pkgsrc/www/php4
adrianp 0163cb059f Update to 4.4.7
* Fixed CVE-2007-1001, GD wbmp used with invalid image size (by Ivan Fratric)
* Fixed asciiz byte truncation inside mail() (MOPB-33 by Stefan Esser)
* Fixed a bug in mb_parse_str() that can be used to activate register_globals
  (MOPB-26 by Stefan Esser)
* Fixed unallocated memory access/double free in in array_user_key_compare()
  (MOPB-24 by Stefan Esser)
* Fixed a double free inside session_regenerate_id() (MOPB-22 by Stefan Esser)
* Added missing open_basedir & safe_mode checks to zip:// and bzip:// wrappers.
  (MOPB-21 by Stefan Esser).
* Limit nesting level of input variables with max_input_nesting_level as fix for
  (MOPB-03 by Stefan Esser)
* Fixed CRLF injection inside ftp_putcmd(). (by loveshell[at]Bug.Center.Team)
* Fixed a possible super-global overwrite inside import_request_variables().
  (by Stefano Di Paola, Stefan Esser)
* Fixed a remotely trigger-able buffer overflow inside bundled libxmlrpc
  library. (by Stanislav Malyshev)
* XSS in phpinfo() (MOPB-8 by Stefan Esser)
2007-05-06 19:50:18 +00:00
..
files Add RCSid for better tracking. 2006-08-16 06:49:56 +00:00
patches Update to 4.4.7 2007-05-06 19:50:18 +00:00
buildlink3.mk Change the format of BUILDLINK_ORDER to contain depth information as well, 2006-07-08 23:10:35 +00:00
DESCR
distinfo Update to 4.4.7 2007-05-06 19:50:18 +00:00
Makefile Update to 4.4.7 2007-05-06 19:50:18 +00:00
Makefile.common Update to 4.4.7 2007-05-06 19:50:18 +00:00
Makefile.php Remove PEAR from the default PHP install 2007-05-05 21:35:05 +00:00
MESSAGE Remove PEAR from the default PHP install 2007-05-05 21:35:05 +00:00
PLIST Remove PEAR from the default PHP install 2007-05-05 21:35:05 +00:00