Script 'mail_helper' called by obssrc Hello community, here is the log from the commit of package xmlrpc-c for openSUSE:Factory checked in at 2026-09-28 10:47:30 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Comparing /work/SRC/openSUSE:Factory/xmlrpc-c (Old) and /work/SRC/openSUSE:Factory/.xmlrpc-c.new.383539 (New) ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "xmlrpc-c" Mon Sep 28 10:47:30 2026 rev:17 rq:1380968 version:1.64.04 Changes: -------- --- /work/SRC/openSUSE:Factory/xmlrpc-c/xmlrpc-c.changes 2026-07-29 19:02:59.449385523 +0200 +++ /work/SRC/openSUSE:Factory/.xmlrpc-c.new.383539/xmlrpc-c.changes 2026-09-28 10:48:13.553410134 +0200 @@ -1,0 +2,11 @@ +Sun Sep 27 15:00:23 UTC 2026 - Martin Pluskal <[email protected]> + +- Update to 1.64.04: + * Abyss: escape user-generated characters in server-generated + HTML error responses and directory listings + (CVE-2026-15928, bsc#1272769). + * Drop 0002-CVE-2026-15928-HTML-injection.patch (fixed upstream). +- Upstream renamed the tarball back to xmlrpc-c-1.64.04.tgz; adjust + Source and %autosetup accordingly. + +------------------------------------------------------------------- Old: ---- 0002-CVE-2026-15928-HTML-injection.patch xmlrpc-1.64.03.tgz New: ---- xmlrpc-c-1.64.04.tgz ----------(Old B)---------- Old: (CVE-2026-15928, bsc#1272769). * Drop 0002-CVE-2026-15928-HTML-injection.patch (fixed upstream). - Upstream renamed the tarball back to xmlrpc-c-1.64.04.tgz; adjust ----------(Old E)---------- ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Other differences: ------------------ ++++++ xmlrpc-c.spec ++++++ --- /var/tmp/diff_new_pack.Yakceb/_old 2026-09-28 10:48:14.289440972 +0200 +++ /var/tmp/diff_new_pack.Yakceb/_new 2026-09-28 10:48:14.290441014 +0200 @@ -20,16 +20,15 @@ %define soname 3 %define soname_cpp 9 Name: xmlrpc-c -Version: 1.64.03 +Version: 1.64.04 Release: 0 Summary: Library implementing XML-based Remote Procedure Calls License: BSD-3-Clause AND MIT URL: https://xmlrpc-c.sourceforge.net/ -# NB: upstream dropped the "-c" from the 1.64.x tarball/dir name (xmlrpc-X.Y.Z) -Source: https://downloads.sourceforge.net/xmlrpc-c/xmlrpc-%{version}.tgz +# NB: 1.64.x renamed the tarball/dir back to xmlrpc-c-X.Y.Z (was xmlrpc-X.Y.Z) +Source: https://downloads.sourceforge.net/xmlrpc-c/xmlrpc-c-%{version}.tgz Source9: %{name}-rpmlintrc Patch1: skip-expat.patch -Patch2: 0002-CVE-2026-15928-HTML-injection.patch BuildRequires: autoconf BuildRequires: automake BuildRequires: gcc-c++ @@ -209,7 +208,7 @@ package is used by XML-RPC clients and servers written in C and C++. %prep -%autosetup -p1 -n xmlrpc-%{version} +%autosetup -p1 echo "Not using the embedded libexpat copy" rm -rvf lib/expat
