Bug 273128 - www/typo3-11: Update to 11.5.30
Summary: www/typo3-11: Update to 11.5.30
Status: Closed FIXED
Alias: None
Product: Ports & Packages
Classification: Unclassified
Component: Individual Port(s) (show other bugs)
Version: Latest
Hardware: Any Any
: --- Affects Only Me
Assignee: Fernando Apesteguía
URL: https://typo3.org/article/typo3-1244-...
Keywords:
Depends on:
Blocks:
 
Reported: 2023-08-14 07:33 UTC by Helmut Ritter
Modified: 2023-08-15 11:59 UTC (History)
1 user (show)

See Also:
fernape: merge-quarterly+


Attachments
Update to 11.5.30 (838 bytes, patch)
2023-08-14 07:34 UTC, Helmut Ritter
freebsd-ports: maintainer-approval+
Details | Diff
Poudriere Log (26.50 KB, text/plain)
2023-08-14 07:34 UTC, Helmut Ritter
no flags Details

Note You need to log in before you can comment on or make changes to this bug.
Description Helmut Ritter 2023-08-14 07:33:56 UTC
All versions are security releases and contain important security fixes - read the corresponding security advisories here:

https://typo3.org/security/advisory/typo3-core-sa-2023-002
https://typo3.org/security/advisory/typo3-core-sa-2023-003
https://typo3.org/security/advisory/typo3-core-sa-2023-004

For details about the releases, please see:

https://typo3.org/article/typo3-1244-and-11530-security-releases-published
Comment 1 Helmut Ritter 2023-08-14 07:34:10 UTC
Created attachment 244085 [details]
Update to 11.5.30
Comment 2 Helmut Ritter 2023-08-14 07:34:47 UTC
Created attachment 244086 [details]
Poudriere Log
Comment 3 Fernando Apesteguía freebsd_committer freebsd_triage 2023-08-14 11:19:40 UTC
Note to self: add VuXML entries.

^Triage: Maintainer-feedback flag (+) not required unless requested (?) first.


Thanks!
Comment 4 commit-hook freebsd_committer freebsd_triage 2023-08-14 14:12:24 UTC
A commit in branch main references this bug:

URL: https://cgit.FreeBSD.org/ports/commit/?id=cc6eb206e592d6be6c11b92e733c56f4914ec9a9

commit cc6eb206e592d6be6c11b92e733c56f4914ec9a9
Author:     Fernando Apesteguía <fernape@FreeBSD.org>
AuthorDate: 2023-08-14 14:00:40 +0000
Commit:     Fernando Apesteguía <fernape@FreeBSD.org>
CommitDate: 2023-08-14 14:10:09 +0000

    security/vuxml: add typo3 vulnerabilities

    https://typo3.org/article/typo3-1244-and-11530-security-releases-published

    CVE-2023-38500  Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
    CVE-2023-38499  Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
    CVE-2023-37905  Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

    PR:     273128

 security/vuxml/vuln/2023.xml | 36 ++++++++++++++++++++++++++++++++++++
 1 file changed, 36 insertions(+)
Comment 5 commit-hook freebsd_committer freebsd_triage 2023-08-15 11:58:06 UTC
A commit in branch main references this bug:

URL: https://cgit.FreeBSD.org/ports/commit/?id=21ddf85e7bf25833683f6f8802a1b621164996dd

commit 21ddf85e7bf25833683f6f8802a1b621164996dd
Author:     Helmut Ritter <freebsd-ports@charlieroot.de>
AuthorDate: 2023-08-14 11:20:00 +0000
Commit:     Fernando Apesteguía <fernape@FreeBSD.org>
CommitDate: 2023-08-15 11:56:47 +0000

    www/typo3-11: Update to 11.5.30

    ChangeLog:
    https://typo3.org/article/typo3-1244-and-11530-security-releases-published

    PR:             273128
    Reported by:    freebsd-ports@charlieroot.de (maintainer)
    MFH:            2023Q3 (bug and security fixes)
    Security:       CVE-2023-38500 CVE-2023-38499 CVE-2023-37905

 www/typo3-11/Makefile | 2 +-
 www/typo3-11/distinfo | 6 +++---
 2 files changed, 4 insertions(+), 4 deletions(-)
Comment 6 commit-hook freebsd_committer freebsd_triage 2023-08-15 11:59:07 UTC
A commit in branch 2023Q3 references this bug:

URL: https://cgit.FreeBSD.org/ports/commit/?id=2a4bbef487d9354885dc46f15208fb7a2a9c9f0a

commit 2a4bbef487d9354885dc46f15208fb7a2a9c9f0a
Author:     Helmut Ritter <freebsd-ports@charlieroot.de>
AuthorDate: 2023-08-14 11:20:00 +0000
Commit:     Fernando Apesteguía <fernape@FreeBSD.org>
CommitDate: 2023-08-15 11:58:44 +0000

    www/typo3-11: Update to 11.5.30

    ChangeLog:
    https://typo3.org/article/typo3-1244-and-11530-security-releases-published

    PR:             273128
    Reported by:    freebsd-ports@charlieroot.de (maintainer)
    MFH:            2023Q3 (bug and security fixes)
    Security:       CVE-2023-38500 CVE-2023-38499 CVE-2023-37905

    (cherry picked from commit 21ddf85e7bf25833683f6f8802a1b621164996dd)

 www/typo3-11/Makefile | 2 +-
 www/typo3-11/distinfo | 6 +++---
 2 files changed, 4 insertions(+), 4 deletions(-)
Comment 7 Fernando Apesteguía freebsd_committer freebsd_triage 2023-08-15 11:59:43 UTC
Committed and merged to 2023Q3,

Thanks!