From 902e5a61ae300a90a88c9520cedf9156b53cf824cc59a3b7eed4b20978d19091 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Ismail=20D=C3=B6nmez?= Date: Sat, 29 Sep 2012 13:17:07 +0000 Subject: [PATCH] Accepting request 136341 from home:flichtenheld Update to current to fix security issues OBS-URL: https://build.opensuse.org/request/show/136341 OBS-URL: https://build.opensuse.org/package/show/system:packagemanager/devscripts?expand=0&rev=2 --- devscripts.changes | 13 +++++++++++++ devscripts.spec | 2 +- devscripts_2.11.7.tar.gz | 3 --- devscripts_2.12.4.tar.gz | 3 +++ 4 files changed, 17 insertions(+), 4 deletions(-) delete mode 100644 devscripts_2.11.7.tar.gz create mode 100644 devscripts_2.12.4.tar.gz diff --git a/devscripts.changes b/devscripts.changes index 32b86dc..a3736fc 100644 --- a/devscripts.changes +++ b/devscripts.changes @@ -1,3 +1,16 @@ +------------------------------------------------------------------- +Thu Sep 27 22:35:26 UTC 2012 - frank.lichtenheld@sophos.com + +- update to devscripts-2.12.4 +* dget: Fix CVE-2012-2241 (arbitrary file deletion) +* dscverify: Fix CVE-2012-2240 (arbitrary code execution) +* annotate-output: Fix to prevent symlink attack: don't delete + safely-created file and reuse its name. Instead, create temporary + directory and create FIFOs therein. Also, be sure to remove temporaries + upon catchable signal. Fixes CVE-2012-3500. +* debdiff: Fix regression in exit code, introduced in 2.11.4. +* see /usr/share/doc/packages/devscripts/changelog for details + ------------------------------------------------------------------- Fri Jul 6 21:56:48 UTC 2012 - frank.lichtenheld@sophos.com diff --git a/devscripts.spec b/devscripts.spec index 7e65aff..8d9bb6b 100644 --- a/devscripts.spec +++ b/devscripts.spec @@ -21,7 +21,7 @@ %{!?python_sitearch: %global python_sitearch %(%{__python} -c "from distutils.sysconfig import get_python_lib; print(get_python_lib(1))")} Name: devscripts -Version: 2.11.7 +Version: 2.12.4 Release: 0 Summary: Scripts to make the life of a Debian Package maintainer easier License: GPL-2.0+ diff --git a/devscripts_2.11.7.tar.gz b/devscripts_2.11.7.tar.gz deleted file mode 100644 index a2422ce..0000000 --- a/devscripts_2.11.7.tar.gz +++ /dev/null @@ -1,3 +0,0 @@ -version https://git-lfs.github.com/spec/v1 -oid sha256:28a6cd13c186555bf3ebb626ccc04d95e16fee08a13a9e75b8655c245e7945a4 -size 776039 diff --git a/devscripts_2.12.4.tar.gz b/devscripts_2.12.4.tar.gz new file mode 100644 index 0000000..7024d38 --- /dev/null +++ b/devscripts_2.12.4.tar.gz @@ -0,0 +1,3 @@ +version https://git-lfs.github.com/spec/v1 +oid sha256:34bcbec78bd4fe34d9f1326b9d1477ff2410e20e2dca6b7bfbf2bf92dbb83904 +size 791085