Changelog for
amanda-3.5.4-bp157.1.3.x86_64.rpm :
* Fri Jul 28 2023 pgajdosAATTsuse.com- version update to 3.5.4
* Fixed: arg checking for runtar.c (CVE-2023-30577) [bsc#1213701]- modified patches % amanda-2.6.1p1-avoid-perl-provides.patch (refreshed)
* Mon Jul 03 2023 Danilo Spinella
- Fix the user owner of the files in /usr from amanda to root, bsc#1172572
* Tue Mar 21 2023 Danilo Spinella - Update to version 3.5.3:
* Fixed: removed vulnerable jQuery dependency
* Fixed: fix suppressed 1st char of error message in common-src/bsdtcp-security.c
* docs: improved README with Markdown
* docs: updated README file name for docs in Debian builds
* Fixed: post_inst_functions.sh to create amkey
* Fixed: added extern keyword for tu_debugging_enabled declaration in testutils.h
* Fixed: https://sogis.eu complaint symmetric encryption key derivation algorithm
* Fixed: removed perror to fix information leak vulnerability found in the calcsize SUID binary. (CVE-2022-37703, bsc#1203390)
* Fixed: added filter for RSH environment settings in rundump to fix privilege escalation vulnerability (CVE-2022-37704, bsc#1208033)
* Fixed: arg checking for runtar.c (CVE-2022-37705, bsc#1208032)- Remove upstreamed patches:
* CVE-2022-37705.patch
* amanda-3.5.1-GCC10_extern.patch
* amanda-3.5.2-fix-tests.patch
* Thu Feb 16 2023 Daniel Garcia - Add CVE-2022-37705.patch to fix privilege scalation (boo#1208032, gh#zmanda/amanda#194)
* Fri Oct 07 2022 Thorsten Kukuk - %_docdir/amanda should be mode 755 and not 644
* Thu Aug 25 2022 Antoine Belvire - Update to version 3.5.2:
* amstatus + new --[no]taped argument, useful when running \'watch amstatus CONF --summary --notaped\' if the run have many tapes
* amvault + new --uniq, --no-uniq argument + Behavior change: The default is --uniq + new --delayed argument + new --run-delayed argument- Switch sources from Sourceforge to Github.- Drop amanda-timestamp.patch: Makefile now handles SOURCE_DATE_EPOCH.- Refresh patches on Perl bindings so that they apply on swig files since generated C files are not included in sources anymore:
* amanda-2.6.1p1-return_val.patch
* amanda-3.5-no_return_in_nonvoid_fnc.patch- Add amanda-3.5.2-fix-tests.patch: Fix tests on Tumbleweed (gh#zmanda/amanda#167).- Add build dependencies on swig and rpcgen: Generated files are not included in sources anymore.- Remove redundant %configure options.
* Mon Jun 08 2020 Kristyna Streitova - add amanda-3.5.1-GCC10_extern.patch to fix build with GCC10
* Thu Nov 28 2019 Kristyna Streitova - change %{_libexecdir}/amanda/application/ owner to root otherwise chkstat refuses to set correct permissions there- add missing BuildRequires
* Thu Oct 17 2019 Richard Brown - Remove obsolete Groups tag (fate#326485)
* Fri May 17 2019 Kristýna Streitová - update the list of suid binaries [bsc#1110797]
* added: ambind, ambsdtar, amgtar, amstar
* removed: amcheck, planner, dumper- update README.SUSE and add a note about setuid binaries and the fact that user amanda and members of the group amanda should be considered privileged users
* Mon Mar 26 2018 dimstarAATTopensuse.org- Own %{_sysconfdir}/xinetd.d: filesystem won\'t own this directory much longer (boo#1084457).
* Wed Mar 21 2018 crrodriguezAATTopensuse.org- Buildrequire curl and libcrypto (enables amazon s3 module)- amanda-libnsl.patch: libnsl is gone, replaced by tirpc fix configure checks.- Buildrequire libtirpc
* Wed Dec 13 2017 kstreitovaAATTsuse.com- update to 3.5.1
* do not check all \'r\' bit on suid binary
* fix parsing of configuration override (-o)
* can unset some setting
* client code will not fail if shared memory is not available
* amreport
* lot of improvement
* allow \'
*\' for a datestamp wildcard
* amgetconf
* print an empty string if a parameter is not set instead of \'no such parameter\'
* amdump
* new --no-dump, --no-flush and --no-vault argument
* amstatus fix
* lock holding disk to protect multiple parallel access
* Fri Oct 13 2017 kstreitovaAATTsuse.com- update to 3.5
* see ReleaseNotes for more information
* refresh amanda-2.6.1p1-shellbang.patch amanda-2.6.1p1-return_val.patch amanda-timestamp.patch
* remove (applied upstream) amanda-automake_add_missing.patch amanda-3.3.3-noundefbool.patch amanda-2.6.1p1-fix-perl-format.patch
* remove chg-
* scripts from the filelist
* pack new files- add amanda-3.5-no_return_in_nonvoid_fnc.patch to fix no-return-in-nonvoid-function rpmlint error- add url for source- remove SLE11 specific stuff from specfile- SuSE -> SUSE
* amanda-SuSE.tar.bz2 is now amanda-SUSE.tar.bz2
* README.SuSE is now README.SUSE- tweak description- run make check- use %configure macro- renumber patches- create a symlink for amoldrecover manpage
* Thu Mar 23 2017 kstreitovaAATTsuse.com- cleanup with spec-cleaner
* Wed Mar 08 2017 sfalkenAATTopensuse.org- Added lines to %files to clear unpackaged files error in openSUSE:Factory
* Fri Jan 27 2017 kstreitovaAATTsuse.com- add openssh to BuildRequires to support ssh [bsc#1022028]
* Sat Apr 16 2016 zaitorAATTopensuse.org- Replace libsmbclient and libsmbclient-devel for pkgconfig(smbclient) BuildRequires: Following samba changes.
* Fri Mar 04 2016 olafAATTaepfle.de- Remove timestamp from binary amanda-timestamp.patch
* Thu Nov 27 2014 mpluskalAATTsuse.com- Fix for boo#907361 -- amanda-2.6.1p1-fix-perl-format.patch- Clean spec file with spec-cleaner