- update ejabberd to 2.0.4

* includes a SECURITY FIX to CVE-2009-0934 (MUC Logs Script Insertion Vulnerability)

from Wiktor Izdebski (MAINTAINER)
This commit is contained in:
jasper 2009-03-19 18:26:45 +00:00
parent c091aa425e
commit 330e6c7760
4 changed files with 9 additions and 21 deletions

View File

@ -1,10 +1,9 @@
# $OpenBSD: Makefile,v 1.12 2009/03/06 09:19:13 jasper Exp $
# $OpenBSD: Makefile,v 1.13 2009/03/19 18:26:45 jasper Exp $
COMMENT= jabber server written in Erlang
V= 2.0.3
V= 2.0.4
DISTNAME= ejabberd-$V
PKGNAME= ${DISTNAME}p0
CATEGORIES= net

View File

@ -1,5 +1,5 @@
MD5 (ejabberd-2.0.3.tar.gz) = tkfnSw+U8DC9h0fIqKTQ+Q==
RMD160 (ejabberd-2.0.3.tar.gz) = 5fd3FannTf7VudvdF60iVdQPPRM=
SHA1 (ejabberd-2.0.3.tar.gz) = 7jpQO+/qeTeMTI985b5hUSCb9HQ=
SHA256 (ejabberd-2.0.3.tar.gz) = 00vPbHPo0/1b87JVWz248L2Bl6YwO22xffiUWizTOf8=
SIZE (ejabberd-2.0.3.tar.gz) = 1089870
MD5 (ejabberd-2.0.4.tar.gz) = H/N8Mp6bwd3zxFjgUbgdYw==
RMD160 (ejabberd-2.0.4.tar.gz) = BbjR/UJyQzWvWIv2+noU5WBb9uM=
SHA1 (ejabberd-2.0.4.tar.gz) = FlFsf5cj4cp4GXDVSvv1gKcsnus=
SHA256 (ejabberd-2.0.4.tar.gz) = bdvRUBvSgkZzUi4qPBGRlazBd84ZiAChFvkNWw49IXI=
SIZE (ejabberd-2.0.4.tar.gz) = 1827181

View File

@ -1,12 +0,0 @@
$OpenBSD: patch-src_tls_tls_drv_c,v 1.1 2009/03/06 09:19:13 jasper Exp $
--- src/tls/tls_drv.c.orig Thu Feb 26 11:37:16 2009
+++ src/tls/tls_drv.c Thu Feb 26 11:38:17 2009
@@ -367,7 +367,7 @@ static int tls_drv_control(ErlDrvData handle,
if (command == SET_CERTIFICATE_FILE_ACCEPT)
SSL_set_accept_state(d->ssl);
else {
- SSL_set_options(d->ssl, SSL_OP_NO_SSLv2);
+ SSL_set_options(d->ssl, SSL_OP_NO_SSLv2|SSL_OP_NO_TICKET);
SSL_set_connect_state(d->ssl);
}
break;

View File

@ -1,4 +1,4 @@
@comment $OpenBSD: PLIST,v 1.4 2009/02/12 09:58:11 sthen Exp $
@comment $OpenBSD: PLIST,v 1.5 2009/03/19 18:26:46 jasper Exp $
@newgroup _ejabberd:594
@newuser _ejabberd:594:_ejabberd:daemon:ejabberd account:/var/db/ejabberd:/bin/sh
%%SHARED%%
@ -131,6 +131,7 @@ lib/ejabberd/ebin/stringprep_sup.beam
lib/ejabberd/ebin/tls.beam
lib/ejabberd/ebin/translate.beam
lib/ejabberd/ebin/treap.beam
@comment lib/ejabberd/ebin/win32_dns.beam
lib/ejabberd/ebin/xml.beam
lib/ejabberd/ebin/xml_stream.beam
lib/ejabberd/priv/