OpenPKG CVS Repository http://cvs.openpkg.org/ ____________________________________________________________________________
Server: cvs.openpkg.org Name: Thomas Lotterer Root: /v/openpkg/cvs Email: [EMAIL PROTECTED] Module: openpkg-src Date: 12-Aug-2005 14:53:50 Branch: HEAD Handle: 2005081213534800 Modified files: openpkg-src/awstats awstats.patch awstats.spec Log: update awstats to resolve security issue CAN-2005-1527; fix tracking Summary: Revision Changes Path 1.3 +4 -8 openpkg-src/awstats/awstats.patch 1.7 +5 -5 openpkg-src/awstats/awstats.spec ____________________________________________________________________________ patch -p0 <<'@@ .' Index: openpkg-src/awstats/awstats.patch ============================================================================ $ cvs diff -u -r1.2 -r1.3 awstats.patch --- openpkg-src/awstats/awstats.patch 8 Nov 2004 16:03:35 -0000 1.2 +++ openpkg-src/awstats/awstats.patch 12 Aug 2005 12:53:48 -0000 1.3 @@ -27,18 +27,14 @@ $mailid=($id eq 'reject'?'999':$id); # id not provided in log, we take '999' if ($mailid) { $mail{$mailid}{'code'}=999; # Unkown error (bounced) -@@ -325,11 +325,11 @@ - # sendmail: Sep 30 04:21:32 halley sendmail[3161]: g8U2LVi03161: ruleset=check_rcpt, arg1=<[EMAIL PROTECTED]>, relay=moon.partenor.fr [10.0.0.254], reject=550 5.7.1 <[EMAIL PROTECTED]>... Relaying denied - +@@ -327,9 +327,9 @@ # sendmail: Jan 10 07:37:48 smtp sendmail[32440]: ruleset=check_relay, arg1=[211.228.26.114], arg2=211.228.26.114, relay=[211.228.26.114], reject=554 5.7.1 Rejected 211.228.26.114 found in dnsbl.sorbs.net -- # sendmail: Jan 10 07:37:08 smtp sendmail[32439]: ruleset=check_relay, arg1=235.Red-213-97-175.pooles.rima-tde.net, arg2=213.97.175.235, relay=235.Red-213-97-175.pooles.rima-tde.net [213.97.175.235], reject=550 5.7.1 Mail from 213.97.175.235 refused. Rejected for bad WHOIS info on IP of your SMTP server - see http://www.rfc-ignorant.org/ -+ # sendmail: Jan 10 07:37:08 smtp sendmail[32439]: ruleset=check_relay, arg1=235.Red-213-97-175.pooles.rima-tde.net, arg2=213.97.175.235, relay=235.Red-213-97-175.pooles.rima-tde.net [213.97.175.235], reject=550 5.7.1 Mail from 213.97.175.235 refused. Rejected for bad WHOIS info on IP of your SMTP server - see http://www.rfc-ignorant.org/ + # sendmail: Jan 10 07:37:08 smtp sendmail[32439]: ruleset=check_relay, arg1=235.Red-213-97-175.pooles.rima-tde.net, arg2=213.97.175.235, relay=235.Red-213-97-175.pooles.rima-tde.net [213.97.175.235], reject=550 5.7.1 Mail from 213.97.175.235 refused. Rejected for bad WHOIS info on IP of your SMTP server - see http://www.rfc-ignorant.org/ # sendmail: Jan 10 17:15:42 smtp sendmail[12770]: ruleset=check_relay, arg1=[63.218.84.21], arg2=63.218.84.21, relay=[63.218.84.21], reject=553 5.3.0 Rejected - see http://spamhaus.org/ - my ($mon,$day,$time,$id,$ruleset,$arg,$relay_s,$code)=m/(\w+)\s+(\d+)\s+(\d+:\d+:\d+)[EMAIL PROTECTED](?:sendmail|sm-mta)\[\d+\][:\s]*(.*?):\sruleset=(\w+),\s+arg1=(.*),\s+relay=(.*),\s+(reject=.*)/; -- # sendmail: Jan 10 18:00:34 smtp sendmail[5759]: i04Axx2c005759: Milter: data, reject=511 Virus found in email! -- if (! $mon) { ($mon,$day,$time,$id,$ruleset,$code)=m/(\w+)\s+(\d+)\s+(\d+:\d+:\d+)[EMAIL PROTECTED](?:sendmail|sm-mta)\[\d+\]:\s+(.*?):\s\w+:\s(\w+),\s+(reject=.*)/; } + my ($mon,$day,$time,$id,$ruleset,$arg,$relay_s,$code)=m/(\w+)\s+(\d+)\s+(\d+:\d+:\d+)\s+[\w\-]+\s+\<\w+\>+\s+(?:sendmail|sm-mta)\[\d+\][:\s]*(.*?):\sruleset=(\w+),\s+arg1=(.*),\s+relay=(.*),\s+(reject=.*)/; -+ # sendmail: Jan 10 18:00:34 smtp sendmail[5759]: i04Axx2c005759: Milter: data, reject=511 Virus found in email! + # sendmail: Jan 10 18:00:34 smtp sendmail[5759]: i04Axx2c005759: Milter: data, reject=511 Virus found in email! +- if (! $mon) { ($mon,$day,$time,$id,$ruleset,$code)=m/(\w+)\s+(\d+)\s+(\d+:\d+:\d+)[EMAIL PROTECTED](?:sendmail|sm-mta)\[\d+\]:\s+(.*?):\s\w+:\s(\w+),\s+(reject=.*)/; } + if (! $mon) { ($mon,$day,$time,$id,$ruleset,$code)=m/(\w+)\s+(\d+)\s+(\d+:\d+:\d+)\s+[\w\-]+\s+\<\w+\>+\s+(?:sendmail|sm-mta)\[\d+\]:\s+(.*?):\s\w+:\s(\w+),\s+(reject=.*)/; } $mailid=(! $id && $mon?'999':$id); # id not provided in log, we take '999' if ($mailid) { @@ . patch -p0 <<'@@ .' Index: openpkg-src/awstats/awstats.spec ============================================================================ $ cvs diff -u -r1.6 -r1.7 awstats.spec --- openpkg-src/awstats/awstats.spec 24 Mar 2005 11:18:27 -0000 1.6 +++ openpkg-src/awstats/awstats.spec 12 Aug 2005 12:53:48 -0000 1.7 @@ -34,11 +34,11 @@ Class: JUNK Group: Mail License: GPL -Version: 6.4 -Release: 20050226 +Version: 6.5 +Release: 20050812 # list of sources -Source0: http://osdn.dl.sourceforge.net/awstats/awstats-%{version}.tgz +Source0: http://awstats.sourceforge.net/files/awstats-%{version}.tar.gz Source1: awstats.postfix.conf Source2: awstats.apache.conf Source3: rc.awstats @@ -67,8 +67,8 @@ %track prog awstats = { version = %{version} - url = http://prdownloads.sourceforge.net/awstats/ - regex = awstats-(__VER__)\.tgz + url = http://awstats.sourceforge.net/files/ + regex = awstats-(__VER__)\.tar.gz } %prep @@ . ______________________________________________________________________ The OpenPKG Project www.openpkg.org CVS Repository Commit List openpkg-cvs@openpkg.org