Fedora 11 Update: hmaccalc-0.9.12-1.fc11

updates at fedoraproject.org updates at fedoraproject.org
Tue Feb 16 13:07:10 UTC 2010


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2010-1257
2010-02-01 00:41:06
--------------------------------------------------------------------------------

Name        : hmaccalc
Product     : Fedora 11
Version     : 0.9.12
Release     : 1.fc11
URL         : https://fedorahosted.org/hmaccalc/
Summary     : Tools for computing and checking HMAC values for files
Description :
The hmaccalc package contains tools which can calculate HMAC (hash-based
message authentication code) values for files.  The names and interfaces are
meant to mimic the sha*sum tools provided by the coreutils package.

--------------------------------------------------------------------------------
Update Information:

This update corrects a regression in how the hmaccalc binaries located the copy
of prelink that they would use to attempt to "un-prelink" themselves before
performing self-tests at startup-time.
--------------------------------------------------------------------------------
ChangeLog:

* Tue Dec 15 2009 Nalin Dahyabhai <nalin at redhat.com> 0.9.12-1
- fix regression of #512275 -- we looked for prelink, but didn't record
  its location properly (#559458)
* Tue Sep  8 2009 Nalin Dahyabhai <nalin at redhat.com> 0.9.11-1
- error out when we previously skipped a check entry because the value to be
  checked is the wrong size
- fix estimation of the expected length for truncated values
* Thu Sep  3 2009 Nalin Dahyabhai <nalin at redhat.com> 0.9.10-1
- refuse to truncate output below half the size of the hash length, or 80
  bits, whichever is higher, in case we get used in a situation where
  not doing so would make us vulnerable to CVE-2009-0217, in which an
  attacker manages to convince a party doing verification to truncate
  both the just-computed value and the value to be checked before
  comparing them, as comparing just 1 bit would make detecting forgeries
  close to impossible
* Fri Jul 24 2009 Fedora Release Engineering <rel-eng at lists.fedoraproject.org> - 0.9.9-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild
* Sat Jul 11 2009 Nalin Dahyabhai <nalin at redhat.com> 0.9.9-1
- look for prelink at compile-time, and if we find it try to invoke it
  using a full pathname before trying with $PATH (#512275)
- buildrequires: prelink so that it will be found at compile-time
* Tue Jun  9 2009 Nalin Dahyabhai <nalin at redhat.com> 0.9.8-1
- when checking, skip input lines which don't look like valid input lines
* Tue Jun  9 2009 Nalin Dahyabhai <nalin at redhat.com> 0.9.7-1
- add a binary (-b) mode when summing
--------------------------------------------------------------------------------

This update can be installed with the "yum" update program.  Use 
su -c 'yum update hmaccalc' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.

All packages are signed with the Fedora Project GPG key.  More details on the
GPG keys used by the Fedora Project can be found at
http://fedoraproject.org/keys
--------------------------------------------------------------------------------


More information about the package-announce mailing list