Subject: CVS commit: [pkgsrc-2005Q3] pkgsrc/devel/gtexinfo
To: None <pkgsrc-changes@NetBSD.org>
From: Soren Jacobsen <snj@netbsd.org>
List: pkgsrc-changes
Date: 10/12/2005 03:56:20
Module Name:	pkgsrc
Committed By:	snj
Date:		Wed Oct 12 03:56:19 UTC 2005

Modified Files:
	pkgsrc/devel/gtexinfo [pkgsrc-2005Q3]: Makefile distinfo
Added Files:
	pkgsrc/devel/gtexinfo/patches [pkgsrc-2005Q3]: patch-al

Log Message:
Pullup ticket 821 - requested by Lubomir Sedlacik
security fix for gtexinfo

Revisions pulled up:
- pkgsrc/devel/gtexinfo/Makefile		1.58
- pkgsrc/devel/gtexinfo/distinfo		1.22
- pkgsrc/devel/gtexinfo/patches/patch-al	1.1

   Module Name:    pkgsrc
   Committed By:   salo
   Date:           Mon Oct 10 15:14:49 UTC 2005

   Modified Files:
           pkgsrc/devel/gtexinfo: Makefile distinfo
   Added Files:
           pkgsrc/devel/gtexinfo/patches: patch-al

   Log Message:
   Security fix for CAN-2005-3011:

   "texindex in texinfo 4.8 and earlier allows local users to overwrite
   arbitrary files via a symlink attack on temporary files."

   http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-3011

   Patch from Ubuntu.


To generate a diff of this commit:
cvs rdiff -r1.57 -r1.57.4.1 pkgsrc/devel/gtexinfo/Makefile
cvs rdiff -r1.21 -r1.21.6.1 pkgsrc/devel/gtexinfo/distinfo
cvs rdiff -r0 -r1.1.2.1 pkgsrc/devel/gtexinfo/patches/patch-al

Please note that diffs are not public domain; they are subject to the
copyright notices on the relevant files.