diff options
author | edwin <edwin@FreeBSD.org> | 2005-12-21 04:52:18 +0800 |
---|---|---|
committer | edwin <edwin@FreeBSD.org> | 2005-12-21 04:52:18 +0800 |
commit | 872c18f9f7592936c8656aa80a8c97031e59f845 (patch) | |
tree | b18a0b3d880552f1ee26e60ead70acc2dff1e5e8 /www/mediawiki/Makefile | |
parent | 2f0c5517ca2ef704255e2873190ac44efceae6bc (diff) | |
download | freebsd-ports-gnome-872c18f9f7592936c8656aa80a8c97031e59f845.tar.gz freebsd-ports-gnome-872c18f9f7592936c8656aa80a8c97031e59f845.tar.zst freebsd-ports-gnome-872c18f9f7592936c8656aa80a8c97031e59f845.zip |
www/mediawiki update to 1.5.3 (security update)
Fixes a security issue: Validation of the user language
option was broken by a code change in May 2005, opening the
possibility of remote code execution as this parameter is
used in forming a class name dynamically created with eval().
The validation has been corrected in this version. All
prior 1.5 release and prelease versions are affected; 1.4
and earlier and not affected.
PR: ports/90335
Submitted by: Thomas Vogt <thomas@bsdunix.ch>
Approved by: maintainer timeout
Diffstat (limited to 'www/mediawiki/Makefile')
-rw-r--r-- | www/mediawiki/Makefile | 2 |
1 files changed, 1 insertions, 1 deletions
diff --git a/www/mediawiki/Makefile b/www/mediawiki/Makefile index d42624bdd984..add085f2e813 100644 --- a/www/mediawiki/Makefile +++ b/www/mediawiki/Makefile @@ -6,7 +6,7 @@ # PORTNAME= mediawiki -PORTVERSION= 1.5.2 +PORTVERSION= 1.5.3 CATEGORIES= www MASTER_SITES= ${MASTER_SITE_SOURCEFORGE} MASTER_SITE_SUBDIR= wikipedia |