LWN.net Logo

Fedora alert FEDORA-2012-13234 (rpmdevtools)

From:  updates@fedoraproject.org
To:  package-announce@lists.fedoraproject.org
Subject:  [SECURITY] Fedora 17 Update: rpmdevtools-8.3-1.fc17
Date:  Wed, 12 Sep 2012 00:24:49 +0000
Message-ID:  <20120912002451.8CE232105F@bastion01.phx2.fedoraproject.org>
Archive-link:  Article, Thread

-------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2012-13234 2012-09-03 22:24:57 -------------------------------------------------------------------------------- Name : rpmdevtools Product : Fedora 17 Version : 8.3 Release : 1.fc17 URL : https://fedorahosted.org/rpmdevtools/ Summary : RPM Development Tools Description : This package contains scripts and (X)Emacs support files to aid in development of RPM packages. rpmdev-setuptree Create RPM build tree within user's home directory rpmdev-diff Diff contents of two archives rpmdev-newspec Creates new .spec from template rpmdev-rmdevelrpms Find (and optionally remove) "development" RPMs rpmdev-checksig Check package signatures using alternate RPM keyring rpminfo Print information about executables and libraries rpmdev-md5/sha* Display checksums of all files in an archive file rpmdev-vercmp RPM version comparison checker spectool Expand and download sources and patches in specfiles rpmdev-wipetree Erase all files within dirs created by rpmdev-setuptree rpmdev-extract Extract various archives, "tar xvf" style rpmdev-bumpspec Bump revision in specfile ...and many more. -------------------------------------------------------------------------------- Update Information: Update to upstream version 8.3, fixing among other issues a symlink attack possibility in annotate-output (CVE-2012-3500). http://git.fedorahosted.org/cgit/rpmdevtools.git/tree/NEW... -------------------------------------------------------------------------------- ChangeLog: * Sun Sep 2 2012 Ville Skyttä <ville.skytta@iki.fi> - 8.3-1 - Update to 8.3. - Drop specfile constructs no longer needed with Fedora's rpm. * Sat Jul 21 2012 Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 8.2-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #841043 - [PATCH] licensecheck "Public domain" output causes truncation https://bugzilla.redhat.com/show_bug.cgi?id=841043 [ 2 ] Bug #789330 - rpmdev-bumpspec is confused on mysql-workbench spec file https://bugzilla.redhat.com/show_bug.cgi?id=789330 [ 3 ] Bug #828455 - rpmdev-newspec should use %make_install https://bugzilla.redhat.com/show_bug.cgi?id=828455 [ 4 ] Bug #853452 - CVE-2012-3500 rpmdevtools: TOCTOU race condition in annotate-output [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=853452 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update rpmdevtools' at the command line. For more information, refer to "Managing Software with yum", available at http://docs.fedoraproject.org/yum/. All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list package-announce@lists.fedoraproject.org https://admin.fedoraproject.org/mailman/listinfo/package-...


(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds