OpenPKG CVS Repository
http://cvs.openpkg.org/
____________________________________________________________________________
Server: cvs.openpkg.org Name: Thomas Lotterer
Root: /v/openpkg/cvs Email: [EMAIL PROTECTED]
Module: openpkg-src Date: 12-Aug-2005 14:53:50
Branch: HEAD Handle: 2005081213534800
Modified files:
openpkg-src/awstats awstats.patch awstats.spec
Log:
update awstats to resolve security issue CAN-2005-1527; fix tracking
Summary:
Revision Changes Path
1.3 +4 -8 openpkg-src/awstats/awstats.patch
1.7 +5 -5 openpkg-src/awstats/awstats.spec
____________________________________________________________________________
patch -p0 <<'@@ .'
Index: openpkg-src/awstats/awstats.patch
============================================================================
$ cvs diff -u -r1.2 -r1.3 awstats.patch
--- openpkg-src/awstats/awstats.patch 8 Nov 2004 16:03:35 -0000 1.2
+++ openpkg-src/awstats/awstats.patch 12 Aug 2005 12:53:48 -0000 1.3
@@ -27,18 +27,14 @@
$mailid=($id eq 'reject'?'999':$id); # id not provided in
log, we take '999'
if ($mailid) {
$mail{$mailid}{'code'}=999; # Unkown error (bounced)
-@@ -325,11 +325,11 @@
- # sendmail: Sep 30 04:21:32 halley sendmail[3161]:
g8U2LVi03161: ruleset=check_rcpt, arg1=<[EMAIL PROTECTED]>,
relay=moon.partenor.fr [10.0.0.254], reject=550 5.7.1 <[EMAIL PROTECTED]>...
Relaying denied
-
+@@ -327,9 +327,9 @@
# sendmail: Jan 10 07:37:48 smtp sendmail[32440]:
ruleset=check_relay, arg1=[211.228.26.114], arg2=211.228.26.114,
relay=[211.228.26.114], reject=554 5.7.1 Rejected 211.228.26.114 found in
dnsbl.sorbs.net
-- # sendmail: Jan 10 07:37:08 smtp sendmail[32439]:
ruleset=check_relay, arg1=235.Red-213-97-175.pooles.rima-tde.net,
arg2=213.97.175.235, relay=235.Red-213-97-175.pooles.rima-tde.net
[213.97.175.235], reject=550 5.7.1 Mail from 213.97.175.235 refused. Rejected
for bad WHOIS info on IP of your SMTP server - see http://www.rfc-ignorant.org/
-+ # sendmail: Jan 10 07:37:08 smtp sendmail[32439]:
ruleset=check_relay, arg1=235.Red-213-97-175.pooles.rima-tde.net,
arg2=213.97.175.235, relay=235.Red-213-97-175.pooles.rima-tde.net
[213.97.175.235], reject=550 5.7.1 Mail from 213.97.175.235 refused. Rejected
for bad WHOIS info on IP of your SMTP server - see http://www.rfc-ignorant.org/
+ # sendmail: Jan 10 07:37:08 smtp sendmail[32439]:
ruleset=check_relay, arg1=235.Red-213-97-175.pooles.rima-tde.net,
arg2=213.97.175.235, relay=235.Red-213-97-175.pooles.rima-tde.net
[213.97.175.235], reject=550 5.7.1 Mail from 213.97.175.235 refused. Rejected
for bad WHOIS info on IP of your SMTP server - see http://www.rfc-ignorant.org/
# sendmail: Jan 10 17:15:42 smtp sendmail[12770]:
ruleset=check_relay, arg1=[63.218.84.21], arg2=63.218.84.21,
relay=[63.218.84.21], reject=553 5.3.0 Rejected - see http://spamhaus.org/
- my
($mon,$day,$time,$id,$ruleset,$arg,$relay_s,$code)=m/(\w+)\s+(\d+)\s+(\d+:\d+:\d+)[EMAIL
PROTECTED](?:sendmail|sm-mta)\[\d+\][:\s]*(.*?):\sruleset=(\w+),\s+arg1=(.*),\s+relay=(.*),\s+(reject=.*)/;
-- # sendmail: Jan 10 18:00:34 smtp sendmail[5759]:
i04Axx2c005759: Milter: data, reject=511 Virus found in email!
-- if (! $mon) {
($mon,$day,$time,$id,$ruleset,$code)=m/(\w+)\s+(\d+)\s+(\d+:\d+:\d+)[EMAIL
PROTECTED](?:sendmail|sm-mta)\[\d+\]:\s+(.*?):\s\w+:\s(\w+),\s+(reject=.*)/; }
+ my
($mon,$day,$time,$id,$ruleset,$arg,$relay_s,$code)=m/(\w+)\s+(\d+)\s+(\d+:\d+:\d+)\s+[\w\-]+\s+\<\w+\>+\s+(?:sendmail|sm-mta)\[\d+\][:\s]*(.*?):\sruleset=(\w+),\s+arg1=(.*),\s+relay=(.*),\s+(reject=.*)/;
-+ # sendmail: Jan 10 18:00:34 smtp sendmail[5759]:
i04Axx2c005759: Milter: data, reject=511 Virus found in email!
+ # sendmail: Jan 10 18:00:34 smtp sendmail[5759]:
i04Axx2c005759: Milter: data, reject=511 Virus found in email!
+- if (! $mon) {
($mon,$day,$time,$id,$ruleset,$code)=m/(\w+)\s+(\d+)\s+(\d+:\d+:\d+)[EMAIL
PROTECTED](?:sendmail|sm-mta)\[\d+\]:\s+(.*?):\s\w+:\s(\w+),\s+(reject=.*)/; }
+ if (! $mon) {
($mon,$day,$time,$id,$ruleset,$code)=m/(\w+)\s+(\d+)\s+(\d+:\d+:\d+)\s+[\w\-]+\s+\<\w+\>+\s+(?:sendmail|sm-mta)\[\d+\]:\s+(.*?):\s\w+:\s(\w+),\s+(reject=.*)/;
}
$mailid=(! $id && $mon?'999':$id); # id not provided in
log, we take '999'
if ($mailid) {
@@ .
patch -p0 <<'@@ .'
Index: openpkg-src/awstats/awstats.spec
============================================================================
$ cvs diff -u -r1.6 -r1.7 awstats.spec
--- openpkg-src/awstats/awstats.spec 24 Mar 2005 11:18:27 -0000 1.6
+++ openpkg-src/awstats/awstats.spec 12 Aug 2005 12:53:48 -0000 1.7
@@ -34,11 +34,11 @@
Class: JUNK
Group: Mail
License: GPL
-Version: 6.4
-Release: 20050226
+Version: 6.5
+Release: 20050812
# list of sources
-Source0: http://osdn.dl.sourceforge.net/awstats/awstats-%{version}.tgz
+Source0: http://awstats.sourceforge.net/files/awstats-%{version}.tar.gz
Source1: awstats.postfix.conf
Source2: awstats.apache.conf
Source3: rc.awstats
@@ -67,8 +67,8 @@
%track
prog awstats = {
version = %{version}
- url = http://prdownloads.sourceforge.net/awstats/
- regex = awstats-(__VER__)\.tgz
+ url = http://awstats.sourceforge.net/files/
+ regex = awstats-(__VER__)\.tar.gz
}
%prep
@@ .
______________________________________________________________________
The OpenPKG Project www.openpkg.org
CVS Repository Commit List [email protected]