diff --git a/.gitignore b/.gitignore index 2268463..784d285 100644 --- a/.gitignore +++ b/.gitignore @@ -1 +1,2 @@ centerim-4.22.9.tar.gz +/centerim-4.22.10.tar.gz diff --git a/centerim-4.22.8-nss.patch b/centerim-4.22.8-nss.patch deleted file mode 100644 index 4e60301..0000000 --- a/centerim-4.22.8-nss.patch +++ /dev/null @@ -1,33 +0,0 @@ -From 3e8cb1fb8e662a205c6f3689d7abce5110893f16 Mon Sep 17 00:00:00 2001 -From: Lubomir Rintel -Date: Thu, 18 Feb 2010 23:40:00 +0100 -Subject: [PATCH] Use RAND_add() with nss_compat_openssl - -It does not provide RAND_seed(). ---- - libgadu/libgadu.c | 7 +++++++ - 1 files changed, 7 insertions(+), 0 deletions(-) - -diff --git a/libgadu/libgadu.c b/libgadu/libgadu.c -index b3f5585..ce05b26 100644 ---- a/libgadu/libgadu.c -+++ b/libgadu/libgadu.c -@@ -760,8 +760,15 @@ struct gg_session *gg_login(const struct gg_login_params *p) - time(&rstruct.time); - rstruct.ptr = (void *) &rstruct; - -+#ifdef HAVE_NSS_COMPAT -+ /* nss compat ossl doesn't implement that, despite -+ * having a definition in header */ -+ RAND_add((void *) rdata, sizeof(rdata), sizeof(rdata)); -+ RAND_add((void *) &rstruct, sizeof(rstruct), sizeof(rstruct)); -+#else - RAND_seed((void *) rdata, sizeof(rdata)); - RAND_seed((void *) &rstruct, sizeof(rstruct)); -+#endif - } - - sess->ssl_ctx = SSL_CTX_new(TLSv1_client_method()); --- -1.7.0 - diff --git a/centerim.spec b/centerim.spec index dc6e169..76b8376 100644 --- a/centerim.spec +++ b/centerim.spec @@ -1,5 +1,5 @@ Name: centerim -Version: 4.22.9 +Version: 4.22.10 Release: 1%{?dist} Epoch: 1 @@ -13,7 +13,6 @@ Source1: http://www.centerim.org/images/b/b5/Centerim_b.svg Source2: centerim.desktop Patch0: centerim-4.22.6-url-escape-fedora.patch -Patch1: centerim-4.22.8-nss.patch BuildRoot: %{_tmppath}/%{name}-%{version}-%{release}-root-%(%{__id_u} -n) @@ -46,7 +45,6 @@ Internal RSS reader and a client for LiveJournal are provided. %prep %setup -q %patch0 -p1 -b .url-escape-fedora -%patch1 -p1 -b .nss iconv -f iso8859-1 -t utf8 ChangeLog >ChangeLog.utf8 touch -r ChangeLog ChangeLog.utf8 @@ -100,6 +98,10 @@ rm -rf $RPM_BUILD_ROOT %changelog +* Sat Dec 04 2010 Lubomir Rintel - 1:4.22.10-1 +- New release, fixing CVE-2009-3720 +- Drop upstreamed nss patch + * Thu Feb 18 2010 Lubomir Rintel - 1:4.22.9-1 - Fix build - New upstream release diff --git a/sources b/sources index 014551a..daf14a2 100644 --- a/sources +++ b/sources @@ -1 +1 @@ -c43911508205e0277529230c8316a298 centerim-4.22.9.tar.gz +7565c3c8cac98a4e2d8524076a44676f centerim-4.22.10.tar.gz