From marc.deslauriers at ubuntu.com Mon Apr 2 17:03:26 2012 From: marc.deslauriers at ubuntu.com (Marc Deslauriers) Date: Mon, 02 Apr 2012 17:03:26 -0000 Subject: [ubuntu/natty-security] aptdaemon, aptdaemon_0.41+bzr661-0ubuntu0.2_i386_translations.tar.gz 0.41+bzr661-0ubuntu0.2 (Accepted) Message-ID: <20120402170326.9342.27513.launchpad@cocoplum.canonical.com> aptdaemon (0.41+bzr661-0ubuntu0.2) natty-security; urgency=low * SECURITY UPDATE: unauthenticated package installation (LP: #959131) - debian/patches/04_CVE-2012-0944.patch: properly handle unauthenticated packages in aptdaemon/worker.py. - CVE-2012-0944 Date: Wed, 28 Mar 2012 13:54:38 -0400 Changed-By: Marc Deslauriers Maintainer: Ubuntu Developers https://launchpad.net/ubuntu/natty/+source/aptdaemon/0.41+bzr661-0ubuntu0.2 -------------- next part -------------- Format: 1.8 Date: Wed, 28 Mar 2012 13:54:38 -0400 Source: aptdaemon Binary: aptdaemon python-aptdaemon python-aptdaemon.test aptdaemon-data python-aptdaemon-gtk python-aptdaemon.gtkwidgets python-aptdaemon.gtk3widgets Architecture: source Version: 0.41+bzr661-0ubuntu0.2 Distribution: natty-security Urgency: low Maintainer: Ubuntu Developers Changed-By: Marc Deslauriers Description: aptdaemon - transaction based package management service aptdaemon-data - data files for clients python-aptdaemon - Python module for the server and client of aptdaemon python-aptdaemon-gtk - Transitional dummy package python-aptdaemon.gtk3widgets - Python GTK+ 3 widgets to run an aptdaemon client python-aptdaemon.gtkwidgets - Python GTK+ 2 widgets to run an aptdaemon client python-aptdaemon.test - Test environment for aptdaemon clients Launchpad-Bugs-Fixed: 959131 Changes: aptdaemon (0.41+bzr661-0ubuntu0.2) natty-security; urgency=low . * SECURITY UPDATE: unauthenticated package installation (LP: #959131) - debian/patches/04_CVE-2012-0944.patch: properly handle unauthenticated packages in aptdaemon/worker.py. - CVE-2012-0944 Checksums-Sha1: c1615dc2037179a403d693da7113af18229417ee 2327 aptdaemon_0.41+bzr661-0ubuntu0.2.dsc 930509f35a769a57c634eff3ffd1c4e18726bd2f 13726 aptdaemon_0.41+bzr661-0ubuntu0.2.debian.tar.gz Checksums-Sha256: 06b67110e8f55da7abbc77943a01e6d3d13943537a1b478691639abc29c21fce 2327 aptdaemon_0.41+bzr661-0ubuntu0.2.dsc 790dea666decdbf681fe611763402e77c7bd49099e409ee743dd95db7d2f5452 13726 aptdaemon_0.41+bzr661-0ubuntu0.2.debian.tar.gz Files: d51124616ea2d6325ab6dd76e6a23864 2327 admin extra aptdaemon_0.41+bzr661-0ubuntu0.2.dsc 3624add0aec83689a07f13abec2aba7e 13726 admin extra aptdaemon_0.41+bzr661-0ubuntu0.2.debian.tar.gz Original-Maintainer: Julian Andres Klode From marc.deslauriers at ubuntu.com Wed Apr 4 21:03:31 2012 From: marc.deslauriers at ubuntu.com (Marc Deslauriers) Date: Wed, 04 Apr 2012 21:03:31 -0000 Subject: [ubuntu/natty-security] tiff 3.9.4-5ubuntu6.1 (Accepted) Message-ID: <20120404210331.22395.18593.launchpad@cocoplum.canonical.com> tiff (3.9.4-5ubuntu6.1) natty-security; urgency=low * SECURITY UPDATE: denial of service and possible code execution via tiffdump - debian/patches/CVE-2010-4665.patch: prevent integer overflow in tools/tiffdump.c. - CVE-2010-4665 * SECURITY UPDATE: arbitrary code execution via size overflow - debian/patches/CVE-2012-1173.patch: use TIFFSafeMultiply in libtiff/tif_getimage.c, fix TIFFSafeMultiply in libtiff/tiffiop.h. - CVE-2012-1173 Date: Mon, 02 Apr 2012 10:55:03 -0400 Changed-By: Marc Deslauriers Maintainer: Ubuntu Developers https://launchpad.net/ubuntu/natty/+source/tiff/3.9.4-5ubuntu6.1 -------------- next part -------------- Format: 1.8 Date: Mon, 02 Apr 2012 10:55:03 -0400 Source: tiff Binary: libtiff4 libtiffxx0c2 libtiff4-dev libtiff-tools libtiff-opengl libtiff-doc Architecture: source Version: 3.9.4-5ubuntu6.1 Distribution: natty-security Urgency: low Maintainer: Ubuntu Developers Changed-By: Marc Deslauriers Description: libtiff-doc - TIFF manipulation and conversion documentation libtiff-opengl - TIFF manipulation and conversion tools libtiff-tools - TIFF manipulation and conversion tools libtiff4 - Tag Image File Format (TIFF) library libtiff4-dev - Tag Image File Format library (TIFF), development files libtiffxx0c2 - Tag Image File Format (TIFF) library -- C++ interface Changes: tiff (3.9.4-5ubuntu6.1) natty-security; urgency=low . * SECURITY UPDATE: denial of service and possible code execution via tiffdump - debian/patches/CVE-2010-4665.patch: prevent integer overflow in tools/tiffdump.c. - CVE-2010-4665 * SECURITY UPDATE: arbitrary code execution via size overflow - debian/patches/CVE-2012-1173.patch: use TIFFSafeMultiply in libtiff/tif_getimage.c, fix TIFFSafeMultiply in libtiff/tiffiop.h. - CVE-2012-1173 Checksums-Sha1: a5b7822ab66a93e9d3f6f16603cfb892e238e268 2002 tiff_3.9.4-5ubuntu6.1.dsc 4da2360088c01c5ab47e23183c4aa531ff33a47c 21153 tiff_3.9.4-5ubuntu6.1.debian.tar.gz Checksums-Sha256: 14e2e48cb955187565e39cd5ba2632c3e6796f26bfe97def436b08bf0b0ed527 2002 tiff_3.9.4-5ubuntu6.1.dsc 61c9c5e119aad55ce814eea0797800477bf94576aa5b83609f072e3a03df6cfc 21153 tiff_3.9.4-5ubuntu6.1.debian.tar.gz Files: 5cdc4ba720a2316c8fceb0556a102426 2002 libs optional tiff_3.9.4-5ubuntu6.1.dsc 5182bd3442d05526007b1fc13e340edc 21153 libs optional tiff_3.9.4-5ubuntu6.1.debian.tar.gz Original-Maintainer: Jay Berkenbilt From jamie at ubuntu.com Thu Apr 5 16:56:49 2012 From: jamie at ubuntu.com (Jamie Strandboge) Date: Thu, 05 Apr 2012 16:56:49 -0000 Subject: [ubuntu/natty-updates] chromium-browser 18.0.1025.142~r129054-0ubuntu0.11.04.1 (Accepted) Message-ID: <20120405165649.28731.10952.launchpad@ackee.canonical.com> chromium-browser (18.0.1025.142~r129054-0ubuntu0.11.04.1) natty-security; urgency=low * New upstream release from the Stable Channel (LP: #968901) This release fixes the following security issues: - [109574] Medium CVE-2011-3058: Bad interaction possibly leading to XSS in EUC-JP. Credit to Masato Kinugawa. - [112317] Medium CVE-2011-3059: Out-of-bounds read in SVG text handling. Credit to Arthur Gerkis. - [114056] Medium CVE-2011-3060: Out-of-bounds read in text fragment handling. Credit to miaubiz. - [116398] Medium CVE-2011-3061: SPDY proxy certificate checking error. Credit to Leonidas Kontothanassis of Google. - [116524] High CVE-2011-3062: Off-by-one in OpenType Sanitizer. Credit to Mateusz Jurczyk of the Google Security Team. - [117417] Low CVE-2011-3063: Validate navigation requests from the renderer more carefully. Credit to kuzzcc, Sergey Glazunov, PinkiePie and scarybeasts (Google Chrome Security Team). - [117471] High CVE-2011-3064: Use-after-free in SVG clipping. Credit to Atte Kettunen of OUSPG. - [117588] High CVE-2011-3065: Memory corruption in Skia. Credit to Omair. - [117794] Medium CVE-2011-3057: Invalid read in v8. Credit to Christian Holler. * Add build dependency on libudev-dev to allow for gamepad detection; see http://code.google.com/p/chromium/issues/detail?id=79050 - update debian/control * Drop dlopen_libgnutls patch as it's been implemented upstream - drop debian/patches/dlopen_libgnutls.patch - update debian/patches/series * Start removing *.so and *.so.* from the upstream tarball creation - update debian/rules * Strip almost the entire third_party/openssl directory as it's needed only on android, but is used by the build system - update debian/rules * Use tar's --exclude-vcs flag instead of just excluding .svn - update debian/rules chromium-browser (17.0.963.83~r127885-0ubuntu0.11.04.1) natty-security; urgency=low * New upstream release from the Stable Channel (LP: #961831) This release fixes the following security issues: - [113902] High CVE-2011-3050: Use-after-free with first-letter handling. Credit to miaubiz. - [116162] High CVE-2011-3045: libpng integer issue from upstream. Credit to Glenn Randers-Pehrson of the libpng project. - [116461] High CVE-2011-3051: Use-after-free in CSS cross-fade handling. Credit to Arthur Gerkis. - [116637] High CVE-2011-3052: Memory corruption in WebGL canvas handling. Credit to Ben Vanik of Google. - [116746] High CVE-2011-3053: Use-after-free in block splitting. Credit to miaubiz. - [117418] Low CVE-2011-3054: Apply additional isolations to webui privileges. Credit to Sergey Glazunov. - [117736] Low CVE-2011-3055: Prompt in the browser native UI for unpacked extension installation. Credit to PinkiePie. - [117550] High CVE-2011-3056: Cross-origin violation with “magic iframe”. Credit to Sergey Glazunov. - [117794] Medium CVE-2011-3057: Invalid read in v8. Credit to Christian Holler. Date: 2012-04-02 15:55:53.907304+00:00 Changed-By: Micah Gersten Maintainer: Fabien Tassin Signed-By: Jamie Strandboge https://launchpad.net/ubuntu/natty/+source/chromium-browser/18.0.1025.142~r129054-0ubuntu0.11.04.1 -------------- next part -------------- Sorry, changesfile not available. From jamie at ubuntu.com Thu Apr 5 17:56:19 2012 From: jamie at ubuntu.com (Jamie Strandboge) Date: Thu, 05 Apr 2012 17:56:19 -0000 Subject: [ubuntu/natty-security] chromium-browser 18.0.1025.142~r129054-0ubuntu0.11.04.1 (Accepted) Message-ID: <20120405175619.13350.5183.launchpad@ackee.canonical.com> chromium-browser (18.0.1025.142~r129054-0ubuntu0.11.04.1) natty-security; urgency=low * New upstream release from the Stable Channel (LP: #968901) This release fixes the following security issues: - [109574] Medium CVE-2011-3058: Bad interaction possibly leading to XSS in EUC-JP. Credit to Masato Kinugawa. - [112317] Medium CVE-2011-3059: Out-of-bounds read in SVG text handling. Credit to Arthur Gerkis. - [114056] Medium CVE-2011-3060: Out-of-bounds read in text fragment handling. Credit to miaubiz. - [116398] Medium CVE-2011-3061: SPDY proxy certificate checking error. Credit to Leonidas Kontothanassis of Google. - [116524] High CVE-2011-3062: Off-by-one in OpenType Sanitizer. Credit to Mateusz Jurczyk of the Google Security Team. - [117417] Low CVE-2011-3063: Validate navigation requests from the renderer more carefully. Credit to kuzzcc, Sergey Glazunov, PinkiePie and scarybeasts (Google Chrome Security Team). - [117471] High CVE-2011-3064: Use-after-free in SVG clipping. Credit to Atte Kettunen of OUSPG. - [117588] High CVE-2011-3065: Memory corruption in Skia. Credit to Omair. - [117794] Medium CVE-2011-3057: Invalid read in v8. Credit to Christian Holler. * Add build dependency on libudev-dev to allow for gamepad detection; see http://code.google.com/p/chromium/issues/detail?id=79050 - update debian/control * Drop dlopen_libgnutls patch as it's been implemented upstream - drop debian/patches/dlopen_libgnutls.patch - update debian/patches/series * Start removing *.so and *.so.* from the upstream tarball creation - update debian/rules * Strip almost the entire third_party/openssl directory as it's needed only on android, but is used by the build system - update debian/rules * Use tar's --exclude-vcs flag instead of just excluding .svn - update debian/rules chromium-browser (17.0.963.83~r127885-0ubuntu0.11.04.1) natty-security; urgency=low * New upstream release from the Stable Channel (LP: #961831) This release fixes the following security issues: - [113902] High CVE-2011-3050: Use-after-free with first-letter handling. Credit to miaubiz. - [116162] High CVE-2011-3045: libpng integer issue from upstream. Credit to Glenn Randers-Pehrson of the libpng project. - [116461] High CVE-2011-3051: Use-after-free in CSS cross-fade handling. Credit to Arthur Gerkis. - [116637] High CVE-2011-3052: Memory corruption in WebGL canvas handling. Credit to Ben Vanik of Google. - [116746] High CVE-2011-3053: Use-after-free in block splitting. Credit to miaubiz. - [117418] Low CVE-2011-3054: Apply additional isolations to webui privileges. Credit to Sergey Glazunov. - [117736] Low CVE-2011-3055: Prompt in the browser native UI for unpacked extension installation. Credit to PinkiePie. - [117550] High CVE-2011-3056: Cross-origin violation with “magic iframe”. Credit to Sergey Glazunov. - [117794] Medium CVE-2011-3057: Invalid read in v8. Credit to Christian Holler. Date: 2012-04-02 15:55:53.907304+00:00 Changed-By: Micah Gersten Maintainer: Fabien Tassin Signed-By: Jamie Strandboge https://launchpad.net/ubuntu/natty/+source/chromium-browser/18.0.1025.142~r129054-0ubuntu0.11.04.1 -------------- next part -------------- Sorry, changesfile not available. From marc.deslauriers at ubuntu.com Thu Apr 5 18:03:36 2012 From: marc.deslauriers at ubuntu.com (Marc Deslauriers) Date: Thu, 05 Apr 2012 18:03:36 -0000 Subject: [ubuntu/natty-security] libpng 1.2.44-1ubuntu3.4 (Accepted) Message-ID: <20120405180336.15178.82694.launchpad@cocoplum.canonical.com> libpng (1.2.44-1ubuntu3.4) natty-security; urgency=low * SECURITY UPDATE: denial of service and possible code execution via memory corruption issue. - debian/patches/CVE-2011-3048.patch: correctly restore to previous condition in pngset.c. - CVE-2011-3048 Date: Thu, 05 Apr 2012 08:40:00 -0400 Changed-By: Marc Deslauriers Maintainer: Ubuntu Developers https://launchpad.net/ubuntu/natty/+source/libpng/1.2.44-1ubuntu3.4 -------------- next part -------------- Format: 1.8 Date: Thu, 05 Apr 2012 08:40:00 -0400 Source: libpng Binary: libpng12-0 libpng12-dev libpng3 libpng12-0-udeb Architecture: source Version: 1.2.44-1ubuntu3.4 Distribution: natty-security Urgency: low Maintainer: Ubuntu Developers Changed-By: Marc Deslauriers Description: libpng12-0 - PNG library - runtime libpng12-0-udeb - PNG library - minimal runtime library (udeb) libpng12-dev - PNG library - development libpng3 - PNG library - runtime Changes: libpng (1.2.44-1ubuntu3.4) natty-security; urgency=low . * SECURITY UPDATE: denial of service and possible code execution via memory corruption issue. - debian/patches/CVE-2011-3048.patch: correctly restore to previous condition in pngset.c. - CVE-2011-3048 Checksums-Sha1: e025848a85113dd59a9b5101c625881906f63356 1950 libpng_1.2.44-1ubuntu3.4.dsc 3cfe1bbfcfd492ca9f6c86913d8b833b25a5c87a 18219 libpng_1.2.44-1ubuntu3.4.debian.tar.bz2 Checksums-Sha256: edc12643294cddbd7fb23159988b30a082d8dd6c6c0eae58c1bd650acf1b66f3 1950 libpng_1.2.44-1ubuntu3.4.dsc 1ebadc5914750e7283cd2c951261b16e23a813bfe92135e8295766ab04a973a1 18219 libpng_1.2.44-1ubuntu3.4.debian.tar.bz2 Files: 641e2fa5779becd008aa0187ecbb9592 1950 libs optional libpng_1.2.44-1ubuntu3.4.dsc 1dec566c3314de1aa031dcb4ed207853 18219 libs optional libpng_1.2.44-1ubuntu3.4.debian.tar.bz2 Original-Maintainer: Anibal Monsalve Salazar From tyhicks at canonical.com Thu Apr 5 22:03:44 2012 From: tyhicks at canonical.com (Tyler Hicks) Date: Thu, 05 Apr 2012 22:03:44 -0000 Subject: [ubuntu/natty-security] gnutls26_2.8.6-1ubuntu2.1_armel_translations.tar.gz, gnutls26_2.8.6-1ubuntu2.1_i386_translations.tar.gz, gnutls26, gnutls26_2.8.6-1ubuntu2.1_amd64_translations.tar.gz, gnutls26_2.8.6-1ubuntu2.1_powerpc_translations.tar.gz 2.8.6-1ubuntu2.1 (Accepted) Message-ID: <20120405220344.18468.91699.launchpad@cocoplum.canonical.com> gnutls26 (2.8.6-1ubuntu2.1) natty-security; urgency=low * SECURITY UPDATE: Denial of service in client application - debian/patches/CVE-2011-4128.patch: Fix buffer bounds check when copying session data. Based on upstream patch. - CVE-2011-4128 * SECURITY UPDATE: Denial of service via crafted TLS record - debian/patches/CVE-2012-1573.patch: Validate the size of a GenericBlockCipher structure as it is processed. Based on upstream patch. - CVE-2012-1573 Date: Wed, 04 Apr 2012 11:13:02 -0500 Changed-By: Tyler Hicks Maintainer: Ubuntu Developers https://launchpad.net/ubuntu/natty/+source/gnutls26/2.8.6-1ubuntu2.1 -------------- next part -------------- Format: 1.8 Date: Wed, 04 Apr 2012 11:13:02 -0500 Source: gnutls26 Binary: libgnutls-dev libgnutls26 libgnutls26-dbg gnutls-bin gnutls-doc guile-gnutls Architecture: source Version: 2.8.6-1ubuntu2.1 Distribution: natty-security Urgency: low Maintainer: Ubuntu Developers Changed-By: Tyler Hicks Description: gnutls-bin - the GNU TLS library - commandline utilities gnutls-doc - the GNU TLS library - documentation and examples guile-gnutls - the GNU TLS library - GNU Guile bindings libgnutls-dev - the GNU TLS library - development files libgnutls26 - the GNU TLS library - runtime library libgnutls26-dbg - GNU TLS library - debugger symbols Changes: gnutls26 (2.8.6-1ubuntu2.1) natty-security; urgency=low . * SECURITY UPDATE: Denial of service in client application - debian/patches/CVE-2011-4128.patch: Fix buffer bounds check when copying session data. Based on upstream patch. - CVE-2011-4128 * SECURITY UPDATE: Denial of service via crafted TLS record - debian/patches/CVE-2012-1573.patch: Validate the size of a GenericBlockCipher structure as it is processed. Based on upstream patch. - CVE-2012-1573 Checksums-Sha1: 892cd95c7fe63f6c7ebe6eea8f398179a3041362 2398 gnutls26_2.8.6-1ubuntu2.1.dsc a99adccab65cad86cafeb081e165f64bf6109a57 20949 gnutls26_2.8.6-1ubuntu2.1.debian.tar.gz Checksums-Sha256: 22afc1963fa02542724c0a018fbec8f8f1dab4dbbfbb8b75912a3b42de592965 2398 gnutls26_2.8.6-1ubuntu2.1.dsc fcef39271587c375e9bd51052f32e5b18fb077cf283ad8b1ed98d49543b957ab 20949 gnutls26_2.8.6-1ubuntu2.1.debian.tar.gz Files: caacf601bc911c6c71628d8995657188 2398 libs optional gnutls26_2.8.6-1ubuntu2.1.dsc 79af2282c7803c375098e528516ae7e3 20949 libs optional gnutls26_2.8.6-1ubuntu2.1.debian.tar.gz Original-Maintainer: Debian GnuTLS Maintainers From tyhicks at canonical.com Thu Apr 5 23:06:05 2012 From: tyhicks at canonical.com (Tyler Hicks) Date: Thu, 05 Apr 2012 23:06:05 -0000 Subject: [ubuntu/natty-security] typo3-src 4.3.9+dfsg1-1+squeeze3build0.11.04.1 (Accepted) Message-ID: <20120405230605.2435.93361.launchpad@cocoplum.canonical.com> typo3-src (4.3.9+dfsg1-1+squeeze3build0.11.04.1) natty-security; urgency=low * fake sync from Debian typo3-src (4.3.9+dfsg1-1+squeeze3) squeeze-security; urgency=high * Security patch backported from new upstream release 4.4.14: - fixes: "TYPO3 Security Bulletin TYPO3-CORE-SA-2012-001: Several Vulnerabilities in TYPO3 Core" (Closes: 666074) typo3-src (4.3.9+dfsg1-1+squeeze2) squeeze-security; urgency=high * Security patch from new upstream release 4.3.14: - fixes: "TYPO3 Security Bulletin TYPO3-CORE-SA-2011-003: Improper error handling could lead to cache flooding in TYPO3 Core" (Closes: 641683) Date: Wed, 04 Apr 2012 19:07:21 -0500 Changed-By: Tyler Hicks Maintainer: Christian Welzel https://launchpad.net/ubuntu/natty/+source/typo3-src/4.3.9+dfsg1-1+squeeze3build0.11.04.1 -------------- next part -------------- Format: 1.8 Date: Wed, 04 Apr 2012 19:07:21 -0500 Source: typo3-src Binary: typo3-src-4.3 typo3-database typo3 Architecture: source Version: 4.3.9+dfsg1-1+squeeze3build0.11.04.1 Distribution: natty-security Urgency: high Maintainer: Christian Welzel Changed-By: Tyler Hicks Description: typo3 - The enterprise level open source WebCMS (Meta) typo3-database - TYPO3 - The enterprise level open source WebCMS (Database) typo3-src-4.3 - TYPO3 - The enterprise level open source WebCMS (Core) Closes: 641683 666074 Changes: typo3-src (4.3.9+dfsg1-1+squeeze3build0.11.04.1) natty-security; urgency=low . * fake sync from Debian . typo3-src (4.3.9+dfsg1-1+squeeze3) squeeze-security; urgency=high . * Security patch backported from new upstream release 4.4.14: - fixes: "TYPO3 Security Bulletin TYPO3-CORE-SA-2012-001: Several Vulnerabilities in TYPO3 Core" (Closes: 666074) . typo3-src (4.3.9+dfsg1-1+squeeze2) squeeze-security; urgency=high . * Security patch from new upstream release 4.3.14: - fixes: "TYPO3 Security Bulletin TYPO3-CORE-SA-2011-003: Improper error handling could lead to cache flooding in TYPO3 Core" (Closes: 641683) Checksums-Sha1: 899f41cf5239f6c208db57ebad08895996fd0d46 1804 typo3-src_4.3.9+dfsg1-1+squeeze3build0.11.04.1.dsc 69a669b25c70a96ab02d17907f4cf2a936b3d484 132083 typo3-src_4.3.9+dfsg1-1+squeeze3build0.11.04.1.debian.tar.gz Checksums-Sha256: 1aa84a895ba74b82cac26856493943f07a9e79971795f7fc3b1750b7817b99f0 1804 typo3-src_4.3.9+dfsg1-1+squeeze3build0.11.04.1.dsc cb52c616074c44eaf9b047cffd3dc87b3175cc057d0775e1a7ba7cfd8865afcf 132083 typo3-src_4.3.9+dfsg1-1+squeeze3build0.11.04.1.debian.tar.gz Files: e192591654a0fe533cc1708360c689d5 1804 web optional typo3-src_4.3.9+dfsg1-1+squeeze3build0.11.04.1.dsc ac444dac585990bf5cd65359b6ec7d95 132083 web optional typo3-src_4.3.9+dfsg1-1+squeeze3build0.11.04.1.debian.tar.gz From tyhicks at canonical.com Thu Apr 5 23:06:10 2012 From: tyhicks at canonical.com (Tyler Hicks) Date: Thu, 05 Apr 2012 23:06:10 -0000 Subject: [ubuntu/natty-security] tryton-server 1.6.1-2+squeeze1build0.11.04.1 (Accepted) Message-ID: <20120405230610.2435.69313.launchpad@cocoplum.canonical.com> tryton-server (1.6.1-2+squeeze1build0.11.04.1) natty-security; urgency=low * fake sync from Debian tryton-server (1.6.1-2+squeeze1) stable-security; urgency=high * Adding patch for "Missing access control on some relation model for Many2Many" (https://bugs.tryton.org/issue2476). The issue is filed under CVE-2012-0215. Date: Wed, 04 Apr 2012 19:12:50 -0500 Changed-By: Tyler Hicks Maintainer: Debian Tryton Maintainers https://launchpad.net/ubuntu/natty/+source/tryton-server/1.6.1-2+squeeze1build0.11.04.1 -------------- next part -------------- Format: 1.8 Date: Wed, 04 Apr 2012 19:12:50 -0500 Source: tryton-server Binary: tryton-server Architecture: source Version: 1.6.1-2+squeeze1build0.11.04.1 Distribution: natty-security Urgency: high Maintainer: Debian Tryton Maintainers Changed-By: Tyler Hicks Description: tryton-server - Tryton Application Platform (Server) Changes: tryton-server (1.6.1-2+squeeze1build0.11.04.1) natty-security; urgency=low . * fake sync from Debian . tryton-server (1.6.1-2+squeeze1) stable-security; urgency=high . * Adding patch for "Missing access control on some relation model for Many2Many" (https://bugs.tryton.org/issue2476). The issue is filed under CVE-2012-0215. Checksums-Sha1: f33f515b8f2df7f08055710a842da3716a6ad8a5 2100 tryton-server_1.6.1-2+squeeze1build0.11.04.1.dsc 1a1042d5626f845f9bf4cf18142cd8b3bd2eb330 8060 tryton-server_1.6.1-2+squeeze1build0.11.04.1.diff.gz Checksums-Sha256: 7dfec99e795c991441d7553bdb3751d150e655be722d0b8a35600bca5f8d2a22 2100 tryton-server_1.6.1-2+squeeze1build0.11.04.1.dsc 4eaa3d0f9c39f888074f52fa0fdee364329c62e0f9a96f3d2e5055056b4892f9 8060 tryton-server_1.6.1-2+squeeze1build0.11.04.1.diff.gz Files: cb830072ba1106e7dad76fbf29c7fb05 2100 python optional tryton-server_1.6.1-2+squeeze1build0.11.04.1.dsc f71ac18bab09ce5c21cc4fb2601be30b 8060 python optional tryton-server_1.6.1-2+squeeze1build0.11.04.1.diff.gz From tyhicks at canonical.com Wed Apr 11 05:04:01 2012 From: tyhicks at canonical.com (Tyler Hicks) Date: Wed, 11 Apr 2012 05:04:01 -0000 Subject: [ubuntu/natty-security] puppet 2.6.4-2ubuntu2.9 (Accepted) Message-ID: <20120411050401.760.14407.launchpad@cocoplum.canonical.com> puppet (2.6.4-2ubuntu2.9) natty-security; urgency=low * SECURITY UPDATE: Arbitrary file writes via predictable filename usage in appdmg and pkgdmg providers - debian/patches/CVE-2012-1906_CVE-2012-1986_to_CVE-2012-1989.patch - CVE-2012-1906 * SECURITY UPDATE: Arbitrary file reads via Filebucket REST requests - debian/patches/CVE-2012-1906_CVE-2012-1986_to_CVE-2012-1989.patch - CVE-2012-1986 * SECURITY UPDATE: Denial of service via Filebucket text/marshall support - debian/patches/CVE-2012-1906_CVE-2012-1986_to_CVE-2012-1989.patch - CVE-2012-1987 * SECURITY UPDATE: Arbitrary code execution via Filebucket requests - debian/patches/CVE-2012-1906_CVE-2012-1986_to_CVE-2012-1989.patch - CVE-2012-1988 * debian/patches/fix-unpredictable-hash-ordering-tests.patch: Fix testsuite failures caused by hash randomization in Ruby Date: Tue, 10 Apr 2012 11:47:14 -0500 Changed-By: Tyler Hicks Maintainer: Ubuntu Developers https://launchpad.net/ubuntu/natty/+source/puppet/2.6.4-2ubuntu2.9 -------------- next part -------------- Format: 1.8 Date: Tue, 10 Apr 2012 11:47:14 -0500 Source: puppet Binary: puppet-common puppet puppetmaster-common puppetmaster puppetmaster-passenger vim-puppet puppet-el puppet-testsuite Architecture: source Version: 2.6.4-2ubuntu2.9 Distribution: natty-security Urgency: low Maintainer: Ubuntu Developers Changed-By: Tyler Hicks Description: puppet - Centralized configuration management - agent startup and compatib puppet-common - Centralized configuration management puppet-el - syntax highlighting for puppet manifests in emacs puppet-testsuite - Centralized configuration management - test suite puppetmaster - Centralized configuration management - master startup and compati puppetmaster-common - Puppet master common scripts puppetmaster-passenger - Centralised configuration management - master setup to run under vim-puppet - syntax highlighting for puppet manifests in vim Changes: puppet (2.6.4-2ubuntu2.9) natty-security; urgency=low . * SECURITY UPDATE: Arbitrary file writes via predictable filename usage in appdmg and pkgdmg providers - debian/patches/CVE-2012-1906_CVE-2012-1986_to_CVE-2012-1989.patch - CVE-2012-1906 * SECURITY UPDATE: Arbitrary file reads via Filebucket REST requests - debian/patches/CVE-2012-1906_CVE-2012-1986_to_CVE-2012-1989.patch - CVE-2012-1986 * SECURITY UPDATE: Denial of service via Filebucket text/marshall support - debian/patches/CVE-2012-1906_CVE-2012-1986_to_CVE-2012-1989.patch - CVE-2012-1987 * SECURITY UPDATE: Arbitrary code execution via Filebucket requests - debian/patches/CVE-2012-1906_CVE-2012-1986_to_CVE-2012-1989.patch - CVE-2012-1988 * debian/patches/fix-unpredictable-hash-ordering-tests.patch: Fix testsuite failures caused by hash randomization in Ruby Checksums-Sha1: 36ac7267e24cad125bb3ee2024834bef9b3ebaa9 2299 puppet_2.6.4-2ubuntu2.9.dsc 9c242ef8e72d7c99684684872df7146ba41ee57a 101869 puppet_2.6.4-2ubuntu2.9.debian.tar.gz Checksums-Sha256: 16c688b96a16e0bce7d2726aa5a57aadee551671157a05826b57755098198fec 2299 puppet_2.6.4-2ubuntu2.9.dsc 972b420e88d2be9f57d612e93ac3659f863c6d3d830350699ea4520af10c3822 101869 puppet_2.6.4-2ubuntu2.9.debian.tar.gz Files: 81a39ff49ff5fa58506e19cb5a878cf1 2299 admin optional puppet_2.6.4-2ubuntu2.9.dsc 962c40fab3005cfe590b23b392f37fc5 101869 admin optional puppet_2.6.4-2ubuntu2.9.debian.tar.gz Original-Maintainer: Puppet Package Maintainers From martin.pitt at ubuntu.com Wed Apr 11 06:43:55 2012 From: martin.pitt at ubuntu.com (Martin Pitt) Date: Wed, 11 Apr 2012 06:43:55 -0000 Subject: [ubuntu/natty-security] linux 2.6.38-14.58 (Accepted) Message-ID: <20120411064355.8463.72653.launchpad@ackee.canonical.com> linux (2.6.38-14.58) natty-proposed; urgency=low [Luis Henriques] * Release Tracking Bug - LP: #965346 [ Andy Whitcroft ] * [Config] restore build-% shortcut [ Upstream Kernel Changes ] * eCryptfs: Make truncate path killable - LP: #947270 * bsg: fix sysfs link remove warning - LP: #946928 * regset: Prevent null pointer reference on readonly regsets - LP: #949905 - CVE-2012-1097 * regset: Return -EFAULT, not -EIO, on host-side memory fault - LP: #949905 - CVE-2012-1097 * mm: memcg: Correct unregistring of events attached to the same eventfd - LP: #952828 - CVE-2012-1146 * KVM: Remove ability to assign a device without iommu support - LP: #897812 - CVE-2011-4347 * eCryptfs: Copy up lower inode attrs after setting lower xattr * eCryptfs: Handle failed metadata read in lookup - LP: #509180 * eCryptfs: Improve statfs reporting - LP: #885744 * KVM: x86: extend "struct x86_emulate_ops" with "get_cpuid" - LP: #917842 - CVE-2012-0045 * KVM: x86: fix missing checks in syscall emulation - LP: #917842 - CVE-2012-0045 Date: 2012-03-27 16:58:01.681479+00:00 Changed-By: Luis Henriques Signed-By: Martin Pitt https://launchpad.net/ubuntu/natty/+source/linux/2.6.38-14.58 -------------- next part -------------- Sorry, changesfile not available. From martin.pitt at ubuntu.com Wed Apr 11 06:43:58 2012 From: martin.pitt at ubuntu.com (Martin Pitt) Date: Wed, 11 Apr 2012 06:43:58 -0000 Subject: [ubuntu/natty-updates] linux-backports-modules-2.6.38 2.6.38-14.10 (Accepted) Message-ID: <20120411064358.8463.54135.launchpad@ackee.canonical.com> linux-backports-modules-2.6.38 (2.6.38-14.10) natty-proposed; urgency=low [ Luis Henriques ] * Bump ABI - Natty ABI 14 Date: 2012-03-28 18:10:48.719142+00:00 Changed-By: Luis Henriques Signed-By: Martin Pitt https://launchpad.net/ubuntu/natty/+source/linux-backports-modules-2.6.38/2.6.38-14.10 -------------- next part -------------- Sorry, changesfile not available. From martin.pitt at ubuntu.com Wed Apr 11 06:43:59 2012 From: martin.pitt at ubuntu.com (Martin Pitt) Date: Wed, 11 Apr 2012 06:43:59 -0000 Subject: [ubuntu/natty-security] linux-backports-modules-2.6.38 2.6.38-14.10 (Accepted) Message-ID: <20120411064359.8463.8594.launchpad@ackee.canonical.com> linux-backports-modules-2.6.38 (2.6.38-14.10) natty-proposed; urgency=low [ Luis Henriques ] * Bump ABI - Natty ABI 14 Date: 2012-03-28 18:10:48.719142+00:00 Changed-By: Luis Henriques Signed-By: Martin Pitt https://launchpad.net/ubuntu/natty/+source/linux-backports-modules-2.6.38/2.6.38-14.10 -------------- next part -------------- Sorry, changesfile not available. From martin.pitt at ubuntu.com Wed Apr 11 06:44:04 2012 From: martin.pitt at ubuntu.com (Martin Pitt) Date: Wed, 11 Apr 2012 06:44:04 -0000 Subject: [ubuntu/natty-updates] linux-meta 2.6.38.14.29 (Accepted) Message-ID: <20120411064404.8463.11272.launchpad@ackee.canonical.com> linux-meta (2.6.38.14.29) natty-proposed; urgency=low * Bump ABI Date: 2012-03-27 16:58:56.231810+00:00 Changed-By: Luis Henriques Signed-By: Martin Pitt https://launchpad.net/ubuntu/natty/+source/linux-meta/2.6.38.14.29 -------------- next part -------------- Sorry, changesfile not available. From martin.pitt at ubuntu.com Wed Apr 11 06:44:13 2012 From: martin.pitt at ubuntu.com (Martin Pitt) Date: Wed, 11 Apr 2012 06:44:13 -0000 Subject: [ubuntu/natty-security] linux-meta 2.6.38.14.29 (Accepted) Message-ID: <20120411064413.8463.31678.launchpad@ackee.canonical.com> linux-meta (2.6.38.14.29) natty-proposed; urgency=low * Bump ABI Date: 2012-03-27 16:58:56.231810+00:00 Changed-By: Luis Henriques Signed-By: Martin Pitt https://launchpad.net/ubuntu/natty/+source/linux-meta/2.6.38.14.29 -------------- next part -------------- Sorry, changesfile not available. From martin.pitt at ubuntu.com Wed Apr 11 06:48:12 2012 From: martin.pitt at ubuntu.com (Martin Pitt) Date: Wed, 11 Apr 2012 06:48:12 -0000 Subject: [ubuntu/natty-updates] gnome-user-docs 3.0.0+git20110406ubuntu12 (Accepted) Message-ID: <20120411064812.9590.27259.launchpad@ackee.canonical.com> gnome-user-docs (3.0.0+git20110406ubuntu12) natty-proposed; urgency=low * Update translations from Rosetta Date: 2012-02-19 22:30:11.836626+00:00 Changed-By: Matthew East Signed-By: Martin Pitt https://launchpad.net/ubuntu/natty/+source/gnome-user-docs/3.0.0+git20110406ubuntu12 -------------- next part -------------- Sorry, changesfile not available. From marc.deslauriers at ubuntu.com Wed Apr 11 14:35:07 2012 From: marc.deslauriers at ubuntu.com (Marc Deslauriers) Date: Wed, 11 Apr 2012 14:35:07 -0000 Subject: [ubuntu/natty-security] nvidia-graphics-drivers-173 173.14.30-0ubuntu1.1 (Accepted) Message-ID: <20120411143507.29135.49377.launchpad@cocoplum.canonical.com> nvidia-graphics-drivers-173 (173.14.30-0ubuntu1.1) natty-security; urgency=low * SECURITY UPDATE: privilege escalation via kernel memory access (LP: #959842) - debian/dkms/patches/blacklist-register-mapping.patch: blacklist certain offsets in nv.{c,h}. - debian/dkms.conf{.in}: added new patch. - Thanks to NVIDIA for providing the patch. - CVE number pending Date: Sat, 07 Apr 2012 17:51:33 -0400 Changed-By: Marc Deslauriers Maintainer: Ubuntu Developers https://launchpad.net/ubuntu/natty/+source/nvidia-graphics-drivers-173/173.14.30-0ubuntu1.1 -------------- next part -------------- Format: 1.8 Date: Sat, 07 Apr 2012 17:51:33 -0400 Source: nvidia-graphics-drivers-173 Binary: nvidia-173 nvidia-173-dev nvidia-glx-173 nvidia-glx-173-dev nvidia-173-kernel-source Architecture: source Version: 173.14.30-0ubuntu1.1 Distribution: natty-security Urgency: low Maintainer: Ubuntu Developers Changed-By: Marc Deslauriers Description: nvidia-173 - NVIDIA binary Xorg driver, kernel module and VDPAU library nvidia-173-dev - NVIDIA binary Xorg driver development files nvidia-173-kernel-source - Transitional package for nvidia-glx-173-kernel-source nvidia-glx-173 - Transitional package for nvidia-glx-173 nvidia-glx-173-dev - Transitional package for nvidia-glx-173-dev Launchpad-Bugs-Fixed: 959842 Changes: nvidia-graphics-drivers-173 (173.14.30-0ubuntu1.1) natty-security; urgency=low . * SECURITY UPDATE: privilege escalation via kernel memory access (LP: #959842) - debian/dkms/patches/blacklist-register-mapping.patch: blacklist certain offsets in nv.{c,h}. - debian/dkms.conf{.in}: added new patch. - Thanks to NVIDIA for providing the patch. - CVE number pending Checksums-Sha1: 793f00acbbb6234e64a9c07fc41ac06098a28e97 2008 nvidia-graphics-drivers-173_173.14.30-0ubuntu1.1.dsc 884f252c35d97f735629263fabaf2f3d5a78cae7 40405 nvidia-graphics-drivers-173_173.14.30-0ubuntu1.1.diff.gz Checksums-Sha256: 82ca3bcbe2cd7abc565060e996aca3d2454cfeb3e296738a31a95e77b35fc7c6 2008 nvidia-graphics-drivers-173_173.14.30-0ubuntu1.1.dsc 532009bc199b41f759be3b8075a32dcb7b5ea388d86af6d18d78c187287c6772 40405 nvidia-graphics-drivers-173_173.14.30-0ubuntu1.1.diff.gz Files: fd52b6a12bbef521674d6996889f9291 2008 restricted/misc optional nvidia-graphics-drivers-173_173.14.30-0ubuntu1.1.dsc 3a5da785794e4b6dc3e7a06911a41fb5 40405 restricted/misc optional nvidia-graphics-drivers-173_173.14.30-0ubuntu1.1.diff.gz From marc.deslauriers at ubuntu.com Wed Apr 11 14:35:38 2012 From: marc.deslauriers at ubuntu.com (Marc Deslauriers) Date: Wed, 11 Apr 2012 14:35:38 -0000 Subject: [ubuntu/natty-security] nvidia-graphics-drivers 270.41.06-0ubuntu1.1 (Accepted) Message-ID: <20120411143538.29135.19458.launchpad@cocoplum.canonical.com> nvidia-graphics-drivers (270.41.06-0ubuntu1.1) natty-security; urgency=low * SECURITY UPDATE: privilege escalation via kernel memory access (LP: #959842) - debian/dkms/patches/blacklist-register-mapping.patch: blacklist certain offsets in nv.{c,h}. - debian/dkms.conf{.in}: added new patch. - Thanks to NVIDIA for providing the patch. - CVE number pending Date: Sat, 07 Apr 2012 17:21:24 -0400 Changed-By: Marc Deslauriers Maintainer: Ubuntu Developers https://launchpad.net/ubuntu/natty/+source/nvidia-graphics-drivers/270.41.06-0ubuntu1.1 -------------- next part -------------- Format: 1.8 Date: Sat, 07 Apr 2012 17:21:24 -0400 Source: nvidia-graphics-drivers Binary: nvidia-current nvidia-current-dev nvidia-glx-185 nvidia-glx-185-dev nvidia-185-kernel-source nvidia-185-libvdpau nvidia-185-libvdpau-dev Architecture: source Version: 270.41.06-0ubuntu1.1 Distribution: natty-security Urgency: low Maintainer: Ubuntu Developers Changed-By: Marc Deslauriers Description: nvidia-185-kernel-source - Transitional package for nvidia-glx-185-kernel-source nvidia-185-libvdpau - Transitional package for nvidia-185-libvdpau nvidia-185-libvdpau-dev - Transitional package for nvidia-185-libvdpau-dev nvidia-current - NVIDIA binary Xorg driver, kernel module and VDPAU library nvidia-current-dev - NVIDIA binary Xorg driver development files nvidia-glx-185 - Transitional package for nvidia-glx-185 nvidia-glx-185-dev - Transitional package for nvidia-glx-185-dev Launchpad-Bugs-Fixed: 959842 Changes: nvidia-graphics-drivers (270.41.06-0ubuntu1.1) natty-security; urgency=low . * SECURITY UPDATE: privilege escalation via kernel memory access (LP: #959842) - debian/dkms/patches/blacklist-register-mapping.patch: blacklist certain offsets in nv.{c,h}. - debian/dkms.conf{.in}: added new patch. - Thanks to NVIDIA for providing the patch. - CVE number pending Checksums-Sha1: 633c05667f146af17d4331a282e3eb055d01229c 2188 nvidia-graphics-drivers_270.41.06-0ubuntu1.1.dsc 343abede5b1494e52457c843cf862b582cdbfdb7 156779 nvidia-graphics-drivers_270.41.06-0ubuntu1.1.diff.gz Checksums-Sha256: 7fe8ba2c78b07142714ad8b171afc5f0d85ef1c9215fbc34fd1471172d2e1c81 2188 nvidia-graphics-drivers_270.41.06-0ubuntu1.1.dsc cadc545d330a515b0b7190f09938e658cb448f4cc8bff55c85240463e5d9f182 156779 nvidia-graphics-drivers_270.41.06-0ubuntu1.1.diff.gz Files: 32a1a68785c9d7cc723fbc69b8191988 2188 restricted/misc optional nvidia-graphics-drivers_270.41.06-0ubuntu1.1.dsc d4bd93556730b5abb96f38013b2bcfe6 156779 restricted/misc optional nvidia-graphics-drivers_270.41.06-0ubuntu1.1.diff.gz From serge.hallyn at ubuntu.com Thu Apr 12 04:54:48 2012 From: serge.hallyn at ubuntu.com (Serge Hallyn) Date: Thu, 12 Apr 2012 04:54:48 -0000 Subject: [ubuntu/natty-proposed] lxc 0.7.4-0ubuntu7.3 (Accepted) Message-ID: <20120412045448.15890.73174.launchpad@soybean.canonical.com> lxc (0.7.4-0ubuntu7.3) natty-proposed; urgency=low * lxcguest.lxcguest.upstart: emit the net-device-up IFACE=lo event, so that any upstart jobs waiting on it (esp rc-sysinit before oneiric) will proceed. (LP: #924337) * debian/rules: install lxcguest.lxcguest.upstart (as it was not in the natty package before) Date: Wed, 28 Mar 2012 13:58:23 -0500 Changed-By: Serge Hallyn Maintainer: Ubuntu Developers https://launchpad.net/ubuntu/natty/+source/lxc/0.7.4-0ubuntu7.3 -------------- next part -------------- Format: 1.8 Date: Wed, 28 Mar 2012 13:58:23 -0500 Source: lxc Binary: lxc lxcguest Architecture: source Version: 0.7.4-0ubuntu7.3 Distribution: natty-proposed Urgency: low Maintainer: Ubuntu Developers Changed-By: Serge Hallyn Description: lxc - Linux containers userspace tools lxcguest - Linux container guest package Launchpad-Bugs-Fixed: 924337 Changes: lxc (0.7.4-0ubuntu7.3) natty-proposed; urgency=low . * lxcguest.lxcguest.upstart: emit the net-device-up IFACE=lo event, so that any upstart jobs waiting on it (esp rc-sysinit before oneiric) will proceed. (LP: #924337) * debian/rules: install lxcguest.lxcguest.upstart (as it was not in the natty package before) Checksums-Sha1: e617305d6fc6d9ee16bbf7d4842b64b8d7b54dcf 1598 lxc_0.7.4-0ubuntu7.3.dsc 19540d36dc3203ba2cea293e27f7aaf3644f3d59 11882 lxc_0.7.4-0ubuntu7.3.debian.tar.gz Checksums-Sha256: ea0da3235dacbb96a378beb54df41372cb78e18abbcedd23a2fb7fcb065a4107 1598 lxc_0.7.4-0ubuntu7.3.dsc 39cc31ceb1b687bdef53033f27abd033f021318ba4c2109449b999b1c0379e85 11882 lxc_0.7.4-0ubuntu7.3.debian.tar.gz Files: e3286b8c476ada2b9d55249130b3cfd5 1598 admin optional lxc_0.7.4-0ubuntu7.3.dsc d0bfe163a05f1b1716cb0bfa1bd4a121 11882 admin optional lxc_0.7.4-0ubuntu7.3.debian.tar.gz Original-Maintainer: Guido Trotter From steve.langasek at ubuntu.com Thu Apr 12 05:10:32 2012 From: steve.langasek at ubuntu.com (Steve Langasek) Date: Thu, 12 Apr 2012 05:10:32 -0000 Subject: [ubuntu/natty-proposed] nis 3.17-31ubuntu0.11.04.2 (Accepted) Message-ID: <20120412051032.9737.3397.launchpad@chaenomeles.canonical.com> nis (3.17-31ubuntu0.11.04.2) natty-proposed; urgency=low * Drop the upstart versioned dependency, so that we aren't depending on a version of upstart only available in oneiric and later. * debian/nis.ypbind.upstart: don't try to start ypserv if NISSERVER=false. nis (3.17-31ubuntu0.11.04.1) natty-proposed; urgency=low * Backport from precise: - Convert to native upstart jobs, with a versioned dependency on upstart (>= 0.9.7-2) because we use the wait-for-state job. LP: #569757. - Depend on portmap (>= 6.0.0-1ubuntu2.1) to ensure our upstart job dependencies are satisfied. * Don't block gdm, lightdm, or atd on ypbind, since these services never declared that they want it, so we shouldn't change this in an SRU. It is at least much easier for an admin to make this change locally now if they want the DM to block on ypbind. * Use 'net-device-up IFACE!=lo' as a start condition, as supported in lucid, instead of 'static-network-up' and 'failsafe-boot' which were introduced in oneiric. * We also don't have the wait-for-state job in upstart prior to oneiric, so implement our wait handling by hand in the relevant jobs. Date: Thu, 15 Mar 2012 11:03:33 -0700 Changed-By: Steve Langasek Maintainer: Ubuntu Developers https://launchpad.net/ubuntu/natty/+source/nis/3.17-31ubuntu0.11.04.2 -------------- next part -------------- Format: 1.8 Date: Thu, 15 Mar 2012 11:03:33 -0700 Source: nis Binary: nis Architecture: source Version: 3.17-31ubuntu0.11.04.2 Distribution: natty-proposed Urgency: low Maintainer: Ubuntu Developers Changed-By: Steve Langasek Description: nis - clients and daemons for the Network Information Service (NIS) Launchpad-Bugs-Fixed: 569757 Changes: nis (3.17-31ubuntu0.11.04.2) natty-proposed; urgency=low . * Drop the upstart versioned dependency, so that we aren't depending on a version of upstart only available in oneiric and later. * debian/nis.ypbind.upstart: don't try to start ypserv if NISSERVER=false. . nis (3.17-31ubuntu0.11.04.1) natty-proposed; urgency=low . * Backport from precise: - Convert to native upstart jobs, with a versioned dependency on upstart (>= 0.9.7-2) because we use the wait-for-state job. LP: #569757. - Depend on portmap (>= 6.0.0-1ubuntu2.1) to ensure our upstart job dependencies are satisfied. * Don't block gdm, lightdm, or atd on ypbind, since these services never declared that they want it, so we shouldn't change this in an SRU. It is at least much easier for an admin to make this change locally now if they want the DM to block on ypbind. * Use 'net-device-up IFACE!=lo' as a start condition, as supported in lucid, instead of 'static-network-up' and 'failsafe-boot' which were introduced in oneiric. * We also don't have the wait-for-state job in upstart prior to oneiric, so implement our wait handling by hand in the relevant jobs. Checksums-Sha1: 96fd12ee324dd773453382bd5e878241e58c5dec 1943 nis_3.17-31ubuntu0.11.04.2.dsc 1a23abb201ab42e7371ef30d174730ac978da1f6 47493 nis_3.17-31ubuntu0.11.04.2.diff.gz Checksums-Sha256: 427840550ac864548a372a82acf9b27652c896817b31a093de40906f6b22b449 1943 nis_3.17-31ubuntu0.11.04.2.dsc fb4b05dcea9f465a8586337a45347389c1c2fbfd00b47541e1d5ab91ffe11d4e 47493 nis_3.17-31ubuntu0.11.04.2.diff.gz Files: ee19924e593b20b75770de319ae7e5c4 1943 net extra nis_3.17-31ubuntu0.11.04.2.dsc 08f22ef7914748a55dfd64becffcbf8f 47493 net extra nis_3.17-31ubuntu0.11.04.2.diff.gz Original-Maintainer: Mark Brown From tyhicks at canonical.com Thu Apr 12 23:35:11 2012 From: tyhicks at canonical.com (Tyler Hicks) Date: Thu, 12 Apr 2012 23:35:11 -0000 Subject: [ubuntu/natty-security] samba_3.5.8~dfsg-1ubuntu2.4_powerpc_translations.tar.gz, samba_3.5.8~dfsg-1ubuntu2.4_amd64_translations.tar.gz, samba, samba_3.5.8~dfsg-1ubuntu2.4_i386_translations.tar.gz, samba_3.5.8~dfsg-1ubuntu2.4_armel_translations.tar.gz 2:3.5.8~dfsg-1ubuntu2.4 (Accepted) Message-ID: <20120412233511.24670.7377.launchpad@cocoplum.canonical.com> samba (2:3.5.8~dfsg-1ubuntu2.4) natty-security; urgency=low * SECURITY UPDATE: Unauthenticated remote code execution via RPC calls (LP: #978458) - debian/patches/CVE-2012-1182-1.patch: Fix PIDL compiler to generate code that uses the same value for array allocation and array length checks. Based on upstream patch. - debian/patches/CVE-2012-1182-2.patch: Regenerate PIDL generated files with the patched PIDL compiler - CVE-2012-1182 Date: Thu, 12 Apr 2012 05:28:44 -0500 Changed-By: Tyler Hicks Maintainer: Ubuntu Developers https://launchpad.net/ubuntu/natty/+source/samba/2:3.5.8~dfsg-1ubuntu2.4 -------------- next part -------------- Format: 1.8 Date: Thu, 12 Apr 2012 05:28:44 -0500 Source: samba Binary: samba samba-common-bin samba-common samba-tools smbclient swat samba-doc samba-doc-pdf libpam-smbpass libsmbclient libsmbclient-dev winbind samba-dbg libwbclient0 Architecture: source Version: 2:3.5.8~dfsg-1ubuntu2.4 Distribution: natty-security Urgency: low Maintainer: Ubuntu Developers Changed-By: Tyler Hicks Description: libpam-smbpass - pluggable authentication module for Samba libsmbclient - shared library for communication with SMB/CIFS servers libsmbclient-dev - development files for libsmbclient libwbclient0 - Samba winbind client library samba - SMB/CIFS file, print, and login server for Unix samba-common - common files used by both the Samba server and client samba-common-bin - common files used by both the Samba server and client samba-dbg - Samba debugging symbols samba-doc - Samba documentation samba-doc-pdf - Samba documentation in PDF format samba-tools - Samba testing utilities smbclient - command-line SMB/CIFS clients for Unix swat - Samba Web Administration Tool winbind - Samba nameservice integration server Launchpad-Bugs-Fixed: 978458 Changes: samba (2:3.5.8~dfsg-1ubuntu2.4) natty-security; urgency=low . * SECURITY UPDATE: Unauthenticated remote code execution via RPC calls (LP: #978458) - debian/patches/CVE-2012-1182-1.patch: Fix PIDL compiler to generate code that uses the same value for array allocation and array length checks. Based on upstream patch. - debian/patches/CVE-2012-1182-2.patch: Regenerate PIDL generated files with the patched PIDL compiler - CVE-2012-1182 Checksums-Sha1: b43c39017ffbca0ae8d421d4ab24702e3e125578 2550 samba_3.5.8~dfsg-1ubuntu2.4.dsc 5d771add634085997bcdbc5f503bdf9ae8cb98c5 736665 samba_3.5.8~dfsg-1ubuntu2.4.debian.tar.gz Checksums-Sha256: fc8ba6ac8743838cc4975e4e4ee5ab4320f9c8469610d93000ddd04e1f508690 2550 samba_3.5.8~dfsg-1ubuntu2.4.dsc 52e39982aebf1d513b861378280b548a18e16ddcd448fbb99b7369f651d0c6a0 736665 samba_3.5.8~dfsg-1ubuntu2.4.debian.tar.gz Files: 3cb756479fba9cb76836db0c459e45f6 2550 net optional samba_3.5.8~dfsg-1ubuntu2.4.dsc 9aa970fdd5af9febdb017866fe94bbb3 736665 net optional samba_3.5.8~dfsg-1ubuntu2.4.debian.tar.gz Original-Maintainer: Debian Samba Maintainers From chris.coulson at canonical.com Mon Apr 16 16:03:43 2012 From: chris.coulson at canonical.com (Chris Coulson) Date: Mon, 16 Apr 2012 16:03:43 -0000 Subject: [ubuntu/natty] adobe-flashplugin 11.2.202.233-0natty1 (Accepted) Message-ID: <20120416160343.6339.26143.launchpad@gac.canonical.com> adobe-flashplugin (11.2.202.233-0natty1) natty; urgency=low * New upstream release Date: Mon, 16 Apr 2012 12:49:58 +0100 Changed-By: Chris Coulson Maintainer: DL-Flash Player Ubuntu https://launchpad.net/ubuntu/natty/+source/adobe-flashplugin/11.2.202.233-0natty1 -------------- next part -------------- Format: 1.8 Date: Mon, 16 Apr 2012 12:49:58 +0100 Source: adobe-flashplugin Binary: adobe-flashplugin adobe-flash-properties-gtk adobe-flash-properties-kde Architecture: source Version: 11.2.202.233-0natty1 Distribution: natty Urgency: low Maintainer: DL-Flash Player Ubuntu Changed-By: Chris Coulson Description: adobe-flash-properties-gtk - GTK+ control panel for Adobe Flash Player plugin version 11 adobe-flash-properties-kde - KDE control panel Adobe Flash Player plugin version 11 adobe-flashplugin - Adobe Flash Player plugin version 11 Changes: adobe-flashplugin (11.2.202.233-0natty1) natty; urgency=low . * New upstream release Checksums-Sha1: 0795eeda6c37cb133391fd57a628e8dcedb89ca7 1731 adobe-flashplugin_11.2.202.233-0natty1.dsc 2e8223ad9aa09df294b3b5f202eb3f40625f2af8 5017 adobe-flashplugin_11.2.202.233-0natty1.diff.gz Checksums-Sha256: 86c72a7b9930aed61626a74cb488e994909d82a363675e0be7dc1e60628bfd72 1731 adobe-flashplugin_11.2.202.233-0natty1.dsc b8ec65eee62ebf7aed1ca82aa628aab9bcae31a505219f877f53ef4695de537d 5017 adobe-flashplugin_11.2.202.233-0natty1.diff.gz Files: e2a5802717bcd09b67ccd10e7e1aad2c 1731 partner/web optional adobe-flashplugin_11.2.202.233-0natty1.dsc 93062cf1ddc1fa1ba01e0ab2b7149e76 5017 partner/web optional adobe-flashplugin_11.2.202.233-0natty1.diff.gz From chris.coulson at canonical.com Mon Apr 16 16:03:43 2012 From: chris.coulson at canonical.com (Chris Coulson) Date: Mon, 16 Apr 2012 16:03:43 -0000 Subject: [ubuntu/natty] acroread 9.5.1-1natty1 (Accepted) Message-ID: <20120416160343.6339.46742.launchpad@gac.canonical.com> acroread (9.5.1-1natty1) natty; urgency=low * New upstream release, addresses security issues: - http://www.adobe.com/support/security/bulletins/apsb12-08.html - CVE-2012-0774 - CVE-2012-0775 - CVE-2012-0776 - CVE-2012-0777 * This is an English only release. The -deu, -fra, -jpn packages still contain 9.4.2, as more recent versions are not available for those languages. Date: Fri, 13 Apr 2012 15:16:03 +0100 Changed-By: Chris Coulson Maintainer: Brian Thomason https://launchpad.net/ubuntu/natty/+source/acroread/9.5.1-1natty1 -------------- next part -------------- Format: 1.8 Date: Fri, 13 Apr 2012 15:16:03 +0100 Source: acroread Binary: acroread adobereader-deu adobereader-fra adobereader-jpn acroread-common Architecture: source Version: 9.5.1-1natty1 Distribution: natty Urgency: low Maintainer: Brian Thomason Changed-By: Chris Coulson Description: acroread - Adobe Reader acroread-common - Adobe Reader - Common Files adobereader-deu - Adobe Reader adobereader-fra - Adobe Reader adobereader-jpn - Adobe Reader Changes: acroread (9.5.1-1natty1) natty; urgency=low . * New upstream release, addresses security issues: - http://www.adobe.com/support/security/bulletins/apsb12-08.html - CVE-2012-0774 - CVE-2012-0775 - CVE-2012-0776 - CVE-2012-0777 * This is an English only release. The -deu, -fra, -jpn packages still contain 9.4.2, as more recent versions are not available for those languages. Checksums-Sha1: 3d3941fddb572bf797cd5d818f962cbbea9651e2 1803 acroread_9.5.1-1natty1.dsc a6e0fddab6df13b995670cafcad362f3fe8c4cff 20021 acroread_9.5.1-1natty1.debian.tar.gz Checksums-Sha256: f65d85f1937fa381c62d41baf7e28fc696211cf3ac4149d698b396d35c6472da 1803 acroread_9.5.1-1natty1.dsc f80beae8335120c5a371ea8fc163a862a5c0b1457122fdbccde9b3e04d08e117 20021 acroread_9.5.1-1natty1.debian.tar.gz Files: c6c6b36a2fb9ea5e5a570160a1772b95 1803 partner/text extra acroread_9.5.1-1natty1.dsc d7b10e490eb939e988c872907076b4b4 20021 partner/text extra acroread_9.5.1-1natty1.debian.tar.gz From sbeattie at ubuntu.com Mon Apr 16 21:34:13 2012 From: sbeattie at ubuntu.com (Steve Beattie) Date: Mon, 16 Apr 2012 21:34:13 -0000 Subject: [ubuntu/natty-security] flashplugin-nonfree, flashplugin-nonfree_11.2.202.233ubuntu0.11.04.2_i386_translations.tar.gz, flashplugin-nonfree_11.2.202.233ubuntu0.11.04.2_amd64_translations.tar.gz 11.2.202.233ubuntu0.11.04.2 (Accepted) Message-ID: <20120416213413.5973.87131.launchpad@cocoplum.canonical.com> flashplugin-nonfree (11.2.202.233ubuntu0.11.04.2) natty-security; urgency=low * New upstream release 11.2.202.233 - debian/{config,postinst.in}: Updated version and sha256sum. Date: Mon, 16 Apr 2012 10:06:36 -0700 Changed-By: Steve Beattie Maintainer: Ubuntu Developers https://launchpad.net/ubuntu/natty/+source/flashplugin-nonfree/11.2.202.233ubuntu0.11.04.2 -------------- next part -------------- Format: 1.8 Date: Mon, 16 Apr 2012 10:06:36 -0700 Source: flashplugin-nonfree Binary: flashplugin-installer flashplugin-nonfree Architecture: source Version: 11.2.202.233ubuntu0.11.04.2 Distribution: natty-security Urgency: low Maintainer: Ubuntu Developers Changed-By: Steve Beattie Description: flashplugin-installer - Adobe Flash Player plugin installer flashplugin-nonfree - Adobe Flash Player plugin installer (transitional package) Changes: flashplugin-nonfree (11.2.202.233ubuntu0.11.04.2) natty-security; urgency=low . * New upstream release 11.2.202.233 - debian/{config,postinst.in}: Updated version and sha256sum. Checksums-Sha1: fd5edcfb37813b9d1ba6c9aa6da29fc575814ab0 1649 flashplugin-nonfree_11.2.202.233ubuntu0.11.04.2.dsc f3766aec9c0c1b3c03c4fbe8e9ab8ff855fb2a44 27577 flashplugin-nonfree_11.2.202.233ubuntu0.11.04.2.tar.gz Checksums-Sha256: 434d07681b855183ea8d888d74a229975c370a7d08fc5ceb386e49255b956c4e 1649 flashplugin-nonfree_11.2.202.233ubuntu0.11.04.2.dsc f6f549d8dd4b9db8081b729a27d2dc0d15cb2794d3d693ec5398588fd4fe1b61 27577 flashplugin-nonfree_11.2.202.233ubuntu0.11.04.2.tar.gz Files: deb5e7663be92300d25ed20d4760111b 1649 contrib/web optional flashplugin-nonfree_11.2.202.233ubuntu0.11.04.2.dsc b538edc65d47d2fba70730121b47b461 27577 contrib/web optional flashplugin-nonfree_11.2.202.233ubuntu0.11.04.2.tar.gz Original-Maintainer: Bart Martens From sbeattie at ubuntu.com Mon Apr 16 22:33:28 2012 From: sbeattie at ubuntu.com (Steve Beattie) Date: Mon, 16 Apr 2012 22:33:28 -0000 Subject: [ubuntu/natty-security] inspircd 1.1.22+dfsg-4squeeze1build0.11.04.1 (Accepted) Message-ID: <20120416223328.21083.77737.launchpad@cocoplum.canonical.com> inspircd (1.1.22+dfsg-4squeeze1build0.11.04.1) natty-security; urgency=low * fake sync from Debian (LP: #982509) inspircd (1.1.22+dfsg-4+squeeze1) stable-security; urgency=low * Non-maintainer upload. * Protect against a buffer overflow in src/dns.cpp Closes: #667914 CVE-2012-1836 Date: Mon, 16 Apr 2012 10:51:24 -0700 Changed-By: Steve Beattie Maintainer: Debian IRC Team https://launchpad.net/ubuntu/natty/+source/inspircd/1.1.22+dfsg-4squeeze1build0.11.04.1 -------------- next part -------------- Format: 1.8 Date: Mon, 16 Apr 2012 10:51:24 -0700 Source: inspircd Binary: inspircd inspircd-dbg Architecture: source Version: 1.1.22+dfsg-4squeeze1build0.11.04.1 Distribution: natty-security Urgency: low Maintainer: Debian IRC Team Changed-By: Steve Beattie Description: inspircd - Modular IRCd written in C++ inspircd-dbg - Modular IRCd written in C++ - debugging symbols Closes: 667914 Launchpad-Bugs-Fixed: 982509 Changes: inspircd (1.1.22+dfsg-4squeeze1build0.11.04.1) natty-security; urgency=low . * fake sync from Debian (LP: #982509) . inspircd (1.1.22+dfsg-4+squeeze1) stable-security; urgency=low . * Non-maintainer upload. * Protect against a buffer overflow in src/dns.cpp Closes: #667914 CVE-2012-1836 Checksums-Sha1: 9f066029dedf7baf4e050c0aba032bc7f05ab6a3 2178 inspircd_1.1.22+dfsg-4squeeze1build0.11.04.1.dsc 669d5f4cec7d0f8f3d055c44a7ed9e1a83fe850d 15366 inspircd_1.1.22+dfsg-4squeeze1build0.11.04.1.diff.gz Checksums-Sha256: 669cd900b114e18dddc9ce05ff46c2c2a7ea217da2753e5b58c96a942f3809da 2178 inspircd_1.1.22+dfsg-4squeeze1build0.11.04.1.dsc 3372efa29d19f8f484146415699a3e78f8abded7369c6bc2621248f1038e4e49 15366 inspircd_1.1.22+dfsg-4squeeze1build0.11.04.1.diff.gz Files: a098c3b413593bdd981acc983143330f 2178 net optional inspircd_1.1.22+dfsg-4squeeze1build0.11.04.1.dsc 965adf2f2f62750cc84d29d10a8ce222 15366 net optional inspircd_1.1.22+dfsg-4squeeze1build0.11.04.1.diff.gz From steve.langasek at ubuntu.com Tue Apr 17 12:18:15 2012 From: steve.langasek at ubuntu.com (Steve Langasek) Date: Tue, 17 Apr 2012 12:18:15 -0000 Subject: [ubuntu/natty-proposed] insserv 1.14.0-2ubuntu0.11.04.2 (Accepted) Message-ID: <20120417121815.16714.59470.launchpad@wampee.canonical.com> insserv (1.14.0-2ubuntu0.11.04.2) natty-proposed; urgency=low * Only try to move links in /etc/rc{0,6}.d that match "S0*". LP: #941867. insserv (1.14.0-2ubuntu0.11.04.1) natty-proposed; urgency=low [ Adam Stokes ] * Add 200_hide_insserv_on_ubuntu.patch: Move insserv out of system path to disuade package maintainers from invoking it directly. (LP: #858122) [ Evan Broder ] * Fix the shutdown sequence if it was broken by insserv being run at some point in the past. Date: Fri, 13 Apr 2012 22:07:25 -0700 Changed-By: Steve Langasek Maintainer: Ubuntu Developers https://launchpad.net/ubuntu/natty/+source/insserv/1.14.0-2ubuntu0.11.04.2 -------------- next part -------------- Format: 1.8 Date: Fri, 13 Apr 2012 22:07:25 -0700 Source: insserv Binary: insserv Architecture: source Version: 1.14.0-2ubuntu0.11.04.2 Distribution: natty-proposed Urgency: low Maintainer: Ubuntu Developers Changed-By: Steve Langasek Description: insserv - Tool to organize boot sequence using LSB init.d script dependenci Launchpad-Bugs-Fixed: 858122 941867 Changes: insserv (1.14.0-2ubuntu0.11.04.2) natty-proposed; urgency=low . * Only try to move links in /etc/rc{0,6}.d that match "S0*". LP: #941867. . insserv (1.14.0-2ubuntu0.11.04.1) natty-proposed; urgency=low . [ Adam Stokes ] * Add 200_hide_insserv_on_ubuntu.patch: Move insserv out of system path to disuade package maintainers from invoking it directly. (LP: #858122) . [ Evan Broder ] * Fix the shutdown sequence if it was broken by insserv being run at some point in the past. Checksums-Sha1: 93bb2d95a9641106cf72b6b5c9008820969050f2 2060 insserv_1.14.0-2ubuntu0.11.04.2.dsc d652fb40622feb0b8e2e771cf241e6ec43387d3f 55076 insserv_1.14.0-2ubuntu0.11.04.2.diff.gz Checksums-Sha256: d9e9021d3ea4f8ce7f5806f12d9b488e24d053afae360f08562485cb59e23328 2060 insserv_1.14.0-2ubuntu0.11.04.2.dsc 3a69818970eb0040a64e751e6832368cc4dabe802862e2c91f1504d69a54ef75 55076 insserv_1.14.0-2ubuntu0.11.04.2.diff.gz Files: ed6c1bbb41fbabd5cd4498a549e150bf 2060 misc optional insserv_1.14.0-2ubuntu0.11.04.2.dsc 49ee5caa3da51fc40ad8870cf3fff597 55076 misc optional insserv_1.14.0-2ubuntu0.11.04.2.diff.gz Debian-Vcs-Browser: http://svn.debian.org/wsvn/initscripts-ng/trunk/src/insserv/ Debian-Vcs-Svn: svn://svn.debian.org/initscripts-ng/trunk/src/insserv Original-Maintainer: Petter Reinholdtsen From andreas at canonical.com Thu Apr 19 09:02:24 2012 From: andreas at canonical.com (Andreas Hasenack) Date: Thu, 19 Apr 2012 09:02:24 -0000 Subject: [ubuntu/natty-proposed] landscape-client 12.04.3-0ubuntu0.11.04 (Accepted) Message-ID: <20120419090224.7083.24370.launchpad@gac.canonical.com> landscape-client (12.04.3-0ubuntu0.11.04) natty-proposed; urgency=low Tracking bug: LP: #978884 [ David Britton ] * Warn on unicode entry into settings UI (LP: #956612). * Sanitise hostname field in settings UI (LP: #954507). * Make it clear that the Landscape service is commercial (LP: #965850) * Further internationalize the settings UI (LP: #962899) * Depend on python-aptdaemon.gtk3widgets instead of python-aptdaemon and replace dependency on python-gobject by python-gi (LP: #961894) * Add i18n to the landscape-client-ui-install script. (LP: #961891) [ Andreas Hasenack ] * Fix default landscape hostname in glib schema. * dpkg test improvements to fix intermittent failures. * If ssl_public_key is supplied, use it also when fetching script attachments. This fixes the case of using script execution with attachments when the Landscape server is using a custom CA, most common in LDS deployments. (LP: #959846) * Make sure we have a PATH variable set before doing package activities, and also set it in the initscript for good measure. If the client was configured and restarted by the new UI configuration tool, PATH wasn't set, triggering an error in dpkg. (LP: #961190) * Make landscape-client-ui depend on landscape-client-ui-install, so that we get an entry in the system settings if just landscape-client-ui is installed. The actual entry comes from landscape-client-ui-install. * Optimization: when adding binaries, don't reload every repo, only the one containing the binaries. (LP: #954822) * Handle the case where the user clicks twice inadvertently on the Landscape icon in system settings and don't start a second copy of itself. (LP: #960211) * Change package management features to use APT instead of Smart (LP: #856244, #861707, #859615, #861345, #863239, #863259, #865270, #865272, #865285, #865273, #871641, #865299, #873196, #873939, #876493, #881973, #882438, #866014, #881998, #884142, #884151, #884131, #887037, #886208, #887578, #887947, #889067, #889069, #889087, #889099, #865303, #889113, #890605, #890606, #890609, #897416, #891855, #898681, #898683, #897656, #898542, #862212, #903202, #914734, #914735, #914737, #916301, #915280, #914742, #918925, #918175, #919179, #921664, #921699, #922582, #922511, #921712, #928750, #932136, #928941, #937411, #937567, #925543, #947803, #952973, #948142, #953136, #953906, #956590). * Add a GTK interface to configure the client (LP: #911279, #911666, #912163, #911665, #916300, #931937, #931937, #943622, #945025, #911279, #944652, #948464, #948416, #949158, #911671, #950864, #949208, #949147, #953070, #953292, #953463, #953034, #949200, #953026, #954499, #954516, #954285, #953065, #954414, #954332, #954542, #955966, #955139, #956030, #956119). * Add the ability to auto discover the server location on local deployment (LP: #917422, #927620, #917422, #928585, #929087, #932325, #948564) * Allow the client to accept arbitrary environment variables from the server for script execution (LP: #954999). * Make landscape-config exit non-zero when registration fails and --ok-no-register is not passed (LP: #271759). * Check for the content of /sys/bus/xen/devices to report a machine as a Xen VM instead of just relying on the existence of /sys/bus/xen (LP: #921970). * Make sure cloud registration succeeds if there is no kernel specified in the meta-data service (LP: #920453). * Report private and public IP adresses from the metadata service at cloud registration time (LP: #918366). * Add support for reporting hardware information using lshw (LP: #899002, #943975, #955734). * Add support for the new attachment service in script execution (LP: #893040). * Adds a new message type, 'register-provisioned-machine', which is meant to register computers using an OTP (LP: #881405). * Add local cloning option for load testing (LP: #872830, #925924). * Add more variables to preseeding (LP: #863204, #867710). * Allow the configuration of the ping interval (LP: #397884). * Add fake package reporters for load testing purposes (LP: #821571, #821570). * Report a package reporter error to the server if no APT sources are configured, to trigger a package reporter alert (LP: #823769). Date: Tue, 10 Apr 2012 14:14:16 -0300 Changed-By: Andreas Hasenack Maintainer: Ubuntu Developers Signed-By: Martin Pitt https://launchpad.net/ubuntu/natty/+source/landscape-client/12.04.3-0ubuntu0.11.04 -------------- next part -------------- Format: 1.8 Date: Tue, 10 Apr 2012 14:14:16 -0300 Source: landscape-client Binary: landscape-common landscape-client landscape-client-ui landscape-client-ui-install Architecture: source Version: 12.04.3-0ubuntu0.11.04 Distribution: natty-proposed Urgency: low Maintainer: Ubuntu Developers Changed-By: Andreas Hasenack Description: landscape-client - The Landscape administration system client landscape-client-ui - The Landscape administration system client - UI configuration landscape-client-ui-install - The Landscape administration system client - UI installer landscape-common - The Landscape administration system client - Common files Launchpad-Bugs-Fixed: 271759 397884 821570 821571 823769 856244 859615 861345 861707 862212 863204 863239 863259 865270 865272 865273 865285 865299 865303 866014 867710 871641 872830 873196 873939 876493 881405 881973 881998 882438 884131 884142 884151 886208 887037 887578 887947 889067 889069 889087 889099 889113 890605 890606 890609 891855 893040 897416 897656 898542 898681 898683 899002 903202 911279 911665 911666 911671 912163 914734 914735 914737 914742 915280 916300 916301 917422 918175 918366 918925 919179 920453 921664 921699 921712 921970 922511 922582 925543 925924 927620 928585 928750 928941 929087 931937 932136 932325 937411 937567 943622 943975 944652 945025 947803 948142 948416 948464 948564 949147 949158 949200 949208 950864 952973 953026 953034 953065 953070 953136 953292 953463 953906 954285 954332 954414 954499 954507 954516 954542 954822 954999 955139 955734 955966 956030 956119 956590 956612 959846 960211 961190 961891 961894 962899 965850 978884 Changes: landscape-client (12.04.3-0ubuntu0.11.04) natty-proposed; urgency=low . Tracking bug: LP: #978884 . [ David Britton ] * Warn on unicode entry into settings UI (LP: #956612). * Sanitise hostname field in settings UI (LP: #954507). * Make it clear that the Landscape service is commercial (LP: #965850) * Further internationalize the settings UI (LP: #962899) * Depend on python-aptdaemon.gtk3widgets instead of python-aptdaemon and replace dependency on python-gobject by python-gi (LP: #961894) * Add i18n to the landscape-client-ui-install script. (LP: #961891) . [ Andreas Hasenack ] * Fix default landscape hostname in glib schema. * dpkg test improvements to fix intermittent failures. * If ssl_public_key is supplied, use it also when fetching script attachments. This fixes the case of using script execution with attachments when the Landscape server is using a custom CA, most common in LDS deployments. (LP: #959846) * Make sure we have a PATH variable set before doing package activities, and also set it in the initscript for good measure. If the client was configured and restarted by the new UI configuration tool, PATH wasn't set, triggering an error in dpkg. (LP: #961190) * Make landscape-client-ui depend on landscape-client-ui-install, so that we get an entry in the system settings if just landscape-client-ui is installed. The actual entry comes from landscape-client-ui-install. * Optimization: when adding binaries, don't reload every repo, only the one containing the binaries. (LP: #954822) * Handle the case where the user clicks twice inadvertently on the Landscape icon in system settings and don't start a second copy of itself. (LP: #960211) * Change package management features to use APT instead of Smart (LP: #856244, #861707, #859615, #861345, #863239, #863259, #865270, #865272, #865285, #865273, #871641, #865299, #873196, #873939, #876493, #881973, #882438, #866014, #881998, #884142, #884151, #884131, #887037, #886208, #887578, #887947, #889067, #889069, #889087, #889099, #865303, #889113, #890605, #890606, #890609, #897416, #891855, #898681, #898683, #897656, #898542, #862212, #903202, #914734, #914735, #914737, #916301, #915280, #914742, #918925, #918175, #919179, #921664, #921699, #922582, #922511, #921712, #928750, #932136, #928941, #937411, #937567, #925543, #947803, #952973, #948142, #953136, #953906, #956590). * Add a GTK interface to configure the client (LP: #911279, #911666, #912163, #911665, #916300, #931937, #931937, #943622, #945025, #911279, #944652, #948464, #948416, #949158, #911671, #950864, #949208, #949147, #953070, #953292, #953463, #953034, #949200, #953026, #954499, #954516, #954285, #953065, #954414, #954332, #954542, #955966, #955139, #956030, #956119). * Add the ability to auto discover the server location on local deployment (LP: #917422, #927620, #917422, #928585, #929087, #932325, #948564) * Allow the client to accept arbitrary environment variables from the server for script execution (LP: #954999). * Make landscape-config exit non-zero when registration fails and --ok-no-register is not passed (LP: #271759). * Check for the content of /sys/bus/xen/devices to report a machine as a Xen VM instead of just relying on the existence of /sys/bus/xen (LP: #921970). * Make sure cloud registration succeeds if there is no kernel specified in the meta-data service (LP: #920453). * Report private and public IP adresses from the metadata service at cloud registration time (LP: #918366). * Add support for reporting hardware information using lshw (LP: #899002, #943975, #955734). * Add support for the new attachment service in script execution (LP: #893040). * Adds a new message type, 'register-provisioned-machine', which is meant to register computers using an OTP (LP: #881405). * Add local cloning option for load testing (LP: #872830, #925924). * Add more variables to preseeding (LP: #863204, #867710). * Allow the configuration of the ping interval (LP: #397884). * Add fake package reporters for load testing purposes (LP: #821571, #821570). * Report a package reporter error to the server if no APT sources are configured, to trigger a package reporter alert (LP: #823769). Checksums-Sha1: faa5c2e3a2a49b38d7af04a2859c140e43ed6a72 2208 landscape-client_12.04.3-0ubuntu0.11.04.dsc 8d560b21ed4e14ae9200afabbfe5ad1a10d0c6b8 551688 landscape-client_12.04.3.orig.tar.gz 226539ccfa9590ed7e26306dfb18e19eea812c0d 4331 landscape-client_12.04.3-0ubuntu0.11.04.diff.gz Checksums-Sha256: 58c89846c846172e58c2d177982ea8ef42eacf878693f94e13efb8696ad6464d 2208 landscape-client_12.04.3-0ubuntu0.11.04.dsc 8a00872f8503d850a2d93f59dd18334aefcaa879283eba84d34d2fe9d28f75cd 551688 landscape-client_12.04.3.orig.tar.gz 742e8b8c3523eedb03adb51284a5e2ee92c6b72ed6f579101bc2452892537227 4331 landscape-client_12.04.3-0ubuntu0.11.04.diff.gz Files: ed6b571e34a1526f2b487050945a606b 2208 admin optional landscape-client_12.04.3-0ubuntu0.11.04.dsc 5de0d044e85d9169ae672a326105a317 551688 admin optional landscape-client_12.04.3.orig.tar.gz 218d7f1325c4fb3f2b5352cb0c0c59b6 4331 admin optional landscape-client_12.04.3-0ubuntu0.11.04.diff.gz Original-Maintainer: Landscape Team From jamie at ubuntu.com Thu Apr 19 22:03:34 2012 From: jamie at ubuntu.com (Jamie Strandboge) Date: Thu, 19 Apr 2012 22:03:34 -0000 Subject: [ubuntu/natty-security] openssl_0.9.8o-5ubuntu1.4_powerpc_translations.tar.gz, openssl_0.9.8o-5ubuntu1.4_i386_translations.tar.gz, openssl_0.9.8o-5ubuntu1.4_armel_translations.tar.gz, openssl, openssl_0.9.8o-5ubuntu1.4_amd64_translations.tar.gz 0.9.8o-5ubuntu1.4 (Accepted) Message-ID: <20120419220334.20732.44215.launchpad@cocoplum.canonical.com> openssl (0.9.8o-5ubuntu1.4) natty-security; urgency=low * SECURITY UPDATE: NULL pointer dereference in S/MIME messages with broken headers - debian/patches/CVE-2006-7250+2012-1165.patch: adjust mime_hdr_cmp() and mime_param_cmp() to not dereference the compared strings if either is NULL - CVE-2006-7250 - CVE-2012-1165 * SECURITY UPDATE: fix various overflows - debian/patches/CVE-2012-2110.patch: adjust crypto/a_d2i_fp.c, crypto/buffer.c and crypto/mem.c to verify size of lengths - CVE-2012-2110 Date: Thu, 19 Apr 2012 09:39:15 -0500 Changed-By: Jamie Strandboge Maintainer: Ubuntu Developers https://launchpad.net/ubuntu/natty/+source/openssl/0.9.8o-5ubuntu1.4 -------------- next part -------------- Format: 1.8 Date: Thu, 19 Apr 2012 09:39:15 -0500 Source: openssl Binary: openssl openssl-doc libssl0.9.8 libcrypto0.9.8-udeb libssl0.9.8-udeb libssl-dev libssl0.9.8-dbg Architecture: source Version: 0.9.8o-5ubuntu1.4 Distribution: natty-security Urgency: low Maintainer: Ubuntu Developers Changed-By: Jamie Strandboge Description: libcrypto0.9.8-udeb - crypto shared library - udeb (udeb) libssl-dev - SSL development libraries, header files and documentation libssl0.9.8 - SSL shared libraries libssl0.9.8-dbg - Symbol tables for libssl and libcrypto libssl0.9.8-udeb - ssl shared library - udeb (udeb) openssl - Secure Socket Layer (SSL) binary and related cryptographic tools openssl-doc - Secure Socket Layer (SSL) documentation Changes: openssl (0.9.8o-5ubuntu1.4) natty-security; urgency=low . * SECURITY UPDATE: NULL pointer dereference in S/MIME messages with broken headers - debian/patches/CVE-2006-7250+2012-1165.patch: adjust mime_hdr_cmp() and mime_param_cmp() to not dereference the compared strings if either is NULL - CVE-2006-7250 - CVE-2012-1165 * SECURITY UPDATE: fix various overflows - debian/patches/CVE-2012-2110.patch: adjust crypto/a_d2i_fp.c, crypto/buffer.c and crypto/mem.c to verify size of lengths - CVE-2012-2110 Checksums-Sha1: c6a6fbef9b657de413d8d924fcbf68177bc45e81 2116 openssl_0.9.8o-5ubuntu1.4.dsc c46039fa77261bb30000c7a68e70baf72274278c 102614 openssl_0.9.8o-5ubuntu1.4.debian.tar.gz Checksums-Sha256: 529599f7ccd2585d0d11e78eca0ad2bb9737cc17cef1092eb30403522c4b7bf3 2116 openssl_0.9.8o-5ubuntu1.4.dsc 21ed889a41db1e2a5b76c31324b74c9f7e08afb5a1d1da590c9c4314b89c5d0e 102614 openssl_0.9.8o-5ubuntu1.4.debian.tar.gz Files: 6186773b43098c4707acfeb090dfe259 2116 utils optional openssl_0.9.8o-5ubuntu1.4.dsc b8b8ba62d1ee0bc0119056d23dcc03de 102614 utils optional openssl_0.9.8o-5ubuntu1.4.debian.tar.gz Original-Maintainer: Debian OpenSSL Team From martin.pitt at ubuntu.com Fri Apr 20 08:47:20 2012 From: martin.pitt at ubuntu.com (Martin Pitt) Date: Fri, 20 Apr 2012 08:47:20 -0000 Subject: [ubuntu/natty-updates] chromium-browser 18.0.1025.151~r130497-0ubuntu0.11.04.1 (Accepted) Message-ID: <20120420084720.28272.72666.launchpad@ackee.canonical.com> chromium-browser (18.0.1025.151~r130497-0ubuntu0.11.04.1) natty-security; urgency=low * New upstream release from the Stable Channel (LP: #977502) - black screen on Hybrid Graphics system with GPU accelerated compositing enabled (Issue: 117371) - CSS not applied to element (Issue: 114667) - Regression rendering a div with background gradient and borders (Issue: 113726) - Canvas 2D line drawing bug with GPU acceleration (Issue: 121285) - Multiple crashes (Issues: 72235, 116825 and 92998) - Pop-up dialog is at wrong position (Issue: 116045) - HTML Canvas patterns are broken if you change the transformation matrix (Issue: 112165) - SSL interstitial error "proceed anyway" / "back to safety" buttons don't work (Issue: 119252) This release fixes the following security issues: - [106577] Medium CVE-2011-3066: Out-of-bounds read in Skia clipping. Credit to miaubiz. - [117583] Medium CVE-2011-3067: Cross-origin iframe replacement. Credit to Sergey Glazunov. - [117698] High CVE-2011-3068: Use-after-free in run-in handling. Credit to miaubiz. - [117728] High CVE-2011-3069: Use-after-free in line box handling. Credit to miaubiz. - [118185] High CVE-2011-3070: Use-after-free in v8 bindings. Credit to Google Chrome Security Team (SkyLined). - [118273] High CVE-2011-3071: Use-after-free in HTMLMediaElement. Credit to pa_kt, reporting through HP TippingPoint ZDI (ZDI-CAN-1528). - [118467] Low CVE-2011-3072: Cross-origin violation parenting pop-up window. Credit to Sergey Glazunov. - [118593] High CVE-2011-3073: Use-after-free in SVG resource handling. Credit to Arthur Gerkis. - [119281] Medium CVE-2011-3074: Use-after-free in media handling. Credit to Sławomir Błażek. - [119525] High CVE-2011-3075: Use-after-free applying style command. Credit to miaubiz. - [120037] High CVE-2011-3076: Use-after-free in focus handling. Credit to miaubiz. - [120189] Medium CVE-2011-3077: Read-after-free in script bindings. Credit to Google Chrome Security Team (Inferno). Date: 2012-04-10 03:05:40.206128+00:00 Changed-By: Micah Gersten Maintainer: Fabien Tassin Signed-By: Martin Pitt https://launchpad.net/ubuntu/natty/+source/chromium-browser/18.0.1025.151~r130497-0ubuntu0.11.04.1 -------------- next part -------------- Sorry, changesfile not available. From martin.pitt at ubuntu.com Fri Apr 20 08:47:26 2012 From: martin.pitt at ubuntu.com (Martin Pitt) Date: Fri, 20 Apr 2012 08:47:26 -0000 Subject: [ubuntu/natty-security] chromium-browser 18.0.1025.151~r130497-0ubuntu0.11.04.1 (Accepted) Message-ID: <20120420084726.28272.82673.launchpad@ackee.canonical.com> chromium-browser (18.0.1025.151~r130497-0ubuntu0.11.04.1) natty-security; urgency=low * New upstream release from the Stable Channel (LP: #977502) - black screen on Hybrid Graphics system with GPU accelerated compositing enabled (Issue: 117371) - CSS not applied to element (Issue: 114667) - Regression rendering a div with background gradient and borders (Issue: 113726) - Canvas 2D line drawing bug with GPU acceleration (Issue: 121285) - Multiple crashes (Issues: 72235, 116825 and 92998) - Pop-up dialog is at wrong position (Issue: 116045) - HTML Canvas patterns are broken if you change the transformation matrix (Issue: 112165) - SSL interstitial error "proceed anyway" / "back to safety" buttons don't work (Issue: 119252) This release fixes the following security issues: - [106577] Medium CVE-2011-3066: Out-of-bounds read in Skia clipping. Credit to miaubiz. - [117583] Medium CVE-2011-3067: Cross-origin iframe replacement. Credit to Sergey Glazunov. - [117698] High CVE-2011-3068: Use-after-free in run-in handling. Credit to miaubiz. - [117728] High CVE-2011-3069: Use-after-free in line box handling. Credit to miaubiz. - [118185] High CVE-2011-3070: Use-after-free in v8 bindings. Credit to Google Chrome Security Team (SkyLined). - [118273] High CVE-2011-3071: Use-after-free in HTMLMediaElement. Credit to pa_kt, reporting through HP TippingPoint ZDI (ZDI-CAN-1528). - [118467] Low CVE-2011-3072: Cross-origin violation parenting pop-up window. Credit to Sergey Glazunov. - [118593] High CVE-2011-3073: Use-after-free in SVG resource handling. Credit to Arthur Gerkis. - [119281] Medium CVE-2011-3074: Use-after-free in media handling. Credit to Sławomir Błażek. - [119525] High CVE-2011-3075: Use-after-free applying style command. Credit to miaubiz. - [120037] High CVE-2011-3076: Use-after-free in focus handling. Credit to miaubiz. - [120189] Medium CVE-2011-3077: Read-after-free in script bindings. Credit to Google Chrome Security Team (Inferno). Date: 2012-04-10 03:05:40.206128+00:00 Changed-By: Micah Gersten Maintainer: Fabien Tassin Signed-By: Martin Pitt https://launchpad.net/ubuntu/natty/+source/chromium-browser/18.0.1025.151~r130497-0ubuntu0.11.04.1 -------------- next part -------------- Sorry, changesfile not available. From chris.j.arges at canonical.com Fri Apr 20 21:58:08 2012 From: chris.j.arges at canonical.com (Chris J Arges) Date: Fri, 20 Apr 2012 21:58:08 -0000 Subject: [ubuntu/natty-proposed] autofs5 5.0.5-0ubuntu6.1 (Accepted) Message-ID: <20120420215808.11169.33800.launchpad@wampee.canonical.com> autofs5 (5.0.5-0ubuntu6.1) natty-proposed; urgency=low * Resolve issue of not updating map stale status following a successful map read - this ensures that automount does not orphan some mounts when stopping (LP: #578536): - d/patches/01UPSTREAM_autofs-5.0.5-fix-stale-map-read.dpatch: Cherry picked commit from upstream to resolve this issue. Date: Fri, 16 Mar 2012 11:27:42 +0000 Changed-By: Chris J Arges Maintainer: Ubuntu Developers Signed-By: James Page https://launchpad.net/ubuntu/natty/+source/autofs5/5.0.5-0ubuntu6.1 -------------- next part -------------- Format: 1.8 Date: Fri, 16 Mar 2012 11:27:42 +0000 Source: autofs5 Binary: autofs5 autofs5-ldap autofs5-hesiod autofs autofs-ldap autofs-hesiod Architecture: source Version: 5.0.5-0ubuntu6.1 Distribution: natty-proposed Urgency: low Maintainer: Ubuntu Developers Changed-By: Chris J Arges Description: autofs - dummy transitional package from autofs to autofs5 autofs-hesiod - dummy transitional package from autofs-hesiod to autofs5-hesiod autofs-ldap - dummy transitional package from autofs-ldap to autofs5-ldap autofs5 - kernel-based automounter for Linux, version 5 autofs5-hesiod - Hesiod map support for autofs, version 5 autofs5-ldap - LDAP map support for autofs, version 5 Launchpad-Bugs-Fixed: 578536 Changes: autofs5 (5.0.5-0ubuntu6.1) natty-proposed; urgency=low . * Resolve issue of not updating map stale status following a successful map read - this ensures that automount does not orphan some mounts when stopping (LP: #578536): - d/patches/01UPSTREAM_autofs-5.0.5-fix-stale-map-read.dpatch: Cherry picked commit from upstream to resolve this issue. Checksums-Sha1: 9263e3a747a79f8ac959e4eaa31226462a611f61 2146 autofs5_5.0.5-0ubuntu6.1.dsc c7ffe3e73c815605df1f46a492483777fd4c39a4 138426 autofs5_5.0.5-0ubuntu6.1.diff.gz Checksums-Sha256: f2fd6adfbdea3eca3e3993ad11d6f8bc897bc9bc19b64f5aff068da59e3b5589 2146 autofs5_5.0.5-0ubuntu6.1.dsc 2e9031d4764e6655261038a3b790afc777005c256583a2dd65724793c37d18be 138426 autofs5_5.0.5-0ubuntu6.1.diff.gz Files: 7fd8e249787e0e6df9af61d6a0433f93 2146 utils extra autofs5_5.0.5-0ubuntu6.1.dsc f3ad4b65a77d8908e5e1883aa3242be8 138426 utils extra autofs5_5.0.5-0ubuntu6.1.diff.gz Orginal-Maintainer: Jan Christoph Nordholz From jamie at ubuntu.com Tue Apr 24 12:28:12 2012 From: jamie at ubuntu.com (Jamie Strandboge) Date: Tue, 24 Apr 2012 12:28:12 -0000 Subject: [ubuntu/natty-updates] mysql-5.1 5.1.62-0ubuntu0.11.04.1 (Accepted) Message-ID: <20120424122812.30415.93782.launchpad@ackee.canonical.com> mysql-5.1 (5.1.62-0ubuntu0.11.04.1) natty-security; urgency=low * SECURITY UPDATE: Update to 5.1.62 to fix security issues (LP: #965523) - http://dev.mysql.com/doc/refman/5.1/en/news-5-1-62.html Date: 2012-03-28 17:46:07.399411+00:00 Changed-By: Marc Deslauriers Signed-By: Jamie Strandboge https://launchpad.net/ubuntu/natty/+source/mysql-5.1/5.1.62-0ubuntu0.11.04.1 -------------- next part -------------- Sorry, changesfile not available. From jamie at ubuntu.com Tue Apr 24 12:28:15 2012 From: jamie at ubuntu.com (Jamie Strandboge) Date: Tue, 24 Apr 2012 12:28:15 -0000 Subject: [ubuntu/natty-security] mysql-5.1 5.1.62-0ubuntu0.11.04.1 (Accepted) Message-ID: <20120424122815.30415.10436.launchpad@ackee.canonical.com> mysql-5.1 (5.1.62-0ubuntu0.11.04.1) natty-security; urgency=low * SECURITY UPDATE: Update to 5.1.62 to fix security issues (LP: #965523) - http://dev.mysql.com/doc/refman/5.1/en/news-5-1-62.html Date: 2012-03-28 17:46:07.399411+00:00 Changed-By: Marc Deslauriers Signed-By: Jamie Strandboge https://launchpad.net/ubuntu/natty/+source/mysql-5.1/5.1.62-0ubuntu0.11.04.1 -------------- next part -------------- Sorry, changesfile not available. From jamie at ubuntu.com Tue Apr 24 18:33:38 2012 From: jamie at ubuntu.com (Jamie Strandboge) Date: Tue, 24 Apr 2012 18:33:38 -0000 Subject: [ubuntu/natty-security] openssl_0.9.8o-5ubuntu1.5_powerpc_translations.tar.gz, openssl_0.9.8o-5ubuntu1.5_amd64_translations.tar.gz, openssl_0.9.8o-5ubuntu1.5_i386_translations.tar.gz, openssl, openssl_0.9.8o-5ubuntu1.5_armel_translations.tar.gz 0.9.8o-5ubuntu1.5 (Accepted) Message-ID: <20120424183338.16306.90555.launchpad@cocoplum.canonical.com> openssl (0.9.8o-5ubuntu1.5) natty-security; urgency=low * SECURITY UPDATE: incomplete fix for CVE-2012-2110 - debian/patches/CVE-2012-2131.patch: also verify 'len' in BUF_MEM_grow and BUF_MEM_grow_clean is non-negative - CVE-2012-2131 * debian/patches/CVE-2012-2110b.patch: Use correct error code in BUF_MEM_grow_clean() Date: Tue, 24 Apr 2012 08:14:16 -0500 Changed-By: Jamie Strandboge Maintainer: Ubuntu Developers https://launchpad.net/ubuntu/natty/+source/openssl/0.9.8o-5ubuntu1.5 -------------- next part -------------- Format: 1.8 Date: Tue, 24 Apr 2012 08:14:16 -0500 Source: openssl Binary: openssl openssl-doc libssl0.9.8 libcrypto0.9.8-udeb libssl0.9.8-udeb libssl-dev libssl0.9.8-dbg Architecture: source Version: 0.9.8o-5ubuntu1.5 Distribution: natty-security Urgency: low Maintainer: Ubuntu Developers Changed-By: Jamie Strandboge Description: libcrypto0.9.8-udeb - crypto shared library - udeb (udeb) libssl-dev - SSL development libraries, header files and documentation libssl0.9.8 - SSL shared libraries libssl0.9.8-dbg - Symbol tables for libssl and libcrypto libssl0.9.8-udeb - ssl shared library - udeb (udeb) openssl - Secure Socket Layer (SSL) binary and related cryptographic tools openssl-doc - Secure Socket Layer (SSL) documentation Changes: openssl (0.9.8o-5ubuntu1.5) natty-security; urgency=low . * SECURITY UPDATE: incomplete fix for CVE-2012-2110 - debian/patches/CVE-2012-2131.patch: also verify 'len' in BUF_MEM_grow and BUF_MEM_grow_clean is non-negative - CVE-2012-2131 * debian/patches/CVE-2012-2110b.patch: Use correct error code in BUF_MEM_grow_clean() Checksums-Sha1: 5a88dc6500adfee3ee75c67ffa5efbe45bec6b43 2116 openssl_0.9.8o-5ubuntu1.5.dsc cf3bf8137a859820f74c8d0f494604565f226250 102977 openssl_0.9.8o-5ubuntu1.5.debian.tar.gz Checksums-Sha256: 43b4a386c053470b2acfb8556dd925dd38c6ec3dd61929a96adb02ca653c7a7c 2116 openssl_0.9.8o-5ubuntu1.5.dsc 49e7904099571776507dc000509c4c89f78a39f1e79efe56fe992e43e0a4980c 102977 openssl_0.9.8o-5ubuntu1.5.debian.tar.gz Files: 0d3c2521621700d07b17d96a9664a186 2116 utils optional openssl_0.9.8o-5ubuntu1.5.dsc 6fe4f21f6ae10d27646d5028a25e3af4 102977 utils optional openssl_0.9.8o-5ubuntu1.5.debian.tar.gz Original-Maintainer: Debian OpenSSL Team From stefanor at ubuntu.com Wed Apr 25 06:04:14 2012 From: stefanor at ubuntu.com (Stefano Rivera) Date: Wed, 25 Apr 2012 06:04:14 -0000 Subject: [ubuntu/natty-proposed] ubuntu-dev-tools 0.122.4 (Accepted) Message-ID: <20120425060414.24463.96943.launchpad@wampee.canonical.com> ubuntu-dev-tools (0.122.4) natty-proposed; urgency=low * Update Ubuntu list from distro-info-data 0.9. - Use full dates (add days for future EOL dates of Ubuntu). - Add Ubuntu Quantal Quetzal. (LP: #987390) Date: Mon, 23 Apr 2012 18:40:48 +0200 Changed-By: Stefano Rivera Maintainer: Ubuntu Developers https://launchpad.net/ubuntu/natty/+source/ubuntu-dev-tools/0.122.4 -------------- next part -------------- Format: 1.8 Date: Mon, 23 Apr 2012 18:40:48 +0200 Source: ubuntu-dev-tools Binary: ubuntu-dev-tools Architecture: source Version: 0.122.4 Distribution: natty-proposed Urgency: low Maintainer: Ubuntu Developers Changed-By: Stefano Rivera Description: ubuntu-dev-tools - useful tools for Ubuntu developers Launchpad-Bugs-Fixed: 987390 Changes: ubuntu-dev-tools (0.122.4) natty-proposed; urgency=low . * Update Ubuntu list from distro-info-data 0.9. - Use full dates (add days for future EOL dates of Ubuntu). - Add Ubuntu Quantal Quetzal. (LP: #987390) Checksums-Sha1: 6480d5ee1839bdc8513912be8b418adf8d9f7495 1988 ubuntu-dev-tools_0.122.4.dsc 10529b10bc37eb217d7b002723bf60e8cf8137d3 194938 ubuntu-dev-tools_0.122.4.tar.gz Checksums-Sha256: 421bdeb104207be51a3c82a358c5872f4a9f0f22848fe99d485d0357f0d4120b 1988 ubuntu-dev-tools_0.122.4.dsc 9d5484d68c585a65d82944363a738b2953b5a166243a56512b7061bb8ae0db47 194938 ubuntu-dev-tools_0.122.4.tar.gz Files: 70263322d198f4384437209ef5661d63 1988 devel optional ubuntu-dev-tools_0.122.4.dsc b453e39ff288237e2db1c44a1d40bdc3 194938 devel optional ubuntu-dev-tools_0.122.4.tar.gz From martin.pitt at ubuntu.com Wed Apr 25 06:04:27 2012 From: martin.pitt at ubuntu.com (Martin Pitt) Date: Wed, 25 Apr 2012 06:04:27 -0000 Subject: [ubuntu/natty-updates] nvidia-graphics-drivers-96 96.43.20-0ubuntu1~natty1 (Accepted) Message-ID: <20120425060427.21385.20909.launchpad@ackee.canonical.com> nvidia-graphics-drivers-96 (96.43.20-0ubuntu1~natty1) natty-proposed; urgency=low * New upstream release: - Fixed a bug that caused freezes and crashes when resizing windows in KDE 4 with desktop effects enabled using X.Org X server version 1.10 or later. - Added support for X.Org xserver 1.10 (LP: #741930). * debian/dkms.conf.in: - Prevent DKMS builds with kernels newer than the ones we ship. * debian/dkms/patches: - Drop obsolete patches. * debian/nvidia-96.postinst.in: - Remove slave link to nvidia-smi since the binary does not exist. * debian/nvidia-96.postrm.in: - Make sure that all of the libraries are removed in the postrm. This should work around cases such as LP: #540143 where some misteriously unremoved links cause the directory removal to fail. * debian/nvidia-96.README.Debian.in - Update the README with the DKMS OBSOLETE_BY option. * debian/rules: - Do not hardcode the X ABI any more. - Remove obsolete instructions from debian/rules - Prevent the build from failing when no patches are available. Date: 2011-08-19 16:20:36.830643+00:00 Changed-By: Alberto Milone Signed-By: Martin Pitt https://launchpad.net/ubuntu/natty/+source/nvidia-graphics-drivers-96/96.43.20-0ubuntu1~natty1 -------------- next part -------------- Sorry, changesfile not available. From martin.pitt at ubuntu.com Wed Apr 25 06:55:16 2012 From: martin.pitt at ubuntu.com (Martin Pitt) Date: Wed, 25 Apr 2012 06:55:16 -0000 Subject: [ubuntu/natty-updates] enigmail 2:1.4-0ubuntu0.11.04.1 (Accepted) Message-ID: <20120425065516.3746.1329.launchpad@ackee.canonical.com> enigmail (2:1.4-0ubuntu0.11.04.1) natty-proposed; urgency=low * New upstream release v1.4 (LP: #972840) * Make sure we remove the .bzr folder from the tarball when we build it - update debian/rules * Actually add the get-orig-source target.. * Build with Latest Thunderbird SDK - update debian/rules * Add a proper get-orig-source target which pulls the build system from lp:~mozillateam/mozilla-build-system/beta, now that we don't have the old build-system.tar.gz from xulrunner * Drop build_system_dont_link_libxul.diff - this isn't needed in current Thunderbird versions, as it ships a libxul.so * Drop the nspr build-dep and don't build with --with-system-nspr. Thunderbird provides this already, and avoids needing to bump nspr on older releases just to build enigmail - update debian/rules - update debian/control * Add build/unix/elfhack/Makefile to debian/clean. It doesn't get cleaned by the build system, and there is a copy in the tree already which breaks the build - update debian/clean * Build with --disable-webm and --disable-libjpeg-turbo so we don't need to build-depend on yasm. I really do need to clean all of this useless junk out of the configure script - update debian/rules * Remove build/pgo/profileserver.py from debian/clean. The new build system has a target depending on this - update debian/clean * Drop debian/patches/autoconf.diff, just generate this at build time * Refresh debian/patches/build_system_dont_link_libxul.diff * libipc seems to be renamed to libipc-pipe. Fix genxpi and chrome.manifest to fix this - add debian/patches/ipc-pipe_rename.diff - update debian/patches/series * The makefiles in extensions/enigmail/ipc have an incorrect DEPTH attribute. Fix this so that they can find the rest of the build system - add debian/patches/makefile_depth.diff - update debian/patches/series * Drop debian/patches/makefile-in-empty-xpcom-fix.diff - fixed in the current version * Don't register a class ID multiple times, as this breaks enigmail entirely - add debian/patches/dont_register_cids_multiple_times.diff - update debian/patches/series * Run autoconf2.13 at build time - update debian/rules - update debian/control * Add useless mesa-common-dev build-dep, just to satisfy the build system. We should just patch this out entirely really, but that's for another upload - update debian/control Date: 2012-04-17 06:10:57.237262+00:00 Changed-By: Chris Coulson Signed-By: Martin Pitt https://launchpad.net/ubuntu/natty/+source/enigmail/2:1.4-0ubuntu0.11.04.1 -------------- next part -------------- Sorry, changesfile not available. From martin.pitt at ubuntu.com Wed Apr 25 06:57:02 2012 From: martin.pitt at ubuntu.com (Martin Pitt) Date: Wed, 25 Apr 2012 06:57:02 -0000 Subject: [ubuntu/natty-updates] thunderbird 11.0.1+build1-0ubuntu0.11.04.1 (Accepted) Message-ID: <20120425065702.3746.69818.launchpad@ackee.canonical.com> thunderbird (11.0.1+build1-0ubuntu0.11.04.1) natty-proposed; urgency=low * New upstream stable release (THUNDERBIRD_11_0_1_BUILD1) * Update globalmenu-extension to 2.0.3 * Ensure we include locales in the tarball if they are in shipped-locales but not in all-locales - update debian/build/create-tarball.py * Always set the update channel - not setting it at build-time on release builds breaks the extensions.checkCompatibility pref. The only things using it at runtime are nsBlocklistService, Test Pilot (beta + aurora) and the about dialog (where the channel is hidden anyway) - update debian/rules - update debian/thunderbird.install.in * Fix LP: #898883 - IPC xpcshell tests hang the buildd's. Give all xpcshell tests an X display, as plugin-container won't work without one - update debian/build/testsuite.mk * Turn on all IPC xpcshell tests again (only applicable when the testsuite is enabled in the future) - update debian/build/testsute.mk * Refresh shipped locales for beta (addition of Armenian and Croatian) - refresh debian/config/locales.shipped - refresh debian/config/locales.all - refresh debian/control * Fix LP: #915895 - Just set autoDisableScopes to 0. Other distributions are already doing this, and we already made this feature pretty much useless by allowing extensions in the application directory, so that our language packs aren't disabled by default - update debian/vendor.js * Fix LP: #926495 - Add patch based on one from bmo: #691898 to enable building on ppc again - add debian/patches/fix-build-failure-without-yarr-jit.patch - update debian/patches/series * Fix LP: #926495 - Disable the SPS profiler on unsupported architectures - add debian/patches/no-sps-profiler-on-unsupported-archs.patch - update debian/patches/series * Disable more hanging IPC xpcshell tests - update debian/build/testsuite.mk * Drop the maintainer script hooks to remove conffiles that never even existed - remove debian/thunderbird.preinst.in - update debian/rules * Update after landing of bmo: #701875 - Rename omni.jar to omni.ja - update debian/thunderbird.install.in * Backport changes to allow per-release/par-arch patches - add debian/build/enable-dist-patches.pl - update debian/rules * Don't unconditionally overwrite SourcePackage when reporting bugs with the nightly apport hook - update debian/apport/source_thunderbird.py.in * Set "Channel = Unavailable" if channel-prefs.js doesn't contain a channel name - update debian/apport/source_thunderbird.py.in * Ensure that create-tarball can handle there not being a locale blacklist - update debian/build/create-tarball.py * Use makedirs to create the local cache directory - update debian/build-create-tarball.py * Drop xpt.py and xpidl from $LIBDIR. xpidl is gone, and xpt.py isn't included there in the upstream SDK - update debian/thunderbird-dev.links.in * Move custom scripts to debian/build - move debian/get-xpi-id.py to debian/build/get-xpi-id.py - move debian/refresh-supported-locales.pl to debian/build/refresh-supported-locales.pl - move debian/extract-file.py to debian/build/extract-file.py - move debian/testsuite.mk to debian/build - update debian/rules * Shrink the default mozconfig right down so that we use mostly upstream defaults, rather than overriding them with our own options. It is still possible to override them though. We also drop the pkg-config checks in debian/rules which allowed a fallback build configuration when dependencies aren't satisfied. Really, the build should just fail here rather than continuing in some undesirable fallback mode - update debian/thunderbird-dev.links.in - update debian/mozconfig.in - update debian/control.in - update debian/rules * Refresh build-depends, as this hasn't been done for a while: - Drop patchutils, libxft-dev, libxinerama-dev, libgnome2-dev, sharutils and bzip2. These don't appear to be needed - Drop liborbit2-dev - only appears to be required if there is no libidl - Add libglib2.0-dev, libext-dev, libfontconfig1-dev and libpango1.0-dev, as the configure script checks for these directly - Add minimum versions to libgconf2-dev, libgnomevfs2-dev, yasm and libgnomeui-dev - Specify minimum versions for libnspr4-dev, libcairo2-dev, libsqlite3-dev and libnss3-dev when using system versions of those libs * Introduce a branch config file (debian/config/branch.mk) which holds settings which shouldn't be merged between branches (eg, whether the crash reporter should be enabled) - add debian/config/branch.mk - update debian/rules * Move debian/locales.* to debian/config - move debian/locales.shipped => debian/config/locales.shipped - move debian/locales.unavail => debian/config/locales.unavail - update debian/rules - update debian/build/refresh-supported-locales.pl * Move debian/mozconfig.in to debian/config * Touch debian/control.in during clean to force a refresh of debian/control, so we can check if it is out-of-date and fail if it is - update debian/rules * Drop the mozilla-devscripts dependency. We were only using this for creating tarballs anyway. Instead, implement our own get-orig-source target, which also fixes some problems we were having - update debian/control.in - remove debian/moz-rev.sh - update debian/rules - remove debian/mozclient/mozclient.mk - remove debian/mozclient/thunderbird.conf - update debian/config/branch.mk - add debian/build/create-source - add debian/build/get-orig-source.mk - remove debian/mozclient/thunderbird-remove.binonly.sh * Lots of workflow improvements for dealing with language packs: - update debian/rules - add debian/build/extract-file.py - add debian/build/dump-langpack-control-entries.pl - update debian/build/refresh-supported-locales.pl - add debian/config/locales.all - update debian/config/locales.shipped - remove debian/config/locales.unavailable - update debian/control - update debian/build/create-tarball.py * Turn off the one-time addon selection dialog (LP: #888307) - update debian/vendor.js * Make sure we actually install the crashreporter and apport blacklist file for branches which use Breakpad - update debian/thunderbird.install.in * Drop the Mail/News reference in the desktop file - just set the name to "Thunderbird Mail". This needs translating for other locales though - update debian/thunderbird.desktop.in * Look in the correct location for the staged langpack xpi's. They moved from dist/install to dist/linux-$(DEB_HOST_GNU_CPU) - update debian/rules * Simplify thunderbird-dev.install a bit by installing everything in /usr/include/ - update debian/thunderbird-dev.install.in * Fix jsreftest failures by setting the correct timezone and locale - update debian/testsuite.mk * Add ${misc:Depends} dependency to transitional language packs - update debian/control.langpacks.unavail * Disable elfhack permanently. It doesn't give us any of the performance wins that the official mozilla.org builds get, due to -Wl,-z,relro - update debian/rules - update debian/mozconfig.in * Don't error out whilst creating the source package if mozilla-devscripts or cdbs aren't installed. This enables us to create source packages on machines which don't have these available - update debian/rules - update debian/mozclient/thunderbird.mk * Switch to comm-release - update debian/mozclient/thunderbird.conf * Update desktop file translations - update debian/thunderbird-trunk.desktop.in * Drop the profile migrator, as it doesn't really make any sense with the new release cycle. Instead, just copy the thunderbird profile (if it exists) to thunderbird-trunk (if it doesn't exist) - remove debian/migrator/xulapp-profilemigrator - update debian/thunderbird.sh.in - update debian/thunderbird.install.in - update debian/rules - update debian/control.in * Drop patches fixed upstream: - remove debian/patches/fix-sdk-bin-install.patch - remove debian/patches/series * xpt_link and xpt_dump have been replaced by xpt.py - update debian/thunderbird-dev.install.in - update debian/thunderbird-dev.links.in * Fix LP: #807805 - invalid language packs created because get-xpi-id.py exits with "xml.parsers.expat.ExpatError: XML or text declaration not at start of entity" exception when the install.rdf starts with empty lines - update debian/get-xpi-id.py * Explicitly specify the mozilla-release repo, as client.py still pulls from mozilla-beta - update debian/mozclient/thunderbird.conf * Parse the correct file for the version number - update debian/rules - update debian/mozclient/thunderbird.conf * Add transitional ta-lk language pack to pull in thunderbird-locale-ta - update debian/control.in - refresh debian/control * Set a Vcs-Bzr URL - update debian/control.in - refresh debian/control * Align packaging with firefox: - rename debian/apport/blacklist => debian/apport/thunderbird.in - rename debian/control => debian/control.in - rename debian/thunderbird-dev.install => debian/thunderbird-dev.install.in - rename debian/thunderbird-gnome-support.install => debian/thunderbird-gnome-support.install.in - rename debian/thunderbird.desktop => debian/thunderbird.desktop.in - rename debian/thunderbird.install => debian/thunderbird.install.in - rename debian/thunderbird.manpages => debian/thunderbird.manpages.in - update debian/apport/thunderbird.in - update debian/control.in - update debian/rules - update debian/thunderbird.sh.in - update debian/thunderbird.xml.in - update debian/thunderbird-dev.install.in - update debian/thunderbird-gnome-support.install - update debian/thunderbird.desktop.in - update debian/thunderbird.install.in - update debian/thunderbird.manpages - added debian/thunderbird-dev.links.in - added debian/thunderbird-globalmenu.dirs.in - added debian/thunderbird-mozsymbols.install.in - added debian/thunderbird.dirs.in - added debian/thunderbird.links.in - added debian/thunderbird.lintian-overrides.in * Build language packs directly from the thunderbird source + Include compare-locales FIREFOX_5_0b1_BUILD1 from http://hg.mozilla.org/build/compare-locales. It's needed for merging en-US strings with incomplete locales + Pull l10n data in to tarball from bzr - update debian/mozclient/thunderbird.conf + Configure build for creating language packs by configuring with "--with-l10n-base=" - update debian/mozconfig.in + Store the list of locales to ship, and provide a way of automatically generating that list and the control file entries from the upstream source. Also provide a way to blacklist languages. We map languages to package names using langpack-o-matic (and also get descriptions from there too) - update debian/rules - add debian/locales.shipped - add debian/control.langpacks - add debian/control.langpacks.unavail - update debian/control - add debian/locales.unavailable - add debian/refresh-supported-locales.pl + Add common-build-indep hook to build the translation xpi's - update debian/rules + Add common-binary-post-install-indep to install the xpi's in to the correct debian packages - update debian/rules - add debian/get-xpi-id.py + When rebuilding debian/control in the clean target, fail the build if the control file was out-of-date. This ensures that we don't accidentally drop language packs, and forces me to maintain an up-to-date control file in bzr - update debian/rules * Rewrite the launcher script to not wrap around the upstream start scripts, but start the Thunderbird binary directly. The upstream start scripts contain a lot of complexity for dealing with things that we don't need to worry about, and are quite slow. Also, add in the hooks for the new profile migrator - update debian/thunderbird.sh.in * Replace the old profile migrator. The previous one relied on hard-coded values and fragile shell script that isn't really scalable enough now that stable Ubuntu releases see new major Thunderbird versions. The new profile migrator doesn't require any hard-coded values, and should be lower maintenance - add debian/migrator/xulapp-profilemigrator - remove debian/migrator/main.c - update debian/rules - update debian/thunderbird.sh.in - update debian/control.in * Build with "make -f client.mk" and using a mozconfig, rather than the autoconf/configure/make steps used previously. The client.mk contains the sequencing for doing PGO builds - add debian/mozconfig.in - update debian/rules * Refreshed patches: - update debian/patches/no-dynamic-nss-softokn.patch - update debian/patches/unity-globalmenu-build-support.patch - update debian/patches/add-syspref-dir.patch * Support running the Mozilla test suite at build time. Currently, we run the following targets: check, jstestbrowser, xpcshell-tests, reftest, crashtest and mochitest. Not enabled yet - add debian/testsuite.mk - update debian/rules * Don't touch $LIBDIR/.autoreg on install or removal. This has no effect with the components registration changes in Gecko >= 2.0 - update debian/thunderbird.postinst.in - remove debian/thunderbird.prerm.in * Ensure that the files in /etc/thunderbird/profile are cleaned up on upgrade - update debian/thunderbird.preinst.in * Drop unneeded patches: - drop debian/patches/bz420391_attXXXX_fix_unix_installer.patch (only seemed to be needed for static builds) - remove bz532198_lp488354_ns_invokebyindex_not_thumb2_safe.patch (fixed upstream) - remove debian/patches/bz591331_att469858_breakpad_allow_ptrace.patch (fixed upstream) - remove debian/patches/bzXXX_ftbfs_static_with_system_hunspell.patch (not doing static builds now) - remove debian/patches/bzXXX_linker_flag_ordering.patch (not doing static builds now) - remove debian/patches/fix_installdir.patch (not sure what it was needed for) - remove debian/patches/fix_sdk_install_mimecrypt.patch (fixed upstream) - remove debian/patches/lp682742_arm_it_instruction.patch (fixed upstream) - remove debian/patches/lp_710648_arm_it_instruction_breakpad.patch (fixed upstream) - remove debian/patches/use-MOZ_APP_LAUNCHER-for-launcher-exec.patch (fixed upstream) - update debian/patches/series * Fix LP: #767115 - use a high-res icon for the launcher - update debian/thunderbird.links.in Date: 2012-04-12 06:10:53.851973+00:00 Changed-By: Chris Coulson Signed-By: Martin Pitt https://launchpad.net/ubuntu/natty/+source/thunderbird/11.0.1+build1-0ubuntu0.11.04.1 -------------- next part -------------- Sorry, changesfile not available. From martin.pitt at ubuntu.com Wed Apr 25 06:57:07 2012 From: martin.pitt at ubuntu.com (Martin Pitt) Date: Wed, 25 Apr 2012 06:57:07 -0000 Subject: [ubuntu/natty-updates] lightning-extension 1.3+build1-0ubuntu0.11.04.1 (Accepted) Message-ID: <20120425065707.3746.67581.launchpad@ackee.canonical.com> lightning-extension (1.3+build1-0ubuntu0.11.04.1) natty-proposed; urgency=low * New upstream stable release (CALENDAR_1_3_BUILD1) (LP: #972840) * Add mozilla/mfbt to tarball * Refresh debian/patches/01_no_sunbird.patch * Add some additional mailnews makefiles to the tarball, to make the build system not sad anymore * Add the new python IDL parser to the tarball - update debian/rules * Pull from comm-beta - update debian/rules * Add db/mork/Makefile.in to the tarball - update debian/rules * Pass --mozilla-rev to client.py when creating the tarball - update debian/rules * Include the files containing the mail/suite version numbers in the tarball, as they're used to populate the version requirements in the install.rdf - update debian/rules * Strip everything we don't need out of the tarball (Firefox, Thunderbird, Seamonkey), leaving just the calendar and build system. This gets the tarball down from 85MB to 6MB, which will make those carrier pigeons who carry the bits from my house to the archive much, much happier - update debian/rules - remove debian/remove-binonly.sh * Add a get-orig-source target * Build with --disable-tests - update debian/rules * Fix LP: #809757 - FTBFS on armel. Build with --disable-elf-hack, as it's basically a noop on Ubuntu anyway - update debian/rules * Bump thunderbird-dev build-dep to 5.0~b1 - update debian/control * Build with --disable-webm and --disable-libjpeg-turbo, to avoid needing a build-depends on yasm - update debian/rules * Add useless build-dep on mesa-common-dev, it's mandatory to be able to configure lightning, even though it doesn't need it - update debian/control * Look for any version of the Thunderbird SDK - update debian/rules * Don't build with --with-system-nspr and --with-system-nss - thunderbird doesn't use these, so we just get everything from the SDK - update debian/rules * Build with --enable-chrome-format=jar. The calendar build.mk should probably specify a default here - update debian/rules * Build with --enable-libxul to force JS_SHARED_LIBRARY=0 and stop some makefile targets depending on a shared libmozjs - update debian/rules Date: 2012-04-17 07:50:54.302716+00:00 Changed-By: Chris Coulson Signed-By: Martin Pitt https://launchpad.net/ubuntu/natty/+source/lightning-extension/1.3+build1-0ubuntu0.11.04.1 -------------- next part -------------- Sorry, changesfile not available. From marc.deslauriers at ubuntu.com Thu Apr 26 19:33:18 2012 From: marc.deslauriers at ubuntu.com (Marc Deslauriers) Date: Thu, 26 Apr 2012 19:33:18 -0000 Subject: [ubuntu/natty-security] jetty 6.1.24-6ubuntu0.11.04.1 (Accepted) Message-ID: <20120426193318.18788.41449.launchpad@cocoplum.canonical.com> jetty (6.1.24-6ubuntu0.11.04.1) natty-security; urgency=low * SECURITY UPDATE: denial of service via many hash collisions - debian/patches/CVE-2011-4461.patch: limit number of form parameters to avoid a DoS in modules/jetty/src/main/java/org/mortbay/jetty/Request.java, modules/jetty/src/main/java/org/mortbay/jetty/handler/ContextHandler.java, modules/jetty/src/test/java/org/mortbay/jetty/RequestTest.java, modules/util/src/main/java/org/mortbay/util/UrlEncoded.java, modules/util/src/test/java/org/mortbay/util/URLEncodedTest.java. - CVE-2011-4461 Date: Mon, 23 Apr 2012 09:26:54 -0400 Changed-By: Marc Deslauriers Maintainer: Ubuntu Developers https://launchpad.net/ubuntu/natty/+source/jetty/6.1.24-6ubuntu0.11.04.1 -------------- next part -------------- Format: 1.8 Date: Mon, 23 Apr 2012 09:26:54 -0400 Source: jetty Binary: libjetty-java libjetty-java-doc libjetty-extra-java libjetty-extra jetty Architecture: source Version: 6.1.24-6ubuntu0.11.04.1 Distribution: natty-security Urgency: low Maintainer: Ubuntu Developers Changed-By: Marc Deslauriers Description: jetty - Java servlet engine and webserver libjetty-extra - Java servlet engine and webserver -- extra libraries libjetty-extra-java - Java servlet engine and webserver -- extra libraries libjetty-java - Java servlet engine and webserver -- core libraries libjetty-java-doc - Javadoc for the Jetty API Changes: jetty (6.1.24-6ubuntu0.11.04.1) natty-security; urgency=low . * SECURITY UPDATE: denial of service via many hash collisions - debian/patches/CVE-2011-4461.patch: limit number of form parameters to avoid a DoS in modules/jetty/src/main/java/org/mortbay/jetty/Request.java, modules/jetty/src/main/java/org/mortbay/jetty/handler/ContextHandler.java, modules/jetty/src/test/java/org/mortbay/jetty/RequestTest.java, modules/util/src/main/java/org/mortbay/util/UrlEncoded.java, modules/util/src/test/java/org/mortbay/util/URLEncodedTest.java. - CVE-2011-4461 Checksums-Sha1: 88035659244fcd48695c2763bc17022f1ec0298a 2538 jetty_6.1.24-6ubuntu0.11.04.1.dsc d5bbcbde7a2fd9774905228a4aa88b87abeefae3 28585 jetty_6.1.24-6ubuntu0.11.04.1.debian.tar.gz Checksums-Sha256: 1384a9f4611688241e99cea94c55832dd206ac0c5b35e1b1431e166d73e4e7b0 2538 jetty_6.1.24-6ubuntu0.11.04.1.dsc d5117194e8d9667e3eac904e4a259e3b6bcd1115f5111dc85d10164134d51ab9 28585 jetty_6.1.24-6ubuntu0.11.04.1.debian.tar.gz Files: 96a0858665e1f8b106b155f2d4c65415 2538 java optional jetty_6.1.24-6ubuntu0.11.04.1.dsc 4acf3c1aaff75a3c8b7bf1e5e48b959e 28585 java optional jetty_6.1.24-6ubuntu0.11.04.1.debian.tar.gz Original-Maintainer: Debian Java Maintainers From jamie at ubuntu.com Fri Apr 27 12:03:58 2012 From: jamie at ubuntu.com (Jamie Strandboge) Date: Fri, 27 Apr 2012 12:03:58 -0000 Subject: [ubuntu/natty-security] dropbear 0.52-5+squeeze1build0.11.04.1 (Accepted) Message-ID: <20120427120358.29253.73650.launchpad@cocoplum.canonical.com> dropbear (0.52-5+squeeze1build0.11.04.1) natty-security; urgency=low * fake sync from Debian dropbear (0.52-5+squeeze1) stable-security; urgency=high * debian/diff/0003-Fix-use-after-free-bug-CVE-2012-0920.diff: new: Fix use-after-free bug (CVE-2012-0920) (closes: #661150). Date: Thu, 26 Apr 2012 06:43:53 -0500 Changed-By: Jamie Strandboge Maintainer: Gerrit Pape https://launchpad.net/ubuntu/natty/+source/dropbear/0.52-5+squeeze1build0.11.04.1 -------------- next part -------------- Format: 1.8 Date: Thu, 26 Apr 2012 06:43:53 -0500 Source: dropbear Binary: dropbear Architecture: source Version: 0.52-5+squeeze1build0.11.04.1 Distribution: natty-security Urgency: high Maintainer: Gerrit Pape Changed-By: Jamie Strandboge Description: dropbear - lightweight SSH2 server and client Closes: 661150 Changes: dropbear (0.52-5+squeeze1build0.11.04.1) natty-security; urgency=low . * fake sync from Debian . dropbear (0.52-5+squeeze1) stable-security; urgency=high . * debian/diff/0003-Fix-use-after-free-bug-CVE-2012-0920.diff: new: Fix use-after-free bug (CVE-2012-0920) (closes: #661150). Checksums-Sha1: c61251ce9c5ce037cb9e4e791ff685cd886ecb38 1669 dropbear_0.52-5+squeeze1build0.11.04.1.dsc 77030eabc4c5e099da70957eaffb4b25836ad76c 6070 dropbear_0.52-5+squeeze1build0.11.04.1.diff.gz Checksums-Sha256: 68bf92e14f7e1d210ae43e83f8525d782394357e90d8cc0600ea65334885d6ce 1669 dropbear_0.52-5+squeeze1build0.11.04.1.dsc 7d66ec70f6e6d34665aded4131be48b2065d62a25c82f64f372ddaff91bbae18 6070 dropbear_0.52-5+squeeze1build0.11.04.1.diff.gz Files: f0db7e8e3c3b808ebdcb964cb5e16b60 1669 net optional dropbear_0.52-5+squeeze1build0.11.04.1.dsc 199d1804224e4cc1fc1de5d8857ec829 6070 net optional dropbear_0.52-5+squeeze1build0.11.04.1.diff.gz From jamie at ubuntu.com Fri Apr 27 20:03:19 2012 From: jamie at ubuntu.com (Jamie Strandboge) Date: Fri, 27 Apr 2012 20:03:19 -0000 Subject: [ubuntu/natty-security] typo3-src 4.3.9+dfsg1-1+squeeze4build0.11.04.1 (Accepted) Message-ID: <20120427200319.27248.16824.launchpad@cocoplum.canonical.com> typo3-src (4.3.9+dfsg1-1+squeeze4build0.11.04.1) natty-security; urgency=low * fake sync from Debian typo3-src (4.3.9+dfsg1-1+squeeze4) squeeze-security; urgency=medium * Security patch backported from new upstream release 4.4.15: - fixes: "TYPO3 Security Bulletin TYPO3-CORE-SA-2012-002: Cross-Site Scripting Vulnerability in TYPO3 Core" (Closes: 669158) Date: Fri, 27 Apr 2012 08:27:21 -0500 Changed-By: Jamie Strandboge Maintainer: Christian Welzel https://launchpad.net/ubuntu/natty/+source/typo3-src/4.3.9+dfsg1-1+squeeze4build0.11.04.1 -------------- next part -------------- Format: 1.8 Date: Fri, 27 Apr 2012 08:27:21 -0500 Source: typo3-src Binary: typo3-src-4.3 typo3-database typo3 Architecture: source Version: 4.3.9+dfsg1-1+squeeze4build0.11.04.1 Distribution: natty-security Urgency: medium Maintainer: Christian Welzel Changed-By: Jamie Strandboge Description: typo3 - The enterprise level open source WebCMS (Meta) typo3-database - TYPO3 - The enterprise level open source WebCMS (Database) typo3-src-4.3 - TYPO3 - The enterprise level open source WebCMS (Core) Closes: 669158 Changes: typo3-src (4.3.9+dfsg1-1+squeeze4build0.11.04.1) natty-security; urgency=low . * fake sync from Debian . typo3-src (4.3.9+dfsg1-1+squeeze4) squeeze-security; urgency=medium . * Security patch backported from new upstream release 4.4.15: - fixes: "TYPO3 Security Bulletin TYPO3-CORE-SA-2012-002: Cross-Site Scripting Vulnerability in TYPO3 Core" (Closes: 669158) Checksums-Sha1: ef7128a355a990897b7f68de4e468fe13b09cb16 1804 typo3-src_4.3.9+dfsg1-1+squeeze4build0.11.04.1.dsc 60aad0dfeaf2a5fe1347fcd2607a22918cef5ad1 131919 typo3-src_4.3.9+dfsg1-1+squeeze4build0.11.04.1.debian.tar.gz Checksums-Sha256: fd91ba8031d294fd50524dc5d0983b4ea13808ede3b525a230ef34714b9d8ff7 1804 typo3-src_4.3.9+dfsg1-1+squeeze4build0.11.04.1.dsc 933842fdd355351b3e26b9b868bd05537a36d16ed17de5e1bf469aa84674fc34 131919 typo3-src_4.3.9+dfsg1-1+squeeze4build0.11.04.1.debian.tar.gz Files: 69001fc6e31a6530269642ac584a5ba7 1804 web optional typo3-src_4.3.9+dfsg1-1+squeeze4build0.11.04.1.dsc fa173c33c08b189da04cf139d3c3d287 131919 web optional typo3-src_4.3.9+dfsg1-1+squeeze4build0.11.04.1.debian.tar.gz From adconrad at 0c3.net Mon Apr 30 18:56:40 2012 From: adconrad at 0c3.net (Adam Conrad) Date: Mon, 30 Apr 2012 18:56:40 -0000 Subject: [ubuntu/natty-updates] landscape-client 12.04.3-0ubuntu0.11.04 (Accepted) Message-ID: <20120430185640.10996.31035.launchpad@ackee.canonical.com> landscape-client (12.04.3-0ubuntu0.11.04) natty-proposed; urgency=low Tracking bug: LP: #978884 [ David Britton ] * Warn on unicode entry into settings UI (LP: #956612). * Sanitise hostname field in settings UI (LP: #954507). * Make it clear that the Landscape service is commercial (LP: #965850) * Further internationalize the settings UI (LP: #962899) * Depend on python-aptdaemon.gtk3widgets instead of python-aptdaemon and replace dependency on python-gobject by python-gi (LP: #961894) * Add i18n to the landscape-client-ui-install script. (LP: #961891) [ Andreas Hasenack ] * Fix default landscape hostname in glib schema. * dpkg test improvements to fix intermittent failures. * If ssl_public_key is supplied, use it also when fetching script attachments. This fixes the case of using script execution with attachments when the Landscape server is using a custom CA, most common in LDS deployments. (LP: #959846) * Make sure we have a PATH variable set before doing package activities, and also set it in the initscript for good measure. If the client was configured and restarted by the new UI configuration tool, PATH wasn't set, triggering an error in dpkg. (LP: #961190) * Make landscape-client-ui depend on landscape-client-ui-install, so that we get an entry in the system settings if just landscape-client-ui is installed. The actual entry comes from landscape-client-ui-install. * Optimization: when adding binaries, don't reload every repo, only the one containing the binaries. (LP: #954822) * Handle the case where the user clicks twice inadvertently on the Landscape icon in system settings and don't start a second copy of itself. (LP: #960211) * Change package management features to use APT instead of Smart (LP: #856244, #861707, #859615, #861345, #863239, #863259, #865270, #865272, #865285, #865273, #871641, #865299, #873196, #873939, #876493, #881973, #882438, #866014, #881998, #884142, #884151, #884131, #887037, #886208, #887578, #887947, #889067, #889069, #889087, #889099, #865303, #889113, #890605, #890606, #890609, #897416, #891855, #898681, #898683, #897656, #898542, #862212, #903202, #914734, #914735, #914737, #916301, #915280, #914742, #918925, #918175, #919179, #921664, #921699, #922582, #922511, #921712, #928750, #932136, #928941, #937411, #937567, #925543, #947803, #952973, #948142, #953136, #953906, #956590). * Add a GTK interface to configure the client (LP: #911279, #911666, #912163, #911665, #916300, #931937, #931937, #943622, #945025, #911279, #944652, #948464, #948416, #949158, #911671, #950864, #949208, #949147, #953070, #953292, #953463, #953034, #949200, #953026, #954499, #954516, #954285, #953065, #954414, #954332, #954542, #955966, #955139, #956030, #956119). * Add the ability to auto discover the server location on local deployment (LP: #917422, #927620, #917422, #928585, #929087, #932325, #948564) * Allow the client to accept arbitrary environment variables from the server for script execution (LP: #954999). * Make landscape-config exit non-zero when registration fails and --ok-no-register is not passed (LP: #271759). * Check for the content of /sys/bus/xen/devices to report a machine as a Xen VM instead of just relying on the existence of /sys/bus/xen (LP: #921970). * Make sure cloud registration succeeds if there is no kernel specified in the meta-data service (LP: #920453). * Report private and public IP adresses from the metadata service at cloud registration time (LP: #918366). * Add support for reporting hardware information using lshw (LP: #899002, #943975, #955734). * Add support for the new attachment service in script execution (LP: #893040). * Adds a new message type, 'register-provisioned-machine', which is meant to register computers using an OTP (LP: #881405). * Add local cloning option for load testing (LP: #872830, #925924). * Add more variables to preseeding (LP: #863204, #867710). * Allow the configuration of the ping interval (LP: #397884). * Add fake package reporters for load testing purposes (LP: #821571, #821570). * Report a package reporter error to the server if no APT sources are configured, to trigger a package reporter alert (LP: #823769). Date: 2012-04-16 10:00:13.947479+00:00 Changed-By: Andreas Hasenack Signed-By: Adam Conrad https://launchpad.net/ubuntu/natty/+source/landscape-client/12.04.3-0ubuntu0.11.04 -------------- next part -------------- Sorry, changesfile not available.