diff options
author | Johannes Huber <johu@gentoo.org> | 2012-02-21 14:13:18 +0000 |
---|---|---|
committer | Johannes Huber <johu@gentoo.org> | 2012-02-21 14:13:18 +0000 |
commit | c9fe8cf8f93dac8ed47667e727e3ce071fb4f277 (patch) | |
tree | d80aba5665553c838ab380f5386305dc9555890a /kde-base | |
parent | Remove old. (diff) | |
download | historical-c9fe8cf8f93dac8ed47667e727e3ce071fb4f277.tar.gz historical-c9fe8cf8f93dac8ed47667e727e3ce071fb4f277.tar.bz2 historical-c9fe8cf8f93dac8ed47667e727e3ce071fb4f277.zip |
Remove old.
Package-Manager: portage-2.2.0_alpha86/cvs/Linux x86_64
Diffstat (limited to 'kde-base')
-rw-r--r-- | kde-base/ark/ChangeLog | 7 | ||||
-rw-r--r-- | kde-base/ark/Manifest | 18 | ||||
-rw-r--r-- | kde-base/ark/files/ark-4.6.5-CVE-2011-2725.patch | 36 | ||||
-rw-r--r-- | kde-base/ark/files/ark-detect-libarchive-in-proper-place.patch | 32 |
4 files changed, 14 insertions, 79 deletions
diff --git a/kde-base/ark/ChangeLog b/kde-base/ark/ChangeLog index f14a66e7c6d8..5f526e9ef807 100644 --- a/kde-base/ark/ChangeLog +++ b/kde-base/ark/ChangeLog @@ -1,6 +1,11 @@ # ChangeLog for kde-base/ark # Copyright 1999-2012 Gentoo Foundation; Distributed under the GPL v2 -# $Header: /var/cvsroot/gentoo-x86/kde-base/ark/ChangeLog,v 1.217 2012/02/21 12:52:46 johu Exp $ +# $Header: /var/cvsroot/gentoo-x86/kde-base/ark/ChangeLog,v 1.218 2012/02/21 14:13:18 johu Exp $ + + 21 Feb 2012; Johannes Huber <johu@gentoo.org> + -files/ark-4.6.5-CVE-2011-2725.patch, + -files/ark-detect-libarchive-in-proper-place.patch: + Remove old. 20 Feb 2012; Johannes Huber <johu@gentoo.org> -ark-4.6.3-r1.ebuild: Remove KDE SC 4.6.3 diff --git a/kde-base/ark/Manifest b/kde-base/ark/Manifest index b50c8b1bc45b..9dbf270b2495 100644 --- a/kde-base/ark/Manifest +++ b/kde-base/ark/Manifest @@ -1,22 +1,20 @@ -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 -AUX ark-4.6.5-CVE-2011-2725.patch 1483 RMD160 5be56edabdb92821c80be42ea39c51dff670398f SHA1 2cd15ea4ef3cc60a2b0321c1872787ae2ef782d2 SHA256 50653ad3d75e4473078fa32108f01f321503f10edb62d25c95f5d064a3e79991 -AUX ark-detect-libarchive-in-proper-place.patch 1350 RMD160 920181d3fbe98cc6435cb421e7e73cd1551be4ca SHA1 967e407f27f264e2ecf4e34498f68fd92dc83dbc SHA256 0680251d0b32ecb24ce5ad8dae0c27473d58edf48aee9096f90b2446fc20c104 DIST ark-4.8.0.tar.bz2 157700 RMD160 42e8e43d527bea4efa94618689eb810d52ffcb0c SHA1 99756e0896938371d6d7036fb3d5d0d152de29c3 SHA256 27b3ef0fef32ccda1cdb5b280b942c829a65c0ae11b7e6de1ac3da421e556dd7 DIST kdeutils-4.7.4.tar.bz2 3802873 RMD160 24c3af30a407523bdf853059fc38bfbf6e6d4604 SHA1 4630f01f36558eb5494fc562086fbd4e488e411e SHA256 bb50a5069808a0280eff671b2f9c0053f5bbbfdc432760bc35ccf654de833c68 EBUILD ark-4.7.4.ebuild 1008 RMD160 26d55619ef83bee9205e8bb7ad0e94dca7454216 SHA1 06a8e888fc97bf4889737b65664a603b6e83dd14 SHA256 24acca6612bab2a9911a853fc4ce544c95ce2a3e022365a1b34c2a25612e5a90 EBUILD ark-4.8.0.ebuild 851 RMD160 69c9b3831cbf49ee34510de2548dd3c7f6213f9e SHA1 da62f2f739bee5108760b855bfe5dcd4a610b01a SHA256 c34469ff0eb8504c44ae65f1ea8bbda5ba215207746ea77016eef59d12f7e975 -MISC ChangeLog 25350 RMD160 102c0ebc5fc25bbc69b46d75339ecab9742eca5c SHA1 1c36a9b9b3d41c87025a03273ca8a2097cde8239 SHA256 0ef51c599575706810006d4ec6f2cef6d54c07678ca5f5422d0a808b7890ccc6 +MISC ChangeLog 25507 RMD160 4deb35e1c369514fde5a0d581b5932226770bb92 SHA1 51b8a53b73eb18d8f86542e1d36313a2293c4f0a SHA256 df2f43deea5076e02c4a6b51d5cce1cc922504d6c1c8b0ac374701fd090b8513 MISC metadata.xml 265 RMD160 6d5c00bd8e060f14a16549ff10280fab7f6f5dfa SHA1 34b7bb42c33bec69214da2e8c19efc1b1e89d02a SHA256 3a6bd8f72e476b5ceea3aa7d397b9f72307a5fea2a381dc1816c21889fd8248f -----BEGIN PGP SIGNATURE----- Version: GnuPG v2.0.18 (GNU/Linux) -iQEcBAEBCgAGBQJPQ5OmAAoJEO+t9ga+3I3aToQIAJY1ugQJBeJ4Jkc7sYXvlzUT -V8sFAsHOr5ZMz7ccCpuJ7uab+2my7K9/vUaPGoGU1kBAVZndhU9+L3QVwnrmZpBF -lB4u9u1pBFB7gYjm/uUm60dwbt5UnmPq9WWcz8t1dAIjNfPBsGDGAIQE6+Z8u43V -HYselxGrrHbTnKrWuRkHBpCEEl+5XIJAj/tAJ3FC8No8aZhJgV4+7xFbdKzsERkd -DpUiFLitgZigVIKT/ZIWttFK7zxuCKcrfgeE+zgqLdaSOj0y16UsRvQzNpWnNuRc -DDziY025ME7xymHPkdFiIsfjFPWqIZQEYJmFQ/C2rJG8Uu3ytaFW0CHX99wXBlw= -=Iyft +iQEcBAEBCgAGBQJPQ6aAAAoJEO+t9ga+3I3aFQIH/0Rs14yQ2jf7kQV7RPDlPX6I +XOxwydv+h6QNrw+YXNMlQJb6WE1CqmnPBg1dRP8edEYRYTuhAZoMVY4BFyJ6nv+/ +IAuAF0vkeQ6/QWuo5Zt64m4lIt+v9GUXO8lonwIjeljiZ1hJuib2jRCjwhzS4BnN +P1BDER79tNjRer4IOjKCuMrGSQPh5Kb3zgNsYU05aIDvQXSc3b39RUOUBh2EYT0i ++1y+hV6tWI+z4u2SfKmUa9iQN4axvK7hm+haK8sbOUkypK7jVT3dEa8LH/p7mopA +Rj64dSfGZSS1pLOrhUXU9dGoXYzBPABFsTMwiZ9ZXf54K6XdR8QLkugsSASu6Eo= +=ummH -----END PGP SIGNATURE----- diff --git a/kde-base/ark/files/ark-4.6.5-CVE-2011-2725.patch b/kde-base/ark/files/ark-4.6.5-CVE-2011-2725.patch deleted file mode 100644 index 39cc52a0396a..000000000000 --- a/kde-base/ark/files/ark-4.6.5-CVE-2011-2725.patch +++ /dev/null @@ -1,36 +0,0 @@ -From: Raphael Kubo da Costa <rakuco@FreeBSD.org> -Date: Mon, 17 Oct 2011 22:28:27 +0000 -Subject: Fix directory traversal issue (CVE-2011-2725). -X-Git-Url: http://quickgit.kde.org/?p=ark.git&a=commitdiff&h=ccb5448eb2aedd150313ea0af431a9b754176975 ---- -Fix directory traversal issue (CVE-2011-2725). - -Tim Brown from Nth Dimension noticed a possible traversal issue where -the previewer dialog would show (and then remove) the wrong file when -a maliciously crafted archive had a file previewed. - -We now do the same thing as infozip and filter out "../" from the -paths being previewed. ---- - - ---- a/ark/part/part.cpp -+++ b/ark/part/part.cpp -@@ -558,8 +558,15 @@ void Part::slotPreviewExtracted(KJob *jo - if (!job->error()) { - const ArchiveEntry& entry = - m_model->entryForIndex(m_view->selectionModel()->currentIndex()); -- const QString fullName = -- m_previewDir->name() + QLatin1Char( '/' ) + entry[ FileName ].toString(); -+ -+ QString fullName = -+ m_previewDir->name() + QLatin1Char('/') + entry[FileName].toString(); -+ -+ // Make sure a maliciously crafted archive with parent folders named ".." do -+ // not cause the previewed file path to be located outside the temporary -+ // directory, resulting in a directory traversal issue. -+ fullName.remove(QLatin1String("../")); -+ - ArkViewer::view(fullName, widget()); - } else { - KMessageBox::error(widget(), job->errorString()); diff --git a/kde-base/ark/files/ark-detect-libarchive-in-proper-place.patch b/kde-base/ark/files/ark-detect-libarchive-in-proper-place.patch deleted file mode 100644 index 0a7bd5085820..000000000000 --- a/kde-base/ark/files/ark-detect-libarchive-in-proper-place.patch +++ /dev/null @@ -1,32 +0,0 @@ -diff --git a/ark/CMakeLists.txt b/ark/CMakeLists.txt -index 6ea72bb..85c5ce0 100644 ---- a/ark/CMakeLists.txt -+++ b/ark/CMakeLists.txt -@@ -1,5 +1,8 @@ - project(ark) - -+macro_optional_find_package(LibArchive) -+macro_log_feature(LIBARCHIVE_FOUND "LibArchive" "A library for dealing with a wide variety of archive file formats" "http://code.google.com/p/libarchive/" FALSE "" "Required for among others tar, tar.gz, tar.bz2 formats in Ark.") -+ - configure_file(config.h.cmake ${CMAKE_CURRENT_BINARY_DIR}/config.h) - - add_subdirectory(part) -diff --git a/ark/plugins/CMakeLists.txt b/ark/plugins/CMakeLists.txt -index a8c4e44..e3cb9ec 100644 ---- a/ark/plugins/CMakeLists.txt -+++ b/ark/plugins/CMakeLists.txt -@@ -1,5 +1,3 @@ --macro_optional_find_package(LibArchive) -- - if (LIBARCHIVE_FOUND) - if( HAVE_LIBARCHIVE_READ_DISK_API ) - if( NOT HAVE_LIBARCHIVE_LZMA_SUPPORT OR NOT HAVE_LIBARCHIVE_XZ_SUPPORT ) -@@ -15,8 +13,6 @@ if (LIBARCHIVE_FOUND) - endif( HAVE_LIBARCHIVE_READ_DISK_API ) - endif (LIBARCHIVE_FOUND) - --macro_log_feature(LIBARCHIVE_FOUND "LibArchive" "A library for dealing with a wide variety of archive file formats" "http://code.google.com/p/libarchive/" FALSE "" "Required for among others tar, tar.gz, tar.bz2 formats in Ark.") -- - add_subdirectory( clirarplugin ) - add_subdirectory( cli7zplugin ) - add_subdirectory( clizipplugin ) |