pkgsrc-Changes-HG archive

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]

[pkgsrc/pkgsrc-2004Q4]: pkgsrc/www/squid Pullup ticket 239 - requested by Tak...



details:   https://anonhg.NetBSD.org/pkgsrc/rev/307491d3b0aa
branches:  pkgsrc-2004Q4
changeset: 485841:307491d3b0aa
user:      salo <salo%pkgsrc.org@localhost>
date:      Fri Jan 21 14:37:07 2005 +0000

description:
Pullup ticket 239 - requested by Takahiro Kambe
security fix for squid

Revisions pulled up:
- pkgsrc/www/squid/Makefile 1.125-1.128
- pkgsrc/www/squid/distinfo 1.73-1.74

   Module Name: pkgsrc
   Committed By:        taca
   Date:                Sun Jan 16 15:46:25 UTC 2005

   Modified Files:
        pkgsrc/www/squid: Makefile

   Log Message:
   Set PKG_USERS and PKG_GROUPS with SQUID_USER and SQUID_GROUP.
   Now squid's user and group are handled by bsd.pkg.install.mk properly.

   Thanks much to Volker Wiegand at t-online dot de noted this problem
   by private mail.

   Bump PKGREVISION.
---
   Module Name: pkgsrc
   Committed By:        kim
   Date:                Wed Jan 19 00:19:27 UTC 2005

   Modified Files:
        pkgsrc/www/squid: Makefile

   Log Message:
   Record SQUID_USER and SQUID_GROUP in BUILD_DEFS.
---
   Module Name: pkgsrc
   Committed By:        taca
   Date:                Wed Jan 19 14:56:55 UTC 2005

   Modified Files:
        pkgsrc/www/squid: Makefile distinfo

   Log Message:
   Apply three official patch including a minor security problem.

   o 2005-01-17 04:29 (Minor Secuity issue) Sanity check usernames
     in squid_ldap_auth
   o 2005-01-17 02:52 (Minor) FQDN names truncated on compressed DNS
     responses
   o 2005-01-17 02:52 (Minor) Internal DNS memory leak on malformed
     responses

   Bump package revision; squid-2.5.7nb7.
---
   Module Name: pkgsrc
   Committed By:        taca
   Date:                Fri Jan 21 13:41:27 UTC 2005

   Modified Files:
        pkgsrc/www/squid: Makefile distinfo

   Log Message:
   Update new official patched.

   o  2005-01-21 12:43 (Security issue)
        Strengthen Squid from HTTP response splitting cache pollution attack

   o  2005-01-21 12:10 (Minor)
        Icons fails to load on non-anonymous FTP when using
        short_icons_url directive

   o  2005-01-21 12:10 (Minor)
        FTP data connection fails on some FTP servers when requesting
        directory without a trailing slash

   One patch has problem to apply and hold to apply

   o  2005-01-21 12:10 (Minor) Disable Path-MTU discovery on intercepted
      requests

   Bump package revision.

diffstat:

 www/squid/Makefile |  16 +++++++++++++---
 www/squid/distinfo |  14 +++++++++++++-
 2 files changed, 26 insertions(+), 4 deletions(-)

diffs (69 lines):

diff -r 7d04f2c12cb7 -r 307491d3b0aa www/squid/Makefile
--- a/www/squid/Makefile        Fri Jan 21 11:23:19 2005 +0000
+++ b/www/squid/Makefile        Fri Jan 21 14:37:07 2005 +0000
@@ -1,8 +1,8 @@
-# $NetBSD: Makefile,v 1.120.2.2 2005/01/15 06:39:25 snj Exp $
+# $NetBSD: Makefile,v 1.120.2.3 2005/01/21 14:37:07 salo Exp $
 
 DISTNAME=      squid-2.5.STABLE7
 PKGNAME=       squid-2.5.7
-PKGREVISION=   5
+PKGREVISION=   8
 CATEGORIES=    www
 MASTER_SITES=  http://www.squid-cache.org/Versions/v2/2.5/ \
                ftp://ftp.leo.org/pub/comp/general/infosys/www/daemons/squid/squid-2/STABLE/ \
@@ -23,7 +23,14 @@
                squid-2.5.STABEL7-close_other.patch \
                squid-2.5.STABLE7-fakeauth_auth.patch \
                squid-2.5.STABLE7-gopher_html_parsing.patch \
-               squid-2.5.STABLE7-wccp_denial_of_service.patch
+               squid-2.5.STABLE7-wccp_denial_of_service.patch \
+               squid-2.5.STABLE7-dns_memleak.patch \
+               squid-2.5.STABLE7-fqdn_truncated.patch \
+               squid-2.5.STABLE7-ldap_spaces.patch \
+               squid-2.5.STABLE7-ftp_datachannel.patch \
+               squid-2.5.STABLE7-short_icons_urls.patch \
+               squid-2.5.STABLE7-response_splitting.patch
+#              squid-2.5.STABLE7-httpd_accel_no_pmtu_disc.patch # not yet
 PATCH_DIST_STRIP=       -p1
 
 MAINTAINER=    taca%NetBSD.org@localhost
@@ -65,7 +72,10 @@
 
 SQUID_USER?=   squid
 SQUID_GROUP?=  squid
+BUILD_DEFS+=   SQUID_USER SQUID_GROUP
 
+PKG_GROUPS=    ${SQUID_GROUP}
+PKG_USERS=     ${SQUID_USER}:${SQUID_GROUP}::Squid\\ Web-Cache\\ pseudo-user
 CONF_FILES+=   ${EXAMPLESDIR}/mime.conf ${PKG_SYSCONFDIR}/mime.conf
 CONF_FILES+=   ${EXAMPLESDIR}/squid.conf ${PKG_SYSCONFDIR}/squid.conf
 OWN_DIRS=      ${DATADIR}
diff -r 7d04f2c12cb7 -r 307491d3b0aa www/squid/distinfo
--- a/www/squid/distinfo        Fri Jan 21 11:23:19 2005 +0000
+++ b/www/squid/distinfo        Fri Jan 21 14:37:07 2005 +0000
@@ -1,4 +1,4 @@
-$NetBSD: distinfo,v 1.68.2.2 2005/01/15 06:39:25 snj Exp $
+$NetBSD: distinfo,v 1.68.2.3 2005/01/21 14:37:07 salo Exp $
 
 SHA1 (squid-2.5.7-2005010100/squid-2.5.STABLE7.tar.bz2) = 24f29e28ec62d7ab5888cd594ac7a1975ee6aa36
 Size (squid-2.5.7-2005010100/squid-2.5.STABLE7.tar.bz2) = 1051830 bytes
@@ -30,6 +30,18 @@
 Size (squid-2.5.7-2005010100/squid-2.5.STABLE7-gopher_html_parsing.patch) = 714 bytes
 SHA1 (squid-2.5.7-2005010100/squid-2.5.STABLE7-wccp_denial_of_service.patch) = e4bec66adbe369eaa91cd6db3a503eb0a6de40e1
 Size (squid-2.5.7-2005010100/squid-2.5.STABLE7-wccp_denial_of_service.patch) = 1928 bytes
+SHA1 (squid-2.5.7-2005010100/squid-2.5.STABLE7-dns_memleak.patch) = ea04865af9edb1db650090a6f163c33cfff69a16
+Size (squid-2.5.7-2005010100/squid-2.5.STABLE7-dns_memleak.patch) = 779 bytes
+SHA1 (squid-2.5.7-2005010100/squid-2.5.STABLE7-fqdn_truncated.patch) = de02ebf4455ce1d2e685d88cb372cb7d6423a9e8
+Size (squid-2.5.7-2005010100/squid-2.5.STABLE7-fqdn_truncated.patch) = 4484 bytes
+SHA1 (squid-2.5.7-2005010100/squid-2.5.STABLE7-ldap_spaces.patch) = f0ae7e6dbb9580186f2e091d840ccf3bda348abc
+Size (squid-2.5.7-2005010100/squid-2.5.STABLE7-ldap_spaces.patch) = 1974 bytes
+SHA1 (squid-2.5.7-2005010100/squid-2.5.STABLE7-ftp_datachannel.patch) = 1022f7166a7bd4d83c93d7d4014865f98efefea1
+Size (squid-2.5.7-2005010100/squid-2.5.STABLE7-ftp_datachannel.patch) = 4825 bytes
+SHA1 (squid-2.5.7-2005010100/squid-2.5.STABLE7-short_icons_urls.patch) = e7cf53c5a7db396d8fe89cf3c585fd591cb17903
+Size (squid-2.5.7-2005010100/squid-2.5.STABLE7-short_icons_urls.patch) = 704 bytes
+SHA1 (squid-2.5.7-2005010100/squid-2.5.STABLE7-response_splitting.patch) = 6e80f83f3cbc277b30bc9e9a6ffbc0918c0e1134
+Size (squid-2.5.7-2005010100/squid-2.5.STABLE7-response_splitting.patch) = 9782 bytes
 SHA1 (patch-aa) = 3e6fb677125eec276fdfa62336c134f26e1e1edd
 SHA1 (patch-ab) = 1224ba4cee98a26d2c9d670eb6d57c6187ff2d56
 SHA1 (patch-ac) = 1b283f0a573c02c82ce26f75e67d19b1ec5ff9f0



Home | Main Index | Thread Index | Old Index