--- rpms/smeserver-vacation/contribs9/smeserver-vacation.spec 2016/07/16 06:19:59 1.23 +++ rpms/smeserver-vacation/contribs9/smeserver-vacation.spec 2017/01/16 21:37:46 1.24 @@ -1,10 +1,10 @@ -# $Id: smeserver-vacation.spec,v 1.22 2016/07/15 18:22:13 stephdl Exp $ +# $Id: smeserver-vacation.spec,v 1.23 2016/07/16 06:19:59 stephdl Exp $ # Authority: dungog # Name: Stephen Noble %define name smeserver-vacation %define version 1.1 -%define release 22 +%define release 23 Summary: SME Server enhancement to enable vacation messages for users. Name: %{name} Version: %{version} @@ -31,6 +31,8 @@ Patch14: smeserver-vacation-1.1-locale-2 Patch15: smeserver-vacation-1.1.bz9661.fix_auto_enable_disable_vacation.patch Patch16: smeserver-vacation-1.1.bz8772.fix.vacation.message.translation.patch Patch17: smeserver-vacation-1.1-locale-2016-07-15.patch +Patch18: smeserver-vacation-1.1-bz9073-race.condition.vulnarability.patch +Patch19: smeserver-vacation-1.1-locale-2017-01-16.patch BuildArchitectures: noarch BuildRoot: /var/tmp/%{name}-%{version} Requires: e-smith-release >= 9.0, @@ -44,6 +46,11 @@ Optionally provides a user-manager panel enable vacation for themselves and to modify their own message %changelog +* Mon Jan 16 2017 Jean-Philipe Pialasse 1.1-23.sme +- Fix possible race condition vulnerability during creation of vacation.msg [SME: 9073] +- thanks to Mats Schuh and Charlie Brady for the work. +- Translation smeserver-vacation-1.1-locale-2017-01-16.patch + * Sat Jul 16 2016 stephane de Labrusse 1.1-22.sme - Added a capital to subject : Subject [SME: 8772] @@ -318,6 +325,9 @@ enable vacation for themselves and to mo %patch15 -p1 %patch16 -p1 %patch17 -p1 +%patch18 -p1 +%patch19 -p1 + %build perl createlinks