File cvs.changes of Package cvs
-------------------------------------------------------------------
Tue Sep 14 14:21:24 UTC 2021 - Josef Möllers <josef.moellers@suse.com>
- Upgrade of SLE15-SP4 to latest Factory release 1.12.13
-------------------------------------------------------------------
Wed Sep 19 15:32:59 UTC 2018 - josef.moellers@suse.com
- Upgrade to 1.12.13
This version fixes two security vulnerabilities in the zlib
compression libraries (see CERT vulnerabilities advisories
#238678 & #680620 for more info), several issues involving
potential data-loss on heavily loaded systems, some minor
potential crashes, hangs, and several minor annoyances in CVS
client and server behavior.
See also:
https://savannah.nongnu.org/forum/forum.php?forum_id=4046
http://cvs.savannah.gnu.org/viewvc/cvs/ccvs/NEWS?revision=1.341
-------------------------------------------------------------------
Fri Feb 9 12:03:19 UTC 2018 - kukuk@suse.com
- Don't create unused xinetd directory
-------------------------------------------------------------------
Fri Aug 11 12:21:12 UTC 2017 - josef.moellers@suse.com
- Disallow a leading dash in the argument of the "-d" option.
[bsc#1053364, CVE-2017-12836,
cvs-Bug-1053364-disallow-dash.patch]
- Changed license to "GPL-2.0"
see http://cvs.savannah.nongnu.org/viewvc/cvs/ccvs/cvs.spec.in
-------------------------------------------------------------------
Thu Jun 15 11:38:00 UTC 2017 - mpluskal@suse.com
- Update dependencies:
* enable kerberos
* explicitly require ssh
-------------------------------------------------------------------
Thu Jun 15 09:41:35 UTC 2017 - tchvatal@suse.com
- Update bit with spec-cleaner
- Use proper url for docu and do not recompress:
* OpenSourceDevWithCVS_2E.tar.gz instead of bz2
- Add systemd socket service to replace the xinetd service
-------------------------------------------------------------------
Fri Mar 22 09:06:16 UTC 2013 - mmeister@suse.com
- Added url as source.
Please see http://en.opensuse.org/SourceUrls
-------------------------------------------------------------------
Mon Feb 4 14:30:50 UTC 2013 - coolo@suse.com
- update license to new format
-------------------------------------------------------------------
Tue Feb 21 11:50:12 CET 2012 - pth@suse.de
- Fix typo in the last patch.
-------------------------------------------------------------------
Mon Jan 30 14:35:57 CET 2012 - pth@suse.de
- Fix the way CVS reads proxy connection HTTP responses
(bnc#744059, CVE-2012-0804).
-------------------------------------------------------------------
Fri Dec 2 07:47:31 UTC 2011 - coolo@suse.com
- add automake as buildrequire to avoid implicit dependency
-------------------------------------------------------------------
Sun Sep 18 00:11:50 UTC 2011 - jengelh@medozas.de
- Remove redundant tags/sections from specfile
-------------------------------------------------------------------
Mon Sep 20 11:20:13 CEST 2010 - pth@suse.de
- Fix spec file (bnc#609970).
-------------------------------------------------------------------
Mon Jun 28 06:38:35 UTC 2010 - jengelh@medozas.de
- use %_smp_mflags
-------------------------------------------------------------------
Mon May 31 10:11:15 UTC 2010 - pth@novell.com
- Mention all included documentation (bnc#609970).
- Change URL to http://www.nongnu.org/cvs/.
-------------------------------------------------------------------
Wed Dec 16 10:52:55 CET 2009 - jengelh@medozas.de
- Package documentation as noarch
-------------------------------------------------------------------
Tue Apr 28 15:37:14 CEST 2009 - pth@suse.de
- Make cvs use ssh by default for :ext: transport (bnc#498801).
-------------------------------------------------------------------
Mon Aug 18 19:30:57 CEST 2008 - schwab@suse.de
- Fix buggy AC_FUNC_MKTIME reimplementation.
-------------------------------------------------------------------
Fri Jun 27 16:36:32 CEST 2008 - schwab@suse.de
- Fix gnulib macros.
- Fix printf format strings.
-------------------------------------------------------------------
Fri Nov 9 16:44:18 CET 2007 - pth@suse.de
- Make rcs2log request the installation of the rcs package if
/usr/bin/rlog isn't found (#331967).
- Install man page for rcs2log.
- Use rpm macros for path names.
- Fix printf format strings.
- Resync patches.
- Give every patch a cvs- prefix.
- Recompress additional sources with bzip2.
-------------------------------------------------------------------
Tue Jun 19 17:57:09 CEST 2007 - mkoenig@suse.de
- adjust path to vitmp [#264909]
-------------------------------------------------------------------
Wed May 2 12:51:01 CEST 2007 - coolo@suse.de
- remove support for susehelp - as cvs is a base pack and susehelp
isn't really used anymore
-------------------------------------------------------------------
Thu Mar 22 16:35:16 CET 2007 - rguenther@suse.de
- add zlib-devel and gdbm-devel BuildRequires
-------------------------------------------------------------------
Wed Mar 7 23:58:48 CET 2007 - rguenther@suse.de
- use vitmp as default editor
-------------------------------------------------------------------
Wed Sep 20 17:40:21 CEST 2006 - rguenther@suse.de
- reference existing file in desktop file
-------------------------------------------------------------------
Mon Sep 4 15:27:00 CEST 2006 - rguenther@suse.de
- get rid of postfix build dependency by making /sbin/sendmail
the default
- patch configure.in in use_vitmp.diff because configure gets
overwritten by autoconf invocation
-------------------------------------------------------------------
Wed Jan 25 21:30:04 CET 2006 - mls@suse.de
- converted neededforbuild to BuildRequires
-------------------------------------------------------------------
Fri Nov 4 13:02:25 CET 2005 - od@suse.de
- corrected fix of type punned pointer warning in ls.c:327
-------------------------------------------------------------------
Mon Oct 31 01:58:49 CET 2005 - od@suse.de
- fix type punned pointer warning in ls.c:327
-------------------------------------------------------------------
Thu Oct 20 15:21:47 CEST 2005 - od@suse.de
- fix "cvs up" segfault on corrupt repository file (#129681)
-------------------------------------------------------------------
Tue Aug 30 11:04:29 CEST 2005 - lnussel@suse.de
- fix /tmp issue in cvsbug (#59450)
-------------------------------------------------------------------
Thu Aug 11 14:18:33 CEST 2005 - schwab@suse.de
- Don't use [v]asnprintf.
-------------------------------------------------------------------
Wed Aug 10 23:08:47 CEST 2005 - hvogel@suse.de
- update to version 1.12.12 to get rid of bugs of locales that use
"GMT" for one of their UTC offsets. [Bug #86422]
-------------------------------------------------------------------
Sun Feb 6 13:02:30 CET 2005 - meissner@suse.de
- added format string markup for 2 functions
-------------------------------------------------------------------
Mon Jan 31 18:35:15 CET 2005 - adrian@suse.de
- update to version 1.12.11
-------------------------------------------------------------------
Mon Jan 24 11:51:25 CET 2005 - meissner@suse.de
- 0 -> NULL for 1 execl, fixed return type of a
function.
-------------------------------------------------------------------
Fri Aug 20 10:53:22 CEST 2004 - adrian@suse.de
- update to version 1.12.9
- remove obsolete security patches
-------------------------------------------------------------------
Fri Jun 4 10:23:14 CEST 2004 - adrian@suse.de
- update last patch to fix WinCVS support (20040521 version)
- new krahmer+esser security fix for (#39773)
* error_prog_name "double-free()" (SE)
CAN-2004-0416
* argument integer overflow (SK)
CAN-2004-0417
* serve_notify() out of bound writes (SK)
CAN-2004-0418
-------------------------------------------------------------------
Mon May 24 18:05:00 CEST 2004 - adrian@suse.de
- update to version 1.12.7
* cleanup obsolete patches
all work made by Dirk Mueller
-------------------------------------------------------------------
Mon May 3 11:50:54 CEST 2004 - adrian@suse.de
- expoit-fix for malformed Entry lines. This can be exploited via
a buffer overflow (#39773)
-------------------------------------------------------------------
Tue Apr 20 12:36:07 CEST 2004 - adrian@suse.de
- update to cvslock 0.2
- add the cvs book from red-bean into new subpackage -doc
- general cleanup
-------------------------------------------------------------------
Sat Apr 17 11:46:02 CEST 2004 - mmj@suse.de
- Fix typepunning
-------------------------------------------------------------------
Thu Mar 25 17:29:40 CET 2004 - mmj@suse.de
- Add postfix to # neededforbuild
-------------------------------------------------------------------
Mon Mar 22 10:57:25 CET 2004 - adrian@suse.de
- apply security fix from Derek
* CVS pserver client side exploit (#36659)
-------------------------------------------------------------------
Sat Mar 13 10:10:42 CET 2004 - adrian@suse.de
- update to new version 1.11.14
(fixes #35890)
-------------------------------------------------------------------
Thu Jan 8 17:55:16 CET 2004 - adrian@suse.de
- update to new version 1.11.11
-------------------------------------------------------------------
Fri Dec 12 12:33:07 CET 2003 - fehr@suse.de
- update to new version 1.11.10
-------------------------------------------------------------------
Tue Nov 18 15:57:27 CET 2003 - meissner@suse.de
- norootforbuild.
- no longer require tcsh, patch configure.in to
fall back to /usr/bin/csh directly.
-------------------------------------------------------------------
Thu Oct 16 11:46:06 CEST 2003 - fehr@suse.de
- update to new version 1.11.9
-------------------------------------------------------------------
Wed Aug 13 11:47:50 CEST 2003 - fehr@suse.de
- provide /etc/profile.d/cvs.{sh,csh} and make cvs use ssh as
default (#28702)
-------------------------------------------------------------------
Mon Jul 14 11:28:58 CEST 2003 - fehr@suse.de
- update to new version 1.11.6
-------------------------------------------------------------------
Wed Jul 9 16:30:43 CEST 2003 - fehr@suse.de
- use new parameters for sort (#26448)
-------------------------------------------------------------------
Fri May 23 13:02:58 CEST 2003 - fehr@suse.de
- adopt patches for tmp-race fixes and vitmp usage from OpenWall
Project
- use zlib from system instead of sources provided with cvs
-------------------------------------------------------------------
Thu Apr 24 12:20:23 CEST 2003 - ro@suse.de
- fix install_info --delete call and move from preun to postun
-------------------------------------------------------------------
Wed Apr 16 09:21:59 CEST 2003 - coolo@suse.de
- use BuildRoot
-------------------------------------------------------------------
Wed Mar 5 14:49:49 CET 2003 - fehr@suse.de
- add missing file /etc/xinetd.d/cvs (#24671)
-------------------------------------------------------------------
Fri Feb 7 15:19:46 CET 2003 - fehr@suse.de
- Use %install_info macro
-------------------------------------------------------------------
Fri Jan 31 15:27:08 CET 2003 fehr@suse.de
- fix race that may lead to aborted checkouts of large files
(fix_sigpipe_flowcontrol.diff, #23178)
- allow trailing slashes on directories (e.g. cvs up src/)
(allow_trailing_dir_slash.diff, #13165)
-------------------------------------------------------------------
Wed Jan 22 11:20:25 CET 2003 - fehr@suse.de
- make the feature Checkin-prog/Update-prog configurable
(default is off)
- update to version 1.11.5
-------------------------------------------------------------------
Mon Jan 20 18:13:38 CET 2003 - fehr@suse.de
- disable the commands Checkin-prog/Update-prog in cvs server
decision was made by SuSE security team (security@suse.de)
-------------------------------------------------------------------
Thu Jan 16 17:52:04 CET 2003 - fehr@suse.de
- update to cvs version 1.11.4
- add a patch that fixes a possible double free in cvs server
-------------------------------------------------------------------
Sat Feb 23 19:55:39 CET 2002 - kukuk@suse.de
- Don't require tcsh [Bug #13424]
-------------------------------------------------------------------
Fri Feb 8 02:10:11 MET 2002 - draht@suse.de
- added patch cvs-1.11.1p1-zlib-zfree.dif against duplicate calls
of free() in zlib
-------------------------------------------------------------------
Fri Dec 14 11:54:28 CET 2001 - fehr@suse.de
- update to new version 1.11.1p1
-------------------------------------------------------------------
Tue May 8 17:26:48 CEST 2001 - mfabian@suse.de
- bzip2 sources
-------------------------------------------------------------------
Mon Mar 19 10:08:40 MET 2001 - fehr@suse.de
- add diff-k.possible.patch which fixes problem when using
cvs diff -k.. (#6653)
-------------------------------------------------------------------
Fri Feb 9 17:58:01 CET 2001 - schwab@suse.de
- Ignore $HOME when running as server (#6293).
-------------------------------------------------------------------
Tue Jan 16 14:23:16 CET 2001 - werner@suse.de
- Make last security patch smarter: Ignore not existing temp files
-------------------------------------------------------------------
Wed Jan 10 17:31:10 CET 2001 - werner@suse.de
- Add temp file patch of Olaf Kirch
-------------------------------------------------------------------
Mon Sep 25 12:35:15 MEST 2000 - fehr@suse.de
- changed to new version 1.11
-------------------------------------------------------------------
Fri Aug 25 09:27:27 MEST 2000 - fehr@suse.de
- changed to new version 1.10.8
-------------------------------------------------------------------
Tue Jul 11 17:29:11 MEST 2000 - fehr@suse.de
- add tcsh to needforbuild to fix a csh-dependet script
-------------------------------------------------------------------
Mon Mar 13 08:45:30 CET 2000 - ro@suse.de
- fixed possible segfault
-------------------------------------------------------------------
Fri Feb 25 12:35:48 CET 2000 - kukuk@suse.de
- Move /usr/{info,man} -> /usr/share/{info,man}
-------------------------------------------------------------------
Mon Sep 13 17:23:57 CEST 1999 - bs@suse.de
- ran old prepare_spec on spec file to switch to new prepare_spec.
-------------------------------------------------------------------
Fri Sep 3 14:36:10 MEST 1999 - fehr@suse.de
- changed to version 1.10.7
-------------------------------------------------------------------
Fri Aug 27 16:33:09 MEST 1999 - fehr@suse.de
- added cvslock package
-------------------------------------------------------------------
Tue Jul 20 12:34:05 MEST 1999 - florian@suse.de
- update to 1.10.6, add server patch
-------------------------------------------------------------------
Fri Feb 19 15:06:01 MET 1999 - uli@suse.de
- update 1.9.28 -> 1.10.5
- eliminated Makefile.Linux
----------------------------------------------------------------------------
Thu Jul 23 14:30:31 MET DST 1998 - werner@suse.de
- use mktemp
----------------------------------------------------------------------------
Thu Jul 16 22:57:48 MEST 1998 - florian@suse.de
- update to version 1.9.28
----------------------------------------------------------------------------
Wed Jul 15 22:24:51 MET DST 1998 - werner@suse.de
- Fix possible exploit of rcs2log.sh
----------------------------------------------------------------------------
Mon Mar 2 17:21:46 MET 1998 - florian@suse.de
- update to version 1.9.24
----------------------------------------------------------------------------
Fri Oct 10 11:57:35 MEST 1997 - florian@suse.de
- update to version 1.9.16
----------------------------------------------------------------------------
Wed Apr 30 15:57:14 CEST 1997 - florian@suse.de
- update to version 1.9.8
----------------------------------------------------------------------------
Sun Apr 13 23:04:29 MEST 1997 - florian@suse.de
- update to new version 1.9.2