From marc.deslauriers at ubuntu.com Thu Aug 2 12:03:52 2012 From: marc.deslauriers at ubuntu.com (Marc Deslauriers) Date: Thu, 02 Aug 2012 12:03:52 -0000 Subject: [ubuntu/natty-security] qemu-kvm 0.14.0+noroms-0ubuntu4.6 (Accepted) Message-ID: <20120802120352.14852.77077.launchpad@cocoplum.canonical.com> qemu-kvm (0.14.0+noroms-0ubuntu4.6) natty-security; urgency=low * SECURITY UPDATE: file overwrite via incorrect temp file checking - debian/patches/CVE-2012-2652.patch: properly check length and failures in block.c, block_int.h, block/vvfat.c. - CVE-2012-2652 Date: Tue, 31 Jul 2012 10:31:50 -0400 Changed-By: Marc Deslauriers Maintainer: Ubuntu Developers https://launchpad.net/ubuntu/natty/+source/qemu-kvm/0.14.0+noroms-0ubuntu4.6 -------------- next part -------------- Format: 1.8 Date: Tue, 31 Jul 2012 10:31:50 -0400 Source: qemu-kvm Binary: qemu-kvm qemu-common kvm qemu Architecture: source Version: 0.14.0+noroms-0ubuntu4.6 Distribution: natty-security Urgency: low Maintainer: Ubuntu Developers Changed-By: Marc Deslauriers Description: kvm - dummy transitional package from kvm to qemu-kvm qemu - dummy transitional package from qemu to qemu-kvm qemu-common - qemu common functionality (bios, documentation, etc) qemu-kvm - Full virtualization on i386 and amd64 hardware Changes: qemu-kvm (0.14.0+noroms-0ubuntu4.6) natty-security; urgency=low . * SECURITY UPDATE: file overwrite via incorrect temp file checking - debian/patches/CVE-2012-2652.patch: properly check length and failures in block.c, block_int.h, block/vvfat.c. - CVE-2012-2652 Checksums-Sha1: 080e592f0f8066374cda0551cc8f31107e269fc6 2099 qemu-kvm_0.14.0+noroms-0ubuntu4.6.dsc 2e90778037b94d25fa08891c145b691fb9ec7add 62212 qemu-kvm_0.14.0+noroms-0ubuntu4.6.diff.gz Checksums-Sha256: 2b4fd7ae0b01c34596f381d801b32177c7b84745d2e42c1165d6f8deb3391938 2099 qemu-kvm_0.14.0+noroms-0ubuntu4.6.dsc be54175d43b6c9ef1813440080ae0cd25e0527a40f57173d6545ebfc5491415a 62212 qemu-kvm_0.14.0+noroms-0ubuntu4.6.diff.gz Files: e41ad70a5cc94ec03052f38e62e16e70 2099 misc optional qemu-kvm_0.14.0+noroms-0ubuntu4.6.dsc 663f4d674c29d13227a349ef5dad1957 62212 misc optional qemu-kvm_0.14.0+noroms-0ubuntu4.6.diff.gz From jamie at ubuntu.com Fri Aug 3 22:04:00 2012 From: jamie at ubuntu.com (Jamie Strandboge) Date: Fri, 03 Aug 2012 22:04:00 -0000 Subject: [ubuntu/natty-security] libapache-mod-security 2.5.12-1+squeeze1build0.11.04.1 (Accepted) Message-ID: <20120803220400.28493.12673.launchpad@cocoplum.canonical.com> libapache-mod-security (2.5.12-1+squeeze1build0.11.04.1) natty-security; urgency=low * fake sync from Debian libapache-mod-security (2.5.12-1+squeeze1) stable-security; urgency=high * CVE-2012-2751: Fix multi-part bypass due to wrong quoting. Applied backported patch from 2.6.6. (Closes: #678529) Date: Fri, 03 Aug 2012 11:56:14 -0500 Changed-By: Jamie Strandboge Maintainer: Alberto Gonzalez Iniesta https://launchpad.net/ubuntu/natty/+source/libapache-mod-security/2.5.12-1+squeeze1build0.11.04.1 -------------- next part -------------- Format: 1.8 Date: Fri, 03 Aug 2012 11:56:14 -0500 Source: libapache-mod-security Binary: libapache-mod-security mod-security-common Architecture: source Version: 2.5.12-1+squeeze1build0.11.04.1 Distribution: natty-security Urgency: high Maintainer: Alberto Gonzalez Iniesta Changed-By: Jamie Strandboge Description: libapache-mod-security - Tighten web applications security for Apache mod-security-common - Tighten web applications security - common files Closes: 678529 Changes: libapache-mod-security (2.5.12-1+squeeze1build0.11.04.1) natty-security; urgency=low . * fake sync from Debian . libapache-mod-security (2.5.12-1+squeeze1) stable-security; urgency=high . * CVE-2012-2751: Fix multi-part bypass due to wrong quoting. Applied backported patch from 2.6.6. (Closes: #678529) Checksums-Sha1: de45981f5ad7dd855cec66ebe79d1c150d08ff4d 1976 libapache-mod-security_2.5.12-1+squeeze1build0.11.04.1.dsc 1d3d2f6be1d524949ba44e9e4d9f5f88331ac390 9260 libapache-mod-security_2.5.12-1+squeeze1build0.11.04.1.debian.tar.gz Checksums-Sha256: 52de6fc438242ad73a90d3a41d65dae6a336c3ad7b6bc2bdfb0474e446c5cd44 1976 libapache-mod-security_2.5.12-1+squeeze1build0.11.04.1.dsc d0b9556f4a2cae254967f450bba392f656091bffcde943fa9174a7f8178d9125 9260 libapache-mod-security_2.5.12-1+squeeze1build0.11.04.1.debian.tar.gz Files: 3ea3e61498f715c3d759ec485b12626e 1976 httpd optional libapache-mod-security_2.5.12-1+squeeze1build0.11.04.1.dsc 170f83c593abd202fa71e6e37bdd57b2 9260 httpd optional libapache-mod-security_2.5.12-1+squeeze1build0.11.04.1.debian.tar.gz From cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk Fri Aug 3 22:28:12 2012 From: cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk (Ubuntu Archive Robot) Date: Fri, 03 Aug 2012 22:28:12 -0000 Subject: [ubuntu/natty-updates] libapache-mod-security 2.5.12-1+squeeze1build0.11.04.1 (Accepted) Message-ID: <20120803222812.14642.81105.launchpad@ackee.canonical.com> libapache-mod-security (2.5.12-1+squeeze1build0.11.04.1) natty-security; urgency=low * fake sync from Debian Date: 2012-08-03 17:35:49.444774+00:00 Changed-By: Jamie Strandboge Signed-By: Ubuntu Archive Robot https://launchpad.net/ubuntu/natty/+source/libapache-mod-security/2.5.12-1+squeeze1build0.11.04.1 -------------- next part -------------- Sorry, changesfile not available. From cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk Fri Aug 3 22:58:11 2012 From: cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk (Ubuntu Archive Robot) Date: Fri, 03 Aug 2012 22:58:11 -0000 Subject: [ubuntu/natty-updates] libapache-mod-security 2.5.12-1+squeeze1build0.11.04.1 (Accepted) Message-ID: <20120803225811.22174.93822.launchpad@ackee.canonical.com> Date: 2012-08-03 17:35:49.444774+00:00 Changed-By: Jamie Strandboge Signed-By: Ubuntu Archive Robot https://launchpad.net/ubuntu/natty/+source/libapache-mod-security/2.5.12-1+squeeze1build0.11.04.1 -------------- next part -------------- Sorry, changesfile not available. From cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk Fri Aug 3 23:28:11 2012 From: cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk (Ubuntu Archive Robot) Date: Fri, 03 Aug 2012 23:28:11 -0000 Subject: [ubuntu/natty-updates] libapache-mod-security 2.5.12-1+squeeze1build0.11.04.1 (Accepted) Message-ID: <20120803232811.31904.14729.launchpad@ackee.canonical.com> Date: 2012-08-03 17:35:49.444774+00:00 Changed-By: Jamie Strandboge Signed-By: Ubuntu Archive Robot https://launchpad.net/ubuntu/natty/+source/libapache-mod-security/2.5.12-1+squeeze1build0.11.04.1 -------------- next part -------------- Sorry, changesfile not available. From cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk Fri Aug 3 23:58:13 2012 From: cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk (Ubuntu Archive Robot) Date: Fri, 03 Aug 2012 23:58:13 -0000 Subject: [ubuntu/natty-updates] libapache-mod-security 2.5.12-1+squeeze1build0.11.04.1 (Accepted) Message-ID: <20120803235813.9659.18423.launchpad@ackee.canonical.com> Date: 2012-08-03 17:35:49.444774+00:00 Changed-By: Jamie Strandboge Signed-By: Ubuntu Archive Robot https://launchpad.net/ubuntu/natty/+source/libapache-mod-security/2.5.12-1+squeeze1build0.11.04.1 -------------- next part -------------- Sorry, changesfile not available. From marc.deslauriers at ubuntu.com Mon Aug 6 12:33:51 2012 From: marc.deslauriers at ubuntu.com (Marc Deslauriers) Date: Mon, 06 Aug 2012 12:33:51 -0000 Subject: [ubuntu/natty-security] nvidia-graphics-drivers-173 173.14.30-0ubuntu1.2 (Accepted) Message-ID: <20120806123351.32144.78829.launchpad@cocoplum.canonical.com> nvidia-graphics-drivers-173 (173.14.30-0ubuntu1.2) natty-security; urgency=low * SECURITY UPDATE: privilege escalation via kernel memory access - debian/dkms/patches/blacklist-vga-pmu-registers.patch: blacklist more offsets in nv.{c,h}. - debian/dkms.conf{.in}: added new patch. - CVE number pending Date: Sun, 05 Aug 2012 10:56:06 -0400 Changed-By: Marc Deslauriers Maintainer: Ubuntu Developers https://launchpad.net/ubuntu/natty/+source/nvidia-graphics-drivers-173/173.14.30-0ubuntu1.2 -------------- next part -------------- Format: 1.8 Date: Sun, 05 Aug 2012 10:56:06 -0400 Source: nvidia-graphics-drivers-173 Binary: nvidia-173 nvidia-173-dev nvidia-glx-173 nvidia-glx-173-dev nvidia-173-kernel-source Architecture: source Version: 173.14.30-0ubuntu1.2 Distribution: natty-security Urgency: low Maintainer: Ubuntu Developers Changed-By: Marc Deslauriers Description: nvidia-173 - NVIDIA binary Xorg driver, kernel module and VDPAU library nvidia-173-dev - NVIDIA binary Xorg driver development files nvidia-173-kernel-source - Transitional package for nvidia-glx-173-kernel-source nvidia-glx-173 - Transitional package for nvidia-glx-173 nvidia-glx-173-dev - Transitional package for nvidia-glx-173-dev Changes: nvidia-graphics-drivers-173 (173.14.30-0ubuntu1.2) natty-security; urgency=low . * SECURITY UPDATE: privilege escalation via kernel memory access - debian/dkms/patches/blacklist-vga-pmu-registers.patch: blacklist more offsets in nv.{c,h}. - debian/dkms.conf{.in}: added new patch. - CVE number pending Checksums-Sha1: ae14621221c6c5ab9a9a65b78356d9d8f78f1c20 2008 nvidia-graphics-drivers-173_173.14.30-0ubuntu1.2.dsc 9dc224d99fb540fb4d15bec5ed6c2eb7645338c3 40668 nvidia-graphics-drivers-173_173.14.30-0ubuntu1.2.diff.gz Checksums-Sha256: 4b776078761cc7e2b9d52038005a062d00943c874e0a9824579bd96ed93b8b79 2008 nvidia-graphics-drivers-173_173.14.30-0ubuntu1.2.dsc e77faf76ae00f4348eac8dcea9b323660f730a3b9ad7d303d3f3bfff4bee6557 40668 nvidia-graphics-drivers-173_173.14.30-0ubuntu1.2.diff.gz Files: 916fdc64cf17f524b789a9a34ffb8951 2008 restricted/misc optional nvidia-graphics-drivers-173_173.14.30-0ubuntu1.2.dsc 5870c98d751d6df70765b45c0a502475 40668 restricted/misc optional nvidia-graphics-drivers-173_173.14.30-0ubuntu1.2.diff.gz From marc.deslauriers at ubuntu.com Mon Aug 6 12:33:54 2012 From: marc.deslauriers at ubuntu.com (Marc Deslauriers) Date: Mon, 06 Aug 2012 12:33:54 -0000 Subject: [ubuntu/natty-security] nvidia-graphics-drivers 270.41.06-0ubuntu1.2 (Accepted) Message-ID: <20120806123354.32144.10526.launchpad@cocoplum.canonical.com> nvidia-graphics-drivers (270.41.06-0ubuntu1.2) natty-security; urgency=low * SECURITY UPDATE: privilege escalation via kernel memory access - debian/dkms/patches/blacklist-vga-pmu-registers.patch: blacklist more offsets in nv.{c,h}. - debian/dkms.conf{.in}: added new patch. - CVE number pending Date: Sun, 05 Aug 2012 09:45:10 -0400 Changed-By: Marc Deslauriers Maintainer: Ubuntu Developers https://launchpad.net/ubuntu/natty/+source/nvidia-graphics-drivers/270.41.06-0ubuntu1.2 -------------- next part -------------- Format: 1.8 Date: Sun, 05 Aug 2012 09:45:10 -0400 Source: nvidia-graphics-drivers Binary: nvidia-current nvidia-current-dev nvidia-glx-185 nvidia-glx-185-dev nvidia-185-kernel-source nvidia-185-libvdpau nvidia-185-libvdpau-dev Architecture: source Version: 270.41.06-0ubuntu1.2 Distribution: natty-security Urgency: low Maintainer: Ubuntu Developers Changed-By: Marc Deslauriers Description: nvidia-185-kernel-source - Transitional package for nvidia-glx-185-kernel-source nvidia-185-libvdpau - Transitional package for nvidia-185-libvdpau nvidia-185-libvdpau-dev - Transitional package for nvidia-185-libvdpau-dev nvidia-current - NVIDIA binary Xorg driver, kernel module and VDPAU library nvidia-current-dev - NVIDIA binary Xorg driver development files nvidia-glx-185 - Transitional package for nvidia-glx-185 nvidia-glx-185-dev - Transitional package for nvidia-glx-185-dev Changes: nvidia-graphics-drivers (270.41.06-0ubuntu1.2) natty-security; urgency=low . * SECURITY UPDATE: privilege escalation via kernel memory access - debian/dkms/patches/blacklist-vga-pmu-registers.patch: blacklist more offsets in nv.{c,h}. - debian/dkms.conf{.in}: added new patch. - CVE number pending Checksums-Sha1: 3ac85fd708fde1d474404ef0ff258331518bf7e2 2188 nvidia-graphics-drivers_270.41.06-0ubuntu1.2.dsc 38ae28a4ecb25a06ee895ca235d28d48ee3f1862 157142 nvidia-graphics-drivers_270.41.06-0ubuntu1.2.diff.gz Checksums-Sha256: 611f2ddea38ac8740f250414fb0887632488fae4de68b02f23f9131dffbc7c96 2188 nvidia-graphics-drivers_270.41.06-0ubuntu1.2.dsc f5498b632ef8c3c4276badbfc9ef488dce9e45028e3f22a88ea9cd2863284c86 157142 nvidia-graphics-drivers_270.41.06-0ubuntu1.2.diff.gz Files: b85b18263852439cadd3238a34d55724 2188 restricted/misc optional nvidia-graphics-drivers_270.41.06-0ubuntu1.2.dsc 05f1e1e587ee6541b441c420a143a16c 157142 restricted/misc optional nvidia-graphics-drivers_270.41.06-0ubuntu1.2.diff.gz From cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk Mon Aug 6 13:29:16 2012 From: cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk (Ubuntu Archive Robot) Date: Mon, 06 Aug 2012 13:29:16 -0000 Subject: [ubuntu/natty-updates] nvidia-graphics-drivers 270.41.06-0ubuntu1.2 (Accepted) Message-ID: <20120806132916.28237.38017.launchpad@ackee.canonical.com> nvidia-graphics-drivers (270.41.06-0ubuntu1.2) natty-security; urgency=low * SECURITY UPDATE: privilege escalation via kernel memory access - debian/dkms/patches/blacklist-vga-pmu-registers.patch: blacklist more offsets in nv.{c,h}. - debian/dkms.conf{.in}: added new patch. - CVE number pending Date: 2012-08-05 15:21:23.001870+00:00 Changed-By: Marc Deslauriers Signed-By: Ubuntu Archive Robot https://launchpad.net/ubuntu/natty/+source/nvidia-graphics-drivers/270.41.06-0ubuntu1.2 -------------- next part -------------- Sorry, changesfile not available. From cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk Mon Aug 6 13:29:17 2012 From: cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk (Ubuntu Archive Robot) Date: Mon, 06 Aug 2012 13:29:17 -0000 Subject: [ubuntu/natty-updates] nvidia-graphics-drivers-173 173.14.30-0ubuntu1.2 (Accepted) Message-ID: <20120806132917.28237.11746.launchpad@ackee.canonical.com> nvidia-graphics-drivers-173 (173.14.30-0ubuntu1.2) natty-security; urgency=low * SECURITY UPDATE: privilege escalation via kernel memory access - debian/dkms/patches/blacklist-vga-pmu-registers.patch: blacklist more offsets in nv.{c,h}. - debian/dkms.conf{.in}: added new patch. - CVE number pending Date: 2012-08-05 15:28:52.829139+00:00 Changed-By: Marc Deslauriers Signed-By: Ubuntu Archive Robot https://launchpad.net/ubuntu/natty/+source/nvidia-graphics-drivers-173/173.14.30-0ubuntu1.2 -------------- next part -------------- Sorry, changesfile not available. From marc.deslauriers at ubuntu.com Thu Aug 9 18:33:44 2012 From: marc.deslauriers at ubuntu.com (Marc Deslauriers) Date: Thu, 09 Aug 2012 18:33:44 -0000 Subject: [ubuntu/natty-security] koffice, koffice_2.3.3-0ubuntu4.1_i386_translations.tar.gz 1:2.3.3-0ubuntu4.1 (Accepted) Message-ID: <20120809183344.21105.30185.launchpad@cocoplum.canonical.com> koffice (1:2.3.3-0ubuntu4.1) natty-security; urgency=low * SECURITY UPDATE: possible arbitrary code execution via malformed Word document (LP: #1032934) - debian/patches/wv2_buffer_overflow_fix.diff: don't overflow grupx in filters/kword/msword-odf/wv2/src/styles.cpp. - CVE number pending Date: Mon, 06 Aug 2012 10:55:34 -0400 Changed-By: Marc Deslauriers Maintainer: Kubuntu Developers https://launchpad.net/ubuntu/natty/+source/koffice/1:2.3.3-0ubuntu4.1 -------------- next part -------------- Format: 1.8 Date: Mon, 06 Aug 2012 10:55:34 -0400 Source: koffice Binary: koffice koffice-doc-html karbon kchart kexi kplato kpresenter krita krita-data kspread kword kword-data kthesaurus koffice-libs koffice-data koffice-dev okular-odp-backend koffice-dbg Architecture: source Version: 1:2.3.3-0ubuntu4.1 Distribution: natty-security Urgency: low Maintainer: Kubuntu Developers Changed-By: Marc Deslauriers Description: karbon - a vector graphics application for the KDE Office Suite kchart - chart drawing components for the KDE Office Suite kexi - integrated database environment for the KDE Office Suite koffice - KDE Office Suite koffice-data - common shared data for the KDE Office Suite koffice-dbg - debugging symbols for KOffice koffice-dev - common libraries for KOffice (development files) koffice-doc-html - KDE Office Suite documentation in HTML format koffice-libs - common libraries and binaries for the KDE Office Suite kplato - an integrated project management and planning tool kpresenter - a presentation program for the KDE Office Suite krita - a pixel-based image manipulation program for the KDE Office Suite krita-data - data files for Krita painting program kspread - a spreadsheet for the KDE Office Suite kthesaurus - thesaurus for the KDE Office Suite kword - a word processor for the KDE Office Suite kword-data - data files for KWord word processor okular-odp-backend - Okular backend for ODP OpenDocument Presentation files Launchpad-Bugs-Fixed: 1032934 Changes: koffice (1:2.3.3-0ubuntu4.1) natty-security; urgency=low . * SECURITY UPDATE: possible arbitrary code execution via malformed Word document (LP: #1032934) - debian/patches/wv2_buffer_overflow_fix.diff: don't overflow grupx in filters/kword/msword-odf/wv2/src/styles.cpp. - CVE number pending Checksums-Sha1: 3f7a026035abdaf472049f2434a7a6cbd06fda49 2863 koffice_2.3.3-0ubuntu4.1.dsc 74119c5ae2a41cb0959c2f1a27467131b0bf2ad0 55987 koffice_2.3.3-0ubuntu4.1.debian.tar.gz Checksums-Sha256: b54ac9c72786053b9ef0dd37db8891765ea7529fea63111537124a39efbb39da 2863 koffice_2.3.3-0ubuntu4.1.dsc a8d41a513c1fc6de8abcce2da679ff5e6dfc93e11d7c90bd41aae588a32e60d7 55987 koffice_2.3.3-0ubuntu4.1.debian.tar.gz Files: eaf8fa7df25bcacea43140abea65058b 2863 kde optional koffice_2.3.3-0ubuntu4.1.dsc ddd77c0ed1afd120f5ddcd152bb4fa72 55987 kde optional koffice_2.3.3-0ubuntu4.1.debian.tar.gz Original-Maintainer: Debian Qt/KDE Maintainers From cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk Thu Aug 9 18:58:13 2012 From: cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk (Ubuntu Archive Robot) Date: Thu, 09 Aug 2012 18:58:13 -0000 Subject: [ubuntu/natty-updates] koffice 1:2.3.3-0ubuntu4.1 (Accepted) Message-ID: <20120809185813.11495.78935.launchpad@ackee.canonical.com> koffice (1:2.3.3-0ubuntu4.1) natty-security; urgency=low * SECURITY UPDATE: possible arbitrary code execution via malformed Word document (LP: #1032934) - debian/patches/wv2_buffer_overflow_fix.diff: don't overflow grupx in filters/kword/msword-odf/wv2/src/styles.cpp. - CVE number pending Date: 2012-08-06 20:01:04.462020+00:00 Changed-By: Marc Deslauriers Maintainer: Kubuntu Members Signed-By: Ubuntu Archive Robot https://launchpad.net/ubuntu/natty/+source/koffice/1:2.3.3-0ubuntu4.1 -------------- next part -------------- Sorry, changesfile not available. From adconrad at 0c3.net Fri Aug 10 00:29:57 2012 From: adconrad at 0c3.net (Adam Conrad) Date: Fri, 10 Aug 2012 00:29:57 -0000 Subject: [ubuntu/natty-updates] linux 2.6.38-15.65 (Accepted) Message-ID: <20120810002957.14640.90937.launchpad@ackee.canonical.com> linux (2.6.38-15.65) natty-proposed; urgency=low [Luis Henriques] * Release Tracking Bug - LP: #1027821 [ Andy Whitcroft ] * SAUCE: rds_ib_send() -- prevent local pings triggering BUG_ON() - LP: #1016299 - CVE-2012-2372 [ Upstream Kernel Changes ] * hugetlb: fix resv_map leak in error path - LP: #1004621 - CVE-2012-2390 * mm: fix vma_resv_map() NULL pointer - LP: #1004621 - CVE-2012-2390 * net: sock: validate data_len before allocating skb in sock_alloc_send_pskb() - LP: #1006622 - CVE-2012-2136 Date: 2012-07-26 20:10:38.186781+00:00 Changed-By: Luis Henriques Signed-By: Adam Conrad https://launchpad.net/ubuntu/natty/+source/linux/2.6.38-15.65 -------------- next part -------------- Sorry, changesfile not available. From adconrad at 0c3.net Fri Aug 10 00:30:18 2012 From: adconrad at 0c3.net (Adam Conrad) Date: Fri, 10 Aug 2012 00:30:18 -0000 Subject: [ubuntu/natty-security] linux 2.6.38-15.65 (Accepted) Message-ID: <20120810003018.14640.37591.launchpad@ackee.canonical.com> linux (2.6.38-15.65) natty-proposed; urgency=low [Luis Henriques] * Release Tracking Bug - LP: #1027821 [ Andy Whitcroft ] * SAUCE: rds_ib_send() -- prevent local pings triggering BUG_ON() - LP: #1016299 - CVE-2012-2372 [ Upstream Kernel Changes ] * hugetlb: fix resv_map leak in error path - LP: #1004621 - CVE-2012-2390 * mm: fix vma_resv_map() NULL pointer - LP: #1004621 - CVE-2012-2390 * net: sock: validate data_len before allocating skb in sock_alloc_send_pskb() - LP: #1006622 - CVE-2012-2136 linux (2.6.38-15.64) natty-proposed; urgency=low [ Andy Whitcroft ] * fix ABI directory naming [ Luis Henriques ] * Release Tracking Bug - LP: #1019992 linux (2.6.38-15.63) natty-proposed; urgency=low [ Andy Whitcroft ] * No change upload to fix .ddeb generation in the PPA. [ Luis Henriques ] * Release Tracking Bug - LP: #1019992 linux (2.6.38-15.62) natty-proposed; urgency=low [Luis Henriques] * Release Tracking Bug - LP: #1019992 [ Upstream Kernel Changes ] * tun: reserves space for network in skb - LP: #905219 * KVM: VMX: do not overwrite uptodate vcpu->arch.cr3 on KVM_SET_SREGS - LP: #1018440 Date: 2012-07-26 20:10:38.186781+00:00 Changed-By: Luis Henriques Signed-By: Adam Conrad https://launchpad.net/ubuntu/natty/+source/linux/2.6.38-15.65 -------------- next part -------------- Sorry, changesfile not available. From adconrad at 0c3.net Fri Aug 10 00:33:04 2012 From: adconrad at 0c3.net (Adam Conrad) Date: Fri, 10 Aug 2012 00:33:04 -0000 Subject: [ubuntu/natty-updates] linux-ti-omap4 2.6.38-1209.25 (Accepted) Message-ID: <20120810003304.15208.39147.launchpad@ackee.canonical.com> linux-ti-omap4 (2.6.38-1209.25) natty-proposed; urgency=low * Release Tracking Bug - LP: #1029784 [ Andy Whitcroft ] * SAUCE: rds_ib_send() -- prevent local pings triggering BUG_ON() - LP: #1016299 - CVE-2012-2372 [ Upstream Kernel Changes ] * fcaps: clear the same personality flags as suid when fcaps are used - LP: #987571 - CVE-2012-2123 * security: fix compile error in commoncap.c - LP: #987571 - CVE-2012-2123 * net: sock: validate data_len before allocating skb in sock_alloc_send_pskb() - LP: #1006622 - CVE-2012-2136 * dl2k: Clean up rio_ioctl - CVE-2012-2313 * hfsplus: Fix potential buffer overflows - CVE-2012-2319 * nfs: don't lose MS_SYNCHRONOUS on remount of noac mount - LP: #775809 * NFSv4.1: Ensure state manager thread dies on last umount - LP: #775809 * NFSv4: Handle expired stateids when the lease is still valid - LP: #793702 * NFSv4.1: Fix the handling of NFS4ERR_SEQ_MISORDERED errors - LP: #793702 * NFSv4: include bitmap in nfsv4 get acl data - LP: #893147 - CVE-2011-4131 * Avoid reading past buffer when calling GETACL - LP: #1002505 - CVE-2012-2375 * Avoid beyond bounds copy while caching ACL - LP: #1002505 - CVE-2012-2375 * Fix length of buffer copied in __nfs4_get_acl_uncached - LP: #1002505 - CVE-2012-2375 Date: 2012-07-30 17:11:14.911652+00:00 Changed-By: Paolo Pisati Signed-By: Adam Conrad https://launchpad.net/ubuntu/natty/+source/linux-ti-omap4/2.6.38-1209.25 -------------- next part -------------- Sorry, changesfile not available. From adconrad at 0c3.net Fri Aug 10 00:33:09 2012 From: adconrad at 0c3.net (Adam Conrad) Date: Fri, 10 Aug 2012 00:33:09 -0000 Subject: [ubuntu/natty-security] linux-ti-omap4 2.6.38-1209.25 (Accepted) Message-ID: <20120810003309.15208.34400.launchpad@ackee.canonical.com> linux-ti-omap4 (2.6.38-1209.25) natty-proposed; urgency=low * Release Tracking Bug - LP: #1029784 [ Andy Whitcroft ] * SAUCE: rds_ib_send() -- prevent local pings triggering BUG_ON() - LP: #1016299 - CVE-2012-2372 [ Upstream Kernel Changes ] * fcaps: clear the same personality flags as suid when fcaps are used - LP: #987571 - CVE-2012-2123 * security: fix compile error in commoncap.c - LP: #987571 - CVE-2012-2123 * net: sock: validate data_len before allocating skb in sock_alloc_send_pskb() - LP: #1006622 - CVE-2012-2136 * dl2k: Clean up rio_ioctl - CVE-2012-2313 * hfsplus: Fix potential buffer overflows - CVE-2012-2319 * nfs: don't lose MS_SYNCHRONOUS on remount of noac mount - LP: #775809 * NFSv4.1: Ensure state manager thread dies on last umount - LP: #775809 * NFSv4: Handle expired stateids when the lease is still valid - LP: #793702 * NFSv4.1: Fix the handling of NFS4ERR_SEQ_MISORDERED errors - LP: #793702 * NFSv4: include bitmap in nfsv4 get acl data - LP: #893147 - CVE-2011-4131 * Avoid reading past buffer when calling GETACL - LP: #1002505 - CVE-2012-2375 * Avoid beyond bounds copy while caching ACL - LP: #1002505 - CVE-2012-2375 * Fix length of buffer copied in __nfs4_get_acl_uncached - LP: #1002505 - CVE-2012-2375 Date: 2012-07-30 17:11:14.911652+00:00 Changed-By: Paolo Pisati Signed-By: Adam Conrad https://launchpad.net/ubuntu/natty/+source/linux-ti-omap4/2.6.38-1209.25 -------------- next part -------------- Sorry, changesfile not available. From tyhicks at canonical.com Fri Aug 10 03:34:41 2012 From: tyhicks at canonical.com (Tyler Hicks) Date: Fri, 10 Aug 2012 03:34:41 -0000 Subject: [ubuntu/natty-security] expat 2.0.1-7ubuntu3.11.04.1 (Accepted) Message-ID: <20120810033441.3546.30428.launchpad@cocoplum.canonical.com> expat (2.0.1-7ubuntu3.11.04.1) natty-security; urgency=low * SECURITY UPDATE: Denial of service via hash collisions - debian/patches/577777_CVE_2012_0876.dpatch: Add random salt value to hash inputs. Based on upstream patch. - CVE-2012-0876 * SECURITY UPDATE: Denial of service via memory leak - debian/patches/588888_CVE_2012_1148.dpatch: Properly reallocate memory. Based on upstream patch. - CVE-2012-1148 Date: Thu, 09 Aug 2012 11:53:57 -0700 Changed-By: Tyler Hicks Maintainer: Ubuntu Developers https://launchpad.net/ubuntu/natty/+source/expat/2.0.1-7ubuntu3.11.04.1 -------------- next part -------------- Format: 1.8 Date: Thu, 09 Aug 2012 11:53:57 -0700 Source: expat Binary: lib64expat1-dev lib64expat1 libexpat1-dev libexpat1 libexpat1-udeb expat Architecture: source Version: 2.0.1-7ubuntu3.11.04.1 Distribution: natty-security Urgency: low Maintainer: Ubuntu Developers Changed-By: Tyler Hicks Description: expat - XML parsing C library - example application lib64expat1 - XML parsing C library - runtime library (64bit) lib64expat1-dev - XML parsing C library - development kit (64bit) libexpat1 - XML parsing C library - runtime library libexpat1-dev - XML parsing C library - development kit libexpat1-udeb - XML parsing C library - runtime library (udeb) Changes: expat (2.0.1-7ubuntu3.11.04.1) natty-security; urgency=low . * SECURITY UPDATE: Denial of service via hash collisions - debian/patches/577777_CVE_2012_0876.dpatch: Add random salt value to hash inputs. Based on upstream patch. - CVE-2012-0876 * SECURITY UPDATE: Denial of service via memory leak - debian/patches/588888_CVE_2012_1148.dpatch: Properly reallocate memory. Based on upstream patch. - CVE-2012-1148 Checksums-Sha1: a10aa4a0f784e3db6820d40a7866aca42e6a4d92 2239 expat_2.0.1-7ubuntu3.11.04.1.dsc a8b49abc6c1b09403ce2ccbc72c99b3168339956 145543 expat_2.0.1-7ubuntu3.11.04.1.diff.gz Checksums-Sha256: f50c537c665caa2143f888188c7e1825f49030a38a5cf0620a91feb77be9d659 2239 expat_2.0.1-7ubuntu3.11.04.1.dsc 251b61c33f55698cd76da86a37464fb5187330b3642cf07e77cfa52d8651451c 145543 expat_2.0.1-7ubuntu3.11.04.1.diff.gz Files: 459102f2326a87a7e1350c8151025ae3 2239 text optional expat_2.0.1-7ubuntu3.11.04.1.dsc 268f122ec74f7e2dd9bb80b0112e7272 145543 text optional expat_2.0.1-7ubuntu3.11.04.1.diff.gz Original-Maintainer: Debian XML/SGML Group From cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk Fri Aug 10 09:42:15 2012 From: cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk (Ubuntu Archive Robot) Date: Fri, 10 Aug 2012 09:42:15 -0000 Subject: [ubuntu/natty-updates] expat 2.0.1-7ubuntu3.11.04.1 (Accepted) Message-ID: <20120810094215.18676.94332.launchpad@ackee.canonical.com> expat (2.0.1-7ubuntu3.11.04.1) natty-security; urgency=low * SECURITY UPDATE: Denial of service via hash collisions - debian/patches/577777_CVE_2012_0876.dpatch: Add random salt value to hash inputs. Based on upstream patch. - CVE-2012-0876 * SECURITY UPDATE: Denial of service via memory leak - debian/patches/588888_CVE_2012_1148.dpatch: Properly reallocate memory. Based on upstream patch. - CVE-2012-1148 Date: 2012-08-09 20:15:29.170401+00:00 Changed-By: Tyler Hicks Signed-By: Ubuntu Archive Robot https://launchpad.net/ubuntu/natty/+source/expat/2.0.1-7ubuntu3.11.04.1 -------------- next part -------------- Sorry, changesfile not available. From marc.deslauriers at canonical.com Tue Aug 14 00:56:50 2012 From: marc.deslauriers at canonical.com (Marc Deslauriers) Date: Tue, 14 Aug 2012 00:56:50 -0000 Subject: [ubuntu/natty-security] libreoffice 1:3.3.4-0ubuntu1.4 (Accepted) Message-ID: <20120814005650.26464.72009.launchpad@ackee.canonical.com> libreoffice (1:3.3.4-0ubuntu1.4) natty-security; urgency=low * SECURITY UPDATE: arbitrary code execution via XML manifest encryption tag parsing code - debian/patches/CVE-2012-2665.patch: merge base64 encoders/decoders, check key size, unwind manifest xml parser and follow tag hierarchy model, count and order of receipt of properties doesn't matter, use sax::Converter::base64 code instead, ThreeByteToFourByte and friends are no longer in use. - CVE-2012-2665 Date: 2012-08-10 00:01:17.148709+00:00 Changed-By: Marc Deslauriers https://launchpad.net/ubuntu/natty/+source/libreoffice/1:3.3.4-0ubuntu1.4 -------------- next part -------------- Sorry, changesfile not available. From cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk Tue Aug 14 02:10:23 2012 From: cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk (Ubuntu Archive Robot) Date: Tue, 14 Aug 2012 02:10:23 -0000 Subject: [ubuntu/natty-updates] libreoffice 1:3.3.4-0ubuntu1.4 (Accepted) Message-ID: <20120814021023.17342.91925.launchpad@ackee.canonical.com> libreoffice (1:3.3.4-0ubuntu1.4) natty-security; urgency=low * SECURITY UPDATE: arbitrary code execution via XML manifest encryption tag parsing code - debian/patches/CVE-2012-2665.patch: merge base64 encoders/decoders, check key size, unwind manifest xml parser and follow tag hierarchy model, count and order of receipt of properties doesn't matter, use sax::Converter::base64 code instead, ThreeByteToFourByte and friends are no longer in use. - CVE-2012-2665 Date: 2012-08-10 00:01:17.148709+00:00 Changed-By: Marc Deslauriers Signed-By: Ubuntu Archive Robot https://launchpad.net/ubuntu/natty/+source/libreoffice/1:3.3.4-0ubuntu1.4 -------------- next part -------------- Sorry, changesfile not available. From chris.coulson at canonical.com Wed Aug 15 14:17:43 2012 From: chris.coulson at canonical.com (Chris Coulson) Date: Wed, 15 Aug 2012 14:17:43 -0000 Subject: [ubuntu/natty] adobe-flashplugin 11.2.202.238-0natty1 (Accepted) Message-ID: <20120815141743.17186.76122.launchpad@gac.canonical.com> adobe-flashplugin (11.2.202.238-0natty1) natty; urgency=low * New upstream release - LP: #1037020 Date: Wed, 15 Aug 2012 14:05:38 +0100 Changed-By: Chris Coulson Maintainer: DL-Flash Player Ubuntu https://launchpad.net/ubuntu/natty/+source/adobe-flashplugin/11.2.202.238-0natty1 -------------- next part -------------- Format: 1.8 Date: Wed, 15 Aug 2012 14:05:38 +0100 Source: adobe-flashplugin Binary: adobe-flashplugin adobe-flash-properties-gtk adobe-flash-properties-kde Architecture: source Version: 11.2.202.238-0natty1 Distribution: natty Urgency: low Maintainer: DL-Flash Player Ubuntu Changed-By: Chris Coulson Description: adobe-flash-properties-gtk - GTK+ control panel for Adobe Flash Player plugin version 11 adobe-flash-properties-kde - KDE control panel Adobe Flash Player plugin version 11 adobe-flashplugin - Adobe Flash Player plugin version 11 Launchpad-Bugs-Fixed: 1037020 Changes: adobe-flashplugin (11.2.202.238-0natty1) natty; urgency=low . * New upstream release - LP: #1037020 Checksums-Sha1: 2e66962a3b4131c7c1d6c18a8ffb83282469b8ca 1731 adobe-flashplugin_11.2.202.238-0natty1.dsc d048ef4731e487401232dc60a79717da9a215696 5119 adobe-flashplugin_11.2.202.238-0natty1.diff.gz Checksums-Sha256: 3abe95086ba16926d3517098fc6c1c7e2e72e432a94e06d15e34d121e82b0718 1731 adobe-flashplugin_11.2.202.238-0natty1.dsc 1e2e6db64eb81a7a566c30f50ff82e8e515255ae8810bdc6a9e313213379027c 5119 adobe-flashplugin_11.2.202.238-0natty1.diff.gz Files: ddcb8eb45746b4a85bc843a21a64cedb 1731 partner/web optional adobe-flashplugin_11.2.202.238-0natty1.dsc 3d6ad1b52853aeacaf80a87d7e7003e8 5119 partner/web optional adobe-flashplugin_11.2.202.238-0natty1.diff.gz From chris.coulson at canonical.com Wed Aug 15 17:06:15 2012 From: chris.coulson at canonical.com (Chris Coulson) Date: Wed, 15 Aug 2012 17:06:15 -0000 Subject: [ubuntu/natty-proposed] firefox 14.0.1+build1-0ubuntu0.11.04.3 (Accepted) Message-ID: <20120815170615.18008.21921.launchpad@gac.canonical.com> firefox (14.0.1+build1-0ubuntu0.11.04.3) natty-proposed; urgency=low * Update globalmenu-extension to 3.2.7 - Fix for LP: #1035305 - Crash when switching apps back to Firefox with Firebug installed firefox (14.0.1+build1-0ubuntu0.11.04.2) natty-proposed; urgency=low * Update globalmenu-extension to 3.2.6 - Partial fix for LP: #1025011 - HUD search crashes Firefox when Firebug is installed. Make all menu nodes reference counted, and hold a strong ref when dispatching events, in case the event results in the removal of the target node. This fixes the crash, although the Firebug submenus may flicker or display duplicated entries Date: Tue, 14 Aug 2012 21:03:58 +0100 Changed-By: Chris Coulson Maintainer: Ubuntu Mozilla Team https://launchpad.net/ubuntu/natty/+source/firefox/14.0.1+build1-0ubuntu0.11.04.3 -------------- next part -------------- Format: 1.8 Date: Tue, 14 Aug 2012 21:03:58 +0100 Source: firefox Binary: firefox firefox-gnome-support firefox-dbg firefox-dev firefox-mozsymbols firefox-globalmenu abrowser firefox-branding abrowser-branding firefox-gnome-support-dbg firefox-locale-af firefox-locale-ar firefox-locale-as firefox-locale-ast firefox-locale-be firefox-locale-bg firefox-locale-bn firefox-locale-br firefox-locale-bs firefox-locale-ca firefox-locale-cs firefox-locale-csb firefox-locale-cy firefox-locale-da firefox-locale-de firefox-locale-el firefox-locale-en firefox-locale-eo firefox-locale-es firefox-locale-et firefox-locale-eu firefox-locale-fa firefox-locale-fi firefox-locale-fr firefox-locale-fy firefox-locale-ga firefox-locale-gd firefox-locale-gl firefox-locale-gu firefox-locale-he firefox-locale-hi firefox-locale-hr firefox-locale-hu firefox-locale-hy firefox-locale-id firefox-locale-is firefox-locale-it firefox-locale-ja firefox-locale-ka firefox-locale-kk firefox-locale-km firefox-locale-kn firefox-locale-ko firefox-locale-ku firefox-locale-lg firefox-locale-lt firefox-locale-lv firefox-locale-mai firefox-locale-mk firefox-locale-ml firefox-locale-mn firefox-locale-mr firefox-locale-nb firefox-locale-nl firefox-locale-nn firefox-locale-nso firefox-locale-oc firefox-locale-or firefox-locale-pa firefox-locale-pl firefox-locale-pt firefox-locale-ro firefox-locale-ru firefox-locale-si firefox-locale-sk firefox-locale-sl firefox-locale-sq firefox-locale-sr firefox-locale-sv firefox-locale-sw firefox-locale-ta firefox-locale-te firefox-locale-th firefox-locale-tr firefox-locale-uk firefox-locale-vi firefox-locale-zh-hans firefox-locale-zh-hant firefox-locale-zu Architecture: source Version: 14.0.1+build1-0ubuntu0.11.04.3 Distribution: natty-proposed Urgency: low Maintainer: Ubuntu Mozilla Team Changed-By: Chris Coulson Description: abrowser - Safe and easy web browser from Mozilla - transitional package abrowser-branding - Safe and easy web browser from Mozilla - transitional package firefox - Safe and easy web browser from Mozilla firefox-branding - Safe and easy web browser from Mozilla - transitional package firefox-dbg - Safe and easy web browser from Mozilla - debug symbols firefox-dev - Safe and easy web browser from Mozilla - development files firefox-globalmenu - Unity appmenu integration for Firefox firefox-gnome-support - Safe and easy web browser from Mozilla - GNOME support firefox-gnome-support-dbg - Safe and easy web browser from Mozilla - transitional package firefox-locale-af - Afrikaans language pack for Firefox firefox-locale-ar - Arabic language pack for Firefox firefox-locale-as - Assamese language pack for Firefox firefox-locale-ast - Asturian language pack for Firefox firefox-locale-be - Belarusian language pack for Firefox firefox-locale-bg - Bulgarian language pack for Firefox firefox-locale-bn - Bengali language pack for Firefox firefox-locale-br - Breton language pack for Firefox firefox-locale-bs - Bosnian language pack for Firefox firefox-locale-ca - Catalan; Valencian language pack for Firefox firefox-locale-cs - Czech language pack for Firefox firefox-locale-csb - Kashubian language pack for Firefox firefox-locale-cy - Welsh language pack for Firefox firefox-locale-da - Danish language pack for Firefox firefox-locale-de - German language pack for Firefox firefox-locale-el - Greek language pack for Firefox firefox-locale-en - English language pack for Firefox firefox-locale-eo - Esperanto language pack for Firefox firefox-locale-es - Spanish; Castilian language pack for Firefox firefox-locale-et - Estonian language pack for Firefox firefox-locale-eu - Basque language pack for Firefox firefox-locale-fa - Persian language pack for Firefox firefox-locale-fi - Finnish language pack for Firefox firefox-locale-fr - French language pack for Firefox firefox-locale-fy - Western Frisian language pack for Firefox firefox-locale-ga - Irish language pack for Firefox firefox-locale-gd - Gaelic; Scottish Gaelic language pack for Firefox firefox-locale-gl - Galician language pack for Firefox firefox-locale-gu - Gujarati language pack for Firefox firefox-locale-he - Hebrew language pack for Firefox firefox-locale-hi - Hindi language pack for Firefox firefox-locale-hr - Croatian language pack for Firefox firefox-locale-hu - Hungarian language pack for Firefox firefox-locale-hy - Armenian language pack for Firefox firefox-locale-id - Indonesian language pack for Firefox firefox-locale-is - Icelandic language pack for Firefox firefox-locale-it - Italian language pack for Firefox firefox-locale-ja - Japanese language pack for Firefox firefox-locale-ka - Transitional package for unavailable language firefox-locale-kk - Kazakh language pack for Firefox firefox-locale-km - Central Khmer language pack for Firefox firefox-locale-kn - Kannada language pack for Firefox firefox-locale-ko - Korean language pack for Firefox firefox-locale-ku - Kurdish language pack for Firefox firefox-locale-lg - Ganda language pack for Firefox firefox-locale-lt - Lithuanian language pack for Firefox firefox-locale-lv - Latvian language pack for Firefox firefox-locale-mai - Maithili language pack for Firefox firefox-locale-mk - Macedonian language pack for Firefox firefox-locale-ml - Malayalam language pack for Firefox firefox-locale-mn - Transitional package for unavailable language firefox-locale-mr - Marathi language pack for Firefox firefox-locale-nb - Bokmål, Norwegian; Norwegian Bokmål language pack for Firefox firefox-locale-nl - Dutch; Flemish language pack for Firefox firefox-locale-nn - Norwegian Nynorsk; Nynorsk, Norwegian language pack for Firefox firefox-locale-nso - Sotho, Northern language pack for Firefox firefox-locale-oc - Transitional package for unavailable language firefox-locale-or - Oriya language pack for Firefox firefox-locale-pa - Panjabi; Punjabi language pack for Firefox firefox-locale-pl - Polish language pack for Firefox firefox-locale-pt - Portuguese language pack for Firefox firefox-locale-ro - Romanian language pack for Firefox firefox-locale-ru - Russian language pack for Firefox firefox-locale-si - Sinhala; Sinhalese language pack for Firefox firefox-locale-sk - Slovak language pack for Firefox firefox-locale-sl - Slovenian language pack for Firefox firefox-locale-sq - Albanian language pack for Firefox firefox-locale-sr - Serbian language pack for Firefox firefox-locale-sv - Swedish language pack for Firefox firefox-locale-sw - Transitional package for unavailable language firefox-locale-ta - Tamil language pack for Firefox firefox-locale-te - Telugu language pack for Firefox firefox-locale-th - Thai language pack for Firefox firefox-locale-tr - Turkish language pack for Firefox firefox-locale-uk - Ukrainian language pack for Firefox firefox-locale-vi - Vietnamese language pack for Firefox firefox-locale-zh-hans - Simplified Chinese language pack for Firefox firefox-locale-zh-hant - Traditional Chinese language pack for Firefox firefox-locale-zu - Zulu language pack for Firefox firefox-mozsymbols - Safe and easy web browser from Mozilla - Breakpad symbols Launchpad-Bugs-Fixed: 1025011 1035305 Changes: firefox (14.0.1+build1-0ubuntu0.11.04.3) natty-proposed; urgency=low . * Update globalmenu-extension to 3.2.7 - Fix for LP: #1035305 - Crash when switching apps back to Firefox with Firebug installed . firefox (14.0.1+build1-0ubuntu0.11.04.2) natty-proposed; urgency=low . * Update globalmenu-extension to 3.2.6 - Partial fix for LP: #1025011 - HUD search crashes Firefox when Firebug is installed. Make all menu nodes reference counted, and hold a strong ref when dispatching events, in case the event results in the removal of the target node. This fixes the crash, although the Firebug submenus may flicker or display duplicated entries Checksums-Sha1: 11878b4d1bec0923510d0dd4a1772570bc32b5ef 6903 firefox_14.0.1+build1-0ubuntu0.11.04.3.dsc a809912b2a08f24278bdc17c19f37118b3f16960 270327 firefox_14.0.1+build1-0ubuntu0.11.04.3.diff.gz Checksums-Sha256: 429b85f2341a74ab18e62a94eb22463b8a754100818ea92e63c3ecd99b8cafe7 6903 firefox_14.0.1+build1-0ubuntu0.11.04.3.dsc d803989d1aba01cd8d44a11be6e59aba6d0329ea4e23445ac64b70d3296bedb3 270327 firefox_14.0.1+build1-0ubuntu0.11.04.3.diff.gz Files: bb087232dc31f5250f2d26106d6df101 6903 web optional firefox_14.0.1+build1-0ubuntu0.11.04.3.dsc ba8e6c7998e0abae800ce5adb144a8ce 270327 web optional firefox_14.0.1+build1-0ubuntu0.11.04.3.diff.gz From marc.deslauriers at ubuntu.com Wed Aug 15 18:33:25 2012 From: marc.deslauriers at ubuntu.com (Marc Deslauriers) Date: Wed, 15 Aug 2012 18:33:25 -0000 Subject: [ubuntu/natty-security] flashplugin-nonfree, flashplugin-nonfree_11.2.202.238ubuntu0.11.04.1_i386_translations.tar.gz, flashplugin-nonfree_11.2.202.238ubuntu0.11.04.1_amd64_translations.tar.gz 11.2.202.238ubuntu0.11.04.1 (Accepted) Message-ID: <20120815183325.7667.2975.launchpad@cocoplum.canonical.com> flashplugin-nonfree (11.2.202.238ubuntu0.11.04.1) natty-security; urgency=low * New upstream release 11.2.202.238 - debian/{config,postinst.in}: Updated version and sha256sum. Date: Wed, 15 Aug 2012 10:53:14 -0400 Changed-By: Marc Deslauriers Maintainer: Ubuntu Developers https://launchpad.net/ubuntu/natty/+source/flashplugin-nonfree/11.2.202.238ubuntu0.11.04.1 -------------- next part -------------- Format: 1.8 Date: Wed, 15 Aug 2012 10:53:14 -0400 Source: flashplugin-nonfree Binary: flashplugin-installer flashplugin-nonfree Architecture: source Version: 11.2.202.238ubuntu0.11.04.1 Distribution: natty-security Urgency: low Maintainer: Ubuntu Developers Changed-By: Marc Deslauriers Description: flashplugin-installer - Adobe Flash Player plugin installer flashplugin-nonfree - Adobe Flash Player plugin installer (transitional package) Changes: flashplugin-nonfree (11.2.202.238ubuntu0.11.04.1) natty-security; urgency=low . * New upstream release 11.2.202.238 - debian/{config,postinst.in}: Updated version and sha256sum. Checksums-Sha1: df869c7bbcb5bb402031d70deedb97c21e5338fa 1649 flashplugin-nonfree_11.2.202.238ubuntu0.11.04.1.dsc df9702262be2d616f734176c1021a97d35cfb090 27562 flashplugin-nonfree_11.2.202.238ubuntu0.11.04.1.tar.gz Checksums-Sha256: 342d2d16593542cda5612139fa9bf6cb5c56b1a68a2286edfb8a3c7e40a8f915 1649 flashplugin-nonfree_11.2.202.238ubuntu0.11.04.1.dsc 079a80c5e0efb1d7df95b3692d242b3c9bfb0972ae2259bf18d2a3c224ef5f2a 27562 flashplugin-nonfree_11.2.202.238ubuntu0.11.04.1.tar.gz Files: 6518a8630acc4b5113e41f65976514ce 1649 contrib/web optional flashplugin-nonfree_11.2.202.238ubuntu0.11.04.1.dsc 6bb1c650df44a4973aa7312b334f4ba6 27562 contrib/web optional flashplugin-nonfree_11.2.202.238ubuntu0.11.04.1.tar.gz Original-Maintainer: Bart Martens From cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk Wed Aug 15 18:59:13 2012 From: cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk (Ubuntu Archive Robot) Date: Wed, 15 Aug 2012 18:59:13 -0000 Subject: [ubuntu/natty-updates] flashplugin-nonfree 11.2.202.238ubuntu0.11.04.1 (Accepted) Message-ID: <20120815185913.21147.21819.launchpad@ackee.canonical.com> flashplugin-nonfree (11.2.202.238ubuntu0.11.04.1) natty-security; urgency=low * New upstream release 11.2.202.238 - debian/{config,postinst.in}: Updated version and sha256sum. Date: 2012-08-15 15:10:48.825378+00:00 Changed-By: Marc Deslauriers Signed-By: Ubuntu Archive Robot https://launchpad.net/ubuntu/natty/+source/flashplugin-nonfree/11.2.202.238ubuntu0.11.04.1 -------------- next part -------------- Sorry, changesfile not available. From adconrad at ubuntu.com Wed Aug 15 19:42:45 2012 From: adconrad at ubuntu.com (Adam Conrad) Date: Wed, 15 Aug 2012 19:42:45 -0000 Subject: [ubuntu/natty-proposed] tzdata 2012e-0ubuntu0.11.04 (Accepted) Message-ID: <20120815194245.18770.78102.launchpad@gac.canonical.com> tzdata (2012e-0ubuntu0.11.04) natty-proposed; urgency=low * New upstream release 2012e: - Fixes timezone data for Port-au-Prince, Haiti (LP: #1031836) * Update debian/copyright and debian/watch for new upstream. Date: Tue, 14 Aug 2012 15:43:23 -0600 Changed-By: Adam Conrad Maintainer: Ubuntu Developers https://launchpad.net/ubuntu/natty/+source/tzdata/2012e-0ubuntu0.11.04 -------------- next part -------------- Format: 1.8 Date: Tue, 14 Aug 2012 15:43:23 -0600 Source: tzdata Binary: tzdata tzdata-java Architecture: source Version: 2012e-0ubuntu0.11.04 Distribution: natty-proposed Urgency: low Maintainer: Ubuntu Developers Changed-By: Adam Conrad Description: tzdata - time zone and daylight-saving time data tzdata-java - time zone and daylight-saving time data for use by java runtimes Launchpad-Bugs-Fixed: 1031836 Changes: tzdata (2012e-0ubuntu0.11.04) natty-proposed; urgency=low . * New upstream release 2012e: - Fixes timezone data for Port-au-Prince, Haiti (LP: #1031836) * Update debian/copyright and debian/watch for new upstream. Checksums-Sha1: f13cb76c4107d56023c8714b6e4c855c77ba3c40 1340 tzdata_2012e-0ubuntu0.11.04.dsc 8520206d8dc2a4188bd6e7a85f25cbb256b10d36 206251 tzdata_2012e.orig.tar.gz abb100e4e0ed53876f9b811ccf930597c70bfbae 252682 tzdata_2012e-0ubuntu0.11.04.debian.tar.gz Checksums-Sha256: 993e0f04bf0662241463f89cbff612a427350eaa90b186f6ac6d9c3dea8d9809 1340 tzdata_2012e-0ubuntu0.11.04.dsc 061c1c289e792f3661135d5ec542e4f9417d3cd7f232f3d54c1949573aadd0fc 206251 tzdata_2012e.orig.tar.gz a6ba1d89d3dd3a4aa90defdd6d480ea156aa217eb97602cb782db0b15d4f4926 252682 tzdata_2012e-0ubuntu0.11.04.debian.tar.gz Files: e9f3d345d489796d86b373820a2d059c 1340 libs required tzdata_2012e-0ubuntu0.11.04.dsc cb74e1f7bcc9a968a891a471e72e47b8 206251 libs required tzdata_2012e.orig.tar.gz 7d7819c86966b657669029295767a3f7 252682 libs required tzdata_2012e-0ubuntu0.11.04.debian.tar.gz Original-Maintainer: GNU Libc Maintainers From scott at kitterman.com Thu Aug 16 07:04:34 2012 From: scott at kitterman.com (Scott Kitterman) Date: Thu, 16 Aug 2012 07:04:34 -0000 Subject: [ubuntu/natty-security] clamav_0.97.5+dfsg-1ubuntu0.11.04.3_powerpc_translations.tar.gz, clamav_0.97.5+dfsg-1ubuntu0.11.04.3_armel_translations.tar.gz, clamav, clamav_0.97.5+dfsg-1ubuntu0.11.04.3_i386_translations.tar.gz, clamav_0.97.5+dfsg-1ubuntu0.11.04.3_amd64_translations.tar.gz 0.97.5+dfsg-1ubuntu0.11.04.3 (Accepted) Message-ID: <20120816070434.6204.2616.launchpad@cocoplum.canonical.com> clamav (0.97.5+dfsg-1ubuntu0.11.04.3) natty-security; urgency=low * SECURITY REGRESSION: Fix scanning failure. (LP: #1015405) - Upstream commit 6a879ad98460303b23a6fc119769a3b463a902f8 to fix unpack errors for various compressed files including some .bz2, .xls, .doc, and PDF Date: Tue, 14 Aug 2012 22:07:10 -0400 Changed-By: Scott Kitterman Maintainer: Ubuntu Developers https://launchpad.net/ubuntu/natty/+source/clamav/0.97.5+dfsg-1ubuntu0.11.04.3 -------------- next part -------------- Format: 1.8 Date: Tue, 14 Aug 2012 22:07:10 -0400 Source: clamav Binary: clamav-base clamav-docs clamav-dbg clamav libclamav-dev libclamav6 clamav-daemon clamav-testfiles clamav-freshclam clamav-milter Architecture: source Version: 0.97.5+dfsg-1ubuntu0.11.04.3 Distribution: natty-security Urgency: low Maintainer: Ubuntu Developers Changed-By: Scott Kitterman Description: clamav - anti-virus utility for Unix - command-line interface clamav-base - anti-virus utility for Unix - base package clamav-daemon - anti-virus utility for Unix - scanner daemon clamav-dbg - debug symbols for ClamAV clamav-docs - anti-virus utility for Unix - documentation clamav-freshclam - anti-virus utility for Unix - virus database update utility clamav-milter - anti-virus utility for Unix - sendmail integration clamav-testfiles - anti-virus utility for Unix - test files libclamav-dev - anti-virus utility for Unix - development files libclamav6 - anti-virus utility for Unix - library Launchpad-Bugs-Fixed: 1015405 Changes: clamav (0.97.5+dfsg-1ubuntu0.11.04.3) natty-security; urgency=low . * SECURITY REGRESSION: Fix scanning failure. (LP: #1015405) - Upstream commit 6a879ad98460303b23a6fc119769a3b463a902f8 to fix unpack errors for various compressed files including some .bz2, .xls, .doc, and PDF Checksums-Sha1: 08aca38f4d83180214af86cd932774ba16546c5a 2354 clamav_0.97.5+dfsg-1ubuntu0.11.04.3.dsc 3db3c93d6fc0f58996bc9745101b81e8201d3824 305763 clamav_0.97.5+dfsg-1ubuntu0.11.04.3.diff.gz Checksums-Sha256: 42e9ee8ed843a7c1954d7d50b20e5883f3eb9efacd09bbf038faedd4882a1b17 2354 clamav_0.97.5+dfsg-1ubuntu0.11.04.3.dsc 19449b7afc22d3a012e5aa3259bbf64d93c0c23c4d08402d23ce43ecf3ea8679 305763 clamav_0.97.5+dfsg-1ubuntu0.11.04.3.diff.gz Files: a8de1fca4627b3a504273118c5b7548d 2354 utils optional clamav_0.97.5+dfsg-1ubuntu0.11.04.3.dsc d60f13fe222976c9f5d08371a5745622 305763 utils optional clamav_0.97.5+dfsg-1ubuntu0.11.04.3.diff.gz Original-Maintainer: ClamAV Team From cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk Thu Aug 16 08:29:35 2012 From: cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk (Ubuntu Archive Robot) Date: Thu, 16 Aug 2012 08:29:35 -0000 Subject: [ubuntu/natty-updates] clamav 0.97.5+dfsg-1ubuntu0.11.04.3 (Accepted) Message-ID: <20120816082935.26015.45131.launchpad@ackee.canonical.com> clamav (0.97.5+dfsg-1ubuntu0.11.04.3) natty-security; urgency=low * SECURITY REGRESSION: Fix scanning failure. (LP: #1015405) - Upstream commit 6a879ad98460303b23a6fc119769a3b463a902f8 to fix unpack errors for various compressed files including some .bz2, .xls, .doc, and PDF Date: 2012-08-16 00:31:12.136048+00:00 Changed-By: Scott Kitterman Signed-By: Ubuntu Archive Robot https://launchpad.net/ubuntu/natty/+source/clamav/0.97.5+dfsg-1ubuntu0.11.04.3 -------------- next part -------------- Sorry, changesfile not available. From marc.deslauriers at canonical.com Thu Aug 16 14:49:14 2012 From: marc.deslauriers at canonical.com (Marc Deslauriers) Date: Thu, 16 Aug 2012 14:49:14 -0000 Subject: [ubuntu/natty-security] nss 3.12.9+ckbi-1.82-0ubuntu2.2 (Accepted) Message-ID: <20120816144914.5821.78533.launchpad@ackee.canonical.com> nss (3.12.9+ckbi-1.82-0ubuntu2.2) natty-security; urgency=low * SECURITY UPDATE: denial of service in QuickDER decoder - debian/patches/CVE-2012-0441.patch: properly handle zero-length basic constraints and zero-length fields in nss/mozilla/security/nss/lib/softoken/legacydb/keydb.c, nss/mozilla/security/nss/lib/softoken/legacydb/lgcreate.c, nss/mozilla/security/nss/lib/softoken/legacydb/lowkey.c, nss/mozilla/security/nss/lib/softoken/legacydb/lowkeyti.h, nss/mozilla/security/nss/lib/util/quickder.c. - CVE-2012-0441 * debian/rules: added a workaround to get package built on more recent kernels. Date: 2012-07-30 18:46:16.774944+00:00 Changed-By: Marc Deslauriers https://launchpad.net/ubuntu/natty/+source/nss/3.12.9+ckbi-1.82-0ubuntu2.2 -------------- next part -------------- Sorry, changesfile not available. From cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk Thu Aug 16 16:29:13 2012 From: cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk (Ubuntu Archive Robot) Date: Thu, 16 Aug 2012 16:29:13 -0000 Subject: [ubuntu/natty-updates] nss 3.12.9+ckbi-1.82-0ubuntu2.2 (Accepted) Message-ID: <20120816162913.3074.11679.launchpad@ackee.canonical.com> nss (3.12.9+ckbi-1.82-0ubuntu2.2) natty-security; urgency=low * SECURITY UPDATE: denial of service in QuickDER decoder - debian/patches/CVE-2012-0441.patch: properly handle zero-length basic constraints and zero-length fields in nss/mozilla/security/nss/lib/softoken/legacydb/keydb.c, nss/mozilla/security/nss/lib/softoken/legacydb/lgcreate.c, nss/mozilla/security/nss/lib/softoken/legacydb/lowkey.c, nss/mozilla/security/nss/lib/softoken/legacydb/lowkeyti.h, nss/mozilla/security/nss/lib/util/quickder.c. - CVE-2012-0441 * debian/rules: added a workaround to get package built on more recent kernels. Date: 2012-07-30 18:46:16.774944+00:00 Changed-By: Marc Deslauriers Signed-By: Ubuntu Archive Robot https://launchpad.net/ubuntu/natty/+source/nss/3.12.9+ckbi-1.82-0ubuntu2.2 -------------- next part -------------- Sorry, changesfile not available. From sbeattie at ubuntu.com Thu Aug 16 18:30:21 2012 From: sbeattie at ubuntu.com (Steve Beattie) Date: Thu, 16 Aug 2012 18:30:21 -0000 Subject: [ubuntu/natty-security] libotr 3.2.0-2ubuntu1.1 (Accepted) Message-ID: <20120816183021.6307.31135.launchpad@ackee.canonical.com> libotr (3.2.0-2ubuntu1.1) natty-security; urgency=low * SECURITY UPDATE: multiple heap-based buffer overflows (LP: #1034623) - src/b64.c, src/b64.h, src/proto.c, toolkit/parse.c: apply upstream git commits b17232f86f8e60d0d22caf9a2400494d3c77da58, 6d4ca89cf1d3c9a8aff696c3a846ac5a51f762c1 and 1902baee5d4b056850274ed0fa8c2409f1187435 - CVE-2012-3461 Date: 2012-08-14 18:47:44.560624+00:00 Changed-By: Felix Geyer Signed-By: Steve Beattie https://launchpad.net/ubuntu/natty/+source/libotr/3.2.0-2ubuntu1.1 -------------- next part -------------- Sorry, changesfile not available. From cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk Thu Aug 16 18:58:13 2012 From: cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk (Ubuntu Archive Robot) Date: Thu, 16 Aug 2012 18:58:13 -0000 Subject: [ubuntu/natty-updates] libotr 3.2.0-2ubuntu1.1 (Accepted) Message-ID: <20120816185813.15151.83338.launchpad@ackee.canonical.com> libotr (3.2.0-2ubuntu1.1) natty-security; urgency=low * SECURITY UPDATE: multiple heap-based buffer overflows (LP: #1034623) - src/b64.c, src/b64.h, src/proto.c, toolkit/parse.c: apply upstream git commits b17232f86f8e60d0d22caf9a2400494d3c77da58, 6d4ca89cf1d3c9a8aff696c3a846ac5a51f762c1 and 1902baee5d4b056850274ed0fa8c2409f1187435 - CVE-2012-3461 Date: 2012-08-14 18:47:44.560624+00:00 Changed-By: Felix Geyer Signed-By: Ubuntu Archive Robot https://launchpad.net/ubuntu/natty/+source/libotr/3.2.0-2ubuntu1.1 -------------- next part -------------- Sorry, changesfile not available. From launchpad at micahscomputing.com Fri Aug 17 23:31:13 2012 From: launchpad at micahscomputing.com (Micah Gersten) Date: Fri, 17 Aug 2012 23:31:13 -0000 Subject: [ubuntu/natty-proposed] icedtea-web 1.2-2ubuntu0.11.04.3 (Accepted) Message-ID: <20120817233113.17771.81416.launchpad@ackee.canonical.com> icedtea-web (1.2-2ubuntu0.11.04.3) natty-security; urgency=low * debian/patches/fix-plugin-error-on-chromium.patch: fix plugin table initialization to check only that the subset of hooks that it uses exists. (LP: #1025553) Date: 2012-08-15 06:11:40.326390+00:00 Changed-By: Steve Beattie Signed-By: Micah Gersten https://launchpad.net/ubuntu/natty/+source/icedtea-web/1.2-2ubuntu0.11.04.3 -------------- next part -------------- Sorry, changesfile not available. From jamie at ubuntu.com Mon Aug 20 17:26:17 2012 From: jamie at ubuntu.com (Jamie Strandboge) Date: Mon, 20 Aug 2012 17:26:17 -0000 Subject: [ubuntu/natty-security] globus-gridftp-server 3.23-1ubuntu0.1 (Accepted) Message-ID: <20120820172617.17656.7615.launchpad@ackee.canonical.com> globus-gridftp-server (3.23-1ubuntu0.1) natty-security; urgency=low * SECURITY UPDATE: Wrong user mapping on badly configured server (LP: #1027324) - debian/patches/globus-gridftp-server-pw195.patch: backported from upstream - CVE-2012-3292 Date: 2012-08-03 00:30:33.501377+00:00 Changed-By: Mattias Ellert Signed-By: Jamie Strandboge https://launchpad.net/ubuntu/natty/+source/globus-gridftp-server/3.23-1ubuntu0.1 -------------- next part -------------- Sorry, changesfile not available. From brad.figg at canonical.com Mon Aug 20 17:27:30 2012 From: brad.figg at canonical.com (Brad Figg) Date: Mon, 20 Aug 2012 17:27:30 -0000 Subject: [ubuntu/natty-proposed] linux 2.6.38-15.66 (Accepted) Message-ID: <20120820172730.17946.24857.launchpad@ackee.canonical.com> linux (2.6.38-15.66) natty-proposed; urgency=low [Luis Henriques] * Release Tracking Bug - LP: #1036250 [ Upstream Kernel Changes ] * udf: Fortify loading of sparing table - LP: #1024497 - CVE-2012-3400 * udf: Avoid run away loop when partition table length is corrupted - LP: #1024497 - CVE-2012-3400 * eCryptfs: Gracefully refuse miscdev file ops on inherited/passed files * eCryptfs: Copy up POSIX ACL and read-only flags from lower mount - LP: #1009207 Date: 2012-08-14 17:22:07.841567+00:00 Changed-By: Luis Henriques Signed-By: Brad Figg https://launchpad.net/ubuntu/natty/+source/linux/2.6.38-15.66 -------------- next part -------------- Sorry, changesfile not available. From jamie at ubuntu.com Mon Aug 20 17:42:24 2012 From: jamie at ubuntu.com (Jamie Strandboge) Date: Mon, 20 Aug 2012 17:42:24 -0000 Subject: [ubuntu/natty-security] globus-gridftp-server-control 0.43-1ubuntu0.1 (Accepted) Message-ID: <20120820174224.23546.21863.launchpad@ackee.canonical.com> globus-gridftp-server-control (0.43-1ubuntu0.1) natty-security; urgency=low * SECURITY UPDATE: Wrong user mapping on badly configured server (LP: #1027323) - debian/patches/globus-gridftp-server-control-pw195.patch: backported from upstream - CVE-2012-3292 Date: 2012-08-03 00:35:31.812431+00:00 Changed-By: Mattias Ellert Signed-By: Jamie Strandboge https://launchpad.net/ubuntu/natty/+source/globus-gridftp-server-control/0.43-1ubuntu0.1 -------------- next part -------------- Sorry, changesfile not available. From cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk Mon Aug 20 17:58:15 2012 From: cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk (Ubuntu Archive Robot) Date: Mon, 20 Aug 2012 17:58:15 -0000 Subject: [ubuntu/natty-updates] globus-gridftp-server 3.23-1ubuntu0.1 (Accepted) Message-ID: <20120820175815.28947.72441.launchpad@ackee.canonical.com> globus-gridftp-server (3.23-1ubuntu0.1) natty-security; urgency=low * SECURITY UPDATE: Wrong user mapping on badly configured server (LP: #1027324) - debian/patches/globus-gridftp-server-pw195.patch: backported from upstream - CVE-2012-3292 Date: 2012-08-03 00:30:33.501377+00:00 Changed-By: Mattias Ellert Signed-By: Ubuntu Archive Robot https://launchpad.net/ubuntu/natty/+source/globus-gridftp-server/3.23-1ubuntu0.1 -------------- next part -------------- Sorry, changesfile not available. From cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk Mon Aug 20 18:58:12 2012 From: cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk (Ubuntu Archive Robot) Date: Mon, 20 Aug 2012 18:58:12 -0000 Subject: [ubuntu/natty-updates] globus-gridftp-server-control 0.43-1ubuntu0.1 (Accepted) Message-ID: <20120820185812.17572.83477.launchpad@ackee.canonical.com> globus-gridftp-server-control (0.43-1ubuntu0.1) natty-security; urgency=low * SECURITY UPDATE: Wrong user mapping on badly configured server (LP: #1027323) - debian/patches/globus-gridftp-server-control-pw195.patch: backported from upstream - CVE-2012-3292 Date: 2012-08-03 00:35:31.812431+00:00 Changed-By: Mattias Ellert Signed-By: Ubuntu Archive Robot https://launchpad.net/ubuntu/natty/+source/globus-gridftp-server-control/0.43-1ubuntu0.1 -------------- next part -------------- Sorry, changesfile not available. From jamie at ubuntu.com Mon Aug 20 21:25:36 2012 From: jamie at ubuntu.com (Jamie Strandboge) Date: Mon, 20 Aug 2012 21:25:36 -0000 Subject: [ubuntu/natty-security] postgresql-8.4 8.4.13-0ubuntu11.04 (Accepted) Message-ID: <20120820212536.2171.76902.launchpad@ackee.canonical.com> postgresql-8.4 (8.4.13-0ubuntu11.04) natty-security; urgency=low * New upstream security/bug fix release: - Prevent access to external files/URLs via XML entity references (Noah Misch, Tom Lane) xml_parse() would attempt to fetch external files or URLs as needed to resolve DTD and entity references in an XML value, thus allowing unprivileged database users to attempt to fetch data with the privileges of the database server. While the external data wouldn't get returned directly to the user, portions of it could be exposed in error messages if the data didn't parse as valid XML; and in any case the mere ability to check existence of a file might be useful to an attacker. (CVE-2012-3489) - Prevent access to external files/URLs via "contrib/xml2"'s xslt_process() (Peter Eisentraut) libxslt offers the ability to read and write both files and URLs through stylesheet commands, thus allowing unprivileged database users to both read and write data with the privileges of the database server. Disable that through proper use of libxslt's security options. (CVE-2012-3488) Also, remove xslt_process()'s ability to fetch documents and stylesheets from external files/URLs. While this was a documented "feature", it was long regarded as a bad idea. The fix for CVE-2012-3489 broke that capability, and rather than expend effort on trying to fix it, we're just going to summarily remove it. - Prevent too-early recycling of btree index pages (Noah Misch) When we allowed read-only transactions to skip assigning XIDs, we introduced the possibility that a deleted btree page could be recycled while a read-only transaction was still in flight to it. This would result in incorrect index search results. The probability of such an error occurring in the field seems very low because of the timing requirements, but nonetheless it should be fixed. - Fix crash-safety bug with newly-created-or-reset sequences (Tom Lane) If "ALTER SEQUENCE" was executed on a freshly created or reset sequence, and then precisely one nextval() call was made on it, and then the server crashed, WAL replay would restore the sequence to a state in which it appeared that no nextval() had been done, thus allowing the first sequence value to be returned again by the next nextval() call. In particular this could manifest for serial columns, since creation of a serial column's sequence includes an "ALTER SEQUENCE OWNED BY" step. - Ensure the "backup_label" file is fsync'd after pg_start_backup() (Dave Kerr) - Back-patch 9.1 improvement to compress the fsync request queue (Robert Haas) This improves performance during checkpoints. The 9.1 change has now seen enough field testing to seem safe to back-patch. - Only allow autovacuum to be auto-canceled by a directly blocked process (Tom Lane) The original coding could allow inconsistent behavior in some cases; in particular, an autovacuum could get canceled after less than deadlock_timeout grace period. - Improve logging of autovacuum cancels (Robert Haas) - Fix log collector so that log_truncate_on_rotation works during the very first log rotation after server start (Tom Lane) - Fix WITH attached to a nested set operation (UNION/INTERSECT/EXCEPT) (Tom Lane) - Ensure that a whole-row reference to a subquery doesn't include any extra GROUP BY or ORDER BY columns (Tom Lane) - Disallow copying whole-row references in CHECK constraints and index definitions during "CREATE TABLE" (Tom Lane) This situation can arise in "CREATE TABLE" with LIKE or INHERITS. The copied whole-row variable was incorrectly labeled with the row type of the original table not the new one. Rejecting the case seems reasonable for LIKE, since the row types might well diverge later. For INHERITS we should ideally allow it, with an implicit coercion to the parent table's row type; but that will require more work than seems safe to back-patch. - Fix memory leak in ARRAY(SELECT ...) subqueries (Heikki Linnakangas, Tom Lane) - Fix extraction of common prefixes from regular expressions (Tom Lane) The code could get confused by quantified parenthesized subexpressions, such as ^(foo)?bar. This would lead to incorrect index optimization of searches for such patterns. - Fix bugs with parsing signed "hh":"mm" and "hh":"mm":"ss" fields in interval constants (Amit Kapila, Tom Lane) - Report errors properly in "contrib/xml2"'s xslt_process() (Tom Lane) - Update time zone data files to tzdata release 2012e for DST law changes in Morocco and Tokelau Date: 2012-08-16 23:01:22.608264+00:00 Changed-By: Jamie Strandboge https://launchpad.net/ubuntu/natty/+source/postgresql-8.4/8.4.13-0ubuntu11.04 -------------- next part -------------- Sorry, changesfile not available. From jamie at ubuntu.com Mon Aug 20 21:50:29 2012 From: jamie at ubuntu.com (Jamie Strandboge) Date: Mon, 20 Aug 2012 21:50:29 -0000 Subject: [ubuntu/natty-security] libconfig-inifiles-perl 2.58-1ubuntu0.1 (Accepted) Message-ID: <20120820215029.10038.17456.launchpad@ackee.canonical.com> libconfig-inifiles-perl (2.58-1ubuntu0.1) natty-security; urgency=low * SECURITY UPDATE: insecure temporary file usage - debian/patches/CVE-2012-2451.patch: adjust to use tempfile() - CVE-2012-2451 Date: 2012-08-17 13:50:37.775907+00:00 Changed-By: Jamie Strandboge https://launchpad.net/ubuntu/natty/+source/libconfig-inifiles-perl/2.58-1ubuntu0.1 -------------- next part -------------- Sorry, changesfile not available. From cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk Mon Aug 20 21:59:58 2012 From: cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk (Ubuntu Archive Robot) Date: Mon, 20 Aug 2012 21:59:58 -0000 Subject: [ubuntu/natty-updates] postgresql-8.4 8.4.13-0ubuntu11.04 (Accepted) Message-ID: <20120820215958.13214.9333.launchpad@ackee.canonical.com> postgresql-8.4 (8.4.13-0ubuntu11.04) natty-security; urgency=low * New upstream security/bug fix release: - Prevent access to external files/URLs via XML entity references (Noah Misch, Tom Lane) xml_parse() would attempt to fetch external files or URLs as needed to resolve DTD and entity references in an XML value, thus allowing unprivileged database users to attempt to fetch data with the privileges of the database server. While the external data wouldn't get returned directly to the user, portions of it could be exposed in error messages if the data didn't parse as valid XML; and in any case the mere ability to check existence of a file might be useful to an attacker. (CVE-2012-3489) - Prevent access to external files/URLs via "contrib/xml2"'s xslt_process() (Peter Eisentraut) libxslt offers the ability to read and write both files and URLs through stylesheet commands, thus allowing unprivileged database users to both read and write data with the privileges of the database server. Disable that through proper use of libxslt's security options. (CVE-2012-3488) Also, remove xslt_process()'s ability to fetch documents and stylesheets from external files/URLs. While this was a documented "feature", it was long regarded as a bad idea. The fix for CVE-2012-3489 broke that capability, and rather than expend effort on trying to fix it, we're just going to summarily remove it. - Prevent too-early recycling of btree index pages (Noah Misch) When we allowed read-only transactions to skip assigning XIDs, we introduced the possibility that a deleted btree page could be recycled while a read-only transaction was still in flight to it. This would result in incorrect index search results. The probability of such an error occurring in the field seems very low because of the timing requirements, but nonetheless it should be fixed. - Fix crash-safety bug with newly-created-or-reset sequences (Tom Lane) If "ALTER SEQUENCE" was executed on a freshly created or reset sequence, and then precisely one nextval() call was made on it, and then the server crashed, WAL replay would restore the sequence to a state in which it appeared that no nextval() had been done, thus allowing the first sequence value to be returned again by the next nextval() call. In particular this could manifest for serial columns, since creation of a serial column's sequence includes an "ALTER SEQUENCE OWNED BY" step. - Ensure the "backup_label" file is fsync'd after pg_start_backup() (Dave Kerr) - Back-patch 9.1 improvement to compress the fsync request queue (Robert Haas) This improves performance during checkpoints. The 9.1 change has now seen enough field testing to seem safe to back-patch. - Only allow autovacuum to be auto-canceled by a directly blocked process (Tom Lane) The original coding could allow inconsistent behavior in some cases; in particular, an autovacuum could get canceled after less than deadlock_timeout grace period. - Improve logging of autovacuum cancels (Robert Haas) - Fix log collector so that log_truncate_on_rotation works during the very first log rotation after server start (Tom Lane) - Fix WITH attached to a nested set operation (UNION/INTERSECT/EXCEPT) (Tom Lane) - Ensure that a whole-row reference to a subquery doesn't include any extra GROUP BY or ORDER BY columns (Tom Lane) - Disallow copying whole-row references in CHECK constraints and index definitions during "CREATE TABLE" (Tom Lane) This situation can arise in "CREATE TABLE" with LIKE or INHERITS. The copied whole-row variable was incorrectly labeled with the row type of the original table not the new one. Rejecting the case seems reasonable for LIKE, since the row types might well diverge later. For INHERITS we should ideally allow it, with an implicit coercion to the parent table's row type; but that will require more work than seems safe to back-patch. - Fix memory leak in ARRAY(SELECT ...) subqueries (Heikki Linnakangas, Tom Lane) - Fix extraction of common prefixes from regular expressions (Tom Lane) The code could get confused by quantified parenthesized subexpressions, such as ^(foo)?bar. This would lead to incorrect index optimization of searches for such patterns. - Fix bugs with parsing signed "hh":"mm" and "hh":"mm":"ss" fields in interval constants (Amit Kapila, Tom Lane) - Report errors properly in "contrib/xml2"'s xslt_process() (Tom Lane) - Update time zone data files to tzdata release 2012e for DST law changes in Morocco and Tokelau Date: 2012-08-16 23:01:22.608264+00:00 Changed-By: Jamie Strandboge Signed-By: Ubuntu Archive Robot https://launchpad.net/ubuntu/natty/+source/postgresql-8.4/8.4.13-0ubuntu11.04 -------------- next part -------------- Sorry, changesfile not available. From cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk Mon Aug 20 22:59:14 2012 From: cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk (Ubuntu Archive Robot) Date: Mon, 20 Aug 2012 22:59:14 -0000 Subject: [ubuntu/natty-updates] libconfig-inifiles-perl 2.58-1ubuntu0.1 (Accepted) Message-ID: <20120820225914.31652.30041.launchpad@ackee.canonical.com> libconfig-inifiles-perl (2.58-1ubuntu0.1) natty-security; urgency=low * SECURITY UPDATE: insecure temporary file usage - debian/patches/CVE-2012-2451.patch: adjust to use tempfile() - CVE-2012-2451 Date: 2012-08-17 13:50:37.775907+00:00 Changed-By: Jamie Strandboge Signed-By: Ubuntu Archive Robot https://launchpad.net/ubuntu/natty/+source/libconfig-inifiles-perl/2.58-1ubuntu0.1 -------------- next part -------------- Sorry, changesfile not available. From jamie at ubuntu.com Tue Aug 21 14:38:15 2012 From: jamie at ubuntu.com (Jamie Strandboge) Date: Tue, 21 Aug 2012 14:38:15 -0000 Subject: [ubuntu/natty-proposed] gnupg 1.4.11-3ubuntu1.11.04.1 (Accepted) Message-ID: <20120821143815.30967.98050.launchpad@ackee.canonical.com> gnupg (1.4.11-3ubuntu1.11.04.1) natty-security; urgency=low * debian/patches/long-keyids.dpatch: Use the longest key ID available when requesting a key from a key server. Date: 2012-08-14 14:21:54.079826+00:00 Changed-By: Marc Deslauriers Signed-By: Jamie Strandboge https://launchpad.net/ubuntu/natty/+source/gnupg/1.4.11-3ubuntu1.11.04.1 -------------- next part -------------- Sorry, changesfile not available. From jamie at ubuntu.com Tue Aug 21 14:38:19 2012 From: jamie at ubuntu.com (Jamie Strandboge) Date: Tue, 21 Aug 2012 14:38:19 -0000 Subject: [ubuntu/natty-proposed] gnupg2 2.0.14-2ubuntu1.2 (Accepted) Message-ID: <20120821143819.30967.29132.launchpad@ackee.canonical.com> gnupg2 (2.0.14-2ubuntu1.2) natty-security; urgency=low * debian/patches/long-keyids.diff: Use the longest key ID available when requesting a key from a key server. Date: 2012-08-14 19:21:22.082317+00:00 Changed-By: Marc Deslauriers Signed-By: Jamie Strandboge https://launchpad.net/ubuntu/natty/+source/gnupg2/2.0.14-2ubuntu1.2 -------------- next part -------------- Sorry, changesfile not available. From jamie at ubuntu.com Wed Aug 22 14:53:21 2012 From: jamie at ubuntu.com (Jamie Strandboge) Date: Wed, 22 Aug 2012 14:53:21 -0000 Subject: [ubuntu/natty-security] imagemagick 7:6.6.2.6-1ubuntu4.2 (Accepted) Message-ID: <20120822145321.13018.42607.launchpad@ackee.canonical.com> imagemagick (7:6.6.2.6-1ubuntu4.2) natty-security; urgency=low * SECURITY UPDATE: denial of service via large resource consumption - debian/patches/CVE-2012-3437.patch: always use correct size argument with libpng memory allocation - CVE-2012-3437 Date: 2012-08-17 16:46:07.771935+00:00 Changed-By: Jamie Strandboge https://launchpad.net/ubuntu/natty/+source/imagemagick/7:6.6.2.6-1ubuntu4.2 -------------- next part -------------- Sorry, changesfile not available. From cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk Wed Aug 22 15:29:15 2012 From: cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk (Ubuntu Archive Robot) Date: Wed, 22 Aug 2012 15:29:15 -0000 Subject: [ubuntu/natty-updates] imagemagick 7:6.6.2.6-1ubuntu4.2 (Accepted) Message-ID: <20120822152915.23827.11416.launchpad@ackee.canonical.com> imagemagick (7:6.6.2.6-1ubuntu4.2) natty-security; urgency=low * SECURITY UPDATE: denial of service via large resource consumption - debian/patches/CVE-2012-3437.patch: always use correct size argument with libpng memory allocation - CVE-2012-3437 Date: 2012-08-17 16:46:07.771935+00:00 Changed-By: Jamie Strandboge Signed-By: Ubuntu Archive Robot https://launchpad.net/ubuntu/natty/+source/imagemagick/7:6.6.2.6-1ubuntu4.2 -------------- next part -------------- Sorry, changesfile not available. From jamie at ubuntu.com Wed Aug 22 16:21:11 2012 From: jamie at ubuntu.com (Jamie Strandboge) Date: Wed, 22 Aug 2012 16:21:11 -0000 Subject: [ubuntu/natty-security] extplorer 2.1.0b6+dfsg.2-1build0.11.04.1 (Accepted) Message-ID: <20120822162111.6748.62691.launchpad@ackee.canonical.com> extplorer (2.1.0b6+dfsg.2-1build0.11.04.1) natty-security; urgency=low * fake sync from Debian Date: 2012-08-21 17:20:26.279265+00:00 Changed-By: Jamie Strandboge https://launchpad.net/ubuntu/natty/+source/extplorer/2.1.0b6+dfsg.2-1build0.11.04.1 -------------- next part -------------- Sorry, changesfile not available. From jamie at ubuntu.com Wed Aug 22 16:21:12 2012 From: jamie at ubuntu.com (Jamie Strandboge) Date: Wed, 22 Aug 2012 16:21:12 -0000 Subject: [ubuntu/natty-security] fckeditor 1:2.6.6-1build0.11.04.1 (Accepted) Message-ID: <20120822162112.6748.55332.launchpad@ackee.canonical.com> fckeditor (1:2.6.6-1build0.11.04.1) natty-security; urgency=low * fake sync from Debian Date: 2012-08-21 17:20:19.564566+00:00 Changed-By: Jamie Strandboge Maintainer: lordlamer https://launchpad.net/ubuntu/natty/+source/fckeditor/1:2.6.6-1build0.11.04.1 -------------- next part -------------- Sorry, changesfile not available. From jamie at ubuntu.com Wed Aug 22 16:21:14 2012 From: jamie at ubuntu.com (Jamie Strandboge) Date: Wed, 22 Aug 2012 16:21:14 -0000 Subject: [ubuntu/natty-security] rssh 2.3.2-13build0.11.04.1 (Accepted) Message-ID: <20120822162114.6748.70644.launchpad@ackee.canonical.com> rssh (2.3.2-13build0.11.04.1) natty-security; urgency=low * fake sync from Debian Date: 2012-08-21 17:20:20.961659+00:00 Changed-By: Jamie Strandboge Maintainer: Russ Allbery https://launchpad.net/ubuntu/natty/+source/rssh/2.3.2-13build0.11.04.1 -------------- next part -------------- Sorry, changesfile not available. From cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk Wed Aug 22 16:58:11 2012 From: cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk (Ubuntu Archive Robot) Date: Wed, 22 Aug 2012 16:58:11 -0000 Subject: [ubuntu/natty-updates] extplorer 2.1.0b6+dfsg.2-1build0.11.04.1 (Accepted) Message-ID: <20120822165811.17345.94755.launchpad@ackee.canonical.com> extplorer (2.1.0b6+dfsg.2-1build0.11.04.1) natty-security; urgency=low * fake sync from Debian Date: 2012-08-21 17:20:26.279265+00:00 Changed-By: Jamie Strandboge Signed-By: Ubuntu Archive Robot https://launchpad.net/ubuntu/natty/+source/extplorer/2.1.0b6+dfsg.2-1build0.11.04.1 -------------- next part -------------- Sorry, changesfile not available. From cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk Wed Aug 22 16:58:12 2012 From: cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk (Ubuntu Archive Robot) Date: Wed, 22 Aug 2012 16:58:12 -0000 Subject: [ubuntu/natty-updates] fckeditor 1:2.6.6-1build0.11.04.1 (Accepted) Message-ID: <20120822165812.17345.88495.launchpad@ackee.canonical.com> fckeditor (1:2.6.6-1build0.11.04.1) natty-security; urgency=low * fake sync from Debian Date: 2012-08-21 17:20:19.564566+00:00 Changed-By: Jamie Strandboge Maintainer: lordlamer Signed-By: Ubuntu Archive Robot https://launchpad.net/ubuntu/natty/+source/fckeditor/1:2.6.6-1build0.11.04.1 -------------- next part -------------- Sorry, changesfile not available. From cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk Wed Aug 22 16:58:13 2012 From: cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk (Ubuntu Archive Robot) Date: Wed, 22 Aug 2012 16:58:13 -0000 Subject: [ubuntu/natty-updates] rssh 2.3.2-13build0.11.04.1 (Accepted) Message-ID: <20120822165813.17345.88210.launchpad@ackee.canonical.com> rssh (2.3.2-13build0.11.04.1) natty-security; urgency=low * fake sync from Debian Date: 2012-08-21 17:20:20.961659+00:00 Changed-By: Jamie Strandboge Maintainer: Russ Allbery Signed-By: Ubuntu Archive Robot https://launchpad.net/ubuntu/natty/+source/rssh/2.3.2-13build0.11.04.1 -------------- next part -------------- Sorry, changesfile not available. From jamie at ubuntu.com Wed Aug 22 19:36:11 2012 From: jamie at ubuntu.com (Jamie Strandboge) Date: Wed, 22 Aug 2012 19:36:11 -0000 Subject: [ubuntu/natty-security] rssh 2.3.2-13squeeze1build0.11.04.1 (Accepted) Message-ID: <20120822193611.31099.5388.launchpad@ackee.canonical.com> rssh (2.3.2-13squeeze1build0.11.04.1) natty-security; urgency=low * fake sync from Debian rssh (2.3.2-13squeeze1) stable-security; urgency=high * Apply upstream patch to close security vulnerability that permitted clever manipulation of environment variables on the ssh command line to bypass rssh checking. (CVE-2012-3478) Date: 2012-08-22 16:30:14.758848+00:00 Changed-By: Jamie Strandboge Maintainer: Russ Allbery https://launchpad.net/ubuntu/natty/+source/rssh/2.3.2-13squeeze1build0.11.04.1 -------------- next part -------------- Sorry, changesfile not available. From jamie at ubuntu.com Wed Aug 22 19:36:12 2012 From: jamie at ubuntu.com (Jamie Strandboge) Date: Wed, 22 Aug 2012 19:36:12 -0000 Subject: [ubuntu/natty-security] extplorer 2.1.0b6+dfsg.2-1+squeeze1build0.11.04.1 (Accepted) Message-ID: <20120822193612.31099.39502.launchpad@ackee.canonical.com> extplorer (2.1.0b6+dfsg.2-1+squeeze1build0.11.04.1) natty-security; urgency=low * fake sync from Debian extplorer (2.1.0b6+dfsg.2-1+squeeze1) stable-security; urgency=low * CVE-2012-3362: fixes a CSRF (Closes: #678737). Date: 2012-08-22 16:40:14.434988+00:00 Changed-By: Jamie Strandboge https://launchpad.net/ubuntu/natty/+source/extplorer/2.1.0b6+dfsg.2-1+squeeze1build0.11.04.1 -------------- next part -------------- Sorry, changesfile not available. From jamie at ubuntu.com Wed Aug 22 19:36:13 2012 From: jamie at ubuntu.com (Jamie Strandboge) Date: Wed, 22 Aug 2012 19:36:13 -0000 Subject: [ubuntu/natty-security] fckeditor 1:2.6.6-1squeeze1build0.11.04.1 (Accepted) Message-ID: <20120822193613.31099.80847.launchpad@ackee.canonical.com> fckeditor (1:2.6.6-1squeeze1build0.11.04.1) natty-security; urgency=low * fake sync from Debian fckeditor (1:2.6.6-1squeeze1) squeeze-security; urgency=high * fixed XSS vulnerability in spellchecker (Closes: #683418) [CVE-2012-4000] Date: 2012-08-22 16:30:17.431375+00:00 Changed-By: Jamie Strandboge Maintainer: lordlamer https://launchpad.net/ubuntu/natty/+source/fckeditor/1:2.6.6-1squeeze1build0.11.04.1 -------------- next part -------------- Sorry, changesfile not available. From cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk Thu Aug 23 11:59:15 2012 From: cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk (Ubuntu Archive Robot) Date: Thu, 23 Aug 2012 11:59:15 -0000 Subject: [ubuntu/natty-updates] extplorer 2.1.0b6+dfsg.2-1+squeeze1build0.11.04.1 (Accepted) Message-ID: <20120823115915.29966.85623.launchpad@ackee.canonical.com> extplorer (2.1.0b6+dfsg.2-1+squeeze1build0.11.04.1) natty-security; urgency=low * fake sync from Debian extplorer (2.1.0b6+dfsg.2-1+squeeze1) stable-security; urgency=low * CVE-2012-3362: fixes a CSRF (Closes: #678737). Date: 2012-08-22 16:40:14.434988+00:00 Changed-By: Jamie Strandboge Signed-By: Ubuntu Archive Robot https://launchpad.net/ubuntu/natty/+source/extplorer/2.1.0b6+dfsg.2-1+squeeze1build0.11.04.1 -------------- next part -------------- Sorry, changesfile not available. From cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk Thu Aug 23 11:59:16 2012 From: cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk (Ubuntu Archive Robot) Date: Thu, 23 Aug 2012 11:59:16 -0000 Subject: [ubuntu/natty-updates] fckeditor 1:2.6.6-1squeeze1build0.11.04.1 (Accepted) Message-ID: <20120823115916.29966.9961.launchpad@ackee.canonical.com> fckeditor (1:2.6.6-1squeeze1build0.11.04.1) natty-security; urgency=low * fake sync from Debian fckeditor (1:2.6.6-1squeeze1) squeeze-security; urgency=high * fixed XSS vulnerability in spellchecker (Closes: #683418) [CVE-2012-4000] Date: 2012-08-22 16:30:17.431375+00:00 Changed-By: Jamie Strandboge Maintainer: lordlamer Signed-By: Ubuntu Archive Robot https://launchpad.net/ubuntu/natty/+source/fckeditor/1:2.6.6-1squeeze1build0.11.04.1 -------------- next part -------------- Sorry, changesfile not available. From cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk Thu Aug 23 11:59:17 2012 From: cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk (Ubuntu Archive Robot) Date: Thu, 23 Aug 2012 11:59:17 -0000 Subject: [ubuntu/natty-updates] rssh 2.3.2-13squeeze1build0.11.04.1 (Accepted) Message-ID: <20120823115917.29966.37662.launchpad@ackee.canonical.com> rssh (2.3.2-13squeeze1build0.11.04.1) natty-security; urgency=low * fake sync from Debian rssh (2.3.2-13squeeze1) stable-security; urgency=high * Apply upstream patch to close security vulnerability that permitted clever manipulation of environment variables on the ssh command line to bypass rssh checking. (CVE-2012-3478) Date: 2012-08-22 16:30:14.758848+00:00 Changed-By: Jamie Strandboge Maintainer: Russ Allbery Signed-By: Ubuntu Archive Robot https://launchpad.net/ubuntu/natty/+source/rssh/2.3.2-13squeeze1build0.11.04.1 -------------- next part -------------- Sorry, changesfile not available. From sbeattie at ubuntu.com Tue Aug 28 20:39:14 2012 From: sbeattie at ubuntu.com (Steve Beattie) Date: Tue, 28 Aug 2012 20:39:14 -0000 Subject: [ubuntu/natty-security] libgc 1:6.8-1.2ubuntu3.2 (Accepted) Message-ID: <20120828203914.14458.99006.launchpad@ackee.canonical.com> libgc (1:6.8-1.2ubuntu3.2) natty-security; urgency=low * SECURITY UPDATE: multiple integer overflows - malloc.c, mallocx.c: check for integer overflow in internal malloc and calloc routines. - CVE-2012-2673 Date: 2012-08-02 22:20:43.966440+00:00 Changed-By: Steve Beattie https://launchpad.net/ubuntu/natty/+source/libgc/1:6.8-1.2ubuntu3.2 -------------- next part -------------- Sorry, changesfile not available. From cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk Tue Aug 28 21:28:13 2012 From: cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk (Ubuntu Archive Robot) Date: Tue, 28 Aug 2012 21:28:13 -0000 Subject: [ubuntu/natty-updates] libgc 1:6.8-1.2ubuntu3.2 (Accepted) Message-ID: <20120828212813.28614.35511.launchpad@ackee.canonical.com> libgc (1:6.8-1.2ubuntu3.2) natty-security; urgency=low * SECURITY UPDATE: multiple integer overflows - malloc.c, mallocx.c: check for integer overflow in internal malloc and calloc routines. - CVE-2012-2673 Date: 2012-08-02 22:20:43.966440+00:00 Changed-By: Steve Beattie Signed-By: Ubuntu Archive Robot https://launchpad.net/ubuntu/natty/+source/libgc/1:6.8-1.2ubuntu3.2 -------------- next part -------------- Sorry, changesfile not available. From sbeattie at ubuntu.com Tue Aug 28 22:12:18 2012 From: sbeattie at ubuntu.com (Steve Beattie) Date: Tue, 28 Aug 2012 22:12:18 -0000 Subject: [ubuntu/natty-security] libgdata 0.8.0-0ubuntu1.1 (Accepted) Message-ID: <20120828221218.9354.28277.launchpad@ackee.canonical.com> libgdata (0.8.0-0ubuntu1.1) natty-security; urgency=low * SECURITY UPDATE: failure to verify SSL certificates (LP: #938812) - debian/patches/01_CVE-2012-1177.patch: cause libsoup to verify SSL certificates by creating soup session with the system CA file - CVE-2012-1177 Date: 2012-05-30 17:05:46.917727+00:00 Changed-By: Steve Beattie https://launchpad.net/ubuntu/natty/+source/libgdata/0.8.0-0ubuntu1.1 -------------- next part -------------- Sorry, changesfile not available. From jamie at ubuntu.com Wed Aug 29 04:48:09 2012 From: jamie at ubuntu.com (Jamie Strandboge) Date: Wed, 29 Aug 2012 04:48:09 -0000 Subject: [ubuntu/natty-security] firefox 15.0+build1-0ubuntu0.11.04.2 (Accepted) Message-ID: <20120829044809.21725.96271.launchpad@ackee.canonical.com> firefox (15.0+build1-0ubuntu0.11.04.2) natty-security; urgency=low * New upstream stable release (FIREFOX_15_0_BUILD1) - see LP: #1041620 for USN information * Update globalmenu-extension to 3.4.1 + Drop the edit UI workarounds + Fixes for LP: #1035305 - Crash when switching apps back to Firefox with Firebug installed - Keep the menu we export in sync with the document tree all of the time, rather than only when the menus are on screen. The HUD likes to open submenus without opening any of its ancestors, which can result in us handling events on menu nodes that are no longer in a document if an ancestor responds to a bubbled-up event by removing its children - Ensure we always null check the result of nsIDocument::GetCurrentDoc + When tearing down a menu, make sure that we empty out our DbusmenuMenuitem in case the parent reuses that item for another menu. Fixes a memory leak and an issue where Firebug menu items are duplicated indefinitely each time a menu is opened + Fixes for LP: #1025011 - HUD search crashes Firefox when Firebug is installed - Provide our own binding for menupopup nodes which derives from the default binding and makes the "state" property work as if there were a frame - Make all menu nodes reference counted, and hold a strong ref when dispatching events, in case the event results in the removal of menu nodes + Fix LP: #813775 - Hitting an assertion in dbusmenu + Fix LP: #861565 - No buttons in the "Show All Bookmarks" dialog + Fix LP: #775305 - An empty menu appears when FFChrome is installed + Add a small delay when opening the menu with the keyboard, so that the additional items are added before the menu appears. Fixes an issue where keyboard focus isn't on the first item when opening the history menu with the keyboard * Add Acholi to the locale blacklist * Separate the package name from the application name in various places. This enables us to change the package name without having to modify the application or packaging (eg, to allow us to provide official branded versions of Firefox ESR using the package name "firefox-esr") - update debian/README.Debian.in - update debian/apport/source_firefox.py.in - update debian/build/get-orig-source.mk - update debian/control{,.in} - update debian/control.langpacks - update debian/control.langpacks.unavail - update debian/firefox-locale.preinst.in - update debian/firefox.install.in - update debian/firefox.links.in - update debian/firefox.lintian-overrides.in - update debian/firefox.postinst.in - update debian/firefox.postrm.in - update debian/firefox.preinst.in - update debian/firefox.sh.in - remove debian/patches/change-moz-app-name.patch - update debian/patches/series - update debian/rules - update debian/usr.bin.firefox.apparmor.* * Move parts of debian/rules that can be shared with Thunderbird to a new, common file (mozbuild.mk) - update debian/rules - add debian/build/mozbuild.mk - add debian/build/mozvars.mk - update debian/build/testsuite.mk * Make it possible to use the same create-tarball.py for Firefox and Thunderbird - update debian/build/create-tarball.py - update debian/build/get-orig-source.mk - add debian/config/tarball.conf * Switch to source format 3.0 - add debian/source/format - add debian/source/options to diff-ignore the .mozclient.mk file which is created during clean, and to pass "--no-preparation" - update debian/build/enable-dist-patches.pl - rename debian/patches/series => debian/patches/series.in so the source isn't built with patches applied - update debian/README.source * Goodbye embedded tarball, and our use of tarball.mk! - update debian/build/create-tarball.py - update debian/build/extract-file.py - update debian/build/get-orig-source.mk - update debian/build/mozbuild.mk * Run the upstream cleansrcdir target during clean - update debian/build/mozbuild.mk * Refresh patches - update debian/patches/mozilla-kde.patch * Support the "parallel" option in DEB_BUILD_OPTIONS - update debian/build/mozbuild.mk - update debian/config/mozconfig.in * Drop some of the complex shell script for creating language packs - update debian/build/mozbuild.mk - update debian/build/get-xpi-id.py * Drop searchplugin patches - these patches are an absolute pain to maintain, as they seem to break frequently and we have to touch each localized plugin. Instead, just keep our own copy of plugins we modify, and add these in to the language packs at the end of the build process - remove debian/patches/ubuntu-codes-google.patch - remove debian/patches/ubuntu-codes-amazon.patch - remove debian/patches/ubuntu-codes-baidu.patch - update debian/patches/series.in - update debian/build/mozbuild.mk - add debian/searchplugins/* * Get rid of pointless python script - remove debian/build/extract-file.py - update debian/build/mozbuild.mk * Add an automated check for finding search engines that match particular patterns and verifying that they are replaced with our own search engine if we think they should be - add debian/build/check-search-overrides.pl - update debian/build/mozbuild.mk - add debian/searchplugins/overrides.json - update debian/control{,.in} * Drop reload-new-plugins.patch, as this shouldn't actually be needed - remove debian/patches/reload-new-plugins.patch - update debian/patches/series.in * Merge get-orig-source.mk in to mozbuild.mk - update debian/build/mozbuild.mk - remove debian/build/get-orig-source.mk * Handle comments in locales.blacklist - update debian/build/refresh-supported-locales.pl - update debian/config/locales.blacklist * Fork the upstream text preprocessor and add support for additional comparison operators, which means we no longer have to add new defines for every distro version specific change we add - add debian/build/Expression.py - add debian/build/Preprocessor.py - update debian/apport/source_firefox.py.in - update debian/build/mozbuild.mk - update debian/config/mozconfig.in - update debian/firefox-dev.install.in - update debian/firefox-locale.preinst.in - update debian/firefox.desktop.in - update debian/firefox.dirs.in - update debian/firefox.install.in - update debian/firefox.links.in - update debian/firefox.postinst.in - update debian/firefox.postrm.in - update debian/firefox.preinst.in - update debian/firefox.prerm.in - update debian/rules * Refresh shipped locales * Drop powerpc patches, which are fixed upstream - remove debian/patches/fix-dtoa-build-on-ppc.patch and - remove debian/patches/fix-build-failure-without-yarr-jit.patch - update debian/patches/series.in * Drop fix-crashreporter-ftbfs-with-gcc4.7.patch, which is fixed upstream firefox (14.0.1+build1-0ubuntu0.11.04.3) natty-proposed; urgency=low * Update globalmenu-extension to 3.2.7 - Fix for LP: #1035305 - Crash when switching apps back to Firefox with Firebug installed firefox (14.0.1+build1-0ubuntu0.11.04.2) natty-proposed; urgency=low * Update globalmenu-extension to 3.2.6 - Partial fix for LP: #1025011 - HUD search crashes Firefox when Firebug is installed. Make all menu nodes reference counted, and hold a strong ref when dispatching events, in case the event results in the removal of the target node. This fixes the crash, although the Firebug submenus may flicker or display duplicated entries Date: 2012-08-26 08:25:11.049178+00:00 Changed-By: Chris Coulson Signed-By: Jamie Strandboge https://launchpad.net/ubuntu/natty/+source/firefox/15.0+build1-0ubuntu0.11.04.2 -------------- next part -------------- Sorry, changesfile not available. From cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk Wed Aug 29 06:09:09 2012 From: cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk (Ubuntu Archive Robot) Date: Wed, 29 Aug 2012 06:09:09 -0000 Subject: [ubuntu/natty-updates] firefox 15.0+build1-0ubuntu0.11.04.2 (Accepted) Message-ID: <20120829060909.14725.1961.launchpad@ackee.canonical.com> firefox (15.0+build1-0ubuntu0.11.04.2) natty-security; urgency=low * New upstream stable release (FIREFOX_15_0_BUILD1) - see LP: #1041620 for USN information * Update globalmenu-extension to 3.4.1 + Drop the edit UI workarounds + Fixes for LP: #1035305 - Crash when switching apps back to Firefox with Firebug installed - Keep the menu we export in sync with the document tree all of the time, rather than only when the menus are on screen. The HUD likes to open submenus without opening any of its ancestors, which can result in us handling events on menu nodes that are no longer in a document if an ancestor responds to a bubbled-up event by removing its children - Ensure we always null check the result of nsIDocument::GetCurrentDoc + When tearing down a menu, make sure that we empty out our DbusmenuMenuitem in case the parent reuses that item for another menu. Fixes a memory leak and an issue where Firebug menu items are duplicated indefinitely each time a menu is opened + Fixes for LP: #1025011 - HUD search crashes Firefox when Firebug is installed - Provide our own binding for menupopup nodes which derives from the default binding and makes the "state" property work as if there were a frame - Make all menu nodes reference counted, and hold a strong ref when dispatching events, in case the event results in the removal of menu nodes + Fix LP: #813775 - Hitting an assertion in dbusmenu + Fix LP: #861565 - No buttons in the "Show All Bookmarks" dialog + Fix LP: #775305 - An empty menu appears when FFChrome is installed + Add a small delay when opening the menu with the keyboard, so that the additional items are added before the menu appears. Fixes an issue where keyboard focus isn't on the first item when opening the history menu with the keyboard * Add Acholi to the locale blacklist * Separate the package name from the application name in various places. This enables us to change the package name without having to modify the application or packaging (eg, to allow us to provide official branded versions of Firefox ESR using the package name "firefox-esr") - update debian/README.Debian.in - update debian/apport/source_firefox.py.in - update debian/build/get-orig-source.mk - update debian/control{,.in} - update debian/control.langpacks - update debian/control.langpacks.unavail - update debian/firefox-locale.preinst.in - update debian/firefox.install.in - update debian/firefox.links.in - update debian/firefox.lintian-overrides.in - update debian/firefox.postinst.in - update debian/firefox.postrm.in - update debian/firefox.preinst.in - update debian/firefox.sh.in - remove debian/patches/change-moz-app-name.patch - update debian/patches/series - update debian/rules - update debian/usr.bin.firefox.apparmor.* * Move parts of debian/rules that can be shared with Thunderbird to a new, common file (mozbuild.mk) - update debian/rules - add debian/build/mozbuild.mk - add debian/build/mozvars.mk - update debian/build/testsuite.mk * Make it possible to use the same create-tarball.py for Firefox and Thunderbird - update debian/build/create-tarball.py - update debian/build/get-orig-source.mk - add debian/config/tarball.conf * Switch to source format 3.0 - add debian/source/format - add debian/source/options to diff-ignore the .mozclient.mk file which is created during clean, and to pass "--no-preparation" - update debian/build/enable-dist-patches.pl - rename debian/patches/series => debian/patches/series.in so the source isn't built with patches applied - update debian/README.source * Goodbye embedded tarball, and our use of tarball.mk! - update debian/build/create-tarball.py - update debian/build/extract-file.py - update debian/build/get-orig-source.mk - update debian/build/mozbuild.mk * Run the upstream cleansrcdir target during clean - update debian/build/mozbuild.mk * Refresh patches - update debian/patches/mozilla-kde.patch * Support the "parallel" option in DEB_BUILD_OPTIONS - update debian/build/mozbuild.mk - update debian/config/mozconfig.in * Drop some of the complex shell script for creating language packs - update debian/build/mozbuild.mk - update debian/build/get-xpi-id.py * Drop searchplugin patches - these patches are an absolute pain to maintain, as they seem to break frequently and we have to touch each localized plugin. Instead, just keep our own copy of plugins we modify, and add these in to the language packs at the end of the build process - remove debian/patches/ubuntu-codes-google.patch - remove debian/patches/ubuntu-codes-amazon.patch - remove debian/patches/ubuntu-codes-baidu.patch - update debian/patches/series.in - update debian/build/mozbuild.mk - add debian/searchplugins/* * Get rid of pointless python script - remove debian/build/extract-file.py - update debian/build/mozbuild.mk * Add an automated check for finding search engines that match particular patterns and verifying that they are replaced with our own search engine if we think they should be - add debian/build/check-search-overrides.pl - update debian/build/mozbuild.mk - add debian/searchplugins/overrides.json - update debian/control{,.in} * Drop reload-new-plugins.patch, as this shouldn't actually be needed - remove debian/patches/reload-new-plugins.patch - update debian/patches/series.in * Merge get-orig-source.mk in to mozbuild.mk - update debian/build/mozbuild.mk - remove debian/build/get-orig-source.mk * Handle comments in locales.blacklist - update debian/build/refresh-supported-locales.pl - update debian/config/locales.blacklist * Fork the upstream text preprocessor and add support for additional comparison operators, which means we no longer have to add new defines for every distro version specific change we add - add debian/build/Expression.py - add debian/build/Preprocessor.py - update debian/apport/source_firefox.py.in - update debian/build/mozbuild.mk - update debian/config/mozconfig.in - update debian/firefox-dev.install.in - update debian/firefox-locale.preinst.in - update debian/firefox.desktop.in - update debian/firefox.dirs.in - update debian/firefox.install.in - update debian/firefox.links.in - update debian/firefox.postinst.in - update debian/firefox.postrm.in - update debian/firefox.preinst.in - update debian/firefox.prerm.in - update debian/rules * Refresh shipped locales * Drop powerpc patches, which are fixed upstream - remove debian/patches/fix-dtoa-build-on-ppc.patch and - remove debian/patches/fix-build-failure-without-yarr-jit.patch - update debian/patches/series.in * Drop fix-crashreporter-ftbfs-with-gcc4.7.patch, which is fixed upstream firefox (14.0.1+build1-0ubuntu0.11.04.3) natty-proposed; urgency=low * Update globalmenu-extension to 3.2.7 - Fix for LP: #1035305 - Crash when switching apps back to Firefox with Firebug installed firefox (14.0.1+build1-0ubuntu0.11.04.2) natty-proposed; urgency=low * Update globalmenu-extension to 3.2.6 - Partial fix for LP: #1025011 - HUD search crashes Firefox when Firebug is installed. Make all menu nodes reference counted, and hold a strong ref when dispatching events, in case the event results in the removal of the target node. This fixes the crash, although the Firebug submenus may flicker or display duplicated entries Date: 2012-08-26 08:25:11.049178+00:00 Changed-By: Chris Coulson Signed-By: Ubuntu Archive Robot https://launchpad.net/ubuntu/natty/+source/firefox/15.0+build1-0ubuntu0.11.04.2 -------------- next part -------------- Sorry, changesfile not available. From cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk Wed Aug 29 06:09:12 2012 From: cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk (Ubuntu Archive Robot) Date: Wed, 29 Aug 2012 06:09:12 -0000 Subject: [ubuntu/natty-updates] libgdata 0.8.0-0ubuntu1.1 (Accepted) Message-ID: <20120829060912.14725.48136.launchpad@ackee.canonical.com> libgdata (0.8.0-0ubuntu1.1) natty-security; urgency=low * SECURITY UPDATE: failure to verify SSL certificates (LP: #938812) - debian/patches/01_CVE-2012-1177.patch: cause libsoup to verify SSL certificates by creating soup session with the system CA file - CVE-2012-1177 Date: 2012-05-30 17:05:46.917727+00:00 Changed-By: Steve Beattie Signed-By: Ubuntu Archive Robot https://launchpad.net/ubuntu/natty/+source/libgdata/0.8.0-0ubuntu1.1 -------------- next part -------------- Sorry, changesfile not available. From sbeattie at ubuntu.com Wed Aug 29 19:25:11 2012 From: sbeattie at ubuntu.com (Steve Beattie) Date: Wed, 29 Aug 2012 19:25:11 -0000 Subject: [ubuntu/natty-security] libapache2-mod-rpaf 0.5-3+squeeze1build0.11.04.1 (Accepted) Message-ID: <20120829192511.30842.92855.launchpad@ackee.canonical.com> libapache2-mod-rpaf (0.5-3+squeeze1build0.11.04.1) natty-security; urgency=low * fake sync from Debian Date: 2012-08-22 23:45:11.638298+00:00 Changed-By: Steve Beattie Maintainer: Sergey B Kirpichev https://launchpad.net/ubuntu/natty/+source/libapache2-mod-rpaf/0.5-3+squeeze1build0.11.04.1 -------------- next part -------------- Sorry, changesfile not available. From cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk Wed Aug 29 19:58:14 2012 From: cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk (Ubuntu Archive Robot) Date: Wed, 29 Aug 2012 19:58:14 -0000 Subject: [ubuntu/natty-updates] libapache2-mod-rpaf 0.5-3+squeeze1build0.11.04.1 (Accepted) Message-ID: <20120829195814.8124.11895.launchpad@ackee.canonical.com> libapache2-mod-rpaf (0.5-3+squeeze1build0.11.04.1) natty-security; urgency=low * fake sync from Debian Date: 2012-08-22 23:45:11.638298+00:00 Changed-By: Steve Beattie Maintainer: Sergey B Kirpichev Signed-By: Ubuntu Archive Robot https://launchpad.net/ubuntu/natty/+source/libapache2-mod-rpaf/0.5-3+squeeze1build0.11.04.1 -------------- next part -------------- Sorry, changesfile not available. From adconrad at 0c3.net Wed Aug 29 22:34:37 2012 From: adconrad at 0c3.net (Adam Conrad) Date: Wed, 29 Aug 2012 22:34:37 -0000 Subject: [ubuntu/natty-security] linux 2.6.38-15.66 (Accepted) Message-ID: <20120829223437.21074.88090.launchpad@ackee.canonical.com> linux (2.6.38-15.66) natty-proposed; urgency=low [Luis Henriques] * Release Tracking Bug - LP: #1036250 [ Upstream Kernel Changes ] * udf: Fortify loading of sparing table - LP: #1024497 - CVE-2012-3400 * udf: Avoid run away loop when partition table length is corrupted - LP: #1024497 - CVE-2012-3400 * eCryptfs: Gracefully refuse miscdev file ops on inherited/passed files * eCryptfs: Copy up POSIX ACL and read-only flags from lower mount - LP: #1009207 Date: 2012-08-14 17:22:07.841567+00:00 Changed-By: Luis Henriques Signed-By: Adam Conrad https://launchpad.net/ubuntu/natty/+source/linux/2.6.38-15.66 -------------- next part -------------- Sorry, changesfile not available. From steve.langasek at canonical.com Wed Aug 29 22:35:15 2012 From: steve.langasek at canonical.com (Steve Langasek) Date: Wed, 29 Aug 2012 22:35:15 -0000 Subject: [ubuntu/natty-security] icedtea-web 1.2-2ubuntu0.11.04.3 (Accepted) Message-ID: <20120829223515.21268.44488.launchpad@ackee.canonical.com> icedtea-web (1.2-2ubuntu0.11.04.3) natty-security; urgency=low * debian/patches/fix-plugin-error-on-chromium.patch: fix plugin table initialization to check only that the subset of hooks that it uses exists. (LP: #1025553) Date: 2012-08-15 06:11:40.326390+00:00 Changed-By: Steve Beattie Signed-By: Steve Langasek https://launchpad.net/ubuntu/natty/+source/icedtea-web/1.2-2ubuntu0.11.04.3 -------------- next part -------------- Sorry, changesfile not available. From steve.langasek at canonical.com Wed Aug 29 22:35:16 2012 From: steve.langasek at canonical.com (Steve Langasek) Date: Wed, 29 Aug 2012 22:35:16 -0000 Subject: [ubuntu/natty-updates] icedtea-web 1.2-2ubuntu0.11.04.3 (Accepted) Message-ID: <20120829223516.21268.37145.launchpad@ackee.canonical.com> icedtea-web (1.2-2ubuntu0.11.04.3) natty-security; urgency=low * debian/patches/fix-plugin-error-on-chromium.patch: fix plugin table initialization to check only that the subset of hooks that it uses exists. (LP: #1025553) Date: 2012-08-15 06:11:40.326390+00:00 Changed-By: Steve Beattie Signed-By: Steve Langasek https://launchpad.net/ubuntu/natty/+source/icedtea-web/1.2-2ubuntu0.11.04.3 -------------- next part -------------- Sorry, changesfile not available. From adconrad at 0c3.net Wed Aug 29 22:38:31 2012 From: adconrad at 0c3.net (Adam Conrad) Date: Wed, 29 Aug 2012 22:38:31 -0000 Subject: [ubuntu/natty-updates] linux 2.6.38-15.66 (Accepted) Message-ID: <20120829223831.21972.31243.launchpad@ackee.canonical.com> linux (2.6.38-15.66) natty-proposed; urgency=low [Luis Henriques] * Release Tracking Bug - LP: #1036250 [ Upstream Kernel Changes ] * udf: Fortify loading of sparing table - LP: #1024497 - CVE-2012-3400 * udf: Avoid run away loop when partition table length is corrupted - LP: #1024497 - CVE-2012-3400 * eCryptfs: Gracefully refuse miscdev file ops on inherited/passed files * eCryptfs: Copy up POSIX ACL and read-only flags from lower mount - LP: #1009207 Date: 2012-08-14 17:22:07.841567+00:00 Changed-By: Luis Henriques Signed-By: Adam Conrad https://launchpad.net/ubuntu/natty/+source/linux/2.6.38-15.66 -------------- next part -------------- Sorry, changesfile not available. From launchpad at micahscomputing.com Thu Aug 30 17:48:22 2012 From: launchpad at micahscomputing.com (Micah Gersten) Date: Thu, 30 Aug 2012 17:48:22 -0000 Subject: [ubuntu/natty-security] lightning-extension 1.7+build1-0ubuntu0.11.04.1 (Accepted) Message-ID: <20120830174822.26811.33070.launchpad@ackee.canonical.com> lightning-extension (1.7+build1-0ubuntu0.11.04.1) natty-security; urgency=low * New upstream stable release to support Thunderbird 15 (CALENDAR_1_7_BUILD1) - LP: #1042165 * Add extra directories required by the build system to the tarball - update debian/rules * Drop fix-dtoa-build-on-ppc.patch, which is fixed upstream Date: 2012-08-28 10:50:27.926276+00:00 Changed-By: Chris Coulson Signed-By: Micah Gersten https://launchpad.net/ubuntu/natty/+source/lightning-extension/1.7+build1-0ubuntu0.11.04.1 -------------- next part -------------- Sorry, changesfile not available. From launchpad at micahscomputing.com Thu Aug 30 17:57:03 2012 From: launchpad at micahscomputing.com (Micah Gersten) Date: Thu, 30 Aug 2012 17:57:03 -0000 Subject: [ubuntu/natty-security] thunderbird 15.0+build1-0ubuntu0.11.04.1 (Accepted) Message-ID: <20120830175703.26811.45841.launchpad@ackee.canonical.com> thunderbird (15.0+build1-0ubuntu0.11.04.1) natty-security; urgency=low * New upstream stable release (THUNDERBIRD_15_0_BUILD1) - see LP: #1042165 for USN information * Update globalmenu-extension to 3.4.1 + Fixes for LP: #1025011 - HUD search crashes Firefox when Firebug is installed - Provide our own binding for menupopup nodes which derives from the default binding and makes the "state" property work as if there were a frame - Make all menu nodes reference counted, and hold a strong ref when dispatching events, in case the event results in the removal of menu nodes + Keep the menu we export in sync with the document tree all of the time, rather than only when the menus are on screen. The HUD likes to open submenus without opening any of its ancestors, which can result in us handling events on menu nodes that are no longer in a document if an ancestor responds to a bubbled-up event by removing its children + Ensure we always null check the result of nsIDocument::GetCurrentDoc + When tearing down a menu, make sure that we empty out our DbusmenuMenuitem in case the parent reuses that item for another menu. Fixes a memory leak and an issue where Firebug menu items are duplicated indefinitely each time a menu is opened + Fix LP: #775080 - Thunderbird with Firetray/MinimizeToTray - Global menu disappears + Fix LP: #813775 - Hitting an assertion in dbusmenu + Fix LP: #775305 - Use style to determine menuitem visibility * Ensure the Apport hook parses the system preferences on Natty - update debian/apport/source_thunderbird.py.in * Make thunderbird-dbg depend on the correct version of thunderbird - update debian/control * Separate the package name from the application name. This enables us to change the package name without having to modify the application (eg, to allow us to provide official branded versions of Thunderbird ESR using the package name "thunderbird-esr"). In doing this, also drop the patch we had to rename Thunderbird in nightlies, and just use some magic in debian/rules instead - update debian/apport/source_thunderbird.py.in - update debian/build/get-orig-source.mk - update debian/control.in - update debian/control.langpacks - update debian/control.langpacks.unavail - remove debian/patches/change-moz-app-name.patch - update debian/patches/series - update debian/rules - update debian/thunderbird.install.in - update debian/thunderbird.links.in - update debian/thunderbird.lintian-overrides.in - update debian/thunderbird.postinst.in - update debian/thunderbird.postrm.in - update debian/thunderbird.preinst.in - update debian/thunderbird.sh.in * Move parts of debian/rules that can be shared with Firefox to a new, common file (mozbuild.mk) - update debian/rules - add debian/build/mozbuild.mk - add debian/build/mozvars.mk - update debian/build/testsuite.mk * Make it possible to use the same create-tarball.py for Firefox and Thunderbird - update debian/build/create-tarball.py - update debian/build/get-orig-source.mk - add debian/config/tarball.conf * Switch to source format 3.0 - add debian/source/format - add debian/source/options to diff-ignore the .mozclient.mk file which is created during clean, and to pass "--no-preparation" - update debian/build/enable-dist-patches.pl - rename debian/patches/series => debian/patches/series.in so the source isn't built with patches applied - add debian/README.source * Goodbye embedded tarball, and our use of tarball.mk! - update debian/build/create-tarball.py - update debian/build/extract-file.py - update debian/build/get-orig-source.mk - update debian/build/mozbuild.mk * Run the upstream cleansrcdir target during clean - update debian/build/mozbuild.mk * Support the "parallel" option in DEB_BUILD_OPTIONS - update debian/build/mozbuild.mk - update debian/config/mozconfig.in * Get rid of pointless python script - remove debian/build/extract-file.py - update debian/build/mozbuild.mk * Merge get-orig-source.mk in to mozbuild.mk - update debian/build/mozbuild.mk - remove debian/build/get-orig-source.mk * Handle comments in locales.blacklist - update debian/build/refresh-supported-locales.pl - update debian/config/locales.blacklist * Fork the upstream text preprocessor and add support for additional comparison operators, which means we no longer have to add new defines for every distro version specific change we add - add debian/build/Expression.py - add debian/build/Preprocessor.py - update debian/apport/source_thunderbird.py.in - update debian/build/mozbuild.mk - update debian/config/mozconfig.in - update debian/rules - update debian/thunderbird.desktop.in - update debian/thunderbird.install.in - update debian/thunderbird.links.in - update debian/thunderbird.postinst.in - update debian/thunderbird.postrm.in - update debian/thunderbird.preinst.in * Drop powerpc patches, which are fixed upstream - remove debian/patches/fix-dtoa-build-on-ppc.patch and - remove debian/patches/fix-build-failure-without-yarr-jit.patch - update debian/patches/series.in * Drop fix-crashreporter-ftbfs-with-gcc4.7.patch, which is fixed upstream Date: 2012-08-27 10:50:21.985464+00:00 Changed-By: Chris Coulson Signed-By: Micah Gersten https://launchpad.net/ubuntu/natty/+source/thunderbird/15.0+build1-0ubuntu0.11.04.1 -------------- next part -------------- Sorry, changesfile not available. From launchpad at micahscomputing.com Thu Aug 30 17:57:13 2012 From: launchpad at micahscomputing.com (Micah Gersten) Date: Thu, 30 Aug 2012 17:57:13 -0000 Subject: [ubuntu/natty-security] enigmail 2:1.4.4-0ubuntu0.11.04.1 (Accepted) Message-ID: <20120830175713.26811.33354.launchpad@ackee.canonical.com> enigmail (2:1.4.4-0ubuntu0.11.04.1) natty-security; urgency=low * New upstream release v1.4.4 to support Thunderbird 15 - LP: #1042165 Date: 2012-08-28 10:45:24.219523+00:00 Changed-By: Chris Coulson Signed-By: Micah Gersten https://launchpad.net/ubuntu/natty/+source/enigmail/2:1.4.4-0ubuntu0.11.04.1 -------------- next part -------------- Sorry, changesfile not available. From cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk Thu Aug 30 18:39:09 2012 From: cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk (Ubuntu Archive Robot) Date: Thu, 30 Aug 2012 18:39:09 -0000 Subject: [ubuntu/natty-updates] thunderbird 15.0+build1-0ubuntu0.11.04.1 (Accepted) Message-ID: <20120830183909.7496.46011.launchpad@ackee.canonical.com> thunderbird (15.0+build1-0ubuntu0.11.04.1) natty-security; urgency=low * New upstream stable release (THUNDERBIRD_15_0_BUILD1) - see LP: #1042165 for USN information * Update globalmenu-extension to 3.4.1 + Fixes for LP: #1025011 - HUD search crashes Firefox when Firebug is installed - Provide our own binding for menupopup nodes which derives from the default binding and makes the "state" property work as if there were a frame - Make all menu nodes reference counted, and hold a strong ref when dispatching events, in case the event results in the removal of menu nodes + Keep the menu we export in sync with the document tree all of the time, rather than only when the menus are on screen. The HUD likes to open submenus without opening any of its ancestors, which can result in us handling events on menu nodes that are no longer in a document if an ancestor responds to a bubbled-up event by removing its children + Ensure we always null check the result of nsIDocument::GetCurrentDoc + When tearing down a menu, make sure that we empty out our DbusmenuMenuitem in case the parent reuses that item for another menu. Fixes a memory leak and an issue where Firebug menu items are duplicated indefinitely each time a menu is opened + Fix LP: #775080 - Thunderbird with Firetray/MinimizeToTray - Global menu disappears + Fix LP: #813775 - Hitting an assertion in dbusmenu + Fix LP: #775305 - Use style to determine menuitem visibility * Ensure the Apport hook parses the system preferences on Natty - update debian/apport/source_thunderbird.py.in * Make thunderbird-dbg depend on the correct version of thunderbird - update debian/control * Separate the package name from the application name. This enables us to change the package name without having to modify the application (eg, to allow us to provide official branded versions of Thunderbird ESR using the package name "thunderbird-esr"). In doing this, also drop the patch we had to rename Thunderbird in nightlies, and just use some magic in debian/rules instead - update debian/apport/source_thunderbird.py.in - update debian/build/get-orig-source.mk - update debian/control.in - update debian/control.langpacks - update debian/control.langpacks.unavail - remove debian/patches/change-moz-app-name.patch - update debian/patches/series - update debian/rules - update debian/thunderbird.install.in - update debian/thunderbird.links.in - update debian/thunderbird.lintian-overrides.in - update debian/thunderbird.postinst.in - update debian/thunderbird.postrm.in - update debian/thunderbird.preinst.in - update debian/thunderbird.sh.in * Move parts of debian/rules that can be shared with Firefox to a new, common file (mozbuild.mk) - update debian/rules - add debian/build/mozbuild.mk - add debian/build/mozvars.mk - update debian/build/testsuite.mk * Make it possible to use the same create-tarball.py for Firefox and Thunderbird - update debian/build/create-tarball.py - update debian/build/get-orig-source.mk - add debian/config/tarball.conf * Switch to source format 3.0 - add debian/source/format - add debian/source/options to diff-ignore the .mozclient.mk file which is created during clean, and to pass "--no-preparation" - update debian/build/enable-dist-patches.pl - rename debian/patches/series => debian/patches/series.in so the source isn't built with patches applied - add debian/README.source * Goodbye embedded tarball, and our use of tarball.mk! - update debian/build/create-tarball.py - update debian/build/extract-file.py - update debian/build/get-orig-source.mk - update debian/build/mozbuild.mk * Run the upstream cleansrcdir target during clean - update debian/build/mozbuild.mk * Support the "parallel" option in DEB_BUILD_OPTIONS - update debian/build/mozbuild.mk - update debian/config/mozconfig.in * Get rid of pointless python script - remove debian/build/extract-file.py - update debian/build/mozbuild.mk * Merge get-orig-source.mk in to mozbuild.mk - update debian/build/mozbuild.mk - remove debian/build/get-orig-source.mk * Handle comments in locales.blacklist - update debian/build/refresh-supported-locales.pl - update debian/config/locales.blacklist * Fork the upstream text preprocessor and add support for additional comparison operators, which means we no longer have to add new defines for every distro version specific change we add - add debian/build/Expression.py - add debian/build/Preprocessor.py - update debian/apport/source_thunderbird.py.in - update debian/build/mozbuild.mk - update debian/config/mozconfig.in - update debian/rules - update debian/thunderbird.desktop.in - update debian/thunderbird.install.in - update debian/thunderbird.links.in - update debian/thunderbird.postinst.in - update debian/thunderbird.postrm.in - update debian/thunderbird.preinst.in * Drop powerpc patches, which are fixed upstream - remove debian/patches/fix-dtoa-build-on-ppc.patch and - remove debian/patches/fix-build-failure-without-yarr-jit.patch - update debian/patches/series.in * Drop fix-crashreporter-ftbfs-with-gcc4.7.patch, which is fixed upstream Date: 2012-08-27 10:50:21.985464+00:00 Changed-By: Chris Coulson Signed-By: Ubuntu Archive Robot https://launchpad.net/ubuntu/natty/+source/thunderbird/15.0+build1-0ubuntu0.11.04.1 -------------- next part -------------- Sorry, changesfile not available. From cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk Thu Aug 30 18:39:10 2012 From: cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk (Ubuntu Archive Robot) Date: Thu, 30 Aug 2012 18:39:10 -0000 Subject: [ubuntu/natty-updates] enigmail 2:1.4.4-0ubuntu0.11.04.1 (Accepted) Message-ID: <20120830183910.7496.90360.launchpad@ackee.canonical.com> enigmail (2:1.4.4-0ubuntu0.11.04.1) natty-security; urgency=low * New upstream release v1.4.4 to support Thunderbird 15 - LP: #1042165 Date: 2012-08-28 10:45:24.219523+00:00 Changed-By: Chris Coulson Signed-By: Ubuntu Archive Robot https://launchpad.net/ubuntu/natty/+source/enigmail/2:1.4.4-0ubuntu0.11.04.1 -------------- next part -------------- Sorry, changesfile not available. From cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk Thu Aug 30 18:39:12 2012 From: cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk (Ubuntu Archive Robot) Date: Thu, 30 Aug 2012 18:39:12 -0000 Subject: [ubuntu/natty-updates] lightning-extension 1.7+build1-0ubuntu0.11.04.1 (Accepted) Message-ID: <20120830183912.7496.93388.launchpad@ackee.canonical.com> lightning-extension (1.7+build1-0ubuntu0.11.04.1) natty-security; urgency=low * New upstream stable release to support Thunderbird 15 (CALENDAR_1_7_BUILD1) - LP: #1042165 * Add extra directories required by the build system to the tarball - update debian/rules * Drop fix-dtoa-build-on-ppc.patch, which is fixed upstream Date: 2012-08-28 10:50:27.926276+00:00 Changed-By: Chris Coulson Signed-By: Ubuntu Archive Robot https://launchpad.net/ubuntu/natty/+source/lightning-extension/1.7+build1-0ubuntu0.11.04.1 -------------- next part -------------- Sorry, changesfile not available. From sbeattie at ubuntu.com Thu Aug 30 19:45:15 2012 From: sbeattie at ubuntu.com (Steve Beattie) Date: Thu, 30 Aug 2012 19:45:15 -0000 Subject: [ubuntu/natty-security] rtfm 2.4.2-4+squeeze1build0.11.04.1 (Accepted) Message-ID: <20120830194515.28315.78217.launchpad@ackee.canonical.com> rtfm (2.4.2-4+squeeze1build0.11.04.1) natty-security; urgency=low * fake sync from Debian Date: 2012-08-30 18:35:12.117277+00:00 Changed-By: Steve Beattie https://launchpad.net/ubuntu/natty/+source/rtfm/2.4.2-4+squeeze1build0.11.04.1 -------------- next part -------------- Sorry, changesfile not available. From cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk Thu Aug 30 20:28:13 2012 From: cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk (Ubuntu Archive Robot) Date: Thu, 30 Aug 2012 20:28:13 -0000 Subject: [ubuntu/natty-updates] rtfm 2.4.2-4+squeeze1build0.11.04.1 (Accepted) Message-ID: <20120830202813.8933.59458.launchpad@ackee.canonical.com> rtfm (2.4.2-4+squeeze1build0.11.04.1) natty-security; urgency=low * fake sync from Debian Date: 2012-08-30 18:35:12.117277+00:00 Changed-By: Steve Beattie Signed-By: Ubuntu Archive Robot https://launchpad.net/ubuntu/natty/+source/rtfm/2.4.2-4+squeeze1build0.11.04.1 -------------- next part -------------- Sorry, changesfile not available. From cjwatson at canonical.com Fri Aug 31 21:32:11 2012 From: cjwatson at canonical.com (Colin Watson) Date: Fri, 31 Aug 2012 21:32:11 -0000 Subject: [ubuntu/natty-updates] debian-installer 20101020ubuntu29.2 (Accepted) Message-ID: <20120831213211.5563.12512.launchpad@ackee.canonical.com> debian-installer (20101020ubuntu29.2) natty-proposed; urgency=low * Move to 2.6.38-15 kernels. Date: 2012-07-04 09:10:49.230812+00:00 Changed-By: Colin Watson https://launchpad.net/ubuntu/natty/+source/debian-installer/20101020ubuntu29.2 -------------- next part -------------- Sorry, changesfile not available.