21 Commits

Author SHA1 Message Date
Andy Postnikov
7bbc0dad2f community/phpmyadmin: security upgrade to 4.8.5 (CVE-2019-6798 CVE-2019-6799) 2019-01-31 18:54:31 +02:00
Leonardo Arena
327df2ce21 community/phpmyadmin: security upgrade to 4.8.4
CVE-2018-19968, CVE-2018-19969, CVE-2018-19970

Fixes #9785
2019-01-08 10:44:14 +00:00
Natanael Copa
a025a7594a community/phpmyadmin: upgrade to 4.8.3 2018-08-24 07:19:56 +00:00
Andy Postnikov
4c248a63b1 community/phpmyadmin: fix apache2 config and improve
Closes #8088
2018-08-10 19:48:28 +03:00
Natanael Copa
7b247d9a30 community/phpmyadmin: security upgrade to 4.8.2 (CVE-2018-12581,CVE-2018-12613)
fixes #9092
2018-07-16 17:52:52 +00:00
Natanael Copa
ca4b594fdc community/phpmyadmin: upgrade to 4.8.1 and update maintainer 2018-06-12 07:46:12 +00:00
Leonardo Arena
49bcffeaf0 community/phpmyadmin: add missing patch 2018-06-11 13:05:09 +00:00
Leonardo Arena
0e6a7a8f8c community/phpmyadmin: security fix (CVE-2018-10188)
Fixes #8847
2018-06-11 12:23:48 +00:00
Andy Postnikov
87cbcd09fe community/phpmyadmin: upgrade to 4.8.0 2018-04-14 03:30:46 +03:00
Natanael Copa
bc6a892eca community/phpmyadmin: security upgrade to 4.7.8 (CVE-2018-7260)
fixes #8589
2018-02-27 18:01:20 +00:00
Roberto Oliveira
59b28fe95c community/phpmyadmin: upgrade to 4.7.7 2018-01-19 02:00:38 +00:00
Jakub Jirutka
63f5e7d295 [various]: unify names of licenses according to SPDX
This commit updates $license variable in all APKBUILDs to comply with
short names specified by SPDX version 3.0 [1] where possible. It was
done using find-and-replace method on substrings inside $license
variables.

Only license names were updated, not "expressions" specifying relation
between the licenses (e.g. "X and Y", "X or Y", "X and (Y or Z)") or
exceptions (e.g. "X with exceptions").

Many licenses have a version or multiple variants, e.g. MPL-2.0,
BSD-2-Clause, BSD-3-Clause. However, $license in many aports do not
contain license version or variant. Since there's no way how to infer
this information just from abuild, it were left without the variant
suffix or version, i.e. non SPDX compliant.

GNU licenses (AGPL, GFDL, GPL, LGPL) are especially complicated. They
exist in two variants: -only (formerly e.g. GPL-2.0) and -or-later
(formerly e.g. GPL-2.0+). We did not systematically noted distinguish
between these variants, so GPL-2.0, GPL2, GPLv2 etc. may mean
GPL-2.0-only or GPL-2.0-or-later. Thus GNU licenses without "+" (e.g.
GPL2+) were left without the variant suffix, i.e. non SPDX compliant.

Note: This commit just fixes format of the license names, no
verification has been done if the specified license information is
actually correct!

[1]: https://spdx.org/licenses/
2017-12-30 21:05:50 +01:00
Andy Postnikov
dab5409bc6 community/phpmyadmin: disable check 2017-12-04 22:55:04 +01:00
Andy Postnikov
cdefb7a9b2 community/phpmyadmin: upgrade to 4.7.6 2017-12-04 22:54:34 +01:00
Jakub Jirutka
4ee7c35b7d community/*: fix homepage url and source from http:// to https://
Most of these updates is based on data from https://repology.org/,
detection based on permanent redirect from http:// to https://.

$source urls are updated when they contain $url as substring.
2017-11-19 14:16:58 +01:00
Natanael Copa
afacb63805 community/phpmyadmin: upgrade to 4.7.1 2017-06-14 15:12:46 +00:00
Andy Postnikov
aeba1ff3b8 community/phpmyadmin: Upgrade to 4.7.0
Release notes https://www.phpmyadmin.net/news/2017/3/29/phpmyadmin-470-released/
2017-04-29 11:03:12 +00:00
Natanael Copa
4c4fe25d00 community/phpmyadmin: upgrade to 4.6.6 2017-01-27 14:34:06 +00:00
Sergey Lukin
517afce6b9 community/phpmyadmin: mistake fixed in secfixes info 2016-12-30 07:22:13 +00:00
Sergey Lukin
311ef72f19 community/phpmyadmin: security upgrade to 4.6.5.2 - fixes #6594
CVE-2016-9847: Unsafe generation of blowfish secret
CVE-2016-9848: phpinfo information leak value of sensitive (HttpOnly) cookies
CVE-2016-9849: Username deny rules bypass (AllowRoot & Others) by using Null Byte
CVE-2016-9850: Username rule matching issues
CVE-2016-9851: With a crafted request parameter value it is possible to bypass the logout timeout.
CVE-2016-9852 CVE-2016-9853 CVE-2016-9854 CVE-2016-9855: Multiple full path disclosure vulnerabilities
CVE-2016-9856 CVE-2016-9857: Multiple XSS vulnerabilities
CVE-2016-9858 CVE-2016-9859 CVE-2016-9860: We consider these vulnerabilities to be of moderate severity.
CVE-2016-9861: Bypass white-list protection for URL redirection
CVE-2016-9862: BBCode injection vulnerability
CVE-2016-9863: DOS vulnerability in table partitioning
CVE-2016-9864: Multiple SQL injection vulnerabilities
CVE-2016-9865: Incorrect serialized string parsing
CVE-2016-9866: CSRF token not stripped from the URL
2016-12-30 07:20:53 +00:00
Natanael Copa
a9b8bfa9d6 community/phpmyadmin: move form main
We don't want maintain this for more than 6 months due to the amount of
security issues.
2016-09-23 14:50:25 +00:00