diff options
author | edwin <edwin@FreeBSD.org> | 2005-12-20 20:52:18 +0000 |
---|---|---|
committer | edwin <edwin@FreeBSD.org> | 2005-12-20 20:52:18 +0000 |
commit | 872c18f9f7592936c8656aa80a8c97031e59f845 (patch) | |
tree | b18a0b3d880552f1ee26e60ead70acc2dff1e5e8 /www/mediawiki17 | |
parent | 2f0c5517ca2ef704255e2873190ac44efceae6bc (diff) | |
download | FreeBSD-ports-872c18f9f7592936c8656aa80a8c97031e59f845.zip FreeBSD-ports-872c18f9f7592936c8656aa80a8c97031e59f845.tar.gz |
www/mediawiki update to 1.5.3 (security update)
Fixes a security issue: Validation of the user language
option was broken by a code change in May 2005, opening the
possibility of remote code execution as this parameter is
used in forming a class name dynamically created with eval().
The validation has been corrected in this version. All
prior 1.5 release and prelease versions are affected; 1.4
and earlier and not affected.
PR: ports/90335
Submitted by: Thomas Vogt <thomas@bsdunix.ch>
Approved by: maintainer timeout
Diffstat (limited to 'www/mediawiki17')
-rw-r--r-- | www/mediawiki17/Makefile | 2 | ||||
-rw-r--r-- | www/mediawiki17/distinfo | 5 |
2 files changed, 4 insertions, 3 deletions
diff --git a/www/mediawiki17/Makefile b/www/mediawiki17/Makefile index d42624b..add085f 100644 --- a/www/mediawiki17/Makefile +++ b/www/mediawiki17/Makefile @@ -6,7 +6,7 @@ # PORTNAME= mediawiki -PORTVERSION= 1.5.2 +PORTVERSION= 1.5.3 CATEGORIES= www MASTER_SITES= ${MASTER_SITE_SOURCEFORGE} MASTER_SITE_SUBDIR= wikipedia diff --git a/www/mediawiki17/distinfo b/www/mediawiki17/distinfo index 8543e69..2c1c183 100644 --- a/www/mediawiki17/distinfo +++ b/www/mediawiki17/distinfo @@ -1,2 +1,3 @@ -MD5 (mediawiki-1.5.2.tar.gz) = 3aedde46937494bc21a5e493ea6a8ffd -SIZE (mediawiki-1.5.2.tar.gz) = 2290374 +MD5 (mediawiki-1.5.3.tar.gz) = fc697787f04208d1842a2c646deca626 +SHA256 (mediawiki-1.5.3.tar.gz) = 0f9620901d652452768ce309bae9ebdf5f1593efb749845f9a78d0a8b63e793a +SIZE (mediawiki-1.5.3.tar.gz) = 2287061 |