--- rpms/e-smith-apache/sme8/e-smith-apache.spec 2014/01/14 04:12:43 1.17 +++ rpms/e-smith-apache/sme8/e-smith-apache.spec 2014/10/24 10:46:50 1.18 @@ -1,10 +1,10 @@ -# $Id: e-smith-apache.spec,v 1.16 2013/10/07 23:19:19 mrjhb3 Exp $ +# $Id: e-smith-apache.spec,v 1.17 2014/01/14 04:12:43 wellsi Exp $ Summary: e-smith server and gateway - apache module %define name e-smith-apache Name: %{name} %define version 2.2.0 -%define release 12 +%define release 13 Version: %{version} Release: %{release}%{?dist} License: GPL @@ -20,6 +20,7 @@ Patch6: e-smith-apache-2.2.0-server-reso Patch7: e-smith-apache-2.2.0-disableIconsIndex.patch Patch8: e-smith-apache-2.2.0-apache_modules.patch Patch9: e-smith-apache-2.2.0-35SSL10SSLCipherSuite.patch +Patch10: e-smith-apache-2.2.0-mitigate_crime.patch BuildRoot: /var/tmp/%{name}-%{version}-%{release}-buildroot BuildArchitectures: noarch Requires: e-smith-base >= 4.15.1 @@ -35,6 +36,9 @@ BuildRequires: e-smith-devtools >= 1.11. e-smith server and gateway software - apache module. %changelog +* Fri Oct 24 2014 Daniel Berteaud 2.2.0-13.sme +- Mitigate CRIM, CVE-2012-4929 [SME: 8614] + * Mon Jan 13 2014 Ian Wells 2.2.0-12.sme - Remove insecure ciphers [SME: 7916] @@ -572,6 +576,7 @@ e-smith server and gateway software - ap %patch7 -p1 %patch8 -p1 %patch9 -p1 +%patch10 -p1 %pre