Hello community, here is the log from the commit of package varnish for openSUSE:Factory checked in at 2014-02-07 11:56:17 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Comparing /work/SRC/openSUSE:Factory/varnish (Old) and /work/SRC/openSUSE:Factory/.varnish.new (New) ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "varnish" Changes: -------- --- /work/SRC/openSUSE:Factory/varnish/varnish.changes 2013-11-02 09:07:56.000000000 +0100 +++ /work/SRC/openSUSE:Factory/.varnish.new/varnish.changes 2014-02-07 11:56:18.000000000 +0100 @@ -1,0 +2,15 @@ +Fri Jan 3 10:57:19 UTC 2014 - dan...@owncloud.com + +- Updated to 3.0.5, contains fix for CVE-2013-4484 +* A bad interaction between -b, -c and -m in the varnishlog tool + has been fixed. +* A malformed request could in some configurations lead to Varnish + crashing has been corrected. (CVE-2013-4484) +* Duplicate Content-Length headers were in some cases sent to + clients when streaming is enabled, this has been fixed. +* ESI parse errors are no longer printed to standard output. +* Stop segfaulting if the first part of a synthetic page is NULL. +- Remove 0001-Make-up-our-mind-Any-req.-we-receive-from-the-client.patch + and varnish-disable-pcrejit.diff (merged upstream) + +------------------------------------------------------------------- Old: ---- 0001-Make-up-our-mind-Any-req.-we-receive-from-the-client.patch varnish-3.0.3.tar.xz varnish-disable-pcrejit.diff New: ---- varnish-3.0.5.tar.gz ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Other differences: ------------------ ++++++ varnish.spec ++++++ --- /var/tmp/diff_new_pack.6lZxdW/_old 2014-02-07 11:56:19.000000000 +0100 +++ /var/tmp/diff_new_pack.6lZxdW/_new 2014-02-07 11:56:19.000000000 +0100 @@ -17,7 +17,7 @@ Name: varnish %define library_name libvarnishapi1 -Version: 3.0.3 +Version: 3.0.5 Release: 0 Summary: Varnish is a high-performance HTTP accelerator License: BSD-2-Clause @@ -27,7 +27,7 @@ #Git-Clone: git://git.varnish-cache.org/varnish-cache #Git-Web: https://varnish-cache.org/trac/browser #DL-URL: http://downloads.sf.net/varnish/%name-%version.tar.bz2 -Source: %name-%version.tar.xz +Source: %name-%version.tar.gz Source2: varnish.init Source3: varnish.sysconfig Source4: vcl.conf @@ -35,11 +35,9 @@ Source6: varnishlog.init Source7: varnish.service Source8: varnishlog.service -Patch1: varnish-disable-pcrejit.diff -Patch2: 0001-Make-up-our-mind-Any-req.-we-receive-from-the-client.patch BuildRoot: %_tmppath/%name-%version-build -BuildRequires: libxslt, ncurses-devel, pcre-devel +BuildRequires: libxslt, ncurses-devel, pcre-devel, readline-devel BuildRequires: pkgconfig, xz Prereq(post): %_sbindir/useradd %_sbindir/groupadd %if 0%{?suse_version} >= 1010 @@ -99,7 +97,6 @@ %prep %setup -q -%patch -P 1 -P 2 -p1 %build export CFLAGS="%optflags -fstack-protector" -- To unsubscribe, e-mail: opensuse-commit+unsubscr...@opensuse.org For additional commands, e-mail: opensuse-commit+h...@opensuse.org