From nobody Wed Jul 05 06:02:42 2023 X-Original-To: dev-commits-ports-all@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4Qwpwf31sBz4lRlZ; Wed, 5 Jul 2023 06:02:42 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from mxrelay.nyi.freebsd.org (mxrelay.nyi.freebsd.org [IPv6:2610:1c1:1:606c::19:3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mxrelay.nyi.freebsd.org", Issuer "R3" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id 4Qwpwf2b9nz4bkn; Wed, 5 Jul 2023 06:02:42 +0000 (UTC) (envelope-from git@FreeBSD.org) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1688536962; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=KxA/wnaE05M4bpqG+HS4avOBgTMjsdqjzMeZ8MdYe/U=; b=HVdsQGH55Ue2z1ZrEP5qL2J701UE2scYQ+UMXxGMRuKEXq9drkcIfQXDAGaEWoYQa5YByK PWJ4mu6l1iVrxt2OsWbrgTUIksewln8sdXd6ZFJk1jkGFCjQGCKyzHodzAg5xX/yTBN/n+ zBX0YLD9hAdMBwmENeOiESHPvSkOWO+k1Wkn1AFCV8GfrGHOY5viGAC+kmyllSFBw0Gsnk jYfpGLDiev2ofw7524dBhUrtvxUuEygwSeLOqkwZTuoDPMw4TkDgO/FzKnNuUqMo1LFCMP GXZX+qqNQRor/Tamfg0AeJoHx2sXNAvF9s7UjL3CwDVkWkfpeS09RBNUrFSlew== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1688536962; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=KxA/wnaE05M4bpqG+HS4avOBgTMjsdqjzMeZ8MdYe/U=; b=mxRXCm2eCAyVu3S46GH9c1VotyDdI3GTokCaYW6hl1KHTmk/775/wn4weu+33ofW4QztXS yjpvUtfocx9PwnRi0RaFu9hyS8xPLwvajwJ2ZPDK9jSY47DDB+cjcj5wjXtU14t2MSZcgz kV2HxSt8T979u1TrHi0QVL7clqXGSeOr6PZIwfv193AF7/l5rt9sYflEVOxMMTPiSAa7UL FAdz/SKRYmUowfNiWGmWQHdKT3mRMbBqnGrUKWpsWKCPN/keZoOu6lvewemM4L5OQ7/47+ /9DkVeJRnHpENCeNQauWBMpvhqxqtMcQnuDfj0kdeeRuXUPGzyzGIkn5LMIcNA== ARC-Authentication-Results: i=1; mx1.freebsd.org; none ARC-Seal: i=1; s=dkim; d=freebsd.org; t=1688536962; a=rsa-sha256; cv=none; b=LnEpupR/ThJwO9N3OHQ9KyA9gyEc262mqe9I/jnJR+Cqa0BAd7i1n+FVBWkdLU8xHmI2so sYgO6e5E3dfb0v2WnaSSb0TWcB3NQfP9LLRpZnkWGePTVO1XsfM7PxJvBuBXO0rqYE+1Vp TWDXsJLFFxaKGepru9vnBvvLXPMHJaSb6AjsxpZgH/O5uamfUUtVBqJvzucgd8xMclGDXe asptfKH6m0F0EWCaYt5M5ZsMVWVqApYHKt2/ciAtB5d7z9n+/uYLxFNGxM9alTa5H8fHe5 hOAyDeKkUz/TNpuyv3Q7SI+khn1766igNB6C+uCooJM51ihkP711Unx9k0X1ag== Received: from gitrepo.freebsd.org (gitrepo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:5]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (Client did not present a certificate) by mxrelay.nyi.freebsd.org (Postfix) with ESMTPS id 4Qwpwf1fk9z13lC; Wed, 5 Jul 2023 06:02:42 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from gitrepo.freebsd.org ([127.0.1.44]) by gitrepo.freebsd.org (8.17.1/8.17.1) with ESMTP id 36562gRd076967; Wed, 5 Jul 2023 06:02:42 GMT (envelope-from git@gitrepo.freebsd.org) Received: (from git@localhost) by gitrepo.freebsd.org (8.17.1/8.17.1/Submit) id 36562gkx076966; Wed, 5 Jul 2023 06:02:42 GMT (envelope-from git) Date: Wed, 5 Jul 2023 06:02:42 GMT Message-Id: <202307050602.36562gkx076966@gitrepo.freebsd.org> To: ports-committers@FreeBSD.org, dev-commits-ports-all@FreeBSD.org, dev-commits-ports-branches@FreeBSD.org From: =?utf-8?Q?Fernando=20Apestegu=C3=ADa?= Subject: git: beb4ec30ad06 - 2023Q3 - net/phpldapadmin: update to 1.2.6.6 List-Id: Commit messages for all branches of the ports repository List-Archive: https://lists.freebsd.org/archives/dev-commits-ports-all List-Help: List-Post: List-Subscribe: List-Unsubscribe: Sender: owner-dev-commits-ports-all@freebsd.org X-BeenThere: dev-commits-ports-all@freebsd.org MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 8bit X-Git-Committer: fernape X-Git-Repository: ports X-Git-Refname: refs/heads/2023Q3 X-Git-Reftype: branch X-Git-Commit: beb4ec30ad06f9bc733a1d407191e695a73d83d8 Auto-Submitted: auto-generated X-ThisMailContainsUnwantedMimeParts: N The branch 2023Q3 has been updated by fernape: URL: https://cgit.FreeBSD.org/ports/commit/?id=beb4ec30ad06f9bc733a1d407191e695a73d83d8 commit beb4ec30ad06f9bc733a1d407191e695a73d83d8 Author: Krzysztof AuthorDate: 2023-07-04 06:10:46 +0000 Commit: Fernando ApesteguĂ­a CommitDate: 2023-07-05 06:02:03 +0000 net/phpldapadmin: update to 1.2.6.6 ChangeLog: https://github.com/leenooks/phpLDAPadmin/compare/1.2.6.5...1.2.6.6 Another fix for CVE-2020-35132. PR: 272348 Reported by: ports@bsdserwis.com (maintainer) MFH: 2023Q3 (security fix) Security: CVE-2020-35132 (cherry picked from commit 61cfb3cbfa0279361042afb790b5722a1a88fd04) --- net/phpldapadmin/Makefile | 2 +- net/phpldapadmin/distinfo | 6 +- .../files/patch-lib_import__functions.php | 79 ++++++++++++++++++++++ 3 files changed, 83 insertions(+), 4 deletions(-) diff --git a/net/phpldapadmin/Makefile b/net/phpldapadmin/Makefile index 20ddb167b609..046e144d3cae 100644 --- a/net/phpldapadmin/Makefile +++ b/net/phpldapadmin/Makefile @@ -1,5 +1,5 @@ PORTNAME= phpldapadmin -PORTVERSION= 1.2.6.5 +DISTVERSION= 1.2.6.6 CATEGORIES= net www PKGNAMESUFFIX= ${PHP_PKGNAMESUFFIX} diff --git a/net/phpldapadmin/distinfo b/net/phpldapadmin/distinfo index dd8beb5b6259..68ac35333cef 100644 --- a/net/phpldapadmin/distinfo +++ b/net/phpldapadmin/distinfo @@ -1,3 +1,3 @@ -TIMESTAMP = 1676551762 -SHA256 (leenooks-phpLDAPadmin-1.2.6.5_GH0.tar.gz) = 882a508029cfa0e42a3a6700f1548b477b135ecb2d4fef9bf63ea8d781ea22c1 -SIZE (leenooks-phpLDAPadmin-1.2.6.5_GH0.tar.gz) = 1132582 +TIMESTAMP = 1688152341 +SHA256 (leenooks-phpLDAPadmin-1.2.6.6_GH0.tar.gz) = 7a8c02a611e60aa6713d1cf863dfac9637e23c3f4d401ea5e47dbe2b22d4895a +SIZE (leenooks-phpLDAPadmin-1.2.6.6_GH0.tar.gz) = 1132820 diff --git a/net/phpldapadmin/files/patch-lib_import__functions.php b/net/phpldapadmin/files/patch-lib_import__functions.php new file mode 100644 index 000000000000..af887114593e --- /dev/null +++ b/net/phpldapadmin/files/patch-lib_import__functions.php @@ -0,0 +1,79 @@ +--- lib/import_functions.php.orig 2023-04-01 13:46:16 UTC ++++ lib/import_functions.php +@@ -255,7 +255,7 @@ class ImportLDIF extends Import { + if (substr($value,0,1) == ':') + $value = base64_decode(trim(substr($value,1))); + else +- $value = trim($value); ++ $value = trim((string) $value); + + return array($attr,$value); + } +@@ -271,7 +271,7 @@ class ImportLDIF extends Import { + + if ($this->hasMoreEntries() && ! $this->eof()) { + # The first line is the DN one +- $current[0]= trim($this->_currentLine); ++ $current[0]= trim((string) $this->_currentLine); + + # While we end on a blank line, fetch the attribute lines + $count = 0; +@@ -282,11 +282,11 @@ class ImportLDIF extends Import { + /* If the next line begin with a space, we append it to the current row + * else we push it into the array (unwrap)*/ + if ($this->isWrappedLine()) +- $current[$count] .= trim($this->_currentLine); ++ $current[$count] .= trim((string) $this->_currentLine); + elseif ($this->isCommentLine()) {} + # Do nothing + elseif (! $this->isBlankLine()) +- $current[++$count] = trim($this->_currentLine); ++ $current[++$count] = trim((string) $this->_currentLine); + else + $endEntryFound = true; + } +@@ -336,7 +336,7 @@ class ImportLDIF extends Import { + * @return boolean true if it's a comment line,false otherwise + */ + private function isCommentLine() { +- return substr(trim($this->_currentLine),0,1) == '#' ? true : false; ++ return substr(trim((string) $this->_currentLine),0,1) == '#' ? true : false; + } + + /** +@@ -354,7 +354,7 @@ class ImportLDIF extends Import { + * @return boolean if it is a blank line,false otherwise. + */ + private function isBlankLine() { +- return(trim($this->_currentLine) == '') ? true : false; ++ return(trim((string) $this->_currentLine) == '') ? true : false; + } + + /** +@@ -386,7 +386,7 @@ class ImportLDIF extends Import { + $url = trim(substr($value,1)); + + if (preg_match('^file://',$url)) { +- $filename = substr(trim($url),7); ++ $filename = substr(trim((string) $url),7); + + if ($fh = @fopen($filename,'rb')) { + if (! $return = @fread($fh,filesize($filename))) +@@ -480,7 +480,7 @@ class ImportLDIF extends Import { + # Fetch the attribute for the following line + $currentLine = array_shift($lines); + +- while ($processline && trim($currentLine) && (trim($currentLine) != '-')) { ++ while ($processline && trim((string) $currentLine) && (trim((string) $currentLine) != '-')) { + $processline = false; + + # If there is a valid line +@@ -541,7 +541,7 @@ class ImportLDIF extends Import { + array_merge(array($currentLine),$lines)); + + $currentLine = array_shift($lines); +- if (trim($currentLine)) ++ if (trim((string) $currentLine)) + $processline = true; + } +