Bug 210870 - www/typo3: Update to 7.6.9
Summary: www/typo3: Update to 7.6.9
Status: Closed FIXED
Alias: None
Product: Ports & Packages
Classification: Unclassified
Component: Individual Port(s) (show other bugs)
Version: Latest
Hardware: Any Any
: --- Affects Only Me
Assignee: Torsten Zuehlsdorff
URL: https://typo3.org/news/article/typo3-...
Keywords: patch, security
Depends on:
Blocks:
 
Reported: 2016-07-06 09:56 UTC by Helmut Ritter
Modified: 2016-07-19 12:57 UTC (History)
2 users (show)

See Also:
junovitch: merge-quarterly+


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Comment 1 Torsten Zuehlsdorff freebsd_committer freebsd_triage 2016-07-06 10:41:41 UTC
Hello,

can you please add the patch as attachment and set the maintainer-approval (next time)? Than the update will be displayed for committers.

Greetings,
Torsten
Comment 2 Helmut Ritter 2016-07-06 11:00:40 UTC
(In reply to Torsten Zuehlsdorff from comment #1)

Where can I set the maintainer-approval? Is there a way to attach the patch from within command line as it was in the past with "port"?

[helmut@BSDHelmut1064 ~]$ port submit
Port submit is currently broken
[helmut@BSDHelmut1064 ~]$

That would help a lot :)
Comment 3 Jason Unovitch freebsd_committer freebsd_triage 2016-07-07 01:05:11 UTC
(In reply to freebsd-ports from comment #2)
You may want to try "ports-mgmt/freebsd-bugzilla-cli"
Comment 4 commit-hook freebsd_committer freebsd_triage 2016-07-08 14:29:43 UTC
A commit references this bug:

Author: tz
Date: Fri Jul  8 14:28:59 UTC 2016
New revision: 418225
URL: https://svnweb.freebsd.org/changeset/ports/418225

Log:
  www/typo3: upgrade from 7.6.5 to 7.6.9

  Changelogs:
  - https://wiki.typo3.org/TYPO3_CMS_7.6.6
  - https://wiki.typo3.org/TYPO3_CMS_7.6.7
  - https://wiki.typo3.org/TYPO3_CMS_7.6.8
  - https://wiki.typo3.org/TYPO3_CMS_7.6.9

  PR:           210870
  Submitted by: freebsd-ports@charlieroot.de
  Approved by:  junovitch (mentor)
  Security:     CVE-2016-5091
  MFH:          2016Q3

Changes:
  head/www/typo3/Makefile
  head/www/typo3/distinfo
Comment 5 commit-hook freebsd_committer freebsd_triage 2016-07-08 15:46:54 UTC
A commit references this bug:

Author: tz
Date: Fri Jul  8 15:46:18 UTC 2016
New revision: 418231
URL: https://svnweb.freebsd.org/changeset/ports/418231

Log:
  MFH: r418225

  www/typo3: upgrade from 7.6.5 to 7.6.9

  Changelogs:
  - https://wiki.typo3.org/TYPO3_CMS_7.6.6
  - https://wiki.typo3.org/TYPO3_CMS_7.6.7
  - https://wiki.typo3.org/TYPO3_CMS_7.6.8
  - https://wiki.typo3.org/TYPO3_CMS_7.6.9

  PR:           210870
  Submitted by: freebsd-ports@charlieroot.de
  Approved by:  junovitch (mentor)
  Security:     CVE-2016-5091

  Approved by:  ports-secteam (junovitch)

Changes:
_U  branches/2016Q3/
  branches/2016Q3/www/typo3/Makefile
  branches/2016Q3/www/typo3/distinfo
Comment 6 Jason Unovitch freebsd_committer freebsd_triage 2016-07-09 01:27:08 UTC
(In reply to commit-hook from comment #5)
Torsten, once merged we set merge-quarterly+.  We would set merge-quarterly- for a denied merge.  The submitter would usually set merge-quarterly? if they wanted to request the commit be MFH'd and the committer would be expected to handle that positively or negatively.

Tag with 'security' keywords and set 'in progress' for you pending the VuXML to finish the job.
Comment 7 commit-hook freebsd_committer freebsd_triage 2016-07-19 12:55:55 UTC
A commit references this bug:

Author: tz
Date: Tue Jul 19 12:55:44 UTC 2016
New revision: 418774
URL: https://svnweb.freebsd.org/changeset/ports/418774

Log:
  www/typo3 and www/typo3-lts: Document missing access check in Extbase

  PR:          210870, 210871
  Security:    CVE-2016-5091
  Security:    https://vuxml.freebsd.org/freebsd/3caf4e6c-4cef-11e6-a15f-00248c0c745d.html
  Approved by: junovitch (mentor)

Changes:
  head/security/vuxml/vuln.xml
Comment 8 Torsten Zuehlsdorff freebsd_committer freebsd_triage 2016-07-19 12:57:21 UTC
Missing vuxml entry committed. Now everything is done, thanks! :)