Subject: PR/26174 CVS commit: [pkgsrc-2005Q2] pkgsrc/databases/gnats
To: None <recht@netbsd.org, gnats-admin@netbsd.org, pkgsrc-bugs@netbsd.org>
From: Lubomir Sedlacik <salo@netbsd.org>
List: pkgsrc-bugs
Date: 08/29/2005 13:42:01
The following reply was made to PR pkg/26174; it has been noted by GNATS.

From: Lubomir Sedlacik <salo@netbsd.org>
To: gnats-bugs@netbsd.org
Cc: 
Subject: PR/26174 CVS commit: [pkgsrc-2005Q2] pkgsrc/databases/gnats
Date: Mon, 29 Aug 2005 13:41:42 +0000 (UTC)

 Module Name:	pkgsrc
 Committed By:	salo
 Date:		Mon Aug 29 13:41:42 UTC 2005
 
 Modified Files:
 	pkgsrc/databases/gnats [pkgsrc-2005Q2]: MESSAGE Makefile PLIST distinfo
 	pkgsrc/databases/gnats/patches [pkgsrc-2005Q2]: patch-aa patch-ab
 Added Files:
 	pkgsrc/databases/gnats/patches [pkgsrc-2005Q2]: patch-ac patch-ad
 	    patch-ae
 
 Log Message:
 Pullup ticket 720 - requested by Adrian Portelli
 update and security fix for gnats
 
 Revisions pulled up:
 - pkgsrc/databases/gnats/Makefile		1.20 (partially), 1.21
 - pkgsrc/databases/gnats/MESSAGE		1.7
 - pkgsrc/databases/gnats/PLIST			1.9
 - pkgsrc/databases/gnats/distinfo		1.7, 1.8
 - pkgsrc/databases/gnats/patches/patch-aa	1.3, 1.4
 - pkgsrc/databases/gnats/patches/patch-ab	1.4
 - pkgsrc/databases/gnats/patches/patch-ac	1.4
 - pkgsrc/databases/gnats/patches/patch-ad	1.3
 - pkgsrc/databases/gnats/patches/patch-ae	1.3
 
    Module Name:		pkgsrc
    Committed By:	recht
    Date:		Sat Aug 27 22:24:02 UTC 2005
 
    Modified Files:
    	pkgsrc/databases/gnats: MESSAGE Makefile PLIST distinfo
    	pkgsrc/databases/gnats/patches: patch-aa patch-ab
    Added Files:
    	pkgsrc/databases/gnats/patches: patch-ac patch-ad patch-ae
 
    Log Message:
    Update to gnats 4.1.0.
    Make a overhaul of the package and bring it closer to pkgsrc standards.
    Addresses PR 26174 by Hauke Fath.
 
    changes:
 
    This is GNATS 4.1.0, a release that incorporates multiple bug fixes
    and enhancements that have been committed to CVS since the release of
    GNATS 4.0.  Notable enhancements include:
 
    - Upgrade to autoconf 2.59 generated configure scripts.
    - New PR numbers are reported to the client upon new submissions
    - Rewrite of install-sid.  Now, rather than editing send-pr, which can
      be installed on a read-only partition, install-sid creates or edits
      user or site configuration files ~/.send-pr.conf or
      /etc/gnats/send-pr.conf.
    - Removal of libiberty, old manpages, and old build framework cruft
    - Performance enhancements to indexing code
    - Various cleanups and bugfixes.  See the ChangeLog files for details.
 ---
    Module Name:		pkgsrc
    Committed By:	recht
    Date:		Sun Aug 28 12:36:42 UTC 2005
 
    Modified Files:
    	pkgsrc/databases/gnats: Makefile distinfo
    	pkgsrc/databases/gnats/patches: patch-aa
 
    Log Message:
    Add a patch from gnats CSV to fix the security problem noted in:
    http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-2180
 
    Patch by adrianp@.
 
    ChangeLog from gnats CSV:
    * Makefile.in (install-gnats-tools, install-gnats-bin): Removed chown
    and chmod entries for setting binaries suid.  CAN-2005-2180 advisory.
    gen-index as setuid root can overwrite any system file.
 
    Bump PKGREVISION to 1.
 
 
 To generate a diff of this commit:
 cvs rdiff -r1.6 -r1.6.6.1 pkgsrc/databases/gnats/MESSAGE
 cvs rdiff -r1.17 -r1.17.2.1 pkgsrc/databases/gnats/Makefile
 cvs rdiff -r1.8 -r1.8.6.1 pkgsrc/databases/gnats/PLIST
 cvs rdiff -r1.6 -r1.6.4.1 pkgsrc/databases/gnats/distinfo
 cvs rdiff -r1.2 -r1.2.6.1 pkgsrc/databases/gnats/patches/patch-aa
 cvs rdiff -r1.3 -r1.3.6.1 pkgsrc/databases/gnats/patches/patch-ab
 cvs rdiff -r0 -r1.3.6.1 pkgsrc/databases/gnats/patches/patch-ac
 cvs rdiff -r0 -r1.2.6.1 pkgsrc/databases/gnats/patches/patch-ad \
     pkgsrc/databases/gnats/patches/patch-ae
 
 Please note that diffs are not public domain; they are subject to the
 copyright notices on the relevant files.