From nobody Tue Jul 04 15:15:47 2023 X-Original-To: dev-commits-ports-main@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4QwRFH3cPWz4lx5F; Tue, 4 Jul 2023 15:15:47 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from mxrelay.nyi.freebsd.org (mxrelay.nyi.freebsd.org [IPv6:2610:1c1:1:606c::19:3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mxrelay.nyi.freebsd.org", Issuer "R3" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id 4QwRFH2yn3z3xcT; Tue, 4 Jul 2023 15:15:47 +0000 (UTC) (envelope-from git@FreeBSD.org) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1688483747; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=MbZ1DRZ7F6PTjwA4QI4ngyMJKMXYCZpWmmQ4C/FO10o=; b=dV7H96G9ekkigqjAF5dCHuNiPiZMuLYHbVc4KY5VHQZJOoutnYuCZZ/85IsQkBfIrgCY10 JitTYj6uZwwyNAT8crQ/phIbUR3oHneQM1uxPnlFEJKfOAO+UAPGxG4o4r+nV46wFHLyLy O8nqkchMX0g2X9ZNDXlA3P+n5jJm3hhNxeHiz+EDS3BAQTJA2AHi0QvmDBBlPduETF3twP 37Ku67EY3lSaoRUVhBtQtxKmj3PaIjBMW4Kql7iPlPPx88NY2QGHTX7KJNAcRpaa24G07R SWCWAlGrrp6VNXvEA8wFkJ95cTD1SfZMMNo5ElX1TyQQJx8L/9DQxbgBaqvTeA== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1688483747; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=MbZ1DRZ7F6PTjwA4QI4ngyMJKMXYCZpWmmQ4C/FO10o=; b=ZxKSXlm/aCdwzn6GV3IZSGHORcaTjbyOiPVvhTDz62+s/3YTl+yZFQIscBM+wnuG5SLC54 VeGwWEh6SQT1Byah8S0m8TEU2JDsC4sbn/4xFd+AwlCxlT7Qf1q37azCL8nFf150PAZAKI 6eQf24Py91xTHTqasCV2PadlOLR0wwydJ2XsRwW6Lzd2IoqQTMwe64KuPjK3YRkicWAKIf EFbbyIPOiUR4PsqSstyE0sxjLrEmP3rID1NRMUN6uFLodPjH+PkoOY6njQHsOBJZCV/M2f 2Bnkw7PVWRFAlQ+PAtljKd4Rmf2JrClLdNeNFFfyTdt7DeB1aFBFul45wSgB2w== ARC-Authentication-Results: i=1; mx1.freebsd.org; none ARC-Seal: i=1; s=dkim; d=freebsd.org; t=1688483747; a=rsa-sha256; cv=none; b=KjiGQB9z3pX07PMVU8bY0O1LnXE0FGcOaMXwjXJ7Yi54hjpnFMQtKVyeyk44c1pYme8jjp NYDePYStCKlkFqXnJpZz+7fYJuX0GSfuwbwWZB/G/ZxD6X1rKEXDnxrWMwCgZz6LzHEZRb Elc7LDfOxB+D1yDYCo/wxJMX2MugBSwa1LNucU7/MuUbiSH5Oyr6jmMF0MR5WhkWzWjEQc ZghUZ3+85SkWOeIQcCwvmgbQ2oOHqp/Wa9YAcp2GfRr1YQVWjXjw8G+RxPt5wtPnwcNUuR nse7BCzXnNN01mpTdSm/Tjg6BQuDP+vpqYVNVJFFD8cCxN7GQvmNzb80jsRuiw== Received: from gitrepo.freebsd.org (gitrepo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:5]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (Client did not present a certificate) by mxrelay.nyi.freebsd.org (Postfix) with ESMTPS id 4QwRFH1vjLzcbs; Tue, 4 Jul 2023 15:15:47 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from gitrepo.freebsd.org ([127.0.1.44]) by gitrepo.freebsd.org (8.17.1/8.17.1) with ESMTP id 364FFlSe000137; Tue, 4 Jul 2023 15:15:47 GMT (envelope-from git@gitrepo.freebsd.org) Received: (from git@localhost) by gitrepo.freebsd.org (8.17.1/8.17.1/Submit) id 364FFls8000136; Tue, 4 Jul 2023 15:15:47 GMT (envelope-from git) Date: Tue, 4 Jul 2023 15:15:47 GMT Message-Id: <202307041515.364FFls8000136@gitrepo.freebsd.org> To: ports-committers@FreeBSD.org, dev-commits-ports-all@FreeBSD.org, dev-commits-ports-main@FreeBSD.org From: =?utf-8?Q?Fernando=20Apestegu=C3=ADa?= Subject: git: 61cfb3cbfa02 - main - net/phpldapadmin: update to 1.2.6.6 List-Id: Commits to the main branch of the FreeBSD ports repository List-Archive: https://lists.freebsd.org/archives/dev-commits-ports-main List-Help: List-Post: List-Subscribe: List-Unsubscribe: Sender: owner-dev-commits-ports-main@freebsd.org X-BeenThere: dev-commits-ports-main@freebsd.org MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 8bit X-Git-Committer: fernape X-Git-Repository: ports X-Git-Refname: refs/heads/main X-Git-Reftype: branch X-Git-Commit: 61cfb3cbfa0279361042afb790b5722a1a88fd04 Auto-Submitted: auto-generated X-ThisMailContainsUnwantedMimeParts: N The branch main has been updated by fernape: URL: https://cgit.FreeBSD.org/ports/commit/?id=61cfb3cbfa0279361042afb790b5722a1a88fd04 commit 61cfb3cbfa0279361042afb790b5722a1a88fd04 Author: Krzysztof AuthorDate: 2023-07-04 06:10:46 +0000 Commit: Fernando ApesteguĂ­a CommitDate: 2023-07-04 15:15:34 +0000 net/phpldapadmin: update to 1.2.6.6 ChangeLog: https://github.com/leenooks/phpLDAPadmin/compare/1.2.6.5...1.2.6.6 Another fix for CVE-2020-35132. PR: 272348 Reported by: ports@bsdserwis.com (maintainer) MFH: 2023Q3 (security fix) Security: CVE-2020-35132 --- net/phpldapadmin/Makefile | 2 +- net/phpldapadmin/distinfo | 6 +- .../files/patch-lib_import__functions.php | 79 ++++++++++++++++++++++ 3 files changed, 83 insertions(+), 4 deletions(-) diff --git a/net/phpldapadmin/Makefile b/net/phpldapadmin/Makefile index 20ddb167b609..046e144d3cae 100644 --- a/net/phpldapadmin/Makefile +++ b/net/phpldapadmin/Makefile @@ -1,5 +1,5 @@ PORTNAME= phpldapadmin -PORTVERSION= 1.2.6.5 +DISTVERSION= 1.2.6.6 CATEGORIES= net www PKGNAMESUFFIX= ${PHP_PKGNAMESUFFIX} diff --git a/net/phpldapadmin/distinfo b/net/phpldapadmin/distinfo index dd8beb5b6259..68ac35333cef 100644 --- a/net/phpldapadmin/distinfo +++ b/net/phpldapadmin/distinfo @@ -1,3 +1,3 @@ -TIMESTAMP = 1676551762 -SHA256 (leenooks-phpLDAPadmin-1.2.6.5_GH0.tar.gz) = 882a508029cfa0e42a3a6700f1548b477b135ecb2d4fef9bf63ea8d781ea22c1 -SIZE (leenooks-phpLDAPadmin-1.2.6.5_GH0.tar.gz) = 1132582 +TIMESTAMP = 1688152341 +SHA256 (leenooks-phpLDAPadmin-1.2.6.6_GH0.tar.gz) = 7a8c02a611e60aa6713d1cf863dfac9637e23c3f4d401ea5e47dbe2b22d4895a +SIZE (leenooks-phpLDAPadmin-1.2.6.6_GH0.tar.gz) = 1132820 diff --git a/net/phpldapadmin/files/patch-lib_import__functions.php b/net/phpldapadmin/files/patch-lib_import__functions.php new file mode 100644 index 000000000000..af887114593e --- /dev/null +++ b/net/phpldapadmin/files/patch-lib_import__functions.php @@ -0,0 +1,79 @@ +--- lib/import_functions.php.orig 2023-04-01 13:46:16 UTC ++++ lib/import_functions.php +@@ -255,7 +255,7 @@ class ImportLDIF extends Import { + if (substr($value,0,1) == ':') + $value = base64_decode(trim(substr($value,1))); + else +- $value = trim($value); ++ $value = trim((string) $value); + + return array($attr,$value); + } +@@ -271,7 +271,7 @@ class ImportLDIF extends Import { + + if ($this->hasMoreEntries() && ! $this->eof()) { + # The first line is the DN one +- $current[0]= trim($this->_currentLine); ++ $current[0]= trim((string) $this->_currentLine); + + # While we end on a blank line, fetch the attribute lines + $count = 0; +@@ -282,11 +282,11 @@ class ImportLDIF extends Import { + /* If the next line begin with a space, we append it to the current row + * else we push it into the array (unwrap)*/ + if ($this->isWrappedLine()) +- $current[$count] .= trim($this->_currentLine); ++ $current[$count] .= trim((string) $this->_currentLine); + elseif ($this->isCommentLine()) {} + # Do nothing + elseif (! $this->isBlankLine()) +- $current[++$count] = trim($this->_currentLine); ++ $current[++$count] = trim((string) $this->_currentLine); + else + $endEntryFound = true; + } +@@ -336,7 +336,7 @@ class ImportLDIF extends Import { + * @return boolean true if it's a comment line,false otherwise + */ + private function isCommentLine() { +- return substr(trim($this->_currentLine),0,1) == '#' ? true : false; ++ return substr(trim((string) $this->_currentLine),0,1) == '#' ? true : false; + } + + /** +@@ -354,7 +354,7 @@ class ImportLDIF extends Import { + * @return boolean if it is a blank line,false otherwise. + */ + private function isBlankLine() { +- return(trim($this->_currentLine) == '') ? true : false; ++ return(trim((string) $this->_currentLine) == '') ? true : false; + } + + /** +@@ -386,7 +386,7 @@ class ImportLDIF extends Import { + $url = trim(substr($value,1)); + + if (preg_match('^file://',$url)) { +- $filename = substr(trim($url),7); ++ $filename = substr(trim((string) $url),7); + + if ($fh = @fopen($filename,'rb')) { + if (! $return = @fread($fh,filesize($filename))) +@@ -480,7 +480,7 @@ class ImportLDIF extends Import { + # Fetch the attribute for the following line + $currentLine = array_shift($lines); + +- while ($processline && trim($currentLine) && (trim($currentLine) != '-')) { ++ while ($processline && trim((string) $currentLine) && (trim((string) $currentLine) != '-')) { + $processline = false; + + # If there is a valid line +@@ -541,7 +541,7 @@ class ImportLDIF extends Import { + array_merge(array($currentLine),$lines)); + + $currentLine = array_shift($lines); +- if (trim($currentLine)) ++ if (trim((string) $currentLine)) + $processline = true; + } +