diff options
author | spz <spz> | 2016-04-17 08:25:00 +0000 |
---|---|---|
committer | spz <spz> | 2016-04-17 08:25:00 +0000 |
commit | 9e0dcec5dc90d10862101159f0fadc9a7e2876be (patch) | |
tree | b041fd16d7c181783e04890317d3568b279ba9cf /www | |
parent | c3dd8fafa301912e1968170edac0bda66b745912 (diff) | |
download | pkgsrc-9e0dcec5dc90d10862101159f0fadc9a7e2876be.tar.gz |
Pullup ticket #4961 - requested by mrg
www/bozohttpd: security-update
Revisions pulled up:
- www/bozohttpd/Makefile 1.86
- www/bozohttpd/distinfo 1.65
- www/bozohttpd/patches/patch-bozohttpd.c deleted
-------------------------------------------------------------------
Module Name: pkgsrc
Committed By: mrg
Date: Fri Apr 15 20:59:17 UTC 2016
Modified Files:
pkgsrc/doc: CHANGES-2016
pkgsrc/www/bozohttpd: Makefile distinfo
Removed Files:
pkgsrc/www/bozohttpd/patches: patch-bozohttpd.c
Log Message:
update bozohttpd to 20160415. changes include:
o add search-word support for CGI
o fix a security issue in CGI suffix handler support which would
allow remote code execution, from shm%netbsd.org@localhost
o -C option supports now CGI scripts only
o add CGI support for ~user translation (-E switch)
o add redirects to ~user translation
o fix bugs around ~user translation
o add schema detection for absolute redirects
o fixed few memory leaks
o bunch of minor tweaks
o removed -r support
o smarter redirects
To generate a diff of this commit:
cvs rdiff -u -r1.1574 -r1.1575 pkgsrc/doc/CHANGES-2016
cvs rdiff -u -r1.85 -r1.86 pkgsrc/www/bozohttpd/Makefile
cvs rdiff -u -r1.64 -r1.65 pkgsrc/www/bozohttpd/distinfo
cvs rdiff -u -r1.2 -r0 pkgsrc/www/bozohttpd/patches/patch-bozohttpd.c
Diffstat (limited to 'www')
-rw-r--r-- | www/bozohttpd/Makefile | 5 | ||||
-rw-r--r-- | www/bozohttpd/distinfo | 11 | ||||
-rw-r--r-- | www/bozohttpd/patches/patch-bozohttpd.c | 19 |
3 files changed, 7 insertions, 28 deletions
diff --git a/www/bozohttpd/Makefile b/www/bozohttpd/Makefile index c40fc333b31..ea0a7452f9c 100644 --- a/www/bozohttpd/Makefile +++ b/www/bozohttpd/Makefile @@ -1,8 +1,7 @@ -# $NetBSD: Makefile,v 1.85 2016/03/05 11:29:35 jperkin Exp $ +# $NetBSD: Makefile,v 1.85.2.1 2016/04/17 08:25:00 spz Exp $ # -DISTNAME= bozohttpd-20150320 -PKGREVISION= 1 +DISTNAME= bozohttpd-20160415 CATEGORIES= www MASTER_SITES= ${MASTER_SITE_LOCAL} EXTRACT_SUFX= .tar.bz2 diff --git a/www/bozohttpd/distinfo b/www/bozohttpd/distinfo index d4e29801c04..49c7574d161 100644 --- a/www/bozohttpd/distinfo +++ b/www/bozohttpd/distinfo @@ -1,10 +1,9 @@ -$NetBSD: distinfo,v 1.64 2015/11/04 02:46:50 agc Exp $ +$NetBSD: distinfo,v 1.64.4.1 2016/04/17 08:25:00 spz Exp $ -SHA1 (bozohttpd-20150320.tar.bz2) = 1126d17a79c87bde1df77f6f71e6e040726579a0 -RMD160 (bozohttpd-20150320.tar.bz2) = 7e8db6b6cc3f6df5638eeabed5ec4ee1efa859c2 -SHA512 (bozohttpd-20150320.tar.bz2) = f1fc5f6c55bd18bef478402dc7d250cd785007233b0d8c6afbf319525fdefb13352954fd8e1285806fd2704235ce1faf97881f29bf162a5473e2f64d288426ed -Size (bozohttpd-20150320.tar.bz2) = 52482 bytes +SHA1 (bozohttpd-20160415.tar.bz2) = 4dddd40db0a004741e48ea4d3b4c4b850b9e41f5 +RMD160 (bozohttpd-20160415.tar.bz2) = 949a2dce5c195ce8270307563e892fa8b821b52b +SHA512 (bozohttpd-20160415.tar.bz2) = 0377b472a0e26ad4cfeb2b0eac084ef3da0ea8d41f3f81da021bed373a14dec85a57ed5bd790826c204ef293a1aa05d29ea9a57afe3a5fe87159f71ad38ced30 +Size (bozohttpd-20160415.tar.bz2) = 55045 bytes SHA1 (patch-aa) = 2e70d3d10aa8bc228331cc1a229ef04106aca210 SHA1 (patch-ab) = a1a56a188084440ab907995c7728e435961c5fbd -SHA1 (patch-bozohttpd.c) = 4e04430fc11034e097876f3f7698134e832bea69 SHA1 (patch-cgi-bozo.c) = 420f981575d7fa1a96ac7049116b9bf64de719df diff --git a/www/bozohttpd/patches/patch-bozohttpd.c b/www/bozohttpd/patches/patch-bozohttpd.c deleted file mode 100644 index 3cd63154d43..00000000000 --- a/www/bozohttpd/patches/patch-bozohttpd.c +++ /dev/null @@ -1,19 +0,0 @@ -$NetBSD: patch-bozohttpd.c,v 1.2 2015/10/17 06:06:49 richard Exp $ - -SunOS doesn't define d_namlen element of dirent structure -only d_reclen, so use strlen to determine d_namlen. - ---- bozohttpd.c.orig 2015-03-25 23:38:50.000000000 +0000 -+++ bozohttpd.c -@@ -1093,7 +1093,11 @@ check_virtual(bozo_httpreq_t *request) - } - debug((httpd, DEBUG_OBESE, "looking at dir``%s''", - d->d_name)); -+#ifndef __sun - if (d->d_namlen == len && strcmp(d->d_name, -+#else -+ if (strlen(d->d_name) == len && strcmp(d->d_name, -+#endif - request->hr_host) == 0) { - /* found it, punch it */ - debug((httpd, DEBUG_OBESE, "found it punch it")); |