------------------------------------------------------------------ --- Changelog.11.0-i386 ----- Tue Jun 10 18:27:27 CEST 2008 ------ ------------------------------------------------------------------ ------------------------------------------------------------------ ------------------ 2008-6-2 - Jun 2 2008 ------------------- ------------------------------------------------------------------ ++++ moneyplex: - update to 2008 version ++++ ralink-firmware: - added supplements tags (bnc#395270) ------------------------------------------------------------------ ------------------ 2008-5-27 - May 27 2008 ------------------- ------------------------------------------------------------------ ++++ xv: - Switch over to jumbo patch 20070520 as this includes not only all of our security patches but also those from debian - Avoid to be fooled on new gcc as the overflow detection with signed integers hadn't worked anymore - Avoid to be fooled on boundary check of new glibc on counting the pointer up and behind the upper boundary ------------------------------------------------------------------ ------------------ 2008-5-23 - May 23 2008 ------------------- ------------------------------------------------------------------ ++++ xv: - Never call X11 functions from within siganl handler (bnc#283914) ------------------------------------------------------------------ ------------------ 2008-5-9 - May 9 2008 ------------------- ------------------------------------------------------------------ ++++ novell-nortelplugins: - fix the scanf sleep when connecting vpn server(bnc#381769). ------------------------------------------------------------------ ------------------ 2008-5-7 - May 7 2008 ------------------- ------------------------------------------------------------------ ++++ ant-antlr: - build using gcj, to allow a openjdk6 bootstrap - change a source and a target level to 1.5 in build.xml ------------------------------------------------------------------ ------------------ 2008-4-30 - Apr 30 2008 ------------------- ------------------------------------------------------------------ ++++ opera: - added hicolor opera icon [bnc#384209] * created by Aakash Soneri (http://www.akkasone.com/) * redistributed with written permission of the author * http://akkasone.deviantart.com/art/Opera-8-Browser-Icon-22991716 - registration file opera.reg no longer needed - refactored spec file ------------------------------------------------------------------ ------------------ 2008-4-28 - Apr 28 2008 ------------------- ------------------------------------------------------------------ ++++ acroread: - bnc#382739: use more robust code in the startscript to find libgtkembedmoz.so. Only use the value found in ~/.adobe/ if it really points to a libgtkembedmoz.so, if not search anew in the system. ++++ java-1_6_0-sun: - update to 1.6.0u6: VUL-0: java 1.6.0 update 6 security update available [bnc#383674] - xcb_xlib.c:50: xcb_xlib_unlock: Assertion 'c->xlib.lock' failed. - HttpClient and HttpsClient should not try to reverse lookup IP address of a proxy server - REGRESSION: setting -Djava.security.debug=failure result in NPE in ACC - (tz) Support tzdata2008a - Incorrect locale specified in the URL embedded in the register[_].html - FontConfiguration exception preventing applets from loading - Java 6 JavaWebstart increases footprint by factor 2 - JWS can't find cache file after network crash - javax.xml.ws.wsaddressing not included in make/docs/CORE_PKGS.gmk - com.sun.crypto.provider.SunJCE instance leak using KRB5 and LoginContext - fix the java 1.6.0_01-b06 getPackage isCompatibleWith Empty version string AMD86 [bnc#331680] ------------------------------------------------------------------ ------------------ 2008-4-26 - Apr 26 2008 ------------------- ------------------------------------------------------------------ ++++ alpine: - fix build ------------------------------------------------------------------ ------------------ 2008-4-25 - Apr 25 2008 ------------------- ------------------------------------------------------------------ ++++ alpine: - Update to alpine-1.10 and update fixes suggested for this version ------------------------------------------------------------------ ------------------ 2008-4-23 - Apr 23 2008 ------------------- ------------------------------------------------------------------ ++++ acroread: - bnc#382777: do not replace the libcurl.so.3.0.0 which comes with the acroread tarball with symbolic links to libcurl.so.4.0.0 in the system, apparently these are *not* compatible. ------------------------------------------------------------------ ------------------ 2008-4-17 - Apr 17 2008 ------------------- ------------------------------------------------------------------ ++++ novell-nortelplugins: - fix the method for getting mtu(bnc#379495) and adding check for reset default route(bnc#379494). ------------------------------------------------------------------ ------------------ 2008-4-10 - Apr 10 2008 ------------------- ------------------------------------------------------------------ ++++ cg: - added baselibs.conf file to build xxbit packages for multilib support ++++ helix-dbus-server: - added baselibs.conf file to build xxbit packages for multilib support ++++ iscan-proprietary-drivers: - Updated to match our current iscan package version 2.10.0.1. There is one new proprietary driver: iscan-plugin-cx4400 ++++ ralink-firmware: - cleaned up specfile ------------------------------------------------------------------ ------------------ 2008-4-9 - Apr 9 2008 ------------------- ------------------------------------------------------------------ ++++ flash-player: - update to 9.0.124.0 (bnc#376639) * CVE-2007-6637 ++++ iscan: - Updated to version 2.10.0-1 (results package version 2.10.0.1): This package still contains /usr/bin/iscan and libesmod. There are many more supported scanners (for details see the NEWS file). ++++ java-1_6_0-sun: - fixed names of java-1.6.0-sun and java-1.6.0-sun-devel provides, fixed directory names (removed update number) ------------------------------------------------------------------ ------------------ 2008-4-4 - Apr 4 2008 ------------------- ------------------------------------------------------------------ ++++ acroread: - bnc#375551: use LD_PRELOAD to prevent acroread from using XGrabServer and XUngrabServer. - bnc#373590: add symlinks to libicu*.so.34 for suse_version < 1030 where libicu* has been deleted from the acroread package. ------------------------------------------------------------------ ------------------ 2008-4-3 - Apr 3 2008 ------------------- ------------------------------------------------------------------ ++++ IPAPGothic: - bnc#374441: add *inofficial* English translation of the license. ++++ opera: - security update to 9.27 [bnc#376714] * Fixed an issue where newsfeed prompts could cause Opera to execute arbitrary code. * Solved an issue where resized canvas patterns could cause Opera to execute arbitrary code. * Improved keyboard handling of password inputs. * Fixed a BitTorrent transfer stability issue. * Resolved stablity issues with the Acid 3 test. * Additional stability fixes. ------------------------------------------------------------------ ------------------ 2008-3-31 - Mar 31 2008 ------------------- ------------------------------------------------------------------ ++++ iwl4965-ucode: - update to version 4.44.1.20 * Improve keep timestramps ++++ jms: - added COPYING file with LGPLv2.1, fixes (bnc#372253) ------------------------------------------------------------------ ------------------ 2008-3-26 - Mar 26 2008 ------------------- ------------------------------------------------------------------ ++++ java-1_5_0-sun: - update to 1.5.0u15: VUL-0: java: multiple vulnerabilities [bnc#368134] - CVE-2008-1158: Unspecified vulnerability in the Virtual Machine for Sun Java Runtime Environment (JRE) and JDK 6 Update 4 and earlier, 5.0 Update 14 and earlier, and SDK/JRE 1.4.2_16 and earlier allows remote attackers should gain privileges via an untrusted application or applet, a different issue than CVE-2008-1186. - CVE-2008-1186: Unspecified vulnerability in the Virtual Machine for Sun Java Runtime Environment (JRE) and JDK 5.0 Update 13 and earlier, and SDK/JRE 1.4.2_16 and earlier, allows remote attackers to gain privileges via an untrusted application or applet, a different issue than CVE-2008-1185. - CVE-2008-1187: Unspecified vulnerability in Sun Java Runtime Environment (JRE) and JDK 6 Update 4 and earlier, 5.0 Update 14 and earlier, and SDK/JRE 1.4.2_16 and earlier allows remote attackers to cause a denial of service (JRE crash) and possibly execute arbitrary code via unknown vectors related to XSLT transforms. - CVE-2008-1188: Multiple buffer overflows in Java Web Start in Sun JDK and JRE 6 Update 4 and earlier, and 5.0 Update 14 and earlier, allow remote attackers to execute arbitrary code via unknown vectors, a different issue than CVE-2008-1189. - CVE-2008-1189: Buffer overflow in Java Web Start in Sun JDK and JRE 6 Update 4 and earlier, 5.0 Update 14 and earlier, and SDK/JRE 1.4.2_16 and earlier allows remote attackers to execute arbitrary code via unknown vectors, a different issue than CVE-2008-1188. - CVE-2008-1190: Unspecified vulnerability in Java Web Start in Sun JDK and JRE 6 Update 4 and earlier, 5.0 Update 14 and earlier, and SDK/JRE 1.4.2_16 and earlier allows remote attackers to gain privileges via an untrusted application, a different issue than CVE-2008-1191. - CVE-2008-1192: Unspecified vulnerability in the Java Plug-in for Sun JDK and JRE 6 Update 4 and earlier, and 5.0 Update 14 and earlier; and SDK and JRE 1.4.2_16 and earlier, and 1.3.1_21 and earlier; allows remote attackers to bypass the same origin policy and "execute local applications" via unknown vectors. - CVE-2008-1193: Unspecified vulnerability in Java Runtime Environment Image Parsing Library in Sun JDK and JRE 6 Update 4 and earlier, and 5.0 Update 14 and earlier, allows remote attackers to gain privileges via an untrusted application. - CVE-2008-1194: Multiple unspecified vulnerabilities in the color management library in Sun JDK and JRE 6 Update 4 and earlier, and 5.0 Update 14 and earlier, allows remote attackers to cause a denial of service (crash) via unknown vectors. - CVE-2008-1195: Unspecified vulnerability in Sun JDK and Java Runtime Environment (JRE) 6 Update 4 and earlier and 5.0 Update 14 and earlier; and SDK and JRE 1.4.2_16 and earlier; allows remote attackers to access arbitrary network services on the local host via unspecified vectors related to JavaScript and Java APIs. - CVE-2008-1196: Stack-based buffer overflow in Java Web Start (javaws.exe) in Sun JDK and JRE 6 Update 4 and earlier and 5.0 Update 14 and earlier; and SDK and JRE 1.4.2_16 and earlier; allows remote attackers to execute arbitrary code via a crafted JNLP file. ++++ java-1_6_0-sun: - update to 1.6.0u5: VUL-0: java: multiple vulnerabilities [bnc#368134] - CVE-2008-1158: Unspecified vulnerability in the Virtual Machine for Sun Java Runtime Environment (JRE) and JDK 6 Update 4 and earlier, 5.0 Update 14 and earlier, and SDK/JRE 1.4.2_16 and earlier allows remote attackers should gain privileges via an untrusted application or applet, a different issue than CVE-2008-1186. - CVE-2008-1187: Unspecified vulnerability in Sun Java Runtime Environment (JRE) and JDK 6 Update 4 and earlier, 5.0 Update 14 and earlier, and SDK/JRE 1.4.2_16 and earlier allows remote attackers to cause a denial of service (JRE crash) and possibly execute arbitrary code via unknown vectors related to XSLT transforms. - CVE-2008-1188: Multiple buffer overflows in Java Web Start in Sun JDK and JRE 6 Update 4 and earlier, and 5.0 Update 14 and earlier, allow remote attackers to execute arbitrary code via unknown vectors, a different issue than CVE-2008-1189. - CVE-2008-1189: Buffer overflow in Java Web Start in Sun JDK and JRE 6 Update 4 and earlier, 5.0 Update 14 and earlier, and SDK/JRE 1.4.2_16 and earlier allows remote attackers to execute arbitrary code via unknown vectors, a different issue than CVE-2008-1188. - CVE-2008-1190: Unspecified vulnerability in Java Web Start in Sun JDK and JRE 6 Update 4 and earlier, 5.0 Update 14 and earlier, and SDK/JRE 1.4.2_16 and earlier allows remote attackers to gain privileges via an untrusted application, a different issue than CVE-2008-1191. - CVE-2008-1191: Unspecified vulnerability in Java Web Start in Sun JDK and JRE 6 Update 4 and earlier allows remote attackers to create arbitrary files via an untrusted application, a different issue than CVE-2008-1190. - CVE-2008-1192: Unspecified vulnerability in the Java Plug-in for Sun JDK and JRE 6 Update 4 and earlier, and 5.0 Update 14 and earlier; and SDK and JRE 1.4.2_16 and earlier, and 1.3.1_21 and earlier; allows remote attackers to bypass the same origin policy and "execute local applications" via unknown vectors. - CVE-2008-1193: Unspecified vulnerability in Java Runtime Environment Image Parsing Library in Sun JDK and JRE 6 Update 4 and earlier, and 5.0 Update 14 and earlier, allows remote attackers to gain privileges via an untrusted application. - CVE-2008-1194: Multiple unspecified vulnerabilities in the color management library in Sun JDK and JRE 6 Update 4 and earlier, and 5.0 Update 14 and earlier, allows remote attackers to cause a denial of service (crash) via unknown vectors. - CVE-2008-1195: Unspecified vulnerability in Sun JDK and Java Runtime Environment (JRE) 6 Update 4 and earlier and 5.0 Update 14 and earlier; and SDK and JRE 1.4.2_16 and earlier; allows remote attackers to access arbitrary network services on the local host via unspecified vectors related to JavaScript and Java APIs. - CVE-2008-1196: Stack-based buffer overflow in Java Web Start (javaws.exe) in Sun JDK and JRE 6 Update 4 and earlier and 5.0 Update 14 and earlier; and SDK and JRE 1.4.2_16 and earlier; allows remote attackers to execute arbitrary code via a crafted JNLP file. ------------------------------------------------------------------ ------------------ 2008-3-17 - Mar 17 2008 ------------------- ------------------------------------------------------------------ ++++ acroread: - bnc#370330 and bnc#353251: add a workaround to the start script /usr/bin/acroread to make input via XIM work when acroread is started in an UTF-8 locale (.UTF-8 is cut off from the locale name then to “fix” the problem). ------------------------------------------------------------------ ------------------ 2008-3-11 - Mar 11 2008 ------------------- ------------------------------------------------------------------ ++++ ipw-firmware: - Remove ipw3945-firmware as ipw3945-kmp is not shipped anymore with 11.0 due to its successor iwl3945 ------------------------------------------------------------------ ------------------ 2008-3-6 - Mar 6 2008 ------------------- ------------------------------------------------------------------ ++++ IPAPGothic: - update to 002.003. From the release notes http://ossipedia.ipa.go.jp/ipafont/releasenote.html: • fixed width flag set to “no” for IPAPGothic (ipagp.ttf), IPAPMincho (ipamp.ttf), and IPAUIGothic (ipagui.ttf). See also bnc359984. In Qt4 the problems have already been fixed by ignoring the “global advance width” when loading the font using freetype2, but in many other applications e.g. Qt3, these fonts were still handled as fixed width. • Glyphs for the following characters have been added: U+2014 EM DASH, U+2016 DOUBLE VERTICAL LINE, U+203E OVERLINE, U+00AC NOT SIGN, U+00A5 YEN SIGN, U+00A2 CENT SIGN, U+00A3 POUND SIGN. ++++ java-1_6_0-sun: - removed Provides and Obsoletes of java-1.5.0-plugin in plugin subpackage: [bnc#365768] ------------------------------------------------------------------ ------------------ 2008-3-5 - Mar 5 2008 ------------------- ------------------------------------------------------------------ ++++ adaptec-firmware: - Update package version to reflect the firmware release (#362527) ------------------------------------------------------------------ ------------------ 2008-2-28 - Feb 28 2008 ------------------- ------------------------------------------------------------------ ++++ java-1_5_0-sun: - changed Requires: %{_libdir}/libodbc.so, %{_libdir}/libodbcinst.so to Requires: unixODBC (bnc#326751) ++++ java-1_6_0-sun: - changed Requires: %{_libdir}/libodbc.so, %{_libdir}/libodbcinst.so to Requires: unixODBC [#326751] ------------------------------------------------------------------ ------------------ 2008-2-21 - Feb 21 2008 ------------------- ------------------------------------------------------------------ ++++ opera: - security update to 9.26 [bnc#363574] * Fixed an issue where simulated text inputs could trick users into uploading arbitrary files. * Image properties can no longer be used to execute scripts. * Fixed an issue where the representation of DOM attribute values could allow cross site scripting. * Fixed a stability issue found in Opera 9.0 to 9.25, when Opera connects securely to Windows Server 2008 or other servers supporting the TLS Certificate Status extension. * Additional stability fixes. ------------------------------------------------------------------ ------------------ 2008-2-20 - Feb 20 2008 ------------------- ------------------------------------------------------------------ ++++ acroread: - bnc#362926: use "mktemp" to create temporary files in a secure way. - detect the correct directory for the 32bit libgtkembedmoz.so on x86_64 systems. - bnc#353251: remove duplicated system libraries (because of security considerations and compatibility problems). ------------------------------------------------------------------ ------------------ 2008-2-17 - Feb 17 2008 ------------------- ------------------------------------------------------------------ ++++ ant-antlr: - fix changelog for build service ------------------------------------------------------------------ ------------------ 2008-2-15 - Feb 15 2008 ------------------- ------------------------------------------------------------------ ++++ opera: - owning directories /usr/share/icons/hicolor/*/* - added missing coreutils PreReq - set Requires: on qt3 only for build with shared libs ------------------------------------------------------------------ ------------------ 2008-2-14 - Feb 14 2008 ------------------- ------------------------------------------------------------------ ++++ acroread: - bnc#358438 comment #31-#33: Workaround to make acroread start when XInputExtension is missing on an X-server (this is missing on VNC X-servers) and the theme package gtk-qt-engine is installed. ------------------------------------------------------------------ ------------------ 2008-2-13 - Feb 13 2008 ------------------- ------------------------------------------------------------------ ++++ jms: - remove NoSource flag, this is free software ++++ novell-nortelplugins: - fix ia64, x86_64 and s390's warning for printf size_t. ------------------------------------------------------------------ ------------------ 2008-2-7 - Feb 7 2008 ------------------- ------------------------------------------------------------------ ++++ acroread: - bnc#275088, commment #134-#139: set ACRO_ENABLE_FONT_CONFIG=1 in the acroread start script. ------------------------------------------------------------------ ------------------ 2008-2-5 - Feb 5 2008 ------------------- ------------------------------------------------------------------ ++++ acroread: - update to final release of 8.1.2. Fixes bnc#358438, bnc#275088, bnc#353927. Official announcement by Adobe is here: http://blogs.adobe.com/acroread/2008/02/adobe_reader_812_for_linux_and.html “Version 8.1.2 contains scores of bug fixes including security vulnerability fixes.” ++++ novell-nortelplugins: - update to 0.1.3. ------------------------------------------------------------------ ------------------ 2008-1-28 - Jan 28 2008 ------------------- ------------------------------------------------------------------ ++++ gst-fluendo-mp3: - added gstreamer-utils to BuildRequres. gst-inspect moved there. ------------------------------------------------------------------ ------------------ 2008-1-24 - Jan 24 2008 ------------------- ------------------------------------------------------------------ ++++ ralink-firmware: - initial package (version 1.0) including o RT61_Firmware_V1.2 o RT71W_Firmware_V1.8 ------------------------------------------------------------------ ------------------ 2008-1-23 - Jan 23 2008 ------------------- ------------------------------------------------------------------ ++++ IPAPGothic: - remove dependency on grass. ++++ java-1_6_0-sun: - New update - 1.6.0u4 - The better alternatives script - Updated the timezone info to 2007k - avoid the building of a src subpackage in BuildService (licencing problems) - added %{bits} to requires of subpackage [#354123] ------------------------------------------------------------------ ------------------ 2008-1-22 - Jan 22 2008 ------------------- ------------------------------------------------------------------ ++++ java-1_5_0-sun: - New update - 1.5.0_update14 - The better alternatives script - Updated the timezone info to 2007k ------------------------------------------------------------------ ------------------ 2008-1-16 - Jan 16 2008 ------------------- ------------------------------------------------------------------ ++++ netbeans: - update to version 6.0 ------------------------------------------------------------------ ------------------ 2008-1-11 - Jan 11 2008 ------------------- ------------------------------------------------------------------ ++++ acroread: - use fdupes only for openSUSE >= 10.3. - update to 8.1.2 (fixes bugzilla #275088). ++++ alpine: - Update to alpine-1.00 and apply fixes suggested for this version ------------------------------------------------------------------ ------------------ 2008-1-9 - Jan 9 2008 ------------------- ------------------------------------------------------------------ ++++ IPAPGothic: - update to 002.001 * now supports JIS X 0213:2004 (needed for bug #343820) * new, better license - remove dependency on grass. ------------------------------------------------------------------ ------------------ 2008-1-2 - Jan 2 2008 ------------------- ------------------------------------------------------------------ ++++ opera: - applying oneclick patch also on ppc arch - security update to 9.25 [#350579] CVE-2007-6520, CVE-2007-6521, CVE-2007-6522, CVE-2007-6523, CVE-2007-6524 * Fixed an issue where plug-ins could be used to allow cross domain scripting. * Fixed an issue with TLS certificates that could be used to execute arbitrary code. * Rich text editing can no longer be used to allow cross domain scripting. * Fixed a problem where malformed BMP files could cause Opera to temporarily freeze. * Prevented bitmaps from revealing random data from memory. ------------------------------------------------------------------ ------------------ 2007-12-20 - Dec 20 2007 ------------------- ------------------------------------------------------------------ ++++ java-1_6_0-sun: - added 32-bit and 64-bit specific provides (jre-32, jre-64) ------------------------------------------------------------------ ------------------ 2007-12-12 - Dec 12 2007 ------------------- ------------------------------------------------------------------ ++++ cg: - #331539: Add Obsoletes/Provides for Cg (compatibility to Packman packages) ------------------------------------------------------------------ ------------------ 2007-12-4 - Dec 4 2007 ------------------- ------------------------------------------------------------------ ++++ flash-player: - update to 9.0.115.0 (#310213) ------------------------------------------------------------------ ------------------ 2007-11-28 - Nov 28 2007 ------------------- ------------------------------------------------------------------ ++++ netbeans: - updated to version 5.5.1 - build from source - added netbeans-build.patch ------------------------------------------------------------------ ------------------ 2007-11-27 - Nov 27 2007 ------------------- ------------------------------------------------------------------ ++++ adaptec-firmware: - Update firmware to v32 (FATE 302809,#341872) ------------------------------------------------------------------ ------------------ 2007-11-20 - Nov 20 2007 ------------------- ------------------------------------------------------------------ ++++ acroread: - apply patch to start script again to use XIM and to add the most important directories to PSRESOURCEPATH. - use fdupes only in %INSTALL_DIR (/usr/lib) to avoid hardlinks to /usr/share which might be on a different partition. ------------------------------------------------------------------ ------------------ 2007-11-9 - Nov 9 2007 ------------------- ------------------------------------------------------------------ ++++ java-1_5_0-sun: - Fixed a perin script, beta build fail ------------------------------------------------------------------ ------------------ 2007-11-6 - Nov 6 2007 ------------------- ------------------------------------------------------------------ ++++ java-1_5_0-sun: - Fixed a manual status of symlinks in /etc/alternatives [#334783] ++++ java-1_6_0-sun: - Fixed a manual state in /etc/alternatives after update [#334783] ------------------------------------------------------------------ ------------------ 2007-10-22 - Oct 22 2007 ------------------- ------------------------------------------------------------------ ++++ java-1_5_0-sun: - Fixed bug [#334783] bad symlinks in /etc/alternatives after update - Fixed bug [#334783] bad symlinks in /etc/alternatives after update ++++ java-1_6_0-sun: - Fixed bug [#334783] bad symlinks in /etc/alternatives after update ++++ opera: - security update to 9.24 CVE-2007-5540, CVE-2007-5541 [#334832] * Fixed an issue where external news readers and e-mail clients could be used to execute arbitrary code * Fixed an issue where scripts could overwrite functions on pages from other domains. - updated language files to meet the version [#331913] ------------------------------------------------------------------ ------------------ 2007-10-18 - Oct 18 2007 ------------------- ------------------------------------------------------------------ ++++ opera: - don't build on x86_64, let's use the x86 version until we get something native ------------------------------------------------------------------ ------------------ 2007-10-17 - Oct 17 2007 ------------------- ------------------------------------------------------------------ ++++ ivtv: - update to 1.0.3, the main driver is now upstream and built in the kernel source - here are the ivtvfb and saa717x drivers ------------------------------------------------------------------ ------------------ 2007-10-16 - Oct 16 2007 ------------------- ------------------------------------------------------------------ ++++ acroread: - add "Requires: libgtkembedmoz.so". ++++ iscan: - Changed fixes-for-GCC43.patch as suggested by Olaf Meeuwissen so that it also works for GCC before 4.3. With the previous fixes-for-GCC43.patch GCC before 4.3 showed: "pisa_tool.h:59: multiple definition of 'double similarity..." and for GCC 4.3 the error was "pisa_tool.h:69: error: explicit template specialization cannot have a storage class". ------------------------------------------------------------------ ------------------ 2007-10-11 - Oct 11 2007 ------------------- ------------------------------------------------------------------ ++++ iscan: - fixes-for-GCC43.patch applies fixes for GCC 4.3, see http://en.opensuse.org/GCC_4.3_Transition ------------------------------------------------------------------ ------------------ 2007-10-10 - Oct 10 2007 ------------------- ------------------------------------------------------------------ ++++ java-1_5_0-sun: - update to 1.5.0_update13 [#332137] - Fixed vulnerabilities: CVE-2007-5232, CVE-2007-5236, CVE-2007-523, CVE-2007-523, CVE-2007-5240 ++++ java-1_6_0-sun: - update to 1.6.0_update3 [#332137] - Fixed vulnerabilities: CVE-2007-5232, CVE-2007-5236, CVE-2007-523, CVE-2007-523, CVE-2007-5240 ------------------------------------------------------------------ ------------------ 2007-10-9 - Oct 9 2007 ------------------- ------------------------------------------------------------------ ++++ gst-fluendo-mp3: - conflicts gst-fluendo-plugins, [Bug 331780] ------------------------------------------------------------------ ------------------ 2007-10-8 - Oct 8 2007 ------------------- ------------------------------------------------------------------ ++++ acroread: - update to 8.1.1. - fix automatic provides and requires. - use fdupes. ------------------------------------------------------------------ ------------------ 2007-9-26 - Sep 26 2007 ------------------- ------------------------------------------------------------------ ++++ unace: - fix build on ppc ------------------------------------------------------------------ ------------------ 2007-9-25 - Sep 25 2007 ------------------- ------------------------------------------------------------------ ++++ alpine: - Use only select patches from Eduardo (fixes crash in mail reader) ------------------------------------------------------------------ ------------------ 2007-9-22 - Sep 22 2007 ------------------- ------------------------------------------------------------------ ++++ moneyplex: - update to 2007 version ------------------------------------------------------------------ ------------------ 2007-9-19 - Sep 19 2007 ------------------- ------------------------------------------------------------------ ++++ alpine: - Remove files with unclear license from packaged sources (#308533) - Add small bug fix: Postponed messages which were labelled as UTF-8 - Spec file cleanup: Comments improved, obsoleted some warning flags ------------------------------------------------------------------ ------------------ 2007-9-4 - Sep 4 2007 ------------------- ------------------------------------------------------------------ ++++ alpine: - Update to final prerelease 0.9999 with updates from Eduardo Chappa ------------------------------------------------------------------ ------------------ 2007-9-3 - Sep 3 2007 ------------------- ------------------------------------------------------------------ ++++ gst-fluendo-mp3: - initial checkin of free binaries for i386, x68_64, ppc, version 2. Sources tarred from svn. ------------------------------------------------------------------ ------------------ 2007-8-31 - Aug 31 2007 ------------------- ------------------------------------------------------------------ ++++ acroread: - Bugzilla #275088: add important font directories to the default PSRESOURCEPATH. ++++ antivir: - updated to antivir-server-prof-2.1.10-15 released on 06.03.2007 - new eval license key for openSUSE-10.3 provided by Avira (valid up to 31 January 2008), updated README files. ++++ opera: - fix #300536 add one-click installation associations to opera ------------------------------------------------------------------ ------------------ 2007-8-23 - Aug 23 2007 ------------------- ------------------------------------------------------------------ ++++ iwl3945-ucode: - fixed Supplements tag ++++ iwl4965-ucode: - fixed Supplements tags ------------------------------------------------------------------ ------------------ 2007-8-16 - Aug 16 2007 ------------------- ------------------------------------------------------------------ ++++ opera: - update to 9.23 (#300605 - VUL-0: opera: a specially crafted JavaScript can make Opera execute arbitrary code) - #300536 - add one-click installation associations to opera ++++ sesam_srv: - fix macro usage for insserv_cleanup ------------------------------------------------------------------ ------------------ 2007-8-10 - Aug 10 2007 ------------------- ------------------------------------------------------------------ ++++ RealPlayer: - Updated to version 10.0.9 (#287791). Fixes: * SMIL wallclock Stack Overflow Vulnerability (CVE-2007-3410) * few more issues ++++ photocd: - BuildRequires libnetpbm-devel to fix the build. ------------------------------------------------------------------ ------------------ 2007-8-9 - Aug 9 2007 ------------------- ------------------------------------------------------------------ ++++ alpine: - add a number of critcally needed fixes for some crashes (and more) ------------------------------------------------------------------ ------------------ 2007-8-8 - Aug 8 2007 ------------------- ------------------------------------------------------------------ ++++ AdobeICCProfiles: - Repackaged using new official source (no change in files). ------------------------------------------------------------------ ------------------ 2007-8-2 - Aug 2 2007 ------------------- ------------------------------------------------------------------ ++++ RealPlayer: - fix typo causing #292327 - RealPlayer shown thrice in application menu ++++ iscan: - Updated to version 2.8.0-1 (results package version 2.8.0.1): This package still contains /usr/bin/iscan and libesmod. There are several more supported scanners. ++++ iscan-firmware: - Updated to match our current iscan package version 2.8.0.1 and our current iscan-proprietary-drivers package version 2.8.0.1 There is one new firmware file: esfw7A.bin ++++ iscan-proprietary-drivers: - Updated to match our current iscan package version 2.8.0.1. There is one new proprietary driver: iscan-plugin-gt-f670 ++++ alpine: - initial version 0.999 + assorted feature patches and some fixes ------------------------------------------------------------------ ------------------ 2007-8-1 - Aug 1 2007 ------------------- ------------------------------------------------------------------ ++++ iwl3945-ucode: - update to version 2.14.1.5 ++++ iwl4965-ucode: - update to version 4.44.1.18 ------------------------------------------------------------------ ------------------ 2007-7-23 - Jul 23 2007 ------------------- ------------------------------------------------------------------ ++++ iwl3945-ucode: - update to version 2.14.4 - fixed postinstall script (this time for real) ++++ iwl4965-ucode: - updated to version 4.44.17 - fixed postinstall script (this time for real) ++++ opera: - update to 9.22 (#293101 VUL-0: opera 9.22 fixes double free bug) Crafted torrent files can execute arbitrary code; CVE-2007-2809 ------------------------------------------------------------------ ------------------ 2007-7-19 - Jul 19 2007 ------------------- ------------------------------------------------------------------ ++++ java-1_5_0-sun: - fix suse_update_desktop_file call ++++ java-1_6_0-sun: - fix suse_update_desktop_file call ------------------------------------------------------------------ ------------------ 2007-7-13 - Jul 13 2007 ------------------- ------------------------------------------------------------------ ++++ sesam_srv: - adapt the spec file for openSUSE 10.3 ------------------------------------------------------------------ ------------------ 2007-7-11 - Jul 11 2007 ------------------- ------------------------------------------------------------------ ++++ flash-player: - update to 9.0.48.0 (#257905, CVE-2007-3456, CVE-2007-3457, CVE-2007-2022) ++++ iscan: - Updated to version 2.7.0-1 (results package version 2.7.0.1): This package still contains /usr/bin/iscan and libesmod. There are several more supported scanners. ------------------------------------------------------------------ ------------------ 2007-7-10 - Jul 10 2007 ------------------- ------------------------------------------------------------------ ++++ opera: - fix #289701 – old opera icons ------------------------------------------------------------------ ------------------ 2007-7-8 - Jul 8 2007 ------------------- ------------------------------------------------------------------ ++++ ant-antlr: - add links to jar files in /usr/share/ant/lib ------------------------------------------------------------------ ------------------ 2007-7-6 - Jul 6 2007 ------------------- ------------------------------------------------------------------ ++++ ant-antlr: - make packages noarch, as jai was removed - update to version 1.7.0 major changes are (for a complete list, consult /usr/share/doc/packages/ant/WHATSNEW): Changes that could break older environments: ------------------------------------------- * Initial support for JDK 6 (JSR 223) scripting. <*script*> tasks will now use javax.scripting if BSF is not available, or if explicitly requested by using a "manager" attribute. * The -noproxy option which was in the previous 1.7 alpha and beta releases has been removed. It is the default behavior and not needed. * Removed launcher classes from nodeps jar. * filter reader uses ISO-8859-1 encoding to read the java class file. Bugzilla report 33604. * Defer reference process. Bugzilla 36955, 34458, 37688. This may break build files in which a reference was set in a target which was never executed. Historically, Ant would set the reference early on, during parse time, so the datatype would be defined. Now it requires the reference to have been in a bit of the build file which was actually executed. If you get an error about an undefined reference, locate the reference and move it somewhere where it is used, or fix the depends attribute of the target in question to depend on the target which defines the reference/datatype. *