diff --git a/csync2.changes b/csync2.changes index 7bf82d4..042298a 100644 --- a/csync2.changes +++ b/csync2.changes @@ -1,27 +1,25 @@ ------------------------------------------------------------------- -Wed Apr 7 09:58:51 UTC 2021 - Peter Varkoly +Wed Apr 7 19:21:54 UTC 2021 - Peter Varkoly - Update to 2.0+git.1600444747.83b3644: * VUL-1: CVE-2019-15522: csync2: daemon fails to enforce TLS (bsc#1147137) + * VUL-1: CVE-2019-15523: csync2: incorrect TLS handshake error handling + (bsc#1147139 * use standard %lld instead of non-standard %Ld format specifier * try to avoid (temporary) -rw------- root:root files on receiving side * fix diff mode truncation to first 512 byte * disable xinetd template by default as preparation for systemd socket unit * add systemd csync2.socket and csync2@.service templates * escape peername in SQL statements +- VUL-1: csync2: bad TLS key generation on installation (bsc#1145032) + Adapt suggested changes in %post section. + Do not hide output on standard error during generating the keys. - Remove patches contained by update: * 0003-Set-AC_PROG_CPP-in-configure.ac.patch * 0002-Patch-sonames.patch * 0001-Add-COPYING-as-docfile.patch -------------------------------------------------------------------- -Wed Nov 20 14:00:30 UTC 2019 - Peter Varkoly - -- VUL-1: csync2: bad TLS key generation on installation (bsc#1145032) - Adapt suggested changes in %post section. - Do not hide output on standard error during generating the keys. - ------------------------------------------------------------------- Mon May 27 08:13:02 UTC 2019 - Kristoffer Gronlund @@ -30,6 +28,17 @@ Mon May 27 08:13:02 UTC 2019 - Kristoffer Gronlund * Add error handling for out-of-memory while parsing config file * create_key: use all random bits; add some error handling +- Update patches + * Add 0001-Add-COPYING-as-docfile.patch + * Add 0002-Patch-sonames.patch + * Add 0003-Set-AC_PROG_CPP-in-configure.ac.patch + * Remove add-COPYING.patch + * Remove add-ac_prog_cpp.patch + * Remove fix-sonames.patch + +------------------------------------------------------------------- +Mon May 27 08:13:02 UTC 2019 - Kristoffer Gronlund + - Update patches * Add 0001-Add-COPYING-as-docfile.patch * Add 0002-Patch-sonames.patch