[ubuntu/natty-security] software-center_4.0.5ubuntu0.1_i386_translations.tar.gz, software-center 4.0.5ubuntu0.1 (Accepted)

Marc Deslauriers marc.deslauriers at ubuntu.com
Mon Nov 21 18:03:59 UTC 2011


software-center (4.0.5ubuntu0.1) natty-security; urgency=low

  * SECURITY UPDATE: MITM via incorrect ssl cert validation (LP: #874242)
    - softwarecenter/view/purchaseview.py: Set the ssl-ca-file libsoup
      property so ssl cert validation works.
    - CVE-2011-3150

Date: Fri, 18 Nov 2011 08:36:12 -0500
Changed-By: Marc Deslauriers <marc.deslauriers at ubuntu.com>
Maintainer: Michael Vogt <mvo at ubuntu.com>
https://launchpad.net/ubuntu/natty/+source/software-center/4.0.5ubuntu0.1
-------------- next part --------------
Format: 1.8
Date: Fri, 18 Nov 2011 08:36:12 -0500
Source: software-center
Binary: software-center
Architecture: source
Version: 4.0.5ubuntu0.1
Distribution: natty-security
Urgency: low
Maintainer: Michael Vogt <mvo at ubuntu.com>
Changed-By: Marc Deslauriers <marc.deslauriers at ubuntu.com>
Description: 
 software-center - Utility for browsing, installing, and removing applications
Launchpad-Bugs-Fixed: 874242
Changes: 
 software-center (4.0.5ubuntu0.1) natty-security; urgency=low
 .
   * SECURITY UPDATE: MITM via incorrect ssl cert validation (LP: #874242)
     - softwarecenter/view/purchaseview.py: Set the ssl-ca-file libsoup
       property so ssl cert validation works.
     - CVE-2011-3150
Checksums-Sha1: 
 72a336b8eadb04c525968d8e1c4f032e4d847c9f 1710 software-center_4.0.5ubuntu0.1.dsc
 c42b6e876a8d095f9de7db41ec1e83810a20cef7 775276 software-center_4.0.5ubuntu0.1.tar.gz
Checksums-Sha256: 
 79072324de044343d33ae9f25008fab9980366c98d658ea448553ffdee542449 1710 software-center_4.0.5ubuntu0.1.dsc
 fd8268082a03fdafe24d1c09df7b165ba0d807561cb9464b76a4e28421f4fdf5 775276 software-center_4.0.5ubuntu0.1.tar.gz
Files: 
 e463313cfcb07bc41b85c7dccc2f9e05 1710 gnome optional software-center_4.0.5ubuntu0.1.dsc
 6dd3234c80b1a64e517aee65569aba41 775276 gnome optional software-center_4.0.5ubuntu0.1.tar.gz


More information about the Natty-changes mailing list