--- rpms/php/sme8/php.spec 2011/09/28 17:13:27 1.5 +++ rpms/php/sme8/php.spec 2011/11/03 22:54:19 1.6 @@ -18,7 +18,7 @@ Summary: PHP scripting language for creating dynamic web sites Name: php Version: 5.3.3 -Release: 1%{?dist}.1.1 +Release: 1%{?dist}.3 License: PHP and LGPLv2 and LGPLv2+ Group: Development/Languages URL: http://www.php.net/ @@ -58,6 +58,16 @@ Patch208: php-5.3.2-CVE-2010-3870.patch Patch209: php-5.3.3-CVE-2010-4156.patch Patch210: php-5.3.3-CVE-2010-3710.patch Patch211: php-5.3.2-CVE-2010-4645.patch +Patch212: php-5.3.3-CVE-2011-0708.patch +Patch213: php-5.3.3-CVE-2011-1148.patch +Patch214: php-5.3.3-CVE-2011-1466.patch +Patch215: php-5.3.3-CVE-2011-1468.patch +Patch216: php-5.3.3-CVE-2011-1469.patch +Patch217: php-5.3.3-CVE-2011-1470.patch +Patch218: php-5.3.3-CVE-2011-1471.patch +Patch219: php-5.3.3-CVE-2011-1938.patch +Patch220: php-5.3.3-CVE-2011-2202.patch +Patch221: php-5.3.3-CVE-2011-2483.patch BuildRoot: %{_tmppath}/%{name}-%{version}-%{release}-root-%(%{__id_u} -n) @@ -353,6 +363,16 @@ support for using the ICU library to PHP %patch209 -p1 -b .cve4156 %patch210 -p1 -b .cve3710 %patch211 -p1 -b .cve4645 +%patch212 -p1 -b .cve0708 +%patch213 -p1 -b .cve1148 +%patch214 -p1 -b .cve1466 +%patch215 -p1 -b .cve1468 +%patch216 -p1 -b .cve1469 +%patch217 -p1 -b .cve1470 +%patch218 -p1 -b .cve1471 +%patch219 -p1 -b .cve1938 +%patch220 -p1 -b .cve2202 +%patch221 -p1 -b .cve2483 # Prevent %%doc confusion over LICENSE files cp -p Zend/LICENSE Zend/ZEND_LICENSE @@ -730,12 +750,18 @@ rm files.* macros.php %files process -f files.process %changelog -* Wed Sep 28 2011 Jonathan Martens - 5.3.3-1.1.1 +* Thu Nov 2 2011 Shad L. Lords - 5.3.3-1.3.sme - Obsolete php-domxml and php-dom [SME: 6733] - -* Tue Sep 13 2011 Shad L. Lords - 5.3.3-1.1.0 - Update Obsoletes and Conflicts [SME: 6436] +* Mon Oct 24 2011 Joe Orton - 5.3.3-1.3 +- improve CVE-2011-1466 fix to cover CAL_GREGORIAN, CAL_JEWISH + +* Mon Sep 26 2011 Joe Orton - 5.3.3-1.2 +- add security fixes for CVE-2011-2483, CVE-2011-0708, CVE-2011-1148, + CVE-2011-1466, CVE-2011-1468, CVE-2011-1469, CVE-2011-1470, + CVE-2011-1471, CVE-2011-1938, and CVE-2011-2202 (#740733) + * Wed Jan 19 2011 Joe Orton - 5.3.3-1.1 - add security fixes for CVE-2010-3710, CVE-2010-4156, CVE-2010-4645 (#670463)