Hello community, here is the log from the commit of package puppet for openSUSE:Factory checked in at 2012-07-12 12:09:34 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Comparing /work/SRC/openSUSE:Factory/puppet (Old) and /work/SRC/openSUSE:Factory/.puppet.new (New) ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "puppet", Maintainer is "vdziewie...@suse.com" Changes: -------- --- /work/SRC/openSUSE:Factory/puppet/puppet.changes 2012-06-26 17:21:56.000000000 +0200 +++ /work/SRC/openSUSE:Factory/.puppet.new/puppet.changes 2012-07-12 12:09:35.000000000 +0200 @@ -1,0 +2,32 @@ +Wed Jul 11 13:24:28 UTC 2012 - vdziewie...@suse.com + +-Update to 2.7.18 +CVEs fixed: +-bnc#770828 - VUL-0: CVE-2012-3864: puppet: authenticated clients can read arbitrary files via a flaw in puppet master +-bnc#770829 - VUL-0: CVE-2012-3865: puppet: arbitrary file delete / Denial of Service on Puppet Master by authenticated clients +-bnc#770827 - VUL-1: CVE-2012-3866: puppet: last_run_report.yaml left world-readable +-bnc#770833 - VUL-1: CVE-2012-3867: puppet: insufficient input validation for agent certificate names + + + +------------------------------------------------------------------- +Tue Jul 3 19:53:18 UTC 2012 - ja...@suse.de + +- update to 2.7.17 + * (maint) Add symlink stub to gentoo service provider spec + * Add comment to upstart provider explaining exclusion of + 'wait-for-state' + * Upstart code cleanup, init provider improvement + * Add spec test for network-interface-security + * Add basic service resource test to upstart acceptance + * Handle network-interface-security in upstart + * Add exclude list to upstart provider + * (#15027, #15028, #15029) Fix upstart version parsing + * (maint) Add --test to puppet run + +------------------------------------------------------------------- +Tue Jul 3 19:02:48 UTC 2012 - ja...@suse.de + +- Copy from devel:openSUSE:Factory + +------------------------------------------------------------------- Old: ---- puppet-2.7.16.tar.gz New: ---- puppet-2.7.18.tar.gz ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Other differences: ------------------ ++++++ puppet.spec ++++++ --- /var/tmp/diff_new_pack.P6IlwW/_old 2012-07-12 12:09:37.000000000 +0200 +++ /var/tmp/diff_new_pack.P6IlwW/_new 2012-07-12 12:09:37.000000000 +0200 @@ -22,7 +22,7 @@ %define _fwdefdir /etc/sysconfig/SuSEfirewall2.d/services Name: puppet -Version: 2.7.16 +Version: 2.7.18 Release: 0 Summary: A network tool for managing many disparate systems License: Apache-2.0 ++++++ puppet-2.7.16.tar.gz -> puppet-2.7.18.tar.gz ++++++ ++++ 2035 lines of diff (skipped) -- To unsubscribe, e-mail: opensuse-commit+unsubscr...@opensuse.org For additional commands, e-mail: opensuse-commit+h...@opensuse.org