[ubuntu-cloud-archive/cloud-tools-proposed] maas (Accepted)

Scott Moser smoser at ubuntu.com
Thu Feb 13 22:33:53 UTC 2014


 maas (1.4+bzr1693+dfsg-0ubuntu2.3~ctools0) precise; urgency=medium
 .
   * New update for the Ubuntu Cloud Archive.
 .
 maas (1.4+bzr1693+dfsg-0ubuntu2.3) saucy-security; urgency=low
 .
   * SECURITY UPDATE: incorrect Content-type header allowed cross-site
     scripting vulnerability if an unknown API was used. (LP: #1251336)
     - debian/patches/CVE-2013-1070.patch: Use Content-type text/plain to force
       browsers to not render error messages as HTML.
     - CVE-2013-1070
   * SECURITY UPDATE: /etc/maas/txlongpoll.yaml contained a publicly readable
     password. (LP: #1254034)
     - debian/maas-region-controller-min.postinst: chown and chmod
       /etc/maas/txlongpoll.yaml with correct permissions
     - CVE-2013-1069
 .
 maas (1.4+bzr1693+dfsg-0ubuntu2.2) saucy-proposed; urgency=low
 .
   * debian/patches:
     - 99_fix_dhcp_template_lp1240972.patch: Do not prevent the MAAS DHCP
       template from adding ignore-client-uids on precise, which causes
       issues with DNS for MAAS in the Cloud Archive. (LP: #1240972)
     - 99_arm_generic_kernel_lp1166994.patch: Re-enable armhf generic as it
       is supported starting from raring. (LP: #1166994)

Date: Thu, 13 Feb 2014 16:34:30 -0500
Changed-By: Scott Moser <smoser at ubuntu.com>
Signed-By: Scott Moser <smoser at ubuntu.com> 
Published-By: Scott Moser <smoser at ubuntu.com>


More information about the Cloud-tools-changes mailing list