Hello community, here is the log from the commit of package zziplib for openSUSE:Factory checked in at 2018-02-21 14:07:47 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Comparing /work/SRC/openSUSE:Factory/zziplib (Old) and /work/SRC/openSUSE:Factory/.zziplib.new (New) ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "zziplib" Wed Feb 21 14:07:47 2018 rev:28 rq:577974 version:0.13.68 Changes: -------- --- /work/SRC/openSUSE:Factory/zziplib/zziplib.changes 2018-02-16 21:40:49.431415249 +0100 +++ /work/SRC/openSUSE:Factory/.zziplib.new/zziplib.changes 2018-02-21 14:07:50.558030161 +0100 @@ -1,0 +2,15 @@ +Sun Feb 18 03:25:53 UTC 2018 - avin...@opensuse.org + +- Update to 0.13.68: + * fix a number of CVEs reported with special *.zip files + * minor doc updates referencing GitHub instead of sf.net +- drop CVE-2018-6381.patch + * merged in a803559fa9194be895422ba3684cf6309b6bb598 +- drop CVE-2018-6484.patch + * merged in 0c0c9256b0903f664bca25dd8d924211f81e01d3 +- drop CVE-2018-6540.patch + * merged in 15b8c969df962a444dfa07b3d5bd4b27dc0dbba7 +- drop CVE-2018-6542.patch + * merged in 938011cd60f5a8a2a16a49e5f317aca640cf4110 + +------------------------------------------------------------------- Old: ---- CVE-2018-6381.patch CVE-2018-6484.patch CVE-2018-6540.patch CVE-2018-6542.patch v0.13.67.tar.gz New: ---- zziplib-0.13.68.tar.gz ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Other differences: ------------------ ++++++ zziplib.spec ++++++ --- /var/tmp/diff_new_pack.MAVhh8/_old 2018-02-21 14:07:51.673989974 +0100 +++ /var/tmp/diff_new_pack.MAVhh8/_new 2018-02-21 14:07:51.673989974 +0100 @@ -1,7 +1,7 @@ # # spec file for package zziplib # -# Copyright (c) 2018 SUSE LINUX Products GmbH, Nuernberg, Germany. +# Copyright (c) 2018 SUSE LINUX GmbH, Nuernberg, Germany. # # All modifications and additions to the file contributed by third parties # remain the property of their copyright owners, unless otherwise agreed @@ -18,21 +18,17 @@ %define lname libzzip-0-13 Name: zziplib -Version: 0.13.67 +Version: 0.13.68 Release: 0 Summary: Free Zip Compression Library with an Easy-to-Use API License: LGPL-2.1+ Group: System/Libraries Url: http://zziplib.sourceforge.net -Source0: https://github.com/gdraheim/zziplib/archive/v%{version}.tar.gz +Source0: https://github.com/gdraheim/zziplib/archive/v%{version}.tar.gz#/%{name}-%{version}.tar.gz Source2: baselibs.conf Patch0: zziplib-0.13.62.patch Patch1: zziplib-0.13.62-wronglinking.patch Patch2: zziplib-largefile.patch -Patch3: CVE-2018-6381.patch -Patch4: CVE-2018-6484.patch -Patch5: CVE-2018-6540.patch -Patch6: CVE-2018-6542.patch BuildRequires: autoconf BuildRequires: automake BuildRequires: fdupes @@ -70,10 +66,6 @@ %patch0 %patch1 %patch2 -%patch3 -p1 -%patch4 -p1 -%patch5 -p1 -%patch6 -p1 # do not bother with html docs saving us python2 dependency sed -i -e 's:docs ::g' Makefile.am