[Lunar-commits] r22360 - moonbase/trunk/archive/tar

Stefan Wold ratler at lunar-linux.org
Thu Nov 30 09:26:35 CET 2006


Author: ratler
Date: 2006-11-30 09:26:35 +0100 (Thu, 30 Nov 2006)
New Revision: 22360

Modified:
   moonbase/trunk/archive/tar/BUILD
   moonbase/trunk/archive/tar/DETAILS
Log:
Added patch to fix vulnerability referred to by
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-6097

Built and tested with a few archives.


Modified: moonbase/trunk/archive/tar/BUILD
===================================================================
--- moonbase/trunk/archive/tar/BUILD	2006-11-30 05:29:02 UTC (rev 22359)
+++ moonbase/trunk/archive/tar/BUILD	2006-11-30 08:26:35 UTC (rev 22360)
@@ -1,5 +1,5 @@
 (
-
+  patch_it $SOURCE3 1 &&
   cp $SOURCE_CACHE/$SOURCE2 tar.1.gz  &&  
   # this sedit restores the tar --list to its older 1.15.1 format
   sedit "s/tartime (st->mtime, false)/tartime (st->mtime, true)/" src/list.c &&

Modified: moonbase/trunk/archive/tar/DETAILS
===================================================================
--- moonbase/trunk/archive/tar/DETAILS	2006-11-30 05:29:02 UTC (rev 22359)
+++ moonbase/trunk/archive/tar/DETAILS	2006-11-30 08:26:35 UTC (rev 22360)
@@ -2,14 +2,17 @@
          VERSION=1.16
           SOURCE=$MODULE-$VERSION.tar.bz2
          SOURCE2=$MODULE.1-$VERSION.gz
+         SOURCE3=$MODULE-1.16-mangling.patch
    SOURCE_URL[0]=$GNU_URL/$MODULE/
    SOURCE_URL[1]=ftp://ftp.gnu.org/gnu/$MODULE/
       SOURCE_VFY=sha1:b98abe392cedb7fcef475a41d61c17a8f800b90c
      SOURCE2_URL=$PATCH_URL/
      SOURCE2_VFY=sha1:a285cfa87f221169320ab5a6cb90ea7b51d6fa81
+     SOURCE3_URL=$PATCH_URL/
+     SOURCE3_VFY=sha1:fff8c96eb17e644214891e3cf44a9ed39bbf392c
         WEB_SITE=http://www.gnu.org/software/tar/tar.html
          ENTERED=20010922
-         UPDATED=20061022
+         UPDATED=20061130
       MAINTAINER=prox at lunar-linux.org
            SHORT="tar creates GNU tar archives."
 



More information about the Lunar-commits mailing list