1
0
mirror of https://git.FreeBSD.org/ports.git synced 2024-11-25 00:51:21 +00:00
Commit Graph

190 Commits

Author SHA1 Message Date
Matthew Seaman
2041739da3 Upgrade to 4.0.9
- Drop LATEST_LINK
  - Apply shebangfix to a couple of shell scripts

ChangeLog:	http://sourceforge.net/projects/phpmyadmin/files/phpMyAdmin/4.0.9/phpMyAdmin-4.0.9-notes.html/view
2013-11-05 07:05:53 +00:00
Matthew Seaman
1c67fbbeac - update to 4.0.8
Change Log: http://sourceforge.net/projects/phpmyadmin/files/phpMyAdmin/4.0.8/phpMyAdmin-4.0.8-notes.html/view
2013-10-06 13:54:01 +00:00
Matthew Seaman
7a7eb0c54c - stagify
- move post-install actions into pkg-install
2013-09-27 16:08:12 +00:00
Matthew Seaman
2b21c0f8a6 Update to 4.0.7
- ChangeLog: http://sourceforge.net/projects/phpmyadmin/files/phpMyAdmin/4.0.7/phpMyAdmin-4.0.7-notes.html/view
2013-09-24 11:34:41 +00:00
Baptiste Daroussin
36117d7097 Add NO_STAGE all over the place in preparation for the staging support (cat: databases) 2013-09-20 16:13:47 +00:00
Matthew Seaman
29953f517e - Update to 4.0.6
ReleaseNotes:	http://sourceforge.net/projects/phpmyadmin/files/phpMyAdmin/4.0.6/phpMyAdmin-4.0.6-notes.html/view
2013-09-07 18:03:49 +00:00
Matthew Seaman
9aacd678d3 - Security update of databases/phpmyadmin to 4.0.5
ChangeLog: http://sourceforge.net/projects/phpmyadmin/files/phpMyAdmin/4.0.5/phpMyAdmin-4.0.5-notes.html/download
SecurityAdvisory: http://www.phpmyadmin.net/home_page/security/PMASA-2013-10.php

- Deprecate databases/phpmyadmin35

This version is vulnerable to the 'clickjacking protection bypass'
problem fixed in 4.0.5, but the development team will not be
publishing a fix. "We have no solution for 3.5.x, due to the proposed
solution requiring JavaScript. We don't want to introduce a dependency
to JavaScript in the 3.5.x family."

Therefore deprecate this port and set expiry for one month.  Please
upgrade to 4.0.5 instead.

Security:	17326fd5-fcfb-11e2-9bb9-6805ca0b3d42
2013-08-04 12:13:50 +00:00
Matthew Seaman
87373d972a Security update: multiple vulnerabilities in databases/phpmyadmin and
databases/phpmyadmin35

 - update phpmyadmin to 4.0.4.2

ChangeLog: http://sourceforge.net/projects/phpmyadmin/files/phpMyAdmin/4.0.4.2/phpMyAdmin-4.0.4.2-notes.html/view

 - update phpmyadmin35 to 3.5.8.2

ChangeLog: http://sourceforge.net/projects/phpmyadmin/files/phpMyAdmin/3.5.8.2/phpMyAdmin-3.5.8.2-notes.html/view

 - vuxml

The PMSA references shown have not been published yet, hence no CVE
numbers and a lack of detail in the descriptions.  Yes, PMSA-2013-10
is missing from the sequence.  According to the security alert e-mail:

   "For more details, see the upcoming PMASA-2013-8 to PMASA-2013-15 (minus
    PMASA-2013-10 which is reserved for a future advisory)."
2013-07-28 15:38:44 +00:00
Matthew Seaman
63cb6cc692 Security update to 4.0.4.1
ChangeLog: http://sourceforge.net/projects/phpmyadmin/files/phpMyAdmin/4.0.4.1/phpMyAdmin-4.0.4.1-notes.html/view

Advisory: http://www.phpmyadmin.net/home_page/security/PMASA-2013-7.php

Security:	1b93f6fe-e1c1-11e2-948d-6805ca0b3d42
2013-06-30 20:49:32 +00:00
Matthew Seaman
66ae9f482e Update to 4.0.4
A routine bugfix update

ChangeLog:
   http://sourceforge.net/projects/phpmyadmin/files/phpMyAdmin/4.0.4/phpMyAdmin-4.0.4-notes.html/view
2013-06-18 05:23:51 +00:00
Matthew Seaman
e9dd2fa24f Security upgrade to 4.0.3
Advisory: http://www.phpmyadmin.net/home_page/security/PMASA-2013-6.php

ChangeLog: http://sourceforge.net/projects/phpmyadmin/files/phpMyAdmin/4.0.3/phpMyAdmin-4.0.3-notes.html/view

Security:	6b97436c-ce1e-11e2-9cb2-6805ca0b3d42
2013-06-05 22:02:13 +00:00
Matthew Seaman
4207feae1f Update to 4.0.2
Routine bugfix update.

ChangeLog:

http://sourceforge.net/projects/phpmyadmin/files/phpMyAdmin/4.0.2/phpMyAdmin-4.0.2-notes.html/view
2013-05-24 18:59:56 +00:00
Matthew Seaman
49d231ced7 Update to 4.0.1
This is a routine, bugfix update.

ChangeLog: http://sourceforge.net/projects/phpmyadmin/files/phpMyAdmin/4.0.1/phpMyAdmin-4.0.1-notes.html/view
2013-05-15 18:21:28 +00:00
Martin Wilke
7c02368b0a - Remove php4 reference 2013-05-13 15:47:47 +00:00
Matthew Seaman
7ceab77300 - Copy databases/phpmyadmin to databases/phpmyadmin35
- Update databases/phpmyadmin to 4.0.0

Version 4.0.0 is the first release of a new major version, and
involves some significant changes in functionality.  In particular it
now requires Javascript in order to operate.

Provide a new phpmyadmin35 port to track the 3.5.x branch for those
not wishing to upgrade yet.  Note that you will have to adjust your
httpd.conf if you switch to this port, as it installs the application to
${LOCALBASE}/www/phpMyAdmin35
2013-05-04 06:24:53 +00:00
Matthew Seaman
5830ed7780 Security updae to 3.5.8.1
Four new serious security alerts were issued today by the phpMyAdmin
them: PMASA-2013-2 and PMASA-2013-3 are documented in this commit to
vuln.xml.

 - Remote code execution via preg_replace().

 - Locally Saved SQL Dump File Multiple File Extension Remote Code
   Execution.

The other two: PMASA-2013-4 and PMASA-2013-5 only affect PMA 4.0.0
pre-releases earlier than 4.0.0-rc3, which are not available through
the ports.
2013-04-24 20:23:16 +00:00
Matthew Seaman
6e949b86b4 Update to 3.5.8
This is a routine, bugfix release.

ChangeLog:
    http://sourceforge.net/projects/phpmyadmin/files/phpMyAdmin/3.5.8/phpMyAdmin-3.5.8-notes.html/download

Feature safe:	yes
2013-04-16 20:58:07 +00:00
Matthew Seaman
3ab133691a Upgrade to 3.5.7
This is a routine bugfix release.

ChangeLog: http://sourceforge.net/projects/phpmyadmin/files/phpMyAdmin/3.5.7/phpMyAdmin-3.5.7-notes.html/view
2013-02-15 23:09:57 +00:00
Matthew Seaman
bccfce66c3 Update to version 3.5.6
This is a routine bugfix update.

ChangeLog: http://sourceforge.net/projects/phpmyadmin/files/phpMyAdmin/3.5.6/phpMyAdmin-3.5.6-notes.html/view
2013-01-28 21:39:20 +00:00
Matthew Seaman
158ae2be38 Routine bugfix update to 3.5.5
- Release Notes: http://sourceforge.net/projects/phpmyadmin/files/phpMyAdmin/3.5.5/phpMyAdmin-3.5.5-notes.html/view
2012-12-20 18:55:05 +00:00
Matthew Seaman
61fdb056ef Update to version 3.5.4
This is a routine bugfix / new feature release.
ChangeLog: http://sourceforge.net/projects/phpmyadmin/files/phpMyAdmin/3.5.4/phpMyAdmin-3.5.4-notes.html/view

Feature safe:	yes
2012-11-20 20:58:49 +00:00
Matthew Seaman
e1fa8da4d0 Update to 3.5.3, including minor security updates.
- This is a fast-reaction patch; security advisory details to follow.

From the advisory notice:

  Welcome to phpMyAdmin 3.5.3, a bugfix release with minor security fixes
  (refer to the upcoming PMASA-2012-6 and PMASA-2012-7 for more details).

  phpMyAdmin no longer contains the Highcharts library (which caused a
  licensing problem).

  Details will appear on http://phpmyadmin.net. In a hurry? you can visit
  http://sourceforge.net/projects/phpmyadmin to download.

- ChangeLog: http://sourceforge.net/projects/phpmyadmin/files/phpMyAdmin/3.5.3/phpMyAdmin-3.5.3-notes.html/view
- Trim Makefile headers
2012-10-08 20:00:29 +00:00
Matthew Seaman
ccd03af592 - Security update to 3.5.2.2
- This is a fast-reaction patch: no details about the vulnerability
    are available yet, other than it involves XSS.
  - VuXML to follow, once the advisories are published
2012-08-12 18:59:11 +00:00
Matthew Seaman
435d1f49d5 - Security update to 3.5.2.1
- ChangeLog:

http://sourceforge.net/projects/phpmyadmin/files/phpMyAdmin/3.5.2.1/phpMyAdmin-3.5.2.1-notes.html/view

- SecurityAdvisory (to be published, eventually) PMSA-2012-3

http://www.phpmyadmin.net/home_page/security/PMASA-2012-3.php

This fixes a local path disclosure vulnerability.  Unfortunately only
the security patches are available now.  Supporting documentation, CVE
references etc. are yet to be published.  VuXML will be updated once
that is available.
2012-08-04 05:33:58 +00:00
Matthew Seaman
b64a694169 Routine bugfix update to 3.5.2
ChangeLog: http://sourceforge.net/projects/phpmyadmin/files/phpMyAdmin/3.5.2/phpMyAdmin-3.5.2-notes.html/view
2012-07-10 05:13:21 +00:00
Matthew Seaman
ce2305af67 - Convert all my remaining ports to OPTIONSng
Files	  affected:

    databases/mysql-connector-java/Makefile
    databases/phpmyadmin/Makefile
    mail/sa-utils/Makefile
    net/phpldapadmin/Makefile
    security/apg/Makefile
    textproc/sphinxsearch/Makefile
    www/p5-RT-Authen-ExternalAuth/Makefile
    www/p5-RT-Extension-LDAPImport/Makefile
    www/p5-RT-Extension-SLA/Makefile
    www/p5-RTx-Calendar/Makefile
    www/rt40/Makefile
    www/rt40/Makefile.cpan
    x11-fonts/gentium/Makefile
    x11-fonts/gentium-basic/Makefile

Approved by:	shaun (mentor)
2012-06-04 19:25:56 +00:00
Matthew Seaman
0a0e1238d1 Routine bugfix update to version 3.5.1
ChangeLog:

http://sourceforge.net/projects/phpmyadmin/files/phpMyAdmin/3.5.1/phpMyAdmin-3.5.1-notes.html/view

Approved by:	shaun (mentor)
2012-05-05 11:37:45 +00:00
Matthew Seaman
bb9914175d This one is a routine bugfix / new functionality update:
Welcome to phpMyAdmin 3.5.0; here are the major new features:

* browse-mode improvements
** grid editing
** remember recent tables
** remember last sort order by table
** flexible column width
** reorder columns
** more compact navigation bar
* AJAXification of many operations
* reorganised server status page, with server monitoring
* improved support for stored routines, events and triggers
* openGIS support
* zoom-search in table search
* Drizzle support
* improved ENUM/SET editor

Or see: http://sourceforge.net/projects/phpmyadmin/files/phpMyAdmin/3.5.0/phpMyAdmin-3.5.0-notes.html/view

Approved by:	shaun (mentor)
Feature safe:	yes
2012-04-07 15:54:46 +00:00
Matthew Seaman
234db45bce Another phpmyadmin security update.
ChangeLog:

http://sourceforge.net/projects/phpmyadmin/files/phpMyAdmin/3.4.10.2/phpMyAdmin-3.4.10.2-notes.html/download

Welcome to phpMyAdmin 3.4.10.2, a minor security release.

3.4.10.2 (2012-03-28)
- [security] Fixed local path disclosure vulnerability, see PMASA-2012-2

Advisory:

http://www.phpmyadmin.net/home_page/security/PMASA-2012-2.php

Approved by:	shaun (mentor)
Feature safe:	yes
Security:	a81161d2-790f-11e1-ac16-e0cb4e266481
2012-03-28 23:50:41 +00:00
Matthew Seaman
37035a72be Security update to 3.4.10.1
XSS in replication setup

  ChangeLog:

    Welcome to phpMyAdmin 3.4.10.1, a minor security release.

3.4.10.1 (2012-02-18)
- [security] XSS in replication setup, see PMASA-2012-1

  Security Advisory:

    http://www.phpmyadmin.net/home_page/security/PMASA-2012-1.php

Approved by:	shaun (mentor)
2012-02-18 15:00:46 +00:00
Matthew Seaman
456a51f8c0 Correct misunderstanding about mysqlnd functionality introduced in
previous commit.  mysql or mysqli drivers are required in all cases.

Approved by:	  shaun (mentor)
2012-02-15 16:42:56 +00:00
Matthew Seaman
66565d11af Routine bugfix update to 3.4.10
ChangeLog:

   http://sourceforge.net/projects/phpmyadmin/files/phpMyAdmin/3.4.10/phpMyAdmin-3.4.10-notes.html/view

3.4.10.0 (2012-02-14)
- bug #3460090 [interface] TextareaAutoSelect feature broken
- patch #3375984 [export] PHP Array export might generate invalid php code
- bug #3049209 [import] Import from ODS ignores cell that is the same as cell be
fore
- bug #3463933 [display] SELECT DISTINCT displays wrong total records found
- patch #3458944 [operations] copy table data missing SET SQL_MODE='NO_AUTO_VALU
E_ON_ZERO'
- bug #3469254 [edit] Setting data to NULL and drop-downs
- bug #3477063 [edit] Missing set fields and values in generated INSERT query
- bug #3460867 [libraries] license issue with TCPDF (updated to 5.9.145)

Other Changes:

   * Drop USE_MYSQL=compat and IGNORE_WITH_MYSQL=41 -- phpmyadmin has
     not suddenly grown compatibility for older versions of MySQL.
     However, USE_MYSQL implies an dependency on mysql-client, but
     phpmyadmin can operate just fine with only the php mysqlnd
     drivers.

   * Add a new WITH_MYSQL Options knob (off by default) -- if you want
     to use the mysql-client driver.

   * PHP52 doesn't have mysqlnd drivers, so require at least one of
     WITH_MYSQL or WITH_MYSQLI to be selected.

Approved by:	shaun (mentor)
2012-02-15 00:01:21 +00:00
Matthew Seaman
23c0a81f8a Update maintainer address to matthew@FreeBSD.org
Approved by:	shaun (mentor)
2012-02-09 17:09:51 +00:00
Xin LI
5233080d96 Add an advise to users who installs phpMyAdmin that it's better to
protect it with an additional layer.

Approved by:	maintainer
2011-12-23 09:00:42 +00:00
Doug Barton
ae9d08a0b0 This is the formal release of the fix for these securty
vulnerabilities. However the code is identical to the quick-reaction
patches in 3.4.9-rc1 other than updating the version number.

Security advisories have now been published:

http://www.phpmyadmin.net/home_page/security/PMASA-2011-19.php
http://www.phpmyadmin.net/home_page/security/PMASA-2011-20.php

CVE Numbers:

CVE-2011-4782
CVE-2011-4780

http://sourceforge.net/projects/phpmyadmin/files%2FphpMyAdmin%2F3.4.9%2FphpMyAdmin-3.4.9-notes.html/view

PR:		ports/163528
Submitted by:	Matthew Seaman <m.seaman@infracaninophile.co.uk> (maintainer)
2011-12-23 07:20:06 +00:00
Doug Barton
f4882d0189 "Welcome to the first release candidate for phpMyAdmin 3.4.9, a bugfix
release with minor security corrections.

Please refer to the upcoming PMASA-2011-19 and PMASA-2011-20
announcements on http://www.phpmyadmin.net/home_page/security.

Details will appear on http://phpmyadmin.net. In a hurry? you can visit
http://sourceforge.net/projects/phpmyadmin to download.

Marc Delisle, for the team"

ChangeLog:

3.4.9.0 (not yet released)
- bug #3442028 [edit] Inline editing enum fields with null shows no dropdown
- bug #3442004 [interface] DB suggestion not correct for user with underscore
- bug #3438420 [core] Magic quotes removed in PHP 5.4
- bug #3398788 [session] No feedback when result is empty (signon auth_type)
- bug #3384035 [display] Problems regarding ShowTooltipAliasTB
- bug #3306875 [edit] Can't rename a database that contains views
- bug #3452506 [edit] Unable to move tables with triggers
- bug #3449659 [navi] Fast filter broken with table tree
- bug #3448485 [GUI] Firefox favicon frameset regression
- [core] Better compatibility with mysql extension
- [security] Self-XSS on export options (export server/database/table), see PMASA-2011-20
- [security] Self-XSS in setup (host parameter), see PMASA-2011-19

http://sourceforge.net/projects/phpmyadmin/files/phpMyAdmin/3.4.9-rc1/phpMyAdmin-3.4.9-rc1-notes.html/download

For the port:

Switch to using lzma compressed tarballs, for a saving of about 1MB
per download.

PR:		ports/163290
Submitted by:	Matthew Seaman <m.seaman@infracaninophile.co.uk>
2011-12-16 01:43:54 +00:00
Doug Barton
3f91066eab Update to version 3.4.8
This is the formal release of the fix to CVE-2011-4634, but there are
no code differences from the preliminary fixes released in 3.4.8-rc1
except for the updated version number.

PMSA-2011-18 has now been published; vuxml entry attached.

PR:		ports/163001
Submitted by:	Matthew Seaman <m.seaman@infracaninophile.co.uk> (maintainer)

Feature safe:	yes
2011-12-01 21:03:31 +00:00
Doug Barton
a76fc9307b Security and bugfix update to 3.4.8-rc1
Announcement:

"Welcome to the first release candidate for phpMyAdmin 3.4.8, a bugfix
release with minor security corrections.

Please refer to the upcoming PMASA-2011-18 announcement on
http://www.phpmyadmin.net/home_page/security.

Marc Delisle, for the team"

Welcome to the first release candidate for phpMyAdmin 3.4.8, a bugfix
release with minor security corrections.

3.4.8.0 (not yet released)
- bug #3425230 [interface] enum data split at space char (more space to
  edit)
- bug #3426840 [interface] ENUM/SET editor can't handle commas in values
- bug #3427256 [interface] no links to browse/empty views and tables
- bug #3430377 [interface] Deleted search results remain visible
- bug #3428627 [import] ODS import ignores memory limits
- bug #3426836 [interface] Visual column separation
- bug #3428065 [parser] TRUE not recognized by parser
+ patch #3433770 [config] Make location of php-gettext configurable
- patch #3430291 [import] Handle conflicts in some open_basedir situations
- bug #3431427 [display] Dropdown results - setting NULL does not work
- patch #3428764 [edit] Inline edit on multi-server configuration
- patch #3437354 [core] Notice: Array to string conversion in PHP 5.4
- [interface] When ShowTooltipAliasTB is true, VIEW is wrongly shown as the
  view name in main panel db Structure page
- bug #3439292 [core] Fail to synchronize column with name of keyword
- bug #3425156 [interface] Add column after drop
- [interface] Avoid showing the password in phpinfo()'s output
- bug #3441572 [GUI] 'newer version of phpMyAdmin' message not shown in IE8
- bug #3407235 [interface] Entering the key through a lookup window does not
  reset NULL
- [security] Self-XSS on database names (Synchronize), see PMASA-2011-18
- [security] Self-XSS on database names (Operations/rename), see PMASA-2011-18
- [security] Self-XSS on column type (Create index), see PMASA-2011-18
- [security] Self-XSS on column type (table Search), see PMASA-2011-18
- [security] Self-XSS on invalid query (table overview), see PMASA-2011-18

PR:		ports/162873
Submitted by:	Matthew Seaman <m.seaman@infracaninophile.co.uk> (maintainer)
Feature safe:	yes
2011-11-26 09:14:38 +00:00
Doug Barton
782fd7bd4d Security update to version 3.4.7.1
Please refer to the upcoming PMASA-2011-17 announcement on
http://www.phpmyadmin.net/home_page/security.

3.4.7.1 (2011-11-10)
- [security] Fixed possible local file inclusion in XML import
(CVE-2011-4107).

http://sourceforge.net/projects/phpmyadmin/files%2FphpMyAdmin%2F3.4.7.1%2FphpMyAdmin-3.4.7.1-notes.html/view

PR:		ports/162442
Submitted by:	Matthew Seaman <m.seaman@infracaninophile.co.uk> (maintainer)

Feature safe:	yes
2011-11-11 00:43:08 +00:00
Doug Barton
2f0ad7dced Routine bugfix upgrade to version 3.4.7
ChangeLog:

http://sourceforge.net/projects/phpmyadmin/files%2FphpMyAdmin%2F3.4.7%2FphpMyAdmin-3.4.7.html/view

Welcome to phpMyAdmin 3.4.7, a bugfix release.

3.4.7.0 (2011-10-23)
- bug #3418610 [interface] Links in navigation when $cfg['MainPageIconic'] = false
- bug #3418849 [interface] Inline edit shows dropdowns even after closing
- bug [view] View renaming did not work
- bug [navi] Wrong icon for view (MySQL 5.5)
- bug #3420229 [doc] Missing documentation section
- bug #3423725 [pdf] Broken PDF file when exporting database to PDF
- [core] Allow to set language in URL
- bug #3425184 [doc] Fix links to PHP documentation
- bug #3426031 [export] Export to bzip2 is not working

PR:		ports/161937
Submitted by:	maintainer
2011-10-24 22:36:19 +00:00
Doug Barton
7ec7e2a3cf Remove references to mysql 323 and 40, most commonly of the form:
IGNORE_WITH_MYSQL=     323 40
2011-10-17 04:35:02 +00:00
Doug Barton
925316a093 Routine update to 3.4.6 release version. Note: despite the discussion
of security fixes in the announcement message and changelog, all of
the fixes were already applied in the previous port update (to
3.4.6-rc1). In fact, diff'ing the distfile tarballs between 3.4.6-rc1
and 3.4.6 shows that the only change is to update the version number.

Announcement message:

"Welcome to phpMyAdmin 3.4.6, a bugfix and minor security release.

Please refer to the upcoming PMASA-2011-15 and -16 announcements on
http://www.phpmyadmin.net/home_page/security.

Details will appear on http://phpmyadmin.net.

Marc Delisle, for the team"

ChangeLog:

http://sourceforge.net/projects/phpmyadmin/files/phpMyAdmin/3.4.6/phpMyAdmin-3.4.6.html/download

The advisories PMASA-15 and PMASA-16 still have not yet been published.

PR:		ports/161709
Submitted by:	Matthew Seaman <m.seaman@infracaninophile.co.uk> (maintainer)
2011-10-17 03:39:14 +00:00
Doug Barton
f21e36ff1c Bugfix and Security update to 3.4.6.r1
From the announce message:

"Welcome to the first release candidate of phpMyAdmin 3.4.6, a bugfix
release containing also fixes for minor security problems.

Details will appear on http://phpmyadmin.net. In a hurry? you can visit
http://sourceforge.net/projects/phpmyadmin to download.

Marc Delisle, for the team"

Security Advisories:

PMASA-2011-15
PMASA-2011-16

(These are not published yet...)

ChangeLog:

(http://sourceforge.net/projects/phpmyadmin/files%2FphpMyAdmin%2F3.4.6-rc1%2FphpMyAdmin-3.4.6-rc1.html/view)

Welcome to the first release candidate for phpMyAdmin 3.4.6, a bugfix release containing also fixes for minor security problems.

3.4.6.0 (not yet released)
- patch #3404173 InnoDB comment display with tooltips/aliases
- bug #3404886 [navi] Edit SQL statement after error
- bug #3403165 [interface] Collation not displayed for long enum fields
- bug #3399951 [export] Config for export compression not used
- bug #3400690 [privileges] DB-specific privileges won't submit
- bug #3410604 [config] Configuration storage incorrect suggested table name
- bug #3383572 [interface] Cannot execute saved query
- bug #3411535 [display] Full text button unchecks results display options
- bug #3411224 [display] Broken binary column when 'Show binary contents' is not set
- bug #3411633 [core] Call to undefined function PMA_isSuperuser()
- bug #3413743 [interface] Display options link missing after search
- bug #3324161 [core] CSP policy causing designer JS buttons to fail
- bug #3412862 [relation] Relations/constraints are dropped/created on every change
- bug #3390832 [display] Delete records from last page breaks search
- bug #3392150 [schema] PMA_User_Schema::processUserChoice() is broken
- bug #3414744 [core] External link fails in 3.4.5
- patch #3314626 [display] CharTextareaRows is not respected
- bug #3417089 [synchronize] Extraneous db choices
- [security] Fixed local path disclosure vulnerability, see PMASA-2011-15
- [security] Fixed XSS in setup (host/verbose parameter), see PMASA-2011-16

PR:		ports/161337
Submitted by:	Matthew Seaman <m.seaman@infracaninophile.co.uk> [maintainer]
2011-10-07 00:45:24 +00:00
Xin LI
af9ae8edb2 Document phpMyAdmin multiple XSS vulnerability.
Update phpMyAdminn to 3.4.5 release. [1]

PR:		ports/160589 [1]
Submitted by:	maitainer [1]
2011-09-14 23:26:28 +00:00
Doug Barton
56f7b60ad3 Security and bug-fix update to version 3.4.4
From the announce message:

Welcome to phpMyAdmin 3.4.4, a bugfix and security release

Please refer to the upcoming PMASA-2011-13 announcements on
http://www.phpmyadmin.net/home_page/security.

Security problem (CVE-2011-3181) is "Multiple XSS in the Tracking
feature."

ChangeLog:

http://sourceforge.net/projects/phpmyadmin/files/phpMyAdmin/3.4.4/phpMyAdmin-3.4.4.html/download

PR:		ports/160156
Submitted by:	maintainer
2011-08-24 21:04:45 +00:00
Ryan Steinmetz
3decd2cb74 Update to 3.4.3.2
PR:		ports/159143
Submitted by:	Matthew Seaman <m.seaman@infracaninophile.co.uk> [maintainer]
Approved by:	wxs (mentor)
2011-07-26 01:21:53 +00:00
Ryan Steinmetz
3bb538877f # New ports collection makefile for: phpMyAdmin
# Date created:		19 Jan 2001
# Whom:			nbm
#
# $FreeBSD: ports/databases/phpmyadmin/Makefile,v 1.139 2011/07/13 01:23:50 sunpoet Exp $
#

PORTNAME=	phpMyAdmin
DISTVERSION=	3.4.3.2
CATEGORIES=	databases www
MASTER_SITES=	SF/${PORTNAME:L}/${PORTNAME}/${PORTVERSION}
DISTNAME=	${PORTNAME}-${DISTVERSION}-all-languages

MAINTAINER=	m.seaman@infracaninophile.co.uk
COMMENT=	A set of PHP-scripts to manage MySQL over the web

LICENSE=	GPLv2

USE_MYSQL=	compat
IGNORE_WITH_PHP=	4
IGNORE_WITH_MYSQL=	323 40 41
USE_BZIP2=	yes
NO_BUILD=	yes
.if !defined(WITHOUT_PHP_DEPENDS)
USE_PHP=	ctype mysql session filter mbstring json spl
.endif

# Note: default settings will pull in X11 client support.  If you don't
# want this, either turn off GD in the config dialog, or else turn off
# FONTCONFIG in the graphics/gd port options.

OPTIONS=	SUPHP	"suPHP support"			      off \
		BZ2	"bzip2 library support" 	      on  \
		GD	"GD library support (requires X11)"   on  \
		MYSQLI	"Improved MySQL support" 	      off \
		OPENSSL	"OpenSSL support" 		      on  \
		PDF	"PDFlib support" 		      on  \
		ZLIB	"ZLIB support" 			      on  \
		MCRYPT	"MCrypt library support" 	      on  \
		ZIP	"Zip compression support" 	      on  \
		APC	"APC (animated progress bar) support" on

.include <bsd.port.options.mk>

.if defined(WITH_SUPHP) && !defined(WITHOUT_SUPHP)

PKGNAMESUFFIX=	-suphp
RUN_DEPENDS+=	${LOCALBASE}/sbin/suphp:${PORTSDIR}/www/suphp
WANT_PHP_CGI=	yes

.else

WANT_PHP_WEB=	yes

.endif

# USERS is only used WITH_SUPHP
GROUPS?=	${WWWGRP}
CFGFILE=	config.inc.php

PLIST=		${WRKDIR}/plist
PLIST_SUB+=	PMA_GRP=${GROUPS}

.if defined(WITH_SUPHP) && !defined(WITHOUT_SUPHP)

USERS?=		_pma

SUB_LIST+=	PMA_USR=${USERS}     \
		PMA_GRP=${GROUPS}
SUB_FILES+=	pkg-install pkg-deinstall

.endif

SUB_LIST+=	PKGNAME=${PKGNAME}
SUB_FILES+=	pkg-message

LATEST_LINK=	${PORTNAME}${PKGNAMESUFFIX}

.if !defined(WITHOUT_PHP_DEPENDS)

# Options that default to on:
.for opt in BZ2 GD OPENSSL PDF ZLIB MCRYPT MBSTRING ZIP APC
.    if !defined(WITHOUT_${opt}) || defined(WITH_${opt})
USE_PHP+=	${opt:L}
.    endif
.endfor

# Options that default to off:
.for opt in MYSQLI
.    if defined(WITH_${opt}) && !defined(WITHOUT_${opt})
USE_PHP+=	${opt:L}
.    endif
.endfor
.endif

.SILENT:

# When creating a package, empty directories will not be generated
# from the pkg tarball.	 Therefore make sure no directories are empty.

post-patch:
	cd ${WRKSRC} ; \
	for emptydir in $$( ${FIND} . -type d -empty -print ) ; do \
	    ${TOUCH} $${emptydir}/.keep-me ; \
	done ; \
	${CP} ${FILESDIR}/${CFGFILE}.sample ${WRKSRC}/${CFGFILE}.sample ; \
	${FIND} . ! -type d ! -name ${CFGFILE}.sample ! -name '*.bak' | \
	    ${SORT} | ${SED} -e "s,^\.,%%WWWDIR%%,"   >${PLIST} ; \
	${CAT} ${PKGDIR}/pkg-plist-chunk	     >>${PLIST} ; \
	${FIND} . -type d | ${SORT} -r | ${SED} \
	    -e "s,^\.$$,@dirrmtry %%WWWDIR%%," \
	    -e "s,^\.,@dirrm %%WWWDIR%%,"	     >>${PLIST}

do-install: install-app install-conf

install-app:
	cd ${WRKSRC} ; \
	for src in $$( ${FIND} . ! -name .cvsignore ! -name '*.bak' ) ; do \
	    dst=${WWWDIR}$${src#.} ; \
	    if ${TEST} -d "$$src" ; then \
		${MKDIR} "$$dst" ; \
	    else \
		${INSTALL_DATA} "$$src" "$$dst" ; \
	    fi \
	done

install-conf: install-app
	cd ${WWWDIR} ; \
	${CHMOD} 0640 ${CFGFILE}.sample ; \
	${CHGRP} ${WWWGRP} ${CFGFILE}.sample ; \
	if ${TEST} ! -f ${CFGFILE} ; then \
	    ${CP} -p ${CFGFILE}.sample ${CFGFILE} ; \
	fi

post-install:
.if defined(WITH_SUPHP)
	${SETENV} ${SCRIPTS_ENV} ${SH} ${PKGINSTALL} ${PKGNAME} POST-INSTALL
.endif
	${CAT} ${PKGMESSAGE}

.include <bsd.port.mk>
2011-07-26 01:13:02 +00:00
Sunpoet Po-Chuan Hsieh
ba932efaa4 - Remove outmoded message
PR:		ports/158844
Submitted by:	Matthew Seaman <m.seaman@infracaninophile.co.uk>
2011-07-13 01:23:50 +00:00
Julien Laffaye
cda22804aa Update to 3.4.3.1
PR:		ports/158603
Submitted by:	Matthew Seaman <m.seaman@infracaninophile.co.uk> (maintainer)
Approved by:	bapt (mentor, implicit)
2011-07-03 11:59:52 +00:00
Frederic Culot
a505a92c47 - Update to 3.4.3
PR:		ports/158356
Submitted by:	Matthew Seaman <m.seaman@infracaninophile.co.uk> (maintainer)
2011-06-28 07:22:44 +00:00