Hello community, here is the log from the commit of package cups checked in at Sat Jan 12 02:48:20 CET 2008. -------- --- cups/cups.changes 2007-12-19 18:42:23.000000000 +0100 +++ /mounts/work_src_done/STABLE/cups/cups.changes 2008-01-07 19:42:43.838382000 +0100 @@ -1,0 +2,59 @@ +Mon Jan 7 19:39:28 CET 2008 - kssingvo@suse.de + +- update to version 1.3.5: + * The SNMP backend did not check for negative string lengths + * The scheduler incorrectly removed auth-info attributes, + potentially leading to a loss of all options for a job. + * The scheduler stopped sending CUPS browse packets on a restart + when using fixed addresses + * Fixed PDF filter security issues (CVE-2007-4352 CVE-2007-5392 + CVE-2007-5393) + * Changing settings would always change the DefaultAuthType and + Allow lines + * The scheduler would crash when submitting an undefined format + file from Samba with LogLevel debug2 + * The scheduler did not use poll() when epoll() was not supported + by the running kernel + * Fixed a compile problem with Heimdal Kerberos + * The USB backend now retries connections to a printer + indefinitely rather than stopping the queue. + * Printers with untranslated JCL options were not exported to + Samba correctly + * The USB backend did not work with some Minolta USB printers + * The strcasecmp() emulation code did not compile + * The scheduler would crash if a job was sent to an empty class + * The lpc command did not work in non-UTF-8 locales + * Subscriptions for printer-stopped events also received other + state changes + * cupstestppd incorrectly reported translation errors for the + "en" locale. + * ppdOpen() did not handle custom options properly when the + Custom attribute appeared before the OpenUI for that option. + * The scheduler could crash when deleting a printer or listing + old jobs. + * The Mac OS X USB backend did not allow for requeuing of jobs + submitted to a class. + * lpmove didn't accept a job ID by itself. + * The scheduler incorrectly removed job history information for + remote print jobs. + * The scheduler incorrectly sent the + "com.apple.printerListChanged" message for printer state + changes. + * The PostScript filter drew the page borders (when enabled) + outside the imageable area. + * The LPD and IPP backends did not default to the correct port + numbers when using alternate scheme names. + * The scheduler incorrectly deleted hardwired remote printers on + system sleep. + * The scheduler would abort if a bad browse protocol name was + listed in the cupsd.conf file. + * The online cupsd.conf help file incorrectly showed "dns-sd" + instead of "dnssd" for Bonjour sharing. + * The scheduler could crash changing the port-monitor value. + * The scheduler generated CoreFoundation errors when run as a + background process. + * When printing with number-up > 1, it was possible to get an + extra blank page. +- removed CVE patches, which are already applied upstream + +------------------------------------------------------------------- Old: ---- cups-1.2-CVE_2007_4352.patch cups-1.2-CVE_2007_5392.patch cups-1.2-CVE_2007_5393.patch cups-1.3.4-source.tar.bz2 New: ---- cups-1.3.5-source.tar.bz2 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Other differences: ------------------ ++++++ cups.spec ++++++ --- /var/tmp/diff_new_pack.F20436/_old 2008-01-12 02:44:40.000000000 +0100 +++ /var/tmp/diff_new_pack.F20436/_new 2008-01-12 02:44:40.000000000 +0100 @@ -1,7 +1,7 @@ # -# spec file for package cups (Version 1.3.4) +# spec file for package cups (Version 1.3.5) # -# Copyright (c) 2007 SUSE LINUX Products GmbH, Nuernberg, Germany. +# Copyright (c) 2008 SUSE LINUX Products GmbH, Nuernberg, Germany. # This file and all modifications and additions to the pristine # package are under the same license as the package itself. # @@ -16,8 +16,8 @@ License: GPL v2 or later Group: Hardware/Printing Summary: The Common UNIX Printing System -Version: 1.3.4 -Release: 10 +Version: 1.3.5 +Release: 1 Requires: cups-libs = %{version}, cups-client = %{version} Requires: ghostscript_any, ghostscript-fonts-std, foomatic-filters Requires: util-linux @@ -52,9 +52,6 @@ Patch15: cups-1.2.11-testppd_filename.patch Patch16: cups-1.2.5-desktop_file.patch Patch17: cups-1.3.3-testppd_none.patch -Patch18: cups-1.2-CVE_2007_4352.patch -Patch19: cups-1.2-CVE_2007_5392.patch -Patch20: cups-1.2-CVE_2007_5393.patch Patch100: cups-1.1.23-testpage.patch BuildRoot: %{_tmppath}/%{name}-%{version}-build %if %suse_version >= 801 @@ -148,9 +145,6 @@ %patch15 -p1 %patch16 -p1 %patch17 -p1 -%patch18 -p1 -%patch19 -p1 -%patch20 -p1 if [ -f /.buildenv ]; then . /.buildenv else @@ -391,6 +385,62 @@ %{_datadir}/locale/*/cups_* %changelog +* Mon Jan 07 2008 - kssingvo@suse.de +- update to version 1.3.5: + * The SNMP backend did not check for negative string lengths + * The scheduler incorrectly removed auth-info attributes, + potentially leading to a loss of all options for a job. + * The scheduler stopped sending CUPS browse packets on a restart + when using fixed addresses + * Fixed PDF filter security issues (CVE-2007-4352 CVE-2007-5392 + CVE-2007-5393) + * Changing settings would always change the DefaultAuthType and + Allow lines + * The scheduler would crash when submitting an undefined format + file from Samba with LogLevel debug2 + * The scheduler did not use poll() when epoll() was not supported + by the running kernel + * Fixed a compile problem with Heimdal Kerberos + * The USB backend now retries connections to a printer + indefinitely rather than stopping the queue. + * Printers with untranslated JCL options were not exported to + Samba correctly + * The USB backend did not work with some Minolta USB printers + * The strcasecmp() emulation code did not compile + * The scheduler would crash if a job was sent to an empty class + * The lpc command did not work in non-UTF-8 locales + * Subscriptions for printer-stopped events also received other + state changes + * cupstestppd incorrectly reported translation errors for the + "en" locale. + * ppdOpen() did not handle custom options properly when the + Custom attribute appeared before the OpenUI for that option. + * The scheduler could crash when deleting a printer or listing + old jobs. + * The Mac OS X USB backend did not allow for requeuing of jobs + submitted to a class. + * lpmove didn't accept a job ID by itself. + * The scheduler incorrectly removed job history information for + remote print jobs. + * The scheduler incorrectly sent the + "com.apple.printerListChanged" message for printer state + changes. + * The PostScript filter drew the page borders (when enabled) + outside the imageable area. + * The LPD and IPP backends did not default to the correct port + numbers when using alternate scheme names. + * The scheduler incorrectly deleted hardwired remote printers on + system sleep. + * The scheduler would abort if a bad browse protocol name was + listed in the cupsd.conf file. + * The online cupsd.conf help file incorrectly showed "dns-sd" + instead of "dnssd" for Bonjour sharing. + * The scheduler could crash changing the port-monitor value. + * The scheduler generated CoreFoundation errors when run as a + background process. + * When printing with number-up > 1, it was possible to get an + extra blank page. +- removed CVE patches, which are already applied upstream * Wed Dec 19 2007 - crivera@suse.de - Add dbus-1-devel to the BuildRequires. * Mon Dec 17 2007 - crivera@suse.de ++++++ cups-1.3.4-source.tar.bz2 -> cups-1.3.5-source.tar.bz2 ++++++ ++++ 6549 lines of diff (skipped) ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Remember to have fun... --------------------------------------------------------------------- To unsubscribe, e-mail: opensuse-commit+unsubscribe@opensuse.org For additional commands, e-mail: opensuse-commit+help@opensuse.org
participants (1)
-
root@Hilbert.suse.de