--- rpms/smeserver-phpwebftp/contribs8/smeserver-phpwebftp-4.0.spec 2013/11/04 23:51:35 1.3 +++ rpms/smeserver-phpwebftp/contribs8/smeserver-phpwebftp-4.0.spec 2016/08/03 08:12:48 1.6 @@ -1,10 +1,10 @@ -# $Id: smeserver-phpwebftp-4.0.spec,v 1.2 2013/03/03 21:48:44 unnilennium Exp $ +# $Id: smeserver-phpwebftp-4.0.spec,v 1.5 2013/11/24 23:00:51 unnilennium Exp $ # Authority: gnujpl # Name: Jean-Paul Leclère %define name smeserver-phpwebftp %define version 4.0 -%define release 6 +%define release 10 Summary: Web FTP access via HTTPS for SME. Name: %{name} @@ -14,6 +14,9 @@ License: GPL Group: Applications/WebFTP Source: %{name}-%{version}.tar.gz Patch0:smeserver-phpwebftp-4.0-patchftpmode.patch +Patch1: smeserver-phpwebftp-4.0-patch1.patch +Patch2: smeserver-phpwebftp-4.0.bz7175.pointusername.patch +Patch3: smeserver-phpwebftp-4.0.bz9528.XSSvulnerability.patch BuildRoot: /var/tmp/%{name}-%{version}-%{release}-buildroot BuildArchitectures: noarch Requires: e-smith-apache @@ -25,10 +28,23 @@ AutoReqProv: no smeserver-phpwebftp adds an ftp panel available to users via SSL web access. %changelog -*Mon Nov 4 2013 JP Pialasse 4.0-6.sme +* Wed Aug 03 2016 Jean-Philipe Pialasse 4.0-10.sme +- fix XSS security issue in phpwebftp [SME: 9528] +- https://sourceforge.net/p/phpwebftp/bugs/17/ +- add utf8 in meta to fix bad display in French + +* Wed Aug 03 2016 Jean-Philipe Pialasse 4.0-9.sme +- fix does not support files owned by user or group with point [SME: 7175] +- SF:https://sourceforge.net/p/phpwebftp/bugs/15/ + +* Sun Nov 24 2013 JP Pialasse 4.0-8.sme +- new patch for [SME: 7973] +- tmp folder set to 0770 to fix the download error + +* Mon Nov 4 2013 JP Pialasse 4.0-6.sme - wrong binary ascii switch [SME: 7973] -*Sun Mar 3 2013 JP Pialasse 4.0-5 +* Sun Mar 3 2013 JP Pialasse 4.0-5 - import into sme 8 tree * Sun Jun 8 2008 Jean-Paul Leclere @@ -70,6 +86,10 @@ smeserver-phpwebftp adds an ftp panel av %setup %patch0 -p1 +%patch1 -p1 +%patch2 -p1 +%patch3 -p1 + %pre @@ -83,7 +103,7 @@ rm -rf $RPM_BUILD_ROOT (cd root ; find . -depth -print | cpio -dump $RPM_BUILD_ROOT) rm -f e-smith-%{version}-filelist /sbin/e-smith/genfilelist $RPM_BUILD_ROOT \ - --dir '/home/httpd/html/webftp/tmp' 'attr(0640,www,www)' \ + --dir '/home/httpd/html/webftp/tmp' 'attr(0770,www,www)' \ > %{name}-%{version}-filelist /usr/lib/rpm/brp-python-bytecompile