Subject: CVS commit: [pkgsrc-2008Q1] pkgsrc/security/mit-krb5
From: Matthias Scheler
Date: 2008-06-08 13:47:13
Message id: 20080608114713.D39DD175D0@cvs.netbsd.org

Log Message:
Pullup ticket #2417 - requested by tonnerre
Security patches for mit-krb5

Revisions pulled up:
- security/mit-krb5/Makefile		1.42
- security/mit-krb5/distinfo		1.17-1.19
- security/mit-krb5/patches/patch-ai	1.3-1.4
- security/mit-krb5/patches/patch-au	1.1-1.2
- security/mit-krb5/patches/patch-av	1.1-1.2
- security/mit-krb5/patches/patch-aw	1.1-1.2
- security/mit-krb5/patches/patch-ax	1.1-1.2
- security/mit-krb5/patches/patch-ay	1.1-1.2
- security/mit-krb5/patches/patch-az	1.1-1.2
- security/mit-krb5/patches/patch-ba	1.1-1.3
- security/mit-krb5/patches/patch-bb	1.1-1.2
- security/mit-krb5/patches/patch-bc	1.1-1.2
- security/mit-krb5/patches/patch-bd	1.1-1.2
- security/mit-krb5/patches/patch-be	1.1-1.2
- security/mit-krb5/patches/patch-bf	1.1
- security/mit-krb5/patches/patch-bg	1.1
---
    Module Name:	pkgsrc
    Committed By:	tonnerre
    Date:		Sat Jun  7 18:36:07 UTC 2008

    Modified Files:
    	pkgsrc/security/mit-krb5: Makefile distinfo
    Added Files:
    	pkgsrc/security/mit-krb5/patches: patch-ai patch-au patch-av
    patch-aw patch-ax patch-ay patch-az patch-ba patch-bb patch-bc patch-bd
    	    patch-be

    Log Message:
    Add security patches for 3 Kerberos vulnerabilities:
     - telnetd username and environment sanitizing vulnerabilities ("-f
    root") as described in MIT Kerberos advisory 2007-001.
     - krb5_klog_syslog() problems with overly long log strings as described
       in MIT Kerberos advisory 2007-002.
     - GSS API kg_unseal_v1() double free vulnerability as described in the
       MIT Kerberos advisory 2007-003.
---
    Module Name:	pkgsrc
    Committed By:	tonnerre
    Date:		Sat Jun  7 20:22:18 UTC 2008

    Modified Files:
    	pkgsrc/security/mit-krb5: distinfo
    	pkgsrc/security/mit-krb5/patches: patch-ai patch-au patch-av
    patch-aw patch-ax patch-ay patch-az patch-ba patch-bb patch-bc patch-bd
    	    patch-be

    Log Message:
    Remove parts of a different security patch which slipped in but are not
    supported yet. Don't bump revision as the package didn't build before.
---
    Module Name:	pkgsrc
    Committed By:	tonnerre
    Date:		Sat Jun  7 22:26:10 UTC 2008

    Modified Files:
    	pkgsrc/security/mit-krb5: distinfo
    	pkgsrc/security/mit-krb5/patches: patch-ba
    Added Files:
    	pkgsrc/security/mit-krb5/patches: patch-bf patch-bg

    Log Message:
    Add patches for MITKRB5-SA-2007-004 and MITKRB5-SA-2007-005. PKGREVISION
    will be bumped again once some other patches are in.

Files:
RevisionActionfile
1.41.8.1modifypkgsrc/security/mit-krb5/Makefile
1.16.10.1modifypkgsrc/security/mit-krb5/distinfo
1.2.24.1addpkgsrc/security/mit-krb5/patches/patch-ai
1.2.2.2addpkgsrc/security/mit-krb5/patches/patch-au
1.2.2.2addpkgsrc/security/mit-krb5/patches/patch-av
1.2.2.2addpkgsrc/security/mit-krb5/patches/patch-aw
1.2.2.2addpkgsrc/security/mit-krb5/patches/patch-ax
1.2.2.2addpkgsrc/security/mit-krb5/patches/patch-ay
1.2.2.2addpkgsrc/security/mit-krb5/patches/patch-az
1.3.2.2addpkgsrc/security/mit-krb5/patches/patch-ba
1.2.2.2addpkgsrc/security/mit-krb5/patches/patch-bb
1.2.2.2addpkgsrc/security/mit-krb5/patches/patch-bc
1.2.2.2addpkgsrc/security/mit-krb5/patches/patch-bd
1.2.2.2addpkgsrc/security/mit-krb5/patches/patch-be
1.1.2.2addpkgsrc/security/mit-krb5/patches/patch-bf
1.1.2.2addpkgsrc/security/mit-krb5/patches/patch-bg