From c89f0d4adeb4c859e6e2db196388e18b3cafcf31 Mon Sep 17 00:00:00 2001 From: Timo Gurr Date: Thu, 28 Feb 2008 20:24:49 +0000 Subject: [PATCH] Add cups-1.2.12-r5.ebuild to fix security issue CVE-2008-0882, see bug #211449.Remove older vulnerable versions. Rename patches for better versioning. Minor ebuild cleanups. Package-Manager: portage-2.1.4.4 --- net-print/cups/ChangeLog | 17 +- net-print/cups/Manifest | 19 +- net-print/cups/cups-1.2.12-r4.ebuild | 8 +- ...1.2.10-r1.ebuild => cups-1.2.12-r5.ebuild} | 58 ++-- net-print/cups/cups-1.3.5.ebuild | 280 ------------------ ...cups-1.3.6.ebuild => cups-1.3.6-r1.ebuild} | 9 +- ....patch => cups-1.2.12-CVE-2007-4045.patch} | 0 ....patch => cups-1.2.12-CVE-2007-4351.patch} | 0 .../files/cups-1.2.12-CVE-2008-0882.patch | 28 ++ net-print/cups/files/cups-1.3.0-bindnow.patch | 47 --- .../cups/files/cups-1.3.4-CVE-2007-4045.patch | 47 --- net-print/cups/files/pdftops.pl | 162 ---------- 12 files changed, 96 insertions(+), 579 deletions(-) rename net-print/cups/{cups-1.2.10-r1.ebuild => cups-1.2.12-r5.ebuild} (77%) delete mode 100644 net-print/cups/cups-1.3.5.ebuild rename net-print/cups/{cups-1.3.6.ebuild => cups-1.3.6-r1.ebuild} (96%) rename net-print/cups/files/{cups-1.2.4-CVE-2007-4045.patch => cups-1.2.12-CVE-2007-4045.patch} (100%) rename net-print/cups/files/{cups-1.2-str2561-v2.patch => cups-1.2.12-CVE-2007-4351.patch} (100%) create mode 100644 net-print/cups/files/cups-1.2.12-CVE-2008-0882.patch delete mode 100644 net-print/cups/files/cups-1.3.0-bindnow.patch delete mode 100644 net-print/cups/files/cups-1.3.4-CVE-2007-4045.patch delete mode 100644 net-print/cups/files/pdftops.pl diff --git a/net-print/cups/ChangeLog b/net-print/cups/ChangeLog index 0f1d73b7720c..ca70056d52bf 100644 --- a/net-print/cups/ChangeLog +++ b/net-print/cups/ChangeLog @@ -1,6 +1,21 @@ # ChangeLog for net-print/cups # Copyright 1999-2008 Gentoo Foundation; Distributed under the GPL v2 -# $Header: /var/cvsroot/gentoo-x86/net-print/cups/ChangeLog,v 1.281 2008/02/22 18:13:58 tgurr Exp $ +# $Header: /var/cvsroot/gentoo-x86/net-print/cups/ChangeLog,v 1.282 2008/02/28 20:24:49 tgurr Exp $ + +*cups-1.3.6-r1 (28 Feb 2008) +*cups-1.2.12-r5 (28 Feb 2008) + + 28 Feb 2008; Timo Gurr + -files/cups-1.2.4-CVE-2007-4045.patch, -files/cups-1.2-str2561-v2.patch, + +files/cups-1.2.12-CVE-2007-4045.patch, + +files/cups-1.2.12-CVE-2007-4351.patch, + +files/cups-1.2.12-CVE-2008-0882.patch, -files/cups-1.3.0-bindnow.patch, + -files/cups-1.3.4-CVE-2007-4045.patch, -files/pdftops.pl, + -cups-1.2.10-r1.ebuild, cups-1.2.12-r4.ebuild, +cups-1.2.12-r5.ebuild, + -cups-1.3.5.ebuild, -cups-1.3.6.ebuild, +cups-1.3.6-r1.ebuild: + Add cups-1.2.12-r5.ebuild to fix security issue CVE-2008-0882, see bug + #211449.Remove older vulnerable versions. Rename patches for better + versioning. Minor ebuild cleanups. *cups-1.3.6 (22 Feb 2008) diff --git a/net-print/cups/Manifest b/net-print/cups/Manifest index 6eed1e86955b..605619858346 100644 --- a/net-print/cups/Manifest +++ b/net-print/cups/Manifest @@ -1,21 +1,16 @@ -AUX cups-1.2-str2561-v2.patch 3910 RMD160 461a232b2a0ebc52a83cb729112c0f7d3f3d0ffe SHA1 9b7706a34fd08c32b7911a9f09f02a02c790a77c SHA256 1da64de6358dea65971105530795ffb8d100ddfe5b42c03cdbd815432de219c8 AUX cups-1.2.0-bindnow.patch 2178 RMD160 cdf51a6734c7a38fab33f270c7c374445a934321 SHA1 5406422e6b92c571f636d521baee354f84fafc2d SHA256 0fffd86557fdfbf85e32781d1b77f9696e5f0ed7eb30a78fb57ca82cfafdc190 +AUX cups-1.2.12-CVE-2007-4045.patch 1737 RMD160 6c239b26443af6cf841a457cc5611a2f78d809c3 SHA1 02c2bd1bf58204fd9e1b380f8899dae2f98c2fed SHA256 0e4898b7e42f74f894b416a1398d75bcf6062497a87e061984f09e904f68489e +AUX cups-1.2.12-CVE-2007-4351.patch 3910 RMD160 461a232b2a0ebc52a83cb729112c0f7d3f3d0ffe SHA1 9b7706a34fd08c32b7911a9f09f02a02c790a77c SHA256 1da64de6358dea65971105530795ffb8d100ddfe5b42c03cdbd815432de219c8 AUX cups-1.2.12-CVE-2007-5849.patch 1017 RMD160 0fd58946d8cfca13460ad07bfde670a3319fe1ff SHA1 4c4cb69d857427de43b5b91b5aceb7cb157be530 SHA256 9288292457f8c8de77b04eab651b547dd6506a03453ed93294577e2fb4f3c67b -AUX cups-1.2.4-CVE-2007-4045.patch 1737 RMD160 6c239b26443af6cf841a457cc5611a2f78d809c3 SHA1 02c2bd1bf58204fd9e1b380f8899dae2f98c2fed SHA256 0e4898b7e42f74f894b416a1398d75bcf6062497a87e061984f09e904f68489e -AUX cups-1.3.0-bindnow.patch 1919 RMD160 8ee1c27c0236b64df1cfc2a71f59370137768cc1 SHA1 16151a09d7b4a1fc431987191bdb09b92dd9631b SHA256 871d92fb8c6f658d1035a3ff058b5186131dfe295f54ecdcd4bc630b517eee4b +AUX cups-1.2.12-CVE-2008-0882.patch 1090 RMD160 f6de4e0a4ebcb70f4969cbcb2cba38e5a98366c5 SHA1 3c834957b3fb625cdde4a0c21e5916c6a8c1667f SHA256 9168456e294e1ca30868580028ab79d68d31aaf208687f80699e3e30f3ad77e6 AUX cups-1.3.0-configure.patch 651 RMD160 e4c7f45d7ddc28157433bf025c7f946c7e3b6d6a SHA1 101bf1893b56640d9fa82078e29319fbbd1449c7 SHA256 d6e5e60a982a3c093c0d0f89cf865e2b4c36290f5b1e188b7bf305d210070736 -AUX cups-1.3.4-CVE-2007-4045.patch 1276 RMD160 4aa328e6c0b30e58cfbf7b645380c147dc20dfd4 SHA1 4595ade2f84a2f868a4735a3ce2e1761e26b0ff4 SHA256 10023e221c1a59263b44d13649a26afbeb7d3e84a52b1c7ab25116eaae92811d AUX cupsd.init 288 RMD160 9bd676af5b43a97ba08ca51f70cefb445faeb8b8 SHA1 922868e1a6acb81b83e87a3c6905149789f16503 SHA256 008eeadc4979ad0e1f05e8ce5d22449eb798375e75ffc3176cbef138a53de4f9 AUX cupsd.init.d 293 RMD160 19fbef21cee7e472e7028f3101b680baa0089c54 SHA1 e6b27b2638fec258fe2f55c926c2530e909ca3d2 SHA256 b4268a6bae95e96b6af21c3716ecc905073736ce7dc33be1489d574a447f3c48 AUX pdftops-1.20.gentoo 10412 RMD160 16e229662c47e03af1d1f4cb5764a76d17a66642 SHA1 6afb8a655b6ff013a2c8c8cbfb615ba1e561503b SHA256 ac5fa01ca776d75bd7cef62eef9f6b0c3945ee87e8950b40ca9f9f3ff46a16c1 -AUX pdftops.pl 5552 RMD160 8c73e4a5bb5ae5a7eafb59b25ec483279dad90d4 SHA1 9c57044a5e1c716fb4b6cdb70d827c35bc0e82c1 SHA256 aeaca40973d4a4df2212e73820f96272923e23717a69b0bf738896a5fc04df25 -DIST cups-1.2.10-source.tar.bz2 3618084 RMD160 85b3bbd46a6fc097891c571ffad8e5e46693743f SHA1 241d7a3c52370fb08ed2ffc3fd8f59673d158299 SHA256 601b3b9256c55361477427c3e8db56c9ee4e141762814aea590bcf110a95bb36 DIST cups-1.2.12-source.tar.bz2 3788301 RMD160 598270e37ff8a9b9ff1e667066d6f7e120493e32 SHA1 11a540f76a1d3164b6636bf8ba47928803ad9356 SHA256 b4ff8e934da7db32d5654360ea9068faa0ed5a00fde02161ae53c2052510d00f -DIST cups-1.3.5-source.tar.bz2 4082098 RMD160 c6157e552e833447e623175a4e90146ceb9d9ba4 SHA1 f0f7674b46e00582f327765acd4133a6035d393e SHA256 3a8ef866ffe2d5aac6a601770d27cfefec3ba40e19b1550ca4c1eb1ab27f19d1 DIST cups-1.3.6-source.tar.bz2 4079258 RMD160 1da6420f473562eba27e1e997e13d60e0ea101a8 SHA1 4f7ed1c2b16db46f945ab113beab8aeaecbca0b9 SHA256 b4003862daffd6887a52cf66a67a21854c1ecda15698bf44b2fe1fc12a833695 -EBUILD cups-1.2.10-r1.ebuild 6348 RMD160 5de50c4fc60398e9c5d15564e11da91b04eeb8dd SHA1 14fe4110363be2772b0088dc341aafae2a2d9568 SHA256 bb463b251d9a6131dfc2d926de59abccc18a1b04dcacef401ea616d1ea23ff61 -EBUILD cups-1.2.12-r4.ebuild 7107 RMD160 c3441cae5322936b013eec7d931babcdfe93a725 SHA1 94b6a1f27a566cb1213f6f69a8c08b3e2bfb5b11 SHA256 beac8389a1798ead8be7e2594842a95181961e641948cdc426ef544a5e691d8a -EBUILD cups-1.3.5.ebuild 8180 RMD160 c29eccb692f4b9064ff275c310526c7574eea17f SHA1 b2e3481cc0a74c53ede976ed96c06f5cfa9d5dcb SHA256 7693bbafa966b8ad342be1201328f567836ed6a7222574ff2fba9c54978d6986 -EBUILD cups-1.3.6.ebuild 8048 RMD160 f38cba97edf437fc75106f1725e879b6594a047b SHA1 859fd6c5c941508a8266ce1e45c9180d6c6e0ee4 SHA256 6daf0906d04a497d1eb874b631c3d699907ebd92d8e2557d075745bf510cd7ce -MISC ChangeLog 40401 RMD160 2479c4557068c0532d350bb163bc2ee3792cbb8e SHA1 b4575051e8e2847df8d6310c8e15bd6dc74981e8 SHA256 bb46b6dc3da4b2dbe026db5a9c6dcea8ed9fa392fc08780df574053d395da87e +EBUILD cups-1.2.12-r4.ebuild 7113 RMD160 992518b586d5212e04fcff686cd537d858df1b71 SHA1 624a3559fb603c57aceb1805ef212a6807daf567 SHA256 ffb0514c243014229cfefdcee5102e4d987526b57fb134e4a55dc3ea84ca9ba8 +EBUILD cups-1.2.12-r5.ebuild 7064 RMD160 1fabc27c7fa0cf200c4d80b77c485dfe7604740b SHA1 e1e2451bb086aaff5a2700392928e729b7784bcb SHA256 a95f4514eb255ab531e5cc62e10fe17a16fbb9dbf8d58e84ac7af696199cd0b9 +EBUILD cups-1.3.6-r1.ebuild 8001 RMD160 1e197d8aa903dccd45842c2440bb8043e50fc467 SHA1 ea7c1c99842520426113e9e271b26cb85a25445e SHA256 e1e633dfd00a9664efd42d52ec7b0f05556968ea2d4a3fba809263ada1b27d34 +MISC ChangeLog 41118 RMD160 5625c11d749641a98e3d524d50133bdd31ea3b29 SHA1 9c76ed708e10fe4d713d19c16eef6d3649d6d246 SHA256 8182a9cf3ec401d74b50eefba233ea748d4c06356535b8349203a1ad076ee318 MISC metadata.xml 161 RMD160 1e5b1e42553c8869b93c4a5448e9a2a2ed9fe525 SHA1 209c6a46e4cdd891980115e42ba419e3799f8088 SHA256 7c85e6739a71f5bb23e8de36c88677d772946e61f7285892f7554e37bd2bca76 diff --git a/net-print/cups/cups-1.2.12-r4.ebuild b/net-print/cups/cups-1.2.12-r4.ebuild index 6644a0c27195..d2fa31426923 100644 --- a/net-print/cups/cups-1.2.12-r4.ebuild +++ b/net-print/cups/cups-1.2.12-r4.ebuild @@ -1,6 +1,6 @@ # Copyright 1999-2008 Gentoo Foundation # Distributed under the terms of the GNU General Public License v2 -# $Header: /var/cvsroot/gentoo-x86/net-print/cups/cups-1.2.12-r4.ebuild,v 1.3 2008/01/10 09:04:24 vapier Exp $ +# $Header: /var/cvsroot/gentoo-x86/net-print/cups/cups-1.2.12-r4.ebuild,v 1.4 2008/02/28 20:24:49 tgurr Exp $ WANT_AUTOMAKE=latest @@ -84,10 +84,10 @@ src_unpack() { # upstream does not acknowledge bindnow as a solution epatch "${FILESDIR}"/cups-1.2.0-bindnow.patch - # CVE-2007-4351 security patch, bug #196736 - epatch "${FILESDIR}"/${PN}-1.2-str2561-v2.patch # CVE-2007-4045 security patch, bug #199195 - epatch "${FILESDIR}"/${PN}-1.2.4-CVE-2007-4045.patch + epatch "${FILESDIR}"/${PN}-1.2.12-CVE-2007-4045.patch + # CVE-2007-4351 security patch, bug #196736 + epatch "${FILESDIR}"/${PN}-1.2.12-CVE-2007-4351.patch # CVE-2007-5849 security patch, bug #201570 epatch "${FILESDIR}"/${PN}-1.2.12-CVE-2007-5849.patch diff --git a/net-print/cups/cups-1.2.10-r1.ebuild b/net-print/cups/cups-1.2.12-r5.ebuild similarity index 77% rename from net-print/cups/cups-1.2.10-r1.ebuild rename to net-print/cups/cups-1.2.12-r5.ebuild index 1a26e80e402f..4f3d54165b21 100644 --- a/net-print/cups/cups-1.2.10-r1.ebuild +++ b/net-print/cups/cups-1.2.12-r5.ebuild @@ -1,8 +1,6 @@ # Copyright 1999-2008 Gentoo Foundation # Distributed under the terms of the GNU General Public License v2 -# $Header: /var/cvsroot/gentoo-x86/net-print/cups/cups-1.2.10-r1.ebuild,v 1.13 2008/02/22 18:13:58 tgurr Exp $ - -WANT_AUTOMAKE=latest +# $Header: /var/cvsroot/gentoo-x86/net-print/cups/cups-1.2.12-r5.ebuild,v 1.1 2008/02/28 20:24:49 tgurr Exp $ inherit autotools eutils flag-o-matic multilib pam @@ -10,12 +8,11 @@ MY_P=${P/_} DESCRIPTION="The Common Unix Printing System" HOMEPAGE="http://www.cups.org/" -SRC_URI="http://ftp.funet.fi/pub/mirrors/ftp.easysw.com/pub/cups/${PV}/${MY_P}-source.tar.bz2" -#ESVN_REPO_URI="http://svn.easysw.com/public/cups/trunk" +SRC_URI="mirror://sourceforge/cups/${MY_P}-source.tar.bz2" LICENSE="GPL-2" SLOT="0" -KEYWORDS="alpha amd64 arm hppa ia64 m68k ~mips ppc ppc64 s390 sh sparc x86 ~x86-fbsd" +KEYWORDS="~alpha ~amd64 ~arm ~hppa ~ia64 ~m68k ~mips ~ppc ~ppc64 ~s390 ~sh ~sparc ~sparc-fbsd ~x86 ~x86-fbsd" IUSE="ldap ssl slp pam php samba nls dbus tiff png ppds jpeg X" DEP="pam? ( virtual/pam ) @@ -60,9 +57,18 @@ PROVIDE="virtual/lpr" # we just leave it out, even if FEATURES=test RESTRICT="test" -S="${WORKDIR}/${MY_P}" +S=${WORKDIR}/${MY_P} pkg_setup() { + if use x86 && [ -d "/usr/lib64" ] + then + eerror "You are running an x86 system, but /usr/lib64 exists, cups will install all library objects into this directory!" + eerror "You should remove /usr/lib64, but before you do, you should check for existing objects, and re-compile all affected packages." + eerror "You can use qfile (emerge portage-utils to install qfile) to get a list of the affected ebuilds:" + eerror "# qfile -qC /usr/lib64" + die "lib64 on x86 detected" + fi + enewgroup lp enewuser lp -1 -1 -1 lp @@ -73,8 +79,14 @@ src_unpack() { unpack ${A} cd "${S}" - # upstream does not acknowledge bindnow as a solution - epatch "${FILESDIR}"/cups-1.2.0-bindnow.patch + # CVE-2007-4045 security patch, bug #199195 + epatch "${FILESDIR}"/${PN}-1.2.12-CVE-2007-4045.patch + # CVE-2007-4351 security patch, bug #196736 + epatch "${FILESDIR}"/${PN}-1.2.12-CVE-2007-4351.patch + # CVE-2007-5849 security patch, bug #201570 + epatch "${FILESDIR}"/${PN}-1.2.12-CVE-2007-5849.patch + # CVE-2008-0882 security patch, bug #211449 + epatch "${FILESDIR}"/${PN}-1.2.12-CVE-2008-0882.patch # cups does not use autotools "the usual way" and ship a static config.h.in eaclocal @@ -83,13 +95,17 @@ src_unpack() { src_compile() { export DSOFLAGS="${LDFLAGS}" + + if use ldap; then + append-flags -DLDAP_DEPRECATED + fi + econf \ --with-cups-user=lp \ --with-cups-group=lp \ --with-system-groups=lpadmin \ --localstatedir=/var \ --with-docdir=/usr/share/cups/html \ - --with-bindnow=$(bindnow-flags) \ $(use_enable pam) \ $(use_enable ssl) \ --enable-gnutls \ @@ -135,7 +151,7 @@ src_install() { # install pdftops filter exeinto /usr/libexec/cups/filter/ - newexe "${FILESDIR}"/pdftops.pl pdftops + newexe "${FILESDIR}"/pdftops-1.20.gentoo pdftops # only for gs-esp this is correct, see bug 163897 if has_version app-text/ghostscript-gpl || has_version app-text/ghostscript-gnu; then @@ -159,18 +175,20 @@ src_install() { pkg_preinst() { # cleanups - [ -n "${PN}" ] && rm -fR "${ROOT}"/usr/share/doc/"${PN}"-* + [ -n "${PN}" ] && rm -fR "${ROOT}"/usr/share/doc/${PN}-* } pkg_postinst() { - einfo "Remote printing: change " - einfo "Listen localhost:631" - einfo "to" - einfo "Listen *:631" - einfo "in /etc/cups/cupsd.conf" - einfo - einfo "For more information about installing a printer take a look at:" - einfo "http://www.gentoo.org/doc/en/printing-howto.xml." + echo + elog "Remote printing: change " + elog "Listen localhost:631" + elog "to" + elog "Listen *:631" + elog "in /etc/cups/cupsd.conf" + echo + elog "For more information about installing a printer take a look at:" + elog "http://www.gentoo.org/doc/en/printing-howto.xml." + echo local good_gs=false for x in app-text/ghostscript-gpl app-text/ghostscript-gnu app-text/ghostscript-esp; do diff --git a/net-print/cups/cups-1.3.5.ebuild b/net-print/cups/cups-1.3.5.ebuild deleted file mode 100644 index de35e522d2ab..000000000000 --- a/net-print/cups/cups-1.3.5.ebuild +++ /dev/null @@ -1,280 +0,0 @@ -# Copyright 1999-2007 Gentoo Foundation -# Distributed under the terms of the GNU General Public License v2 -# $Header: /var/cvsroot/gentoo-x86/net-print/cups/cups-1.3.5.ebuild,v 1.2 2007/12/26 16:55:59 cardoe Exp $ - -inherit autotools eutils flag-o-matic multilib pam - -MY_P=${P/_} - -DESCRIPTION="The Common Unix Printing System" -HOMEPAGE="http://www.cups.org/" -SRC_URI="mirror://sourceforge/cups/${MY_P}-source.tar.bz2" - -LICENSE="GPL-2" -SLOT="0" -KEYWORDS="~alpha ~amd64 ~arm ~hppa ~ia64 ~m68k ~mips ~ppc ~ppc64 ~s390 ~sh ~sparc ~sparc-fbsd ~x86 ~x86-fbsd" -IUSE="acl avahi dbus java jpeg kerberos ldap nls pam perl php png ppds python samba slp ssl static tiff X zeroconf" - -COMMON_DEPEND="acl? ( kernel_linux? ( sys-apps/acl sys-apps/attr ) ) - avahi? ( net-dns/avahi ) - dbus? ( sys-apps/dbus ) - java? ( >=virtual/jre-1.4 ) - jpeg? ( >=media-libs/jpeg-6b ) - kerberos? ( virtual/krb5 ) - ldap? ( net-nds/openldap ) - pam? ( virtual/pam ) - perl? ( dev-lang/perl ) - php? ( dev-lang/php ) - png? ( >=media-libs/libpng-1.2.1 ) - python? ( dev-lang/python ) - slp? ( >=net-libs/openslp-1.0.4 ) - ssl? ( net-libs/gnutls ) - tiff? ( >=media-libs/tiff-3.5.5 ) - zeroconf? ( !avahi? ( net-misc/mDNSResponder ) ) - app-text/libpaper - dev-libs/libgcrypt" - -DEPEND="${COMMON_DEPEND} - ! "${T}"/cupsd - doinitd "${T}"/cupsd - - # install our pam script - pamd_mimic_system cups auth account - - # correct path - sed -i -e "s:server = .*:server = /usr/libexec/cups/daemon/cups-lpd:" "${D}"/etc/xinetd.d/cups-lpd - # it is safer to disable this by default, bug 137130 - grep -w 'disable' "${D}"/etc/xinetd.d/cups-lpd || \ - sed -i -e "s:}:\tdisable = yes\n}:" "${D}"/etc/xinetd.d/cups-lpd - - # install pdftops filter - exeinto /usr/libexec/cups/filter/ - newexe "${FILESDIR}"/pdftops-1.20.gentoo pdftops - - # only for gs-esp this is correct, see bug 163897 - if has_version app-text/ghostscript-gpl || has_version app-text/ghostscript-gnu; then - sed -i -e "s:#application/vnd.cups-postscript:application/vnd.cups-postscript:" "${D}"/etc/cups/mime.convs - fi - - keepdir /usr/share/cups/profiles /usr/libexec/cups/driver /var/log/cups \ - /var/run/cups/certs /var/cache/cups /var/spool/cups/tmp /etc/cups/ssl - - # .desktop handling. X useflag. xdg-open from freedesktop is preferred - if use X; then - sed -i -e "s:htmlview:xdg-open:" "${D}"/usr/share/applications/cups.desktop - else - rm -r "${D}"/usr/share/applications - fi - - # fix a symlink collision, see bug #172341 - dodir /usr/share/ppd - dosym /usr/share/ppd /usr/share/cups/model/foomatic-ppds - - # create RSS feed directory - diropts -m 0740 -o lp -g lp - dodir /var/cache/cups/rss -} - -pkg_preinst() { - # cleanups - [ -n "${PN}" ] && rm -fR "${ROOT}"/usr/share/doc/"${PN}"-* -} - -pkg_postinst() { - echo - elog "For information about installing a printer and general cups setup" - elog "take a look at: http://www.gentoo.org/doc/en/printing-howto.xml" - echo - - local good_gs=false - for x in app-text/ghostscript-gpl app-text/ghostscript-gnu app-text/ghostscript-esp; do - if has_version ${x} && built_with_use ${x} cups; then - good_gs=true - break - fi - done; - if ! ${good_gs}; then - echo - ewarn "You need to emerge ghostscript with the \"cups\" USE flag turned on" - echo - fi - - if has_version =net-print/cups-1.1*; then - echo - ewarn "The configuration changed with cups-1.3, you may want to save the old" - ewarn "one and start from scratch:" - ewarn "# mv /etc/cups /etc/cups.orig; emerge -va1 cups" - echo - ewarn "You need to rebuild kdelibs for kdeprinter to work with cups-1.3" - echo - fi - - if [ -e "${ROOT}"/usr/lib/cups ]; then - echo - ewarn "/usr/lib/cups exists - You need to remerge every ebuild that" - ewarn "installed into /usr/lib/cups and /etc/cups, qfile is in portage-utils:" - ewarn "# FEATURES=-collision-protect emerge -va1 \$(qfile -qC /usr/lib/cups /etc/cups | sed \"s:net-print/cups$::\")" - echo - ewarn "FEATURES=-collision-protect is needed to overwrite the compatibility" - ewarn "symlinks installed by this package, it won't be needed on later merges." - ewarn "You should also run revdep-rebuild" - echo - - # place symlinks to make the update smoothless - for i in "${ROOT}"/usr/lib/cups/{backend,filter}/*; do - if [ "${i/\*}" == "${i}" ] && ! [ -e ${i/lib/libexec} ]; then - ln -s ${i} ${i/lib/libexec} - fi - done - fi -} diff --git a/net-print/cups/cups-1.3.6.ebuild b/net-print/cups/cups-1.3.6-r1.ebuild similarity index 96% rename from net-print/cups/cups-1.3.6.ebuild rename to net-print/cups/cups-1.3.6-r1.ebuild index ce8da7d51c5d..39d6d1032242 100644 --- a/net-print/cups/cups-1.3.6.ebuild +++ b/net-print/cups/cups-1.3.6-r1.ebuild @@ -1,6 +1,6 @@ # Copyright 1999-2008 Gentoo Foundation # Distributed under the terms of the GNU General Public License v2 -# $Header: /var/cvsroot/gentoo-x86/net-print/cups/cups-1.3.6.ebuild,v 1.1 2008/02/22 18:13:58 tgurr Exp $ +# $Header: /var/cvsroot/gentoo-x86/net-print/cups/cups-1.3.6-r1.ebuild,v 1.1 2008/02/28 20:24:49 tgurr Exp $ inherit autotools eutils flag-o-matic multilib pam @@ -94,12 +94,9 @@ src_unpack() { unpack ${A} cd "${S}" - # disable configure automagic for acl/attr + # disable configure automagic for acl/attr, upstream bug STR #2723. epatch "${FILESDIR}/${PN}-1.3.0-configure.patch" - # CVE-2007-4045 security patch, bug #199195 - epatch "${FILESDIR}/${PN}-1.3.4-CVE-2007-4045.patch" - # cups does not use autotools "the usual way" and ship a static config.h.in eaclocal eautoconf @@ -205,7 +202,7 @@ src_install() { keepdir /usr/share/cups/profiles /usr/libexec/cups/driver /var/log/cups \ /var/run/cups/certs /var/cache/cups /var/spool/cups/tmp /etc/cups/ssl - # .desktop handling. X useflag. xdg-open from freedesktop is preferred + # .desktop handling. X useflag. xdg-open from freedesktop is preferred, upstream bug STR #2724. if use X ; then sed -i -e "s:htmlview:xdg-open:" "${D}"/usr/share/applications/cups.desktop else diff --git a/net-print/cups/files/cups-1.2.4-CVE-2007-4045.patch b/net-print/cups/files/cups-1.2.12-CVE-2007-4045.patch similarity index 100% rename from net-print/cups/files/cups-1.2.4-CVE-2007-4045.patch rename to net-print/cups/files/cups-1.2.12-CVE-2007-4045.patch diff --git a/net-print/cups/files/cups-1.2-str2561-v2.patch b/net-print/cups/files/cups-1.2.12-CVE-2007-4351.patch similarity index 100% rename from net-print/cups/files/cups-1.2-str2561-v2.patch rename to net-print/cups/files/cups-1.2.12-CVE-2007-4351.patch diff --git a/net-print/cups/files/cups-1.2.12-CVE-2008-0882.patch b/net-print/cups/files/cups-1.2.12-CVE-2008-0882.patch new file mode 100644 index 000000000000..655e70e01bf7 --- /dev/null +++ b/net-print/cups/files/cups-1.2.12-CVE-2008-0882.patch @@ -0,0 +1,28 @@ +diff -up cups-1.2.4/scheduler/dirsvc.c.str2656 cups-1.2.4/scheduler/dirsvc.c +--- cups-1.2.4/scheduler/dirsvc.c.str2656 2008-02-21 13:33:06.000000000 +0000 ++++ cups-1.2.4/scheduler/dirsvc.c 2008-02-21 13:33:49.000000000 +0000 +@@ -1943,9 +1943,9 @@ process_browse_data( + if (hptr && !*hptr) + *hptr = '.'; /* Resource FQDN */ + +- if ((p = cupsdFindClass(name)) == NULL && BrowseShortNames) ++ if ((p = cupsdFindDest(name)) == NULL && BrowseShortNames) + { +- if ((p = cupsdFindClass(resource + 9)) != NULL) ++ if ((p = cupsdFindDest(resource + 9)) != NULL) + { + if (p->hostname && strcasecmp(p->hostname, host)) + { +@@ -2049,9 +2049,9 @@ process_browse_data( + if (hptr && !*hptr) + *hptr = '.'; /* Resource FQDN */ + +- if ((p = cupsdFindPrinter(name)) == NULL && BrowseShortNames) ++ if ((p = cupsdFindDest(name)) == NULL && BrowseShortNames) + { +- if ((p = cupsdFindPrinter(resource + 10)) != NULL) ++ if ((p = cupsdFindDest(resource + 10)) != NULL) + { + if (p->hostname && strcasecmp(p->hostname, host)) + { + diff --git a/net-print/cups/files/cups-1.3.0-bindnow.patch b/net-print/cups/files/cups-1.3.0-bindnow.patch deleted file mode 100644 index aa97cd4e60fe..000000000000 --- a/net-print/cups/files/cups-1.3.0-bindnow.patch +++ /dev/null @@ -1,47 +0,0 @@ -diff -Naur cups-1.3.0/config-scripts/cups-setXid.m4 cups-1.3.0/config-scripts/cups-setXid.m4.new ---- cups-1.3.0/config-scripts/cups-setXid.m4 1970-01-01 01:00:00.000000000 +0100 -+++ cups-1.3.0/config-scripts/cups-setXid.m4.new 2006-05-08 23:50:22.000000000 +0200 -@@ -0,0 +1,9 @@ -+dnl -+dnl Copyright 1999-2007 Gentoo Foundation -+dnl Distributed under the terms of the GNU General Public License v2 -+dnl -+ -+AC_ARG_WITH(bindnow, [ --with-bindnow Set linker flags for force-binding setuid binaries], -+ BINDNOW_FLAGS="$withval", -+ BINDNOW_FLAGS="") -+AC_SUBST(BINDNOW_FLAGS) -diff -Naur cups-1.3.0/configure.in cups-1.3.0/configure.in.new ---- cups-1.3.0/configure.in 2007-07-25 01:47:12.000000000 +0200 -+++ cups-1.3.0/configure.in.new 2007-08-15 10:31:58.896923749 +0200 -@@ -41,6 +41,7 @@ - sinclude(config-scripts/cups-pap.m4) - sinclude(config-scripts/cups-pdf.m4) - sinclude(config-scripts/cups-scripting.m4) -+sinclude(config-scripts/cups-setXid.m4) - - INSTALL_LANGUAGES="" - UNINSTALL_LANGUAGES="" -diff -Naur cups-1.3.0/Makedefs.in cups-1.3.0/Makedefs.in.new ---- cups-1.3.0/Makedefs.in 2007-07-18 21:49:45.000000000 +0200 -+++ cups-1.3.0/Makedefs.in.new 2007-08-15 10:24:56.634342552 +0200 -@@ -132,6 +132,7 @@ - LEGACY_BACKENDS = @LEGACY_BACKENDS@ - LIBCUPSORDER = @LIBCUPSORDER@ - LIBCUPSIMAGEORDER = @LIBCUPSIMAGEORDER@ -+BINDNOW_FLAGS = @BINDNOW_FLAGS@ - LINKCUPS = @LINKCUPS@ $(SSLLIBS) - LINKCUPSIMAGE = @LINKCUPSIMAGE@ - LIBS = $(LINKCUPS) $(COMMONLIBS) -diff -Naur cups-1.3.0/systemv/Makefile cups-1.3.0/systemv/Makefile.new ---- cups-1.3.0/systemv/Makefile 2007-07-11 23:46:42.000000000 +0200 -+++ cups-1.3.0/systemv/Makefile.new 2007-08-15 10:34:29.771906823 +0200 -@@ -212,7 +212,7 @@ - - lppasswd: lppasswd.o ../cups/$(LIBCUPS) - echo Linking $@... -- $(CC) $(LDFLAGS) -o lppasswd lppasswd.o $(LIBZ) $(LIBS) -+ $(CC) $(LDFLAGS) $(BINDNOW_FLAGS) -o lppasswd lppasswd.o $(LIBZ) $(LIBS) - - - # diff --git a/net-print/cups/files/cups-1.3.4-CVE-2007-4045.patch b/net-print/cups/files/cups-1.3.4-CVE-2007-4045.patch deleted file mode 100644 index aab1b213d018..000000000000 --- a/net-print/cups/files/cups-1.3.4-CVE-2007-4045.patch +++ /dev/null @@ -1,47 +0,0 @@ -diff -up cups-1.3.4/scheduler/client.c.CVE-2007-4045 cups-1.3.4/scheduler/client.c ---- cups-1.3.4/scheduler/client.c.CVE-2007-4045 2007-11-07 21:11:58.000000000 +0000 -+++ cups-1.3.4/scheduler/client.c 2007-11-07 21:13:26.000000000 +0000 -@@ -114,6 +114,25 @@ static int write_file(cupsd_client_t *c - static void write_pipe(cupsd_client_t *con); - - -+void -+_cupsdFixClientsBIO(void) -+{ -+#ifdef HAVE_LIBSSL -+ cupsd_client_t *c; -+ BIO *bio; -+ cupsArraySave (Clients); -+ for (c = (cupsd_client_t *)cupsArrayFirst(Clients); -+ c; -+ c = (cupsd_client_t *)cupsArrayNext(Clients)) -+ { -+ bio = SSL_get_wbio(c->http.tls); -+ BIO_ctrl(bio, BIO_C_SET_FILE_PTR, 0, (char *)HTTP(c)); -+ } -+ cupsArrayRestore (Clients); -+#endif -+} -+ -+ - /* - * 'cupsdAcceptClient()' - Accept a new client. - */ -@@ -451,6 +470,7 @@ cupsdAcceptClient(cupsd_listener_t *lis) - } - - cupsArrayAdd(Clients, con); -+ _cupsdFixClientsBIO(); - - cupsdLogMessage(CUPSD_LOG_DEBUG2, - "cupsdAcceptClient: %d connected to server on %s:%d", -@@ -735,6 +755,7 @@ cupsdCloseClient(cupsd_client_t *con) /* - */ - - cupsArrayRemove(Clients, con); -+ _cupsdFixClientsBIO(); - - free(con); - } -diff -up cups-1.3.4/scheduler/main.c.CVE-2007-4045 cups-1.3.4/scheduler/main.c - diff --git a/net-print/cups/files/pdftops.pl b/net-print/cups/files/pdftops.pl deleted file mode 100644 index 36932234bc14..000000000000 --- a/net-print/cups/files/pdftops.pl +++ /dev/null @@ -1,162 +0,0 @@ -#!/usr/bin/perl -w -# pdftops.pl - wrapper script for xpdf's pdftops utility to act as a CUPS filter -# ============================================================================== -# 1.00 - 2004-10-05/Bl -# Initial implementation -# -# Copyright: Helge Blischke / SRZ Berlin 2004 -# This program is free seoftware and governed by the GNU Public License Version 2. -# -# Description: -# ------------ -# This program wraps the pdftops utility from the xpdf 3.00 (and higher) suite -# to behave as a CUPS filter as a replacement for the original pdftops filter. -# -# The main purpose of this approach is to keep the properties of a PDF to be -# printed as undesturbed as possible, especially with respect to page size, -# scaling, and positioning. -# -# The pdftops utility reads a configuration file 'pdftops.conf' in the -# CUPS_SERVERROOT directory, which must exist but may be empty. The sample -# configuration file accompanying this program sets the defaults which -# seem plausible to me with respect to high end production printers. -# -# To give the user highest possible flexibility, this program accepts and -# evaluates a set of job attributes special to this filter, which are -# described below: -# -# pdf-pages=, -# expands to the -f and -l options of pdftops -# to select a page range to process. This is independent -# of the page-ranges attribute and may significantly -# increase throughput when printing page ranges. -# Either of these numbers may be omitted. -# -# pdf-paper= -# pdf-paper=x -# may be one of letter, legal , A4, A3, or match; -# and are the paper width and height -# in printers points (1/72 inch). This expands to -# either the -paper or the -paperh and -paperw options -# of pdftops -# -# pdf-opw= -# pdf-upw= -# expand to the -opw and -upw options of pdftops, -# respectively and permit printing of password -# protected PDFs. -# -# pdf-