From 95114a7972b8cc11048cdb87d40faec951d7eecd Mon Sep 17 00:00:00 2001 From: CentOS Sources Date: Jul 22 2019 13:09:30 +0000 Subject: import rh-redis5-redis-5.0.5-1.el7 --- diff --git a/.gitignore b/.gitignore index 8cf8837..8cfce9b 100644 --- a/.gitignore +++ b/.gitignore @@ -1 +1 @@ -SOURCES/redis-5.0.3.tar.gz +SOURCES/redis-5.0.5.tar.gz diff --git a/.rh-redis5-redis.metadata b/.rh-redis5-redis.metadata index b570929..b6107f4 100644 --- a/.rh-redis5-redis.metadata +++ b/.rh-redis5-redis.metadata @@ -1 +1 @@ -a43c24ea6365482323b78e21752d610756efcc39 SOURCES/redis-5.0.3.tar.gz +71e38ae09ac70012b5bc326522b976bcb8e269d6 SOURCES/redis-5.0.5.tar.gz diff --git a/SOURCES/0001-1st-man-pageis-for-redis-cli-redis-benchmark-redis-c.patch b/SOURCES/0001-1st-man-pageis-for-redis-cli-redis-benchmark-redis-c.patch index ab62c0c..d18bbb0 100644 --- a/SOURCES/0001-1st-man-pageis-for-redis-cli-redis-benchmark-redis-c.patch +++ b/SOURCES/0001-1st-man-pageis-for-redis-cli-redis-benchmark-redis-c.patch @@ -1,4 +1,4 @@ -From c7958ad1c0d615b81276ec2d4dbc1bf6a67dcc4d Mon Sep 17 00:00:00 2001 +From ae2235dab50c86480ee37f50119af6668f312ba3 Mon Sep 17 00:00:00 2001 From: Remi Collet Date: Thu, 8 Sep 2016 14:51:15 +0200 Subject: [PATCH 1/2] 1st man pageis for - redis-cli - redis-benchmark - @@ -7,12 +7,12 @@ Subject: [PATCH 1/2] 1st man pageis for - redis-cli - redis-benchmark - as redis-sentinel is a symlink to redis-server, same page can be used (also symlinked) redis.conf can also be used for sentinel.conf --- - man/man1/redis-benchmark.1 | 132 ++++++++++++++++++++++++++++++++++ - man/man1/redis-check-aof.1 | 60 ++++++++++++++++ - man/man1/redis-check-rdb.1 | 53 ++++++++++++++ - man/man1/redis-cli.1 | 171 +++++++++++++++++++++++++++++++++++++++++++++ - man/man1/redis-server.1 | 117 +++++++++++++++++++++++++++++++ - man/man5/redis.conf.5 | 57 +++++++++++++++ + man/man1/redis-benchmark.1 | 132 ++++++++++++++++++++++++++++ + man/man1/redis-check-aof.1 | 60 +++++++++++++ + man/man1/redis-check-rdb.1 | 53 ++++++++++++ + man/man1/redis-cli.1 | 171 +++++++++++++++++++++++++++++++++++++ + man/man1/redis-server.1 | 117 +++++++++++++++++++++++++ + man/man5/redis.conf.5 | 57 +++++++++++++ 6 files changed, 590 insertions(+) create mode 100644 man/man1/redis-benchmark.1 create mode 100644 man/man1/redis-check-aof.1 @@ -648,5 +648,5 @@ index 0000000..1e0c9c9 +(INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF THIS +SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. -- -2.13.5 +2.20.1 diff --git a/SOURCES/0002-install-redis-check-rdb-as-a-symlink-instead-of-dupl.patch b/SOURCES/0002-install-redis-check-rdb-as-a-symlink-instead-of-dupl.patch index ce09350..3d90660 100644 --- a/SOURCES/0002-install-redis-check-rdb-as-a-symlink-instead-of-dupl.patch +++ b/SOURCES/0002-install-redis-check-rdb-as-a-symlink-instead-of-dupl.patch @@ -1,18 +1,18 @@ -From 992c773e70462a6fbe1536e18e673c9ab55d5901 Mon Sep 17 00:00:00 2001 +From 85d847361b519dca524178e3197dbb0ed24e0cb5 Mon Sep 17 00:00:00 2001 From: Remi Collet Date: Fri, 9 Sep 2016 17:23:27 +0200 -Subject: [PATCH 2/2] install redis-check-rdb as a symlink instead of duplicating - the binary +Subject: [PATCH 2/2] install redis-check-rdb as a symlink instead of + duplicating the binary --- src/Makefile | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/src/Makefile b/src/Makefile -index fdbe36a..c3083f8 100644 +index 2a68649..585c95b 100644 --- a/src/Makefile +++ b/src/Makefile -@@ -287,6 +287,6 @@ install: all +@@ -307,9 +307,9 @@ install: all $(REDIS_INSTALL) $(REDIS_SERVER_NAME) $(INSTALL_BIN) $(REDIS_INSTALL) $(REDIS_BENCHMARK_NAME) $(INSTALL_BIN) $(REDIS_INSTALL) $(REDIS_CLI_NAME) $(INSTALL_BIN) @@ -21,6 +21,9 @@ index fdbe36a..c3083f8 100644 @ln -sf $(REDIS_SERVER_NAME) $(INSTALL_BIN)/$(REDIS_SENTINEL_NAME) + @ln -sf $(REDIS_SERVER_NAME) $(INSTALL_BIN)/$(REDIS_CHECK_RDB_NAME) + @ln -sf $(REDIS_SERVER_NAME) $(INSTALL_BIN)/$(REDIS_CHECK_AOF_NAME) + + uninstall: + rm -f $(INSTALL_BIN)/{$(REDIS_SERVER_NAME),$(REDIS_BENCHMARK_NAME),$(REDIS_CLI_NAME),$(REDIS_CHECK_RDB_NAME),$(REDIS_CHECK_AOF_NAME),$(REDIS_SENTINEL_NAME)} -- -2.13.5 +2.20.1 diff --git a/SPECS/redis.spec b/SPECS/redis.spec index 8229a1b..95a6027 100644 --- a/SPECS/redis.spec +++ b/SPECS/redis.spec @@ -22,8 +22,8 @@ %global with_tests %{?_with_tests:1}%{!?_with_tests:0} Name: %{?scl_prefix}redis -Version: 5.0.3 -Release: 2%{?dist} +Version: 5.0.5 +Release: 1%{?dist} Summary: A persistent key-value database Group: Applications/Databases @@ -108,7 +108,7 @@ mv deps/hiredis/COPYING COPYING-hiredis # Configuration file changes and additions sed -i -e 's|^logfile .*$|logfile /var/log/redis/redis.log|g' redis.conf -sed -i -e '$ alogfile /var/log/redis/sentinel.log' sentinel.conf +sed -i -e 's|^logfile .*$|logfile /var/log/redis/sentinel.log|g' sentinel.conf sed -i -e 's|^dir .*$|dir /var/lib/redis|g' redis.conf %global make_flags DEBUG="" V="echo" LDFLAGS="%{?__global_ldflags}" CFLAGS+="%{optflags} -fPIC" INSTALL="install -p" PREFIX=%{buildroot}%{_prefix} @@ -252,6 +252,13 @@ exit 0 %changelog +* Fri Jul 12 2019 Remi Collet - 5.0.5-1 +- rebase to 5.0.5 +- fix Heap buffer overflow in HyperLogLog triggered by malicious client + CVE-2019-10192 +- fix Stack buffer overflow in HyperLogLog triggered by malicious client + CVE-2019-10193 + * Mon Jan 14 2019 Remi Collet - 5.0.3-2 - fix License and URL