summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorAlex Legler <a3li@gentoo.org>2010-03-05 13:03:22 +0000
committerAlex Legler <a3li@gentoo.org>2010-03-05 13:03:22 +0000
commita2d6650c04e38d2b1e030a0a0b2258ce1ce1e74d (patch)
tree4fa4820ba419a80788189c5c9284f99fb530217a /www-apps
parentstable x86, security bug 304147 (diff)
downloadhistorical-a2d6650c04e38d2b1e030a0a0b2258ce1ce1e74d.tar.gz
historical-a2d6650c04e38d2b1e030a0a0b2258ce1ce1e74d.tar.bz2
historical-a2d6650c04e38d2b1e030a0a0b2258ce1ce1e74d.zip
Non-maintainer commit: Version bumps for security bugs 307811, 300199, 238571.
Package-Manager: portage-2.2_rc63/cvs/Linux x86_64
Diffstat (limited to 'www-apps')
-rw-r--r--www-apps/drupal/ChangeLog13
-rw-r--r--www-apps/drupal/Manifest20
-rw-r--r--www-apps/drupal/drupal-5.22.ebuild (renamed from www-apps/drupal/drupal-5.21.ebuild)12
-rw-r--r--www-apps/drupal/drupal-6.16.ebuild (renamed from www-apps/drupal/drupal-6.15.ebuild)13
-rw-r--r--www-apps/drupal/files/postinstall-en.txt9
5 files changed, 51 insertions, 16 deletions
diff --git a/www-apps/drupal/ChangeLog b/www-apps/drupal/ChangeLog
index 5ab5dd7974b6..71b9716f05a8 100644
--- a/www-apps/drupal/ChangeLog
+++ b/www-apps/drupal/ChangeLog
@@ -1,6 +1,15 @@
# ChangeLog for www-apps/drupal
-# Copyright 1999-2009 Gentoo Foundation; Distributed under the GPL v2
-# $Header: /var/cvsroot/gentoo-x86/www-apps/drupal/ChangeLog,v 1.62 2009/12/18 20:16:07 alexxy Exp $
+# Copyright 1999-2010 Gentoo Foundation; Distributed under the GPL v2
+# $Header: /var/cvsroot/gentoo-x86/www-apps/drupal/ChangeLog,v 1.63 2010/03/05 13:03:22 a3li Exp $
+
+*drupal-6.16 (05 Mar 2010)
+*drupal-5.22 (05 Mar 2010)
+
+ 05 Mar 2010; Alex Legler <a3li@gentoo.org> -drupal-5.21.ebuild,
+ +drupal-5.22.ebuild, -drupal-6.15.ebuild, +drupal-6.16.ebuild,
+ files/postinstall-en.txt:
+ Non-maintainer commit: Version bumps for security bugs 307811, 300199,
+ 238571.
*drupal-6.15 (18 Dec 2009)
*drupal-5.21 (18 Dec 2009)
diff --git a/www-apps/drupal/Manifest b/www-apps/drupal/Manifest
index c47b0309904a..ab0348696c88 100644
--- a/www-apps/drupal/Manifest
+++ b/www-apps/drupal/Manifest
@@ -1,17 +1,17 @@
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
-AUX postinstall-en.txt 501 RMD160 c5e116848f3c1dc5b51d2f3b81911f5569119f2e SHA1 2dc808031b46939f115769f8f36f28eefb1e3d75 SHA256 83e41dae36c0d98540d0d4599eed0fc2ad6f1aa2815ca2454e5cb6307a9d3fcd
-DIST drupal-5.21.tar.gz 767162 RMD160 e01121759dbcbe396ba0063e611519e07cce299a SHA1 a361c7e0259f30994ff47c7f363711df2cd12793 SHA256 6c71b091915afa562896235a3fa3d4167e1510dcdbc810dcf7998500b00b6057
-DIST drupal-6.15.tar.gz 1085634 RMD160 146709dd487fa6a0d1cb39d1a79c7f7519f73643 SHA1 5be5ebf85c9ffa33e71c5a0f05d1308d3af19ab8 SHA256 eff5f840ebc104698846e9a1b3977829ca65c8a4ff892f4656790584225bf9a1
-EBUILD drupal-5.21.ebuild 1240 RMD160 62f89d04e294aa82e141d54af2679798ddaa8c35 SHA1 446e66f63dd89514a47107fde5a385c128c9973f SHA256 d936014129283c854a61b5f8858c1add7780ebc79182d11fe90e7075533f3783
-EBUILD drupal-6.15.ebuild 1553 RMD160 4f2c3b9c6218d3dc07a6ca71862bfb025f725838 SHA1 fa7cae9ef5ac43e7f454d5f25fc2a390bc77986e SHA256 6f572c454b7c4b5a3cde8a130e8af87041a30d483b5523f8bb42d012380bc86c
-MISC ChangeLog 10012 RMD160 6f3aa98c36b9c136f73bd47cdcbc33ec7f93bc77 SHA1 36bd6161a9cad4a4212995f3c1d4c4b78bf641c9 SHA256 dafe62eb18de3fd8c8d569db0519e45ef2539b2a57c49b6139bdda812c766de9
+AUX postinstall-en.txt 830 RMD160 f31ca807facccbbc5274b99d7b31be69cbcd5ea2 SHA1 68778191a89da1a357593396e2d3c3dc1c5fb5bd SHA256 1995a3fe6950f236d590d12f94ad70a41b7e3e849850395c8568e3ee8516897b
+DIST drupal-5.22.tar.gz 768157 RMD160 fcec6b3e9609ed4de5f83b909733ea586aa757d5 SHA1 32e8d4dbaf6dee6841b2ea8496535ca0ebe1ebd9 SHA256 8dff3bce3de1aa1289cc65e61d1a02a503bbcdf76fb64b56cec85c612bd99514
+DIST drupal-6.16.tar.gz 1090616 RMD160 2d8579d76bc06c623fdad88c30b8aebf48bd88d7 SHA1 90db81b6f4b9b0514c9cdd1338f344492beb5477 SHA256 1ad0cb1b3b99e19d3f433409f7418bce3f2e4ea6fee7ac4e5a35837cd948b613
+EBUILD drupal-5.22.ebuild 1451 RMD160 cbbf8771808bdf0ab3abcc8110c3f12090c18165 SHA1 c8e452aaa11fddb937852766e7c493fa91943cf4 SHA256 e4f857dc3eefbaca8b6b8980092b77cd956b4e398e1a0a9014fe3688e039cb37
+EBUILD drupal-6.16.ebuild 1765 RMD160 83f69e82955c654cb36a7b394a151617e99b6d14 SHA1 ec9648a3e957cf0c7f164171cf55f5e7d1d2dc67 SHA256 cfcdae8afe9b182dbb51e3fd81857567f030b0d0b72ae1ee94be518f8b7255c9
+MISC ChangeLog 10308 RMD160 4d095cfaaca8fe9183d6c1f4db426536c5336e05 SHA1 71dc40da5983de169c3067d557eba9f06d9b6da8 SHA256 e21769dbc32059ce0e01bbefdcbebf41806d7ed1df6b3933875f7c0a0c0843f0
MISC metadata.xml 162 RMD160 ece93b69f0e3148e7f73f6ccbde8555665c34be5 SHA1 49168d414be17b0cc9cf29ca70eb19c6754d0853 SHA256 43c8abb1bfcf55dc16e273c011f146d11197054559a26da3500c9b454ceeed40
-----BEGIN PGP SIGNATURE-----
-Version: GnuPG v2.0.13 (GNU/Linux)
+Version: GnuPG v2.0.14 (GNU/Linux)
-iEYEARECAAYFAksr4yIACgkQ5BmOA85PVLjFLgCfRmQ4n5MUwEIPgufuCLmTiOug
-C+YAn0aNhIjHT9H2PXqb/g/31MlRbEHr
-=WfSC
+iEYEARECAAYFAkuRASkACgkQ+tgfDpkAy6AkzwCfZ4Ql5AHFAhpiQfN3K9ogg0MQ
+bjEAmgKEkmGIcvEVrpCE4ekcQRYAB02H
+=XLc7
-----END PGP SIGNATURE-----
diff --git a/www-apps/drupal/drupal-5.21.ebuild b/www-apps/drupal/drupal-5.22.ebuild
index 4693e1a93756..9e6d99c96460 100644
--- a/www-apps/drupal/drupal-5.21.ebuild
+++ b/www-apps/drupal/drupal-5.22.ebuild
@@ -1,6 +1,6 @@
-# Copyright 1999-2009 Gentoo Foundation
+# Copyright 1999-2010 Gentoo Foundation
# Distributed under the terms of the GNU General Public License v2
-# $Header: /var/cvsroot/gentoo-x86/www-apps/drupal/drupal-5.21.ebuild,v 1.1 2009/12/18 20:16:07 alexxy Exp $
+# $Header: /var/cvsroot/gentoo-x86/www-apps/drupal/drupal-5.22.ebuild,v 1.1 2010/03/05 13:03:22 a3li Exp $
inherit webapp eutils depend.php
@@ -49,3 +49,11 @@ src_install() {
webapp_src_install
}
+
+pkg_postinst() {
+ ewarn
+ ewarn "SECURITY NOTICE"
+ ewarn "If you plan on using SSL on your Drupal site, please consult the postinstall information:"
+ ewarn "\t# webapp-config --show-postinst ${PN} ${PV}"
+ ewarn
+}
diff --git a/www-apps/drupal/drupal-6.15.ebuild b/www-apps/drupal/drupal-6.16.ebuild
index 68f5d459043d..76928b1ed431 100644
--- a/www-apps/drupal/drupal-6.15.ebuild
+++ b/www-apps/drupal/drupal-6.16.ebuild
@@ -1,6 +1,6 @@
-# Copyright 1999-2009 Gentoo Foundation
+# Copyright 1999-2010 Gentoo Foundation
# Distributed under the terms of the GNU General Public License v2
-# $Header: /var/cvsroot/gentoo-x86/www-apps/drupal/drupal-6.15.ebuild,v 1.1 2009/12/18 20:16:07 alexxy Exp $
+# $Header: /var/cvsroot/gentoo-x86/www-apps/drupal/drupal-6.16.ebuild,v 1.1 2010/03/05 13:03:22 a3li Exp $
inherit webapp eutils depend.php
@@ -54,3 +54,12 @@ src_install() {
webapp_src_install
}
+
+pkg_postinst() {
+ ewarn
+ ewarn "SECURITY NOTICE"
+ ewarn "If you plan on using SSL on your Drupal site, please consult the postinstall information:"
+ ewarn "\t# webapp-config --show-postinst ${PN} ${PV}"
+ ewarn
+}
+
diff --git a/www-apps/drupal/files/postinstall-en.txt b/www-apps/drupal/files/postinstall-en.txt
index 54ff3320f14b..95ac8287a64e 100644
--- a/www-apps/drupal/files/postinstall-en.txt
+++ b/www-apps/drupal/files/postinstall-en.txt
@@ -13,4 +13,13 @@ http://${VHOST_HOSTNAME}/${VHOST_APPDIR}
and provide the credential required for the database access.
+SECURITY NOTICE: If you use SSL on your Drupal installation, you
+should enable the PHP configuration option `session.cookie-secure'
+to make it harder for attackers to sniff session cookies.
+
+References:
+CVE-2008-3661
+http://www.php.net/manual/en/session.configuration.php#ini.session.cookie-secure
+http://drupal.org/node/315703
+
After that you can start to use drupal.