pkgsrc-Changes archive

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]

CVS commit: pkgsrc/www/geeklog



Module Name:    pkgsrc
Committed By:   taca
Date:           Sun Sep 13 01:15:11 UTC 2009

Modified Files:
        pkgsrc/www/geeklog: Makefile PLIST distinfo
        pkgsrc/www/geeklog/patches: patch-aa patch-aj
Added Files:
        pkgsrc/www/geeklog/patches: patch-ak patch-al patch-ba patch-bb
            patch-bc patch-bd

Log Message:
Update Geeklog 1.5.2sr5 by adding patches since 1.5.2sr5 isn't provided
as full release.

And add updated fckeditor for Geeklog.

These updates should fix known security problems, Secunia SA36372.

Jul 30, 2009 (1.5.2sr5)
------------

This release addresses the following security issues:
- Gerendi Sandor Attila reported an XSS in the forms to email a user and to
  email a story to a friend.
- The "Mail Story to a Friend" function didn't check story permissions, so that
  it was possible to email a story even if you didn't have the permissions to
  view it on the site.


To generate a diff of this commit:
cvs rdiff -u -r1.22 -r1.23 pkgsrc/www/geeklog/Makefile
cvs rdiff -u -r1.9 -r1.10 pkgsrc/www/geeklog/PLIST \
    pkgsrc/www/geeklog/distinfo
cvs rdiff -u -r1.3 -r1.4 pkgsrc/www/geeklog/patches/patch-aa
cvs rdiff -u -r1.1 -r1.2 pkgsrc/www/geeklog/patches/patch-aj
cvs rdiff -u -r0 -r1.1 pkgsrc/www/geeklog/patches/patch-ak \
    pkgsrc/www/geeklog/patches/patch-al pkgsrc/www/geeklog/patches/patch-ba \
    pkgsrc/www/geeklog/patches/patch-bb pkgsrc/www/geeklog/patches/patch-bc \
    pkgsrc/www/geeklog/patches/patch-bd

Please note that diffs are not public domain; they are subject to the
copyright notices on the relevant files.



Home | Main Index | Thread Index | Old Index