From mboxrd@z Thu Jan 1 00:00:00 1970 From: rmccabe@sourceware.org Date: 27 Mar 2007 02:20:05 -0000 Subject: [Cluster-devel] conga conga.spec.in.in Message-ID: <20070327022005.20847.qmail@sourceware.org> List-Id: To: cluster-devel.redhat.com MIME-Version: 1.0 Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: 7bit CVSROOT: /cvs/cluster Module name: conga Branch: RHEL5 Changes by: rmccabe at sourceware.org 2007-03-27 03:20:03 Modified files: . : conga.spec.in.in Log message: - Update changelog Patches: http://sourceware.org/cgi-bin/cvsweb.cgi/conga/conga.spec.in.in.diff?cvsroot=cluster&only_with_tag=RHEL5&r1=1.45.2.27&r2=1.45.2.28 --- conga/conga.spec.in.in 2007/03/27 02:11:03 1.45.2.27 +++ conga/conga.spec.in.in 2007/03/27 02:20:03 1.45.2.28 @@ -285,7 +285,8 @@ %changelog * Tue Mar 20 2007 Stanko Kupcevic 0.8-31 -- Upgrade to Zope 2.9.7-final +- Fixed bz233326 (CVE-2007-0240 Conga includes version of Zope that is vulnerable to a XSS attack) +- Fixed bz228637 (CVE-2007-1462 security alert - passwords sent back from server as input value) - Fixed bz229027 (luci failover domain forms are missing/empty) - Fixed bz230447 (fence_xvm is incorrectly listed as "xmv" in virtual cluster) - Fixed bz230452 (Advanced options parameters settings don't do anything) @@ -293,7 +294,7 @@ - Fixed bz230457 (kmod-gfs-xen not installed with Conga install) - Fixed bz230461 ('enable shared storage' option cleared whenever there is a configuration error) - Fixed bz230469 (Must manually edit cluster.conf on the dom0 cluster to add "") -- Resolves: bz229027, bz230447, bz230452, bz230454, bz230457, bz230461, bz230469 +- Resolves: bz229027, bz230447, bz230452, bz230454, bz230457, bz230461, bz230469, bz228637, bz233326 * Tue Jan 23 2007 Stanko Kupcevic 0.8-30 - Fixed bz212445 (release blocker: prevent management page access)