Bug 198882 - [lang/php55][security]Multiple vulnerabilities
Summary: [lang/php55][security]Multiple vulnerabilities
Status: Closed FIXED
Alias: None
Product: Ports & Packages
Classification: Unclassified
Component: Individual Port(s) (show other bugs)
Version: Latest
Hardware: Any Any
: --- Affects Only Me
Assignee: Alex Dupre
URL:
Keywords:
Depends on:
Blocks:
 
Reported: 2015-03-24 20:36 UTC by Sevan Janiyan
Modified: 2015-04-26 12:38 UTC (History)
2 users (show)

See Also:
bugzilla: maintainer-feedback? (ale)


Attachments
PHP 5.5.22 -> 5.5.23 Patch (889 bytes, patch)
2015-03-28 22:54 UTC, Jason Unovitch
no flags Details | Diff
Poudriere Build Logs from 10.1-RELEASE amd64 (352.98 KB, text/x-log)
2015-03-28 22:57 UTC, Jason Unovitch
no flags Details

Note You need to log in before you can comment on or make changes to this bug.
Description Sevan Janiyan 2015-03-24 20:36:23 UTC
CVE-2015-0231, CVE-2015-2305 and CVE-2015-2331
http://php.net/archive/2015.php#id2015-03-20-1
Comment 1 Jason Unovitch freebsd_committer freebsd_triage 2015-03-28 22:54:15 UTC
Created attachment 154935 [details]
PHP 5.5.22 -> 5.5.23 Patch

Build time tested: php55 php55-extensions php55-curl php55-xml php55-mbstring php55-json php55-simplexml php55-dom

Basic Runtime tested: php55 php55-curl php55-xml php55-mbstring php55-json php55-simplexml php55-dom

Poudriere logs are forthcoming.
Comment 2 Jason Unovitch freebsd_committer freebsd_triage 2015-03-28 22:57:14 UTC
Created attachment 154936 [details]
Poudriere Build Logs from 10.1-RELEASE amd64

Also build tested and available upon request:
10.1-RELEASE i386, 9.3-RELEASE amd64, 9.3-RELEASE i386, 8.4-RELEASE amd64, 8.4-RELEASE i386
Comment 3 rainer 2015-03-30 00:22:34 UTC
It would be nice and very much appreciated if this could get in the tree before the 2015Q2 cut.
Comment 4 rainer 2015-03-30 00:23:05 UTC
It would be nice and very much appreciated if this could get in the tree before the 2015Q2 cut.
Comment 5 Jason Unovitch freebsd_committer freebsd_triage 2015-03-30 23:02:51 UTC
(In reply to rainer from comment #4)

I wouldn't worry about the timeline for the 2015Q2 cut; since this is a security fix, this justifies merging to the quarterly branch.  I have the patch for vuxml to show it during pkg audit in the lang/php5 at https://bugs.freebsd.org/198993.  The PHP project documents the same 3 CVE's for all 3 PHP versions so it should just be the one entry.
Comment 6 Jason Unovitch freebsd_committer freebsd_triage 2015-04-13 02:36:20 UTC
This PR can be closed.

lang/php55 was updated from 5.5.22 -> 5.5.23 in r382895:
https://svnweb.freebsd.org/ports?view=revision&revision=382895

security/vuxml updated in r382948:
https://svnweb.freebsd.org/ports?view=revision&revision=382948