summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorMike Doty <kingtaco@gentoo.org>2005-01-11 15:34:23 +0000
committerMike Doty <kingtaco@gentoo.org>2005-01-11 15:34:23 +0000
commit786945cbb87c92e71146e53ccd7ef9270344d28f (patch)
treeddea76eb550b0d0d2ae926f58ec05d50c3f28ad5 /net-misc/hylafax
parentadded wolk fix (diff)
downloadhistorical-786945cbb87c92e71146e53ccd7ef9270344d28f.tar.gz
historical-786945cbb87c92e71146e53ccd7ef9270344d28f.tar.bz2
historical-786945cbb87c92e71146e53ccd7ef9270344d28f.zip
bump to -r2 per security bug 75941
Diffstat (limited to 'net-misc/hylafax')
-rw-r--r--net-misc/hylafax/ChangeLog8
-rw-r--r--net-misc/hylafax/Manifest27
-rw-r--r--net-misc/hylafax/files/digest-hylafax-4.2.0-r21
-rw-r--r--net-misc/hylafax/files/hylafax-hostvuln.patch55
-rw-r--r--net-misc/hylafax/hylafax-4.1.8-r4.ebuild4
-rw-r--r--net-misc/hylafax/hylafax-4.2.0-r1.ebuild4
-rw-r--r--net-misc/hylafax/hylafax-4.2.0-r2.ebuild119
7 files changed, 206 insertions, 12 deletions
diff --git a/net-misc/hylafax/ChangeLog b/net-misc/hylafax/ChangeLog
index 0b39b3fd7cc0..913034f1e4c9 100644
--- a/net-misc/hylafax/ChangeLog
+++ b/net-misc/hylafax/ChangeLog
@@ -1,6 +1,12 @@
# ChangeLog for net-misc/hylafax
# Copyright 2002-2005 Gentoo Foundation; Distributed under the GPL v2
-# $Header: /var/cvsroot/gentoo-x86/net-misc/hylafax/ChangeLog,v 1.46 2005/01/06 20:41:01 gmsoft Exp $
+# $Header: /var/cvsroot/gentoo-x86/net-misc/hylafax/ChangeLog,v 1.47 2005/01/11 15:34:23 kingtaco Exp $
+
+*hylafax-4.2.0-r2 (11 Jan 2005)
+
+ 11 Jan 2005; Mike Doty <kingtaco@gentoo.org> +files/hylafax-hostvuln.patch,
+ +hylafax-4.2.0-r2.ebuild:
+ bump to -r2 per security bug 75941
06 Jan 2005; Guy Martin <gmsoft@gentoo.org> +files/hylafax-4.2.0-fPIC.patch,
hylafax-4.2.0-r1.ebuild:
diff --git a/net-misc/hylafax/Manifest b/net-misc/hylafax/Manifest
index b25efc35ce05..ffb5163b0f74 100644
--- a/net-misc/hylafax/Manifest
+++ b/net-misc/hylafax/Manifest
@@ -1,16 +1,29 @@
-MD5 2ef49611e5e4d075c29330483addee2c ChangeLog 9282
-MD5 026e3afcec6bb6a5e7659439650651ac hylafax-4.2.0-r1.ebuild 3353
-MD5 93b89855f1349b94b334cbe94ceafd0f hylafax-4.1.8-r4.ebuild 3187
+-----BEGIN PGP SIGNED MESSAGE-----
+Hash: SHA1
+
+MD5 d83f32c1c30e2a8804a0f5524ed411d2 hylafax-4.1.8-r4.ebuild 3189
+MD5 5f241443de8ec4140795d14470026faa hylafax-4.2.0-r1.ebuild 3355
MD5 d82acf1bcf0f7f9e181d6a2821292f2e metadata.xml 435
+MD5 0df327db19a01eb5f2dae907a5d24aac hylafax-4.2.0-r2.ebuild 3351
+MD5 d362969b00ccd5aa969ab61d1b85a1b8 ChangeLog 9461
MD5 46bbae3c77d5651a20e606eb6228c159 files/99hylafax 62
MD5 fa83948864d83f34f54ce35f26b38ed6 files/99hylafax-4.2 75
-MD5 61b6d16148a84723c2996b519a57d498 files/digest-hylafax-4.2.0-r1 66
-MD5 6fd09a3cd0a1657591fc6c5c076cd462 files/hylafax-4.2.0-tiff_version.patch 1011
-MD5 c4edcc178e6eeca8ec4680be0790e6da files/hylafax-4.2.0-fPIC.patch 1627
+MD5 eab749cee07de1984c9756e6eb886df0 files/configure-gcc-3.4.patch 696
MD5 5243f5e3321151d074643f652133fdfd files/digest-hylafax-4.1.8-r4 66
+MD5 61b6d16148a84723c2996b519a57d498 files/digest-hylafax-4.2.0-r1 66
MD5 bc084d075b601d42fbd417b97a45f1b2 files/hylafax 3757
MD5 5f2f2e3fe04414f953d4010d32261318 files/hylafax-4.1.8-fPIC.patch 2086
MD5 ad3b0e7082e6e71ee6ba940ce1b6b071 files/hylafax-4.1.8-gcc-version.patch 520
MD5 491e78765b433d7c11146120cf7e40f8 files/hylafax-4.2 3759
+MD5 363ea0f56887928eb876bbe25223de85 files/hylafax-hostvuln.patch 2098
MD5 cfcafeadd916b8a9103b9b9110887916 files/hylafax-4.2.0-faxcron_uid.patch 527
-MD5 eab749cee07de1984c9756e6eb886df0 files/configure-gcc-3.4.patch 696
+MD5 6fd09a3cd0a1657591fc6c5c076cd462 files/hylafax-4.2.0-tiff_version.patch 1011
+MD5 61b6d16148a84723c2996b519a57d498 files/digest-hylafax-4.2.0-r2 66
+MD5 c4edcc178e6eeca8ec4680be0790e6da files/hylafax-4.2.0-fPIC.patch 1627
+-----BEGIN PGP SIGNATURE-----
+Version: GnuPG v1.2.6 (GNU/Linux)
+
+iD8DBQFB4/IJ0K3RJaeXx6cRAoPcAJwN+gSqVK3kIn7iRGfDZ9vxNaFcNgCgzZz8
+5aBkZqn2MhEB/nAKijQhMWE=
+=oGKi
+-----END PGP SIGNATURE-----
diff --git a/net-misc/hylafax/files/digest-hylafax-4.2.0-r2 b/net-misc/hylafax/files/digest-hylafax-4.2.0-r2
new file mode 100644
index 000000000000..9de57e0107eb
--- /dev/null
+++ b/net-misc/hylafax/files/digest-hylafax-4.2.0-r2
@@ -0,0 +1 @@
+MD5 463726ed21cfdac730c5d6915e0840cf hylafax-4.2.0.tar.gz 1351870
diff --git a/net-misc/hylafax/files/hylafax-hostvuln.patch b/net-misc/hylafax/files/hylafax-hostvuln.patch
new file mode 100644
index 000000000000..dd60220e1df1
--- /dev/null
+++ b/net-misc/hylafax/files/hylafax-hostvuln.patch
@@ -0,0 +1,55 @@
+diff -Nru hylafax-4.2.0.orig/hfaxd/InetFaxServer.c++ hylafax-4.2.0/hfaxd/InetFaxServer.c++
+--- hylafax-4.2.0.orig/hfaxd/InetFaxServer.c++ Mon Dec 27 14:10:09 2004
++++ hylafax-4.2.0/hfaxd/InetFaxServer.c++ Tue Dec 28 10:49:52 2004
+@@ -177,16 +177,14 @@
+ /*
+ * Check host identity returned by gethostbyaddr to
+ * weed out clients trying to spoof us (this is mostly
+- * a sanity check; it's still trivial to spoof).
+- * If the name returned by gethostbyaddr is in our domain,
+- * look up the name and check that the peer's address
++ * a sanity check; if they have full control of DNS
++ * they can still spoof)
++ * Look up the name and check that the peer's address
+ * corresponds to the host name.
+ */
+ bool
+ InetFaxServer::checkHostIdentity(hostent*& hp)
+ {
+- if (!isLocalDomain(hp->h_name)) // not local, don't check
+- return (true);
+ fxStr name(hp->h_name); // must copy static value
+ hp = Socket::gethostbyname(name);
+ if (hp) {
+diff -Nru hylafax-4.2.0.orig/hfaxd/User.c++ hylafax-4.2.0/hfaxd/User.c++
+--- hylafax-4.2.0.orig/hfaxd/User.c++ Mon Dec 27 14:10:21 2004
++++ hylafax-4.2.0/hfaxd/User.c++ Tue Dec 28 11:00:32 2004
+@@ -136,16 +136,26 @@
+ * must supply. The next field is the password that
+ * must be presented to gain administrative privileges.
+ *
++ * If the regex is a single word (no @ sign), we take it
++ * as a host only short form for (^[^@]*@<input>
++ *
+ * If the first character of the <regex> is a ``!''
+ * then the line specifies user(s) to disallow; a match
+ * causes the user to be rejected w/o a password prompt.
+ * This facility is mainly for backwards compatibility.
+ */
+ char* cp;
++ bool userandhost = false;
+ for (cp = line; *cp && *cp != ':'; cp++)
+- ;
++ if (*cp == '@') userandhost = true;
++
+ const char* base = &line[line[0] == '!'];
+- RE pat(base, cp-base);
++ fxStr pattern(base, cp-base);
++ if (! userandhost) {
++ pattern.insert("^.*@");
++ pattern.append("$");
++ }
++ RE pat(pattern);
+ if (line[0] == '!') { // disallow access on match
+ if (pat.Find(dotform) || pat.Find(hostform))
+ return (false);
diff --git a/net-misc/hylafax/hylafax-4.1.8-r4.ebuild b/net-misc/hylafax/hylafax-4.1.8-r4.ebuild
index 31241b941044..087feb278c36 100644
--- a/net-misc/hylafax/hylafax-4.1.8-r4.ebuild
+++ b/net-misc/hylafax/hylafax-4.1.8-r4.ebuild
@@ -1,6 +1,6 @@
-# Copyright 1999-2004 Gentoo Foundation
+# Copyright 1999-2005 Gentoo Foundation
# Distributed under the terms of the GNU General Public License v2
-# $Header: /var/cvsroot/gentoo-x86/net-misc/hylafax/hylafax-4.1.8-r4.ebuild,v 1.5 2004/10/13 16:20:24 gmsoft Exp $
+# $Header: /var/cvsroot/gentoo-x86/net-misc/hylafax/hylafax-4.1.8-r4.ebuild,v 1.6 2005/01/11 15:34:23 kingtaco Exp $
# This was originally contributed by Stephane Loeuillet, via
# Gentoo bug: http://bugs.gentoo.org/show_bug.cgi?id=28574
diff --git a/net-misc/hylafax/hylafax-4.2.0-r1.ebuild b/net-misc/hylafax/hylafax-4.2.0-r1.ebuild
index 431b6eb67b36..0cae3d474dd9 100644
--- a/net-misc/hylafax/hylafax-4.2.0-r1.ebuild
+++ b/net-misc/hylafax/hylafax-4.2.0-r1.ebuild
@@ -1,6 +1,6 @@
-# Copyright 1999-2004 Gentoo Foundation
+# Copyright 1999-2005 Gentoo Foundation
# Distributed under the terms of the GNU General Public License v2
-# $Header: /var/cvsroot/gentoo-x86/net-misc/hylafax/hylafax-4.2.0-r1.ebuild,v 1.5 2005/01/06 20:41:01 gmsoft Exp $
+# $Header: /var/cvsroot/gentoo-x86/net-misc/hylafax/hylafax-4.2.0-r1.ebuild,v 1.6 2005/01/11 15:34:23 kingtaco Exp $
inherit eutils
diff --git a/net-misc/hylafax/hylafax-4.2.0-r2.ebuild b/net-misc/hylafax/hylafax-4.2.0-r2.ebuild
new file mode 100644
index 000000000000..960f7ba65a1d
--- /dev/null
+++ b/net-misc/hylafax/hylafax-4.2.0-r2.ebuild
@@ -0,0 +1,119 @@
+# Copyright 1999-2005 Gentoo Foundation
+# Distributed under the terms of the GNU General Public License v2
+# $Header: /var/cvsroot/gentoo-x86/net-misc/hylafax/hylafax-4.2.0-r2.ebuild,v 1.1 2005/01/11 15:34:23 kingtaco Exp $
+
+inherit eutils
+
+IUSE="faxonly jpeg pam"
+
+DESCRIPTION="Client-server fax package for class 1 and 2 fax modems."
+HOMEPAGE="http://www.hylafax.org"
+SRC_URI="ftp://ftp.hylafax.org/source/${P}.tar.gz"
+
+SLOT="0"
+LICENSE="hylafax"
+KEYWORDS="x86 sparc hppa ~alpha amd64 ~ppc"
+
+DEPEND="!faxonly? ( net-dialup/mgetty )
+ >=sys-libs/zlib-1.1.4
+ virtual/ghostscript
+ >=media-libs/tiff-3.7.0
+ jpeg? ( media-libs/jpeg )
+ sys-apps/gawk
+ pam? ( sys-libs/pam )"
+
+RDEPEND="${DEPEND}
+ app-arch/sharutils"
+
+export CONFIG_PROTECT="${CONFIG_PROTECT} /var/spool/fax/etc"
+
+src_unpack() {
+ unpack ${A}
+ cd ${S}
+ epatch ${FILESDIR}/${P}-faxcron_uid.patch
+ epatch ${FILESDIR}/${P}-tiff_version.patch
+ epatch ${FILESDIR}/configure-gcc-3.4.patch
+ epatch ${FILESDIR}/hylafax-hostvuln.patch
+}
+
+src_compile() {
+ local my_conf="
+ --with-DIR_BIN=/usr/bin
+ --with-DIR_SBIN=/usr/sbin
+ --with-DIR_LIB=/usr/lib
+ --with-DIR_LIBEXEC=/usr/sbin
+ --with-DIR_LIBDATA=/usr/lib/fax
+ --with-DIR_LOCKS=/var/lock
+ --with-DIR_MAN=/usr/share/man
+ --with-DIR_SPOOL=/var/spool/fax
+ --with-DIR_HTML=/usr/share/doc/${P}/html
+ --with-DIR_CGI=${WORKDIR}
+ --with-PATH_EGETTY=/bin/false
+ --with-HTML=yes
+ --with-PATH_DPSRIP=/var/spool/fax/bin/ps2fax
+ --with-PATH_IMPRIP=\"\"
+ --with-SYSVINIT=no
+ --with-LIBTIFF=\"-ltiff -ljpeg -lz\"
+ --with-OPTIMIZER=\"${CFLAGS}\"
+ --with-DSO=auto"
+
+ if [ -h /etc/localtime ]; then
+ local continent=$(readlink /etc/localtime | cut -d / -f 5)
+ if [ "${continent}" == "Europe" ]; then
+ my_conf="${my_conf} --with-PAGESIZE=A4"
+ fi
+ fi
+
+ use faxonly && my_conf="${my_conf} --with-PATH_GETTY=/bin/false
+ --with-PATH_VGETTY=/bin/false"
+ #--enable-pam isn't valid
+ use pam || my_conf="${my_conf} $(use_enable pam)"
+
+ # eval required for quoting in ${my_conf} to work properly, better way?
+ eval ./configure --nointeractive ${my_conf} || die "./configure failed"
+
+ emake -j1 || die "emake failed"
+}
+
+src_install() {
+ dodir /usr/{bin,sbin} /usr/lib/fax /usr/share/man /var/spool /var/spool/recvq
+ dodir /usr/share/doc/${P}/html
+
+ make \
+ BIN=${D}/usr/bin \
+ SBIN=${D}/usr/sbin \
+ LIBDIR=${D}/usr/lib \
+ LIB=${D}/usr/lib \
+ LIBEXEC=${D}/usr/sbin \
+ LIBDATA=${D}/usr/lib/fax \
+ MAN=${D}/usr/share/man \
+ SPOOL=${D}/var/spool/fax \
+ HTMLDIR=${D}/usr/share/doc/${P}/html \
+ install || die "make install failed"
+
+ keepdir /var/spool/fax/{archive,client,etc,pollq,recvq,tmp}
+ keepdir /var/spool/fax/{status,sendq,log,info,doneq,docq,dev}
+
+ einfo "Adding env.d entry for Hylafax"
+ insinto /etc/env.d
+ newins ${FILESDIR}/99hylafax-4.2 99hylafax
+
+ einfo "Adding init.d entry for Hylafax"
+ insinto /etc/init.d
+ insopts -m 755
+ newins ${FILESDIR}/hylafax-4.2 hylafax
+
+ dodoc COPYRIGHT README TODO VERSION
+}
+
+pkg_postinst() {
+ ewarn "New Hylafax tiff support requires tiff-3.7.0 now,"
+ ewarn "but hopefully this libtiff silliness is now fixed."
+ echo
+ einfo "Hylafax now depends on sharutils instead of metamail for mime"
+ einfo "handling, however, you can continue to use the latter if you"
+ einfo "like (emerge metamail manually)."
+ echo
+ einfo "Now run faxsetup and (if necessary) faxaddmodem."
+ echo
+}