This releaes adds some bugfixes for the new changelog system, fixes
minor issues in the installer and other parts of DokuWiki, and closes
an XSS vulnerability.
PR: ports/104644
Submitted by: chinsan
Approved by: portmgr (erwin)
delphij (mentor)
- Bump PORTREVISION due to plist changes
- Remove user-modified files conf/acl.auth.php, conf/users.auth.php, and
data/changes.log from the plist. This results in data/changes.log being
reported as erroneously left behind.
PR: ports/98863
Submitted by: aaron
Reviewed by: maintainer
Approved by: maintainer, tobez (implicit)
- Update distinfo
Vendor's Announcement:
Hello again!
Just two days after the last security problem another flaw was discovered.
Luckily not as bad as the last one.
Andreas .kre Solberg discovered a security flaw which allows registered
users to view page content they usually have no access to. The problem is
in the way how a successful user profile change is handled.
This affects only installs which have Access Control Lists enabled (off by
default) and restricted the READ permission for certain pages even for
logged in users. Non-authenticated users can not exploit this bug.
The package available at http://www.splitbrain.org/go/dokuwiki was updated
again to reflect the change but fixing it manually is simple, too. Info on
how to do this is available at
http://bugs.splitbrain.org/?do=details&id=825
Andi
I request that the package be immediately rebuilt and distributed.
PR: ports/98599
Submitted by: aaron
Reviewed by: maintainer
Approved by: maintainer, tobez (implicit)
Security: http://bugs.splitbrain.org/index.php?do=details&id=825
- Bump PORTREVISION
- Change default install location
- This is a major security fix and I would ask that portmgr@ immediately
rebuild and redistribute the port's package!
PR: ports/98514
Submitted by: aaron
Approved by: secteam (simon)