--- rpms/smeserver-phpwebftp/contribs9/smeserver-phpwebftp-4.0.spec 2016/08/03 06:09:25 1.2 +++ rpms/smeserver-phpwebftp/contribs9/smeserver-phpwebftp-4.0.spec 2016/08/03 08:05:50 1.3 @@ -1,10 +1,10 @@ -# $Id: smeserver-phpwebftp-4.0.spec,v 1.1 2016/08/03 05:48:10 unnilennium Exp $ +# $Id: smeserver-phpwebftp-4.0.spec,v 1.2 2016/08/03 06:09:25 unnilennium Exp $ # Authority: gnujpl # Name: Jean-Paul Leclère %define name smeserver-phpwebftp %define version 4.0 -%define release 10 +%define release 11 Summary: Web FTP access via HTTPS for SME. Name: %{name} @@ -16,6 +16,7 @@ Source: %{name}-%{version}.tar.gz Patch0:smeserver-phpwebftp-4.0-patchftpmode.patch Patch1: smeserver-phpwebftp-4.0-patch1.patch Patch2: smeserver-phpwebftp-4.0.bz7175.pointusername.patch +Patch3: smeserver-phpwebftp-4.0.bz9528.XSSvulnerability.patch BuildRoot: /var/tmp/%{name}-%{version}-%{release}-buildroot BuildArchitectures: noarch Requires: e-smith-apache @@ -27,6 +28,11 @@ AutoReqProv: no smeserver-phpwebftp adds an ftp panel available to users via SSL web access. %changelog +* Wed Aug 03 2016 Jean-Philipe Pialasse 4.0-11.sme +- fix XSS security issue in phpwebftp [SME: 9528] +- https://sourceforge.net/p/phpwebftp/bugs/17/ +- add utf8 in meta to fix bad display in French + * Wed Aug 03 2016 Jean-Philipe Pialasse 4.0-10.sme - fix does not support files owned by user or group with point [SME: 7175] - SF:https://sourceforge.net/p/phpwebftp/bugs/15/ @@ -85,7 +91,7 @@ smeserver-phpwebftp adds an ftp panel av %patch0 -p1 %patch1 -p1 %patch2 -p1 - +%patch3 -p1 %pre