[puppet] Update to 2.7.18, fixes CVE-2012-3864, CVE-2012-3865, CVE-2012-3866, CVE-2012-3867

Todd Zullinger tmz at fedoraproject.org
Wed Jul 18 21:57:48 UTC 2012


commit f4d623b933097278964d6997a65cbdec337f14cb
Author: Todd Zullinger <tmz at pobox.com>
Date:   Wed Jul 11 08:54:02 2012 -0400

    Update to 2.7.18, fixes CVE-2012-3864, CVE-2012-3865, CVE-2012-3866, CVE-2012-3867

 ...Do-not-sent-tagmail-reports-if-no-changes.patch |   46 --------------------
 puppet-2.6.16.tar.gz.asc                           |   17 -------
 puppet-2.7.13.tar.gz.asc                           |   17 -------
 puppet-2.7.18.tar.gz.asc                           |   18 ++++++++
 puppet.spec                                        |   11 +++--
 sources                                            |    2 +-
 6 files changed, 25 insertions(+), 86 deletions(-)
---
diff --git a/puppet-2.7.18.tar.gz.asc b/puppet-2.7.18.tar.gz.asc
new file mode 100644
index 0000000..ffa35a6
--- /dev/null
+++ b/puppet-2.7.18.tar.gz.asc
@@ -0,0 +1,18 @@
+-----BEGIN PGP SIGNATURE-----
+Version: GnuPG/MacGPG2 v2.0.18 (Darwin)
+Comment: GPGTools - http://gpgtools.org
+
+iQIcBAABAgAGBQJP/JQ9AAoJEBBUt6JL1uwwko0P/igNdI01Lkss73TaRRSGiJcF
+dLSSqyNjrgyiAoZkBTlyL7qPf76l5t7qhzO6cjj6q64e5yaGfZAbr65d4LhIGs7Z
+fcpzC4MpRhcaZKTqp9864Fhwd0UC/rzMAMaR1bRkSLVgcR0F6WXDcoclnwcRZXb5
+e6b51JI85G0lyQB95Gq0SIUZQ/n8OsMDC/IhLpJLCbZIw7jRB1hciFPL6SuMGFlK
+Zw+3ZpMwWGOpLU0bxLL6Nw54vVwJDf1pq/Upi+EChPdkzJQw2rZR0qwDlavNd6Ax
+mEBwFyBOQ/mEiIRZslQk/TYQ+xuq3eCSk11E3ZJ+VDx2h7T4mqdEdZRoYmwliGOW
+EXR/+QmB7Jqmgi0Ue0Y1LYUsydHKvXYTeR8R/wmm4O3qD8CTQ0SxbsemO78o/dp0
+pM++wMjoAKO5vyZ0/3k+kblIzXy+BYdzeqThZArMhV5q3iIm5daYSegyIA4RCSgG
+mnyTGtaSQRQP685gwGdlF9P1kfrhnvw7UK2HW3WDsmkZh9lGlKSM3stwlB4FgXGu
+9OAFFhRVh23Ka5B6CAXBqIdXvjz3LOmKKalxcRwR36UEaJZ4OIlTDMAmbXofOvHq
+YbR0dWBovVMUn7N9vMC5AosOXApbQWNQINW2th21KV4lNvzc76bi3j5iTMsBKARE
+qNhzL1TXuJYNPUv88UxJ
+=mjJz
+-----END PGP SIGNATURE-----
diff --git a/puppet.spec b/puppet.spec
index 90b9418..719f3fd 100644
--- a/puppet.spec
+++ b/puppet.spec
@@ -12,7 +12,7 @@
 %global ruby_version    %(ruby -rrbconfig -e 'puts RbConfig::CONFIG["ruby_version"]')
 
 Name:           puppet
-Version:        2.7.13
+Version:        2.7.18
 Release:        1%{?dist}
 Summary:        A network tool for managing many disparate systems
 License:        ASL 2.0
@@ -20,11 +20,9 @@ URL:            http://puppetlabs.com
 Source0:        http://downloads.puppetlabs.com/%{name}/%{name}-%{version}.tar.gz
 Source1:        http://downloads.puppetlabs.com/%{name}/%{name}-%{version}.tar.gz.asc
 Source2:        puppetstoredconfigclean.rb
-# https://projects.puppetlabs.com/issues/9167
-Patch0:         0001-9167-Do-not-sent-tagmail-reports-if-no-changes.patch
 # http://projects.puppetlabs.com/issues/11325
 # https://github.com/puppetlabs/puppet/commit/a71208ba
-Patch1:         0001-Ruby-1.9.3-has-a-different-error-when-require-fails.patch
+Patch0:         0001-Ruby-1.9.3-has-a-different-error-when-require-fails.patch
 
 Group:          System Environment/Base
 
@@ -85,7 +83,6 @@ The server can also function as a certificate authority and file server.
 %prep
 %setup -q
 %patch0 -p1
-%patch1 -p1
 patch -s -p1 < conf/redhat/rundir-perms.patch
 
 # Fix some rpmlint complaints
@@ -278,6 +275,10 @@ fi
 rm -rf %{buildroot}
 
 %changelog
+* Wed Jul 11 2012 Todd Zullinger <tmz at pobox.com> - 2.7.18-1
+- Update to 2.7.17, fixes CVE-2012-3864, CVE-2012-3865, CVE-2012-3866,
+  CVE-2012-3867
+
 * Wed Apr 25 2012 Todd Zullinger <tmz at pobox.com> - 2.7.13-1
 - Update to 2.7.13
 - Change license from GPLv2 to ASL 2.0
diff --git a/sources b/sources
index 2872b17..d232dc6 100644
--- a/sources
+++ b/sources
@@ -1 +1 @@
-8062f371cc7ec5c7e5cd5f4b6c3f9278  puppet-2.7.13.tar.gz
+210725704692a0ca7b8ffc312471796e  puppet-2.7.18.tar.gz


More information about the scm-commits mailing list