From jamie at ubuntu.com Mon Oct 3 21:03:30 2011 From: jamie at ubuntu.com (Jamie Strandboge) Date: Mon, 03 Oct 2011 21:03:30 -0000 Subject: [ubuntu/natty-security] rsyslog 4.6.4-2ubuntu4.1 (Accepted) Message-ID: <20111003210330.619.5623.launchpad@cocoplum.canonical.com> rsyslog (4.6.4-2ubuntu4.1) natty-security; urgency=low * debian/patches/03-CVE-2011-3200.patch: fix denial of service via off by two - CVE-2011-3200 Date: Tue, 30 Aug 2011 14:27:10 -0500 Changed-By: Jamie Strandboge Maintainer: Ubuntu Developers https://launchpad.net/ubuntu/natty/+source/rsyslog/4.6.4-2ubuntu4.1 -------------- next part -------------- Format: 1.8 Date: Tue, 30 Aug 2011 14:27:10 -0500 Source: rsyslog Binary: rsyslog rsyslog-doc rsyslog-mysql rsyslog-pgsql rsyslog-gssapi rsyslog-gnutls rsyslog-relp Architecture: source Version: 4.6.4-2ubuntu4.1 Distribution: natty-security Urgency: low Maintainer: Ubuntu Developers Changed-By: Jamie Strandboge Description: rsyslog - enhanced multi-threaded syslogd rsyslog-doc - documentation for rsyslog rsyslog-gnutls - TLS protocol support for rsyslog rsyslog-gssapi - GSSAPI authentication and encryption support for rsyslog rsyslog-mysql - MySQL output plugin for rsyslog rsyslog-pgsql - PostgreSQL output plugin for rsyslog rsyslog-relp - RELP protocol support for rsyslog Changes: rsyslog (4.6.4-2ubuntu4.1) natty-security; urgency=low . * debian/patches/03-CVE-2011-3200.patch: fix denial of service via off by two - CVE-2011-3200 Checksums-Sha1: 17d31ad26c8e5b0af9a0e2dcafa639473350bf9c 2140 rsyslog_4.6.4-2ubuntu4.1.dsc 04b64760e73f021cedfbd91080ed0473e91d2692 28348 rsyslog_4.6.4-2ubuntu4.1.debian.tar.gz Checksums-Sha256: abecc212791f8e8f30715157545edcefbf6246dbf48b33c222a3284b9d73fc3f 2140 rsyslog_4.6.4-2ubuntu4.1.dsc a04382196bb4d2986e9f2992f0da8c0a405efeb989ebe1593d7e7ee3919a93a9 28348 rsyslog_4.6.4-2ubuntu4.1.debian.tar.gz Files: e6908935d79baebe54e34ba1c37094a7 2140 admin important rsyslog_4.6.4-2ubuntu4.1.dsc bc5dd18983b768af81575ab81ddcf2fd 28348 admin important rsyslog_4.6.4-2ubuntu4.1.debian.tar.gz Original-Maintainer: Michael Biebl Original-Vcs-Browser: http://git.debian.org/?p=collab-maint/rsyslog.git;a=summary Original-Vcs-Git: git://git.debian.org/git/collab-maint/rsyslog.git From gary.lasker at canonical.com Tue Oct 4 05:46:03 2011 From: gary.lasker at canonical.com (Gary Lasker) Date: Tue, 04 Oct 2011 05:46:03 -0000 Subject: [ubuntu/natty-proposed] tzdata 2011k-0ubuntu0.11.04 (Accepted) Message-ID: <20111004054603.11795.13461.launchpad@chaenomeles.canonical.com> tzdata (2011k-0ubuntu0.11.04) natty-proposed; urgency=low * New upstream release 2011k: (LP: #865750) - Palestine suspends DST during Ramadan in 2011 - Gaza and Hebron split in 2011, leading to a new Asia/Hebron zone - Belarus adopts permanent DST in 2011 - Ukraine adopts permanent DST in 2011 * debian/control: update maintainer fields Date: Mon, 03 Oct 2011 22:02:21 -0400 Changed-By: Gary Lasker Maintainer: Ubuntu Developers Signed-By: Martin Pitt https://launchpad.net/ubuntu/natty/+source/tzdata/2011k-0ubuntu0.11.04 -------------- next part -------------- Format: 1.8 Date: Mon, 03 Oct 2011 22:02:21 -0400 Source: tzdata Binary: tzdata tzdata-java Architecture: source Version: 2011k-0ubuntu0.11.04 Distribution: natty-proposed Urgency: low Maintainer: Ubuntu Developers Changed-By: Gary Lasker Description: tzdata - time zone and daylight-saving time data tzdata-java - time zone and daylight-saving time data for use by java runtimes Launchpad-Bugs-Fixed: 865750 Changes: tzdata (2011k-0ubuntu0.11.04) natty-proposed; urgency=low . * New upstream release 2011k: (LP: #865750) - Palestine suspends DST during Ramadan in 2011 - Gaza and Hebron split in 2011, leading to a new Asia/Hebron zone - Belarus adopts permanent DST in 2011 - Ukraine adopts permanent DST in 2011 * debian/control: update maintainer fields Checksums-Sha1: d4d4272a1ef7c66907212db0824df90949d9be8d 1908 tzdata_2011k-0ubuntu0.11.04.dsc 56f0847a10eaea672be19984b4b403e29631c98b 199725 tzdata_2011k.orig.tar.gz fa2b34966c41db96af162b02d8550b6906c42ad1 260881 tzdata_2011k-0ubuntu0.11.04.debian.tar.gz Checksums-Sha256: 10e8f992c537d4b319008c493d578789040deeab5b14f7d0e88f50a615e1dcae 1908 tzdata_2011k-0ubuntu0.11.04.dsc 51f7d2a42b7fb9465feced642a6676afdf8b04a071e55f3fef1f0925bd67ef21 199725 tzdata_2011k.orig.tar.gz 06792fc12da89dac10e04840ee61ec2d9e77bbaa4033a886573ce8eda4c00eb5 260881 tzdata_2011k-0ubuntu0.11.04.debian.tar.gz Files: 5d539dc784a223b08c08336d1d80f723 1908 libs required tzdata_2011k-0ubuntu0.11.04.dsc 9da1c2d4d1a01f9f504b73ccd371830f 199725 libs required tzdata_2011k.orig.tar.gz b399c17cf6926b0b0c1b7b2f089a715c 260881 libs required tzdata_2011k-0ubuntu0.11.04.debian.tar.gz Original-Maintainer: GNU Libc Maintainers From marc.deslauriers at ubuntu.com Tue Oct 4 20:03:36 2011 From: marc.deslauriers at ubuntu.com (Marc Deslauriers) Date: Tue, 04 Oct 2011 20:03:36 -0000 Subject: [ubuntu/natty-security] cifs-utils 2:4.5-2ubuntu0.11.04.1 (Accepted) Message-ID: <20111004200336.28769.68561.launchpad@cocoplum.canonical.com> cifs-utils (2:4.5-2ubuntu0.11.04.1) natty-security; urgency=low * SECURITY UPDATE: mtab corruption via resource limits - debian/patches/CVE-2011-1678.patch: truncate mtab file if updating it failed in mount.cifs.c, mount.h, mtab.c. - CVE-2011-1678 * SECURITY UPDATE: mtab corruption via incorrect new line check - debian/patches/CVE-2011-2724.patch: check proper return codes in mount.cifs.c. - CVE-2011-2724 Date: Fri, 30 Sep 2011 12:02:12 -0400 Changed-By: Marc Deslauriers Maintainer: Ubuntu Developers https://launchpad.net/ubuntu/natty/+source/cifs-utils/2:4.5-2ubuntu0.11.04.1 -------------- next part -------------- Format: 1.8 Date: Fri, 30 Sep 2011 12:02:12 -0400 Source: cifs-utils Binary: cifs-utils smbfs Architecture: source Version: 2:4.5-2ubuntu0.11.04.1 Distribution: natty-security Urgency: low Maintainer: Ubuntu Developers Changed-By: Marc Deslauriers Description: cifs-utils - Common Internet File System utilities smbfs - Common Internet File System utilities - compatibility package Changes: cifs-utils (2:4.5-2ubuntu0.11.04.1) natty-security; urgency=low . * SECURITY UPDATE: mtab corruption via resource limits - debian/patches/CVE-2011-1678.patch: truncate mtab file if updating it failed in mount.cifs.c, mount.h, mtab.c. - CVE-2011-1678 * SECURITY UPDATE: mtab corruption via incorrect new line check - debian/patches/CVE-2011-2724.patch: check proper return codes in mount.cifs.c. - CVE-2011-2724 Checksums-Sha1: ffbb945210e7d1b1c6d1a8eb24070f6ecb909fc5 2217 cifs-utils_4.5-2ubuntu0.11.04.1.dsc 160439792a13d58f9b35754b27c3f60a8c42e22a 6960 cifs-utils_4.5-2ubuntu0.11.04.1.debian.tar.gz Checksums-Sha256: 70985a9ff9d5207bae2937662970a7829bfc1cf7e60946054bf4a9980801cb25 2217 cifs-utils_4.5-2ubuntu0.11.04.1.dsc c4f18da4ba3f615fa7ae9822ba4ec42c5ff3238aac8ceed6369fae58a67fe9f7 6960 cifs-utils_4.5-2ubuntu0.11.04.1.debian.tar.gz Files: 20a7bcef9c1733eb66b04a51cdc06449 2217 otherosfs optional cifs-utils_4.5-2ubuntu0.11.04.1.dsc 70b91ae4041ce8e0e1878dc2a2158e62 6960 otherosfs optional cifs-utils_4.5-2ubuntu0.11.04.1.debian.tar.gz Original-Maintainer: Debian Samba Maintainers From brian.thomason at canonical.com Thu Oct 6 16:10:32 2011 From: brian.thomason at canonical.com (Brian Thomason) Date: Thu, 06 Oct 2011 16:10:32 -0000 Subject: [ubuntu/natty] adobe-flashplugin 11.0.1.152-0natty1 (Accepted) Message-ID: <20111006161032.31954.8901.launchpad@cocoplum.canonical.com> adobe-flashplugin (11.0.1.152-0natty1) natty; urgency=low * Initial release of 11.0.1.152 for natty Date: Thu, 06 Oct 2011 11:53:51 -0400 Changed-By: Brian Thomason Maintainer: DL-Flash Player Ubuntu https://launchpad.net/ubuntu/natty/+source/adobe-flashplugin/11.0.1.152-0natty1 -------------- next part -------------- -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Format: 1.8 Date: Thu, 06 Oct 2011 11:53:51 -0400 Source: adobe-flashplugin Binary: adobe-flashplugin adobe-flash-properties-gtk adobe-flash-properties-kde Architecture: source Version: 11.0.1.152-0natty1 Distribution: natty Urgency: low Maintainer: DL-Flash Player Ubuntu Changed-By: Brian Thomason Description: adobe-flash-properties-gtk - GTK+ control panel for Adobe Flash Player plugin version 10 adobe-flash-properties-kde - KDE control panel Adobe Flash Player plugin version 10 adobe-flashplugin - Adobe Flash Player plugin version 10 Changes: adobe-flashplugin (11.0.1.152-0natty1) natty; urgency=low . * Initial release of 11.0.1.152 for natty Checksums-Sha1: 0f97f0e32de69fd8dcbf0e9714168289c04a6f70 1260 adobe-flashplugin_11.0.1.152-0natty1.dsc 73d1ca937427198c01be535b256edefd5fe61d1b 4692 adobe-flashplugin_11.0.1.152-0natty1.diff.gz Checksums-Sha256: 8efac226d444f1bfc6c0f1253cde1adca6e909c02315bd6be29981c5c58c30a5 1260 adobe-flashplugin_11.0.1.152-0natty1.dsc 3708561f875aa86adb54c131f475b88cbbe47432ac113be624b92b328d16fcc7 4692 adobe-flashplugin_11.0.1.152-0natty1.diff.gz Files: 32f6a6d8fc1a66c1421e7d5465508214 1260 partner/web optional adobe-flashplugin_11.0.1.152-0natty1.dsc 55c0e04f28edc8dcbc02b6610f6ab4a3 4692 partner/web optional adobe-flashplugin_11.0.1.152-0natty1.diff.gz -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iEYEARECAAYFAk6NzyQACgkQOb4zNfJqN5fJJACePPAREV6p7hlaPnv4O2AE+flw ZmQAmgN+JYFijejnWaPcecgQiEi53oBz =tkr9 -----END PGP SIGNATURE----- From scott at kitterman.com Fri Oct 7 07:37:28 2011 From: scott at kitterman.com (Scott Kitterman) Date: Fri, 07 Oct 2011 07:37:28 -0000 Subject: [ubuntu/natty-proposed] postfix 2.8.5-2~build0.11.04 (Accepted) Message-ID: <20111007073728.27861.33726.launchpad@soybean.canonical.com> postfix (2.8.5-2~build0.11.04) natty-proposed; urgency=low [ LaMont Jones ] * Trial microversion update per TB 10/6/11 (LP: #869411) [Wietse Venema] * 2.8.5 - Workaround: report a {client_connections} Milter macro value of zero instead of garbage, when the remote SMTP client is not subject to any smtpd_client_* limits. Problem reported by Christian Roessner. - Bugfix: allow for Milters that send an SMTP server reply without RFC 3463 enhanced status code. Reported by Vladimir Vassiliev. * 2.8.4 - Performance: a high load of DSN success notification requests could slow down the queue manager. - Bugfix (introduced Postfix 2.3 and Postfix 2.7): the Milter client reported some "file too large" errors as temporary errors. - Bugfix (introduced in Postfix 1.1, duplicated in Postfix 2.3, unrelated mistake in Postfix 2.7): the local(8) delivery agent ignored table lookup errors in mailbox_command_maps, mailbox_transport_maps, fallback_transport_maps and (while bouncing mail to alias) alias owner lookup. - Bugfix (introduced Postfix 2.6 with master_service_disable) loop control error when parsing a malformed master.cf file. - Bugfix (introduced: Postfix 2.7): "sendmail -t" reported "protocol error" after queue file write error. - Linux kernel version 3 support. - Workaround: some Spamhaus RHSBL rejects lookups with "No IP queries" even if the name has an alphanumerical prefix. We play safe, and skip both RHSBL and RHSWL queries for names ending in a numerical suffix. * 2.8.3 - Cleanup: postscreen(8) and verify(8) daemons now lock their respective cache file exclusively upon open, to avoid massive cache corruption by unsupported sharing. - Bugfix (introduced with Postfix SASL patch 20000314): don't reuse a server SASL handle after authentication failure. CVE-2011-1720 Date: Fri, 07 Oct 2011 00:59:20 -0500 Changed-By: Scott Kitterman Maintainer: Ubuntu Developers https://launchpad.net/ubuntu/natty/+source/postfix/2.8.5-2~build0.11.04 -------------- next part -------------- Format: 1.8 Date: Fri, 07 Oct 2011 00:59:20 -0500 Source: postfix Binary: postfix postfix-ldap postfix-cdb postfix-pcre postfix-mysql postfix-pgsql postfix-dev postfix-doc Architecture: source Version: 2.8.5-2~build0.11.04 Distribution: natty-proposed Urgency: low Maintainer: Ubuntu Developers Changed-By: Scott Kitterman Description: postfix - High-performance mail transport agent postfix-cdb - CDB map support for Postfix postfix-dev - Loadable modules development environment for Postfix postfix-doc - Documentation for Postfix postfix-ldap - LDAP map support for Postfix postfix-mysql - MySQL map support for Postfix postfix-pcre - PCRE map support for Postfix postfix-pgsql - PostgreSQL map support for Postfix Launchpad-Bugs-Fixed: 869411 Changes: postfix (2.8.5-2~build0.11.04) natty-proposed; urgency=low . [ LaMont Jones ] * Trial microversion update per TB 10/6/11 (LP: #869411) . [Wietse Venema] . * 2.8.5 - Workaround: report a {client_connections} Milter macro value of zero instead of garbage, when the remote SMTP client is not subject to any smtpd_client_* limits. Problem reported by Christian Roessner. - Bugfix: allow for Milters that send an SMTP server reply without RFC 3463 enhanced status code. Reported by Vladimir Vassiliev. * 2.8.4 - Performance: a high load of DSN success notification requests could slow down the queue manager. - Bugfix (introduced Postfix 2.3 and Postfix 2.7): the Milter client reported some "file too large" errors as temporary errors. - Bugfix (introduced in Postfix 1.1, duplicated in Postfix 2.3, unrelated mistake in Postfix 2.7): the local(8) delivery agent ignored table lookup errors in mailbox_command_maps, mailbox_transport_maps, fallback_transport_maps and (while bouncing mail to alias) alias owner lookup. - Bugfix (introduced Postfix 2.6 with master_service_disable) loop control error when parsing a malformed master.cf file. - Bugfix (introduced: Postfix 2.7): "sendmail -t" reported "protocol error" after queue file write error. - Linux kernel version 3 support. - Workaround: some Spamhaus RHSBL rejects lookups with "No IP queries" even if the name has an alphanumerical prefix. We play safe, and skip both RHSBL and RHSWL queries for names ending in a numerical suffix. * 2.8.3 - Cleanup: postscreen(8) and verify(8) daemons now lock their respective cache file exclusively upon open, to avoid massive cache corruption by unsupported sharing. - Bugfix (introduced with Postfix SASL patch 20000314): don't reuse a server SASL handle after authentication failure. CVE-2011-1720 Checksums-Sha1: 445d0e1019cdaae023ca9856bfae4c5bf81eb28a 1608 postfix_2.8.5-2~build0.11.04.dsc 49ef711c80b5a3434258ab24ae00940932503e80 3647010 postfix_2.8.5.orig.tar.gz 127f3713fa0418f39e49cb5532f6dd5ad729b105 233518 postfix_2.8.5-2~build0.11.04.diff.gz Checksums-Sha256: b2ce69669bd50056d34bedf0224822575916ee7da6609c0846c127258b1786dc 1608 postfix_2.8.5-2~build0.11.04.dsc f8ed6c98bf5058c363da936a8034c64cee38ca67110e9212491de862116e1c17 3647010 postfix_2.8.5.orig.tar.gz 106cd0f8e81f41d4b0349e74a9bb384bbeafd2a9b5a02be71091cdd08cae3400 233518 postfix_2.8.5-2~build0.11.04.diff.gz Files: 56038c97973d1ada1c67cfc014039d5b 1608 mail extra postfix_2.8.5-2~build0.11.04.dsc a38128959af680009cae8cbcc03e0f10 3647010 mail extra postfix_2.8.5.orig.tar.gz b6b7deb4b4f8589e5817398cad9c2e72 233518 mail extra postfix_2.8.5-2~build0.11.04.diff.gz Original-Maintainer: LaMont Jones From marc.deslauriers at ubuntu.com Sat Oct 8 15:03:17 2011 From: marc.deslauriers at ubuntu.com (Marc Deslauriers) Date: Sat, 08 Oct 2011 15:03:17 -0000 Subject: [ubuntu/natty-security] flashplugin-nonfree, flashplugin-nonfree_11.0.1.152ubuntu0.11.04.1_amd64_translations.tar.gz, flashplugin-nonfree_11.0.1.152ubuntu0.11.04.1_i386_translations.tar.gz 11.0.1.152ubuntu0.11.04.1 (Accepted) Message-ID: <20111008150317.19239.96506.launchpad@cocoplum.canonical.com> flashplugin-nonfree (11.0.1.152ubuntu0.11.04.1) natty-security; urgency=low * New upstream release 11.0.1.152 (LP: #868545) - debian/{config,postinst}: Updated sha256sums and version. Date: Fri, 07 Oct 2011 21:36:39 -0400 Changed-By: Marc Deslauriers Maintainer: Ubuntu Developers https://launchpad.net/ubuntu/natty/+source/flashplugin-nonfree/11.0.1.152ubuntu0.11.04.1 -------------- next part -------------- Format: 1.8 Date: Fri, 07 Oct 2011 21:36:39 -0400 Source: flashplugin-nonfree Binary: flashplugin-installer flashplugin-nonfree Architecture: source Version: 11.0.1.152ubuntu0.11.04.1 Distribution: natty-security Urgency: low Maintainer: Ubuntu Developers Changed-By: Marc Deslauriers Description: flashplugin-installer - Adobe Flash Player plugin installer flashplugin-nonfree - Adobe Flash Player plugin installer (transitional package) Launchpad-Bugs-Fixed: 868545 Changes: flashplugin-nonfree (11.0.1.152ubuntu0.11.04.1) natty-security; urgency=low . * New upstream release 11.0.1.152 (LP: #868545) - debian/{config,postinst}: Updated sha256sums and version. Checksums-Sha1: b997f85ab8f05ceb92e59d34deda05e2ae930c97 1635 flashplugin-nonfree_11.0.1.152ubuntu0.11.04.1.dsc 6caf0d9a87fad25ba4bd8a183fc06ec6241704b4 27925 flashplugin-nonfree_11.0.1.152ubuntu0.11.04.1.tar.gz Checksums-Sha256: 9e8e6e10f1ea951ba23c1ea5aeb50666c0199764919f7e38456e4d3658a915cf 1635 flashplugin-nonfree_11.0.1.152ubuntu0.11.04.1.dsc b6d257de5052b9343e4622bee657c92f7cd31b68c5bc44c336f68a7669baed76 27925 flashplugin-nonfree_11.0.1.152ubuntu0.11.04.1.tar.gz Files: 4c66dc87292570bbe3181b999db05104 1635 contrib/web optional flashplugin-nonfree_11.0.1.152ubuntu0.11.04.1.dsc e25293e6ee616062ece310beeccffccf 27925 contrib/web optional flashplugin-nonfree_11.0.1.152ubuntu0.11.04.1.tar.gz Original-Maintainer: Bart Martens From om26er at ubuntu.com Tue Oct 11 07:37:35 2011 From: om26er at ubuntu.com (Omer Akram) Date: Tue, 11 Oct 2011 07:37:35 -0000 Subject: [ubuntu/natty-proposed] unity 3.8.16-0ubuntu1~natty3 (Accepted) Message-ID: <20111011073735.588.97280.launchpad@gac.canonical.com> unity (3.8.16-0ubuntu1~natty3) natty-proposed; urgency=low * src/PanelTray.cpp: * src/PanelTray.h: - make systray behave nice when the whitelist is on (LP: #761409) * src/IndicatorObjectEntryProxyRemote.cpp: - Fix leak of GMemoryInputStream. (thx hyperair) (LP: #816632) Date: Tue, 06 Sep 2011 00:09:33 +0500 Changed-By: Omer Akram Maintainer: Ubuntu Core Developers Signed-By: Bryce Harrington https://launchpad.net/ubuntu/natty/+source/unity/3.8.16-0ubuntu1~natty3 -------------- next part -------------- Format: 1.8 Date: Tue, 06 Sep 2011 00:09:33 +0500 Source: unity Binary: unity unity-common netbook-launcher Architecture: source Version: 3.8.16-0ubuntu1~natty3 Distribution: natty-proposed Urgency: low Maintainer: Ubuntu Core Developers Changed-By: Omer Akram Description: netbook-launcher - transitional package unity - Interface designed for efficiency of space and interaction. unity-common - Common files for the Unity interface. Launchpad-Bugs-Fixed: 761409 816632 Changes: unity (3.8.16-0ubuntu1~natty3) natty-proposed; urgency=low . * src/PanelTray.cpp: * src/PanelTray.h: - make systray behave nice when the whitelist is on (LP: #761409) * src/IndicatorObjectEntryProxyRemote.cpp: - Fix leak of GMemoryInputStream. (thx hyperair) (LP: #816632) Checksums-Sha1: b6858d2f2734c4a663d559cc6c84b2047e7b5a6b 1918 unity_3.8.16-0ubuntu1~natty3.dsc d4d7cd4b6cde50c9bb6966e2d8d41ff2c4aee424 34615 unity_3.8.16-0ubuntu1~natty3.diff.gz Checksums-Sha256: eaab7f9044fe2edb762697dbb65734366681f46a4188793302c5fe9ddf73fc3a 1918 unity_3.8.16-0ubuntu1~natty3.dsc 2a336bb2889933903abb81d888c61b03c3075bfb43d5d20ddf39cdc576be049a 34615 unity_3.8.16-0ubuntu1~natty3.diff.gz Files: a4f462b7c6f877a6091c59dbf86300c7 1918 gnome optional unity_3.8.16-0ubuntu1~natty3.dsc 44d8188f7ff3d8ac67bacb7d30778981 34615 gnome optional unity_3.8.16-0ubuntu1~natty3.diff.gz From dc at 0xdc.org Tue Oct 11 07:38:05 2011 From: dc at 0xdc.org (Robert BARABAS) Date: Tue, 11 Oct 2011 07:38:05 -0000 Subject: [ubuntu/natty-proposed] libdvdread 4.1.3-10ubuntu3.1 (Accepted) Message-ID: <20111011073805.1146.71950.launchpad@gac.canonical.com> libdvdread (4.1.3-10ubuntu3.1) natty-proposed; urgency=low * debian/patches/101-fix-msb-unicode.patch: Fixes unicode issue encountered when playing DVDs with newer protection. (LP: #852345) Date: Sun, 18 Sep 2011 13:56:04 -0400 Changed-By: Robert BARABAS Maintainer: Ubuntu Developers Signed-By: Bryce Harrington https://launchpad.net/ubuntu/natty/+source/libdvdread/4.1.3-10ubuntu3.1 -------------- next part -------------- Format: 1.8 Date: Sun, 18 Sep 2011 13:56:04 -0400 Source: libdvdread Binary: libdvdread4 libdvdread-dbg libdvdread-dev Architecture: source Version: 4.1.3-10ubuntu3.1 Distribution: natty-proposed Urgency: low Maintainer: Ubuntu Developers Changed-By: Robert BARABAS Description: libdvdread-dbg - library for reading DVDs (debug) libdvdread-dev - library for reading DVDs (development) libdvdread4 - library for reading DVDs Launchpad-Bugs-Fixed: 852345 Changes: libdvdread (4.1.3-10ubuntu3.1) natty-proposed; urgency=low . * debian/patches/101-fix-msb-unicode.patch: Fixes unicode issue encountered when playing DVDs with newer protection. (LP: #852345) Checksums-Sha1: 5f0d7bb625ad8d5b82c1c2dc3f9c61289f0c74aa 1365 libdvdread_4.1.3-10ubuntu3.1.dsc a8073db9aa3a08afa03551f2ae66253cc0cb22e2 14638 libdvdread_4.1.3-10ubuntu3.1.diff.gz Checksums-Sha256: d4a1ce3f9f8c6fd58d98577c0ba2575be785d4a149e40a5d6c1062a48ac5931a 1365 libdvdread_4.1.3-10ubuntu3.1.dsc 9ee97dbe0b3c8e931e328b266dbf17bce7b99e8197120a91a767003f2b721c8f 14638 libdvdread_4.1.3-10ubuntu3.1.diff.gz Files: c52801224eeac07f0ffc046ed4a17b0b 1365 graphics optional libdvdread_4.1.3-10ubuntu3.1.dsc fa1c44630ce27ec93efeaf0b8b191ed7 14638 graphics optional libdvdread_4.1.3-10ubuntu3.1.diff.gz Original-Maintainer: Daniel Baumann From jesstess at mit.edu Tue Oct 11 07:38:34 2011 From: jesstess at mit.edu (Jessica McKellar) Date: Tue, 11 Oct 2011 07:38:34 -0000 Subject: [ubuntu/natty-proposed] python-meld3 0.6.5-3ubuntu0.11.04.1 (Accepted) Message-ID: <20111011073834.1146.60972.launchpad@gac.canonical.com> python-meld3 (0.6.5-3ubuntu0.11.04.1) natty-proposed; urgency=low * Apply most of commit afe92611 upstream to make the package compatible with Python 2.7. (LP: #749880) Date: Sun, 02 Oct 2011 16:08:55 -0400 Changed-By: Jessica McKellar Maintainer: Ubuntu Developers Signed-By: Colin Watson https://launchpad.net/ubuntu/natty/+source/python-meld3/0.6.5-3ubuntu0.11.04.1 -------------- next part -------------- Format: 1.8 Date: Sun, 02 Oct 2011 16:08:55 -0400 Source: python-meld3 Binary: python-meld3 Architecture: source Version: 0.6.5-3ubuntu0.11.04.1 Distribution: natty-proposed Urgency: low Maintainer: Ubuntu Developers Changed-By: Jessica McKellar Description: python-meld3 - An HTML/XML templating system for Python Launchpad-Bugs-Fixed: 749880 Changes: python-meld3 (0.6.5-3ubuntu0.11.04.1) natty-proposed; urgency=low . * Apply most of commit afe92611 upstream to make the package compatible with Python 2.7. (LP: #749880) Checksums-Sha1: 64b69693132a385a1a33a1d05e68189631c0eae3 1955 python-meld3_0.6.5-3ubuntu0.11.04.1.dsc 454d037596beef1a5fedf363e7d1345b08efe700 4148 python-meld3_0.6.5-3ubuntu0.11.04.1.diff.gz Checksums-Sha256: 04b2da414ce97f7e80b974d26358df3501b4518320be01dd982c176b67dfb788 1955 python-meld3_0.6.5-3ubuntu0.11.04.1.dsc 60d30f7f154523413060598259e29f55bae92f5b8785c5d52b1c1d2afb06bb1c 4148 python-meld3_0.6.5-3ubuntu0.11.04.1.diff.gz Files: d9d167b490f68186941c4291126b29ca 1955 python extra python-meld3_0.6.5-3ubuntu0.11.04.1.dsc 8770d1c0fe4a7d35b1ed1f4a3e92b332 4148 python extra python-meld3_0.6.5-3ubuntu0.11.04.1.diff.gz Original-Maintainer: Anders Hammarquist From lfaraone at ubuntu.com Tue Oct 11 07:40:05 2011 From: lfaraone at ubuntu.com (Luke Faraone) Date: Tue, 11 Oct 2011 07:40:05 -0000 Subject: [ubuntu/natty-proposed] pithos 0.3.9-1~ubuntu3 (Accepted) Message-ID: <20111011074005.23604.73789.launchpad@chaenomeles.canonical.com> pithos (0.3.9-1~ubuntu3) natty-proposed; urgency=low * Support protocol 32. (LP: #856035) Date: Fri, 30 Sep 2011 14:22:37 -0400 Changed-By: Luke Faraone https://launchpad.net/ubuntu/natty/+source/pithos/0.3.9-1~ubuntu3 -------------- next part -------------- Format: 1.8 Date: Fri, 30 Sep 2011 14:22:37 -0400 Source: pithos Binary: pithos Architecture: source Version: 0.3.9-1~ubuntu3 Distribution: natty-proposed Urgency: low Maintainer: Luke Faraone Changed-By: Luke Faraone Description: pithos - Pandora Radio client for the GNOME desktop Launchpad-Bugs-Fixed: 856035 Changes: pithos (0.3.9-1~ubuntu3) natty-proposed; urgency=low . * Support protocol 32. (LP: #856035) Checksums-Sha1: f793aa687fbe2b94ceec5f23e98578465aca7f39 1905 pithos_0.3.9-1~ubuntu3.dsc 0cfd603acc16ae551a3e3faa8583dcab0ac0e4dd 5329 pithos_0.3.9-1~ubuntu3.debian.tar.gz Checksums-Sha256: 729f90a3dc3d363c451aec13f59c098632642c504e34ec7b62d1dc2c4ec85e4a 1905 pithos_0.3.9-1~ubuntu3.dsc 6670592370ca21fbc27490fe471726784f77a6604e73aae30251d1fb7aac1f81 5329 pithos_0.3.9-1~ubuntu3.debian.tar.gz Files: ec78d3deb8a61015a4e9651561e385d0 1905 gnome optional pithos_0.3.9-1~ubuntu3.dsc 287e271a7ed8535af1f5a4204f7c8598 5329 gnome optional pithos_0.3.9-1~ubuntu3.debian.tar.gz From jtaylor.debian at googlemail.com Tue Oct 11 07:40:42 2011 From: jtaylor.debian at googlemail.com (Julian Taylor) Date: Tue, 11 Oct 2011 07:40:42 -0000 Subject: [ubuntu/natty-proposed] singularity 0.30c-0ubuntu0.1 (Accepted) Message-ID: <20111011074042.1892.38560.launchpad@gac.canonical.com> singularity (0.30c-0ubuntu0.1) natty-proposed; urgency=low * New upstream bugfix release. - fixes incompatibility with python 2.7 (LP: #576504) Date: Wed, 05 Oct 2011 18:50:48 +0200 Changed-By: Julian Taylor Maintainer: Ubuntu Developers Signed-By: Daniel Holbach https://launchpad.net/ubuntu/natty/+source/singularity/0.30c-0ubuntu0.1 -------------- next part -------------- Format: 1.8 Date: Wed, 05 Oct 2011 18:50:48 +0200 Source: singularity Binary: singularity Architecture: source Version: 0.30c-0ubuntu0.1 Distribution: natty-proposed Urgency: low Maintainer: Ubuntu Developers Changed-By: Julian Taylor Description: singularity - game where one becomes the singularity Launchpad-Bugs-Fixed: 576504 Changes: singularity (0.30c-0ubuntu0.1) natty-proposed; urgency=low . * New upstream bugfix release. - fixes incompatibility with python 2.7 (LP: #576504) Checksums-Sha1: 863d9c51e1ec486f47abf0de70a430e7fd62d3ef 1229 singularity_0.30c-0ubuntu0.1.dsc f4cb2d9e7a04cf22fe76c58b482c568c817baa02 2265133 singularity_0.30c.orig.tar.gz 7dedf718d042c850e2adb6e856c3f4fb61caa621 35302 singularity_0.30c-0ubuntu0.1.debian.tar.gz Checksums-Sha256: 69ef88af1187b50720d8276eaf1b1e35d71c62d4d6145b29e49a86b0c4fb5f5a 1229 singularity_0.30c-0ubuntu0.1.dsc f4759fc059ef136c2d4d9668a021b14922dd7300ab5f37ed318ad6778c83f28f 2265133 singularity_0.30c.orig.tar.gz 94c2fa6c1cbf9cf37137874f65423654732c77a1328bea4cff1dea849ac9401a 35302 singularity_0.30c-0ubuntu0.1.debian.tar.gz Files: 24827b3023164deeefcec34857b72f60 1229 games optional singularity_0.30c-0ubuntu0.1.dsc ea4e7d28dd19c33585691ee608672a63 2265133 games optional singularity_0.30c.orig.tar.gz b704b5a6dfaf4d804496c26c9089d88f 35302 games optional singularity_0.30c-0ubuntu0.1.debian.tar.gz Original-Maintainer: Kari Pahula From bigras.bruno at gmail.com Tue Oct 11 07:41:06 2011 From: bigras.bruno at gmail.com (Bruno Bigras) Date: Tue, 11 Oct 2011 07:41:06 -0000 Subject: [ubuntu/natty-proposed] lfm 2.2-1ubuntu0.11.04.1 (Accepted) Message-ID: <20111011074106.24002.28778.launchpad@chaenomeles.canonical.com> lfm (2.2-1ubuntu0.11.04.1) natty-proposed; urgency=low * Fix a crash at startup, because of UnicodeDecodeError (LP: #786491) Date: Sat, 17 Sep 2011 22:19:56 -0400 Changed-By: Bruno Bigras Maintainer: Ubuntu Developers Signed-By: Daniel Holbach https://launchpad.net/ubuntu/natty/+source/lfm/2.2-1ubuntu0.11.04.1 -------------- next part -------------- Format: 1.8 Date: Sat, 17 Sep 2011 22:19:56 -0400 Source: lfm Binary: lfm Architecture: source Version: 2.2-1ubuntu0.11.04.1 Distribution: natty-proposed Urgency: low Maintainer: Ubuntu Developers Changed-By: Bruno Bigras Description: lfm - simple but powerful file manager for the UNIX console Launchpad-Bugs-Fixed: 786491 Changes: lfm (2.2-1ubuntu0.11.04.1) natty-proposed; urgency=low . * Fix a crash at startup, because of UnicodeDecodeError (LP: #786491) Checksums-Sha1: 4fa7b2f7fd36f72a887f4334de7e345b5d973b2d 1217 lfm_2.2-1ubuntu0.11.04.1.dsc 0f91d48e2966854ba87d031ade910374cc53f430 212754 lfm_2.2-1ubuntu0.11.04.1.debian.tar.gz Checksums-Sha256: 3791b30be1ea50aae2ae30c268af51cf9b9aef5fa6d0be70610242719eca4f74 1217 lfm_2.2-1ubuntu0.11.04.1.dsc 55e7f432853e223cde9cd870381f0e5d2f1a8176bac3c578135a7b56f6476533 212754 lfm_2.2-1ubuntu0.11.04.1.debian.tar.gz Files: 663818d4e68a424e499759b46ef5eeb0 1217 utils optional lfm_2.2-1ubuntu0.11.04.1.dsc 64426cb58183c2104282b6613f25aa3a 212754 utils optional lfm_2.2-1ubuntu0.11.04.1.debian.tar.gz Original-Maintainer: Chris Silva From martin.pitt at ubuntu.com Wed Oct 12 04:35:49 2011 From: martin.pitt at ubuntu.com (Martin Pitt) Date: Wed, 12 Oct 2011 04:35:49 -0000 Subject: [ubuntu/natty-proposed] libimobiledevice 1.1.0-3ubuntu1 (Accepted) Message-ID: <20111012043549.13882.31785.launchpad@wampee.canonical.com> libimobiledevice (1.1.0-3ubuntu1) natty-proposed; urgency=low * Add 00git_ios5_support.patch: Fix "Unhandled lockdown error" for iOS 5. (LP: #795475) Date: Fri, 07 Oct 2011 18:01:41 +0200 Changed-By: Martin Pitt Maintainer: Ubuntu Developers https://launchpad.net/ubuntu/natty/+source/libimobiledevice/1.1.0-3ubuntu1 -------------- next part -------------- Format: 1.8 Date: Fri, 07 Oct 2011 18:01:41 +0200 Source: libimobiledevice Binary: libimobiledevice2 libimobiledevice-dev libimobiledevice2-dbg python-imobiledevice libimobiledevice-utils libimobiledevice-doc Architecture: source Version: 1.1.0-3ubuntu1 Distribution: natty-proposed Urgency: low Maintainer: Ubuntu Developers Changed-By: Martin Pitt Description: libimobiledevice-dev - Library for communicating with iPhone and iPod Touch devices libimobiledevice-doc - Library for communicating with iPhone and iPod Touch devices libimobiledevice-utils - Library for communicating with iPhone and iPod Touch devices libimobiledevice2 - Library for communicating with the iPhone and iPod Touch libimobiledevice2-dbg - Library for communicating with iPhone and iPod Touch devices python-imobiledevice - Library for communicating with iPhone and iPod Touch devices Launchpad-Bugs-Fixed: 795475 Changes: libimobiledevice (1.1.0-3ubuntu1) natty-proposed; urgency=low . * Add 00git_ios5_support.patch: Fix "Unhandled lockdown error" for iOS 5. (LP: #795475) Checksums-Sha1: 40128a5d3aa92d464d0f7877dce893476ba9feb8 2537 libimobiledevice_1.1.0-3ubuntu1.dsc b3112fe8908bf1911239b0f7d6ba4dea0b5af348 9436 libimobiledevice_1.1.0-3ubuntu1.debian.tar.gz Checksums-Sha256: 31bbf9988723464f9f9b9d74a1d80a47b9a8b9962a7b1a9c9f1a82b75f5807b6 2537 libimobiledevice_1.1.0-3ubuntu1.dsc b2f376e3126f3a581f9faff0073073dd3f0dc54bb1128883a7af895d887b952e 9436 libimobiledevice_1.1.0-3ubuntu1.debian.tar.gz Files: 5f19d8bcfff2d5bc4a76a7de0a11185e 2537 libs optional libimobiledevice_1.1.0-3ubuntu1.dsc 344393cdeedd341569ab147728d9fbec 9436 libs optional libimobiledevice_1.1.0-3ubuntu1.debian.tar.gz Original-Maintainer: gtkpod Maintainers From rodney.dawes at ubuntu.com Wed Oct 12 04:35:30 2011 From: rodney.dawes at ubuntu.com (Rodney Dawes) Date: Wed, 12 Oct 2011 04:35:30 -0000 Subject: [ubuntu/natty-proposed] ubuntuone-client 1.6.2-0ubuntu2 (Accepted) Message-ID: <20111012043530.30221.34422.launchpad@soybean.canonical.com> ubuntuone-client (1.6.2-0ubuntu2) natty-proposed; urgency=low * debian/patches/01_getnodebyid_fix.patch: - Fix filter by share and path (LP: #807737) Date: Tue, 11 Oct 2011 15:42:40 -0400 Changed-By: Rodney Dawes Maintainer: Ubuntu Developers https://launchpad.net/ubuntu/natty/+source/ubuntuone-client/1.6.2-0ubuntu2 -------------- next part -------------- Format: 1.8 Date: Tue, 11 Oct 2011 15:42:40 -0400 Source: ubuntuone-client Binary: ubuntuone-client ubuntuone-client-gnome python-ubuntuone-client libsyncdaemon-1.0-1 libsyncdaemon-1.0-dev gir1.2-syncdaemon-1.0 ubuntuone-client-dbg Architecture: source Version: 1.6.2-0ubuntu2 Distribution: natty-proposed Urgency: low Maintainer: Ubuntu Developers Changed-By: Rodney Dawes Description: gir1.2-syncdaemon-1.0 - Ubuntu One synchronization daemon library libsyncdaemon-1.0-1 - Ubuntu One synchronization daemon library libsyncdaemon-1.0-dev - Ubuntu One synchronization daemon library python-ubuntuone-client - Ubuntu One client Python libraries ubuntuone-client - Ubuntu One client ubuntuone-client-dbg - Debugging symbols for ubuntuone-client ubuntuone-client-gnome - Ubuntu One client GNOME integration Launchpad-Bugs-Fixed: 807737 Changes: ubuntuone-client (1.6.2-0ubuntu2) natty-proposed; urgency=low . * debian/patches/01_getnodebyid_fix.patch: - Fix filter by share and path (LP: #807737) Checksums-Sha1: e491e6f289b6aef12da5e099a477cb0925c71568 1718 ubuntuone-client_1.6.2-0ubuntu2.dsc acf743c0287e41c7505d13d2cd452450ee20e9b1 1294639 ubuntuone-client_1.6.2.orig.tar.gz f83473fd7172983803016979c40a9c4062a84bef 23698 ubuntuone-client_1.6.2-0ubuntu2.debian.tar.gz Checksums-Sha256: 5ce80568088bcb7d4df2c59a4013e9da6124ecee4b8222c934f7f592fe9cace9 1718 ubuntuone-client_1.6.2-0ubuntu2.dsc 933dca244e0b1eefc322cbf350cbf4d9c314d430f73a4defd7ff3f3b242ff8d3 1294639 ubuntuone-client_1.6.2.orig.tar.gz e386732fbe56e799463aa488489d8420102c08d48d70eedefb5c99b172a6cee1 23698 ubuntuone-client_1.6.2-0ubuntu2.debian.tar.gz Files: 5ca795f0dcc67cfae591ffb54bfd6087 1718 net optional ubuntuone-client_1.6.2-0ubuntu2.dsc 52f0835ba18fffe8af38e3b52e11248f 1294639 net optional ubuntuone-client_1.6.2.orig.tar.gz fa4a6634a8829fb9374dff556d2de8a6 23698 net optional ubuntuone-client_1.6.2-0ubuntu2.debian.tar.gz Original-Maintainer: Rick McBride From debfx-pkg at fobos.de Wed Oct 12 20:03:19 2011 From: debfx-pkg at fobos.de (Felix Geyer) Date: Wed, 12 Oct 2011 20:03:19 -0000 Subject: [ubuntu/natty-security] rails 2.3.5-1.2ubuntu1.1 (Accepted) Message-ID: <20111012200319.26927.98791.launchpad@cocoplum.canonical.com> rails (2.3.5-1.2ubuntu1.1) natty-security; urgency=low * SECURITY UPDATE: multiple cross-site scripting (XSS) vulnerabilities in the mail_to helper - Add 0001-Be-sure-to-javascript_escape-the-email-address-to-pr.patch from Debian and fix Debian bug #629067 by replacing .html_safe with html_escape() - https://groups.google.com/group/rubyonrails-security/browse_thread/thread/f02a48ede8315f81 - CVE-2011-0446 - LP: #870846 * SECURITY UPDATE: rails does not properly validate HTTP requests that contain an X-Requested-With header - Add 0002-Change-the-CSRF-whitelisting-to-only-apply-to-get-re.patch from Debian - https://groups.google.com/group/rubyonrails-security/browse_thread/thread/2d95a3cc23e03665 - CVE-2011-0447 * SECURITY UPDATE: multiple SQL injection vulnerabilities in the quote_table_name method in the ActiveRecord adapters - Add CVE-2011-2930.patch from Debian - https://groups.google.com/group/rubyonrails-security/browse_thread/thread/6a1e473744bc389b - CVE-2011-2930 * SECURITY UPDATE: cross-site scripting (XSS) vulnerability in the strip_tags helper - Add CVE-2011-2931.patch from Debian - https://groups.google.com/group/rubyonrails-security/browse_thread/thread/2b9130749b74ea12 - CVE-2011-2931 * SECURITY UPDATE: cross-site scripting vulnerability which allows remote attackers to inject arbitrary web script or HTML via a malformed Unicode string - Add CVE-2011-2932.patch, backported from upstream - https://groups.google.com/group/rubyonrails-security/browse_thread/thread/56bffb5923ab1195 - CVE-2011-2932 * SECURITY UPDATE: response splitting vulnerability - Add CVE-2011-3186.patch from Debian - https://groups.google.com/group/rubyonrails-security/browse_thread/thread/6ffc93bde0298768 - CVE-2011-3186 Date: Wed, 12 Oct 2011 20:05:02 +0200 Changed-By: Felix Geyer Maintainer: Ubuntu Developers https://launchpad.net/ubuntu/natty/+source/rails/2.3.5-1.2ubuntu1.1 -------------- next part -------------- Format: 1.8 Date: Wed, 12 Oct 2011 20:05:02 +0200 Source: rails Binary: rails rails-ruby1.8 rails-doc libactiverecord-ruby libactiverecord-ruby1.8 libactiverecord-ruby1.9.1 libactivesupport-ruby libactivesupport-ruby1.8 libactivesupport-ruby1.9.1 libactionpack-ruby libactionpack-ruby1.8 libactionmailer-ruby libactionmailer-ruby1.8 libactiveresource-ruby libactiveresource-ruby1.8 Architecture: source Version: 2.3.5-1.2ubuntu1.1 Distribution: natty-security Urgency: low Maintainer: Ubuntu Developers Changed-By: Felix Geyer Description: libactionmailer-ruby - Framework for generation of customized email messages libactionmailer-ruby1.8 - Framework for generation of customized email messages libactionpack-ruby - Controller and View framework used by Rails libactionpack-ruby1.8 - Controller and View framework used by Rails libactiverecord-ruby - ORM database interface for ruby libactiverecord-ruby1.8 - ORM database interface for ruby libactiverecord-ruby1.9.1 - ORM database interface for ruby libactiveresource-ruby - Connects objects and REST web services libactiveresource-ruby1.8 - Connects objects and REST web services libactivesupport-ruby - utility classes and extensions (Ruby 1.8) libactivesupport-ruby1.8 - utility classes and extensions (Ruby 1.8) libactivesupport-ruby1.9.1 - utility classes and extensions (Ruby 1.8) rails - MVC ruby based framework geared for web application development rails-doc - Documentation for rails, a MVC ruby based framework rails-ruby1.8 - MVC ruby based framework geared for web application development Launchpad-Bugs-Fixed: 870846 Changes: rails (2.3.5-1.2ubuntu1.1) natty-security; urgency=low . * SECURITY UPDATE: multiple cross-site scripting (XSS) vulnerabilities in the mail_to helper - Add 0001-Be-sure-to-javascript_escape-the-email-address-to-pr.patch from Debian and fix Debian bug #629067 by replacing .html_safe with html_escape() - https://groups.google.com/group/rubyonrails-security/browse_thread/thread/f02a48ede8315f81 - CVE-2011-0446 - LP: #870846 * SECURITY UPDATE: rails does not properly validate HTTP requests that contain an X-Requested-With header - Add 0002-Change-the-CSRF-whitelisting-to-only-apply-to-get-re.patch from Debian - https://groups.google.com/group/rubyonrails-security/browse_thread/thread/2d95a3cc23e03665 - CVE-2011-0447 * SECURITY UPDATE: multiple SQL injection vulnerabilities in the quote_table_name method in the ActiveRecord adapters - Add CVE-2011-2930.patch from Debian - https://groups.google.com/group/rubyonrails-security/browse_thread/thread/6a1e473744bc389b - CVE-2011-2930 * SECURITY UPDATE: cross-site scripting (XSS) vulnerability in the strip_tags helper - Add CVE-2011-2931.patch from Debian - https://groups.google.com/group/rubyonrails-security/browse_thread/thread/2b9130749b74ea12 - CVE-2011-2931 * SECURITY UPDATE: cross-site scripting vulnerability which allows remote attackers to inject arbitrary web script or HTML via a malformed Unicode string - Add CVE-2011-2932.patch, backported from upstream - https://groups.google.com/group/rubyonrails-security/browse_thread/thread/56bffb5923ab1195 - CVE-2011-2932 * SECURITY UPDATE: response splitting vulnerability - Add CVE-2011-3186.patch from Debian - https://groups.google.com/group/rubyonrails-security/browse_thread/thread/6ffc93bde0298768 - CVE-2011-3186 Checksums-Sha1: f746235efc94e43dbbf4d3b0ead17bcff025b6aa 2410 rails_2.3.5-1.2ubuntu1.1.dsc 8922f52e7d2b12e9950aab2cb67563d8ea2a2128 25868 rails_2.3.5-1.2ubuntu1.1.debian.tar.gz Checksums-Sha256: 1963f358d1df23617d8137929664a4a0c5038422eb19facf92d4f128634f7942 2410 rails_2.3.5-1.2ubuntu1.1.dsc e576fa250ac709d8f5af42d8dd5fbb3d29c061cd731ccef99d4f52ff9323d923 25868 rails_2.3.5-1.2ubuntu1.1.debian.tar.gz Files: 75acfa2cbf3fa975b809b80afe7606bf 2410 ruby optional rails_2.3.5-1.2ubuntu1.1.dsc d0501e38ce5ed6ad4359b0794bdf5703 25868 ruby optional rails_2.3.5-1.2ubuntu1.1.debian.tar.gz Original-Maintainer: Adam Majer From martin.pitt at ubuntu.com Thu Oct 13 13:04:09 2011 From: martin.pitt at ubuntu.com (Martin Pitt) Date: Thu, 13 Oct 2011 13:04:09 -0000 Subject: [ubuntu/natty-security] postgresql-8.4, postgresql-8.4_8.4.9-0ubuntu0.11.04_i386_translations.tar.gz, postgresql-8.4_8.4.9-0ubuntu0.11.04_amd64_translations.tar.gz, postgresql-8.4_8.4.9-0ubuntu0.11.04_powerpc_translations.tar.gz, postgresql-8.4_8.4.9-0ubuntu0.11.04_armel_translations.tar.gz 8.4.9-0ubuntu0.11.04 (Accepted) Message-ID: <20111013130409.502.91959.launchpad@cocoplum.canonical.com> postgresql-8.4 (8.4.9-0ubuntu0.11.04) natty-security; urgency=low * New upstream bug fix/security release: (LP: #866049) - Fix bugs in indexing of in-doubt HOT-updated tuples. These bugs could result in index corruption after reindexing a system catalog. They are not believed to affect user indexes. - Fix multiple bugs in GiST index page split processing. The probability of occurrence was low, but these could lead to index corruption. - Fix possible buffer overrun in tsvector_concat(). The function could underestimate the amount of memory needed for its result, leading to server crashes. - Fix crash in xml_recv when processing a "standalone" parameter. - Make pg_options_to_table return NULL for an option with no value. Previously such cases would result in a server crash. - Avoid possibly accessing off the end of memory in "ANALYZE" and in SJIS-2004 encoding conversion. This fixes some very-low-probability server crash scenarios. - Prevent intermittent hang in interactions of startup process with bgwriter process. This affected recovery in non-hot-standby cases. - Fix race condition in relcache init file invalidation. There was a window wherein a new backend process could read a stale init file but miss the inval messages that would tell it the data is stale. The result would be bizarre failures in catalog accesses, typically "could not read block 0 in file ..." later during startup. - Fix memory leak at end of a GiST index scan. Commands that perform many separate GiST index scans, such as verification of a new GiST-based exclusion constraint on a table already containing many rows, could transiently require large amounts of memory due to this leak. - Fix incorrect memory accounting (leading to possible memory bloat) in tuplestores supporting holdable cursors and plpgsql's RETURN NEXT command. - Fix performance problem when constructing a large, lossy bitmap. - Fix join selectivity estimation for unique columns. This fixes an erroneous planner heuristic that could lead to poor estimates of the result size of a join. - Fix nested PlaceHolderVar expressions that appear only in sub-select target lists. This mistake could result in outputs of an outer join incorrectly appearing as NULL. - Allow nested EXISTS queries to be optimized properly. - Fix array- and path-creating functions to ensure padding bytes are zeroes. This avoids some situations where the planner will think that semantically-equal constants are not equal, resulting in poor optimization. - Fix "EXPLAIN" to handle gating Result nodes within inner-indexscan subplans. The usual symptom of this oversight was "bogus varno" errors. - Work around gcc 4.6.0 bug that breaks WAL replay. This could lead to loss of committed transactions after a server crash. - Fix dump bug for VALUES in a view. - Disallow SELECT FOR UPDATE/SHARE on sequences. This operation doesn't work as expected and can lead to failures. - Fix "VACUUM" so that it always updates pg_class.reltuples/relpages. This fixes some scenarios where autovacuum could make increasingly poor decisions about when to vacuum tables. - Defend against integer overflow when computing size of a hash table. - Fix cases where "CLUSTER" might attempt to access already-removed TOAST data. - Fix portability bugs in use of credentials control messages for "peer" authentication. - Fix SSPI login when multiple roundtrips are required. The typical symptom of this problem was "The function requested is not supported" errors during SSPI login. - Throw an error if "pg_hba.conf" contains hostssl but SSL is disabled. This was concluded to be more user-friendly than the previous behavior of silently ignoring such lines. - Fix typo in pg_srand48 seed initialization. This led to failure to use all bits of the provided seed. This function is not used on most platforms (only those without srandom), and the potential security exposure from a less-random-than-expected seed seems minimal in any case. - Avoid integer overflow when the sum of LIMIT and OFFSET values exceeds 2^63. - Add overflow checks to int4 and int8 versions of generate_series(). - Fix trailing-zero removal in to_char(). In a format with FM and no digit positions after the decimal point, zeroes to the left of the decimal point could be removed incorrectly. - Fix pg_size_pretty() to avoid overflow for inputs close to 2^63. - Weaken plpgsql's check for typmod matching in record values. An overly enthusiastic check could lead to discarding length modifiers that should have been kept. - Fix pg_upgrade to preserve toast tables' relfrozenxids during an upgrade from 8.3. Failure to do this could lead to "pg_clog" files being removed too soon after the upgrade. - Fix psql's counting of script file line numbers during COPY from a different file. - Fix pg_restore's direct-to-database mode for standard_conforming_strings. pg_restore could emit incorrect commands when restoring directly to a database server from an archive file that had been made with standard_conforming_strings set to on. - Be more user-friendly about unsupported cases for parallel pg_restore. This change ensures that such cases are detected and reported before any restore actions have been taken. - Fix write-past-buffer-end and memory leak in libpq's LDAP service lookup code. - In libpq, avoid failures when using nonblocking I/O and an SSL connection. - Improve libpq's handling of failures during connection startup. In particular, the response to a server report of fork() failure during SSL connection startup is now saner. - Improve libpq's error reporting for SSL failures. - Fix PQsetvalue() to avoid possible crash when adding a new tuple to a PGresult originally obtained from a server query. - Make ecpglib write double values with 15 digits precision. - In ecpglib, be sure LC_NUMERIC setting is restored after an error. - Apply upstream fix for blowfish signed-character bug (CVE-2011-2483) (Closes: #631285) "contrib/pg_crypto"'s blowfish encryption code could give wrong results on platforms where char is signed (which is most), leading to encrypted passwords being weaker than they should be. - Fix memory leak in "contrib/seg". - Fix pgstatindex() to give consistent results for empty indexes. - Allow building with perl 5.14. (Closes: #628503) Date: Tue, 04 Oct 2011 12:00:41 +0200 Changed-By: Martin Pitt Maintainer: Ubuntu Developers https://launchpad.net/ubuntu/natty/+source/postgresql-8.4/8.4.9-0ubuntu0.11.04 -------------- next part -------------- Format: 1.8 Date: Tue, 04 Oct 2011 12:00:41 +0200 Source: postgresql-8.4 Binary: libpq-dev libpq5 libecpg6 libecpg-dev libecpg-compat3 libpgtypes3 postgresql-8.4 postgresql-client-8.4 postgresql-server-dev-8.4 postgresql-doc-8.4 postgresql-contrib-8.4 postgresql-plperl-8.4 postgresql-plpython-8.4 postgresql-pltcl-8.4 postgresql postgresql-client postgresql-doc postgresql-contrib Architecture: source Version: 8.4.9-0ubuntu0.11.04 Distribution: natty-security Urgency: low Maintainer: Ubuntu Developers Changed-By: Martin Pitt Description: libecpg-compat3 - older version of run-time library for ECPG programs libecpg-dev - development files for ECPG (Embedded PostgreSQL for C) libecpg6 - run-time library for ECPG programs libpgtypes3 - shared library libpgtypes for PostgreSQL 8.4 libpq-dev - header files for libpq5 (PostgreSQL library) libpq5 - PostgreSQL C client library postgresql - object-relational SQL database (supported version) postgresql-8.4 - object-relational SQL database, version 8.4 server postgresql-client - front-end programs for PostgreSQL (supported version) postgresql-client-8.4 - front-end programs for PostgreSQL 8.4 postgresql-contrib - additional facilities for PostgreSQL (supported version) postgresql-contrib-8.4 - additional facilities for PostgreSQL postgresql-doc - documentation for the PostgreSQL database management system postgresql-doc-8.4 - documentation for the PostgreSQL database management system postgresql-plperl-8.4 - PL/Perl procedural language for PostgreSQL 8.4 postgresql-plpython-8.4 - PL/Python procedural language for PostgreSQL 8.4 postgresql-pltcl-8.4 - PL/Tcl procedural language for PostgreSQL 8.4 postgresql-server-dev-8.4 - development files for PostgreSQL 8.4 server-side programming Closes: 628503 631285 Launchpad-Bugs-Fixed: 866049 Changes: postgresql-8.4 (8.4.9-0ubuntu0.11.04) natty-security; urgency=low . * New upstream bug fix/security release: (LP: #866049) - Fix bugs in indexing of in-doubt HOT-updated tuples. These bugs could result in index corruption after reindexing a system catalog. They are not believed to affect user indexes. - Fix multiple bugs in GiST index page split processing. The probability of occurrence was low, but these could lead to index corruption. - Fix possible buffer overrun in tsvector_concat(). The function could underestimate the amount of memory needed for its result, leading to server crashes. - Fix crash in xml_recv when processing a "standalone" parameter. - Make pg_options_to_table return NULL for an option with no value. Previously such cases would result in a server crash. - Avoid possibly accessing off the end of memory in "ANALYZE" and in SJIS-2004 encoding conversion. This fixes some very-low-probability server crash scenarios. - Prevent intermittent hang in interactions of startup process with bgwriter process. This affected recovery in non-hot-standby cases. - Fix race condition in relcache init file invalidation. There was a window wherein a new backend process could read a stale init file but miss the inval messages that would tell it the data is stale. The result would be bizarre failures in catalog accesses, typically "could not read block 0 in file ..." later during startup. - Fix memory leak at end of a GiST index scan. Commands that perform many separate GiST index scans, such as verification of a new GiST-based exclusion constraint on a table already containing many rows, could transiently require large amounts of memory due to this leak. - Fix incorrect memory accounting (leading to possible memory bloat) in tuplestores supporting holdable cursors and plpgsql's RETURN NEXT command. - Fix performance problem when constructing a large, lossy bitmap. - Fix join selectivity estimation for unique columns. This fixes an erroneous planner heuristic that could lead to poor estimates of the result size of a join. - Fix nested PlaceHolderVar expressions that appear only in sub-select target lists. This mistake could result in outputs of an outer join incorrectly appearing as NULL. - Allow nested EXISTS queries to be optimized properly. - Fix array- and path-creating functions to ensure padding bytes are zeroes. This avoids some situations where the planner will think that semantically-equal constants are not equal, resulting in poor optimization. - Fix "EXPLAIN" to handle gating Result nodes within inner-indexscan subplans. The usual symptom of this oversight was "bogus varno" errors. - Work around gcc 4.6.0 bug that breaks WAL replay. This could lead to loss of committed transactions after a server crash. - Fix dump bug for VALUES in a view. - Disallow SELECT FOR UPDATE/SHARE on sequences. This operation doesn't work as expected and can lead to failures. - Fix "VACUUM" so that it always updates pg_class.reltuples/relpages. This fixes some scenarios where autovacuum could make increasingly poor decisions about when to vacuum tables. - Defend against integer overflow when computing size of a hash table. - Fix cases where "CLUSTER" might attempt to access already-removed TOAST data. - Fix portability bugs in use of credentials control messages for "peer" authentication. - Fix SSPI login when multiple roundtrips are required. The typical symptom of this problem was "The function requested is not supported" errors during SSPI login. - Throw an error if "pg_hba.conf" contains hostssl but SSL is disabled. This was concluded to be more user-friendly than the previous behavior of silently ignoring such lines. - Fix typo in pg_srand48 seed initialization. This led to failure to use all bits of the provided seed. This function is not used on most platforms (only those without srandom), and the potential security exposure from a less-random-than-expected seed seems minimal in any case. - Avoid integer overflow when the sum of LIMIT and OFFSET values exceeds 2^63. - Add overflow checks to int4 and int8 versions of generate_series(). - Fix trailing-zero removal in to_char(). In a format with FM and no digit positions after the decimal point, zeroes to the left of the decimal point could be removed incorrectly. - Fix pg_size_pretty() to avoid overflow for inputs close to 2^63. - Weaken plpgsql's check for typmod matching in record values. An overly enthusiastic check could lead to discarding length modifiers that should have been kept. - Fix pg_upgrade to preserve toast tables' relfrozenxids during an upgrade from 8.3. Failure to do this could lead to "pg_clog" files being removed too soon after the upgrade. - Fix psql's counting of script file line numbers during COPY from a different file. - Fix pg_restore's direct-to-database mode for standard_conforming_strings. pg_restore could emit incorrect commands when restoring directly to a database server from an archive file that had been made with standard_conforming_strings set to on. - Be more user-friendly about unsupported cases for parallel pg_restore. This change ensures that such cases are detected and reported before any restore actions have been taken. - Fix write-past-buffer-end and memory leak in libpq's LDAP service lookup code. - In libpq, avoid failures when using nonblocking I/O and an SSL connection. - Improve libpq's handling of failures during connection startup. In particular, the response to a server report of fork() failure during SSL connection startup is now saner. - Improve libpq's error reporting for SSL failures. - Fix PQsetvalue() to avoid possible crash when adding a new tuple to a PGresult originally obtained from a server query. - Make ecpglib write double values with 15 digits precision. - In ecpglib, be sure LC_NUMERIC setting is restored after an error. - Apply upstream fix for blowfish signed-character bug (CVE-2011-2483) (Closes: #631285) "contrib/pg_crypto"'s blowfish encryption code could give wrong results on platforms where char is signed (which is most), leading to encrypted passwords being weaker than they should be. - Fix memory leak in "contrib/seg". - Fix pgstatindex() to give consistent results for empty indexes. - Allow building with perl 5.14. (Closes: #628503) Checksums-Sha1: 766ea42d54ebfbd0ec6f9c6db46142da041a4880 2598 postgresql-8.4_8.4.9-0ubuntu0.11.04.dsc 08e2a6f939e221437f8cfcc044f0f29210e43a78 17853113 postgresql-8.4_8.4.9.orig.tar.gz 12f53e141674ad204d75411bf418176d9cbbedfc 45335 postgresql-8.4_8.4.9-0ubuntu0.11.04.diff.gz Checksums-Sha256: dab93520d30f09a615658a60074d8ac32d84e35805b76e85a436f69164f943e4 2598 postgresql-8.4_8.4.9-0ubuntu0.11.04.dsc d23ab8edf48f7e058ddc8ef2d97159a0da37c328061bc287255288868d781a57 17853113 postgresql-8.4_8.4.9.orig.tar.gz 8070f4c221008b5628e9a0dcfc51b379e097ce85b722c6900021ee75e5b76c59 45335 postgresql-8.4_8.4.9-0ubuntu0.11.04.diff.gz Files: fb339eeb9494312e291c697e6152bb65 2598 database optional postgresql-8.4_8.4.9-0ubuntu0.11.04.dsc 7f69c8bb6b7994cbd863685a2d65f4db 17853113 database optional postgresql-8.4_8.4.9.orig.tar.gz 093d902cf6d8725274646ab5269f5e17 45335 database optional postgresql-8.4_8.4.9-0ubuntu0.11.04.diff.gz Original-Maintainer: Martin Pitt From brian.thomason at canonical.com Thu Oct 13 15:43:21 2011 From: brian.thomason at canonical.com (Brian Thomason) Date: Thu, 13 Oct 2011 15:43:21 -0000 Subject: [ubuntu/natty] acroread 9.4.2.0-0natty1 (Accepted) Message-ID: <20111013154321.7219.38986.launchpad@cocoplum.canonical.com> acroread (9.4.2.0-0natty1) natty; urgency=low * Initial release of new language builds for Natty Date: Thu, 13 Oct 2011 11:35:53 -0400 Changed-By: Brian Thomason https://launchpad.net/ubuntu/natty/+source/acroread/9.4.2.0-0natty1 -------------- next part -------------- -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Format: 1.8 Date: Thu, 13 Oct 2011 11:35:53 -0400 Source: acroread Binary: acroread adobereader-deu adobereader-fra adobereader-jpn acroread-common Architecture: source Version: 9.4.2.0-0natty1 Distribution: natty Urgency: low Maintainer: Brian Thomason Changed-By: Brian Thomason Description: acroread - Adobe Reader acroread-common - Adobe Reader - Common Files adobereader-deu - Adobe Reader adobereader-fra - Adobe Reader adobereader-jpn - Adobe Reader Changes: acroread (9.4.2.0-0natty1) natty; urgency=low . * Initial release of new language builds for Natty Checksums-Sha1: 7e1a0a277654f63aa8a1ccb5cd8679ed5aae782d 1291 acroread_9.4.2.0-0natty1.dsc 368f44542334f4ea5f0b7bbb4534fa71371881d4 18410 acroread_9.4.2.0-0natty1.diff.gz Checksums-Sha256: 065ad1d5db39df7f5015bcc4b60babfb32f7464c5c48debec596514233fd0c57 1291 acroread_9.4.2.0-0natty1.dsc 75c47e0af77f19f92e667a8a14d4aa9620f75bead25e308149cef4a7c2feeeb2 18410 acroread_9.4.2.0-0natty1.diff.gz Files: b49a1d0f39ebd0f1f8ddfa9722aac5f6 1291 partner/text extra acroread_9.4.2.0-0natty1.dsc 72ea553f0abcd3d540c929349cf0598e 18410 partner/text extra acroread_9.4.2.0-0natty1.diff.gz -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.11 (GNU/Linux) iEYEARECAAYFAk6XBX4ACgkQOb4zNfJqN5dyAQCfcUSIDUwEzNe45xzvdvCAyA5O bEQAn3DNrRzGQzZQi+i9lcFx+tfYZeuI =bkxL -----END PGP SIGNATURE----- From debfx-pkg at fobos.de Fri Oct 14 04:03:28 2011 From: debfx-pkg at fobos.de (Felix Geyer) Date: Fri, 14 Oct 2011 04:03:28 -0000 Subject: [ubuntu/natty-security] quassel_0.7.2-0ubuntu2.3_i386_translations.tar.gz, quassel_0.7.2-0ubuntu2.3_amd64_translations.tar.gz, quassel_0.7.2-0ubuntu2.3_powerpc_translations.tar.gz, quassel_0.7.2-0ubuntu2.3_armel_translations.tar.gz, quassel 0.7.2-0ubuntu2.3 (Accepted) Message-ID: <20111014040328.31179.75829.launchpad@cocoplum.canonical.com> quassel (0.7.2-0ubuntu2.3) natty-security; urgency=low * SECURITY UPDATE: data and log dir are world-readable (LP: #846922) - Set permissions of /var/lib/quassel and /var/log/quassel to 750. - Set permissions of /var/lib/quassel/quasselCert.pem to 640. Date: Mon, 26 Sep 2011 18:41:25 +0200 Changed-By: Felix Geyer Maintainer: Ubuntu Developers https://launchpad.net/ubuntu/natty/+source/quassel/0.7.2-0ubuntu2.3 -------------- next part -------------- Format: 1.8 Date: Mon, 26 Sep 2011 18:41:25 +0200 Source: quassel Binary: quassel quassel-client quassel-core quassel-qt4 quassel-client-qt4 quassel-data quassel-dbg Architecture: source Version: 0.7.2-0ubuntu2.3 Distribution: natty-security Urgency: low Maintainer: Ubuntu Developers Changed-By: Felix Geyer Description: quassel - KDE/Qt-based IRC client quassel-client - distributed, KDE/Qt-based IRC client - client component quassel-client-qt4 - distributed, Qt based IRC client - client component (no KDE depen quassel-core - distributed, KDE/Qt-based IRC client - core/server component quassel-data - distributed, KDE/Qt-based IRC client - data files quassel-dbg - distributed, KDE/Qt-based IRC client - debugging symbols quassel-qt4 - Qt-based IRC client (no KDE dependencies) Launchpad-Bugs-Fixed: 846922 Changes: quassel (0.7.2-0ubuntu2.3) natty-security; urgency=low . * SECURITY UPDATE: data and log dir are world-readable (LP: #846922) - Set permissions of /var/lib/quassel and /var/log/quassel to 750. - Set permissions of /var/lib/quassel/quasselCert.pem to 640. Checksums-Sha1: 9df19960327a93eea1af1ec0e44b2d04aedca8f3 2158 quassel_0.7.2-0ubuntu2.3.dsc 7c5cd7b25611fcdcb7946ac01974b120bd570c8d 19337 quassel_0.7.2-0ubuntu2.3.debian.tar.gz Checksums-Sha256: 0306e40381208e6327cc28f5fa61dd98ef132ee6836ed791ee163d893dc97f1e 2158 quassel_0.7.2-0ubuntu2.3.dsc 5c105af9ab2cca9e8c7a60db460cf6355c79ce046a8fbbda36c4e0356b6f4158 19337 quassel_0.7.2-0ubuntu2.3.debian.tar.gz Files: b976ea3118c292588f908e226746f525 2158 net optional quassel_0.7.2-0ubuntu2.3.dsc ccee1e5f3934aa5261787d6c06c6629d 19337 net optional quassel_0.7.2-0ubuntu2.3.debian.tar.gz Original-Maintainer: Harald Sitter From michael.vogt at ubuntu.com Fri Oct 14 08:11:25 2011 From: michael.vogt at ubuntu.com (Michael Vogt) Date: Fri, 14 Oct 2011 08:11:25 -0000 Subject: [ubuntu/natty-proposed] update-manager 1:0.150.4 (Accepted) Message-ID: <20111014081125.1785.83141.launchpad@gac.canonical.com> update-manager (1:0.150.4) natty-proposed; urgency=low * check-new-release-gtk: - ensure to write a integer when calculating the next time that the release available window will be presented (LP: #873424) - hide redundant release-notes button (LP: #873432) Date: Thu, 13 Oct 2011 17:35:24 +0200 Changed-By: Michael Vogt https://launchpad.net/ubuntu/natty/+source/update-manager/1:0.150.4 -------------- next part -------------- Format: 1.8 Date: Thu, 13 Oct 2011 17:35:24 +0200 Source: update-manager Binary: update-manager-core update-manager update-manager-text update-manager-kde auto-upgrade-tester Architecture: source Version: 1:0.150.4 Distribution: natty-proposed Urgency: low Maintainer: Michael Vogt Changed-By: Michael Vogt Description: auto-upgrade-tester - Test release upgrades in a virtual environment update-manager - GNOME application that manages apt updates update-manager-core - manage release upgrades update-manager-kde - Support modules for KPackageKit update-manager-text - Text application that manages apt updates Launchpad-Bugs-Fixed: 873424 873432 Changes: update-manager (1:0.150.4) natty-proposed; urgency=low . * check-new-release-gtk: - ensure to write a integer when calculating the next time that the release available window will be presented (LP: #873424) - hide redundant release-notes button (LP: #873432) Checksums-Sha1: 7c05fc763e3bc93da8a947f47d8b2cfb523d0700 1133 update-manager_0.150.4.dsc 630cf024bb72dbfc3b30919b011da6280cf15d74 2939851 update-manager_0.150.4.tar.gz Checksums-Sha256: 10ddfd2e1a7947687e29fc2e8d2992043b68979d10f2b9febde482708c8c19cf 1133 update-manager_0.150.4.dsc 34b6031bdbea86fa3b1f9f0c2579e56a1652f37f767e2dcf2032f685bc91f0e4 2939851 update-manager_0.150.4.tar.gz Files: d2a05309e01fb83cfb1e6d723a0432c0 1133 gnome optional update-manager_0.150.4.dsc 1e9b2bcb40d15edbded4dd8aac2e607a 2939851 gnome optional update-manager_0.150.4.tar.gz From sbeattie at ubuntu.com Mon Oct 17 22:04:35 2011 From: sbeattie at ubuntu.com (Steve Beattie) Date: Mon, 17 Oct 2011 22:04:35 -0000 Subject: [ubuntu/natty-security] php5, php5_5.3.5-1ubuntu7.3_powerpc_translations.tar.gz, php5_5.3.5-1ubuntu7.3_armel_translations.tar.gz, php5_5.3.5-1ubuntu7.3_i386_translations.tar.gz, php5_5.3.5-1ubuntu7.3_amd64_translations.tar.gz 5.3.5-1ubuntu7.3 (Accepted) Message-ID: <20111017220435.29516.96840.launchpad@cocoplum.canonical.com> php5 (5.3.5-1ubuntu7.3) natty-security; urgency=low [ Angel Abad ] * SECURITY UPDATE: File path injection vulnerability in RFC1867 File upload filename (LP: #813115) - debian/patches/php5-CVE-2011-2202.patch: - CVE-2011-2202 * SECURITY UPDATE: Fixed stack buffer overflow in socket_connect() (LP: #813110) - debian/patches/php5-CVE-2011-1938.patch: - CVE-2011-1938 [ Steve Beattie ] * SECURITY UPDATE: DoS in zip handling due to addGlob() crashing on invalid flags - debian/patches/php5-CVE-2011-1657.patch: check for valid flags - CVE-2011-1657 * SECURITY UPDATE: crypt_blowfish doesn't properly handle 8-bit (non-ascii) passwords leading to a smaller collision space - debian/patches/php5-CVE-2011-2483.patch: update crypt_blowfish to 1.2 to correct handling of passwords containing 8-bit (non-ascii) characters. CVE-2011-2483 * SECURITY UPDATE: DoS due to failure to check for memory allocation errors - debian/patches/php5-CVE-2011-3182.patch: check the return values of the malloc, calloc, and realloc functions - CVE-2011-3182 * SECURITY UPDATE: DoS in errorlog() when passed NULL - debian/patches/php5-CVE-2011-3267.patch: fix NULL pointer crash in errorlog() - CVE-2011-3267 * debian/patches/fix_crash_in__php_mssql_get_column_content_without_type.patch: refresh patch to make it cleanly apply. Date: Thu, 13 Oct 2011 13:49:23 -0700 Changed-By: Steve Beattie Maintainer: Ubuntu Developers https://launchpad.net/ubuntu/natty/+source/php5/5.3.5-1ubuntu7.3 -------------- next part -------------- Format: 1.8 Date: Thu, 13 Oct 2011 13:49:23 -0700 Source: php5 Binary: php5 php5-common libapache2-mod-php5 libapache2-mod-php5filter php5-cgi php5-cli php5-fpm php5-dev php5-dbg php-pear php5-curl php5-enchant php5-gd php5-gmp php5-intl php5-ldap php5-mysql php5-odbc php5-pgsql php5-pspell php5-recode php5-snmp php5-sqlite php5-sybase php5-tidy php5-xmlrpc php5-xsl Architecture: source Version: 5.3.5-1ubuntu7.3 Distribution: natty-security Urgency: low Maintainer: Ubuntu Developers Changed-By: Steve Beattie Description: libapache2-mod-php5 - server-side, HTML-embedded scripting language (Apache 2 module) libapache2-mod-php5filter - server-side, HTML-embedded scripting language (apache 2 filter mo php-pear - PEAR - PHP Extension and Application Repository php5 - server-side, HTML-embedded scripting language (metapackage) php5-cgi - server-side, HTML-embedded scripting language (CGI binary) php5-cli - command-line interpreter for the php5 scripting language php5-common - Common files for packages built from the php5 source php5-curl - CURL module for php5 php5-dbg - Debug symbols for PHP5 php5-dev - Files for PHP5 module development php5-enchant - Enchant module for php5 php5-fpm - server-side, HTML-embedded scripting language (FPM-CGI binary) php5-gd - GD module for php5 php5-gmp - GMP module for php5 php5-intl - internationalisation module for php5 php5-ldap - LDAP module for php5 php5-mysql - MySQL module for php5 php5-odbc - ODBC module for php5 php5-pgsql - PostgreSQL module for php5 php5-pspell - pspell module for php5 php5-recode - recode module for php5 php5-snmp - SNMP module for php5 php5-sqlite - SQLite module for php5 php5-sybase - Sybase / MS SQL Server module for php5 php5-tidy - tidy module for php5 php5-xmlrpc - XML-RPC module for php5 php5-xsl - XSL module for php5 Launchpad-Bugs-Fixed: 813110 813115 Changes: php5 (5.3.5-1ubuntu7.3) natty-security; urgency=low . [ Angel Abad ] * SECURITY UPDATE: File path injection vulnerability in RFC1867 File upload filename (LP: #813115) - debian/patches/php5-CVE-2011-2202.patch: - CVE-2011-2202 * SECURITY UPDATE: Fixed stack buffer overflow in socket_connect() (LP: #813110) - debian/patches/php5-CVE-2011-1938.patch: - CVE-2011-1938 . [ Steve Beattie ] * SECURITY UPDATE: DoS in zip handling due to addGlob() crashing on invalid flags - debian/patches/php5-CVE-2011-1657.patch: check for valid flags - CVE-2011-1657 * SECURITY UPDATE: crypt_blowfish doesn't properly handle 8-bit (non-ascii) passwords leading to a smaller collision space - debian/patches/php5-CVE-2011-2483.patch: update crypt_blowfish to 1.2 to correct handling of passwords containing 8-bit (non-ascii) characters. CVE-2011-2483 * SECURITY UPDATE: DoS due to failure to check for memory allocation errors - debian/patches/php5-CVE-2011-3182.patch: check the return values of the malloc, calloc, and realloc functions - CVE-2011-3182 * SECURITY UPDATE: DoS in errorlog() when passed NULL - debian/patches/php5-CVE-2011-3267.patch: fix NULL pointer crash in errorlog() - CVE-2011-3267 * debian/patches/fix_crash_in__php_mssql_get_column_content_without_type.patch: refresh patch to make it cleanly apply. Checksums-Sha1: 306ec1fd53fdcc9936a7b19198edbf106ea907e5 3268 php5_5.3.5-1ubuntu7.3.dsc 3619fee6463a2bbc9507e7082ce7f6e870c2478e 232007 php5_5.3.5-1ubuntu7.3.diff.gz Checksums-Sha256: 3b3cd0fd07b0c90ddadddf10723de3cfa3b2c011853ec922c73a148c0ecf9fd3 3268 php5_5.3.5-1ubuntu7.3.dsc 20b3c2962153fc81029bb983732c349da7881bcdff251c0b556bb6be240492d7 232007 php5_5.3.5-1ubuntu7.3.diff.gz Files: b1fb89186e5a78c86a4e0bb9074f3c01 3268 php optional php5_5.3.5-1ubuntu7.3.dsc 3b282581ba089f56bd931c03b373f942 232007 php optional php5_5.3.5-1ubuntu7.3.diff.gz Original-Maintainer: Debian PHP Maintainers From stgraber at ubuntu.com Mon Oct 17 22:22:16 2011 From: stgraber at ubuntu.com (Stephane Graber) Date: Mon, 17 Oct 2011 22:22:16 -0000 Subject: [ubuntu/natty-proposed] nagios-nrpe 2.12-4ubuntu1.11.04.1 (Accepted) Message-ID: <20111017222216.17459.62213.launchpad@soybean.canonical.com> nagios-nrpe (2.12-4ubuntu1.11.04.1) natty-proposed; urgency=low * Use pidfile for start-stop-daemon and fix pidfile deletion (LP: #600941) Date: Fri, 14 Oct 2011 10:39:21 +0100 Changed-By: Stéphane Graber Maintainer: Ubuntu Developers https://launchpad.net/ubuntu/natty/+source/nagios-nrpe/2.12-4ubuntu1.11.04.1 -------------- next part -------------- Format: 1.8 Date: Fri, 14 Oct 2011 10:39:21 +0100 Source: nagios-nrpe Binary: nagios-nrpe-server nagios-nrpe-plugin Architecture: source Version: 2.12-4ubuntu1.11.04.1 Distribution: natty-proposed Urgency: low Maintainer: Ubuntu Developers Changed-By: Stéphane Graber Description: nagios-nrpe-plugin - Nagios Remote Plugin Executor Plugin nagios-nrpe-server - Nagios Remote Plugin Executor Server Launchpad-Bugs-Fixed: 600941 Changes: nagios-nrpe (2.12-4ubuntu1.11.04.1) natty-proposed; urgency=low . * Use pidfile for start-stop-daemon and fix pidfile deletion (LP: #600941) Checksums-Sha1: 3487eb136e81e3e76d6a8d39e8159bd0dc383286 2033 nagios-nrpe_2.12-4ubuntu1.11.04.1.dsc 9996ba7530a0f873428a7b4c9bfb8b15cb69fe94 10279 nagios-nrpe_2.12-4ubuntu1.11.04.1.diff.gz Checksums-Sha256: c6f1f9aec2eefd5f244967fb91ad5321a1275f696e50b592e233173ac8c9638d 2033 nagios-nrpe_2.12-4ubuntu1.11.04.1.dsc 2b9f4f5b528137fe72bafaceb0ad9e4514ad27ed8cfb847e65890c38a5363821 10279 nagios-nrpe_2.12-4ubuntu1.11.04.1.diff.gz Files: 5f401d70029edab8eae5a437eaa62d1e 2033 net optional nagios-nrpe_2.12-4ubuntu1.11.04.1.dsc e8db1c4926a8438d738f1f42dd6a6993 10279 net optional nagios-nrpe_2.12-4ubuntu1.11.04.1.diff.gz Original-Maintainer: Debian Nagios Maintainer Group From marc.deslauriers at ubuntu.com Tue Oct 18 16:04:20 2011 From: marc.deslauriers at ubuntu.com (Marc Deslauriers) Date: Tue, 18 Oct 2011 16:04:20 -0000 Subject: [ubuntu/natty-security] xorg-server 2:1.10.1-1ubuntu1.3 (Accepted) Message-ID: <20111018160420.20604.81678.launchpad@cocoplum.canonical.com> xorg-server (2:1.10.1-1ubuntu1.3) natty-security; urgency=low * SECURITY UPDATE: file existence disclosure - debian/patches/505_CVE-2011-4028.patch: open lockfile with O_NOFOLLOW in os/utils.c. - CVE-2011-4028 * SECURITY UPDATE: privilege escalation via file permission change - debian/patches/506_CVE-2011-4029.patch: use fchmod to prevent race in os/utils.c. - CVE-2011-4029 Date: Thu, 13 Oct 2011 11:03:44 -0400 Changed-By: Marc Deslauriers Maintainer: Ubuntu X-SWAT https://launchpad.net/ubuntu/natty/+source/xorg-server/2:1.10.1-1ubuntu1.3 -------------- next part -------------- Format: 1.8 Date: Thu, 13 Oct 2011 11:03:44 -0400 Source: xorg-server Binary: xserver-xorg-core xserver-xorg-core-udeb xserver-xorg-dev xdmx xdmx-tools xnest xvfb xserver-xephyr xserver-xfbdev xserver-xorg-core-dbg xserver-common Architecture: source Version: 2:1.10.1-1ubuntu1.3 Distribution: natty-security Urgency: low Maintainer: Ubuntu X-SWAT Changed-By: Marc Deslauriers Description: xdmx - distributed multihead X server xdmx-tools - Distributed Multihead X tools xnest - Nested X server xserver-common - common files used by various X servers xserver-xephyr - nested X server xserver-xfbdev - Linux framebuffer device tiny X server xserver-xorg-core - Xorg X server - core server xserver-xorg-core-dbg - Xorg - the X.Org X server (debugging symbols) xserver-xorg-core-udeb - Xorg X server - core server (udeb) xserver-xorg-dev - Xorg X server - development files xvfb - Virtual Framebuffer 'fake' X server Changes: xorg-server (2:1.10.1-1ubuntu1.3) natty-security; urgency=low . * SECURITY UPDATE: file existence disclosure - debian/patches/505_CVE-2011-4028.patch: open lockfile with O_NOFOLLOW in os/utils.c. - CVE-2011-4028 * SECURITY UPDATE: privilege escalation via file permission change - debian/patches/506_CVE-2011-4029.patch: use fchmod to prevent race in os/utils.c. - CVE-2011-4029 Checksums-Sha1: 0bc23adff57b309931c6224de31bb07a578c72f2 3821 xorg-server_1.10.1-1ubuntu1.3.dsc 27376c2177a012a1489b06412fd713c3412b1e2d 459987 xorg-server_1.10.1-1ubuntu1.3.diff.gz Checksums-Sha256: fb48b9ec04fcf2d523bff19d021ac89a7df8504182b24de881300a6b49da53e5 3821 xorg-server_1.10.1-1ubuntu1.3.dsc aedb05c01fb70d250fe81e4067c7518d11a6f4aad6b158a805be2fdb927638c5 459987 xorg-server_1.10.1-1ubuntu1.3.diff.gz Files: ee0f079cc19e846f515d3f238d9972f8 3821 x11 optional xorg-server_1.10.1-1ubuntu1.3.dsc 1ffa6cfbcf41b7c589137867fe4e46fb 459987 x11 optional xorg-server_1.10.1-1ubuntu1.3.diff.gz Original-Maintainer: Debian X Strike Force From sbeattie at ubuntu.com Tue Oct 18 22:03:49 2011 From: sbeattie at ubuntu.com (Steve Beattie) Date: Tue, 18 Oct 2011 22:03:49 -0000 Subject: [ubuntu/natty-security] krb5, krb5_1.8.3+dfsg-5ubuntu2.2_amd64_translations.tar.gz, krb5_1.8.3+dfsg-5ubuntu2.2_powerpc_translations.tar.gz, krb5_1.8.3+dfsg-5ubuntu2.2_armel_translations.tar.gz, krb5_1.8.3+dfsg-5ubuntu2.2_i386_translations.tar.gz 1.8.3+dfsg-5ubuntu2.2 (Accepted) Message-ID: <20111018220349.24909.26094.launchpad@cocoplum.canonical.com> krb5 (1.8.3+dfsg-5ubuntu2.2) natty-security; urgency=low * SECURITY UPDATE: fix multiple kdc DoS issues: - db2/lockout.c, ldap/libkdb_ldap/ldap_principal2.c, ldap/libkdb_ldap/lockout.c: + more strict checking for null pointers + disable assert iand return when db is locked + applied inline - CVE-2011-1528 and CVE-2011-1529 - MITKRB5-SA-2011-006 Date: Mon, 10 Oct 2011 15:23:12 -0700 Changed-By: Steve Beattie Maintainer: Ubuntu Developers https://launchpad.net/ubuntu/natty/+source/krb5/1.8.3+dfsg-5ubuntu2.2 -------------- next part -------------- Format: 1.8 Date: Mon, 10 Oct 2011 15:23:12 -0700 Source: krb5 Binary: krb5-user krb5-kdc krb5-kdc-ldap krb5-admin-server krb5-multidev libkrb5-dev libkrb5-dbg krb5-pkinit krb5-doc libkrb5-3 libgssapi-krb5-2 libgssrpc4 libkadm5srv-mit7 libkadm5clnt-mit7 libk5crypto3 libkdb5-4 libkrb5support0 libkrb53 Architecture: source Version: 1.8.3+dfsg-5ubuntu2.2 Distribution: natty-security Urgency: low Maintainer: Ubuntu Developers Changed-By: Steve Beattie Description: krb5-admin-server - MIT Kerberos master server (kadmind) krb5-doc - Documentation for MIT Kerberos krb5-kdc - MIT Kerberos key server (KDC) krb5-kdc-ldap - MIT Kerberos key server (KDC) LDAP plugin krb5-multidev - Development files for MIT Kerberos without Heimdal conflict krb5-pkinit - PKINIT plugin for MIT Kerberos krb5-user - Basic programs to authenticate using MIT Kerberos libgssapi-krb5-2 - MIT Kerberos runtime libraries - krb5 GSS-API Mechanism libgssrpc4 - MIT Kerberos runtime libraries - GSS enabled ONCRPC libk5crypto3 - MIT Kerberos runtime libraries - Crypto Library libkadm5clnt-mit7 - MIT Kerberos runtime libraries - Administration Clients libkadm5srv-mit7 - MIT Kerberos runtime libraries - KDC and Admin Server libkdb5-4 - MIT Kerberos runtime libraries - Kerberos database libkrb5-3 - MIT Kerberos runtime libraries libkrb5-dbg - Debugging files for MIT Kerberos libkrb5-dev - Headers and development libraries for MIT Kerberos libkrb53 - transitional package for MIT Kerberos libraries libkrb5support0 - MIT Kerberos runtime libraries - Support library Changes: krb5 (1.8.3+dfsg-5ubuntu2.2) natty-security; urgency=low . * SECURITY UPDATE: fix multiple kdc DoS issues: - db2/lockout.c, ldap/libkdb_ldap/ldap_principal2.c, ldap/libkdb_ldap/lockout.c: + more strict checking for null pointers + disable assert iand return when db is locked + applied inline - CVE-2011-1528 and CVE-2011-1529 - MITKRB5-SA-2011-006 Checksums-Sha1: d2dc88b4cb17eed22e799cb5db57ddcbe1d54cdf 2344 krb5_1.8.3+dfsg-5ubuntu2.2.dsc cd27fc3b7054bec8fa62cf1b1b78baef65523536 108601 krb5_1.8.3+dfsg-5ubuntu2.2.diff.gz Checksums-Sha256: 99358fd79d8772bb71699326379e12a9f1145834dc0602194159b0c19591ad9e 2344 krb5_1.8.3+dfsg-5ubuntu2.2.dsc 25086dd889ebb07a0fc0923e566332242cc924de4cc9fa6d06fba1fc73c987fe 108601 krb5_1.8.3+dfsg-5ubuntu2.2.diff.gz Files: 0d344d029cb22184df4805e61c3141c8 2344 net standard krb5_1.8.3+dfsg-5ubuntu2.2.dsc 76f68f57d375155e42735c1aa8215e11 108601 net standard krb5_1.8.3+dfsg-5ubuntu2.2.diff.gz Original-Maintainer: Sam Hartman From gary.lasker at canonical.com Wed Oct 19 05:18:51 2011 From: gary.lasker at canonical.com (Gary Lasker) Date: Wed, 19 Oct 2011 05:18:51 -0000 Subject: [ubuntu/natty-proposed] tzdata 2011l-0ubuntu0.11.04 (Accepted) Message-ID: <20111019051851.28171.21016.launchpad@gac.canonical.com> tzdata (2011l-0ubuntu0.11.04) natty-proposed; urgency=low * New upstream release 2011l: (LP: #876090) - Fiji adopts DST for 2011 (effective Oct 23rd, 2011) - West Bank changes date for DST end in 2011 to Sep 30th Date: Sun, 16 Oct 2011 20:02:22 -0400 Changed-By: Gary Lasker Maintainer: Ubuntu Developers Signed-By: Martin Pitt https://launchpad.net/ubuntu/natty/+source/tzdata/2011l-0ubuntu0.11.04 -------------- next part -------------- Format: 1.8 Date: Sun, 16 Oct 2011 20:02:22 -0400 Source: tzdata Binary: tzdata tzdata-java Architecture: source Version: 2011l-0ubuntu0.11.04 Distribution: natty-proposed Urgency: low Maintainer: Ubuntu Developers Changed-By: Gary Lasker Description: tzdata - time zone and daylight-saving time data tzdata-java - time zone and daylight-saving time data for use by java runtimes Launchpad-Bugs-Fixed: 876090 Changes: tzdata (2011l-0ubuntu0.11.04) natty-proposed; urgency=low . * New upstream release 2011l: (LP: #876090) - Fiji adopts DST for 2011 (effective Oct 23rd, 2011) - West Bank changes date for DST end in 2011 to Sep 30th Checksums-Sha1: 01e12c6857981558d87238f2013ad9ed4c9801ec 1908 tzdata_2011l-0ubuntu0.11.04.dsc c6740ec9645b78750e2109b6d42cd283e16988d7 203374 tzdata_2011l.orig.tar.gz 89262711798d168596eaea1ffc0cdddaae5a8f90 261009 tzdata_2011l-0ubuntu0.11.04.debian.tar.gz Checksums-Sha256: aca8a73c66260c2923c0296ea17a2220eb5b8d5ea8d07beba324caaad1ef472e 1908 tzdata_2011l-0ubuntu0.11.04.dsc cb9fec68a19c9c3b900bb71f3ca20d0051a863f765387b52fc2d144a5bbb0c7d 203374 tzdata_2011l.orig.tar.gz afabb2e274fae25a990ee894995e6b020e0f86e5ecfa7fb3330d852bbdf7e077 261009 tzdata_2011l-0ubuntu0.11.04.debian.tar.gz Files: 971acd7d665ea0d09ea761176197f6cf 1908 libs required tzdata_2011l-0ubuntu0.11.04.dsc bae1b93673e1aef80186c90dfd493f1c 203374 libs required tzdata_2011l.orig.tar.gz 2dc241afc6386c1681c7bc02e6e87496 261009 libs required tzdata_2011l-0ubuntu0.11.04.debian.tar.gz Original-Maintainer: GNU Libc Maintainers From brian at ubuntu.com Thu Oct 20 06:32:03 2011 From: brian at ubuntu.com (Brian Murray) Date: Thu, 20 Oct 2011 06:32:03 -0000 Subject: [ubuntu/natty-proposed] update-manager 1:0.150.5 (Accepted) Message-ID: <20111020063203.18643.26461.launchpad@gac.canonical.com> update-manager (1:0.150.5) natty-proposed; urgency=low * update apport package hook to the same one as in Oneiric (LP: #878585) Date: Wed, 19 Oct 2011 17:13:17 -0700 Changed-By: Brian Murray Maintainer: Michael Vogt Signed-By: =?utf-8?q?St=C3=A9phane_Graber?= https://launchpad.net/ubuntu/natty/+source/update-manager/1:0.150.5 -------------- next part -------------- Format: 1.8 Date: Wed, 19 Oct 2011 17:13:17 -0700 Source: update-manager Binary: update-manager-core update-manager update-manager-text update-manager-kde auto-upgrade-tester Architecture: source Version: 1:0.150.5 Distribution: natty-proposed Urgency: low Maintainer: Michael Vogt Changed-By: Brian Murray Description: auto-upgrade-tester - Test release upgrades in a virtual environment update-manager - GNOME application that manages apt updates update-manager-core - manage release upgrades update-manager-kde - Support modules for KPackageKit update-manager-text - Text application that manages apt updates Launchpad-Bugs-Fixed: 878585 Changes: update-manager (1:0.150.5) natty-proposed; urgency=low . * update apport package hook to the same one as in Oneiric (LP: #878585) Checksums-Sha1: fa5a53f1d17defb50a4feb2d810c3129bc4c2372 1773 update-manager_0.150.5.dsc bc3d3b50fc458cf00ba4c6ae628058639e6dd339 2939770 update-manager_0.150.5.tar.gz Checksums-Sha256: 91b7c0df9e9c27d5b493ec45e3986da174a9bc157838a2e36706884f6290289d 1773 update-manager_0.150.5.dsc 9db3805a6d484157cd45d123a5b5f8a15c5ba21e13383739f67c1471e26c6bbf 2939770 update-manager_0.150.5.tar.gz Files: da5da6a351d5fce7bb8e6e2f4a2d7368 1773 gnome optional update-manager_0.150.5.dsc 9843c2c185500a36a24e2bee8b32983e 2939770 gnome optional update-manager_0.150.5.tar.gz From davrosmeglos at gmail.com Thu Oct 20 06:32:51 2011 From: davrosmeglos at gmail.com (Bill Cahill) Date: Thu, 20 Oct 2011 06:32:51 -0000 Subject: [ubuntu/natty-proposed] sysvinit 2.87dsf-4ubuntu23.1 (Accepted) Message-ID: <20111020063251.17856.63140.launchpad@wampee.canonical.com> sysvinit (2.87dsf-4ubuntu23.1) natty-proposed; urgency=low * debian/initscripts/etc/init.d/sendsigs: Only omit jobs that are in the 'start' goal. Those that are destined for 'stop' are waited on and killed like all other processes. (LP: #616287) Thanks to Launchpad user "codewarrior". Date: Tue, 13 Sep 2011 22:41:05 -0700 Changed-By: Bill Cahill Maintainer: Ubuntu Core Developers Signed-By: Clint Byrum https://launchpad.net/ubuntu/natty/+source/sysvinit/2.87dsf-4ubuntu23.1 -------------- next part -------------- Format: 1.8 Date: Tue, 13 Sep 2011 22:41:05 -0700 Source: sysvinit Binary: sysvinit-utils sysv-rc initscripts sysvutils Architecture: source Version: 2.87dsf-4ubuntu23.1 Distribution: natty-proposed Urgency: low Maintainer: Ubuntu Core Developers Changed-By: Bill Cahill Description: initscripts - scripts for initializing and shutting down the system sysv-rc - System-V-like runlevel change mechanism sysvinit-utils - System-V-like utilities sysvutils - System-V-like utilities (transitional package) Launchpad-Bugs-Fixed: 616287 Changes: sysvinit (2.87dsf-4ubuntu23.1) natty-proposed; urgency=low . * debian/initscripts/etc/init.d/sendsigs: Only omit jobs that are in the 'start' goal. Those that are destined for 'stop' are waited on and killed like all other processes. (LP: #616287) Thanks to Launchpad user "codewarrior". Checksums-Sha1: 9ec83eb252f4fd1898c8671bafe36d5df2db10be 1674 sysvinit_2.87dsf-4ubuntu23.1.dsc 5365a68904dc6d2fdf3e8c3223b4e02824020c3d 265057 sysvinit_2.87dsf-4ubuntu23.1.tar.gz Checksums-Sha256: b8024daf7aba493ce519fa789f084ee264545fcd0d71c7a7103451af638e2d2e 1674 sysvinit_2.87dsf-4ubuntu23.1.dsc 50101a76dbd6d897de960a8852995d40727d6afe452fe3b77e92f7f7ce5b5326 265057 sysvinit_2.87dsf-4ubuntu23.1.tar.gz Files: a34c83fd74fc36ccad5b57889358e815 1674 admin required sysvinit_2.87dsf-4ubuntu23.1.dsc 1a2d64c8ef0391ba6400c549a997624d 265057 admin required sysvinit_2.87dsf-4ubuntu23.1.tar.gz Original-Maintainer: Debian sysvinit maintainers From jtaylor.debian at googlemail.com Thu Oct 20 06:38:34 2011 From: jtaylor.debian at googlemail.com (Julian Taylor) Date: Thu, 20 Oct 2011 06:38:34 -0000 Subject: [ubuntu/natty-proposed] pycryptopp 0.5.29-0ubuntu0.1 (Accepted) Message-ID: <20111020063834.19039.24083.launchpad@gac.canonical.com> pycryptopp (0.5.29-0ubuntu0.1) natty-proposed; urgency=low * New upstream release. (LP: #811721) * refresh patches - add new patch from debian to not ship extraversion.h Date: Wed, 05 Oct 2011 19:32:34 +0200 Changed-By: Julian Taylor Maintainer: Ubuntu Developers Signed-By: Stefano Rivera https://launchpad.net/ubuntu/natty/+source/pycryptopp/0.5.29-0ubuntu0.1 -------------- next part -------------- Format: 1.8 Date: Wed, 05 Oct 2011 19:32:34 +0200 Source: pycryptopp Binary: python-pycryptopp python-pycryptopp-dbg Architecture: source Version: 0.5.29-0ubuntu0.1 Distribution: natty-proposed Urgency: low Maintainer: Ubuntu Developers Changed-By: Julian Taylor Description: python-pycryptopp - Python wrappers for the Crypto++ library python-pycryptopp-dbg - Python wrappers for the Crypto++ library (debug extension) Launchpad-Bugs-Fixed: 811721 Changes: pycryptopp (0.5.29-0ubuntu0.1) natty-proposed; urgency=low . * New upstream release. (LP: #811721) * refresh patches - add new patch from debian to not ship extraversion.h Checksums-Sha1: 807a851577ae778185942e092645e2f1c56e18af 2286 pycryptopp_0.5.29-0ubuntu0.1.dsc 53127f9f9748c159f99700684c86098c2e96573d 1114525 pycryptopp_0.5.29.orig.tar.gz e2e6e9263f154723d29940117dc9b1d0d2aa9a8d 5316 pycryptopp_0.5.29-0ubuntu0.1.diff.gz Checksums-Sha256: eeaa7e9c322c8c667e14e917df3eb77a4ce7840ce037c51617d5be7b16bc7dd5 2286 pycryptopp_0.5.29-0ubuntu0.1.dsc d504775b73d30fb05a3237f83c4e9e1ff3312cbba90a4a23e6cbb7d32219502b 1114525 pycryptopp_0.5.29.orig.tar.gz b5eee648baaea285be15deb972357a25f3a6701b3aed6287d9a7a8b60e68be72 5316 pycryptopp_0.5.29-0ubuntu0.1.diff.gz Files: c4d648d56b12c6606b84daa21d8d65ea 2286 python optional pycryptopp_0.5.29-0ubuntu0.1.dsc c5b86ad1ebda0e7999bb50d72e412c6a 1114525 python optional pycryptopp_0.5.29.orig.tar.gz 4acc3e613f75bb8114e236ab35e34eac 5316 python optional pycryptopp_0.5.29-0ubuntu0.1.diff.gz Original-Maintainer: Zooko O'Whielacronx From jamie at ubuntu.com Thu Oct 20 18:03:44 2011 From: jamie at ubuntu.com (Jamie Strandboge) Date: Thu, 20 Oct 2011 18:03:44 -0000 Subject: [ubuntu/natty-security] acpid 1:2.0.7-1ubuntu2.1 (Accepted) Message-ID: <20111020180344.6332.67099.launchpad@cocoplum.canonical.com> acpid (1:2.0.7-1ubuntu2.1) natty-security; urgency=low * SECURITY UPDATE: denial of service via blocking socket - sock.c: adjust the socket fd to use O_NONBLOCK - Patch from upstream - CVE-2011-1159 Date: Thu, 13 Oct 2011 17:36:33 -0500 Changed-By: Jamie Strandboge Maintainer: Ubuntu Developers https://launchpad.net/ubuntu/natty/+source/acpid/1:2.0.7-1ubuntu2.1 -------------- next part -------------- Format: 1.8 Date: Thu, 13 Oct 2011 17:36:33 -0500 Source: acpid Binary: acpid kacpimon Architecture: source Version: 1:2.0.7-1ubuntu2.1 Distribution: natty-security Urgency: low Maintainer: Ubuntu Developers Changed-By: Jamie Strandboge Description: acpid - Advanced Configuration and Power Interface event daemon kacpimon - Kernel ACPI Event Monitor Changes: acpid (1:2.0.7-1ubuntu2.1) natty-security; urgency=low . * SECURITY UPDATE: denial of service via blocking socket - sock.c: adjust the socket fd to use O_NONBLOCK - Patch from upstream - CVE-2011-1159 Checksums-Sha1: 2f97a4b1c7cff66fcf9acde1c75a9f298e632f18 1970 acpid_2.0.7-1ubuntu2.1.dsc 2970ce6e89a351305f6ee230f321b32c3f54ff85 20899 acpid_2.0.7-1ubuntu2.1.diff.gz Checksums-Sha256: 6ceac45267776afdfa066fed72710dd66876beeea7bd3ea25b99a512ead7cdfe 1970 acpid_2.0.7-1ubuntu2.1.dsc 742d5c58e661baadf672ef91ab396ac5773af6c06651756c8f8d600747b618e4 20899 acpid_2.0.7-1ubuntu2.1.diff.gz Files: 94033e841a4b6a2e77ff97203e4c795f 1970 admin optional acpid_2.0.7-1ubuntu2.1.dsc 8cb8de62717d48beb9a5dabe9077831a 20899 admin optional acpid_2.0.7-1ubuntu2.1.diff.gz Original-Maintainer: Debian Acpi Team From marc.deslauriers at ubuntu.com Mon Oct 24 19:03:51 2011 From: marc.deslauriers at ubuntu.com (Marc Deslauriers) Date: Mon, 24 Oct 2011 19:03:51 -0000 Subject: [ubuntu/natty-security] pam_1.1.2-2ubuntu8.4_powerpc_translations.tar.gz, pam_1.1.2-2ubuntu8.4_armel_translations.tar.gz, pam_1.1.2-2ubuntu8.4_i386_translations.tar.gz, pam, pam_1.1.2-2ubuntu8.4_amd64_translations.tar.gz 1.1.2-2ubuntu8.4 (Accepted) Message-ID: <20111024190351.25513.23026.launchpad@cocoplum.canonical.com> pam (1.1.2-2ubuntu8.4) natty-security; urgency=low * SECURITY UPDATE: possible code execution via incorrect environment file parsing (LP: #874469) - debian/patches-applied/CVE-2011-3148.patch: correctly count leading whitespace when parsing environment file in modules/pam_env/pam_env.c. - CVE-2011-3148 * SECURITY UPDATE: denial of service via overflowed environment variable expansion (LP: #874565) - debian/patches-applied/CVE-2011-3149.patch: when overflowing, exit with PAM_BUF_ERR in modules/pam_env/pam_env.c. - CVE-2011-3149 * SECURITY UPDATE: code execution via incorrect environment cleaning - debian/patches-applied/update-motd: updated to use clean environment and absolute paths in modules/pam_motd/pam_motd.c. - CVE-2011-XXXX Date: Tue, 18 Oct 2011 10:03:44 -0400 Changed-By: Marc Deslauriers Maintainer: Ubuntu Developers https://launchpad.net/ubuntu/natty/+source/pam/1.1.2-2ubuntu8.4 -------------- next part -------------- Format: 1.8 Date: Tue, 18 Oct 2011 10:03:44 -0400 Source: pam Binary: libpam0g libpam-modules libpam-modules-bin libpam-runtime libpam0g-dev libpam-cracklib libpam-doc Architecture: source Version: 1.1.2-2ubuntu8.4 Distribution: natty-security Urgency: low Maintainer: Ubuntu Developers Changed-By: Marc Deslauriers Description: libpam-cracklib - PAM module to enable cracklib support libpam-doc - Documentation of PAM libpam-modules - Pluggable Authentication Modules for PAM libpam-modules-bin - Pluggable Authentication Modules for PAM - helper binaries libpam-runtime - Runtime support for the PAM library libpam0g - Pluggable Authentication Modules library libpam0g-dev - Development files for PAM Launchpad-Bugs-Fixed: 874469 874565 Changes: pam (1.1.2-2ubuntu8.4) natty-security; urgency=low . * SECURITY UPDATE: possible code execution via incorrect environment file parsing (LP: #874469) - debian/patches-applied/CVE-2011-3148.patch: correctly count leading whitespace when parsing environment file in modules/pam_env/pam_env.c. - CVE-2011-3148 * SECURITY UPDATE: denial of service via overflowed environment variable expansion (LP: #874565) - debian/patches-applied/CVE-2011-3149.patch: when overflowing, exit with PAM_BUF_ERR in modules/pam_env/pam_env.c. - CVE-2011-3149 * SECURITY UPDATE: code execution via incorrect environment cleaning - debian/patches-applied/update-motd: updated to use clean environment and absolute paths in modules/pam_motd/pam_motd.c. - CVE-2011-XXXX Checksums-Sha1: 00710457d3217168dc610c020204bf3cce46c923 2267 pam_1.1.2-2ubuntu8.4.dsc 7cee6fa301d5857cfd4ae9f30869d9dbd8bfa07c 338910 pam_1.1.2-2ubuntu8.4.diff.gz Checksums-Sha256: 088990c816e5f0f9aaf1256d4f3f19b39305f3325a8b96826f3929898477638e 2267 pam_1.1.2-2ubuntu8.4.dsc c29847bf2e4cefb3707a10405b0bb166d8ec7eb262a5a2c9ff7b01471c9667ea 338910 pam_1.1.2-2ubuntu8.4.diff.gz Files: 584a58bc7c9712c493002abb4d068cc7 2267 libs optional pam_1.1.2-2ubuntu8.4.dsc f338715825e4319eaba3359f4f0e0668 338910 libs optional pam_1.1.2-2ubuntu8.4.diff.gz Original-Maintainer: Steve Langasek From marc.deslauriers at ubuntu.com Mon Oct 24 22:03:26 2011 From: marc.deslauriers at ubuntu.com (Marc Deslauriers) Date: Mon, 24 Oct 2011 22:03:26 -0000 Subject: [ubuntu/natty-security] puppet 2.6.4-2ubuntu2.5 (Accepted) Message-ID: <20111024220326.26174.96127.launchpad@cocoplum.canonical.com> puppet (2.6.4-2ubuntu2.5) natty-security; urgency=low * SECURITY UPDATE: puppet master impersonation via incorrect certificates - debian/patches/CVE-2011-3872.patch: refactor certificate handling. - Thanks to upstream for providing the patch. - CVE-2011-3872 Date: Mon, 24 Oct 2011 15:06:51 -0400 Changed-By: Marc Deslauriers Maintainer: Ubuntu Developers https://launchpad.net/ubuntu/natty/+source/puppet/2.6.4-2ubuntu2.5 -------------- next part -------------- Format: 1.8 Date: Mon, 24 Oct 2011 15:06:51 -0400 Source: puppet Binary: puppet-common puppet puppetmaster-common puppetmaster puppetmaster-passenger vim-puppet puppet-el puppet-testsuite Architecture: source Version: 2.6.4-2ubuntu2.5 Distribution: natty-security Urgency: low Maintainer: Ubuntu Developers Changed-By: Marc Deslauriers Description: puppet - Centralized configuration management - agent startup and compatib puppet-common - Centralized configuration management puppet-el - syntax highlighting for puppet manifests in emacs puppet-testsuite - Centralized configuration management - test suite puppetmaster - Centralized configuration management - master startup and compati puppetmaster-common - Puppet master common scripts puppetmaster-passenger - Centralised configuration management - master setup to run under vim-puppet - syntax highlighting for puppet manifests in vim Changes: puppet (2.6.4-2ubuntu2.5) natty-security; urgency=low . * SECURITY UPDATE: puppet master impersonation via incorrect certificates - debian/patches/CVE-2011-3872.patch: refactor certificate handling. - Thanks to upstream for providing the patch. - CVE-2011-3872 Checksums-Sha1: 7362b767ba5e66f8fb57143d0d133d2ecfc637c9 2296 puppet_2.6.4-2ubuntu2.5.dsc 168e0da99dd93a18c149bbf1bd64831348e9c53e 87965 puppet_2.6.4-2ubuntu2.5.debian.tar.gz Checksums-Sha256: 48ab143b66a2f7b6d6ab99d0914fc54a32807f8da9e1540c1fb62645c69c2c28 2296 puppet_2.6.4-2ubuntu2.5.dsc 3e538c12ed83d865f660effa8142844c3178c81b3a3c8234f26af6859b2a4348 87965 puppet_2.6.4-2ubuntu2.5.debian.tar.gz Files: a9c9777c247ed7827fa5870c91347621 2296 admin optional puppet_2.6.4-2ubuntu2.5.dsc 3fff6d85bb9dbd732684cc2b80fc3b0a 87965 admin optional puppet_2.6.4-2ubuntu2.5.debian.tar.gz Original-Maintainer: Puppet Package Maintainers From brian at ubuntu.com Tue Oct 25 05:06:12 2011 From: brian at ubuntu.com (Brian Murray) Date: Tue, 25 Oct 2011 05:06:12 -0000 Subject: [ubuntu/natty-proposed] isc-dhcp 4.1.1-P1-15ubuntu9.2 (Accepted) Message-ID: <20111025050612.27558.94562.launchpad@soybean.canonical.com> isc-dhcp (4.1.1-P1-15ubuntu9.2) natty-proposed; urgency=low * modify AppArmor profile for DHCP server to work with IPv6 thanks to Launchpad user nikolas for the patch (LP: #787212) Date: Mon, 10 Oct 2011 08:25:07 -0700 Changed-By: Brian Murray Maintainer: Ubuntu Developers Signed-By: Steve Langasek https://launchpad.net/ubuntu/natty/+source/isc-dhcp/4.1.1-P1-15ubuntu9.2 -------------- next part -------------- Format: 1.8 Date: Mon, 10 Oct 2011 08:25:07 -0700 Source: isc-dhcp Binary: isc-dhcp-server isc-dhcp-server-dbg isc-dhcp-server-ldap isc-dhcp-common isc-dhcp-dev isc-dhcp-client isc-dhcp-client-dbg isc-dhcp-client-udeb isc-dhcp-relay isc-dhcp-relay-dbg dhcp3-server dhcp3-client dhcp3-relay dhcp3-common dhcp3-dev Architecture: source Version: 4.1.1-P1-15ubuntu9.2 Distribution: natty-proposed Urgency: low Maintainer: Ubuntu Developers Changed-By: Brian Murray Description: dhcp3-client - ISC DHCP server (transitional package) dhcp3-common - ISC DHCP common files (transitional package) dhcp3-dev - ISC DHCP development files (transitional package) dhcp3-relay - ISC DHCP relay (transitional package) dhcp3-server - ISC DHCP server (transitional package) isc-dhcp-client - ISC DHCP client isc-dhcp-client-dbg - ISC DHCP client (debugging symbols) isc-dhcp-client-udeb - ISC DHCP Client for debian-installer (udeb) isc-dhcp-common - common files used by all the isc-dhcp* packages isc-dhcp-dev - API for accessing and modifying the DHCP server and client state isc-dhcp-relay - ISC DHCP relay daemon isc-dhcp-relay-dbg - DHCP relay daemon (debugging symbols) isc-dhcp-server - ISC DHCP server for automatic IP address assignment isc-dhcp-server-dbg - ISC DHCP server for automatic IP address assignment (debug) isc-dhcp-server-ldap - DHCP server able to use LDAP as backend Launchpad-Bugs-Fixed: 787212 Changes: isc-dhcp (4.1.1-P1-15ubuntu9.2) natty-proposed; urgency=low . * modify AppArmor profile for DHCP server to work with IPv6 thanks to Launchpad user nikolas for the patch (LP: #787212) Checksums-Sha1: 891f51e33b08ab96bdd8e676756cfb4a826cb6ae 2340 isc-dhcp_4.1.1-P1-15ubuntu9.2.dsc f21ca0b6533550647192ad049d209c65a3caa31a 154690 isc-dhcp_4.1.1-P1-15ubuntu9.2.diff.gz Checksums-Sha256: b675f729a9f6c22552442a5c3b6977f77162617a5ddca671a293c30e5f956f3b 2340 isc-dhcp_4.1.1-P1-15ubuntu9.2.dsc 08eb37593d9f5095ef7422c85d53ffb8feddf495aa5ae3af84f7ab7baeb7baf0 154690 isc-dhcp_4.1.1-P1-15ubuntu9.2.diff.gz Files: 98581fa7a970c7b4af276ad3d6c58728 2340 net important isc-dhcp_4.1.1-P1-15ubuntu9.2.dsc b1cfd7543d96ab8325a4dcb47cf7f518 154690 net important isc-dhcp_4.1.1-P1-15ubuntu9.2.diff.gz Original-Maintainer: Debian ISC DHCP maintainers From stefanor at ubuntu.com Tue Oct 25 05:06:35 2011 From: stefanor at ubuntu.com (Stefano Rivera) Date: Tue, 25 Oct 2011 05:06:35 -0000 Subject: [ubuntu/natty-proposed] microcode.ctl 1.17-13ubuntu2.1 (Accepted) Message-ID: <20111025050635.22015.48956.launchpad@gac.canonical.com> microcode.ctl (1.17-13ubuntu2.1) natty-proposed; urgency=low * Fix failure to untar firmware from Intel, due to internal filename change. Thanks to Daniel J Blueman for the patch. (LP: #783239) Date: Thu, 20 Oct 2011 18:22:44 +0200 Changed-By: Stefano Rivera Maintainer: Ubuntu Developers https://launchpad.net/ubuntu/natty/+source/microcode.ctl/1.17-13ubuntu2.1 -------------- next part -------------- Format: 1.8 Date: Thu, 20 Oct 2011 18:22:44 +0200 Source: microcode.ctl Binary: microcode.ctl Architecture: source Version: 1.17-13ubuntu2.1 Distribution: natty-proposed Urgency: low Maintainer: Ubuntu Developers Changed-By: Stefano Rivera Description: microcode.ctl - Intel IA32/IA64 CPU Microcode Utility Launchpad-Bugs-Fixed: 783239 Changes: microcode.ctl (1.17-13ubuntu2.1) natty-proposed; urgency=low . * Fix failure to untar firmware from Intel, due to internal filename change. Thanks to Daniel J Blueman for the patch. (LP: #783239) Checksums-Sha1: 3e284340898d4800b235fa921942c2e61ca5d220 1867 microcode.ctl_1.17-13ubuntu2.1.dsc e385927498d65150b5a9864aca6daf0c2adbdd98 18601 microcode.ctl_1.17-13ubuntu2.1.diff.gz Checksums-Sha256: d9fee714b4d3a5d3c06de4a4631c6d0fd87c231dfb44386d61d29bf8e2ae38d9 1867 microcode.ctl_1.17-13ubuntu2.1.dsc 4bfa9dc18a826a27e111f1b116c8c1586654719af5491baa3960c53c542a7591 18601 microcode.ctl_1.17-13ubuntu2.1.diff.gz Files: 68d877b2e45d7d23b272966a8c623103 1867 contrib/utils optional microcode.ctl_1.17-13ubuntu2.1.dsc b469df095df0e1656decc2ae807c0da4 18601 contrib/utils optional microcode.ctl_1.17-13ubuntu2.1.diff.gz Original-Maintainer: Giacomo Catenazzi From jamie at ubuntu.com Tue Oct 25 17:03:31 2011 From: jamie at ubuntu.com (Jamie Strandboge) Date: Tue, 25 Oct 2011 17:03:31 -0000 Subject: [ubuntu/natty-security] nova_2011.2-0ubuntu1.1_i386_translations.tar.gz, nova 2011.2-0ubuntu1.1 (Accepted) Message-ID: <20111025170331.29049.76122.launchpad@cocoplum.canonical.com> nova (2011.2-0ubuntu1.1) natty-security; urgency=low * SECURITY UPDATE: fix information leak via invalid key debina/patches/security-fix-lp868360.patch: adjust nova/auth/manager.py to not return access, secret or admin fields for User error and project_manager_id, description and member_ids for Project - LP: #868360 - CVE-2011-XXXX Date: Tue, 25 Oct 2011 09:04:51 -0500 Changed-By: Jamie Strandboge Maintainer: Soren Hansen https://launchpad.net/ubuntu/natty/+source/nova/2011.2-0ubuntu1.1 -------------- next part -------------- Format: 1.8 Date: Tue, 25 Oct 2011 09:04:51 -0500 Source: nova Binary: python-nova nova-common nova-compute nova-scheduler nova-volume nova-ajax-console-proxy nova-api nova-network nova-objectstore nova-instancemonitor nova-doc Architecture: source Version: 2011.2-0ubuntu1.1 Distribution: natty-security Urgency: low Maintainer: Soren Hansen Changed-By: Jamie Strandboge Description: nova-ajax-console-proxy - OpenStack Compute - Nova - AJAX console proxy nova-api - OpenStack Compute - Nova - API frontend nova-common - OpenStack Compute - Nova - common files nova-compute - OpenStack Compute - Nova - compute node nova-doc - OpenStack Compute - Nova - documetation nova-instancemonitor - Nova instance monitor nova-network - OpenStack Compute - Nova - Network thingamajig nova-objectstore - OpenStack Compute - Nova - object store nova-scheduler - OpenStack Compute - Nova - Scheduler nova-volume - OpenStack Compute - Nova - storage python-nova - OpenStack Compute - Nova - Python libraries Launchpad-Bugs-Fixed: 868360 Changes: nova (2011.2-0ubuntu1.1) natty-security; urgency=low . * SECURITY UPDATE: fix information leak via invalid key debina/patches/security-fix-lp868360.patch: adjust nova/auth/manager.py to not return access, secret or admin fields for User error and project_manager_id, description and member_ids for Project - LP: #868360 - CVE-2011-XXXX Checksums-Sha1: f452951f2acf7d7bd453e84966b189bc79508f43 2572 nova_2011.2-0ubuntu1.1.dsc 4397d5779e14b5064e7fee12a10263a3423748e3 13739 nova_2011.2-0ubuntu1.1.debian.tar.gz Checksums-Sha256: 83add84b5a1794ea7ed61603a8ae797d1aff7f30eaee218b746293ef6634c77d 2572 nova_2011.2-0ubuntu1.1.dsc 970969ea52e28a160e6c29fbf6db0e3def4983b78f10cc685d993706cb5cea73 13739 nova_2011.2-0ubuntu1.1.debian.tar.gz Files: 93b8f0401e0643a4d7a9d232b99f17f3 2572 net extra nova_2011.2-0ubuntu1.1.dsc 461bdcb2e3bda12de807ba5908125a75 13739 net extra nova_2011.2-0ubuntu1.1.debian.tar.gz From marc.deslauriers at ubuntu.com Tue Oct 25 19:03:21 2011 From: marc.deslauriers at ubuntu.com (Marc Deslauriers) Date: Tue, 25 Oct 2011 19:03:21 -0000 Subject: [ubuntu/natty-security] puppet 2.6.4-2ubuntu2.6 (Accepted) Message-ID: <20111025190321.7575.59687.launchpad@cocoplum.canonical.com> puppet (2.6.4-2ubuntu2.6) natty-security; urgency=low * REGRESSION FIX (LP: #881361) - debian/patches/CVE-2011-3872.patch: updated to fix regression with "puppetca" command. Date: Tue, 25 Oct 2011 13:16:29 -0400 Changed-By: Marc Deslauriers Maintainer: Ubuntu Developers https://launchpad.net/ubuntu/natty/+source/puppet/2.6.4-2ubuntu2.6 -------------- next part -------------- Format: 1.8 Date: Tue, 25 Oct 2011 13:16:29 -0400 Source: puppet Binary: puppet-common puppet puppetmaster-common puppetmaster puppetmaster-passenger vim-puppet puppet-el puppet-testsuite Architecture: source Version: 2.6.4-2ubuntu2.6 Distribution: natty-security Urgency: low Maintainer: Ubuntu Developers Changed-By: Marc Deslauriers Description: puppet - Centralized configuration management - agent startup and compatib puppet-common - Centralized configuration management puppet-el - syntax highlighting for puppet manifests in emacs puppet-testsuite - Centralized configuration management - test suite puppetmaster - Centralized configuration management - master startup and compati puppetmaster-common - Puppet master common scripts puppetmaster-passenger - Centralised configuration management - master setup to run under vim-puppet - syntax highlighting for puppet manifests in vim Launchpad-Bugs-Fixed: 881361 Changes: puppet (2.6.4-2ubuntu2.6) natty-security; urgency=low . * REGRESSION FIX (LP: #881361) - debian/patches/CVE-2011-3872.patch: updated to fix regression with "puppetca" command. Checksums-Sha1: 520d5080fa08769622ee740701fc83d1828070f0 2296 puppet_2.6.4-2ubuntu2.6.dsc c3aaa6f29d72bf0ce2a883e50b570756a8302d61 86437 puppet_2.6.4-2ubuntu2.6.debian.tar.gz Checksums-Sha256: 1c739b5499921e68bf656b7723c4149c36070e8eed41f0961afcce593dade709 2296 puppet_2.6.4-2ubuntu2.6.dsc 4aaff6d6a78605baaa8b002d58a58f97472c158a93e91ba9642b32a5e2fc734a 86437 puppet_2.6.4-2ubuntu2.6.debian.tar.gz Files: e4caac2d0c6d654ec60dff484eec6d33 2296 admin optional puppet_2.6.4-2ubuntu2.6.dsc 2f8007fe42492c9e11acf49a74bc4b47 86437 admin optional puppet_2.6.4-2ubuntu2.6.debian.tar.gz Original-Maintainer: Puppet Package Maintainers From jamie at ubuntu.com Tue Oct 25 22:03:24 2011 From: jamie at ubuntu.com (Jamie Strandboge) Date: Tue, 25 Oct 2011 22:03:24 -0000 Subject: [ubuntu/natty-security] kde4libs_4.6.5-0ubuntu1.1_powerpc_translations.tar.gz, kde4libs_4.6.5-0ubuntu1.1_amd64_translations.tar.gz, kde4libs_4.6.5-0ubuntu1.1_armel_translations.tar.gz, kde4libs, kde4libs_4.6.5-0ubuntu1.1_i386_translations.tar.gz 4:4.6.5-0ubuntu1.1 (Accepted) Message-ID: <20111025220324.5553.54767.launchpad@cocoplum.canonical.com> kde4libs (4:4.6.5-0ubuntu1.1) natty-security; urgency=low * SECURITY UPDATE: Fix vulnerability in kioslave which let the opportunity to interpret html tags - debian/patches/security_04_CVE-2011-3365-kioslave.patch: Use HTML escaping on texts that come from the website. - LP: #857437 Date: Fri, 14 Oct 2011 10:20:24 -0500 Changed-By: Jamie Strandboge Maintainer: Kubuntu Developers https://launchpad.net/ubuntu/natty/+source/kde4libs/4:4.6.5-0ubuntu1.1 -------------- next part -------------- Format: 1.8 Date: Fri, 14 Oct 2011 10:20:24 -0500 Source: kde4libs Binary: libkdecore5 libkdeui5 libkpty4 libkdesu5 libkjsapi4 libkjsembed4 libkio5 libkntlm4 libsolid4 libkde3support4 libkfile4 libknewstuff2-4 libknewstuff3-4 libkparts4 libkutils4 libthreadweaver4 libkhtml5 libkimproxy4 libkmediaplayer4 libktexteditor4 libknotifyconfig4 libkdnssd4 libkrosscore4 libkrossui4 libnepomuk4 libnepomukutils4 libnepomukquery4a libplasma3 libkunitconversion4 libkdewebkit5 libkatepartinterfaces4 libkcmutils4 libkemoticons4 libkidletime4 libkprintutils4 kdelibs-bin kdelibs5-plugins kdelibs5-data kdoctools kdelibs5-dev kdelibs5 kdelibs5-dbg Architecture: source Version: 4:4.6.5-0ubuntu1.1 Distribution: natty-security Urgency: low Maintainer: Kubuntu Developers Changed-By: Jamie Strandboge Description: kdelibs-bin - core executables for KDE Applications kdelibs5 - transitional package for the KDE Development Platform libraries kdelibs5-data - core shared data for all KDE Applications kdelibs5-dbg - debugging symbols for the KDE Development Platform libraries kdelibs5-dev - development files for the KDE Development Platform libraries kdelibs5-plugins - core plugins for KDE Applications kdoctools - various tools for accessing application documentation libkatepartinterfaces4 - the kate part library libkcmutils4 - utility classes for using KCM modules libkde3support4 - the KDE 3 Support Library for the KDE 4 Platform libkdecore5 - the KDE Platform Core Library libkdesu5 - the Console-mode Authentication Library for the KDE Platform libkdeui5 - the KDE Platform User Interface Library libkdewebkit5 - the KDE WebKit Library libkdnssd4 - the DNS-SD Protocol Library for the KDE Platform libkemoticons4 - utility classes to deal with emoticon themes libkfile4 - the File Selection Dialog Library for KDE Platform libkhtml5 - the KHTML Web Content Rendering Engine libkidletime4 - library to provide information about idle time libkimproxy4 - the Instant Messaging Interface Library for the KDE Platform libkio5 - the Network-enabled File Management Library for the KDE Platform libkjsapi4 - the KJS API Library for the KDE Development Platform libkjsembed4 - library for binding JavaScript objects to QObjects libkmediaplayer4 - the KMediaPlayer Interface for the KDE Platform libknewstuff2-4 - the "Get Hot New Stuff" v2 Library for the KDE Platform libknewstuff3-4 - the "Get Hot New Stuff" v3 Library for the KDE Platform libknotifyconfig4 - library for configuring KDE Notifications libkntlm4 - the NTLM Authentication Library for the KDE Platform libkparts4 - the Framework for the KDE Platform Graphical Components libkprintutils4 - utility classes to deal with printing libkpty4 - the Pseudo Terminal Library for the KDE Platform libkrosscore4 - the Kross Core Library libkrossui4 - the Kross UI Library libktexteditor4 - the KTextEditor interfaces for the KDE Platform libkunitconversion4 - the Unit Conversion library for the KDE Platform libkutils4 - dummy transitional library libnepomuk4 - the Nepomuk Meta Data Library libnepomukquery4a - the Nepomuk Query Library for the KDE Platform libnepomukutils4 - the Nepomuk Utility Library libplasma3 - the Plasma Library for the KDE Platform libsolid4 - Solid Library for KDE Platform libthreadweaver4 - the ThreadWeaver Library for the KDE Platform Launchpad-Bugs-Fixed: 857437 Changes: kde4libs (4:4.6.5-0ubuntu1.1) natty-security; urgency=low . * SECURITY UPDATE: Fix vulnerability in kioslave which let the opportunity to interpret html tags - debian/patches/security_04_CVE-2011-3365-kioslave.patch: Use HTML escaping on texts that come from the website. - LP: #857437 Checksums-Sha1: 36e05a1f71600ace1a9dd705814a76d7368475d5 3589 kde4libs_4.6.5-0ubuntu1.1.dsc 35e6e25243502369f65c68c66560592f5652d0c4 426004 kde4libs_4.6.5-0ubuntu1.1.debian.tar.gz Checksums-Sha256: c020dfaf04ceb11d6768acdadf8da4d0398a6f96f655cb5add6483abd25d6f4b 3589 kde4libs_4.6.5-0ubuntu1.1.dsc 5784ec31bbab54a6412217ecc3596d7977e8e08fc52fefcbc0065a6570fdc5bb 426004 kde4libs_4.6.5-0ubuntu1.1.debian.tar.gz Files: 814e01c77a9f05db14ab02f947db85f5 3589 libs optional kde4libs_4.6.5-0ubuntu1.1.dsc 588ef03f7c364b14f84b8a67dc6cce5f 426004 libs optional kde4libs_4.6.5-0ubuntu1.1.debian.tar.gz Original-Maintainer: Debian Qt/KDE Maintainers From scott at kitterman.com Thu Oct 27 04:20:54 2011 From: scott at kitterman.com (Scott Kitterman) Date: Thu, 27 Oct 2011 04:20:54 -0000 Subject: [ubuntu/natty-proposed] clamav 0.97.3+dfsg-1ubuntu0.11.04 (Accepted) Message-ID: <20111027042054.7920.80777.launchpad@gac.canonical.com> clamav (0.97.3+dfsg-1ubuntu0.11.04) natty-proposed; urgency=low * Update to new clamav version per microversion release exception (LP: #882031) clamav (0.97.3+dfsg-1ubuntu1) precise; urgency=low * Merge from Debian unstable. Remaining changes: - Drop build-dep on electric-fence (in Universe) - Add apparmor profiles for clamd and freshclam along with maintainer script changes clamav (0.97.3+dfsg-1) unstable; urgency=medium [ Michael Tautschnig ] * New upstream release: Fixes potential DoS Date: Wed, 26 Oct 2011 13:05:52 -0400 Changed-By: Scott Kitterman Maintainer: Ubuntu Developers https://launchpad.net/ubuntu/natty/+source/clamav/0.97.3+dfsg-1ubuntu0.11.04 -------------- next part -------------- Format: 1.8 Date: Wed, 26 Oct 2011 13:05:52 -0400 Source: clamav Binary: clamav-base clamav-docs clamav-dbg clamav libclamav-dev libclamav6 clamav-daemon clamav-testfiles clamav-freshclam clamav-milter Architecture: source Version: 0.97.3+dfsg-1ubuntu0.11.04 Distribution: natty-proposed Urgency: medium Maintainer: Ubuntu Developers Changed-By: Scott Kitterman Description: clamav - anti-virus utility for Unix - command-line interface clamav-base - anti-virus utility for Unix - base package clamav-daemon - anti-virus utility for Unix - scanner daemon clamav-dbg - debug symbols for ClamAV clamav-docs - anti-virus utility for Unix - documentation clamav-freshclam - anti-virus utility for Unix - virus database update utility clamav-milter - anti-virus utility for Unix - sendmail integration clamav-testfiles - anti-virus utility for Unix - test files libclamav-dev - anti-virus utility for Unix - development files libclamav6 - anti-virus utility for Unix - library Launchpad-Bugs-Fixed: 882031 Changes: clamav (0.97.3+dfsg-1ubuntu0.11.04) natty-proposed; urgency=low . * Update to new clamav version per microversion release exception (LP: #882031) . clamav (0.97.3+dfsg-1ubuntu1) precise; urgency=low . * Merge from Debian unstable. Remaining changes: - Drop build-dep on electric-fence (in Universe) - Add apparmor profiles for clamd and freshclam along with maintainer script changes . clamav (0.97.3+dfsg-1) unstable; urgency=medium . [ Michael Tautschnig ] * New upstream release: Fixes potential DoS Checksums-Sha1: d5741c84a18f2abb540f9ea233fb5df86dcd8779 1667 clamav_0.97.3+dfsg-1ubuntu0.11.04.dsc ca4819038d9f49b7c7b8963aee22598e8f5f8ece 295342 clamav_0.97.3+dfsg-1ubuntu0.11.04.diff.gz Checksums-Sha256: 109b2c4def173f1bee0dbe9264666a892e1341ff95d8aa06f5402e421bd73f16 1667 clamav_0.97.3+dfsg-1ubuntu0.11.04.dsc 24ed093f93cf33212e948523b50405b68a6bf32a0cd5416b12f628d60f82274d 295342 clamav_0.97.3+dfsg-1ubuntu0.11.04.diff.gz Files: bacf2c8266ed8d8bccaae58c37afc782 1667 utils optional clamav_0.97.3+dfsg-1ubuntu0.11.04.dsc 8ca973b12af2f3d127929783f287a73b 295342 utils optional clamav_0.97.3+dfsg-1ubuntu0.11.04.diff.gz Original-Maintainer: ClamAV Team From colin at colino.net Thu Oct 27 04:21:23 2011 From: colin at colino.net (Colin Leroy) Date: Thu, 27 Oct 2011 04:21:23 -0000 Subject: [ubuntu/natty-proposed] gvfs 1.8.0-0ubuntu4 (Accepted) Message-ID: <20111027042123.16401.65244.launchpad@wampee.canonical.com> gvfs (1.8.0-0ubuntu4) natty-proposed; urgency=low * 11_webdav_recursive_copy.patch: SRU of patch that allows gvfs to correctly copy recursively from WebDAV shares (lp: #500863) Date: Wed, 28 Sep 2011 16:07:47 -0400 Changed-By: Colin Leroy Maintainer: Ubuntu Desktop Team Signed-By: Martin Pitt https://launchpad.net/ubuntu/natty/+source/gvfs/1.8.0-0ubuntu4 -------------- next part -------------- Format: 1.8 Date: Wed, 28 Sep 2011 16:07:47 -0400 Source: gvfs Binary: libgvfscommon0 libgvfscommon-dev gvfs gvfs-fuse gvfs-backends gvfs-bin Architecture: source Version: 1.8.0-0ubuntu4 Distribution: natty-proposed Urgency: low Maintainer: Ubuntu Desktop Team Changed-By: Colin Leroy Description: gvfs - userspace virtual filesystem - server gvfs-backends - userspace virtual filesystem - backends gvfs-bin - userspace virtual filesystem - binaries gvfs-fuse - userspace virtual filesystem - fuse server libgvfscommon-dev - userspace virtual filesystem - development files libgvfscommon0 - userspace virtual filesystem - library Launchpad-Bugs-Fixed: 500863 Changes: gvfs (1.8.0-0ubuntu4) natty-proposed; urgency=low . * 11_webdav_recursive_copy.patch: SRU of patch that allows gvfs to correctly copy recursively from WebDAV shares (lp: #500863) Checksums-Sha1: c371da427d24f2b092862a0b52fac9db4e5f9339 2446 gvfs_1.8.0-0ubuntu4.dsc dc86e0ad59244223ed7578330b70a6b23f3186a2 20647 gvfs_1.8.0-0ubuntu4.debian.tar.gz Checksums-Sha256: 03d89f76d2ed67bf8701b362dbc36b6f4bda8a85697334bb140bdaaef49c96f2 2446 gvfs_1.8.0-0ubuntu4.dsc 275fbb94e636b6b617941fab93d48ecc424353e8ffe549eb13cca0524e23bd27 20647 gvfs_1.8.0-0ubuntu4.debian.tar.gz Files: 82f0edf62075cd9c019adb1038bf3e01 2446 libs optional gvfs_1.8.0-0ubuntu4.dsc cfdb387ec2ce257cc66dc4362eb82093 20647 libs optional gvfs_1.8.0-0ubuntu4.debian.tar.gz Original-Maintainer: Sebastien Bacher From jamie at ubuntu.com Thu Oct 27 13:03:19 2011 From: jamie at ubuntu.com (Jamie Strandboge) Date: Thu, 27 Oct 2011 13:03:19 -0000 Subject: [ubuntu/natty-security] libfcgi-perl 0.71-1+squeeze1build0.11.04.1 (Accepted) Message-ID: <20111027130319.31189.43527.launchpad@cocoplum.canonical.com> libfcgi-perl (0.71-1+squeeze1build0.11.04.1) natty-security; urgency=low * fake sync from Debian libfcgi-perl (0.71-1+squeeze1) stable-security; urgency=high * Team upload * Add patch from upstream bug tracker fixing CVE-2011-2766 Closes: #607479. Thaks to Ferdinand for reporting, Russ Allbery for the analysis and chansen for the patch. * control: update Vcs-* fields to point to Git Date: Wed, 26 Oct 2011 16:11:33 -0500 Changed-By: Jamie Strandboge Maintainer: Debian Perl Group https://launchpad.net/ubuntu/natty/+source/libfcgi-perl/0.71-1+squeeze1build0.11.04.1 -------------- next part -------------- Format: 1.8 Date: Wed, 26 Oct 2011 16:11:33 -0500 Source: libfcgi-perl Binary: libfcgi-perl Architecture: source Version: 0.71-1+squeeze1build0.11.04.1 Distribution: natty-security Urgency: high Maintainer: Debian Perl Group Changed-By: Jamie Strandboge Description: libfcgi-perl - helper module for FastCGI Closes: 607479 Changes: libfcgi-perl (0.71-1+squeeze1build0.11.04.1) natty-security; urgency=low . * fake sync from Debian . libfcgi-perl (0.71-1+squeeze1) stable-security; urgency=high . * Team upload . * Add patch from upstream bug tracker fixing CVE-2011-2766 Closes: #607479. Thaks to Ferdinand for reporting, Russ Allbery for the analysis and chansen for the patch. * control: update Vcs-* fields to point to Git Checksums-Sha1: 286b16581630887e3c9750146e666b69fe0b734d 2089 libfcgi-perl_0.71-1+squeeze1build0.11.04.1.dsc 045939113b8fc89fbc7bb5c9505081c7c180373e 5331 libfcgi-perl_0.71-1+squeeze1build0.11.04.1.debian.tar.gz Checksums-Sha256: 3d79988aa837bafd2086ba718edb2a0492482fc71f03c96b86cdd45170c541db 2089 libfcgi-perl_0.71-1+squeeze1build0.11.04.1.dsc d876b072473294a3d33c42cb2066528010a4d261cc7aa288ba02f43af0ae092c 5331 libfcgi-perl_0.71-1+squeeze1build0.11.04.1.debian.tar.gz Files: 010ac8b8605fd404be346902aa01db05 2089 perl optional libfcgi-perl_0.71-1+squeeze1build0.11.04.1.dsc 007c6481a27ad20a7d4ec4d6f030bf80 5331 perl optional libfcgi-perl_0.71-1+squeeze1build0.11.04.1.debian.tar.gz From jamie at ubuntu.com Thu Oct 27 22:03:42 2011 From: jamie at ubuntu.com (Jamie Strandboge) Date: Thu, 27 Oct 2011 22:03:42 -0000 Subject: [ubuntu/natty-security] backuppc, backuppc_3.2.0-3ubuntu4.2_i386_translations.tar.gz 3.2.0-3ubuntu4.2 (Accepted) Message-ID: <20111027220342.28313.24823.launchpad@cocoplum.canonical.com> backuppc (3.2.0-3ubuntu4.2) natty-security; urgency=low * SECURITY UPDATE: XSS in CGI/Browse.pm - lib/BackupPC/CGI/Browse.pm: update to verify backup number is numeric - http://backuppc.cvs.sourceforge.net/viewvc/backuppc/BackupPC/lib/BackupPC/CGI/Browse.pm?r1=1.23&r2=1.24&view=patch - CVE-2011-3361 * SECURITY UPDATE: XSS in CGI/View.pm - lib/BackupPC/CGI/View.pm: update to verify backup number is numeric - CVE-2011-XXXX Date: Thu, 27 Oct 2011 14:27:58 -0500 Changed-By: Jamie Strandboge Maintainer: Ubuntu Developers https://launchpad.net/ubuntu/natty/+source/backuppc/3.2.0-3ubuntu4.2 -------------- next part -------------- Format: 1.8 Date: Thu, 27 Oct 2011 14:27:58 -0500 Source: backuppc Binary: backuppc Architecture: source Version: 3.2.0-3ubuntu4.2 Distribution: natty-security Urgency: low Maintainer: Ubuntu Developers Changed-By: Jamie Strandboge Description: backuppc - high-performance, enterprise-grade system for backing up PCs Changes: backuppc (3.2.0-3ubuntu4.2) natty-security; urgency=low . * SECURITY UPDATE: XSS in CGI/Browse.pm - lib/BackupPC/CGI/Browse.pm: update to verify backup number is numeric - http://backuppc.cvs.sourceforge.net/viewvc/backuppc/BackupPC/lib/BackupPC/CGI/Browse.pm?r1=1.23&r2=1.24&view=patch - CVE-2011-3361 * SECURITY UPDATE: XSS in CGI/View.pm - lib/BackupPC/CGI/View.pm: update to verify backup number is numeric - CVE-2011-XXXX Checksums-Sha1: 0c52acbb451867493a0619225376cfeefa329cfe 1771 backuppc_3.2.0-3ubuntu4.2.dsc 6125fca6c619bee4e3e9dbed1e95714533c3c31a 30313 backuppc_3.2.0-3ubuntu4.2.diff.gz Checksums-Sha256: 033b9c5e0b9a5c8f76ff45fd33d2e7c8cbf1f799b5622906c9f4bce2c3021859 1771 backuppc_3.2.0-3ubuntu4.2.dsc cb4dc3ad55af99365647002fabfdf2be296bc43a17b2990ed9afda36ebfd0e29 30313 backuppc_3.2.0-3ubuntu4.2.diff.gz Files: 12d72b1224202522d9c04ffc10689d55 1771 utils optional backuppc_3.2.0-3ubuntu4.2.dsc 86582b62fca6f134a7ccb961152b88cf 30313 utils optional backuppc_3.2.0-3ubuntu4.2.diff.gz Original-Maintainer: Ludovic Drolez From sbeattie at ubuntu.com Fri Oct 28 17:05:03 2011 From: sbeattie at ubuntu.com (Steve Beattie) Date: Fri, 28 Oct 2011 17:05:03 -0000 Subject: [ubuntu/natty-security] empathy, empathy_2.34.0-0ubuntu3.2_armel_translations.tar.gz, empathy_2.34.0-0ubuntu3.2_i386_translations.tar.gz, empathy_2.34.0-0ubuntu3.2_static_translations.tar.gz, empathy_2.34.0-0ubuntu3.2_amd64_translations.tar.gz, empathy_2.34.0-0ubuntu3.2_powerpc_translations.tar.gz 2.34.0-0ubuntu3.2 (Accepted) Message-ID: <20111028170503.18815.77831.launchpad@cocoplum.canonical.com> empathy (2.34.0-0ubuntu3.2) natty-security; urgency=low * SECURITY UPDATE: remote HTML injection (LP: #879301) - debian/patches/75_empathy-CVE-2011-3635-lp879301.patch: escape HTML in when displaying other users' names. (Thanks to upstream for patch.) - CVE-2011-3635, CVE-2011-4170 Date: Tue, 25 Oct 2011 15:21:46 -0700 Changed-By: Steve Beattie Maintainer: Ubuntu Developers https://launchpad.net/ubuntu/natty/+source/empathy/2.34.0-0ubuntu3.2 -------------- next part -------------- Format: 1.8 Date: Tue, 25 Oct 2011 15:21:46 -0700 Source: empathy Binary: empathy empathy-dbg empathy-common nautilus-sendto-empathy Architecture: source Version: 2.34.0-0ubuntu3.2 Distribution: natty-security Urgency: low Maintainer: Ubuntu Developers Changed-By: Steve Beattie Description: empathy - GNOME multi-protocol chat and call client empathy-common - GNOME multi-protocol chat and call client (common files) empathy-dbg - GNOME multi-protocol chat and call client (debug symbols) nautilus-sendto-empathy - GNOME multi-protocol chat and call client (nautilus-sendto plugin Launchpad-Bugs-Fixed: 879301 Changes: empathy (2.34.0-0ubuntu3.2) natty-security; urgency=low . * SECURITY UPDATE: remote HTML injection (LP: #879301) - debian/patches/75_empathy-CVE-2011-3635-lp879301.patch: escape HTML in when displaying other users' names. (Thanks to upstream for patch.) - CVE-2011-3635, CVE-2011-4170 Checksums-Sha1: 25b9de6685aef45cac450ebe1e075b2e46766619 3246 empathy_2.34.0-0ubuntu3.2.dsc 95df72320acb1a798a0b7159f6e172a5f24f11ef 37831 empathy_2.34.0-0ubuntu3.2.debian.tar.bz2 Checksums-Sha256: 6e048c9cf25fb885d60a75e3786e417212102dd8281e83f31748f9f9bcfac7ac 3246 empathy_2.34.0-0ubuntu3.2.dsc ab3db6dc23e0528b06620f81102560a7ff3e80d0b028b49b4d8ecd9a7109420b 37831 empathy_2.34.0-0ubuntu3.2.debian.tar.bz2 Files: 7fc4e989036522b32dd43af612189ca6 3246 gnome optional empathy_2.34.0-0ubuntu3.2.dsc 768a1b9f98786cd07ef72e04f98646bb 37831 gnome optional empathy_2.34.0-0ubuntu3.2.debian.tar.bz2 Original-Maintainer: Debian Telepathy maintainers From adconrad at ubuntu.com Fri Oct 28 21:56:24 2011 From: adconrad at ubuntu.com (Adam Conrad) Date: Fri, 28 Oct 2011 21:56:24 -0000 Subject: [ubuntu/natty-proposed] tzdata 2011m-0ubuntu0.11.04 (Accepted) Message-ID: <20111028215624.29436.85928.launchpad@cocoplum.canonical.com> tzdata (2011m-0ubuntu0.11.04) natty-proposed; urgency=low * New upstream version, fix DST for: - Pridnestrovian Moldavian Republic. - Ukraine (LP: #881250). - Bahia, Brazil. Date: Fri, 28 Oct 2011 14:47:37 -0600 Changed-By: Adam Conrad Maintainer: Ubuntu Developers https://launchpad.net/ubuntu/natty/+source/tzdata/2011m-0ubuntu0.11.04 -------------- next part -------------- Format: 1.8 Date: Fri, 28 Oct 2011 14:47:37 -0600 Source: tzdata Binary: tzdata tzdata-java Architecture: source Version: 2011m-0ubuntu0.11.04 Distribution: natty-proposed Urgency: low Maintainer: Ubuntu Developers Changed-By: Adam Conrad Description: tzdata - time zone and daylight-saving time data tzdata-java - time zone and daylight-saving time data for use by java runtimes Launchpad-Bugs-Fixed: 881250 Changes: tzdata (2011m-0ubuntu0.11.04) natty-proposed; urgency=low . * New upstream version, fix DST for: - Pridnestrovian Moldavian Republic. - Ukraine (LP: #881250). - Bahia, Brazil. Checksums-Sha1: 6f58d5510cd9b4d740a12f8005ae84cee83293a7 1268 tzdata_2011m-0ubuntu0.11.04.dsc e6374cd41c5bffd7ade27c365c4bdc5213bb9d85 204214 tzdata_2011m.orig.tar.gz 38aa8f6f0da143f87bab0bcdc2d034d53d07b10b 260959 tzdata_2011m-0ubuntu0.11.04.debian.tar.gz Checksums-Sha256: 2062f0eed21d06031ddbdb9511543e1c8be91901acd864918844bfe955749b22 1268 tzdata_2011m-0ubuntu0.11.04.dsc c8e01f5b4a3cd8b8aee84b4befb4b671cef34353e5af022ed22071f5b86ef5f4 204214 tzdata_2011m.orig.tar.gz 16164bffa14903584a06881299979216b67d21fe0494c9de1f23a41d092cbb98 260959 tzdata_2011m-0ubuntu0.11.04.debian.tar.gz Files: 254e2773b94e0a4331bf1d2d1b5913ff 1268 libs required tzdata_2011m-0ubuntu0.11.04.dsc 6dc4455b62c951dcf367a239ca249e69 204214 libs required tzdata_2011m.orig.tar.gz cba44254b14f962262cdff1f8188d122 260959 libs required tzdata_2011m-0ubuntu0.11.04.debian.tar.gz Original-Maintainer: GNU Libc Maintainers From adamg at canonical.com Mon Oct 31 19:53:13 2011 From: adamg at canonical.com (Adam Gandelman) Date: Mon, 31 Oct 2011 19:53:13 -0000 Subject: [ubuntu/natty-proposed] facter 1.5.8-2ubuntu2.1 (Accepted) Message-ID: <20111031195313.8316.35055.launchpad@gac.canonical.com> facter (1.5.8-2ubuntu2.1) natty-proposed; urgency=low * debian/patches/reload_all_facts.patch: Reload all facts if the requested fact is not found. Ensures consistency after facts have been cleared. (LP: #876130) * debian/patches/fix_ec2_metadata_facts.patch: Properly handle ip+port when testing connectivity of ec2 metadata service.(LP: #732953) Date: Thu, 20 Oct 2011 10:40:35 -0700 Changed-By: Adam Gandelman Maintainer: Ubuntu Core Developers Signed-By: Luke Yelavich https://launchpad.net/ubuntu/natty/+source/facter/1.5.8-2ubuntu2.1 -------------- next part -------------- Format: 1.8 Date: Thu, 20 Oct 2011 10:40:35 -0700 Source: facter Binary: facter Architecture: source Version: 1.5.8-2ubuntu2.1 Distribution: natty-proposed Urgency: low Maintainer: Ubuntu Core Developers Changed-By: Adam Gandelman Description: facter - a library for retrieving facts from operating systems Launchpad-Bugs-Fixed: 732953 876130 Changes: facter (1.5.8-2ubuntu2.1) natty-proposed; urgency=low . * debian/patches/reload_all_facts.patch: Reload all facts if the requested fact is not found. Ensures consistency after facts have been cleared. (LP: #876130) * debian/patches/fix_ec2_metadata_facts.patch: Properly handle ip+port when testing connectivity of ec2 metadata service.(LP: #732953) Checksums-Sha1: 764fed13bd223233ac13c2f98cf94be81ef220a0 1490 facter_1.5.8-2ubuntu2.1.dsc e65fff0df929a982053903a2421500df781a79aa 7742 facter_1.5.8-2ubuntu2.1.debian.tar.gz Checksums-Sha256: b08bcdf1a5ce7649d74a0093e2de3dbec219cae170364233ab514d4001119f90 1490 facter_1.5.8-2ubuntu2.1.dsc e00549a59780f98ee0c4ab058844a16cfd6c3603e200a2d3c5d02b188da2d20c 7742 facter_1.5.8-2ubuntu2.1.debian.tar.gz Files: 5a709ea55c566da82c454939b8282087 1490 admin optional facter_1.5.8-2ubuntu2.1.dsc bf77e9e023c61c4a56647bc8c8c99770 7742 admin optional facter_1.5.8-2ubuntu2.1.debian.tar.gz Original-Maintainer: Puppet Package Maintainers