Script 'mail_helper' called by obssrc Hello community, here is the log from the commit of package squid for openSUSE:Factory checked in at 2023-11-02 20:22:22 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Comparing /work/SRC/openSUSE:Factory/squid (Old) and /work/SRC/openSUSE:Factory/.squid.new.17445 (New) ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "squid" Thu Nov 2 20:22:22 2023 rev:116 rq:1122203 version:6.4 Changes: -------- --- /work/SRC/openSUSE:Factory/squid/squid.changes 2023-09-20 13:34:19.369679452 +0200 +++ /work/SRC/openSUSE:Factory/.squid.new.17445/squid.changes 2023-11-02 20:22:34.634280387 +0100 @@ -1,0 +2,17 @@ +Wed Oct 25 14:32:33 UTC 2023 - Adam Majer <adam.ma...@suse.de> + +- update to 6.4: + * security fixes: + + Request/Response smuggling in HTTP/1.1 and ICAP (bsc#1216500, CVE-2023-46846) + + Multiple issues in HTTP response caching (bsc#1216496, CVE-2023-5824) + + Denial of Service in HTTP Digest Authentication (bsc#1216495, CVE-2023-46847) + + Denial of Service in FTP (bsc#1216498, CVE-2023-46848) + + Fix validation of certificates (bsc#1216803, CVE-2023-46724) + * Bug 5294: ERR_CANNOT_FORWARD returned instead of ERR_DNS_FAIL + * Bug 4981: Work around in-call job invalidation bugs + * basic_smb_lm_auth: fix 'no previous declaration' warnings + * CacheManager: require /squid-internal-mgr/ URL path prefix + * ESI: Fix build [-Wsingle-bit-bitfield-constant-conversion] + * documentation changes + +------------------------------------------------------------------- Old: ---- squid-6.3.tar.xz squid-6.3.tar.xz.asc New: ---- squid-6.4.tar.xz squid-6.4.tar.xz.asc ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Other differences: ------------------ ++++++ squid.spec ++++++ --- /var/tmp/diff_new_pack.0NDjXm/_old 2023-11-02 20:22:35.330305998 +0100 +++ /var/tmp/diff_new_pack.0NDjXm/_new 2023-11-02 20:22:35.330305998 +0100 @@ -24,14 +24,17 @@ %define squidhelperdir %{_sbindir} %endif Name: squid -Version: 6.3 +Version: 6.4 Release: 0 Summary: Caching and forwarding HTTP web proxy License: GPL-2.0-or-later Group: Productivity/Networking/Web/Proxy URL: http://www.squid-cache.org -Source0: http://www.squid-cache.org/Versions/v6/squid-%{version}.tar.xz -Source1: http://www.squid-cache.org/Versions/v6/squid-%{version}.tar.xz.asc +### commented because of mirror issues... +#Source0: http://www.squid-cache.org/Versions/v6/squid-%{version}.tar.xz +#Source1: http://www.squid-cache.org/Versions/v6/squid-%{version}.tar.xz.asc +Source0: squid-%{version}.tar.xz +Source1: squid-%{version}.tar.xz.asc Source5: pam.squid Source6: unsquid.pl Source7: %{name}.logrotate @@ -40,7 +43,8 @@ Source11: %{name}.service Source12: %{name}-user.conf # http://lists.squid-cache.org/pipermail/squid-announce/2016-October/000064.html -Source13: http://www.squid-cache.org/pgp.asc#/squid.keyring +#Source13: http://www.squid-cache.org/pgp.asc#/squid.keyring +Source13: squid.keyring Source15: cache_dir.sed Source16: initialize_cache_if_needed.sh Source17: tmpfilesdir.squid.conf ++++++ squid-6.3.tar.xz -> squid-6.4.tar.xz ++++++ ++++ 4454 lines of diff (skipped) ++++++ squid-6.3.tar.xz.asc -> squid-6.4.tar.xz.asc ++++++ --- /work/SRC/openSUSE:Factory/squid/squid-6.3.tar.xz.asc 2023-09-20 13:34:19.361679165 +0200 +++ /work/SRC/openSUSE:Factory/.squid.new.17445/squid-6.4.tar.xz.asc 2023-11-02 20:22:34.478274646 +0100 @@ -1,25 +1,25 @@ -File: squid-6.3.tar.xz -Date: Sun 03 Sep 2023 15:42:32 UTC -Size: 2547264 -MD5 : 2512b5d27856e6f91a97719784506893 -SHA1: 7bd74034015c6a4d345a4d277a431908bed2ec4a +File: squid-6.4.tar.xz +Date: Sat 21 Oct 2023 12:51:05 UTC +Size: 2553476 +MD5 : 8031857fd54fad4a7b4f4db4d44aa761 +SHA1: 23733fc08ed7a76d7e19877a4e04c105222b6cec Key : CD6DBF8EF3B17D3E <squ...@treenet.co.nz> B068 84ED B779 C89B 044E 64E3 CD6D BF8E F3B1 7D3E keyring = http://www.squid-cache.org/pgp.asc keyserver = pool.sks-keyservers.net -----BEGIN PGP SIGNATURE----- -iQIzBAABCgAdFiEEsGiE7bd5yJsETmTjzW2/jvOxfT4FAmT0qW8ACgkQzW2/jvOx -fT56xRAAjfNBcwBJzAMjXoGBPypHb6NmNDamFblgS11EBXrUFqTK/GyYCxYbXwxJ -MEt4xnxJKehEelInd03gw7o9z+402gdlGFzCwtuNb5BmYTvIGgudNIC/LzpTiuaG -mPgIsSaRSsIrzVpgrz5MzWGj2lwUi+wg+x1hwB0GYVzxHDXTikNrvBgSbK47Z4cR -Fc/4iGhNJ3iGnML0LSStbXAsHuXx8LmI0tD9koy688eVSL9AUymoJVrkU3iBFIGY -MKVr9icrtwvqhT7doFdiKw4AfGL5ex/RxjY/sbu4OtDlsx6oQPKNNSjZt+vG92lT -yZGKQGBtdQV8O0J7REeaHIt8TiKlNvmw1J+65pMpx7DYo7Dd0YZh9DHSJrG/zDWE -CT7WxKNV0Mt8k3bnhHpMqeV2t/AHdUzRULymUI46JrtBaNzb+mduwagCV6/EGENU -kwJ+bvVg3H+30HmUIfNCuvlfFrLaCROKkmA5VQ5fNBQPLibJEZMi32haIn7Mftue -gw9MkxmX6kUi/1FhS9Kbe3qEOVrJnoaFDmfXn+iIeMpNTBNKGQOWUGPBZdsfRKLr -ISKMfxOjCHn072X2Abtbod1DSKgTc/XK4Wvc6LQfp8fDy4Kzzu4BZJmM4N6xgj2F -GO31kwuQhQFEFGUh6CXOiFeivlAaWBu3/rjh/SMREuir6IJ/K6o= -=/lJx +iQIzBAABCgAdFiEEsGiE7bd5yJsETmTjzW2/jvOxfT4FAmUzyUEACgkQzW2/jvOx +fT4IBw/9GrNFjQTgyNSlcDGhRwI1DQzANOId9Aj51TNbwBTs/CPnfISwOBq2Y6IH +wOfQaRxl0T4f5Mkj4xAimPKYz4qDe+JjQNN/IzX0O9ngMX4f4gHpuWqelHKU+732 +QZjqMunf2nLnWtpENsEPL0REYISy/nu0w8cZm3vUfiqwvc32/cDdPIYFCWbIdg/H +7dpOhNgvgNYGrUSfBBkUeH1B2XCf8hkBhidMRAh/vyg4RQSKAs5F0Mx8gW6lLS06 +3dfHXuTP4AsF4MZh1YFe385oFl0uO1liaaXB41+TT8k0s0CrEnJKNabT9FQ/EUhG +K2cV/9oEBU2Z72RujwVapwdbDPbAwlhbnM/34sYAAVo1/Zil1Ucu1irb9WMuaffB +H2GZiu0naiAbILJkAjz5/n2jXxvgiOM3So3vQQm8BaH13KLlPiVkonoICxBZD2rN +Z134qMo/VHT05GOFZR/eZ8UBAVkdRWx16kGe/BaflDwQdGToYNnJSisc2rKH+jxY +KMNpe7vtE8VkyBqh/qmZA0XLH4uY1ve/tduDdwRRZeYRfrd+wi7ejwzUhDvjQSie +3W6rBsW1gfVXYOKvz+lss3AvHjlyTQ1TW3dkm4VHnIRWfNi55vCmQaJ8ye4UUpcg +G0JS4nepLyyH/4rXBbxylFMPMSa1XhMOtPmpnvL4XDp3wXxSYbE= +=aGhF -----END PGP SIGNATURE-----