From jamie at ubuntu.com Wed Dec 7 00:09:32 2011 From: jamie at ubuntu.com (Jamie Strandboge) Date: Wed, 07 Dec 2011 00:09:32 -0000 Subject: [ubuntu/natty-security] vsftpd_2.3.2-3ubuntu4.1_powerpc_translations.tar.gz, vsftpd, vsftpd_2.3.2-3ubuntu4.1_armel_translations.tar.gz, vsftpd_2.3.2-3ubuntu4.1_i386_translations.tar.gz, vsftpd_2.3.2-3ubuntu4.1_amd64_translations.tar.gz 2.3.2-3ubuntu4.1 (Accepted) Message-ID: <20111207000932.23344.54916.launchpad@cocoplum.canonical.com> vsftpd (2.3.2-3ubuntu4.1) natty-security; urgency=low * SECURITY UPDATE: remote DoS via network namespaces - debian/patches/12-CVE-2011-2189.patch: only use network namespaces on 2.6.36 and higher kernels - patch based on Debian's patch - CVE-2011-2189 Date: Thu, 01 Dec 2011 14:08:14 -0600 Changed-By: Jamie Strandboge Maintainer: Ubuntu Developers https://launchpad.net/ubuntu/natty/+source/vsftpd/2.3.2-3ubuntu4.1 -------------- next part -------------- Format: 1.8 Date: Thu, 01 Dec 2011 14:08:14 -0600 Source: vsftpd Binary: vsftpd Architecture: source Version: 2.3.2-3ubuntu4.1 Distribution: natty-security Urgency: low Maintainer: Ubuntu Developers Changed-By: Jamie Strandboge Description: vsftpd - lightweight, efficient FTP server written for security Changes: vsftpd (2.3.2-3ubuntu4.1) natty-security; urgency=low . * SECURITY UPDATE: remote DoS via network namespaces - debian/patches/12-CVE-2011-2189.patch: only use network namespaces on 2.6.36 and higher kernels - patch based on Debian's patch - CVE-2011-2189 Checksums-Sha1: 517e429ba48155fede221969fcc92880a3f06754 2058 vsftpd_2.3.2-3ubuntu4.1.dsc 41b3c7035241ceeab0ac78bd368c27efee8aea69 28410 vsftpd_2.3.2-3ubuntu4.1.diff.gz Checksums-Sha256: 8ce2acf4040102030244527159a30171d933be94c7257046b292e140c971dfff 2058 vsftpd_2.3.2-3ubuntu4.1.dsc e021fd2a6050962e94fcfe8b7e77f2855fabdd942b91f9b3b7b31c8371568aad 28410 vsftpd_2.3.2-3ubuntu4.1.diff.gz Files: f32c7a380abd65929fd4a1bf3909971d 2058 net extra vsftpd_2.3.2-3ubuntu4.1.dsc 58cea8256bc75ed40731bc0696db8ebd 28410 net extra vsftpd_2.3.2-3ubuntu4.1.diff.gz Original-Maintainer: Daniel Baumann From marc.deslauriers at ubuntu.com Wed Dec 7 17:03:59 2011 From: marc.deslauriers at ubuntu.com (Marc Deslauriers) Date: Wed, 07 Dec 2011 17:03:59 -0000 Subject: [ubuntu/natty-security] clearsilver 0.10.5-1+squeeze1build0.11.04.1 (Accepted) Message-ID: <20111207170359.23848.72811.launchpad@cocoplum.canonical.com> clearsilver (0.10.5-1+squeeze1build0.11.04.1) natty-security; urgency=low * fake sync from Debian clearsilver (0.10.5-1+squeeze1) stable-security; urgency=high * CVE-2011-4357 Date: Mon, 05 Dec 2011 11:27:04 -0500 Changed-By: Marc Deslauriers Maintainer: Jesus Climent https://launchpad.net/ubuntu/natty/+source/clearsilver/0.10.5-1+squeeze1build0.11.04.1 -------------- next part -------------- Format: 1.8 Date: Mon, 05 Dec 2011 11:27:04 -0500 Source: clearsilver Binary: clearsilver-dev python-clearsilver libclearsilver-perl Architecture: source Version: 0.10.5-1+squeeze1build0.11.04.1 Distribution: natty-security Urgency: high Maintainer: Jesus Climent Changed-By: Marc Deslauriers Description: clearsilver-dev - headers and static library for clearsilver libclearsilver-perl - Perl bindings for clearsilver python-clearsilver - Python bindings for clearsilver Changes: clearsilver (0.10.5-1+squeeze1build0.11.04.1) natty-security; urgency=low . * fake sync from Debian . clearsilver (0.10.5-1+squeeze1) stable-security; urgency=high . * CVE-2011-4357 Checksums-Sha1: 0a76d466f73bb7683c6561717f1d90e64aac4cba 2025 clearsilver_0.10.5-1+squeeze1build0.11.04.1.dsc 67184fddba7791c771b2f944179c0204f2f54322 29252 clearsilver_0.10.5-1+squeeze1build0.11.04.1.debian.tar.gz Checksums-Sha256: f92b6f90a4860efebe2f82261fa428416ed81b75b84cfb081c815dec99bb6527 2025 clearsilver_0.10.5-1+squeeze1build0.11.04.1.dsc 01ad4d41262b8e3f412d1586602c16e69c05efc3ed5c42d794869ffe69ff9eb6 29252 clearsilver_0.10.5-1+squeeze1build0.11.04.1.debian.tar.gz Files: ae5de3077bb7c844dab3d5f10be1a70a 2025 devel optional clearsilver_0.10.5-1+squeeze1build0.11.04.1.dsc 779a56860d9c8bb692213e5bd77f18dc 29252 devel optional clearsilver_0.10.5-1+squeeze1build0.11.04.1.debian.tar.gz From tyhicks at canonical.com Thu Dec 8 23:05:10 2011 From: tyhicks at canonical.com (Tyler Hicks) Date: Thu, 08 Dec 2011 23:05:10 -0000 Subject: [ubuntu/natty-security] acpid 1:2.0.7-1ubuntu2.4 (Accepted) Message-ID: <20111208230510.27477.14468.launchpad@cocoplum.canonical.com> acpid (1:2.0.7-1ubuntu2.4) natty-security; urgency=low * SECURITY UPDATE: Arbitrary code execution in the power button handling script (LP: #893821) - debian/powerbtn.sh: Ensure that the DBUS_SESSION_BUS_ADDRESS environment variable is only read from a process owned by the user that will be evaluating the variable. - CVE-2011-2777 * SECURITY UPDATE: Unprivileged users may be able to write to directories and read files created by event handler scripts - event.c: Set a restrictive umask of 0077 before running an event handler script. Based on upstream patch. - CVE-2011-4578 Date: Wed, 07 Dec 2011 16:35:28 -0600 Changed-By: Tyler Hicks Maintainer: Ubuntu Developers https://launchpad.net/ubuntu/natty/+source/acpid/1:2.0.7-1ubuntu2.4 -------------- next part -------------- Format: 1.8 Date: Wed, 07 Dec 2011 16:35:28 -0600 Source: acpid Binary: acpid kacpimon Architecture: source Version: 1:2.0.7-1ubuntu2.4 Distribution: natty-security Urgency: low Maintainer: Ubuntu Developers Changed-By: Tyler Hicks Description: acpid - Advanced Configuration and Power Interface event daemon kacpimon - Kernel ACPI Event Monitor Launchpad-Bugs-Fixed: 893821 Changes: acpid (1:2.0.7-1ubuntu2.4) natty-security; urgency=low . * SECURITY UPDATE: Arbitrary code execution in the power button handling script (LP: #893821) - debian/powerbtn.sh: Ensure that the DBUS_SESSION_BUS_ADDRESS environment variable is only read from a process owned by the user that will be evaluating the variable. - CVE-2011-2777 * SECURITY UPDATE: Unprivileged users may be able to write to directories and read files created by event handler scripts - event.c: Set a restrictive umask of 0077 before running an event handler script. Based on upstream patch. - CVE-2011-4578 Checksums-Sha1: 0666b1e3fbbad0b4779b7e9fd6b60707feaff0a5 1970 acpid_2.0.7-1ubuntu2.4.dsc 7fd0967442b00f9eed3ccc6c34e8ac2337810e58 21228 acpid_2.0.7-1ubuntu2.4.diff.gz Checksums-Sha256: 9d48de189cb89b56d0080be261d4f18bd85e87afc6af9e37dc91c6c8cd30c1ad 1970 acpid_2.0.7-1ubuntu2.4.dsc b6257e984bb7d334e93f0d86ba56cb1133ad96ee952afd7e1daf3ef988408d3d 21228 acpid_2.0.7-1ubuntu2.4.diff.gz Files: e19a18d1c1875a7792ffee04cc73b915 1970 admin optional acpid_2.0.7-1ubuntu2.4.dsc 044896eb0c71bb1da557ea64fca6a8e3 21228 admin optional acpid_2.0.7-1ubuntu2.4.diff.gz Original-Maintainer: Debian Acpi Team From jamie at ubuntu.com Fri Dec 9 00:07:02 2011 From: jamie at ubuntu.com (Jamie Strandboge) Date: Fri, 09 Dec 2011 00:07:02 -0000 Subject: [ubuntu/natty-security] python-django_1.2.5-1ubuntu1.1_i386_translations.tar.gz, python-django 1.2.5-1ubuntu1.1 (Accepted) Message-ID: <20111209000702.16122.31329.launchpad@cocoplum.canonical.com> python-django (1.2.5-1ubuntu1.1) natty-security; urgency=low * SECURITY UPDATE: session manipulation when using django.contrib.sessions with memory-based sessions and caching - debian/patches/CVE-2011-4136.patch: use namespace of cache to store keys for session instead of root namespace - CVE-2011-4136 * SECURITY UPDATE: potential denial of service and information disclosure in URLField - debian/patches/CVE-2011-4137+4138.patch: set verify_exists to False by default and use a timeout if available. - CVE-2011-4137, CVE-2011-4138 * SECURITY UPDATE: potential cache-poisoning via crafted Host header - debian/patches/CVE-2011-4139.patch: ignore X-Forwarded-Host header by default when constructing full URLs - CVE-2011-4139 * More information on these issues can be found at: https://www.djangoproject.com/weblog/2011/sep/09/security-releases-issued/ Date: Wed, 07 Dec 2011 15:28:04 -0600 Changed-By: Jamie Strandboge Maintainer: Ubuntu Developers https://launchpad.net/ubuntu/natty/+source/python-django/1.2.5-1ubuntu1.1 -------------- next part -------------- Format: 1.8 Date: Wed, 07 Dec 2011 15:28:04 -0600 Source: python-django Binary: python-django python-django-doc Architecture: source Version: 1.2.5-1ubuntu1.1 Distribution: natty-security Urgency: low Maintainer: Ubuntu Developers Changed-By: Jamie Strandboge Description: python-django - High-level Python web development framework python-django-doc - High-level Python web development framework (documentation) Changes: python-django (1.2.5-1ubuntu1.1) natty-security; urgency=low . * SECURITY UPDATE: session manipulation when using django.contrib.sessions with memory-based sessions and caching - debian/patches/CVE-2011-4136.patch: use namespace of cache to store keys for session instead of root namespace - CVE-2011-4136 * SECURITY UPDATE: potential denial of service and information disclosure in URLField - debian/patches/CVE-2011-4137+4138.patch: set verify_exists to False by default and use a timeout if available. - CVE-2011-4137, CVE-2011-4138 * SECURITY UPDATE: potential cache-poisoning via crafted Host header - debian/patches/CVE-2011-4139.patch: ignore X-Forwarded-Host header by default when constructing full URLs - CVE-2011-4139 * More information on these issues can be found at: https://www.djangoproject.com/weblog/2011/sep/09/security-releases-issued/ Checksums-Sha1: 53629a1160745104f2316ed3c9f94170b5a0444c 2244 python-django_1.2.5-1ubuntu1.1.dsc f49ddc01932dcb1f743c390e357b507d8e8bf28b 21935 python-django_1.2.5-1ubuntu1.1.debian.tar.gz Checksums-Sha256: a410f9d5497a2b69bf9e635d15e9ec234970763ca4b919dd4ee1e72ad95c0abb 2244 python-django_1.2.5-1ubuntu1.1.dsc fec6db8ca32fd76e37e292567cf1db7d5ca8fff73a4f76a4af80180247e74893 21935 python-django_1.2.5-1ubuntu1.1.debian.tar.gz Files: 1f6f9135ddeb95772cf0815779ef77c1 2244 python optional python-django_1.2.5-1ubuntu1.1.dsc c5d301873595794b01614dfb90c8f923 21935 python optional python-django_1.2.5-1ubuntu1.1.debian.tar.gz Original-Maintainer: Chris Lamb From marc.deslauriers at ubuntu.com Mon Dec 12 17:03:48 2011 From: marc.deslauriers at ubuntu.com (Marc Deslauriers) Date: Mon, 12 Dec 2011 17:03:48 -0000 Subject: [ubuntu/natty-security] commons-daemon 1.0.4-1ubuntu0.1 (Accepted) Message-ID: <20111212170348.19975.34986.launchpad@cocoplum.canonical.com> commons-daemon (1.0.4-1ubuntu0.1) natty-security; urgency=low * SECURITY UPDATE: permissions bypass via incorrect capability dropping - debian/patches/CVE-2011-2729.diff: correctly drop capabilities in src/native/unix/native/jsvc-unix.c. - CVE-2011-2729 Date: Tue, 29 Nov 2011 11:19:39 -0500 Changed-By: Marc Deslauriers Maintainer: Ubuntu Developers https://launchpad.net/ubuntu/natty/+source/commons-daemon/1.0.4-1ubuntu0.1 -------------- next part -------------- Format: 1.8 Date: Tue, 29 Nov 2011 11:19:39 -0500 Source: commons-daemon Binary: libcommons-daemon-java jsvc Architecture: source Version: 1.0.4-1ubuntu0.1 Distribution: natty-security Urgency: low Maintainer: Ubuntu Developers Changed-By: Marc Deslauriers Description: jsvc - wrapper to launch Java applications as daemons libcommons-daemon-java - library to launch Java applications as daemons Changes: commons-daemon (1.0.4-1ubuntu0.1) natty-security; urgency=low . * SECURITY UPDATE: permissions bypass via incorrect capability dropping - debian/patches/CVE-2011-2729.diff: correctly drop capabilities in src/native/unix/native/jsvc-unix.c. - CVE-2011-2729 Checksums-Sha1: 3ebf8984d6e73af7c7a24547d52a3f8558b94988 2251 commons-daemon_1.0.4-1ubuntu0.1.dsc 3b3a8bc7628ad816e57721d0c00da3dd1f739fdb 7832 commons-daemon_1.0.4-1ubuntu0.1.debian.tar.gz Checksums-Sha256: 73b5599022145daef87e47d096140c07217cd8b282c348f72c910e932edd5e32 2251 commons-daemon_1.0.4-1ubuntu0.1.dsc be68bf7091f6d9f6dc25019b20790b400ba87d5ea8b7a745c5120c236c2ba839 7832 commons-daemon_1.0.4-1ubuntu0.1.debian.tar.gz Files: 9e118d9e63a1b377b659536b472f2330 2251 java optional commons-daemon_1.0.4-1ubuntu0.1.dsc fcc8e76b02dffe46bd41ee6c7a2f464a 7832 java optional commons-daemon_1.0.4-1ubuntu0.1.debian.tar.gz Original-Maintainer: Debian Java Maintainers From jamie at ubuntu.com Tue Dec 13 16:03:42 2011 From: jamie at ubuntu.com (Jamie Strandboge) Date: Tue, 13 Dec 2011 16:03:42 -0000 Subject: [ubuntu/natty-security] nova_2011.2-0ubuntu1.2_i386_translations.tar.gz, nova 2011.2-0ubuntu1.2 (Accepted) Message-ID: <20111213160342.7526.52691.launchpad@cocoplum.canonical.com> nova (2011.2-0ubuntu1.2) natty-security; urgency=low * SECURITY UPDATE: fix directory traversal during image registration via EC2 API and S3/RegisterImage - fix-traversal-via-image-register.patch: adjust nova/image/s3.py to use basename instead of absolute path - CVE-2011-XXXX Date: Fri, 09 Dec 2011 06:55:10 -0600 Changed-By: Jamie Strandboge Maintainer: Soren Hansen https://launchpad.net/ubuntu/natty/+source/nova/2011.2-0ubuntu1.2 -------------- next part -------------- Format: 1.8 Date: Fri, 09 Dec 2011 06:55:10 -0600 Source: nova Binary: python-nova nova-common nova-compute nova-scheduler nova-volume nova-ajax-console-proxy nova-api nova-network nova-objectstore nova-instancemonitor nova-doc Architecture: source Version: 2011.2-0ubuntu1.2 Distribution: natty-security Urgency: low Maintainer: Soren Hansen Changed-By: Jamie Strandboge Description: nova-ajax-console-proxy - OpenStack Compute - Nova - AJAX console proxy nova-api - OpenStack Compute - Nova - API frontend nova-common - OpenStack Compute - Nova - common files nova-compute - OpenStack Compute - Nova - compute node nova-doc - OpenStack Compute - Nova - documetation nova-instancemonitor - Nova instance monitor nova-network - OpenStack Compute - Nova - Network thingamajig nova-objectstore - OpenStack Compute - Nova - object store nova-scheduler - OpenStack Compute - Nova - Scheduler nova-volume - OpenStack Compute - Nova - storage python-nova - OpenStack Compute - Nova - Python libraries Changes: nova (2011.2-0ubuntu1.2) natty-security; urgency=low . * SECURITY UPDATE: fix directory traversal during image registration via EC2 API and S3/RegisterImage - fix-traversal-via-image-register.patch: adjust nova/image/s3.py to use basename instead of absolute path - CVE-2011-XXXX Checksums-Sha1: c8fb97983a8d9a9a43aa1ffd1226339ef6de802f 2572 nova_2011.2-0ubuntu1.2.dsc 7f5a404d63e1abfd396b4f2f6c9a1b88093308a8 14626 nova_2011.2-0ubuntu1.2.debian.tar.gz Checksums-Sha256: a3a9a638b2449fc1c427a8794cf24ab77a254085e65135e960e60d426212c091 2572 nova_2011.2-0ubuntu1.2.dsc 89bd595323da468719ac5f3e381229b1c0cfb3d6b85cdae272b7957d1e070a4d 14626 nova_2011.2-0ubuntu1.2.debian.tar.gz Files: 547e85392b8bed10caa1748434bdb13b 2572 net extra nova_2011.2-0ubuntu1.2.dsc cde9ee87facf39fbde333603344dd3d7 14626 net extra nova_2011.2-0ubuntu1.2.debian.tar.gz From bryce at ubuntu.com Tue Dec 13 23:54:50 2011 From: bryce at ubuntu.com (Bryce Harrington) Date: Tue, 13 Dec 2011 23:54:50 -0000 Subject: [ubuntu/natty-proposed] python-launchpadlib 1.9.7-0ubuntu2.1 (Accepted) Message-ID: <20111213235450.4341.84538.launchpad@soybean.canonical.com> python-launchpadlib (1.9.7-0ubuntu2.1) natty-proposed; urgency=low * Add 100_base64_encode_credentials.patch cherrypicked from upstream tree to fix issue causing launchpadlib scripts to fail due to problems associated with keyring corruption. We encode launchpadlib's entries so the keyring won't be confused by unexpected characters. - Convert credentials from unicode when retrieved from the keyring. (LP: #877374) - Use base 64 encoding for credentials stored in the keyring. (LP: #745801) - Properly handle decoding base 64. (LP: #900307) Date: Fri, 09 Dec 2011 15:03:01 -0800 Changed-By: Bryce Harrington Maintainer: Ubuntu Developers https://launchpad.net/ubuntu/natty/+source/python-launchpadlib/1.9.7-0ubuntu2.1 -------------- next part -------------- Format: 1.8 Date: Fri, 09 Dec 2011 15:03:01 -0800 Source: python-launchpadlib Binary: python-launchpadlib Architecture: source Version: 1.9.7-0ubuntu2.1 Distribution: natty-proposed Urgency: low Maintainer: Ubuntu Developers Changed-By: Bryce Harrington Description: python-launchpadlib - Launchpad web services client library Launchpad-Bugs-Fixed: 745801 877374 900307 Changes: python-launchpadlib (1.9.7-0ubuntu2.1) natty-proposed; urgency=low . * Add 100_base64_encode_credentials.patch cherrypicked from upstream tree to fix issue causing launchpadlib scripts to fail due to problems associated with keyring corruption. We encode launchpadlib's entries so the keyring won't be confused by unexpected characters. - Convert credentials from unicode when retrieved from the keyring. (LP: #877374) - Use base 64 encoding for credentials stored in the keyring. (LP: #745801) - Properly handle decoding base 64. (LP: #900307) Checksums-Sha1: 1ad5af2d7241d7a613b08816f65a9f0faf760bae 1603 python-launchpadlib_1.9.7-0ubuntu2.1.dsc 7b537f48b61c2856f21a16ffe1506ced765e3b70 6970 python-launchpadlib_1.9.7-0ubuntu2.1.debian.tar.gz Checksums-Sha256: f700efb3dada14d7b5cc66268a1fd44d0f450287ef44fcccc18b319292bda250 1603 python-launchpadlib_1.9.7-0ubuntu2.1.dsc 22d5c0b37514af0758eae0cd6a8d3aa5e36ef7ed045275360b2157855ee86f75 6970 python-launchpadlib_1.9.7-0ubuntu2.1.debian.tar.gz Files: c218f5d060da39d3b8624c202e2c81f0 1603 python optional python-launchpadlib_1.9.7-0ubuntu2.1.dsc 895e11833f4cb818e06cda58edf292ac 6970 python optional python-launchpadlib_1.9.7-0ubuntu2.1.debian.tar.gz Original-Maintainer: Luca Falavigna From mrpouit at ubuntu.com Wed Dec 14 00:08:05 2011 From: mrpouit at ubuntu.com (Lionel Le Folgoc) Date: Wed, 14 Dec 2011 00:08:05 -0000 Subject: [ubuntu/natty-proposed] xfce4-weather-plugin 0.7.4-0ubuntu1.1 (Accepted) Message-ID: <20111214000805.6734.89141.launchpad@gac.canonical.com> xfce4-weather-plugin (0.7.4-0ubuntu1.1) natty-proposed; urgency=low * debian/patches: - 00_license added, change the license key for the one from CTW since it seems to work and brings back the feature. Temporary fix until a real solution is found. lp: #888285 Date: Sun, 11 Dec 2011 12:18:59 +0100 Changed-By: Lionel Le Folgoc Maintainer: Xubuntu Developers https://launchpad.net/ubuntu/natty/+source/xfce4-weather-plugin/0.7.4-0ubuntu1.1 -------------- next part -------------- Format: 1.8 Date: Sun, 11 Dec 2011 12:18:59 +0100 Source: xfce4-weather-plugin Binary: xfce4-weather-plugin Architecture: source Version: 0.7.4-0ubuntu1.1 Distribution: natty-proposed Urgency: low Maintainer: Xubuntu Developers Changed-By: Lionel Le Folgoc Description: xfce4-weather-plugin - weather information plugin for the Xfce4 panel Launchpad-Bugs-Fixed: 888285 Changes: xfce4-weather-plugin (0.7.4-0ubuntu1.1) natty-proposed; urgency=low . * debian/patches: - 00_license added, change the license key for the one from CTW since it seems to work and brings back the feature. Temporary fix until a real solution is found. lp: #888285 Checksums-Sha1: b9ee90c16df54e4337c5f6eb41f332c0e1586987 2340 xfce4-weather-plugin_0.7.4-0ubuntu1.1.dsc 91e454a175e11f51b575436b79960f4a4bf76f22 4522 xfce4-weather-plugin_0.7.4-0ubuntu1.1.debian.tar.gz Checksums-Sha256: f09d3aa54f80236c753bcf5692f2896556f9036d0ed30cb843a5cc4d5684d137 2340 xfce4-weather-plugin_0.7.4-0ubuntu1.1.dsc ddc7178b9007b9ac4d7c1bd1dba6de5eb3487c5bf45d671711ac327b03310a5c 4522 xfce4-weather-plugin_0.7.4-0ubuntu1.1.debian.tar.gz Files: 2b8ce2935e42f0585514dca08aa1d666 2340 xfce optional xfce4-weather-plugin_0.7.4-0ubuntu1.1.dsc e6d8e5212213f66af04b015c14052dc9 4522 xfce optional xfce4-weather-plugin_0.7.4-0ubuntu1.1.debian.tar.gz Original-Maintainer: Debian Xfce Maintainers From evan at ebroder.net Wed Dec 14 00:28:17 2011 From: evan at ebroder.net (Evan Broder) Date: Wed, 14 Dec 2011 00:28:17 -0000 Subject: [ubuntu/natty-proposed] libgweather 2.30.3-1ubuntu1.1 (Accepted) Message-ID: <20111214002817.6525.19632.launchpad@gac.canonical.com> libgweather (2.30.3-1ubuntu1.1) natty-proposed; urgency=low * debian/patches/50_fix_bom.gov.au_part1.patch, debian/patches/51_fix_bom.gov.au_part2.patch: - Cherry-pick upstream commits a80552f5 and 73829e64 to fix fetching weather data from bom.gov.au (LP: #629646) Date: Sun, 27 Nov 2011 12:24:25 -0800 Changed-By: Evan Broder Maintainer: Ubuntu Desktop Team Signed-By: Martin Pitt https://launchpad.net/ubuntu/natty/+source/libgweather/2.30.3-1ubuntu1.1 -------------- next part -------------- Format: 1.8 Date: Sun, 27 Nov 2011 12:24:25 -0800 Source: libgweather Binary: libgweather-dev libgweather1 libgweather-common python-gweather Architecture: source Version: 2.30.3-1ubuntu1.1 Distribution: natty-proposed Urgency: low Maintainer: Ubuntu Desktop Team Changed-By: Evan Broder Description: libgweather-common - GWeather common files libgweather-dev - GWeather development files libgweather1 - GWeather shared library python-gweather - Python bindings for GWeather Launchpad-Bugs-Fixed: 629646 Changes: libgweather (2.30.3-1ubuntu1.1) natty-proposed; urgency=low . * debian/patches/50_fix_bom.gov.au_part1.patch, debian/patches/51_fix_bom.gov.au_part2.patch: - Cherry-pick upstream commits a80552f5 and 73829e64 to fix fetching weather data from bom.gov.au (LP: #629646) Checksums-Sha1: e34797be25a8afe0168ec6ca07b8484f6daa6ba0 2716 libgweather_2.30.3-1ubuntu1.1.dsc 35a0206b34ae948b5e0fc165659844eb3f615704 12704 libgweather_2.30.3-1ubuntu1.1.debian.tar.gz Checksums-Sha256: 9717fc5e3eb86e7750b6dd52d17210bfe37cc37f68f368c9a2899f344509c435 2716 libgweather_2.30.3-1ubuntu1.1.dsc 4f8b625fcc37952bdbe2648f872b81092dcf5bd215b45a2f47fc8e50876350f0 12704 libgweather_2.30.3-1ubuntu1.1.debian.tar.gz Files: cd3f616a416488dc75a47029cfb2a31b 2716 libs optional libgweather_2.30.3-1ubuntu1.1.dsc 4af0475172f8750f0febc37968e8cf86 12704 libs optional libgweather_2.30.3-1ubuntu1.1.debian.tar.gz Original-Maintainer: Debian GNOME Maintainers From bhavi at ubuntu.com Wed Dec 14 00:36:27 2011 From: bhavi at ubuntu.com (Bhavani Shankar) Date: Wed, 14 Dec 2011 00:36:27 -0000 Subject: [ubuntu/natty-proposed] mobile-broadband-provider-info 20111113-1ubuntu0.11.04 (Accepted) Message-ID: <20111214003627.6939.51137.launchpad@gac.canonical.com> mobile-broadband-provider-info (20111113-1ubuntu0.11.04) natty-proposed; urgency=low * SRU exception upload to support various updated networks (LP: #856700), (LP: #709049) Date: Mon, 05 Dec 2011 21:00:50 +0530 Changed-By: Bhavani Shankar Signed-By: Mathieu Trudel-Lapierre https://launchpad.net/ubuntu/natty/+source/mobile-broadband-provider-info/20111113-1ubuntu0.11.04 -------------- next part -------------- Format: 1.8 Date: Mon, 05 Dec 2011 21:00:50 +0530 Source: mobile-broadband-provider-info Binary: mobile-broadband-provider-info Architecture: source Version: 20111113-1ubuntu0.11.04 Distribution: natty-proposed Urgency: low Maintainer: Bhavani Shankar Changed-By: Bhavani Shankar Description: mobile-broadband-provider-info - database of mobile broadband service providers Launchpad-Bugs-Fixed: 709049 856700 Changes: mobile-broadband-provider-info (20111113-1ubuntu0.11.04) natty-proposed; urgency=low . * SRU exception upload to support various updated networks (LP: #856700), (LP: #709049) Checksums-Sha1: d78576e554b9952db2018394db1bd7748251f1b9 2154 mobile-broadband-provider-info_20111113-1ubuntu0.11.04.dsc 9906d4b15375938472ff6cb7555c0d4735db1466 6042 mobile-broadband-provider-info_20111113-1ubuntu0.11.04.debian.tar.gz Checksums-Sha256: fabef5de926230d51188522972cdd9114ff01ce506f625c378a7469e4a3e3ee6 2154 mobile-broadband-provider-info_20111113-1ubuntu0.11.04.dsc 75e5ab23260725b5cb2d88cad372d5bc81ce6357d1323b3293e4df901b037b4d 6042 mobile-broadband-provider-info_20111113-1ubuntu0.11.04.debian.tar.gz Files: b0f8375d72e4a23a99b4d0e7bd6cde1c 2154 admin optional mobile-broadband-provider-info_20111113-1ubuntu0.11.04.dsc 1cec31f561ff28fdb43dc5e9f7b96913 6042 admin optional mobile-broadband-provider-info_20111113-1ubuntu0.11.04.debian.tar.gz From marc.deslauriers at ubuntu.com Wed Dec 14 16:05:15 2011 From: marc.deslauriers at ubuntu.com (Marc Deslauriers) Date: Wed, 14 Dec 2011 16:05:15 -0000 Subject: [ubuntu/natty-security] php5, php5_5.3.5-1ubuntu7.4_amd64_translations.tar.gz, php5_5.3.5-1ubuntu7.4_powerpc_translations.tar.gz, php5_5.3.5-1ubuntu7.4_i386_translations.tar.gz, php5_5.3.5-1ubuntu7.4_armel_translations.tar.gz 5.3.5-1ubuntu7.4 (Accepted) Message-ID: <20111214160515.32279.26970.launchpad@cocoplum.canonical.com> php5 (5.3.5-1ubuntu7.4) natty-security; urgency=low * SECURITY UPDATE: Denial of service and possible information disclosure via exif integer overflow - debian/patches/php5-CVE-2011-4566.patch: fix count checks in ext/exif/exif.c. - CVE-2011-4566 Date: Mon, 12 Dec 2011 15:20:19 -0500 Changed-By: Marc Deslauriers Maintainer: Ubuntu Developers https://launchpad.net/ubuntu/natty/+source/php5/5.3.5-1ubuntu7.4 -------------- next part -------------- Format: 1.8 Date: Mon, 12 Dec 2011 15:20:19 -0500 Source: php5 Binary: php5 php5-common libapache2-mod-php5 libapache2-mod-php5filter php5-cgi php5-cli php5-fpm php5-dev php5-dbg php-pear php5-curl php5-enchant php5-gd php5-gmp php5-intl php5-ldap php5-mysql php5-odbc php5-pgsql php5-pspell php5-recode php5-snmp php5-sqlite php5-sybase php5-tidy php5-xmlrpc php5-xsl Architecture: source Version: 5.3.5-1ubuntu7.4 Distribution: natty-security Urgency: low Maintainer: Ubuntu Developers Changed-By: Marc Deslauriers Description: libapache2-mod-php5 - server-side, HTML-embedded scripting language (Apache 2 module) libapache2-mod-php5filter - server-side, HTML-embedded scripting language (apache 2 filter mo php-pear - PEAR - PHP Extension and Application Repository php5 - server-side, HTML-embedded scripting language (metapackage) php5-cgi - server-side, HTML-embedded scripting language (CGI binary) php5-cli - command-line interpreter for the php5 scripting language php5-common - Common files for packages built from the php5 source php5-curl - CURL module for php5 php5-dbg - Debug symbols for PHP5 php5-dev - Files for PHP5 module development php5-enchant - Enchant module for php5 php5-fpm - server-side, HTML-embedded scripting language (FPM-CGI binary) php5-gd - GD module for php5 php5-gmp - GMP module for php5 php5-intl - internationalisation module for php5 php5-ldap - LDAP module for php5 php5-mysql - MySQL module for php5 php5-odbc - ODBC module for php5 php5-pgsql - PostgreSQL module for php5 php5-pspell - pspell module for php5 php5-recode - recode module for php5 php5-snmp - SNMP module for php5 php5-sqlite - SQLite module for php5 php5-sybase - Sybase / MS SQL Server module for php5 php5-tidy - tidy module for php5 php5-xmlrpc - XML-RPC module for php5 php5-xsl - XSL module for php5 Changes: php5 (5.3.5-1ubuntu7.4) natty-security; urgency=low . * SECURITY UPDATE: Denial of service and possible information disclosure via exif integer overflow - debian/patches/php5-CVE-2011-4566.patch: fix count checks in ext/exif/exif.c. - CVE-2011-4566 Checksums-Sha1: 03af0e1881acd22db3ce437fde51bd87ba683a5b 3268 php5_5.3.5-1ubuntu7.4.dsc 706f71338597844760f8cf09a0117fc99df5564e 233050 php5_5.3.5-1ubuntu7.4.diff.gz Checksums-Sha256: ba7ba7997a96495f7d7a886cb285109a3536c5901e77e52791cb239068475dad 3268 php5_5.3.5-1ubuntu7.4.dsc 2739fcbe86c68f503d9dccc5da8f6241949dc32ef55be69005789e554af9a243 233050 php5_5.3.5-1ubuntu7.4.diff.gz Files: 4faaf2b013749bdd36835a10f951a2dd 3268 php optional php5_5.3.5-1ubuntu7.4.dsc 9bbcbc5f919e68d221e54774df393ccd 233050 php optional php5_5.3.5-1ubuntu7.4.diff.gz Original-Maintainer: Debian PHP Maintainers From tyhicks at canonical.com Wed Dec 14 22:04:10 2011 From: tyhicks at canonical.com (Tyler Hicks) Date: Wed, 14 Dec 2011 22:04:10 -0000 Subject: [ubuntu/natty-security] bzip2 1.0.5-6ubuntu1.11.04.1 (Accepted) Message-ID: <20111214220410.29394.85128.launchpad@cocoplum.canonical.com> bzip2 (1.0.5-6ubuntu1.11.04.1) natty-security; urgency=low * SECURITY UPDATE: Fix temporary file creation race condition - bzexe: Ensure link target is a regular file. Patch from vladz. - http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=632862#5 - CVE-2011-4089 Date: Mon, 12 Dec 2011 11:32:00 -0600 Changed-By: Tyler Hicks Maintainer: Ubuntu Developers https://launchpad.net/ubuntu/natty/+source/bzip2/1.0.5-6ubuntu1.11.04.1 -------------- next part -------------- Format: 1.8 Date: Mon, 12 Dec 2011 11:32:00 -0600 Source: bzip2 Binary: libbz2-1.0 libbz2-dev bzip2 lib64bz2-1.0 lib64bz2-dev lib32bz2-1.0 lib32bz2-dev bzip2-doc Architecture: source Version: 1.0.5-6ubuntu1.11.04.1 Distribution: natty-security Urgency: low Maintainer: Ubuntu Developers Changed-By: Tyler Hicks Description: bzip2 - high-quality block-sorting file compressor - utilities bzip2-doc - high-quality block-sorting file compressor - documentation lib32bz2-1.0 - high-quality block-sorting file compressor library - 32bit runtim lib32bz2-dev - high-quality block-sorting file compressor library - 32bit develo lib64bz2-1.0 - high-quality block-sorting file compressor library - 64bit runtim lib64bz2-dev - high-quality block-sorting file compressor library - 64bit develo libbz2-1.0 - high-quality block-sorting file compressor library - runtime libbz2-dev - high-quality block-sorting file compressor library - development Changes: bzip2 (1.0.5-6ubuntu1.11.04.1) natty-security; urgency=low . * SECURITY UPDATE: Fix temporary file creation race condition - bzexe: Ensure link target is a regular file. Patch from vladz. - http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=632862#5 - CVE-2011-4089 Checksums-Sha1: 23415bd05afb37dc75d69b5161864cb7472fae0f 2202 bzip2_1.0.5-6ubuntu1.11.04.1.dsc b80bd56461fef6cbb996a7bb0a48b4bff33d5052 77688 bzip2_1.0.5-6ubuntu1.11.04.1.diff.gz Checksums-Sha256: eade8815fabc5cfd103f4ab80667e06cf42075dcf794027f4b86dd8be3d84065 2202 bzip2_1.0.5-6ubuntu1.11.04.1.dsc a75acd6372c4529dc5d95d60c62a9d5ae115e588f52e6c60d929a2297b0902a7 77688 bzip2_1.0.5-6ubuntu1.11.04.1.diff.gz Files: d453e3b3c98efef9d812ca4d8dd56201 2202 utils important bzip2_1.0.5-6ubuntu1.11.04.1.dsc 333a5500c1ce871fd35ea5a800994b96 77688 utils important bzip2_1.0.5-6ubuntu1.11.04.1.diff.gz Original-Maintainer: Anibal Monsalve Salazar From martin.pitt at ubuntu.com Thu Dec 15 10:02:06 2011 From: martin.pitt at ubuntu.com (Martin Pitt) Date: Thu, 15 Dec 2011 10:02:06 -0000 Subject: [ubuntu/natty-proposed] postgresql-8.4 8.4.10-0ubuntu0.11.04 (Accepted) Message-ID: <20111215100206.6128.5864.launchpad@gac.canonical.com> postgresql-8.4 (8.4.10-0ubuntu0.11.04) natty-proposed; urgency=low * New upstream release (LP: #904631): - Fix bugs in information_schema.referential_constraints view. This view was being insufficiently careful about matching the foreign-key constraint to the depended-on primary or unique key constraint. That could result in failure to show a foreign key constraint at all, or showing it multiple times, or claiming that it depends on a different constraint than the one it really does. Since the view definition is installed by initdb, merely upgrading will not fix the problem. If you need to fix this in an existing installation, you can (as a superuser) drop the information_schema schema then re-create it by sourcing "SHAREDIR/information_schema.sql". (Run pg_config --sharedir if you're uncertain where "SHAREDIR" is.) This must be repeated in each database to be fixed. - Fix incorrect replay of WAL records for GIN index updates. This could result in transiently failing to find index entries after a crash, or on a hot-standby server. The problem would be repaired by the next "VACUUM" of the index, however. - Fix TOAST-related data corruption during CREATE TABLE dest AS SELECT - FROM src or INSERT INTO dest SELECT * FROM src. If a table has been modified by "ALTER TABLE ADD COLUMN", attempts to copy its data verbatim to another table could produce corrupt results in certain corner cases. The problem can only manifest in this precise form in 8.4 and later, but we patched earlier versions as well in case there are other code paths that could trigger the same bug. - Fix race condition during toast table access from stale syscache entries. - Track dependencies of functions on items used in parameter default expressions. Previously, a referenced object could be dropped without having dropped or modified the function, leading to misbehavior when the function was used. Note that merely installing this update will not fix the missing dependency entries; to do that, you'd need to "CREATE OR REPLACE" each such function afterwards. If you have functions whose defaults depend on non-built-in objects, doing so is recommended. - Allow inlining of set-returning SQL functions with multiple OUT parameters. - Make DatumGetInetP() unpack inet datums that have a 1-byte header, and add a new macro, DatumGetInetPP(), that does not. - Improve locale support in money type's input and output. Aside from not supporting all standard lc_monetary formatting options, the input and output functions were inconsistent, meaning there were locales in which dumped money values could not be re-read. - Don't let transform_null_equals affect CASE foo WHEN NULL ... constructs. transform_null_equals is only supposed to affect foo = NULL expressions written directly by the user, not equality checks generated internally by this form of CASE. - Change foreign-key trigger creation order to better support self-referential foreign keys. For a cascading foreign key that references its own table, a row update will fire both the ON UPDATE trigger and the CHECK trigger as one event. The ON UPDATE trigger must execute first, else the CHECK will check a non-final state of the row and possibly throw an inappropriate error. However, the firing order of these triggers is determined by their names, which generally sort in creation order since the triggers have auto-generated names following the convention "RI_ConstraintTrigger_NNNN". A proper fix would require modifying that convention, which we will do in 9.2, but it seems risky to change it in existing releases. So this patch just changes the creation order of the triggers. Users encountering this type of error should drop and re-create the foreign key constraint to get its triggers into the right order. - Avoid floating-point underflow while tracking buffer allocation rate. - Preserve blank lines within commands in psql's command history. The former behavior could cause problems if an empty line was removed from within a string literal, for example. - Fix pg_dump to dump user-defined casts between auto-generated types, such as table rowtypes. - Use the preferred version of xsubpp to build PL/Perl, not necessarily the operating system's main copy. - Fix incorrect coding in "contrib/dict_int" and "contrib/dict_xsyn". - Honor query cancel interrupts promptly in pgstatindex(). - Ensure VPATH builds properly install all server header files. - Shorten file names reported in verbose error messages. Regular builds have always reported just the name of the C file containing the error message call, but VPATH builds formerly reported an absolute path name. Date: Thu, 15 Dec 2011 10:56:20 +0100 Changed-By: Martin Pitt Maintainer: Ubuntu Developers https://launchpad.net/ubuntu/natty/+source/postgresql-8.4/8.4.10-0ubuntu0.11.04 -------------- next part -------------- Format: 1.8 Date: Thu, 15 Dec 2011 10:56:20 +0100 Source: postgresql-8.4 Binary: libpq-dev libpq5 libecpg6 libecpg-dev libecpg-compat3 libpgtypes3 postgresql-8.4 postgresql-client-8.4 postgresql-server-dev-8.4 postgresql-doc-8.4 postgresql-contrib-8.4 postgresql-plperl-8.4 postgresql-plpython-8.4 postgresql-pltcl-8.4 postgresql postgresql-client postgresql-doc postgresql-contrib Architecture: source Version: 8.4.10-0ubuntu0.11.04 Distribution: natty-proposed Urgency: low Maintainer: Ubuntu Developers Changed-By: Martin Pitt Description: libecpg-compat3 - older version of run-time library for ECPG programs libecpg-dev - development files for ECPG (Embedded PostgreSQL for C) libecpg6 - run-time library for ECPG programs libpgtypes3 - shared library libpgtypes for PostgreSQL 8.4 libpq-dev - header files for libpq5 (PostgreSQL library) libpq5 - PostgreSQL C client library postgresql - object-relational SQL database (supported version) postgresql-8.4 - object-relational SQL database, version 8.4 server postgresql-client - front-end programs for PostgreSQL (supported version) postgresql-client-8.4 - front-end programs for PostgreSQL 8.4 postgresql-contrib - additional facilities for PostgreSQL (supported version) postgresql-contrib-8.4 - additional facilities for PostgreSQL postgresql-doc - documentation for the PostgreSQL database management system postgresql-doc-8.4 - documentation for the PostgreSQL database management system postgresql-plperl-8.4 - PL/Perl procedural language for PostgreSQL 8.4 postgresql-plpython-8.4 - PL/Python procedural language for PostgreSQL 8.4 postgresql-pltcl-8.4 - PL/Tcl procedural language for PostgreSQL 8.4 postgresql-server-dev-8.4 - development files for PostgreSQL 8.4 server-side programming Launchpad-Bugs-Fixed: 904631 Changes: postgresql-8.4 (8.4.10-0ubuntu0.11.04) natty-proposed; urgency=low . * New upstream release (LP: #904631): - Fix bugs in information_schema.referential_constraints view. This view was being insufficiently careful about matching the foreign-key constraint to the depended-on primary or unique key constraint. That could result in failure to show a foreign key constraint at all, or showing it multiple times, or claiming that it depends on a different constraint than the one it really does. Since the view definition is installed by initdb, merely upgrading will not fix the problem. If you need to fix this in an existing installation, you can (as a superuser) drop the information_schema schema then re-create it by sourcing "SHAREDIR/information_schema.sql". (Run pg_config --sharedir if you're uncertain where "SHAREDIR" is.) This must be repeated in each database to be fixed. - Fix incorrect replay of WAL records for GIN index updates. This could result in transiently failing to find index entries after a crash, or on a hot-standby server. The problem would be repaired by the next "VACUUM" of the index, however. - Fix TOAST-related data corruption during CREATE TABLE dest AS SELECT - FROM src or INSERT INTO dest SELECT * FROM src. If a table has been modified by "ALTER TABLE ADD COLUMN", attempts to copy its data verbatim to another table could produce corrupt results in certain corner cases. The problem can only manifest in this precise form in 8.4 and later, but we patched earlier versions as well in case there are other code paths that could trigger the same bug. - Fix race condition during toast table access from stale syscache entries. - Track dependencies of functions on items used in parameter default expressions. Previously, a referenced object could be dropped without having dropped or modified the function, leading to misbehavior when the function was used. Note that merely installing this update will not fix the missing dependency entries; to do that, you'd need to "CREATE OR REPLACE" each such function afterwards. If you have functions whose defaults depend on non-built-in objects, doing so is recommended. - Allow inlining of set-returning SQL functions with multiple OUT parameters. - Make DatumGetInetP() unpack inet datums that have a 1-byte header, and add a new macro, DatumGetInetPP(), that does not. - Improve locale support in money type's input and output. Aside from not supporting all standard lc_monetary formatting options, the input and output functions were inconsistent, meaning there were locales in which dumped money values could not be re-read. - Don't let transform_null_equals affect CASE foo WHEN NULL ... constructs. transform_null_equals is only supposed to affect foo = NULL expressions written directly by the user, not equality checks generated internally by this form of CASE. - Change foreign-key trigger creation order to better support self-referential foreign keys. For a cascading foreign key that references its own table, a row update will fire both the ON UPDATE trigger and the CHECK trigger as one event. The ON UPDATE trigger must execute first, else the CHECK will check a non-final state of the row and possibly throw an inappropriate error. However, the firing order of these triggers is determined by their names, which generally sort in creation order since the triggers have auto-generated names following the convention "RI_ConstraintTrigger_NNNN". A proper fix would require modifying that convention, which we will do in 9.2, but it seems risky to change it in existing releases. So this patch just changes the creation order of the triggers. Users encountering this type of error should drop and re-create the foreign key constraint to get its triggers into the right order. - Avoid floating-point underflow while tracking buffer allocation rate. - Preserve blank lines within commands in psql's command history. The former behavior could cause problems if an empty line was removed from within a string literal, for example. - Fix pg_dump to dump user-defined casts between auto-generated types, such as table rowtypes. - Use the preferred version of xsubpp to build PL/Perl, not necessarily the operating system's main copy. - Fix incorrect coding in "contrib/dict_int" and "contrib/dict_xsyn". - Honor query cancel interrupts promptly in pgstatindex(). - Ensure VPATH builds properly install all server header files. - Shorten file names reported in verbose error messages. Regular builds have always reported just the name of the C file containing the error message call, but VPATH builds formerly reported an absolute path name. Checksums-Sha1: c86753d20b63f0a88b98544d449b5f9b2d5d14f2 3313 postgresql-8.4_8.4.10-0ubuntu0.11.04.dsc c9b8c3f97e0e12669faad31fd2d5caf13d741297 46261 postgresql-8.4_8.4.10-0ubuntu0.11.04.diff.gz Checksums-Sha256: 78aafd85e24abfefb02feb826ce8923cdd2e92b4dbbcdc5f2963f6a2136dbf2a 3313 postgresql-8.4_8.4.10-0ubuntu0.11.04.dsc 30a863caff9e2ee0d8ed0de025bfd55179513965e0d9c9d16ebc051da0611afb 46261 postgresql-8.4_8.4.10-0ubuntu0.11.04.diff.gz Files: 307894da7ac6fb7a8e0373bb84f2e7cc 3313 database optional postgresql-8.4_8.4.10-0ubuntu0.11.04.dsc 3fbe91b6c9ea275a3c94c839c4985ed0 46261 database optional postgresql-8.4_8.4.10-0ubuntu0.11.04.diff.gz Original-Maintainer: Martin Pitt From marc.deslauriers at ubuntu.com Thu Dec 15 15:03:58 2011 From: marc.deslauriers at ubuntu.com (Marc Deslauriers) Date: Thu, 15 Dec 2011 15:03:58 -0000 Subject: [ubuntu/natty-security] isc-dhcp_4.1.1-P1-15ubuntu9.3_armel_translations.tar.gz, isc-dhcp, isc-dhcp_4.1.1-P1-15ubuntu9.3_powerpc_translations.tar.gz, isc-dhcp_4.1.1-P1-15ubuntu9.3_i386_translations.tar.gz, isc-dhcp_4.1.1-P1-15ubuntu9.3_amd64_translations.tar.gz 4.1.1-P1-15ubuntu9.3 (Accepted) Message-ID: <20111215150358.10457.32249.launchpad@cocoplum.canonical.com> isc-dhcp (4.1.1-P1-15ubuntu9.3) natty-security; urgency=low * SECURITY UPDATE: denial of service via regular expressions - debian/patches/CVE-2011-4539.dpatch: add check for null pointer in common/tree.c. - CVE-2011-4539 * This update does _not_ contain the changes from 4.1.1-P1-15ubuntu9.2 that is currently in -proposed. Date: Wed, 14 Dec 2011 15:55:43 -0500 Changed-By: Marc Deslauriers Maintainer: Ubuntu Developers https://launchpad.net/ubuntu/natty/+source/isc-dhcp/4.1.1-P1-15ubuntu9.3 -------------- next part -------------- Format: 1.8 Date: Wed, 14 Dec 2011 15:55:43 -0500 Source: isc-dhcp Binary: isc-dhcp-server isc-dhcp-server-dbg isc-dhcp-server-ldap isc-dhcp-common isc-dhcp-dev isc-dhcp-client isc-dhcp-client-dbg isc-dhcp-client-udeb isc-dhcp-relay isc-dhcp-relay-dbg dhcp3-server dhcp3-client dhcp3-relay dhcp3-common dhcp3-dev Architecture: source Version: 4.1.1-P1-15ubuntu9.3 Distribution: natty-security Urgency: low Maintainer: Ubuntu Developers Changed-By: Marc Deslauriers Description: dhcp3-client - ISC DHCP server (transitional package) dhcp3-common - ISC DHCP common files (transitional package) dhcp3-dev - ISC DHCP development files (transitional package) dhcp3-relay - ISC DHCP relay (transitional package) dhcp3-server - ISC DHCP server (transitional package) isc-dhcp-client - ISC DHCP client isc-dhcp-client-dbg - ISC DHCP client (debugging symbols) isc-dhcp-client-udeb - ISC DHCP Client for debian-installer (udeb) isc-dhcp-common - common files used by all the isc-dhcp* packages isc-dhcp-dev - API for accessing and modifying the DHCP server and client state isc-dhcp-relay - ISC DHCP relay daemon isc-dhcp-relay-dbg - DHCP relay daemon (debugging symbols) isc-dhcp-server - ISC DHCP server for automatic IP address assignment isc-dhcp-server-dbg - ISC DHCP server for automatic IP address assignment (debug) isc-dhcp-server-ldap - DHCP server able to use LDAP as backend Changes: isc-dhcp (4.1.1-P1-15ubuntu9.3) natty-security; urgency=low . * SECURITY UPDATE: denial of service via regular expressions - debian/patches/CVE-2011-4539.dpatch: add check for null pointer in common/tree.c. - CVE-2011-4539 * This update does _not_ contain the changes from 4.1.1-P1-15ubuntu9.2 that is currently in -proposed. Checksums-Sha1: 2e63a0ce2255321d92122077b002377c828d09fc 2348 isc-dhcp_4.1.1-P1-15ubuntu9.3.dsc f343e5b1e35ef252ab4320a7ab2b8caea4aac0cb 152688 isc-dhcp_4.1.1-P1-15ubuntu9.3.diff.gz Checksums-Sha256: 8c397ebf5cb620986e8394714ceaa72c7d1a2b98bd9427c8969c811e8b34f95f 2348 isc-dhcp_4.1.1-P1-15ubuntu9.3.dsc 9c82726534783b11463e70d1a4b6a5c2770bd74e86826a0426966c460b645c9b 152688 isc-dhcp_4.1.1-P1-15ubuntu9.3.diff.gz Files: 5c0dce5400da7bd27b2a54d379057598 2348 net important isc-dhcp_4.1.1-P1-15ubuntu9.3.dsc 232984d13187c33cbfb8b13b4a04f793 152688 net important isc-dhcp_4.1.1-P1-15ubuntu9.3.diff.gz Original-Maintainer: Debian ISC DHCP maintainers From james.westby at canonical.com Thu Dec 15 18:40:59 2011 From: james.westby at canonical.com (James Westby) Date: Thu, 15 Dec 2011 18:40:59 -0000 Subject: [ubuntu/natty] sun-java6 6.26-2natty1 (Accepted) Message-ID: <20111215184059.28016.42576.launchpad@cocoplum.canonical.com> sun-java6 (6.26-2natty1) natty; urgency=low * Disable the browser plugin due to security issues. - http://www.oracle.com/technetwork/topics/security/javacpuoct2011-443431.html Date: Sat, 10 Dec 2011 13:55:02 -0500 Changed-By: James Westby Maintainer: Debian Java Maintainers Signed-By: Jamie Strandboge https://launchpad.net/ubuntu/natty/+source/sun-java6/6.26-2natty1 -------------- next part -------------- -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sat, 10 Dec 2011 13:55:02 -0500 Source: sun-java6 Binary: sun-java6-jre sun-java6-bin sun-java6-plugin ia32-sun-java6-bin ia32-sun-java6-plugin sun-java6-fonts sun-java6-jdk sun-java6-demo sun-java6-source sun-java6-javadb Architecture: source Version: 6.26-2natty1 Distribution: natty Urgency: low Maintainer: Debian Java Maintainers Changed-By: James Westby Description: ia32-sun-java6-bin - Sun Java(TM) Runtime Environment (JRE) 6 (32-bit) ia32-sun-java6-plugin - Java(TM) Plug-in, Java SE 6 (32-bit) sun-java6-bin - Sun Java(TM) Runtime Environment (JRE) 6 (architecture dependent sun-java6-demo - Sun Java(TM) Development Kit (JDK) 6 demos and examples sun-java6-fonts - Lucida TrueType fonts (from the Sun JRE) sun-java6-javadb - Java(TM) DB, Sun Microsystems' distribution of Apache Derby sun-java6-jdk - Sun Java(TM) Development Kit (JDK) 6 sun-java6-jre - Sun Java(TM) Runtime Environment (JRE) 6 (architecture independen sun-java6-plugin - Java(TM) Plug-in, Java SE 6 sun-java6-source - Sun Java(TM) Development Kit (JDK) 6 source files Changes: sun-java6 (6.26-2natty1) natty; urgency=low . * Disable the browser plugin due to security issues. - http://www.oracle.com/technetwork/topics/security/javacpuoct2011-443431.html Checksums-Sha1: 3e7a99a6f2016128fbda3a052b872efc703c8f80 2314 sun-java6_6.26-2natty1.dsc 948015d808ef0ac2d4cfdc8cbd1c6866e481e472 90340 sun-java6_6.26-2natty1.debian.tar.gz Checksums-Sha256: d41a772d0e0dccef6ed15f26aa5bcd00bc62c8bcb1837342ed6c9221ed094c8b 2314 sun-java6_6.26-2natty1.dsc b10e581ab60e1cd02171510df15e0a49c9f3af3bfb4fe38bc761259e631f75e2 90340 sun-java6_6.26-2natty1.debian.tar.gz Files: e654802aecf916d8f1335d29eb16e3d6 2314 partner/java optional sun-java6_6.26-2natty1.dsc 92e7f5a00c09d2819d940f3c874ade84 90340 partner/java optional sun-java6_6.26-2natty1.debian.tar.gz -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.11 (GNU/Linux) iQIcBAEBCgAGBQJO6jXaAAoJEFHb3FjMVZVzlMAQAIt6y2Et/gEVJwxbsi06k0Qv nkN5jfNw0yFR8ZjLckanbu5vIrprbH5dBwBzKb9tJmsfI4Il6Iv7y2b/3acPJb7N MNNdLfyVBpUwIDaNyKCX/xvx9Uf0IfWFvl18dukll8/cVXGEbjLFTV91EAE0Qg7Z Z40WaFZ7hcdM3hUKS26UeOcRZGO8Ap8TSLoM59UeZIZJL4uw2v+jWt/zYxStgYIq In4vrEk9cYDobrnDMOaO53YgorHygUxZ37ItFvQZvaVk82I+lizcmNznI6RToqYI iMTMzdFAx2nDTvITCZ+guyJsInenxMYEWzHptg6JOufusBUVdfuZ2SmRoNby0wLC YiM33DyNFcnvAt7hL4tfxCxV4Thmjo2BDj+uRzxMm6E8SVZ+S5+mq4jXafKP2bPA OtFtVT1sd1Wrm8Kak/t4A9cdIwIz+cMlV+vfeG0QxnDer3TJICFxMQ1U5U9+8JB8 y2Oyd22sHppv1WqQFJX+R6O6Vbf+yqPyHelKwoi0jmD0Khat4VZU3xHe6YN6JPbu iE15e13mslHbYj51j+y9dO3Yx7WBx5Ynfj/q/yx7iZpaipSg4uWaim8MUN5246vc edInzIzHUjU/RfbB4SE4lIdNBzMDhh9KEqIUjkZs/84vqtdwVaOyiWoKyeF+ljgk venI2Zluxmbt0WH5MbAQ =R9Ul -----END PGP SIGNATURE----- From marc.deslauriers at ubuntu.com Mon Dec 19 14:03:30 2011 From: marc.deslauriers at ubuntu.com (Marc Deslauriers) Date: Mon, 19 Dec 2011 14:03:30 -0000 Subject: [ubuntu/natty-security] libarchive 2.8.4-1ubuntu0.11.04.1 (Accepted) Message-ID: <20111219140330.7426.26781.launchpad@cocoplum.canonical.com> libarchive (2.8.4-1ubuntu0.11.04.1) natty-security; urgency=low * SECURITY UPDATE: arbitrary code execution via iso9660 overflows - debian/patches/CVE-2011-1777.patch: correctly fail on out of memory conditions in libarchive/archive_read_support_format_iso9660.c. - CVE-2011-1777 * SECURITY UPDATE: arbitrary code execution via tar overflows - debian/patches/CVE-2011-1778.patch: correctly fail on out of memory conditions in libarchive/archive_read_support_format_tar.c - CVE-2011-1778 Date: Fri, 09 Dec 2011 15:22:52 -0500 Changed-By: Marc Deslauriers Maintainer: Ubuntu Developers https://launchpad.net/ubuntu/natty/+source/libarchive/2.8.4-1ubuntu0.11.04.1 -------------- next part -------------- Format: 1.8 Date: Fri, 09 Dec 2011 15:22:52 -0500 Source: libarchive Binary: libarchive-dev libarchive1 bsdtar bsdcpio Architecture: source Version: 2.8.4-1ubuntu0.11.04.1 Distribution: natty-security Urgency: low Maintainer: Ubuntu Developers Changed-By: Marc Deslauriers Description: bsdcpio - cpio(1) from FreeBSD, using libarchive bsdtar - tar(1) from FreeBSD, using libarchive libarchive-dev - Single library to read/write tar, cpio, pax, zip, iso9660, etc. libarchive1 - Single library to read/write tar, cpio, pax, zip, iso9660, etc. Changes: libarchive (2.8.4-1ubuntu0.11.04.1) natty-security; urgency=low . * SECURITY UPDATE: arbitrary code execution via iso9660 overflows - debian/patches/CVE-2011-1777.patch: correctly fail on out of memory conditions in libarchive/archive_read_support_format_iso9660.c. - CVE-2011-1777 * SECURITY UPDATE: arbitrary code execution via tar overflows - debian/patches/CVE-2011-1778.patch: correctly fail on out of memory conditions in libarchive/archive_read_support_format_tar.c - CVE-2011-1778 Checksums-Sha1: 5bb47adaec412d5951d8d71b628fd0f8030e92a1 2131 libarchive_2.8.4-1ubuntu0.11.04.1.dsc 7a4b596ad52eed399eefb7c37a10268e81cea67d 16088 libarchive_2.8.4-1ubuntu0.11.04.1.debian.tar.gz Checksums-Sha256: 06676c38c23f63b72515d663d221a44c408ad064fbb989e4a9943f7fe7d30265 2131 libarchive_2.8.4-1ubuntu0.11.04.1.dsc cfea100b7884121a969a54491ee83d15613ef1653deb328263bce4099476e20f 16088 libarchive_2.8.4-1ubuntu0.11.04.1.debian.tar.gz Files: 5fab822cad76e1c3f67a3f66d77c08db 2131 libs optional libarchive_2.8.4-1ubuntu0.11.04.1.dsc dda035c0e08810638dcc0388964a3c90 16088 libs optional libarchive_2.8.4-1ubuntu0.11.04.1.debian.tar.gz Original-Maintainer: Andreas Henriksson From sbeattie at ubuntu.com Mon Dec 19 17:03:29 2011 From: sbeattie at ubuntu.com (Steve Beattie) Date: Mon, 19 Dec 2011 17:03:29 -0000 Subject: [ubuntu/natty-security] chasen 2.4.4-11+squeeze2build0.11.04.1 (Accepted) Message-ID: <20111219170329.14143.88184.launchpad@cocoplum.canonical.com> chasen (2.4.4-11+squeeze2build0.11.04.1) natty-security; urgency=low * fake sync from Debian chasen (2.4.4-11+squeeze2) stable-security; urgency=high * Fix buffer overflow in chasen_sparse_main (CVE-2011-4000) Date: Fri, 16 Dec 2011 11:44:51 -0800 Changed-By: Steve Beattie Maintainer: NOKUBI Takatsugu https://launchpad.net/ubuntu/natty/+source/chasen/2.4.4-11+squeeze2build0.11.04.1 -------------- next part -------------- Format: 1.8 Date: Fri, 16 Dec 2011 11:44:51 -0800 Source: chasen Binary: libchasen-dev libchasen2 chasen chasen-dictutils Architecture: source Version: 2.4.4-11+squeeze2build0.11.04.1 Distribution: natty-security Urgency: high Maintainer: NOKUBI Takatsugu Changed-By: Steve Beattie Description: chasen - a Japanese Morphological Analysis System chasen-dictutils - a Japanese Morphological Analysis System - utilities for dictiona libchasen-dev - a Japanese Morphological Analysis System (libraries and headers) libchasen2 - a Japanese Morphological Analysis System (shared libraries) Changes: chasen (2.4.4-11+squeeze2build0.11.04.1) natty-security; urgency=low . * fake sync from Debian . chasen (2.4.4-11+squeeze2) stable-security; urgency=high . * Fix buffer overflow in chasen_sparse_main (CVE-2011-4000) Checksums-Sha1: 56c143ef4e74b657bb515fd5f6bb3491d871409c 1875 chasen_2.4.4-11+squeeze2build0.11.04.1.dsc bd42eab1cee3860551175813bbd11f08b5e7c78a 8752 chasen_2.4.4-11+squeeze2build0.11.04.1.diff.gz Checksums-Sha256: eed1fa300b494c8a901a0f716ceadc85db26582a61d40a6f584353d742d108a2 1875 chasen_2.4.4-11+squeeze2build0.11.04.1.dsc a9a87488a1638642e0ca0ca725649c37acb493f6dcf527b89bc03da392e64f5c 8752 chasen_2.4.4-11+squeeze2build0.11.04.1.diff.gz Files: b2692cf4cfd32b249f15e6f2b8411775 1875 misc optional chasen_2.4.4-11+squeeze2build0.11.04.1.dsc 17361a5427a504e467d0c87c15bb5fbb 8752 misc optional chasen_2.4.4-11+squeeze2build0.11.04.1.diff.gz From sbeattie at ubuntu.com Mon Dec 19 17:03:36 2011 From: sbeattie at ubuntu.com (Steve Beattie) Date: Mon, 19 Dec 2011 17:03:36 -0000 Subject: [ubuntu/natty-security] mojarra 2.0.3-1+squeeze1build0.11.04.1 (Accepted) Message-ID: <20111219170336.14143.40821.launchpad@cocoplum.canonical.com> mojarra (2.0.3-1+squeeze1build0.11.04.1) natty-security; urgency=low * fake sync from Debian mojarra (2.0.3-1+squeeze1) stable-security; urgency=high * Fixed critical bug by not allowing the value of UIViewParam to be an EL Expression: CVE-2011-4358. (Closes: #650430). Date: Thu, 15 Dec 2011 00:00:59 -0800 Changed-By: Steve Beattie Maintainer: Debian Java Maintainers https://launchpad.net/ubuntu/natty/+source/mojarra/2.0.3-1+squeeze1build0.11.04.1 -------------- next part -------------- Format: 1.8 Date: Thu, 15 Dec 2011 00:00:59 -0800 Source: mojarra Binary: libjsf-api-java libjsf-impl-java libjsf-java-doc Architecture: source Version: 2.0.3-1+squeeze1build0.11.04.1 Distribution: natty-security Urgency: high Maintainer: Debian Java Maintainers Changed-By: Steve Beattie Description: libjsf-api-java - JavaServer Faces 2.0 Java EE web framework - API libjsf-impl-java - JavaServer Faces 2.0 Java EE web framework - Implementation libjsf-java-doc - Documentation for libjsf-api-java Closes: 650430 Changes: mojarra (2.0.3-1+squeeze1build0.11.04.1) natty-security; urgency=low . * fake sync from Debian . mojarra (2.0.3-1+squeeze1) stable-security; urgency=high . * Fixed critical bug by not allowing the value of UIViewParam to be an EL Expression: CVE-2011-4358. (Closes: #650430). Checksums-Sha1: c5770335344988f39ae63992491467dd6f15baf4 2305 mojarra_2.0.3-1+squeeze1build0.11.04.1.dsc 23013532ae9ea523b1057efb5aa66015c7a65600 17639 mojarra_2.0.3-1+squeeze1build0.11.04.1.debian.tar.gz Checksums-Sha256: 04d1d44c3c1f23d2f74511715ae27dec8c2c11333b084fa35a8d042273be2dfd 2305 mojarra_2.0.3-1+squeeze1build0.11.04.1.dsc 55c69682ec01dd28b706672c86276fc03802a07fd3b9dc48302661381c2d7a77 17639 mojarra_2.0.3-1+squeeze1build0.11.04.1.debian.tar.gz Files: 76da139928920f6fe336c2701a71af1e 2305 java optional mojarra_2.0.3-1+squeeze1build0.11.04.1.dsc 8068a16115e6f513dc3c58fd9d558fca 17639 java optional mojarra_2.0.3-1+squeeze1build0.11.04.1.debian.tar.gz From jamie at ubuntu.com Tue Dec 20 00:33:21 2011 From: jamie at ubuntu.com (Jamie Strandboge) Date: Tue, 20 Dec 2011 00:33:21 -0000 Subject: [ubuntu/natty-security] python3.2 3.2-1ubuntu1.1 (Accepted) Message-ID: <20111220003321.24332.28464.launchpad@cocoplum.canonical.com> python3.2 (3.2-1ubuntu1.1) natty-security; urgency=low * SECURITY UPDATE: only process Location headers for http, https, and ftp - http://bugs.python.org/issue11662 - CVE-2011-1521 Date: Thu, 08 Dec 2011 08:51:51 -0600 Changed-By: Jamie Strandboge Maintainer: Ubuntu Core Developers https://launchpad.net/ubuntu/natty/+source/python3.2/3.2-1ubuntu1.1 -------------- next part -------------- Format: 1.8 Date: Thu, 08 Dec 2011 08:51:51 -0600 Source: python3.2 Binary: python3.2 python3.2-minimal libpython3.2 python3.2-examples python3.2-dev idle-python3.2 python3.2-doc python3.2-dbg Architecture: source Version: 3.2-1ubuntu1.1 Distribution: natty-security Urgency: low Maintainer: Ubuntu Core Developers Changed-By: Jamie Strandboge Description: idle-python3.2 - An IDE for Python (v3.2) using Tkinter libpython3.2 - Shared Python runtime library (version 3.2) python3.2 - An interactive high-level object-oriented language (version 3.2) python3.2-dbg - Debug Build of the Python Interpreter (version 3.2) python3.2-dev - Header files and a static library for Python (v3.2) python3.2-doc - Documentation for the high-level object-oriented language Python python3.2-examples - Examples for the Python language (v3.2) python3.2-minimal - A minimal subset of the Python language (version 3.2) Changes: python3.2 (3.2-1ubuntu1.1) natty-security; urgency=low . * SECURITY UPDATE: only process Location headers for http, https, and ftp - http://bugs.python.org/issue11662 - CVE-2011-1521 Checksums-Sha1: b0f19256e46a401620109a469e6da4e0ebd85038 2474 python3.2_3.2-1ubuntu1.1.dsc dee9b366c241b35fce06cc1ba3ea2b2d6ea7c6d7 228705 python3.2_3.2-1ubuntu1.1.diff.gz Checksums-Sha256: ccb7ddc548cf92b25963d8c3fb4402f7cb4e4eb128681e375abee19142822016 2474 python3.2_3.2-1ubuntu1.1.dsc 004cfc6c6c98397b88d970c7015aaf083148fa385e2bda2266931fe8657a95a5 228705 python3.2_3.2-1ubuntu1.1.diff.gz Files: 4dd572cabc41f93adc3793b7ff105e59 2474 python optional python3.2_3.2-1ubuntu1.1.dsc 183216e9b1407f6e3d1634b51b379c81 228705 python optional python3.2_3.2-1ubuntu1.1.diff.gz Original-Maintainer: Matthias Klose From jamie at ubuntu.com Tue Dec 20 00:33:45 2011 From: jamie at ubuntu.com (Jamie Strandboge) Date: Tue, 20 Dec 2011 00:33:45 -0000 Subject: [ubuntu/natty-security] python3.1 3.1.3-1ubuntu1.1 (Accepted) Message-ID: <20111220003345.24332.27832.launchpad@cocoplum.canonical.com> python3.1 (3.1.3-1ubuntu1.1) natty-security; urgency=low * SECURITY UPDATE: only process Location headers for http, https, and ftp - http://bugs.python.org/issue11662 - CVE-2011-1521 Date: Fri, 09 Dec 2011 09:02:22 -0600 Changed-By: Jamie Strandboge Maintainer: Ubuntu Core Developers https://launchpad.net/ubuntu/natty/+source/python3.1/3.1.3-1ubuntu1.1 -------------- next part -------------- Format: 1.8 Date: Fri, 09 Dec 2011 09:02:22 -0600 Source: python3.1 Binary: python3.1 python3.1-minimal libpython3.1 python3.1-examples python3.1-dev idle-python3.1 python3.1-doc python3.1-dbg Architecture: source Version: 3.1.3-1ubuntu1.1 Distribution: natty-security Urgency: low Maintainer: Ubuntu Core Developers Changed-By: Jamie Strandboge Description: idle-python3.1 - An IDE for Python (v3.1) using Tkinter libpython3.1 - Shared Python runtime library (version 3.1) python3.1 - An interactive high-level object-oriented language (version 3.1) python3.1-dbg - Debug Build of the Python Interpreter (version 3.1) python3.1-dev - Header files and a static library for Python (v3.1) python3.1-doc - Documentation for the high-level object-oriented language Python python3.1-examples - Examples for the Python language (v3.1) python3.1-minimal - A minimal subset of the Python language (version 3.1) Changes: python3.1 (3.1.3-1ubuntu1.1) natty-security; urgency=low . * SECURITY UPDATE: only process Location headers for http, https, and ftp - http://bugs.python.org/issue11662 - CVE-2011-1521 Checksums-Sha1: 8c1d139ea2b21c5ddc9b42f2e2f2e06da1efaf80 2473 python3.1_3.1.3-1ubuntu1.1.dsc 51ff950a3a27f9bc96d827248bcd28d964cf1377 253377 python3.1_3.1.3-1ubuntu1.1.diff.gz Checksums-Sha256: 0e4772fc4f0d4aa1358acf41632972a0fa9aaa0d70be794cfaf47410cfef1278 2473 python3.1_3.1.3-1ubuntu1.1.dsc fd52908102ae845f84fa8ba04debcfe8c11250e80b69528b20691e1f979446e9 253377 python3.1_3.1.3-1ubuntu1.1.diff.gz Files: 4da15384d47531d3ba00f6917e2d8cf0 2473 python optional python3.1_3.1.3-1ubuntu1.1.dsc 0bec878421a729a8ad6a564430430d94 253377 python optional python3.1_3.1.3-1ubuntu1.1.diff.gz Original-Maintainer: Matthias Klose From michael.vogt at ubuntu.com Tue Dec 20 07:55:27 2011 From: michael.vogt at ubuntu.com (Michael Vogt) Date: Tue, 20 Dec 2011 07:55:27 -0000 Subject: [ubuntu/natty-proposed] app-install-data-partner 12.11.04.3 (Accepted) Message-ID: <20111220075527.32548.19987.launchpad@gac.canonical.com> app-install-data-partner (12.11.04.3) natty-proposed; urgency=low * add vmware-view-client (LP: #905413) Date: Fri, 16 Dec 2011 23:07:48 +0100 Changed-By: Michael Vogt https://launchpad.net/ubuntu/natty/+source/app-install-data-partner/12.11.04.3 -------------- next part -------------- Format: 1.8 Date: Fri, 16 Dec 2011 23:07:48 +0100 Source: app-install-data-partner Binary: app-install-data-partner app-install-data-commercial Architecture: source Version: 12.11.04.3 Distribution: natty-proposed Urgency: low Maintainer: Michael Vogt Changed-By: Michael Vogt Description: app-install-data-commercial - Transitional package app-install-data-partner - Application Installer (data files for partner applications/reposi Launchpad-Bugs-Fixed: 905413 Changes: app-install-data-partner (12.11.04.3) natty-proposed; urgency=low . * add vmware-view-client (LP: #905413) Checksums-Sha1: 225524e8d6b0d222ddffec08235a31a4d424a8f9 1031 app-install-data-partner_12.11.04.3.dsc 2bf1d3b7703b71c3008635a93b1bbadffea51246 49614 app-install-data-partner_12.11.04.3.tar.gz Checksums-Sha256: e76b1303c6d53b47360a8ac9d3445cd638e9db7cc98abcf4a237b34a6422ee57 1031 app-install-data-partner_12.11.04.3.dsc 9a3101f1fc23ae49cc875b1e438b9d38c1278872a239cc5a41447922dd53bba7 49614 app-install-data-partner_12.11.04.3.tar.gz Files: 4605d9bae53e1374131332cee1b12760 1031 x11 optional app-install-data-partner_12.11.04.3.dsc b9df3a2b91153988c8282c4e09be65f1 49614 x11 optional app-install-data-partner_12.11.04.3.tar.gz From michael.vogt at ubuntu.com Tue Dec 20 10:50:48 2011 From: michael.vogt at ubuntu.com (Michael Vogt) Date: Tue, 20 Dec 2011 10:50:48 -0000 Subject: [ubuntu/natty] vmware-view-client 1.3.0-0ubuntu1+natty2 (Accepted) Message-ID: <20111220105048.32749.68922.launchpad@gac.canonical.com> vmware-view-client (1.3.0-0ubuntu1+natty2) natty; urgency=low * debian/copyright: - fix license to "Proprietary" * debian/vmware-view.wrapper: - show question after license text so that the user explicitely has to accept it because lucid, maverick, natty does not support "yes", "no" for --text-info yet Date: Tue, 20 Dec 2011 10:24:58 +0100 Changed-By: Michael Vogt Maintainer: Michael Vogt https://launchpad.net/ubuntu/natty/+source/vmware-view-client/1.3.0-0ubuntu1+natty2 -------------- next part -------------- Format: 1.8 Date: Tue, 20 Dec 2011 10:24:58 +0100 Source: vmware-view-client Binary: vmware-view-client Architecture: source Version: 1.3.0-0ubuntu1+natty2 Distribution: natty Urgency: low Maintainer: Michael Vogt Changed-By: Michael Vogt Description: vmware-view-client - Deliver rich, personalized virtual desktops with VMware View 5 Changes: vmware-view-client (1.3.0-0ubuntu1+natty2) natty; urgency=low . * debian/copyright: - fix license to "Proprietary" * debian/vmware-view.wrapper: - show question after license text so that the user explicitely has to accept it because lucid, maverick, natty does not support "yes", "no" for --text-info yet Checksums-Sha1: 89898d17a0e20944cfffc9a305d37862420f0c8c 1408 vmware-view-client_1.3.0-0ubuntu1+natty2.dsc f9f8c686653a5b116d5ce11b8948fc2b34e4f208 16726 vmware-view-client_1.3.0-0ubuntu1+natty2.debian.tar.gz Checksums-Sha256: ff31265a7a289edb46982623c4a6d4b2acfec98ded85776082447dcaf9bf4adc 1408 vmware-view-client_1.3.0-0ubuntu1+natty2.dsc b1f162231604d9d6f3a6c6c81e2e42c3821a7612584d24805a9c507fb8d6c723 16726 vmware-view-client_1.3.0-0ubuntu1+natty2.debian.tar.gz Files: 62e694fe5cf524975f5513efda58d53c 1408 partner/net extra vmware-view-client_1.3.0-0ubuntu1+natty2.dsc 5ab4fcfb890d43fc54a78da35f55a10a 16726 partner/net extra vmware-view-client_1.3.0-0ubuntu1+natty2.debian.tar.gz From marc.deslauriers at ubuntu.com Tue Dec 20 15:03:30 2011 From: marc.deslauriers at ubuntu.com (Marc Deslauriers) Date: Tue, 20 Dec 2011 15:03:30 -0000 Subject: [ubuntu/natty-security] jasper 1.900.1-7ubuntu2.11.04.1 (Accepted) Message-ID: <20111220150330.30928.76405.launchpad@cocoplum.canonical.com> jasper (1.900.1-7ubuntu2.11.04.1) natty-security; urgency=low * SECURITY UPDATE: denial of service and possible code execution via heap-based buffer overflows. - src/libjasper/jpc/jpc_cs.c: validate compparms->numrlvls and allocate proper size in src/libjasper/jpc/jpc_cs.c. - Thanks to Red Hat for the patch - CVE-2011-4516 - CVE-2011-4517 Date: Mon, 19 Dec 2011 10:45:25 -0500 Changed-By: Marc Deslauriers Maintainer: Ubuntu Developers https://launchpad.net/ubuntu/natty/+source/jasper/1.900.1-7ubuntu2.11.04.1 -------------- next part -------------- Format: 1.8 Date: Mon, 19 Dec 2011 10:45:25 -0500 Source: jasper Binary: libjasper1 libjasper-dev libjasper-runtime Architecture: source Version: 1.900.1-7ubuntu2.11.04.1 Distribution: natty-security Urgency: low Maintainer: Ubuntu Developers Changed-By: Marc Deslauriers Description: libjasper-dev - Development files for the JasPer JPEG-2000 library libjasper-runtime - Programs for manipulating JPEG-2000 files libjasper1 - The JasPer JPEG-2000 runtime library Changes: jasper (1.900.1-7ubuntu2.11.04.1) natty-security; urgency=low . * SECURITY UPDATE: denial of service and possible code execution via heap-based buffer overflows. - src/libjasper/jpc/jpc_cs.c: validate compparms->numrlvls and allocate proper size in src/libjasper/jpc/jpc_cs.c. - Thanks to Red Hat for the patch - CVE-2011-4516 - CVE-2011-4517 Checksums-Sha1: 61ed8e995e1e0d029badcefbd172d40cf8a31f17 1845 jasper_1.900.1-7ubuntu2.11.04.1.dsc 00873b91830dc68c7a381d32cf1c3f17ba71810b 53785 jasper_1.900.1-7ubuntu2.11.04.1.diff.gz Checksums-Sha256: 033c1efd62b727982c55442e69246c9254ddbed86255cbeb60589f93dbb835a5 1845 jasper_1.900.1-7ubuntu2.11.04.1.dsc 998092ab9dd3821d602c42359e2ed06dc4f0891d279f2b551cbad0c6e8132d57 53785 jasper_1.900.1-7ubuntu2.11.04.1.diff.gz Files: 56608a1d0f69db020f6fd0ba174bdadc 1845 graphics optional jasper_1.900.1-7ubuntu2.11.04.1.dsc c0492923cee053eadce3369492edbefa 53785 graphics optional jasper_1.900.1-7ubuntu2.11.04.1.diff.gz Original-Maintainer: Roland Stigge From udienz at ubuntu.com Tue Dec 20 16:03:43 2011 From: udienz at ubuntu.com (Mahyuddin Susanto) Date: Tue, 20 Dec 2011 16:03:43 -0000 Subject: [ubuntu/natty-security] lighttpd 1.4.28-2ubuntu1.1 (Accepted) Message-ID: <20111220160343.20835.97762.launchpad@cocoplum.canonical.com> lighttpd (1.4.28-2ubuntu1.1) natty-security; urgency=low * SECURITY UPDATE: Fix DoS because of incorrect code in src/http_auth.c:67 (LP: #906792) - debian/patches/CVE-2011-4362.patch: patch derived from upstream - CVE-2011-4362 Date: Tue, 20 Dec 2011 17:36:09 +0700 Changed-By: Mahyuddin Susanto Maintainer: Ubuntu Developers https://launchpad.net/ubuntu/natty/+source/lighttpd/1.4.28-2ubuntu1.1 -------------- next part -------------- Format: 1.8 Date: Tue, 20 Dec 2011 17:36:09 +0700 Source: lighttpd Binary: lighttpd lighttpd-doc lighttpd-mod-mysql-vhost lighttpd-mod-trigger-b4-dl lighttpd-mod-cml lighttpd-mod-magnet lighttpd-mod-webdav lighttpd-dev Architecture: source Version: 1.4.28-2ubuntu1.1 Distribution: natty-security Urgency: low Maintainer: Ubuntu Developers Changed-By: Mahyuddin Susanto Description: lighttpd - A fast webserver with minimal memory footprint lighttpd-dev - Development files for lighttpd lighttpd-doc - Documentation for lighttpd lighttpd-mod-cml - Cache meta language module for lighttpd lighttpd-mod-magnet - Control the request handling module for lighttpd lighttpd-mod-mysql-vhost - MySQL-based virtual host configuration for lighttpd lighttpd-mod-trigger-b4-dl - Anti-deep-linking module for lighttpd lighttpd-mod-webdav - WebDAV module for lighttpd Launchpad-Bugs-Fixed: 906792 Changes: lighttpd (1.4.28-2ubuntu1.1) natty-security; urgency=low . * SECURITY UPDATE: Fix DoS because of incorrect code in src/http_auth.c:67 (LP: #906792) - debian/patches/CVE-2011-4362.patch: patch derived from upstream - CVE-2011-4362 Checksums-Sha1: a227ddcf9c8f4117ab24c1a38b9e7add18b2eedc 2435 lighttpd_1.4.28-2ubuntu1.1.dsc 3f9394ec6b33c35b15e4a029b59cbd244cfb73d2 32811 lighttpd_1.4.28-2ubuntu1.1.debian.tar.gz Checksums-Sha256: 853ded7db85c4ef4133995c67e6d8acf9b686852474dad3b83b8ce45e23fc1b2 2435 lighttpd_1.4.28-2ubuntu1.1.dsc 3fe4b73706fa5f159b737de9e2b298bb9b9c7885074e4205a84c7285a86bca1e 32811 lighttpd_1.4.28-2ubuntu1.1.debian.tar.gz Files: b7ef7696beeee38494ecee8c1718a77c 2435 httpd optional lighttpd_1.4.28-2ubuntu1.1.dsc 56587e87a1d4e8b3d841dfa47127ec24 32811 httpd optional lighttpd_1.4.28-2ubuntu1.1.debian.tar.gz Original-Maintainer: Debian lighttpd maintainers From udienz at ubuntu.com Tue Dec 20 22:33:45 2011 From: udienz at ubuntu.com (Mahyuddin Susanto) Date: Tue, 20 Dec 2011 22:33:45 -0000 Subject: [ubuntu/natty-security] cacti_0.8.7g-1ubuntu0.11.04.1_i386_translations.tar.gz, cacti 0.8.7g-1ubuntu0.11.04.1 (Accepted) Message-ID: <20111220223345.10467.57474.launchpad@cocoplum.canonical.com> cacti (0.8.7g-1ubuntu0.11.04.1) natty-security; urgency=low * SECURITY UPDATE: FIX SQL injection in auth_login.php (LP: #906773) - debian/patches/CVE-2011-4824.patch: patch derived from upstream. - CVE-2011-4824 Date: Tue, 20 Dec 2011 15:52:09 +0700 Changed-By: Mahyuddin Susanto Maintainer: Ubuntu Developers https://launchpad.net/ubuntu/natty/+source/cacti/0.8.7g-1ubuntu0.11.04.1 -------------- next part -------------- Format: 1.8 Date: Tue, 20 Dec 2011 15:52:09 +0700 Source: cacti Binary: cacti Architecture: source Version: 0.8.7g-1ubuntu0.11.04.1 Distribution: natty-security Urgency: low Maintainer: Ubuntu Developers Changed-By: Mahyuddin Susanto Description: cacti - Frontend to rrdtool for monitoring systems and services Launchpad-Bugs-Fixed: 906773 Changes: cacti (0.8.7g-1ubuntu0.11.04.1) natty-security; urgency=low . * SECURITY UPDATE: FIX SQL injection in auth_login.php (LP: #906773) - debian/patches/CVE-2011-4824.patch: patch derived from upstream. - CVE-2011-4824 Checksums-Sha1: 11413a7ffd4200d73c032e2ace14e347febd55f9 1892 cacti_0.8.7g-1ubuntu0.11.04.1.dsc 17a360e28fc194d39f0a14897330030b9fc747f8 42367 cacti_0.8.7g-1ubuntu0.11.04.1.diff.gz Checksums-Sha256: b4cbfeaaa30773443b7fc17399faf8b272d1e70999b561f61845a436bbadc1be 1892 cacti_0.8.7g-1ubuntu0.11.04.1.dsc 5fdddf37335e2b3ef08fb28594bf10e71134e9ee24c398fd95e69e172cb148e0 42367 cacti_0.8.7g-1ubuntu0.11.04.1.diff.gz Files: cbffefb23d2b9e12c3541d8b75a2877f 1892 web extra cacti_0.8.7g-1ubuntu0.11.04.1.dsc f7d02c843a6de864cdf995d1f40f3d8c 42367 web extra cacti_0.8.7g-1ubuntu0.11.04.1.diff.gz Original-Maintainer: Sean Finney From tyhicks at canonical.com Wed Dec 21 17:03:30 2011 From: tyhicks at canonical.com (Tyler Hicks) Date: Wed, 21 Dec 2011 17:03:30 -0000 Subject: [ubuntu/natty-security] t1lib 5.1.2-3ubuntu0.11.04.1 (Accepted) Message-ID: <20111221170330.8274.56648.launchpad@cocoplum.canonical.com> t1lib (5.1.2-3ubuntu0.11.04.1) natty-security; urgency=low * SECURITY UPDATE: Arbitrary code execution via crafted Type 1 font - lib/type1/type1.c: Only use ppoints when it is a valid pointer - CVE-2011-0764 Date: Mon, 19 Dec 2011 11:24:23 -0600 Changed-By: Tyler Hicks Maintainer: Ubuntu Developers https://launchpad.net/ubuntu/natty/+source/t1lib/5.1.2-3ubuntu0.11.04.1 -------------- next part -------------- Format: 1.8 Date: Mon, 19 Dec 2011 11:24:23 -0600 Source: t1lib Binary: libt1-5 libt1-dev t1lib-bin libt1-doc libt1-5-dbg Architecture: source Version: 5.1.2-3ubuntu0.11.04.1 Distribution: natty-security Urgency: low Maintainer: Ubuntu Developers Changed-By: Tyler Hicks Description: libt1-5 - Type 1 font rasterizer library - runtime libt1-5-dbg - Type 1 font rasterizer library - debugging runtime libt1-dev - Type 1 font rasterizer library - development libt1-doc - Type 1 font rasterizer library - developers documentation t1lib-bin - Type 1 font rasterizer library - user binaries Changes: t1lib (5.1.2-3ubuntu0.11.04.1) natty-security; urgency=low . * SECURITY UPDATE: Arbitrary code execution via crafted Type 1 font - lib/type1/type1.c: Only use ppoints when it is a valid pointer - CVE-2011-0764 Checksums-Sha1: 8aab370e75c7298011fccdd99d151e421d484aad 1906 t1lib_5.1.2-3ubuntu0.11.04.1.dsc 9a1544b1b07f4cdb26a230649f7e2da1bc5ef842 18301 t1lib_5.1.2-3ubuntu0.11.04.1.diff.gz Checksums-Sha256: 637b749699a99a996e262175f364f4da6bdf99fe4f7d556e55528d20497a359a 1906 t1lib_5.1.2-3ubuntu0.11.04.1.dsc 647425811c5d26c4a74942990dd52f57d153eb96e1c829a91746a6385daa6684 18301 t1lib_5.1.2-3ubuntu0.11.04.1.diff.gz Files: 14e7bde1fc12838293673264566c67d1 1906 libs optional t1lib_5.1.2-3ubuntu0.11.04.1.dsc 1b655cb51c21366d3109803ee56e05aa 18301 libs optional t1lib_5.1.2-3ubuntu0.11.04.1.diff.gz Original-Maintainer: Ruben Molina From scott at kitterman.com Fri Dec 23 15:03:18 2011 From: scott at kitterman.com (Scott Kitterman) Date: Fri, 23 Dec 2011 15:03:18 -0000 Subject: [ubuntu/natty-security] unbound 1.4.9-0ubuntu1.2 (Accepted) Message-ID: <20111223150318.5859.86039.launchpad@cocoplum.canonical.com> unbound (1.4.9-0ubuntu1.2) natty-security; urgency=high * SECURITY UPDATE: * References: CVE 2011-4528, 2011-4869 (LP: #907983) * Add debian/patches/CVE-2011-4528 to fix DoS with DNSSEC - Patch from Debian security update Date: Fri, 23 Dec 2011 00:12:43 -0500 Changed-By: Scott Kitterman Maintainer: Ubuntu Developers https://launchpad.net/ubuntu/natty/+source/unbound/1.4.9-0ubuntu1.2 -------------- next part -------------- Format: 1.8 Date: Fri, 23 Dec 2011 00:12:43 -0500 Source: unbound Binary: unbound unbound-host libunbound2 libunbound-dev Architecture: source Version: 1.4.9-0ubuntu1.2 Distribution: natty-security Urgency: high Maintainer: Ubuntu Developers Changed-By: Scott Kitterman Description: libunbound-dev - static library, header files, and docs for libunbound libunbound2 - library implementing DNS resolution and validation unbound - validating, recursive, caching DNS resolver unbound-host - reimplementation of the 'host' command Launchpad-Bugs-Fixed: 907983 Changes: unbound (1.4.9-0ubuntu1.2) natty-security; urgency=high . * SECURITY UPDATE: * References: CVE 2011-4528, 2011-4869 (LP: #907983) * Add debian/patches/CVE-2011-4528 to fix DoS with DNSSEC - Patch from Debian security update Checksums-Sha1: 371477ecc1f05a25e22bd418a6d1b87ce200197e 2020 unbound_1.4.9-0ubuntu1.2.dsc cb7931ae8e60041d84a695a3ec0a345f4999dc1b 8613 unbound_1.4.9-0ubuntu1.2.diff.gz Checksums-Sha256: 6ff416fd86040c7d5bc75cd96053f72c4648921a91c08a7def5953c34da87dfa 2020 unbound_1.4.9-0ubuntu1.2.dsc 60ae3af1e740bd4121c951cd74abac5d993daa453960327563f823d11d3d01fd 8613 unbound_1.4.9-0ubuntu1.2.diff.gz Files: f093caebcf43734a4a7ef61acbd490a6 2020 net optional unbound_1.4.9-0ubuntu1.2.dsc 11a5ad39c18712fad0ab423dca7ed723 8613 net optional unbound_1.4.9-0ubuntu1.2.diff.gz Original-Maintainer: Robert S. Edmonds