Created attachment 392762 [details, diff] The new ebuild for webmin-1.720 (diff to 1.690) There is a new upstream version of webmin -> 1.720 There are a couple of new features (and new Perl deps), but most important are the tightening/fixing of some security issues. This security tightening needs some small extra changes in the installation and configure/reconfigure routines. So a new ebuild and a new setup script are needed for this version. I have tested the webmin-1.720.ebuild and the gentoo-setup script and they work OK on amd64 and x86. Please update the portage tree and remove any webmin versions prior to this one... Thanks
Created attachment 392764 [details, diff] The new gentoo-setup script for the webmin-1.720 ebuild
Version 1.730 is now available for download.
(In reply to Frank Krömmelbein from comment #2) > Version 1.730 is now available for download. ATM 1.730 is marked as a development version. The official latest one is still 1.720
(In reply to PhobosK from comment #3) > (In reply to Frank Krömmelbein from comment #2) > > Version 1.730 is now available for download. > > ATM 1.730 is marked as a development version. NO. > The official latest one is > still 1.720 NO. It only lacked the announcement on the Website;-) But it is there now: Webmin 1.730 and Usermin 1.640 released This update includes security fixes to produce against malicious links in the Read Mail module, a new API for theme authors, German and Catalan translation updates, numerous code cleanups, bug fixes and minor improvements. You can get it from the Webmin downloads page, or from our YUM or APT repositories. January 1, 2015
Created attachment 392934 [details, diff] The new ebuild for webmin-1.730 (diff to 1.690)
Created attachment 392936 [details, diff] The new gentoo-setup script for the webmin-1.730 ebuild
Ok... Thanks @Frank Krömmelbein. Changes are applied properly.... For the proxy-committer: Meanwhile a new 1.730 version of webmin is out, so I've added the changes. The only change compared to 1.720 version is that the blue-theme is deprecated in favor of the gray-theme, so that is done in the gentoo-setup script.... All other changes in the gentoo-setup script are described in my first description of this bug report... Thanks
Created attachment 392940 [details, diff] The new gentoo-setup script for the webmin-1.730 ebuild (fixed) A small fix to replace the deprecated theme directly instead of adding the new theme at the end of both config files (and thus duplicating entries)
(In reply to PhobosK from comment #8) > Created attachment 392940 [details, diff] [details, diff] > The new gentoo-setup script for the webmin-1.730 ebuild (fixed) > > A small fix to replace the deprecated theme directly instead of adding the > new theme at the end of both config files (and thus duplicating entries) I assume the change of gentoo-setup script can also apply to version 1.690, correct? otherwise we need to create gentoo-setup-r1
(In reply to Yixun Lan from comment #9) > (In reply to PhobosK from comment #8) > > Created attachment 392940 [details, diff] [details, diff] [details, diff] > > The new gentoo-setup script for the webmin-1.730 ebuild (fixed) > > > > A small fix to replace the deprecated theme directly instead of adding the > > new theme at the end of both config files (and thus duplicating entries) > > I assume the change of gentoo-setup script can also apply to version 1.690, > correct? otherwise we need to create gentoo-setup-r1 Yes the changes can safely be applied to 1.690 too, but the problem is that the new 1.730 fixes some potential cross-site scripting issues, tightens security etc, so any versions prior to it, better be removed from portage... See also bug 511624 comment 25 and bug 511624 comment 26
+*webmin-1.730 (05 Jan 2015) + + 05 Jan 2015; Yixun Lan <dlan@gentoo.org> -webmin-1.690.ebuild, + +webmin-1.730.ebuild, files/gentoo-setup: + drop old due to security issue, bug 511624; bump new, bug 534092, thanks + PhobosK Ok, I've dropped old, thanks for maintaining this ebuild