Hello community,

here is the log from the commit of package yast2-packager for openSUSE:Factory 
checked in at 2012-09-14 12:43:28
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Comparing /work/SRC/openSUSE:Factory/yast2-packager (Old)
 and      /work/SRC/openSUSE:Factory/.yast2-packager.new (New)
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Package is "yast2-packager", Maintainer is "[email protected]"

Changes:
--------
--- /work/SRC/openSUSE:Factory/yast2-packager/yast2-packager.changes    
2012-05-22 10:11:12.000000000 +0200
+++ /work/SRC/openSUSE:Factory/.yast2-packager.new/yast2-packager.changes       
2012-09-14 12:43:29.000000000 +0200
@@ -1,0 +2,11 @@
+Tue Sep  4 14:13:07 CEST 2012 - [email protected]
+
+- fixed dependencies for libyui
+
+-------------------------------------------------------------------
+Mon Aug  6 12:52:30 UTC 2012 - [email protected]
+
+- fixed ISO image detection (space in file name or path), fixed
+  shell injection vulnerability (bnc#770157)
+
+-------------------------------------------------------------------

++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Other differences:
------------------
++++++ yast2-packager.spec ++++++
--- /var/tmp/diff_new_pack.noYEfg/_old  2012-09-14 12:43:30.000000000 +0200
+++ /var/tmp/diff_new_pack.noYEfg/_new  2012-09-14 12:43:30.000000000 +0200
@@ -1,7 +1,7 @@
 #
 # spec file for package yast2-packager
 #
-# Copyright (c) 2012 SUSE LINUX Products GmbH, Nuernberg, Germany.
+# Copyright (c) 2011 SUSE LINUX Products GmbH, Nuernberg, Germany.
 #
 # All modifications and additions to the file contributed by third parties
 # remain the property of their copyright owners, unless otherwise agreed
@@ -15,6 +15,9 @@
 # Please submit bugfixes or comments via http://bugs.opensuse.org/
 #
 
+# norootforbuild
+
+
 
 Name:           yast2-packager
 Version:        2.22.6
@@ -23,14 +26,10 @@
 BuildRoot:      %{_tmppath}/%{name}-%{version}-build
 Source0:        yast2-packager-%{version}.tar.bz2
 
-BuildRequires:  gcc-c++
-BuildRequires:  perl-XML-Writer
-BuildRequires:  update-desktop-files
-BuildRequires:  yast2-country-data
-BuildRequires:  yast2-devtools
-BuildRequires:  yast2-slp
-BuildRequires:  yast2-testsuite
-BuildRequires:  yast2-xml
+
+Group: System/YaST
+License: GPL-2.0+
+BuildRequires: gcc-c++ yast2-country-data yast2-xml perl-XML-Writer 
update-desktop-files yast2-devtools yast2-testsuite yast2-slp
 
 # HTTP.ycp
 BuildRequires:  yast2-transfer
@@ -72,35 +71,25 @@
 # NotEnoughMemory-related functions moved to misc.ycp import-file
 Conflicts:      yast2-add-on < 2.15.15
 
-# One of yast2-qt-pkg, yast2-ncurses-pkg, yast2-gtk (-pkg)
-Requires:       yast2_ui_pkg
+# One of libyui-qt-pkg, libyui-ncurses-pkg, libyui-gtk-pkg
+Requires:      libyui_pkg
 
 # ensure that 'checkmedia' is on the medium
 Recommends:     checkmedia
 
 Provides:       yast2-config-package-manager
 Obsoletes:      yast2-config-package-manager
-Provides:       y2c_spkg
-Provides:       y2pkginf
-Provides:       y2t_inst-packages
-Provides:       y2t_spkg
-Obsoletes:      y2c_spkg
-Obsoletes:      y2pkginf
-Obsoletes:      y2t_inst-packages
-Obsoletes:      y2t_spkg
-Provides:       yast2-trans-inst-packages
-Provides:       yast2-trans-package-manager
-Obsoletes:      yast2-trans-inst-packages
-Obsoletes:      yast2-trans-package-manager
+Provides:      y2t_spkg y2t_inst-packages y2pkginf y2c_spkg
+Obsoletes:     y2t_spkg y2t_inst-packages y2pkginf y2c_spkg
+Provides:      yast2-trans-package-manager yast2-trans-inst-packages
+Obsoletes:     yast2-trans-package-manager yast2-trans-inst-packages
 
 Summary:        YaST2 - Package Library
-License:        GPL-2.0+
-Group:          System/YaST
 
 %package webpin
 
-Summary:        YaST2 - Webpin package search client
 Group:          System/YaST
+Summary:       YaST2 - Webpin package search client
 
 %description
 This package contains the scanner/parser and dependency checker for all
@@ -135,6 +124,7 @@
     %suse_update_desktop_file -d ycc_${d%.desktop} ${d%.desktop}
 done
 
+
 %clean
 rm -rf "$RPM_BUILD_ROOT"
 
@@ -159,5 +149,3 @@
 /usr/share/YaST2/clients/webpin_package_search.ycp
 /usr/share/YaST2/modules/WebpinPackageSearch.ycp
 /usr/share/YaST2/modules/WebpinPackageSearch.ybc
-
-%changelog

++++++ yast2-packager-2.22.6.tar.bz2 ++++++
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/yast2-packager-2.22.6/configure.in 
new/yast2-packager-2.22.6/configure.in
--- old/yast2-packager-2.22.6/configure.in      2012-05-21 16:33:51.000000000 
+0200
+++ new/yast2-packager-2.22.6/configure.in      2012-09-11 09:24:43.000000000 
+0200
@@ -1,6 +1,6 @@
 dnl configure.in for yast2-packager
 dnl
-dnl -- This file is generated by y2autoconf 2.21.6 - DO NOT EDIT! --
+dnl -- This file is generated by y2autoconf 2.21.2 - DO NOT EDIT! --
 dnl    (edit configure.in.in instead)
 
 AC_INIT(yast2-packager, 2.22.6, http://bugs.opensuse.org/, yast2-packager)
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/yast2-packager-2.22.6/src/modules/SourceDialogs.ycp 
new/yast2-packager-2.22.6/src/modules/SourceDialogs.ycp
--- old/yast2-packager-2.22.6/src/modules/SourceDialogs.ycp     2012-05-21 
15:27:06.000000000 +0200
+++ new/yast2-packager-2.22.6/src/modules/SourceDialogs.ycp     2012-08-08 
11:44:02.000000000 +0200
@@ -822,7 +822,7 @@
     // try to detect ISO image by file if it's present
     if (SCR::Read(.target.size, file) > 0)
     {
-       string command = file + " -b " + s;
+       string command = sformat("%1 -b -- '%2'", file, String::Quote(s));
 
        map out = (map)SCR::Execute(.target.bash_output, command);
 

-- 
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to