From a0cdd7fb9456b7983925291ba5f2c6ae08f13a9f Mon Sep 17 00:00:00 2001 From: adam <adam@pkgsrc.org> Date: Sat, 23 Aug 2014 12:16:45 +0000 Subject: Changes 1.4.14: Security fixes: * Issue: reverse() can generate URLs pointing to other hosts (CVE-2014-0480) * Issue: file upload denial of service (CVE-2014-0481) * Issue: RemoteUserMiddleware session hijacking (CVE-2014-0482) * Issue: data leakage via querystring manipulation in admin (CVE-2014-0483) --- www/py-django14/Makefile | 4 ++-- www/py-django14/PLIST | 5 ++++- www/py-django14/distinfo | 8 ++++---- 3 files changed, 10 insertions(+), 7 deletions(-) (limited to 'www/py-django14') diff --git a/www/py-django14/Makefile b/www/py-django14/Makefile index f872850f47b..8ef8d515dcc 100644 --- a/www/py-django14/Makefile +++ b/www/py-django14/Makefile @@ -1,6 +1,6 @@ -# $NetBSD: Makefile,v 1.7 2014/06/10 12:01:56 joerg Exp $ +# $NetBSD: Makefile,v 1.8 2014/08/23 12:16:45 adam Exp $ -DISTNAME= Django-1.4.13 +DISTNAME= Django-1.4.14 PKGNAME= ${PYPKGPREFIX}-${DISTNAME:tl} CATEGORIES= www python MASTER_SITES= http://www.djangoproject.com/m/releases/${PKGVERSION_NOREV:R}/ diff --git a/www/py-django14/PLIST b/www/py-django14/PLIST index a4be9319fa7..98c52b9487d 100644 --- a/www/py-django14/PLIST +++ b/www/py-django14/PLIST @@ -1,4 +1,4 @@ -@comment $NetBSD: PLIST,v 1.1 2013/11/14 21:27:01 joerg Exp $ +@comment $NetBSD: PLIST,v 1.2 2014/08/23 12:16:45 adam Exp $ bin/django-admin.py ${PYSITELIB}/${EGG_FILE} ${PYSITELIB}/django/__init__.py @@ -598,6 +598,9 @@ ${PYSITELIB}/django/contrib/admin/__init__.pyo ${PYSITELIB}/django/contrib/admin/actions.py ${PYSITELIB}/django/contrib/admin/actions.pyc ${PYSITELIB}/django/contrib/admin/actions.pyo +${PYSITELIB}/django/contrib/admin/exceptions.py +${PYSITELIB}/django/contrib/admin/exceptions.pyc +${PYSITELIB}/django/contrib/admin/exceptions.pyo ${PYSITELIB}/django/contrib/admin/filters.py ${PYSITELIB}/django/contrib/admin/filters.pyc ${PYSITELIB}/django/contrib/admin/filters.pyo diff --git a/www/py-django14/distinfo b/www/py-django14/distinfo index 0995ae40420..7c2da1daf62 100644 --- a/www/py-django14/distinfo +++ b/www/py-django14/distinfo @@ -1,5 +1,5 @@ -$NetBSD: distinfo,v 1.3 2014/06/10 11:58:10 joerg Exp $ +$NetBSD: distinfo,v 1.4 2014/08/23 12:16:45 adam Exp $ -SHA1 (Django-1.4.13.tar.gz) = f9df618fc07628a0caffc46ecfb0ead65220665d -RMD160 (Django-1.4.13.tar.gz) = 3fa6bca9e8d16414143f398cec974930544034fb -Size (Django-1.4.13.tar.gz) = 7753532 bytes +SHA1 (Django-1.4.14.tar.gz) = ce1db876daceea9f9252b3a886e70ebda8978d6c +RMD160 (Django-1.4.14.tar.gz) = 7ba597bc413ce855d881b6aecb5f2e7d9068104d +Size (Django-1.4.14.tar.gz) = 7754876 bytes -- cgit v1.2.3