 02446, and 02448 to TRACE1 from DEBUG.
       *) mod_remoteip: Correct the trusted proxy match test.
       *) mod_proxy_fcgi: Fix error message when an unexpected protocol version
          number is received from the application.
       *) mod_remoteip: Use the correct IP addresses to populate the proxy_ips fie=
       *) mod_lua: Update r:setcookie() to accept a table of options and add domai=
          path and httponly to the list of options available to set.
       *) mod_lua: Fix r:setcookie() to add, rather than replace,
          the Set-Cookie header.
       *) mod_lua: Allow for database results to be returned as a hash with
          row-name/value pairs instead of just row-number/value.
       *) mod_rewrite: Add %{CONN_REMOTE_ADDR} as the non-useragent counterpart to
       *) WinNT MPM: If ap_run_pre_connection() fails or sets c->aborted, don't
          save the socket for reuse by the next worker as if it were an
          APR_SO_DISCONNECTED socket. Restores 2.2 behavior.
       *) mod_dir: Don't search for a DirectoryIndex or DirectorySlash on a URL
          that was just rewritten by mod_rewrite.
       *) mod_session: When we have a session we were unable to decode,
          behave as if there was no session at all.
       *) mod_session: Fix problems interpreting the SessionInclude and
          SessionExclude configuration.
       *) mod_authn_core: Allow <AuthnProviderAlias>'es to be seen from auth
          stanzas under virtual hosts.
       *) mod_proxy_fcgi: Use apr_socket_timeout_get instead of hard-coded
          30 seconds timeout.
       *) mod_proxy: Added support for unix domain sockets as the
          backend server endpoint
       *) build: only search for modules (config*.m4) in known subdirectories, see
       *) mod_cache_disk: Fix potential hangs on Windows when using mod_cache_disk.
       *) mod_ssl: Add support for OpenSSL configuration commands by introducing
          the SSLOpenSSLConfCmd directive.
       *) mod_proxy: Remove (never documented) <Proxy ~ wildcard-url> syntax which
          is equivalent to <ProxyMatch wildcard-url>.
       *) mod_authz_user, mod_authz_host, mod_authz_groupfile, mod_authz_dbm,
          mod_authz_dbd, mod_authnz_ldap: Support the expression parser within the
          require directives.
       *) mod_proxy_http: Core dumped under high load.
       *) mod_socache_shmcb.c: Remove arbitrary restriction on shared memory size
          previously limited to 64MB.
       *) mod_lua: Use binary copy when dealing with uploads through r:parsebody()
          to prevent truncating files.
       To generate a diff of this commit:
       cvs rdiff -u -r1.25 -r1.26 pkgsrc/www/apache24/Makefile
       cvs rdiff -u -r1.14 -r1.15 pkgsrc/www/apache24/PLIST
       cvs rdiff -u -r1.12 -r1.13 pkgsrc/www/apache24/distinfo
Commits on Mar 18, 2014
  1. Pullup ticket #4348.

    tron committed Mar 18, 2014
  2. Pullup ticket #4348 - requested by taca

    tron committed Mar 18, 2014
    net/samba: security update
    Revisions pulled up:
    - net/samba/Makefile                                            1.242-1.247
    - net/samba/distinfo                                            1.97-1.98
    - net/samba/patches/patch-ab                                    1.29
       Module Name:	pkgsrc
       Committed By:	obache
       Date:		Tue Jan 28 12:16:39 UTC 2014
       Modified Files:
       	pkgsrc/net/samba: Makefile
       Log Message:
       Use GNU_CONFIGURE_LIBDIR for --libdir.
       Module Name:	pkgsrc
       Committed By:	tron
       Date:		Wed Feb 12 23:18:57 UTC 2014
       Modified Files:
       	pkgsrc/net/samba: Makefile
       Log Message:
       Recursive PKGREVISION bump for OpenSSL API version bump.
       Module Name:	pkgsrc
       Committed By:	obache
       Date:		Mon Mar  3 08:05:07 UTC 2014
       Modified Files:
       	pkgsrc/net/samba: Makefile
       Log Message:
       simplify with SUBST_VARS.
       Module Name:	pkgsrc
       Committed By:	obache
       Date:		Mon Mar  3 08:15:10 UTC 2014
       Modified Files:
       	pkgsrc/net/samba: Makefile distinfo
       	pkgsrc/net/samba/patches: patch-ab
       Log Message:
       Replace log dir in the default sample config file correctly.
       Bump PKGREVISION.
       Module Name:	pkgsrc
       Committed By:	jperkin
       Date:		Thu Mar 13 11:08:54 UTC 2014
       Modified Files:
       	pkgsrc/net/samba: Makefile
       Log Message:
       Set USE_GCC_RUNTIME=yes for packages which build shared libraries but do
       not use libtool to do so.  This is required to correctly depend upon a
       gcc runtime package (e.g. gcc47-libs) when using USE_PKGSRC_GCC_RUNTIME.
       Module Name:	pkgsrc
       Committed By:	taca
       Date:		Mon Mar 17 14:01:57 UTC 2014
       Modified Files:
       	pkgsrc/net/samba: Makefile distinfo
       Log Message:
       Update samba to 3.6.23.
                          Release Notes for Samba 3.6.23
                                  March 11, 2014
       This is a security release in order to address
       CVE-2013-4496 (Password lockout not enforced for SAMR password changes).
       o  CVE-2013-4496:
          Samba versions 3.4.0 and above allow the administrator to implement
          locking out Samba accounts after a number of bad password attempts.
          However, all released versions of Samba did not implement this check for
          password changes, such as are available over multiple SAMR and RAP
          interfaces, allowing password guessing attacks.
Commits on Mar 17, 2014
  1. Pullup ticket #4347.

    tron committed Mar 17, 2014
  2. Pullup ticket #4347 - requested by spz

    tron committed Mar 17, 2014
    graphics/freetype2: security update
    Revisions pulled up:
    - graphics/freetype2/Makefile                                   1.92-1.94
    - graphics/freetype2/PLIST                                      1.21
    - graphics/freetype2/                              1.38-1.43
    - graphics/freetype2/distinfo                                   1.51
    - graphics/freetype2/                                 1.1-1.2
       Module Name:	pkgsrc
       Committed By:	spz
       Date:		Thu Mar 13 23:26:35 UTC 2014
       Modified Files:
       	pkgsrc/graphics/freetype2: Makefile PLIST distinfo
       Log Message:
       security update, upstream short changelog ('here' being releasenotes):
       FreeType 2.5.3
       FreeType 2.5.3 has been released. All users should upgrade due to fixed
       vulnerability in the CFF driver (CVE-2014-2240).
       Its main new feature is much enhanced support of auto-hinting SFNT fonts
       (i.e., TrueType and CFF fonts) due to the use of the HarfBuzz library.
       A more detailed description of this and other changes can be found here.
       FreeType 2.5.2
       FreeType 2.5.2 has been released. It fixes a serious bug introduced
       in version 2.5.1; all users should upgrade.
       A listing of the changes can be found here.
       FreeType 2.5.1
       FreeType 2.5.1 has been released, providing three major new features.
          - Support for the WOFF font format, contributed by Behdad Esfahbod.
          - The auto-hinter now supports Hebrew, together with improved support
            for Cyrillic and Greek.
          - The directory layout of the (installed) FreeType header files has
            been simplified.
       Among other changes I want to mention that FreeType's TrueType debugger
       (ttdebug) has been made more versatile. An exhaustive list of changes
       can be found here.
       FreeType 2.5
       FreeType 2.5 has been released. A major new feature is support for
       color embedded bitmaps (eg. color emoji), contributed by Behdad Esfahbod
       on behalf of Google. Additionally, Adobe's CFF engine is now the default,
       which makes a good reason to change from the 2.4.x to the 2.5.x series.
       On the technical side, the property API to access FreeType module
       parameters (FT_Property_Set and FT_Property_Get) is now declared as
       As usual, see this file for the complete release notes, which give
       more details. And we have again blog entries from Adobe and Google.
       FreeType 2.4.12
       FreeType 2.4.12 has been released. A major new feature is a new parsing
       and hinting engine for CFF fonts, contributed by Adobe in collaboration
       with Google. It was my job the last few months to fully adapt the code
       to FreeType, and we are very pleased with the results. You might also
       read the blog entries from Adobe and Google.
       In connection with the new CFF engine, the demo programs, especially
       ftview and ftdiff, have been improved a lot; as usual, more details
       on the changes can be found in the release notes.
       Module Name:	pkgsrc
       Committed By:	ryoon
       Date:		Fri Mar 14 13:12:34 UTC 2014
       Modified Files:
       Log Message:
       graphics/png is also needed now
       Module Name:	pkgsrc
       Committed By:	ryoon
       Date:		Fri Mar 14 13:38:20 UTC 2014
       Modified Files:
       Log Message:
       graphics/png should be included when non-builtin freetype2.
       Pointed out by obache@, thank you.
       Module Name:	pkgsrc
       Committed By:	obache
       Date:		Fri Mar 14 13:43:17 UTC 2014
       Modified Files:
       Log Message:
       To get USE_BUILTIN.freetype2, must be included.
       Module Name:	pkgsrc
       Committed By:	ryoon
       Date:		Fri Mar 14 14:54:02 UTC 2014
       Modified Files:
       	pkgsrc/graphics/freetype2: Makefile
       Added Files:
       Log Message:
       Make png dependency as option, and move option to
       Revert bump of BUILDLINK_ABI_DEPENDS.freetype2
       Module Name:	pkgsrc
       Committed By:	drochner
       Date:		Fri Mar 14 19:39:52 UTC 2014
       Modified Files:
       	pkgsrc/graphics/freetype2: Makefile
       Log Message:
       make the optional-png logics work
Commits on Mar 14, 2014
  1. Pullup ticket #4346.

    tron committed Mar 14, 2014
  2. Pullup ticket #4346 - requested by obache

    tron committed Mar 14, 2014
    graphics/MesaLib: build fix for depending packages
    Revisions pulled up:
    - graphics/MesaLib/                                       1.8
    - graphics/MesaLib/                                   1.26
       Module Name:	pkgsrc
       Committed By:	obache
       Date:		Fri Mar 14 07:19:36 UTC 2014
       Modified Files:
       Log Message:
       Overall dri related dependency clean up.
       * move dri related API_DEPENDS into
       * add missing API_DEPENDS.
       * only define such API_DEPENDS only not using builtin MesaLib.
       Fixes following issues on platforms that builtin one is older than required
       version (ex. NetBSD-5).
       * build issue of MesaLib
       * unwanted dependency on MesaLib from pkgsrc even if builtin one is
  3. Pullup ticket #4345.

    tron committed Mar 14, 2014
  4. Pullup ticket #4345 - requested by taca

    tron committed Mar 14, 2014
    graphics/freetype2: build fix for depending packages
    Revisions pulled up:
    - graphics/freetype2/                              1.37
       Module Name:	pkgsrc
       Committed By:	schmonz
       Date:		Sun Jan 12 21:19:33 UTC 2014
       Modified Files:
       Log Message:
       Let naive configure scripts find freetype-config (needed for latest php55-gd).
Commits on Mar 13, 2014
  1. Pullup ticket #4344.

    tron committed Mar 13, 2014
  2. Pullup ticket #4344 - requested by obache

    tron committed Mar 13, 2014
    emulators/suse131_libpng: security update
    Revisions pulled up:
    - emulators/suse131_libpng/Makefile                             1.3
    - emulators/suse131_libpng/distinfo                             1.3
       Module Name:	pkgsrc
       Committed By:	obache
       Date:		Thu Mar 13 11:33:47 UTC 2014
       Modified Files:
       	pkgsrc/emulators/suse131_libpng: Makefile distinfo
       Log Message:
       Update suse131 libpng16 RPM to libpng16-16-1.6.6-12.1 for CVE-2014-0333.
       Bump PKGREVISION.
  3. pullup 4343

    spz committed Mar 13, 2014
  4. Pullup ticket #4343 - requested by tron

    spz committed Mar 13, 2014
    mail/mutt-devel: security update
    Revisions pulled up:
    - mail/mutt-devel/Makefile                                      1.98
    - mail/mutt-devel/distinfo                                      1.79
       Module Name:	pkgsrc
       Committed By:	tron
       Date:		Wed Mar 12 23:55:56 UTC 2014
       Modified Files:
       	pkgsrc/mail/mutt-devel: Makefile distinfo
       Log Message:
       Update the "mutt-devel" package to version 1.5.23. This release fixes
       the security vulnerability reported in CVE-2014-0467.
       To generate a diff of this commit:
       cvs rdiff -u -r1.97 -r1.98 pkgsrc/mail/mutt-devel/Makefile
       cvs rdiff -u -r1.78 -r1.79 pkgsrc/mail/mutt-devel/distinfo
Commits on Mar 12, 2014
  1. Pullup ticket #4342.

    tron committed Mar 12, 2014
  2. Pullup ticket #4342 - requested by obache

    tron committed Mar 12, 2014
    multimedia/adobe-flash-plugin11: security update
    Revisions pulled up:
    - multimedia/adobe-flash-plugin11/Makefile                      1.26
    - multimedia/adobe-flash-plugin11/distinfo                      1.24
       Module Name:	pkgsrc
       Committed By:	obache
       Date:		Wed Mar 12 12:22:25 UTC 2014
       Modified Files:
       	pkgsrc/multimedia/adobe-flash-plugin11: Makefile distinfo
       Log Message:
       Update adobe-flash-plugin11 to for APSB14-08.
  3. Pullup ticket #4341.

    tron committed Mar 12, 2014
  4. Pullup ticket #4341 - requested by jym

    tron committed Mar 12, 2014
    security/stunnel: security update
    Revisions pulled up:
    - security/stunnel/Makefile                         1.86-1.87,1.89 via patch
    - security/stunnel/distinfo                         1.38-1.39
    - security/stunnel/patches/patch-ac                 1.16
       Module Name:	pkgsrc
       Committed By:	tron
       Date:		Sun Jan 26 15:51:54 UTC 2014
       Modified Files:
       	pkgsrc/security/stunnel: Makefile
       Log Message:
       Fix permissions so that "etc/stunnel" belongs to the actual "root" user
       and not to the user that build the package. Bump package revision
       because of this fix.
       Module Name:	pkgsrc
       Committed By:	tron
       Date:		Sun Jan 26 16:59:13 UTC 2014
       Modified Files:
       	pkgsrc/security/stunnel: Makefile distinfo
       Log Message:
       Update "stunnel" package to version 4.56. Changes since 4.55:
       - Fixed a regression bug introduced in version 4.55 causing random
         crashes on several platforms, including Windows 7.
       - Fixed incorrect "stunnel -exit" process synchronisation.
       - Fixed FIPS detection with new versions of the OpenSSL library.
       - Failure to open the log file at startup is no longer ignored.
       Module Name:	pkgsrc
       Committed By:	jym
       Date:		Wed Mar 12 00:24:35 UTC 2014
       Modified Files:
       	pkgsrc/security/stunnel: Makefile distinfo
       	pkgsrc/security/stunnel/patches: patch-ac
       Log Message:
       Update stunnel to 5.00.
       Of utmost importance: it fixes CVE 2014-0016.
       Thanks to jgw (Jeff W) _AT_ for working on the same patch
       In before the freeze! Changelog follows.
           Security bugfixes
               Added PRNG state update in fork threading (CVE-2014-0016).
           New global configuration file defaults
               Default "fips" option value is now "no", as FIPS mode is only helpful for compliance, and never for actual security.
               Default "pid" is now "", i.e. not to create a pid file at startup.
           New service-level configuration file defaults
               Default "ciphers" updated to "HIGH:MEDIUM:+3DES:+DH:!aNULL:!SSLv2" due to AlFBPPS attack and bad performance of DH ciphersuites.
               Default "libwrap" setting is now "no" to improve performance.
           New features
               OpenSSL DLLs updated to version 1.0.1f.
               zlib DLL updated to version 1.2.8.
               autoconf scripts upgraded to version 2.69.
               TLS 1.1 and TLS 1.2 are now allowed in the FIPS mode.
               New service-level option "redirect" to redirect SSL client connections on authentication failures instead of rejecting them.
               New global "engineDefault" configuration file option to control which OpenSSL tasks are delegated to the current engine. Available tasks: ALL, RSA, DSA, ECDH, ECDSA, DH, RAND, CIPHERS, DIGESTS, PKEY, PKEY_CRYPTO, PKEY_ASN1.
               New service-level configuration file option "engineId" to select the engine by identifier, e.g. "engineId = capi".
               New global configuration file option "log" to control whether to append (the default), or to overwrite log file while (re)opening.
               Different taskbar icon colors to indicate the service state.
               New global configuration file options "iconIdle", "iconActive", and "iconError" to select status icon on GUI taskbar.
               Removed the limit of 63 stunnel.conf sections on Win32 platform.
               Installation of a sample certificate was moved to a separate "cert" target in order to allow unattended (e.g. scripted) installations.
               Reduced length of the logged thread identifier. It is still based on the OS thread ID, and thus not unique over long periods of time.
               Improved readability of error messages printed when stunnel refuses to start due to a critical error.
               LD_PRELOAD Solaris compatibility bug fixed (thx to Norm Jacobs).
               CRYPTO_NUM_LOCKS replaced with CRYPTO_num_locks() to improve binary compatibility with diverse builds of OpenSSL (thx to Norm Jacobs).
               Corrected round-robin failover behavior under heavy load.
               Numerous fixes in the engine support code.
               On Win32 platform .rnd file moved from c:\ to the stunnel folder.
Commits on Mar 11, 2014
  1. Pullup tickets #4338, #4339 and #4340.

    tron committed Mar 11, 2014
  2. Pullup ticket #4340 - requested by taca

    tron committed Mar 11, 2014
    lang/php54: security update
    lang/php55: security update
    Revisions pulled up:
    - lang/php/                                        1.53-1.58
    - lang/php54/Makefile                                           1.17-1.18
    - lang/php54/distinfo                                           1.32-1.34
    - lang/php54/patches/patch-configure                            1.5
    - lang/php54/patches/patch-ext_date_lib_parse__iso__intervals.c deleted
    - lang/php54/patches/ deleted
    - lang/php54/patches/patch-php.ini-development                  1.2
    - lang/php54/patches/patch-php.ini-production                   1.2
    - lang/php55/Makefile                                           1.8-1.9
    - lang/php55/distinfo                                           1.13-1.15
    - lang/php55/patches/patch-configure                            1.4
    - lang/php55/patches/patch-ext_date_lib_parse__iso__intervals.c deleted
    - lang/php55/patches/ deleted
    - lang/php55/patches/patch-ext_sockets_sockaddr__conv.c         deleted
    - lang/php55/patches/patch-makedist                             1.2
    - lang/php55/patches/patch-php.ini-development                  1.3
    - lang/php55/patches/patch-php.ini-production                   1.3
       Module Name:	pkgsrc
       Committed By:	taca
       Date:		Sat Jan 11 17:03:57 UTC 2014
       Modified Files:
       	pkgsrc/lang/php54: distinfo
       	pkgsrc/lang/php54/patches: patch-configure patch-php.ini-development
       Removed Files:
       	pkgsrc/lang/php54/patches: patch-ext_date_lib_parse__iso__intervals.c
       Log Message:
       Update php to 5.4.24.
       09 Jan 2014, PHP 5.4.24
       - Core:
         . Added validation of class names in the autoload process. (Dmitry)
         . Fixed invalid C code in zend_strtod.c. (Lior Kaplan)
         . Fixed bug #61645 (fopen and O_NONBLOCK). (Mike)
       - Date:
         . Fixed bug #66060 (Heap buffer over-read in DateInterval). (Remi)
         . Fixed bug #63391 (Incorrect/inconsistent day of week prior to the year
           1600). (Derick, T. Carter)
         . Fixed bug #61599 (Wrong Day of Week). (Derick, T. Carter)
       - DOM:
         . Fixed bug #65196 (Passing DOMDocumentFragment to DOMDocument::saveHTML()
           Produces invalid Markup). (Mike)
       - Exif:
         . Fixed bug #65873 (Integer overflow in exif_read_data()). (Stas)
       - Filter:
         . Fixed bug #66229 ( isn't reserved any longer). (Adam)
       - GD:
         . Fixed bug #64405 (Use freetype-config for determining freetype2 dir(s)).
       - PDO_odbc:
         . Fixed bug #66311 (Stack smashing protection kills PDO/ODBC queries).
           (michael at orlitzky dot com)
       - SNMP:
         . Fixed SNMP_ERR_TOOBIG handling for bulk walk operations. (Boris Lytochkin)
       - XSL
         . Fixed bug #49634 (Segfault throwing an exception in a XSL registered
           function). (Mike)
       - ZIP:
         . Fixed Bug #66321 (ZipArchive::open() ze_obj->filename_len not real). (Remi)
       Module Name:	pkgsrc
       Committed By:	taca
       Date:		Sat Jan 11 17:05:09 UTC 2014
       Modified Files:
       	pkgsrc/lang/php55: distinfo
       	pkgsrc/lang/php55/patches: patch-configure patch-php.ini-development
       Removed Files:
       	pkgsrc/lang/php55/patches: patch-ext_date_lib_parse__iso__intervals.c
       Log Message:
       Update php55 to 5.5.8.
       9 Jan 2014, PHP 5.5.8
       - Core:
         . Disallowed JMP into a finally block. (Laruence)
         . Added validation of class names in the autoload process. (Dmitry)
         . Fixed invalid C code in zend_strtod.c. (Lior Kaplan)
         . Fixed bug #66041 (list() fails to unpack yielded ArrayAccess object).
         . Fixed bug #65764 (generators/throw_rethrow FAIL with
           ZEND_COMPILE_EXTENDED_INFO). (Nikita)
         . Fixed bug #61645 (fopen and O_NONBLOCK). (Mike)
         . Fixed bug #66218 (zend_register_functions breaks reflection). (Remi)
       - Date:
         . Fixed bug #66060 (Heap buffer over-read in DateInterval). (Remi)
         . Fixed bug #65768 (DateTimeImmutable::diff does not work). (Nikita Nefedov)
       - DOM:
         . Fixed bug #65196 (Passing DOMDocumentFragment to DOMDocument::saveHTML()
           Produces invalid Markup). (Mike)
       - Exif:
         . Fixed bug #65873 (Integer overflow in exif_read_data()). (Stas)
       - Filter:
         . Fixed bug #66229 ( isn't reserved any longer). (Adam)
       - GD:
         . Fixed bug #64405 (Use freetype-config for determining freetype2 dir(s)).
       - PDO_odbc:
         . Fixed bug #66311 (Stack smashing protection kills PDO/ODBC queries).
           (michael at orlitzky dot com)
       - MySQLi:
         . Fixed bug #65486 (mysqli_poll() is broken on win x64). (Anatol)
       - OPCache:
         . Fixed reavlidate_path=1 behavior to avoid caching of symlinks values.
         . Fixed Issue #140: "opcache.enable_file_override" doesn't respect
           "opcache.revalidate_freq". (Dmitry).
       - SNMP:
         . Fixed SNMP_ERR_TOOBIG handling for bulk walk operations. (Boris Lytochkin)
       - SOAP
         . Fixed bug #66112 (Use after free condition in SOAP extension).
           (martin dot koegler at brz dot gv dot at)
       - Sockets:
         . Fixed bug #65923 (ext/socket assumes AI_V4MAPPED is defined). (Felipe)
       - XSL
         . Fixed bug #49634 (Segfault throwing an exception in a XSL registered
           function). (Mike)
       - ZIP:
         . Fixed Bug #66321 (ZipArchive::open() ze_obj->filename_len not real). (Remi)
       Module Name:	pkgsrc
       Committed By:	taca
       Date:		Fri Feb  7 15:35:05 UTC 2014
       Modified Files:
       	pkgsrc/lang/php55: distinfo
       	pkgsrc/lang/php55/patches: patch-makedist
       Log Message:
       Update php55 to 5.5.9 (PHP 5.5.9).
       06 Feb 2014, PHP 5.5.9
       - Core:
         . Fixed bug #66509 (copy() arginfo has changed starting from 5.4). (willfitch)
       - GD:
         . Fixed bug #66356 (Heap Overflow Vulnerability in imagecrop()).
           (Laruence, Remi)
       - OPCache:
         . Fixed bug #66474 (Optimizer bug in constant string to boolean conversion).
         . Fixed bug #66461 (PHP crashes if opcache.interned_strings_buffer=0).
         . Fixed bug #66298 (ext/opcache/Optimizer/zend_optimizer.c has dos-style
           ^M as lineend). (Laruence)
       - PDO_pgsql:
         . Fixed bug #62479 (PDO-psql cannot connect if password contains
       spaces) (willfitch, iliaa)
       - Readline
         . Fixed Bug #66412 (readline_clear_history() with libedit causes segfault after
           #65714). (Remi)
       - Session
         . Fixed bug #66469 (Session module is sending multiple set-cookie headers when
           session.use_strict_mode=1) (Yasuo)
         . Fixed bug #66481 (Segfaults on session_name()).
           (cmcdermottroe at engineyard dot com, Yasuo)
       - Standard
         . Fixed bug #66395 (basename function doesn't remove drive letter). (Anatol)
       - Sockets:
         . Fixed bug #66381 (__ss_family was changed on AIX 5.3). (Felipe)
       - Zend Engine
         . Fixed bug #66009 (Failed compilation of PHP extension with C++ std
           library using VS 2012). (Anatol)
       Module Name:	pkgsrc
       Committed By:	taca
       Date:		Fri Feb  7 15:36:07 UTC 2014
       Modified Files:
       	pkgsrc/lang/php54: distinfo
       Log Message:
       Update php54 to 5.4.25.
       06 Feb 2014, PHP 5.4.25
       - Core:
         . Fixed bug #66286 (Incorrect object comparison with inheritance). (Nikita)
         . Fixed bug #66509 (copy() arginfo has changed starting from 5.4).
           (Will Fitch)
       - mysqlnd
         . Fixed bug #66283 (Segmentation fault after memory_limit). (Johannes)
       - PDO_pgsql:
         . Fixed bug #62479 (PDO-psql cannot connect if password contains spaces).
           (Will Fitch, Ilia)
       - Session:
         . Fixed bug #66481 (Calls to session_name() segfault when is
           null). (Laruence)
       Module Name:	pkgsrc
       Committed By:	tron
       Date:		Wed Feb 12 23:18:57 UTC 2014
       Modified Files:
       Log Message:
       Module Name:	pkgsrc
       Committed By:	taca
       Date:		Sun Mar  9 14:08:17 UTC 2014
       Modified Files:
       	pkgsrc/lang/php54: Makefile distinfo
       Log Message:
       Module Name:	pkgsrc
       Committed By:	taca
       Date:		Sun Mar  9 14:09:20 UTC 2014
       Modified Files:
       	pkgsrc/lang/php55: Makefile distinfo
       Log Message:
       Module Name:	pkgsrc
       Committed By:	taca
       Date:		Sun Mar  2 14:59:25 UTC 2014
       Modified Files:
       Log Message:
       Module Name:	pkgsrc
       Committed By:	taca
       Date:		Sun
Commits on Mar 8, 2014
  1. 4336 + 4337

    spz committed Mar 8, 2014
  2. Pullup ticket #4337 - requested by kim

    spz committed Mar 8, 2014
    security/sudo: security update
    Revisions pulled up:
    - security/sudo/Makefile                                        1.142
    - security/sudo/distinfo                                        1.81
    - security/sudo/patches/patch-af                                1.31
    - security/sudo/patches/patch-ag                                1.22
    - security/sudo/patches/patch-logging.c                         1.4
       Module Name:    pkgsrc
       Committed By:   kim
       Date:           Sat Mar  8 11:51:56 UTC 2014
       Modified Files:
               pkgsrc/security/sudo: Makefile distinfo
               pkgsrc/security/sudo/patches: patch-af patch-ag patch-logging.c
       Log Message:
       Upgrade to address CVE-2014-0106
       What's new in Sudo 1.7.10p8?
       * Sudo's exit code now indicates a failure if the user does not
         successfully authenticate.
       * On HP-UX systems, sudo will now use the pstat() function to
         determine the tty instead of ttyname().
       * Fixed compilation when --without-iologdir configure option is
       * On systems with BSD login classes, if the user specified a group
         (not a user) to run the command as, it was possible to specify
         a different login class even when the command was not run as the
         super user.
       * The closefrom() emulation on Mac OS X now uses /dev/fd if possible.
         It also now sets the close on exec flag instead of actually
         closing the descriptors to avoid a crash in libdispatch.
       * The sudoers plugin will now ignore invalid domain names when
         checking netgroup membership.  Most Linux systems use the string
         "(none)" for the NIS-style domain name instead of an empty string.
       * Fixed the logic when checking environment variables on the
         command line against the env_check and env_delete blacklists.
         This is only a problem when env_reset is disabled in sudoers.
       To generate a diff of this commit:
       cvs rdiff -u -r1.141 -r1.142 pkgsrc/security/sudo/Makefile
       cvs rdiff -u -r1.80 -r1.81 pkgsrc/security/sudo/distinfo
       cvs rdiff -u -r1.30 -r1.31 pkgsrc/security/sudo/patches/patch-af
       cvs rdiff -u -r1.21 -r1.22 pkgsrc/security/sudo/patches/patch-ag
       cvs rdiff -u -r1.3 -r1.4 pkgsrc/security/sudo/patches/patch-logging.c
  3. Pullup ticket #4336 - requested by tron

    spz committed Mar 8, 2014
    net/wireshark: security update
    Revisions pulled up:
    - net/wireshark/Makefile                                        1.117
    - net/wireshark/distinfo                                        1.73
       Module Name:	pkgsrc
       Committed By:	tron
       Date:		Sat Mar  8 10:38:26 UTC 2014
       Modified Files:
       	pkgsrc/net/wireshark: Makefile distinfo
       Log Message:
       Update "wireshark" package to version 1.10.6. Changes since 1.10.5:
       - Bug Fixes
          The following vulnerabilities have been fixed.
            * wnpa-sec-2014-01
              The NFS dissector could crash. Discovered by Moshe Kaplan.
              (Bug 9672)
              Versions affected: 1.10.0 to 1.10.5, 1.8.0 to 1.8.12
            * wnpa-sec-2014-02
              The M3UA dissector could crash. Discovered by Laurent
              Butti. (Bug 9699)
              Versions affected: 1.10.0 to 1.10.5
            * wnpa-sec-2014-03
              The RLC dissector could crash. (Bug 9730)
              Versions affected: 1.10.0 to 1.10.5, 1.8.0 to 1.8.12
            * wnpa-sec-2014-04
              The MPEG file parser could overflow a buffer. Discovered by
              Wesley Neelen. (Bug 9843)
              Versions affected: 1.10.0 to 1.10.5, 1.8.0 to 1.8.12
          The following bugs have been fixed:
            * Customized OUI is not recognized correctly during
              dissection. (Bug 9122)
            * Properly decode CAPWAP Data Keep-Alives. (Bug 9165)
            * Build failure with GTK 3.10 - GTK developers have gone
              insane. (Bug 9340)
            * SIGSEGV/SIGABRT during free of TvbRange using a chained
              dissector in lua. (Bug 9483)
            * MPLS dissector no longer registers itself in "ppp.protocol"
              table. (Bug 9492)
            * Tshark doesn't display the longer data fields (mbtcp).
              (Bug 9572)
            * DMX-CHAN disector does not clear strbuf between rows.
              (Bug 9598)
            * Dissector bug, protocol SDP: proto.c:4214: failed assertion
              "length >=3D 0". (Bug 9633)
            * False error: capture file appears to be damaged or corrupt.
              (Bug 9634)
            * SMPP field source_telematics_id field length different from
              spec. (Bug 9649)
            * Lua: bitop library is missing in Lua 5.2. (Bug 9720)
            * GTPv1-C / MM Context / Authentication quintuplet / RAND is
              not correct. (Bug 9722)
            * Lua: is buggy. (Bug 9725)
            * Lua: ProtoField.bool() VALUESTRING argument is not optional
              but was supposed to be. (Bug 9728)
            * Problem with CAPWAP Wireshark Dissector. (Bug 9752)
            * nas-eps dissector: CS Service notification dissection stops
              after Paging identity IE. (Bug 9789)
       - New and Updated Features
         IPv4 checksum verfification is now disabled by default.
       - Updated Protocol Support
          AppleTalk, CAPWAP, DMX-CHAN, DSI, DVB-CI, ESS, GTPv1, IEEE
          802a, M3UA, Modbus/TCP, NAS-EPS, NFS, OpenSafety, SDP, and SMPP
       - New and Updated Capture File Support
          libpcap, MPEG, and pcap-ng
       To generate a diff of this commit:
       cvs rdiff -u -r1.116 -r1.117 pkgsrc/net/wireshark/Makefile
       cvs rdiff -u -r1.72 -r1.73 pkgsrc/net/wireshark/distinfo
Commits on Feb 27, 2014
  1. Pullup ticket #4334.

    tron committed Feb 27, 2014
  2. Pullup ticket #4334 - requested by wiz

    tron committed Feb 27, 2014
    graphics/png: security update
    Revisions pulled up:
    - graphics/png/Makefile                                         1.166-1.168
    - graphics/png/distinfo                                         1.111-1.113
    - graphics/png/patches/patch-aa                                 deleted
    - graphics/png/patches/patch-contrib_tools_pngfix.c             deleted
       Module Name:	pkgsrc
       Committed By:	wiz
       Date:		Tue Dec 31 17:27:48 UTC 2013
       Modified Files:
       	pkgsrc/graphics/png: Makefile distinfo
       Log Message:
       Update to 1.6.8:
       Version 1.6.8beta01 [November 24, 2013]
         Moved prototype for png_handle_unknown() in pngpriv.h outside of
           the #ifdef PNG_SET_UNKNOWN_CHUNKS_SUPPORTED/#endif block.
         Added "-Wall" to CFLAGS in contrib/pngminim/*/makefile
         Conditionally compile some unused functions reported by -Wall in
         Fixed 'minimal' builds. Various obviously useful minimal configurations
           don't build because of missing contrib/libtests test programs and
           overly complex dependencies in scripts/pnglibconf.dfa. This change
           adds contrib/conftest/*.dfa files that can be used in automatic build
           scripts to ensure that these configurations continue to build.
         Enabled WRITE_INVERT and WRITE_PACK in contrib/pngminim/encoder.
         Fixed pngvalid 'fail' function declaration on the Intel C Compiler.
           This reverts to the previous 'static' implementation and works round
           the 'unused static function' warning by using PNG_UNUSED().
       Version 1.6.8beta02 [November 30, 2013]
         Removed or marked PNG_UNUSED some harmless "dead assignments" reported
           by clang scan-build.
         Changed tabs to 3 spaces in png_debug macros and changed '"%s"m'
           to '"%s" m' to improve portability among compilers.
         Changed png_free_default() to free() in pngtest.c
       Version 1.6.8rc01 [December 12, 2013]
         Tidied up pngfix inits and fixed pngtest no-write builds.
       Version 1.6.8rc02 [December 14, 2013]
         Handle zero-length PLTE chunk or NULL palette with png_error()
           instead of png_chunk_report(), which by default issues a warning
           rather than an error, leading to later reading from a NULL pointer
           (png_ptr->palette) in png_do_expand_palette(). This is CVE-2013-6954
           and VU#650142.
       Version 1.6.8 [December 19, 2013]
       Module Name:	pkgsrc
       Committed By:	wiz
       Date:		Thu Feb  6 18:24:11 UTC 2014
       Modified Files:
       	pkgsrc/graphics/png: Makefile distinfo
       Removed Files:
       	pkgsrc/graphics/png/patches: patch-aa patch-contrib_tools_pngfix.c
       Log Message:
       Update to 1.6.9, getting rid of the final two patches after discussion
       with very helpful upstream.
       Version 1.6.9beta01 [December 26, 2013]
         Bookkeeping: Moved functions around (no changes). Moved transform
           function definitions before the place where they are called so that
           they can be masde static. Move the intrapixel functions and the
           grayscale palette builder out of the png?tran.c files. The latter
           isn't a transform function and is no longer used internally, and the
           former MNG specific functions are better placed in pngread/pngwrite.c
         Made transform implementation functions static. This makes the internal
           functions called by png_do_{read|write}_transformations static. On an
           x86-64 DLL build (Gentoo Linux) this reduces the size of the text
           segment of the DLL by 1208 bytes, about 0.6%. It also simplifies
           maintenance by removing the declarations from pngpriv.h and allowing
           easier changes to the internal interfaces.
         Rebuilt configure scripts with automake-1.14.1 and autoconf-2.69
           in the tar distributions.
       Version 1.6.9beta02 [January 1, 2014]
         Added checks for libpng 1.5 to pngvalid.c.  This supports the use of
           this version of pngvalid in libpng 1.5
         Merged with pngvalid.c from libpng-1.7 changes to create a single
         Removed #error macro from contrib/tools/pngfix.c (Thomas Klausner).
         Merged pngrio.c, pngtrans.c, pngwio.c, and pngerror.c with libpng-1.7.0
         Merged libpng-1.7.0 changes to make no-interlace configurations work
           with test programs.
         Revised pngvalid.c to support libpng 1.5, which does not support the
           PNG_MAXIMUM_INFLATE_WINDOW option, so #define it out when appropriate in
         Allow unversioned links created on install to be disabled in configure.
           In configure builds 'make install' changes/adds links like png.h
           and libpng.a to point to the newly installed, versioned, files (e.g.
           libpng17/png.h and libpng17.a). Three new configure options and some
           rearrangement of allow creation of these links to be disabled.
       Version 1.6.9beta03 [January 10, 2014]
         Removed potentially misleading warning from png_check_IHDR().
       Version 1.6.9beta04 [January 20, 2014]
         Updated scripts/makefile.* to use CPPFLAGS (Cosmin).
         Added clang attribute support (Cosmin).
       Version 1.6.9rc01 [January 28, 2014]
         No changes.
       Version 1.6.9rc02 [January 30, 2014]
         Quiet an uninitialized memory warning from VC2013 in png_get_png().
       Version 1.6.9 [February 6, 2014]
       Module Name:	pkgsrc
       Committed By:	wiz
       Date:		Thu Feb 27 15:07:09 UTC 2014
       Modified Files:
       	pkgsrc/graphics/png: Makefile distinfo
       Log Message:
       Update to 1.6.10rc01:
       This fixes CERT VU#684412 and CVE-2014-0333.
       Version 1.6.10beta01 [February 9, 2014]
         Backported changes from libpng-1.7.0beta30 and beta31:
         Fixed a large number of instances where PNGCBAPI was omitted from
           function definitions.
         Added pngimage test program for png_read_png() and png_write_png()
           with two new test scripts.
         Removed dependence on !PNG_READ_EXPAND_SUPPORTED for calling
           png_set_packing() in png_read_png().
         Fixed combination of ~alpha with shift. On read invert alpha, processing
           occurred after shift processing, which causes the final values to be
           outside the range that should be produced by the shift. Reversing the
           order on read makes the two transforms work together correctly and mirrors
           the order used on write.
         Do not read invalid sBIT chunks. Previously libpng only checked sBIT
           values on write, so a malicious PNG writer could therefore cause
           the read code to return an invalid sBIT chunk, which might lead to
           application errors or crashes.  Such chunks are now skipped (with
         Make png_read_png() and png_write_png() prototypes in png.h depend
         Support builds with unsupported PNG_TRANSFORM_* values.  All of the
           PNG_TRANSFORM_* values are always defined in png.h and, because they
           are used for both read and write in some cases, it is not reliable
           to #if out ones that are totally unsupported. This change adds error
           detection in png_read_image() and png_write_image() to do a
           png_app_error() if the app requests something that cannot be done
           and it adds corresponding code to pngimage.c to handle such options
           by not attempting to test them.
       Version 1.6.10beta02 [February 23, 2014]
         Moved redefines of png_error(), png_warning(), png_chunk_error(),
           and png_chunk_warning() from pngpriv.h to png.h to make them visible
           to libpng-calling applications.
         Moved OS dependent code from arm/arm_init.c, to allow the included
           implementation of the ARM NEON discovery function to be set at
           build-time and provide sample implementations from the current code in the
           contrib/arm-neon subdirectory. The __linux__ code has also been changed to
           compile and link on Android by using /proc/cpuinfo, and the old linux code
           is in contrib/arm-neon/linux-auxv.c.  The new code avoids POSIX and Linux
           dependencies apart from opening /proc/cpuinfo and is C90 compliant.
         Check for info_ptr == NULL early in png_read_end() so we don't need to
           run all the png_handle_*() and depend on them to return if info_ptr == NULL.
           This improves the performance of png_read_end(png_ptr, NULL) and makes
           it more robust against future programming errors.
         Check for __has_extension before using it in pngconf.h, to
           support older Clang versions (Jeremy Sequoia).
         Treat CRC error handling with png_set_crc_action(), instead of with
           png_set_benign_errors(), which has been the case since libpng-1.6.0beta18.
         Use a user warning handler in contrib/gregbook/readpng2.c instead of default,
           so warnings will be put on stderr even if libpng has CONSOLE_IO disabled.
         Added png_ptr->process_mode = PNG_READ_IDAT_MODE in png_push_read_chunk
           after recognizing the IDAT chunk, which avoids an infinite loop while
           reading a datastream whose first IDAT chunk is of zero-length.
           This fixes CERT VU#684412 and CVE-2014-0333.
         Don't recognize known sRGB profiles as sRGB if they have been hacked,
           but don't reject them and don't issue a copyright violation warning.
       Version 1.6.10beta03 [February 25, 2014]
         Moved some documentation from png.h to libpng.3 and libpng-manual.txt
         Minor editing of contrib/arm-neon/README and contrib/examples/*.c
       Version 1.6.10rc01 [February 27, 2014]
         Fixed typos in the manual and in scripts/pnglibconf.dfa (CFLAGS -> CPPFLAGS
           and PNG_USR_CONFIG -> PNG_USER_CONFIG).
Commits on Feb 24, 2014
  1. Pullup tickets #4333

    schnoebe committed Feb 24, 2014
  2. Resolve the vunerability reported in PMASA-2014-1.

    schnoebe committed Feb 24, 2014
    Based on GIT commit
    RT ticket 4333.
Commits on Feb 21, 2014
  1. Pullup ticket #4332.

    tron committed Feb 21, 2014
  2. Pullup ticket #4332 - requested by obache

    tron committed Feb 21, 2014
    multimedia/adobe-flash-plugin11: security update
    Revisions pulled up:
    - multimedia/adobe-flash-plugin11/Makefile                      1.25
    - multimedia/adobe-flash-plugin11/distinfo                      1.23
       Module Name:	pkgsrc
       Committed By:	obache
       Date:		Fri Feb 21 08:50:20 UTC 2014
       Modified Files:
       	pkgsrc/multimedia/adobe-flash-plugin11: Makefile distinfo
       Log Message:
       Update adobe-flash-plugin11 to for APSB14-07.
Commits on Feb 20, 2014
  1. Pullup tickets #4330 and #4331.

    tron committed Feb 20, 2014
  2. Pullup ticket #4331 - requested by drochner

    tron committed Feb 20, 2014
    security/gnutls: security patch
    Apply patch to fix security vulnerability reported in CVE-2014-1959.