Browse Source

fix security issue

git-svn-id: http://trac.vinelinux.org/repos/projects/specs@3712 ec354946-7b23-47d6-9f5a-488ba84defc7
Takemikaduchi 14 years ago
parent
commit
d8e42481b0
1 changed files with 15 additions and 1 deletions
  1. 15 1
      g/gimp/gimp-vl.spec

+ 15 - 1
g/gimp/gimp-vl.spec

@@ -6,12 +6,18 @@ Summary: 	The GNU Image Manipulation Program
 Summary(ja):    GNU 画像加工プログラム
 Name: 		gimp
 Version: 	2.6.11
-Release:        3%{?_dist_release}
+Release:        4%{?_dist_release}
 License: 	GPL, LGPL
 Group: 		Applications/Graphics
 URL: 		http://www.gimp.org/
 Source: 	ftp://ftp.gimp.org/pub/gimp/%{verdir}/%{name}-%{version}.tar.bz2
+
 Patch10:	gimp-2.0-desktopfile-no-gimp-remote.patch
+
+# patch21,22 from debian
+Patch21:	05_CVE-2010-454x.patch
+Patch22:	06_CVE-2010-4543.patch
+
 Patch100:       gimp-2.6.11-gimprc-vine.patch
 BuildRoot: 	%{_tmppath}/%{name}-%{version}-root
 Obsoletes: 	gimp-data-min
@@ -115,6 +121,8 @@ and gimp, and you may want to install gimp-data-extras.
 
 %prep
 %setup -q -n %{name}-%{version}
+%patch21 -p1 -b .454x
+%patch22 -p1 -b .4543
 %patch100 -p1 -b .gimprc
 
 
@@ -226,6 +234,12 @@ rm -rf %{buildroot}
 
 
 %changelog
+* Wed Apr 27 2011 Yoji TOYODA <bsyamato@sea.plala.or.jp> 2.6.11-4
+- add Patch21 (05_CVE-2010-454x.patch) from debian
+  (including security fix for CVE-2010-4540,4541,4542)
+- add Patch22 (06_CVE-2010-4543.patch) from debian
+  (including security fix for CVE-2010-4543)
+
 * Fri Apr 22 2011 Daisuke SUZUKI <daisuke@linux.or.jp> 2.6.11-3
 - update Patch100 to use xdg-open instead of htmlview
 - add R: xdg-utils, remove R: htmlview