Commit graph

142 commits

Author SHA1 Message Date
Doug Barton
f21e36ff1c Bugfix and Security update to 3.4.6.r1
From the announce message:

"Welcome to the first release candidate of phpMyAdmin 3.4.6, a bugfix
release containing also fixes for minor security problems.

Details will appear on http://phpmyadmin.net. In a hurry? you can visit
http://sourceforge.net/projects/phpmyadmin to download.

Marc Delisle, for the team"

Security Advisories:

PMASA-2011-15
PMASA-2011-16

(These are not published yet...)

ChangeLog:

(http://sourceforge.net/projects/phpmyadmin/files%2FphpMyAdmin%2F3.4.6-rc1%2FphpMyAdmin-3.4.6-rc1.html/view)

Welcome to the first release candidate for phpMyAdmin 3.4.6, a bugfix release containing also fixes for minor security problems.

3.4.6.0 (not yet released)
- patch #3404173 InnoDB comment display with tooltips/aliases
- bug #3404886 [navi] Edit SQL statement after error
- bug #3403165 [interface] Collation not displayed for long enum fields
- bug #3399951 [export] Config for export compression not used
- bug #3400690 [privileges] DB-specific privileges won't submit
- bug #3410604 [config] Configuration storage incorrect suggested table name
- bug #3383572 [interface] Cannot execute saved query
- bug #3411535 [display] Full text button unchecks results display options
- bug #3411224 [display] Broken binary column when 'Show binary contents' is not set
- bug #3411633 [core] Call to undefined function PMA_isSuperuser()
- bug #3413743 [interface] Display options link missing after search
- bug #3324161 [core] CSP policy causing designer JS buttons to fail
- bug #3412862 [relation] Relations/constraints are dropped/created on every change
- bug #3390832 [display] Delete records from last page breaks search
- bug #3392150 [schema] PMA_User_Schema::processUserChoice() is broken
- bug #3414744 [core] External link fails in 3.4.5
- patch #3314626 [display] CharTextareaRows is not respected
- bug #3417089 [synchronize] Extraneous db choices
- [security] Fixed local path disclosure vulnerability, see PMASA-2011-15
- [security] Fixed XSS in setup (host/verbose parameter), see PMASA-2011-16

PR:		ports/161337
Submitted by:	Matthew Seaman <m.seaman@infracaninophile.co.uk> [maintainer]
2011-10-07 00:45:24 +00:00
Xin LI
af9ae8edb2 Document phpMyAdmin multiple XSS vulnerability.
Update phpMyAdminn to 3.4.5 release. [1]

PR:		ports/160589 [1]
Submitted by:	maitainer [1]
2011-09-14 23:26:28 +00:00
Doug Barton
56f7b60ad3 Security and bug-fix update to version 3.4.4
From the announce message:

Welcome to phpMyAdmin 3.4.4, a bugfix and security release

Please refer to the upcoming PMASA-2011-13 announcements on
http://www.phpmyadmin.net/home_page/security.

Security problem (CVE-2011-3181) is "Multiple XSS in the Tracking
feature."

ChangeLog:

http://sourceforge.net/projects/phpmyadmin/files/phpMyAdmin/3.4.4/phpMyAdmin-3.4.4.html/download

PR:		ports/160156
Submitted by:	maintainer
2011-08-24 21:04:45 +00:00
Ryan Steinmetz
3decd2cb74 Update to 3.4.3.2
PR:		ports/159143
Submitted by:	Matthew Seaman <m.seaman@infracaninophile.co.uk> [maintainer]
Approved by:	wxs (mentor)
2011-07-26 01:21:53 +00:00
Sunpoet Po-Chuan Hsieh
ba932efaa4 - Remove outmoded message
PR:		ports/158844
Submitted by:	Matthew Seaman <m.seaman@infracaninophile.co.uk>
2011-07-13 01:23:50 +00:00
Julien Laffaye
cda22804aa Update to 3.4.3.1
PR:		ports/158603
Submitted by:	Matthew Seaman <m.seaman@infracaninophile.co.uk> (maintainer)
Approved by:	bapt (mentor, implicit)
2011-07-03 11:59:52 +00:00
Frederic Culot
a505a92c47 - Update to 3.4.3
PR:		ports/158356
Submitted by:	Matthew Seaman <m.seaman@infracaninophile.co.uk> (maintainer)
2011-06-28 07:22:44 +00:00
Frederic Culot
35aef635c0 - Update to 3.4.2
PR:		ports/157699
Submitted by:	Matthew Seaman <m.seaman@infracaninophile.co.uk> (maintainer)
2011-06-08 08:43:11 +00:00
Wen Heping
521f160c83 - Update to 3.4.1
PR:		ports/157232
Submitted by:	Matthew Seaman <m.seaman@infracaninophile.co.uk> (maintainer)
2011-05-23 08:28:48 +00:00
Sylvio Cesar Teixeira
76e4168b36 - Add spl module because when installed with php-5.2.x the phpMyAdmin require the spl module.
PR:		ports/157145
Submitted by:	Matthew Seaman <m.seaman@infracaninophile.co.uk> (maintainer)
2011-05-18 13:28:35 +00:00
Frederic Culot
f7408b6a99 - Update to 3.4.0
PR:		ports/157033
Submitted by:	Matthew Seaman <m.seaman@infracaninophile.co.uk> (maintainer)
2011-05-16 14:49:33 +00:00
Frederic Culot
b45fe6b23b - Update to 3.3.10
PR:		ports/155694
Submitted by:	Matthew Seaman <m.seaman AT infracaninophile.co.uk> (maintainer)
2011-03-19 19:58:15 +00:00
Doug Barton
671274d9a3 Update to 3.3.9.2, a security release to fix the following:
http://www.phpmyadmin.net/home_page/security/PMASA-2011-2.php

Announcement-ID: PMASA-2011-2
Date: 2011-02-11

Summary
SQL query could be executed under another user.

Description
It was possible to create a bookmark which would be executed
unintentionally by other users.

Severity
We consider this vulnerability to be critical.

PR:		ports/154695
Submitted by:	me
Approved by:	maintainer
2011-02-11 20:44:11 +00:00
Martin Wilke
d4e0e31458 - Update to 3.3.9.1
PR:		154602
Submitted by:	Matthew Seaman <m.seaman@infracaninophile.co.uk> (maintainer)
Security:	http://www.phpmyadmin.net/home_page/security/PMASA-2011-1.php
2011-02-09 14:28:26 +00:00
Wen Heping
b32a923e1b - Update to 3.3.9
PR:		ports/153652
Submitted by:	Matthew Seaman <m.seaman@infracaninophile.co.uk> (maintainer)
2011-01-04 02:17:21 +00:00
Sunpoet Po-Chuan Hsieh
6a839064d8 - Update to 3.3.8.1
PR:		ports/152685
Submitted by:	Matthew Seaman <m.seaman@infracaninophile.co.uk> (maintainer)
Security:	http://www.phpmyadmin.net/home_page/security/PMASA-2010-8.php
2010-11-30 02:58:43 +00:00
Sunpoet Po-Chuan Hsieh
7480ce3673 - Update to 3.3.8
Changes:
- bug #3059311 [import] BIGINT field type added to table analysis
- [core] Update library PHPExcel to version 1.7.4
- bug #3062455 [core] copy procedures and routines before tables
- bug #3062455 [export] with SQL, export procedures and routines before tables
- bug #3056023 [import] USE query not working
- bug #3038193 [display] Error when editing row with GEOMETRY column
- bug #3062454 [interface] Display routines/events also when no tables are
  defined
- support ARIA storage engine as well as its previous name MARIA

PR:		ports/151738
Submitted by:	Matthew Seaman <m.seaman@infracaninophile.co.uk> (maintainer)
Approved by:	pgollucci (mentor, implicit)
2010-10-26 15:26:02 +00:00
Pav Lucistnik
88c593dad6 - Update to 3.3.7
PR:		ports/150374
Submitted by:	Matthew Seaman <m.seaman@infracaninophile.co.uk> (maintainer)
2010-09-09 13:40:50 +00:00
Sahil Tandon
e3c72d5924 - Update to 3.3.6
PR:		ports/150081
Submitted by:	Matthew Seaman <m.seaman@infracaninophile.co.uk> (maintainer)
2010-08-29 16:25:05 +00:00
Li-Wen Hsu
5e35568bf3 - Update to 3.3.5.1, this fixes for various XSS vulnerabilities
PR:		ports/149841
Submitted by:	Matthew Seaman <m.seaman AT infracaninophile.co.uk> (maintainer)
Security:	CVE-2010-3056
2010-08-21 12:30:56 +00:00
Martin Wilke
09d03dbea6 - Update to 3.3.5
PR:		148999
Submitted by:	Matthew Seaman <m.seaman@infracaninophile.co.uk> (maintainer)
2010-08-02 15:01:43 +00:00
Sylvio Cesar Teixeira
27a6bfafa6 - Update to 3.3.4
PR:		ports/148209
Submitted by:	Matthew Seaman <m.seaman@infracaninophile.co.uk> (maintainer)
Feature safe:	yes
2010-06-30 01:38:20 +00:00
Martin Wilke
757fa4bbc0 - Update to 3.3.3
PR:		146492
Submitted by:	Matthew Seaman <m.seaman@infracaninophile.co.uk> (maintainer)
2010-05-16 09:28:51 +00:00
Martin Wilke
dbba7c87fc - Update to 3.3.2
PR:		145689
Submitted by:	Matthew Seaman <m.seaman@infracaninophile.co.uk> (maintainer)
2010-04-17 07:13:42 +00:00
Pav Lucistnik
abdcaaab04 - Make mcrypt dependency optional
PR:		ports/144983
Submitted by:	Matthew Seaman <m.seaman@infracaninophile.co.uk> (maintainer)
2010-04-02 13:43:54 +00:00
Martin Wilke
1361749bbb - Update to 3.3.1
PR:		144789
Submitted by:	Matthew Seaman <m.seaman@infracaninophile.co.uk> (maintainer)
2010-03-20 18:56:56 +00:00
Martin Wilke
f536429d27 - Update to 3.3.0
PR:		144550
Submitted by:	Matthew Seaman <m.seaman@infracaninophile.co.uk> (maintainer)
2010-03-08 23:24:47 +00:00
Philip M. Gollucci
29456aea6e - Update to 3.2.5
PR:             ports/142572
Submitted by:   Matthew Seaman <m.seaman@infracaninophile.co.uk> (maintainer)
Changes:        http://sourceforge.net/projects/phpmyadmin/files/phpMyAdmin/3.2.5/phpMyAdmin-3.2.5-notes.html/view
2010-01-12 01:15:17 +00:00
Martin Wilke
9ce226fbd7 - Switch to using bsd.ports.options.mk
- Use USERS and GROUPS functionality , instead of supplying pkg-install
- Drop some warnings about changes that happened a long time ago now.

PR:		141801
Submitted by:	Matthew Seaman <m.seaman@infracaninophile.co.uk> (maintainer)
2009-12-22 11:48:41 +00:00
Martin Wilke
a6bcc4cb0b - Update to 3.2.4
PR:		141118
Submitted by:	Matthew Seaman <m.seaman@infracaninophile.co.uk> (maintainer)
2009-12-11 15:35:07 +00:00
Martin Wilke
2fa893ee6b - Update to 3.2.3
PR:		140123
Submitted by:	Matthew Seaman <m.seaman@infracaninophile.co.uk> (maintainer)
2009-11-02 10:54:04 +00:00
Martin Wilke
83cf35893c - Update to 3.2.2.1
PR:		139562
Submitted by:	Matthew Seaman <m.seaman@infracaninophile.co.uk> (maintainer)
Security:	http://www.vuxml.org/freebsd/4769914e-b844-11de-b159-0030843d3802.html
2009-10-13 22:25:08 +00:00
Martin Wilke
d82c7dd716 - Update to 3.2.2
PR:		138783
Submitted by:	Matthew Seaman <m.seaman@infracaninophile.co.uk> (maintainer)
2009-09-13 18:12:53 +00:00
Dmitry Marakasov
8c9b17f3f8 - Remove remaining SFP references (switch these ports to SF)
Approved by:	portmgr (pav)
2009-08-27 15:04:16 +00:00
Martin Wilke
3b033f9c90 - Update to 3.2.1
PR:		137645
Submitted by:	Matthew Seaman <m.seaman@infracaninophile.co.uk> (maintainer)
2009-08-13 15:06:40 +00:00
Xin LI
7b137cca0c Update to 3.2.0.1.
Security:	ba73f494-65a8-11de-aef5-001c2514716c
2009-06-30 19:10:53 +00:00
Martin Wilke
186a9f3e23 - Update to 3.2.0
PR:		135597
Submitted by:	Matthew Seaman <m.seaman@infracaninophile.co.uk> (maintainer)
2009-06-15 21:07:45 +00:00
Martin Wilke
6ba683c323 - Update to 3.1.5
PR:		134573
Submitted by:	Matthew Seaman <m.seaman@infracaninophile.co.uk> (maintainer)
2009-05-16 22:42:46 +00:00
Martin Wilke
91c2cb3bfd - Update to 3.1.4 [1]
- Add missing dependency [2]

PR:		134001 [1]
		133960 [2]
Submitted by:	Matthew Seaman <m.seaman@infracaninophile.co.uk> [1] (maintainer)
		Mel Flynn <mel@rachie.is-a-geek.net> [2]
2009-04-26 23:44:34 +00:00
Martin Wilke
5e9071eb83 - Update to 3.1.3.2
PR:		133729
Submitted by:	Matthew Seaman <m.seaman@infracaninophile.co.uk> (maintainer)
Approved by:	portmgr (pav)
Security:	http://www.vuxml.org/freebsd/1a0e4cc6-29bf-11de-bdeb-0030843d3802.html
2009-04-15 14:45:06 +00:00
Xin LI
4f50044cf3 Update to 3.1.3.1 and 2.11.9.5.
Submitted by:	maintainer
Security:	06f9174f-190f-11de-b2f0-001c2514716c
2009-03-25 07:44:34 +00:00
Martin Wilke
2cfdc4e1a5 - Update to 3.1.3
PR:		132195
Submitted by:	Matthew Seaman <m.seaman@infracaninophile.co.uk> (maintainer)
2009-02-28 19:46:38 +00:00
Pav Lucistnik
c899872a17 - Update to 3.1.2
PR:		ports/130750
Submitted by:	Matthew Seaman <m.seaman@infracaninophile.co.uk> (maintainer)
2009-01-20 22:18:15 +00:00
Martin Wilke
3ffccaff03 - Update to 3.1.1
PR:		129533
Submitted by:	Matthew Seaman <m.seaman@infracaninophile.co.uk> (maintainer)
Security:	http://www.vuxml.org/freebsd/54f72962-c7ba-11dd-a721-0030843d3802.html
2008-12-11 19:47:57 +00:00
Martin Wilke
228ebff813 - Update to 3.1.0
PR:		129257
Submitted by:	Matthew Seaman <m.seaman@infracaninophile.co.uk> (maintainer)
2008-11-29 20:13:08 +00:00
Martin Wilke
126e286936 - Use explicit mysql 5
PR:		128889
Reported by:	Till Klampaeckel <till@php.net>
Approved by:	maintainer
2008-11-22 22:43:10 +00:00
Xin LI
4f173ccf05 Update to 3.0.1.1.
Submitted by:	maintainer
Security:	85b0bbc8-a7a5-11dd-8283-001c2514716c
2008-10-31 23:59:29 +00:00
Martin Wilke
23f87d6559 - Update to 3.0.1
PR:		128321
Submitted by:	Matthew Seaman <m.seaman@infracaninophile.co.uk> (maintainer)
2008-10-24 12:37:15 +00:00
Martin Wilke
aa2de37e50 - Add missing dependency
PR:		128137
Submitted by:	Yi-Huan Chan <yhchan@csie.nctu.edu.tw>
Approved by:	maintainer
2008-10-17 19:48:35 +00:00
Martin Wilke
62f8f6d68f - Update to 3.0.0
PR:		127880
Submitted by:	Matthew Seaman <m.seaman@infracaninophile.co.uk> (maintainer)
2008-10-15 14:51:53 +00:00