Commit graph

204 commits

Author SHA1 Message Date
Matthew Seaman
614df2ebae Update to 4.1.8
This is a routine bugfix relaease

ChangeLog:	  http://sourceforge.net/projects/phpmyadmin/files/phpMyAdmin/4.1.8/phpMyAdmin-4.1.8-notes.html/view
2014-02-22 22:21:50 +00:00
Matthew Seaman
e2021d50ec Update to 4.1.7
This is a routine bugfix release

ChangeLog:	  http://sourceforge.net/projects/phpmyadmin/files/phpMyAdmin/4.1.7/phpMyAdmin-4.1.7-notes.html/view
2014-02-09 18:26:02 +00:00
Matthew Seaman
be54c1c7db Update to 4.1.6
This is a routine bugfix update.

ChangeLog:	  http://sourceforge.net/projects/phpmyadmin/files/phpMyAdmin/4.1.6/phpMyAdmin-4.1.6-notes.html/download
2014-01-26 20:05:47 +00:00
Matthew Seaman
461b13f7eb Update to 4.1.5
This is a routine bugfix update.

ChangeLog:	  http://sourceforge.net/projects/phpmyadmin/files/phpMyAdmin/4.1.5/phpMyAdmin-4.1.5-notes.html/download
2014-01-17 20:34:30 +00:00
Matthew Seaman
f23cdcfb28 Update to 4.1.4
This is a routine bugfix upgrade

ChangeLog:	  http://sourceforge.net/projects/phpmyadmin/files/phpMyAdmin/4.1.4/phpMyAdmin-4.1.4-notes.html/view
2014-01-07 20:40:42 +00:00
Matthew Seaman
705358bdfe Update to 4.1.3
This is a routine bugfix update

ChangeLog:	  http://sourceforge.net/projects/phpmyadmin/files/phpMyAdmin/4.1.3/phpMyAdmin-4.1.3-notes.html/view
2013-12-31 13:24:54 +00:00
Matthew Seaman
5ac9c8c021 Fix instructions for the apache>=2.3 case
Submitted by:	starlition@tp.edu.tw
2013-12-25 09:43:15 +00:00
Matthew Seaman
330a78b248 Update to 4.1.2
- Add instructions for more recent verions of Apache to
    pkg-message (1)

Release Notes:	http://sourceforge.net/projects/phpmyadmin/files/phpMyAdmin/4.1.2/phpMyAdmin-4.1.2-notes.html/view
Submitted by:	poinsot.julien@gmail.com (1)
2013-12-23 22:58:24 +00:00
Matthew Seaman
0df3512c38 Update to 4.1.1
Routine bugfix update.

ChangeLog:	http://sourceforge.net/projects/phpmyadmin/files/phpMyAdmin/4.1.1/phpMyAdmin-4.1.1-notes.html/view
2013-12-18 08:00:47 +00:00
Matthew Seaman
0b5b6ce159 Drop the SUPHP option as the www/suphp port has expired.
General cleanup:

   pkg-install and pkg-deinstall are redundant: it's all handled by
   @exec and @unexec actions in pkg-plist.

PR:		ports/184923
Submitted by:	rene
2013-12-17 13:56:24 +00:00
Matthew Seaman
4cbc7172d6 Update to 4.1.0
With this release, the minimum required version of PHP is now php-5.3,
and the minimum compatible version of MySQL is now mysql-5.5.  See
http://docs.phpmyadmin.net/en/latest/require.html for details.

ChangeLog:	http://sourceforge.net/projects/phpmyadmin/files/phpMyAdmin/4.1.0/phpMyAdmin-4.1.0-notes.html/view
2013-12-12 22:48:04 +00:00
Bryan Drewery
77197dd811 - Chase r336083 and bump all ports using NO_ARCH so that users building
their own packages and still on pkg 1.1.4 can upgrade.

With hat:	portmgr
2013-12-10 19:47:42 +00:00
Matthew Seaman
08f342435d Mark all my architecture independent ports using shell/perl/PHP as
NO_ARCH=yes

While here, fix a few other niggles:

net/phpldapadmin -- remove indefinite article from COMMENT

www/p5-RT* -- fix comments referencing the different versions of RT

x11-fonts/gentium-{basic,plus} -- mention ${STAGEDIR} explicitly in the
  install targets; rework the handling of ${FONTPATH}
2013-12-08 22:38:52 +00:00
Matthew Seaman
687cfd015e Update to 4.0.10
A routine bugfix update.

ChangeLog:	http://sourceforge.net/projects/phpmyadmin/files/phpMyAdmin/4.0.10/phpMyAdmin-4.0.10-notes.html/download
2013-12-04 21:10:27 +00:00
Matthew Seaman
2041739da3 Upgrade to 4.0.9
- Drop LATEST_LINK
  - Apply shebangfix to a couple of shell scripts

ChangeLog:	http://sourceforge.net/projects/phpmyadmin/files/phpMyAdmin/4.0.9/phpMyAdmin-4.0.9-notes.html/view
2013-11-05 07:05:53 +00:00
Matthew Seaman
1c67fbbeac - update to 4.0.8
Change Log: http://sourceforge.net/projects/phpmyadmin/files/phpMyAdmin/4.0.8/phpMyAdmin-4.0.8-notes.html/view
2013-10-06 13:54:01 +00:00
Matthew Seaman
7a7eb0c54c - stagify
- move post-install actions into pkg-install
2013-09-27 16:08:12 +00:00
Matthew Seaman
2b21c0f8a6 Update to 4.0.7
- ChangeLog: http://sourceforge.net/projects/phpmyadmin/files/phpMyAdmin/4.0.7/phpMyAdmin-4.0.7-notes.html/view
2013-09-24 11:34:41 +00:00
Baptiste Daroussin
36117d7097 Add NO_STAGE all over the place in preparation for the staging support (cat: databases) 2013-09-20 16:13:47 +00:00
Matthew Seaman
29953f517e - Update to 4.0.6
ReleaseNotes:	http://sourceforge.net/projects/phpmyadmin/files/phpMyAdmin/4.0.6/phpMyAdmin-4.0.6-notes.html/view
2013-09-07 18:03:49 +00:00
Matthew Seaman
9aacd678d3 - Security update of databases/phpmyadmin to 4.0.5
ChangeLog: http://sourceforge.net/projects/phpmyadmin/files/phpMyAdmin/4.0.5/phpMyAdmin-4.0.5-notes.html/download
SecurityAdvisory: http://www.phpmyadmin.net/home_page/security/PMASA-2013-10.php

- Deprecate databases/phpmyadmin35

This version is vulnerable to the 'clickjacking protection bypass'
problem fixed in 4.0.5, but the development team will not be
publishing a fix. "We have no solution for 3.5.x, due to the proposed
solution requiring JavaScript. We don't want to introduce a dependency
to JavaScript in the 3.5.x family."

Therefore deprecate this port and set expiry for one month.  Please
upgrade to 4.0.5 instead.

Security:	17326fd5-fcfb-11e2-9bb9-6805ca0b3d42
2013-08-04 12:13:50 +00:00
Matthew Seaman
87373d972a Security update: multiple vulnerabilities in databases/phpmyadmin and
databases/phpmyadmin35

 - update phpmyadmin to 4.0.4.2

ChangeLog: http://sourceforge.net/projects/phpmyadmin/files/phpMyAdmin/4.0.4.2/phpMyAdmin-4.0.4.2-notes.html/view

 - update phpmyadmin35 to 3.5.8.2

ChangeLog: http://sourceforge.net/projects/phpmyadmin/files/phpMyAdmin/3.5.8.2/phpMyAdmin-3.5.8.2-notes.html/view

 - vuxml

The PMSA references shown have not been published yet, hence no CVE
numbers and a lack of detail in the descriptions.  Yes, PMSA-2013-10
is missing from the sequence.  According to the security alert e-mail:

   "For more details, see the upcoming PMASA-2013-8 to PMASA-2013-15 (minus
    PMASA-2013-10 which is reserved for a future advisory)."
2013-07-28 15:38:44 +00:00
Matthew Seaman
63cb6cc692 Security update to 4.0.4.1
ChangeLog: http://sourceforge.net/projects/phpmyadmin/files/phpMyAdmin/4.0.4.1/phpMyAdmin-4.0.4.1-notes.html/view

Advisory: http://www.phpmyadmin.net/home_page/security/PMASA-2013-7.php

Security:	1b93f6fe-e1c1-11e2-948d-6805ca0b3d42
2013-06-30 20:49:32 +00:00
Matthew Seaman
66ae9f482e Update to 4.0.4
A routine bugfix update

ChangeLog:
   http://sourceforge.net/projects/phpmyadmin/files/phpMyAdmin/4.0.4/phpMyAdmin-4.0.4-notes.html/view
2013-06-18 05:23:51 +00:00
Matthew Seaman
e9dd2fa24f Security upgrade to 4.0.3
Advisory: http://www.phpmyadmin.net/home_page/security/PMASA-2013-6.php

ChangeLog: http://sourceforge.net/projects/phpmyadmin/files/phpMyAdmin/4.0.3/phpMyAdmin-4.0.3-notes.html/view

Security:	6b97436c-ce1e-11e2-9cb2-6805ca0b3d42
2013-06-05 22:02:13 +00:00
Matthew Seaman
4207feae1f Update to 4.0.2
Routine bugfix update.

ChangeLog:

http://sourceforge.net/projects/phpmyadmin/files/phpMyAdmin/4.0.2/phpMyAdmin-4.0.2-notes.html/view
2013-05-24 18:59:56 +00:00
Matthew Seaman
49d231ced7 Update to 4.0.1
This is a routine, bugfix update.

ChangeLog: http://sourceforge.net/projects/phpmyadmin/files/phpMyAdmin/4.0.1/phpMyAdmin-4.0.1-notes.html/view
2013-05-15 18:21:28 +00:00
Martin Wilke
7c02368b0a - Remove php4 reference 2013-05-13 15:47:47 +00:00
Matthew Seaman
7ceab77300 - Copy databases/phpmyadmin to databases/phpmyadmin35
- Update databases/phpmyadmin to 4.0.0

Version 4.0.0 is the first release of a new major version, and
involves some significant changes in functionality.  In particular it
now requires Javascript in order to operate.

Provide a new phpmyadmin35 port to track the 3.5.x branch for those
not wishing to upgrade yet.  Note that you will have to adjust your
httpd.conf if you switch to this port, as it installs the application to
${LOCALBASE}/www/phpMyAdmin35
2013-05-04 06:24:53 +00:00
Matthew Seaman
5830ed7780 Security updae to 3.5.8.1
Four new serious security alerts were issued today by the phpMyAdmin
them: PMASA-2013-2 and PMASA-2013-3 are documented in this commit to
vuln.xml.

 - Remote code execution via preg_replace().

 - Locally Saved SQL Dump File Multiple File Extension Remote Code
   Execution.

The other two: PMASA-2013-4 and PMASA-2013-5 only affect PMA 4.0.0
pre-releases earlier than 4.0.0-rc3, which are not available through
the ports.
2013-04-24 20:23:16 +00:00
Matthew Seaman
6e949b86b4 Update to 3.5.8
This is a routine, bugfix release.

ChangeLog:
    http://sourceforge.net/projects/phpmyadmin/files/phpMyAdmin/3.5.8/phpMyAdmin-3.5.8-notes.html/download

Feature safe:	yes
2013-04-16 20:58:07 +00:00
Matthew Seaman
3ab133691a Upgrade to 3.5.7
This is a routine bugfix release.

ChangeLog: http://sourceforge.net/projects/phpmyadmin/files/phpMyAdmin/3.5.7/phpMyAdmin-3.5.7-notes.html/view
2013-02-15 23:09:57 +00:00
Matthew Seaman
bccfce66c3 Update to version 3.5.6
This is a routine bugfix update.

ChangeLog: http://sourceforge.net/projects/phpmyadmin/files/phpMyAdmin/3.5.6/phpMyAdmin-3.5.6-notes.html/view
2013-01-28 21:39:20 +00:00
Matthew Seaman
158ae2be38 Routine bugfix update to 3.5.5
- Release Notes: http://sourceforge.net/projects/phpmyadmin/files/phpMyAdmin/3.5.5/phpMyAdmin-3.5.5-notes.html/view
2012-12-20 18:55:05 +00:00
Matthew Seaman
61fdb056ef Update to version 3.5.4
This is a routine bugfix / new feature release.
ChangeLog: http://sourceforge.net/projects/phpmyadmin/files/phpMyAdmin/3.5.4/phpMyAdmin-3.5.4-notes.html/view

Feature safe:	yes
2012-11-20 20:58:49 +00:00
Matthew Seaman
e1fa8da4d0 Update to 3.5.3, including minor security updates.
- This is a fast-reaction patch; security advisory details to follow.

From the advisory notice:

  Welcome to phpMyAdmin 3.5.3, a bugfix release with minor security fixes
  (refer to the upcoming PMASA-2012-6 and PMASA-2012-7 for more details).

  phpMyAdmin no longer contains the Highcharts library (which caused a
  licensing problem).

  Details will appear on http://phpmyadmin.net. In a hurry? you can visit
  http://sourceforge.net/projects/phpmyadmin to download.

- ChangeLog: http://sourceforge.net/projects/phpmyadmin/files/phpMyAdmin/3.5.3/phpMyAdmin-3.5.3-notes.html/view
- Trim Makefile headers
2012-10-08 20:00:29 +00:00
Matthew Seaman
ccd03af592 - Security update to 3.5.2.2
- This is a fast-reaction patch: no details about the vulnerability
    are available yet, other than it involves XSS.
  - VuXML to follow, once the advisories are published
2012-08-12 18:59:11 +00:00
Matthew Seaman
435d1f49d5 - Security update to 3.5.2.1
- ChangeLog:

http://sourceforge.net/projects/phpmyadmin/files/phpMyAdmin/3.5.2.1/phpMyAdmin-3.5.2.1-notes.html/view

- SecurityAdvisory (to be published, eventually) PMSA-2012-3

http://www.phpmyadmin.net/home_page/security/PMASA-2012-3.php

This fixes a local path disclosure vulnerability.  Unfortunately only
the security patches are available now.  Supporting documentation, CVE
references etc. are yet to be published.  VuXML will be updated once
that is available.
2012-08-04 05:33:58 +00:00
Matthew Seaman
b64a694169 Routine bugfix update to 3.5.2
ChangeLog: http://sourceforge.net/projects/phpmyadmin/files/phpMyAdmin/3.5.2/phpMyAdmin-3.5.2-notes.html/view
2012-07-10 05:13:21 +00:00
Matthew Seaman
ce2305af67 - Convert all my remaining ports to OPTIONSng
Files	  affected:

    databases/mysql-connector-java/Makefile
    databases/phpmyadmin/Makefile
    mail/sa-utils/Makefile
    net/phpldapadmin/Makefile
    security/apg/Makefile
    textproc/sphinxsearch/Makefile
    www/p5-RT-Authen-ExternalAuth/Makefile
    www/p5-RT-Extension-LDAPImport/Makefile
    www/p5-RT-Extension-SLA/Makefile
    www/p5-RTx-Calendar/Makefile
    www/rt40/Makefile
    www/rt40/Makefile.cpan
    x11-fonts/gentium/Makefile
    x11-fonts/gentium-basic/Makefile

Approved by:	shaun (mentor)
2012-06-04 19:25:56 +00:00
Matthew Seaman
0a0e1238d1 Routine bugfix update to version 3.5.1
ChangeLog:

http://sourceforge.net/projects/phpmyadmin/files/phpMyAdmin/3.5.1/phpMyAdmin-3.5.1-notes.html/view

Approved by:	shaun (mentor)
2012-05-05 11:37:45 +00:00
Matthew Seaman
bb9914175d This one is a routine bugfix / new functionality update:
Welcome to phpMyAdmin 3.5.0; here are the major new features:

* browse-mode improvements
** grid editing
** remember recent tables
** remember last sort order by table
** flexible column width
** reorder columns
** more compact navigation bar
* AJAXification of many operations
* reorganised server status page, with server monitoring
* improved support for stored routines, events and triggers
* openGIS support
* zoom-search in table search
* Drizzle support
* improved ENUM/SET editor

Or see: http://sourceforge.net/projects/phpmyadmin/files/phpMyAdmin/3.5.0/phpMyAdmin-3.5.0-notes.html/view

Approved by:	shaun (mentor)
Feature safe:	yes
2012-04-07 15:54:46 +00:00
Matthew Seaman
234db45bce Another phpmyadmin security update.
ChangeLog:

http://sourceforge.net/projects/phpmyadmin/files/phpMyAdmin/3.4.10.2/phpMyAdmin-3.4.10.2-notes.html/download

Welcome to phpMyAdmin 3.4.10.2, a minor security release.

3.4.10.2 (2012-03-28)
- [security] Fixed local path disclosure vulnerability, see PMASA-2012-2

Advisory:

http://www.phpmyadmin.net/home_page/security/PMASA-2012-2.php

Approved by:	shaun (mentor)
Feature safe:	yes
Security:	a81161d2-790f-11e1-ac16-e0cb4e266481
2012-03-28 23:50:41 +00:00
Matthew Seaman
37035a72be Security update to 3.4.10.1
XSS in replication setup

  ChangeLog:

    Welcome to phpMyAdmin 3.4.10.1, a minor security release.

3.4.10.1 (2012-02-18)
- [security] XSS in replication setup, see PMASA-2012-1

  Security Advisory:

    http://www.phpmyadmin.net/home_page/security/PMASA-2012-1.php

Approved by:	shaun (mentor)
2012-02-18 15:00:46 +00:00
Matthew Seaman
456a51f8c0 Correct misunderstanding about mysqlnd functionality introduced in
previous commit.  mysql or mysqli drivers are required in all cases.

Approved by:	  shaun (mentor)
2012-02-15 16:42:56 +00:00
Matthew Seaman
66565d11af Routine bugfix update to 3.4.10
ChangeLog:

   http://sourceforge.net/projects/phpmyadmin/files/phpMyAdmin/3.4.10/phpMyAdmin-3.4.10-notes.html/view

3.4.10.0 (2012-02-14)
- bug #3460090 [interface] TextareaAutoSelect feature broken
- patch #3375984 [export] PHP Array export might generate invalid php code
- bug #3049209 [import] Import from ODS ignores cell that is the same as cell be
fore
- bug #3463933 [display] SELECT DISTINCT displays wrong total records found
- patch #3458944 [operations] copy table data missing SET SQL_MODE='NO_AUTO_VALU
E_ON_ZERO'
- bug #3469254 [edit] Setting data to NULL and drop-downs
- bug #3477063 [edit] Missing set fields and values in generated INSERT query
- bug #3460867 [libraries] license issue with TCPDF (updated to 5.9.145)

Other Changes:

   * Drop USE_MYSQL=compat and IGNORE_WITH_MYSQL=41 -- phpmyadmin has
     not suddenly grown compatibility for older versions of MySQL.
     However, USE_MYSQL implies an dependency on mysql-client, but
     phpmyadmin can operate just fine with only the php mysqlnd
     drivers.

   * Add a new WITH_MYSQL Options knob (off by default) -- if you want
     to use the mysql-client driver.

   * PHP52 doesn't have mysqlnd drivers, so require at least one of
     WITH_MYSQL or WITH_MYSQLI to be selected.

Approved by:	shaun (mentor)
2012-02-15 00:01:21 +00:00
Matthew Seaman
23c0a81f8a Update maintainer address to matthew@FreeBSD.org
Approved by:	shaun (mentor)
2012-02-09 17:09:51 +00:00
Xin LI
5233080d96 Add an advise to users who installs phpMyAdmin that it's better to
protect it with an additional layer.

Approved by:	maintainer
2011-12-23 09:00:42 +00:00
Doug Barton
ae9d08a0b0 This is the formal release of the fix for these securty
vulnerabilities. However the code is identical to the quick-reaction
patches in 3.4.9-rc1 other than updating the version number.

Security advisories have now been published:

http://www.phpmyadmin.net/home_page/security/PMASA-2011-19.php
http://www.phpmyadmin.net/home_page/security/PMASA-2011-20.php

CVE Numbers:

CVE-2011-4782
CVE-2011-4780

http://sourceforge.net/projects/phpmyadmin/files%2FphpMyAdmin%2F3.4.9%2FphpMyAdmin-3.4.9-notes.html/view

PR:		ports/163528
Submitted by:	Matthew Seaman <m.seaman@infracaninophile.co.uk> (maintainer)
2011-12-23 07:20:06 +00:00
Doug Barton
f4882d0189 "Welcome to the first release candidate for phpMyAdmin 3.4.9, a bugfix
release with minor security corrections.

Please refer to the upcoming PMASA-2011-19 and PMASA-2011-20
announcements on http://www.phpmyadmin.net/home_page/security.

Details will appear on http://phpmyadmin.net. In a hurry? you can visit
http://sourceforge.net/projects/phpmyadmin to download.

Marc Delisle, for the team"

ChangeLog:

3.4.9.0 (not yet released)
- bug #3442028 [edit] Inline editing enum fields with null shows no dropdown
- bug #3442004 [interface] DB suggestion not correct for user with underscore
- bug #3438420 [core] Magic quotes removed in PHP 5.4
- bug #3398788 [session] No feedback when result is empty (signon auth_type)
- bug #3384035 [display] Problems regarding ShowTooltipAliasTB
- bug #3306875 [edit] Can't rename a database that contains views
- bug #3452506 [edit] Unable to move tables with triggers
- bug #3449659 [navi] Fast filter broken with table tree
- bug #3448485 [GUI] Firefox favicon frameset regression
- [core] Better compatibility with mysql extension
- [security] Self-XSS on export options (export server/database/table), see PMASA-2011-20
- [security] Self-XSS in setup (host parameter), see PMASA-2011-19

http://sourceforge.net/projects/phpmyadmin/files/phpMyAdmin/3.4.9-rc1/phpMyAdmin-3.4.9-rc1-notes.html/download

For the port:

Switch to using lzma compressed tarballs, for a saving of about 1MB
per download.

PR:		ports/163290
Submitted by:	Matthew Seaman <m.seaman@infracaninophile.co.uk>
2011-12-16 01:43:54 +00:00