From l3on at ubuntu.com Wed Feb 1 15:34:05 2012 From: l3on at ubuntu.com (Leo Iannacone) Date: Wed, 01 Feb 2012 15:34:05 -0000 Subject: [ubuntu/natty-security] usbmuxd 1.0.7-1ubuntu0.11.04.1 (Accepted) Message-ID: <20120201153405.26424.85577.launchpad@cocoplum.canonical.com> usbmuxd (1.0.7-1ubuntu0.11.04.1) natty-security; urgency=high * SECURITY UPDATE: fix possible buffer overflow - 90-cve-2012-0065.patch: use strncpy() instead of strcpy in libusbmuxd/libusbmuxd.c receive_packet() with a size that ensures we don't overflow dev->serial_number - CVE-2012-0065 - LP: #919435 Date: Sun, 29 Jan 2012 16:14:32 +0100 Changed-By: Leo Iannacone Maintainer: Ubuntu Developers https://launchpad.net/ubuntu/natty/+source/usbmuxd/1.0.7-1ubuntu0.11.04.1 -------------- next part -------------- Format: 1.8 Date: Sun, 29 Jan 2012 16:14:32 +0100 Source: usbmuxd Binary: usbmuxd libusbmuxd1 libusbmuxd-dev libusbmuxd1-dbg Architecture: source Version: 1.0.7-1ubuntu0.11.04.1 Distribution: natty-security Urgency: high Maintainer: Ubuntu Developers Changed-By: Leo Iannacone Description: libusbmuxd-dev - USB multiplexor daemon for iPhone and iPod Touch devices - devel libusbmuxd1 - USB multiplexor daemon for iPhone and iPod Touch devices - librar libusbmuxd1-dbg - USB multiplexor daemon for iPhone and iPod Touch devices - debug usbmuxd - USB multiplexor daemon for iPhone and iPod Touch devices Launchpad-Bugs-Fixed: 919435 Changes: usbmuxd (1.0.7-1ubuntu0.11.04.1) natty-security; urgency=high . * SECURITY UPDATE: fix possible buffer overflow - 90-cve-2012-0065.patch: use strncpy() instead of strcpy in libusbmuxd/libusbmuxd.c receive_packet() with a size that ensures we don't overflow dev->serial_number - CVE-2012-0065 - LP: #919435 Checksums-Sha1: 92d4971b35db16379c1223ce0d7f4cae3a6a2268 2085 usbmuxd_1.0.7-1ubuntu0.11.04.1.dsc 3d93bef43d8c37afa4c80c187f1e6ef25dada5e6 6533 usbmuxd_1.0.7-1ubuntu0.11.04.1.debian.tar.gz Checksums-Sha256: a15bef6a83c879b34260c5d561612b0fd04bd166b5b108085bf903b95a3a1cb3 2085 usbmuxd_1.0.7-1ubuntu0.11.04.1.dsc c599800365faaa224c8f866dccfec249afafb1ca8049ea56dd4359e337449113 6533 usbmuxd_1.0.7-1ubuntu0.11.04.1.debian.tar.gz Files: cbcc825403fa6655687e655f5e8c229f 2085 utils optional usbmuxd_1.0.7-1ubuntu0.11.04.1.dsc d897c67cb1fdbab010e0504bfa295f99 6533 utils optional usbmuxd_1.0.7-1ubuntu0.11.04.1.debian.tar.gz Original-Maintainer: Julien Lavergne From cjwatson at ubuntu.com Fri Feb 3 08:54:02 2012 From: cjwatson at ubuntu.com (Colin Watson) Date: Fri, 03 Feb 2012 08:54:02 -0000 Subject: [ubuntu/natty-proposed] kickseed 0.55ubuntu1.2 (Accepted) Message-ID: <20120203085402.27677.63778.launchpad@soybean.canonical.com> kickseed (0.55ubuntu1.2) natty-proposed; urgency=low * Fix iSCSI ks_preseed calls to include a type field (LP: #810068). kickseed (0.55ubuntu1.1) natty-proposed; urgency=low * Preseed partman-lvm/confirm_overwrite as well as partman-lvm/confirm. * Preseed partman-lvm/device_remove_lvm when confirming logvol results, since Kickstart doesn't have a separate control with a one-to-one correspondence to this (LP: #708548). Date: Fri, 20 Jan 2012 16:54:23 +0000 Changed-By: Colin Watson Maintainer: Ubuntu Installer Team https://launchpad.net/ubuntu/natty/+source/kickseed/0.55ubuntu1.2 -------------- next part -------------- Format: 1.8 Date: Fri, 20 Jan 2012 16:54:23 +0000 Source: kickseed Binary: kickseed-common initrd-kickseed Architecture: source Version: 0.55ubuntu1.2 Distribution: natty-proposed Urgency: low Maintainer: Ubuntu Installer Team Changed-By: Colin Watson Description: initrd-kickseed - Load Kickstart file from the initrd (udeb) kickseed-common - Common files for Kickstart compatibility (udeb) Launchpad-Bugs-Fixed: 708548 810068 Changes: kickseed (0.55ubuntu1.2) natty-proposed; urgency=low . * Fix iSCSI ks_preseed calls to include a type field (LP: #810068). . kickseed (0.55ubuntu1.1) natty-proposed; urgency=low . * Preseed partman-lvm/confirm_overwrite as well as partman-lvm/confirm. * Preseed partman-lvm/device_remove_lvm when confirming logvol results, since Kickstart doesn't have a separate control with a one-to-one correspondence to this (LP: #708548). Checksums-Sha1: ceb1f07f68813c63c6fff7811214540f7f5f521a 1843 kickseed_0.55ubuntu1.2.dsc f67c772264ed41d2e3887526ff5a807847b7be91 25309 kickseed_0.55ubuntu1.2.tar.gz Checksums-Sha256: 3e5564f0850c1517ca04e35e0e4313fda5c18fe4c48a0360c5d064a7640fe7a7 1843 kickseed_0.55ubuntu1.2.dsc c208780553e6e88bc85b404f43a561ea09372fbabca2fd62e665057b3d69afdb 25309 kickseed_0.55ubuntu1.2.tar.gz Files: f11b6490de1afefb49db5ef47e16f292 1843 debian-installer optional kickseed_0.55ubuntu1.2.dsc 572a11057f855f24cec8b13a948aa9cc 25309 debian-installer optional kickseed_0.55ubuntu1.2.tar.gz Original-Maintainer: Debian Install System Team From cjwatson at ubuntu.com Fri Feb 3 08:55:39 2012 From: cjwatson at ubuntu.com (Colin Watson) Date: Fri, 03 Feb 2012 08:55:39 -0000 Subject: [ubuntu/natty-proposed] partman-iscsi 16.1 (Accepted) Message-ID: <20120203085539.12214.9969.launchpad@chaenomeles.canonical.com> partman-iscsi (16.1) natty-proposed; urgency=low * Don't fail if debconf questions are preseeded (LP: #810068). Date: Fri, 20 Jan 2012 16:48:28 +0000 Changed-By: Colin Watson Maintainer: Ubuntu Installer Team https://launchpad.net/ubuntu/natty/+source/partman-iscsi/16.1 -------------- next part -------------- Format: 1.8 Date: Fri, 20 Jan 2012 16:48:28 +0000 Source: partman-iscsi Binary: partman-iscsi Architecture: source Version: 16.1 Distribution: natty-proposed Urgency: low Maintainer: Ubuntu Installer Team Changed-By: Colin Watson Description: partman-iscsi - Adds support for iSCSI to partman (udeb) Launchpad-Bugs-Fixed: 810068 Changes: partman-iscsi (16.1) natty-proposed; urgency=low . * Don't fail if debconf questions are preseeded (LP: #810068). Checksums-Sha1: 9184c2b1f00aca5c5839dd0e10f56a654fa9ee95 1584 partman-iscsi_16.1.dsc b8abff4830a9a5a7b9cb03a919ec648daf3f2dec 14606 partman-iscsi_16.1.tar.gz Checksums-Sha256: 225def0fdbda29d2b693eb90cfdb0fa35fe6708f452bef3a53f3c279ed1a7bb5 1584 partman-iscsi_16.1.dsc 9e091972e5fc319f846f9e81a3095d50a94daa95e0afaa4e7056f27dc6c6b086 14606 partman-iscsi_16.1.tar.gz Files: 4387b22f7fb360aaccd770a619450872 1584 debian-installer standard partman-iscsi_16.1.dsc 3c8a954da2138296ad3425ac9d5b4828 14606 debian-installer standard partman-iscsi_16.1.tar.gz From jamie at ubuntu.com Fri Feb 3 20:50:27 2012 From: jamie at ubuntu.com (Jamie Strandboge) Date: Fri, 03 Feb 2012 20:50:27 -0000 Subject: [ubuntu/natty-updates] mozvoikko 2.0.1-0ubuntu0.11.04.1 (Accepted) Message-ID: <20120203205027.887.63877.launchpad@ackee.canonical.com> mozvoikko (2.0.1-0ubuntu0.11.04.1) natty-security; urgency=low * Update to the 2.0 rewrite - Now uses js-ctypes (yay, good riddance evil binary extension) - Fixes LP: #914706 - can't select any other spell-check language in Firefox with mozvoikko installed - see LP: #923319 for USN information * Drop firefox-dev, libvoikko-dev, pkg-config and lsb-release build-depends - update debian/control * Make xul-ext-mozvoikko Arch: all - update debian/control * Drop debian/patches/fix_sdk_build.patch * Drop debian/patches/port_to_latest_firefox.patch * Drop everything related to the old build system from debian/rules Date: 2012-01-29 14:25:50.546132+00:00 Changed-By: Chris Coulson Signed-By: Jamie Strandboge https://launchpad.net/ubuntu/natty/+source/mozvoikko/2.0.1-0ubuntu0.11.04.1 -------------- next part -------------- Sorry, changesfile not available. From jamie at ubuntu.com Fri Feb 3 20:50:28 2012 From: jamie at ubuntu.com (Jamie Strandboge) Date: Fri, 03 Feb 2012 20:50:28 -0000 Subject: [ubuntu/natty-security] mozvoikko 2.0.1-0ubuntu0.11.04.1 (Accepted) Message-ID: <20120203205028.887.58390.launchpad@ackee.canonical.com> mozvoikko (2.0.1-0ubuntu0.11.04.1) natty-security; urgency=low * Update to the 2.0 rewrite - Now uses js-ctypes (yay, good riddance evil binary extension) - Fixes LP: #914706 - can't select any other spell-check language in Firefox with mozvoikko installed - see LP: #923319 for USN information * Drop firefox-dev, libvoikko-dev, pkg-config and lsb-release build-depends - update debian/control * Make xul-ext-mozvoikko Arch: all - update debian/control * Drop debian/patches/fix_sdk_build.patch * Drop debian/patches/port_to_latest_firefox.patch * Drop everything related to the old build system from debian/rules Date: 2012-01-29 14:25:50.546132+00:00 Changed-By: Chris Coulson Signed-By: Jamie Strandboge https://launchpad.net/ubuntu/natty/+source/mozvoikko/2.0.1-0ubuntu0.11.04.1 -------------- next part -------------- Sorry, changesfile not available. From jamie at ubuntu.com Fri Feb 3 20:54:30 2012 From: jamie at ubuntu.com (Jamie Strandboge) Date: Fri, 03 Feb 2012 20:54:30 -0000 Subject: [ubuntu/natty-updates] firefox 10.0+build1-0ubuntu0.11.04.1 (Accepted) Message-ID: <20120203205430.887.31029.launchpad@ackee.canonical.com> firefox (10.0+build1-0ubuntu0.11.04.1) natty-security; urgency=low * New upstream stable release (FIREFOX_10_0_BUILD1) - see LP: #923319 for USN information [ Chris Coulson ] * Update patches for PRBool -> bool transition - refresh debian/patches/firefox-kde.patch - refresh debian/patches/mozilla-kde.patch - refresh debian/patches/ubuntu-ua-string-changes.patch * Drop some more hanging IPC xpcshell tests - update debian/build/testsuite.mk * Remove prerm hook for cleaning up pyc files in the apport package-hooks folder. Nothing creates these - update debian/firefox.prerm.in * Set up alternatives in the postinst script on abort-remove too - update debian/firefox.postinst.in * Imporove maintainer script magic for moving the system pref file and removing obsolete conffiles when upgrading from 3.6, by doing what dpkg-maintscripts-helper does - update debian/firefox.postinst.in - update debian/firefox.postrm.in - update debian/firefox.preinst.in * Only run the Apparmor stuff in the postinst script on configure, and in the preinst script on install or upgrade, so it handles upgrade failures gracefully - update debian/firefox.postinst.in - update debian/firefox.preinst.in * Drop the Ubuntuzilla workarounds now - update debian/firefox.postinst.in * Refresh patches - update debian/patches/allow-lockPref-everywhere.patch - update debian/patches/ubuntu_bookmarks.patch * Turn off Network Manager integration for now, as it causes Firefox to always start in offline mode. In any case, probing Network Manager isn't the most reliable way to test if there is a connection - update debian/vendor.js * Update after landing of bmo: #701875 - Rename omni.jar to omni.ja - update debian/firefox.install.in * Disable the tests on powerpc, because it sucks too much to run them - update debian/rules * "Fix" LP: #897794 - some websites expect "X11" to be the first token of the platform component in the UA string - update debian/patches/ubuntu-ua-string-changes.patch * Defuzz ubuntu-codes-google.patch * Refresh shipped locales (adds Assamese and Kashubian) - refresh debian/config/locales.shipped - refresh debian/control * Update KDE patches for removal of nsCStringArray - update debian/firefox-kde.patch - update debian/mozilla-kde.patch * Backport changes to allow per-release/per-arch patches - add debian/build/enable-dist-patches.pl - update debian/rules * Fix LP: #908508 - Add patch from upstream to fix powerpc build failure. Only apply this patch on powerpc to avoid compromising the quality of the architectures that we care about - add debian/patches/fix-build-failure-without-yarr-jit2.patch - update debian/patches/series * Also make the previous powerpc build fix apply on ppc only - update debian/patches/series [ Micah Gersten ] * Rebase patches for PRBool -> bool transition (bmo: 675553) - update debian/patches/allow-lockPref-everywhere.patch - update debian/patches/mozilla-kde.patch * Drop patch after upstream landing of (bmo: 690432) aka Logging.h passes a string directly to printf - drop debian/patches/printf-fix.patch - update debian/patches/series * Fix LP: #917529 - Make sure new transitional packages have a versioned dependency on Firefox so as to not break Firefox during partial upgrades - update debian/control{,.in} [ Adam Conrad ] * Add missing build-dep on non-essential locales, since we use it. - update debian/control{,.in} Date: 2012-01-29 14:16:05.748983+00:00 Changed-By: Chris Coulson Signed-By: Jamie Strandboge https://launchpad.net/ubuntu/natty/+source/firefox/10.0+build1-0ubuntu0.11.04.1 -------------- next part -------------- Sorry, changesfile not available. From jamie at ubuntu.com Fri Feb 3 20:55:26 2012 From: jamie at ubuntu.com (Jamie Strandboge) Date: Fri, 03 Feb 2012 20:55:26 -0000 Subject: [ubuntu/natty-security] firefox 10.0+build1-0ubuntu0.11.04.1 (Accepted) Message-ID: <20120203205526.887.69706.launchpad@ackee.canonical.com> firefox (10.0+build1-0ubuntu0.11.04.1) natty-security; urgency=low * New upstream stable release (FIREFOX_10_0_BUILD1) - see LP: #923319 for USN information [ Chris Coulson ] * Update patches for PRBool -> bool transition - refresh debian/patches/firefox-kde.patch - refresh debian/patches/mozilla-kde.patch - refresh debian/patches/ubuntu-ua-string-changes.patch * Drop some more hanging IPC xpcshell tests - update debian/build/testsuite.mk * Remove prerm hook for cleaning up pyc files in the apport package-hooks folder. Nothing creates these - update debian/firefox.prerm.in * Set up alternatives in the postinst script on abort-remove too - update debian/firefox.postinst.in * Imporove maintainer script magic for moving the system pref file and removing obsolete conffiles when upgrading from 3.6, by doing what dpkg-maintscripts-helper does - update debian/firefox.postinst.in - update debian/firefox.postrm.in - update debian/firefox.preinst.in * Only run the Apparmor stuff in the postinst script on configure, and in the preinst script on install or upgrade, so it handles upgrade failures gracefully - update debian/firefox.postinst.in - update debian/firefox.preinst.in * Drop the Ubuntuzilla workarounds now - update debian/firefox.postinst.in * Refresh patches - update debian/patches/allow-lockPref-everywhere.patch - update debian/patches/ubuntu_bookmarks.patch * Turn off Network Manager integration for now, as it causes Firefox to always start in offline mode. In any case, probing Network Manager isn't the most reliable way to test if there is a connection - update debian/vendor.js * Update after landing of bmo: #701875 - Rename omni.jar to omni.ja - update debian/firefox.install.in * Disable the tests on powerpc, because it sucks too much to run them - update debian/rules * "Fix" LP: #897794 - some websites expect "X11" to be the first token of the platform component in the UA string - update debian/patches/ubuntu-ua-string-changes.patch * Defuzz ubuntu-codes-google.patch * Refresh shipped locales (adds Assamese and Kashubian) - refresh debian/config/locales.shipped - refresh debian/control * Update KDE patches for removal of nsCStringArray - update debian/firefox-kde.patch - update debian/mozilla-kde.patch * Backport changes to allow per-release/per-arch patches - add debian/build/enable-dist-patches.pl - update debian/rules * Fix LP: #908508 - Add patch from upstream to fix powerpc build failure. Only apply this patch on powerpc to avoid compromising the quality of the architectures that we care about - add debian/patches/fix-build-failure-without-yarr-jit2.patch - update debian/patches/series * Also make the previous powerpc build fix apply on ppc only - update debian/patches/series [ Micah Gersten ] * Rebase patches for PRBool -> bool transition (bmo: 675553) - update debian/patches/allow-lockPref-everywhere.patch - update debian/patches/mozilla-kde.patch * Drop patch after upstream landing of (bmo: 690432) aka Logging.h passes a string directly to printf - drop debian/patches/printf-fix.patch - update debian/patches/series * Fix LP: #917529 - Make sure new transitional packages have a versioned dependency on Firefox so as to not break Firefox during partial upgrades - update debian/control{,.in} [ Adam Conrad ] * Add missing build-dep on non-essential locales, since we use it. - update debian/control{,.in} Date: 2012-01-29 14:16:05.748983+00:00 Changed-By: Chris Coulson Signed-By: Jamie Strandboge https://launchpad.net/ubuntu/natty/+source/firefox/10.0+build1-0ubuntu0.11.04.1 -------------- next part -------------- Sorry, changesfile not available. From jamie at ubuntu.com Sat Feb 4 04:05:09 2012 From: jamie at ubuntu.com (Jamie Strandboge) Date: Sat, 04 Feb 2012 04:05:09 -0000 Subject: [ubuntu/natty-updates] chromium-browser 16.0.912.77~r118311-0ubuntu0.11.04.1 (Accepted) Message-ID: <20120204040509.29152.87467.launchpad@ackee.canonical.com> chromium-browser (16.0.912.77~r118311-0ubuntu0.11.04.1) natty-security; urgency=low * New upstream release from the Stable Channel (LP: #923602) This release fixes the following security issues: - [106484] High CVE-2011-3924: Use-after-free in DOM selections. Credit to Arthur Gerkis. - [107182] Critical CVE-2011-3925: Use-after-free in Safe Browsing navigation. Credit to Chamal de Silva. - [108461] High CVE-2011-3928: Use-after-free in DOM handling. Credit to wushi of team509 reported through ZDI (ZDI-CAN-1415). - [108605] High CVE-2011-3927: Uninitialized value in Skia. Credit to miaubiz. - [109556] High CVE-2011-3926: Heap-buffer-overflow in tree builder. Credit to Arthur Gerkis. chromium-browser (16.0.912.75~r116452-0ubuntu0.11.04.1) natty-security; urgency=low * New upstream release from the Stable Channel (LP: #914648, #889711) This release fixes the following security issues: - [106672] High CVE-2011-3921: Use-after-free in animation frames. Credit to Boris Zbarsky of Mozilla. - [107128] High CVE-2011-3919: Heap-buffer-overflow in libxml. Credit to Jüri Aedla. - [108006] High CVE-2011-3922: Stack-buffer-overflow in glyph handling. Credit to Google Chrome Security Team (Cris Neckar). This upload also includes the following security fixes from 16.0.912.63: - [81753] Medium CVE-2011-3903: Out-of-bounds read in regex matching. Credit to David Holloway of the Chromium development community. - [95465] Low CVE-2011-3905: Out-of-bounds reads in libxml. Credit to Google Chrome Security Team (Inferno). - [98809] Medium CVE-2011-3906: Out-of-bounds read in PDF parser. Credit to Aki Helin of OUSPG. - [99016] High CVE-2011-3907: URL bar spoofing with view-source. Credit to Luka Treiber of ACROS Security. - [100863] Low CVE-2011-3908: Out-of-bounds read in SVG parsing. Credit to Aki Helin of OUSPG. - [101010] Medium CVE-2011-3909: [64-bit only] Memory corruption in CSS property array. Credit to Google Chrome Security Team (scarybeasts) and Chu. - [101494] Medium CVE-2011-3910: Out-of-bounds read in YUV video frame handling. Credit to Google Chrome Security Team (Cris Neckar). - [101779] Medium CVE-2011-3911: Out-of-bounds read in PDF. Credit to Google Chrome Security Team (scarybeasts) and Robert Swiecki of the Google Security Team. - [102359] High CVE-2011-3912: Use-after-free in SVG filters. Credit to Arthur Gerkis. - [103921] High CVE-2011-3913: Use-after-free in Range handling. Credit to Arthur Gerkis. - [104011] High CVE-2011-3914: Out-of-bounds write in v8 i18n handling. Credit to Sławomir Błażek. - [104529] High CVE-2011-3915: Buffer overflow in PDF font handling. Credit to Atte Kettunen of OUSPG. - [104959] Medium CVE-2011-3916: Out-of-bounds reads in PDF cross references. Credit to Atte Kettunen of OUSPG. - [105162] Medium CVE-2011-3917: Stack-buffer-overflow in FileWatcher. Credit to Google Chrome Security Team (Marty Barbella). - [107258] High CVE-2011-3904: Use-after-free in bidi handling. Credit to Google Chrome Security Team (Inferno) and miaubiz. This upload also includes the following security fixes from 15.0.874.121: - [103259] High CVE-2011-3900: Out-of-bounds write in v8. Credit to Christian Holler. This upload also includes the following security fixes from 15.0.874.120: - [100465] High CVE-2011-3892: Double free in Theora decoder. Credit to Aki Helin of OUSPG. - [100492] [100543] Medium CVE-2011-3893: Out of bounds reads in MKV and Vorbis media handlers. Credit to Aki Helin of OUSPG. - [101172] High CVE-2011-3894: Memory corruption regression in VP8 decoding. Credit to Andrew Scherkus of the Chromium development community. - [101458] High CVE-2011-3895: Heap overflow in Vorbis decoder. Credit to Aki Helin of OUSPG. - [101624] High CVE-2011-3896: Buffer overflow in shader variable mapping. Credit to Ken “strcpy” Russell of the Chromium development community. - [102242] High CVE-2011-3897: Use-after-free in editing. Credit to pa_kt reported through ZDI (ZDI-CAN-1416). [ Brandon Snider ] * Refresh patch - update debian/patches/chromium_useragent.patch.in chromium-browser (15.0.874.106~r107270-0ubuntu0.11.04.1) natty-security; urgency=low * New upstream release from the Stable Channel (LP: #881786) This release fixes the following security issues: - [86758] High CVE-2011-2845: URL bar spoof in history handling. Credit to Jordi Chancel. - [88949] Medium CVE-2011-3875: URL bar spoof with drag+drop of URLs. Credit to Jordi Chancel. - [90217] Low CVE-2011-3876: Avoid stripping whitespace at the end of download filenames. Credit to Marc Novak. - [91218] Low CVE-2011-3877: XSS in appcache internals page. Credit to Google Chrome Security Team (Tom Sepez) plus independent discovery by Juho Nurminen. - [94487] Medium CVE-2011-3878: Race condition in worker process initialization. Credit to miaubiz. - [95374] Low CVE-2011-3879: Avoid redirect to chrome scheme URIs. Credit to Masato Kinugawa. - [95992] Low CVE-2011-3880: Don’t permit as a HTTP header delimiter. Credit to Vladimir Vorontsov, ONsec company. - [96047] [96885] [98053] [99512] [99750] High CVE-2011-3881: Cross-origin policy violations. Credit to Sergey Glazunov. - [96292] High CVE-2011-3882: Use-after-free in media buffer handling. Credit to Google Chrome Security Team (Inferno). - [96902] High CVE-2011-3883: Use-after-free in counter handling. Credit to miaubiz. - [97148] High CVE-2011-3884: Timing issues in DOM traversal. Credit to Brian Ryner of the Chromium development community. - [97599] [98064] [98556] [99294] [99880] [100059] High CVE-2011-3885: Stale style bugs leading to use-after-free. Credit to miaubiz. - [98773] [99167] High CVE-2011-3886: Out of bounds writes in v8. Credit to Christian Holler. - [98407] Medium CVE-2011-3887: Cookie theft with javascript URIs. Credit to Sergey Glazunov. - [99138] High CVE-2011-3888: Use-after-free with plug-in and editing. Credit to miaubiz. - [99211] High CVE-2011-3889: Heap overflow in Web Audio. Credit to miaubiz. - [99553] High CVE-2011-3890: Use-after-free in video source handling. Credit to Ami Fischman of the Chromium development community. - [100332] High CVE-2011-3891: Exposure of internal v8 functions. Credit to Steven Keuchel of the Chromium development community plus independent discovery by Daniel Divricean. [ Chris Coulson ] * Refresh patches - update debian/patches/dlopen_sonamed_gl.patch - update debian/patches/webkit_rev_parser.patch [ Fabien Tassin ] * Disable NaCl until we figure out what to do with the private toolchain - update debian/rules * Do not install the pseudo_locales files in the debs - update debian/rules * Add python-simplejson to Build-depends. This is needed by NaCl even with NaCl disabled, so this is a temporary workaround to unbreak the build, it must be fixed upstream - update debian/control Date: 2012-01-30 06:15:45.960367+00:00 Changed-By: Micah Gersten Maintainer: Fabien Tassin Signed-By: Jamie Strandboge https://launchpad.net/ubuntu/natty/+source/chromium-browser/16.0.912.77~r118311-0ubuntu0.11.04.1 -------------- next part -------------- Sorry, changesfile not available. From jamie at ubuntu.com Sat Feb 4 04:05:18 2012 From: jamie at ubuntu.com (Jamie Strandboge) Date: Sat, 04 Feb 2012 04:05:18 -0000 Subject: [ubuntu/natty-security] chromium-browser 16.0.912.77~r118311-0ubuntu0.11.04.1 (Accepted) Message-ID: <20120204040518.29152.21606.launchpad@ackee.canonical.com> chromium-browser (16.0.912.77~r118311-0ubuntu0.11.04.1) natty-security; urgency=low * New upstream release from the Stable Channel (LP: #923602) This release fixes the following security issues: - [106484] High CVE-2011-3924: Use-after-free in DOM selections. Credit to Arthur Gerkis. - [107182] Critical CVE-2011-3925: Use-after-free in Safe Browsing navigation. Credit to Chamal de Silva. - [108461] High CVE-2011-3928: Use-after-free in DOM handling. Credit to wushi of team509 reported through ZDI (ZDI-CAN-1415). - [108605] High CVE-2011-3927: Uninitialized value in Skia. Credit to miaubiz. - [109556] High CVE-2011-3926: Heap-buffer-overflow in tree builder. Credit to Arthur Gerkis. chromium-browser (16.0.912.75~r116452-0ubuntu0.11.04.1) natty-security; urgency=low * New upstream release from the Stable Channel (LP: #914648, #889711) This release fixes the following security issues: - [106672] High CVE-2011-3921: Use-after-free in animation frames. Credit to Boris Zbarsky of Mozilla. - [107128] High CVE-2011-3919: Heap-buffer-overflow in libxml. Credit to Jüri Aedla. - [108006] High CVE-2011-3922: Stack-buffer-overflow in glyph handling. Credit to Google Chrome Security Team (Cris Neckar). This upload also includes the following security fixes from 16.0.912.63: - [81753] Medium CVE-2011-3903: Out-of-bounds read in regex matching. Credit to David Holloway of the Chromium development community. - [95465] Low CVE-2011-3905: Out-of-bounds reads in libxml. Credit to Google Chrome Security Team (Inferno). - [98809] Medium CVE-2011-3906: Out-of-bounds read in PDF parser. Credit to Aki Helin of OUSPG. - [99016] High CVE-2011-3907: URL bar spoofing with view-source. Credit to Luka Treiber of ACROS Security. - [100863] Low CVE-2011-3908: Out-of-bounds read in SVG parsing. Credit to Aki Helin of OUSPG. - [101010] Medium CVE-2011-3909: [64-bit only] Memory corruption in CSS property array. Credit to Google Chrome Security Team (scarybeasts) and Chu. - [101494] Medium CVE-2011-3910: Out-of-bounds read in YUV video frame handling. Credit to Google Chrome Security Team (Cris Neckar). - [101779] Medium CVE-2011-3911: Out-of-bounds read in PDF. Credit to Google Chrome Security Team (scarybeasts) and Robert Swiecki of the Google Security Team. - [102359] High CVE-2011-3912: Use-after-free in SVG filters. Credit to Arthur Gerkis. - [103921] High CVE-2011-3913: Use-after-free in Range handling. Credit to Arthur Gerkis. - [104011] High CVE-2011-3914: Out-of-bounds write in v8 i18n handling. Credit to Sławomir Błażek. - [104529] High CVE-2011-3915: Buffer overflow in PDF font handling. Credit to Atte Kettunen of OUSPG. - [104959] Medium CVE-2011-3916: Out-of-bounds reads in PDF cross references. Credit to Atte Kettunen of OUSPG. - [105162] Medium CVE-2011-3917: Stack-buffer-overflow in FileWatcher. Credit to Google Chrome Security Team (Marty Barbella). - [107258] High CVE-2011-3904: Use-after-free in bidi handling. Credit to Google Chrome Security Team (Inferno) and miaubiz. This upload also includes the following security fixes from 15.0.874.121: - [103259] High CVE-2011-3900: Out-of-bounds write in v8. Credit to Christian Holler. This upload also includes the following security fixes from 15.0.874.120: - [100465] High CVE-2011-3892: Double free in Theora decoder. Credit to Aki Helin of OUSPG. - [100492] [100543] Medium CVE-2011-3893: Out of bounds reads in MKV and Vorbis media handlers. Credit to Aki Helin of OUSPG. - [101172] High CVE-2011-3894: Memory corruption regression in VP8 decoding. Credit to Andrew Scherkus of the Chromium development community. - [101458] High CVE-2011-3895: Heap overflow in Vorbis decoder. Credit to Aki Helin of OUSPG. - [101624] High CVE-2011-3896: Buffer overflow in shader variable mapping. Credit to Ken “strcpy” Russell of the Chromium development community. - [102242] High CVE-2011-3897: Use-after-free in editing. Credit to pa_kt reported through ZDI (ZDI-CAN-1416). [ Brandon Snider ] * Refresh patch - update debian/patches/chromium_useragent.patch.in chromium-browser (15.0.874.106~r107270-0ubuntu0.11.04.1) natty-security; urgency=low * New upstream release from the Stable Channel (LP: #881786) This release fixes the following security issues: - [86758] High CVE-2011-2845: URL bar spoof in history handling. Credit to Jordi Chancel. - [88949] Medium CVE-2011-3875: URL bar spoof with drag+drop of URLs. Credit to Jordi Chancel. - [90217] Low CVE-2011-3876: Avoid stripping whitespace at the end of download filenames. Credit to Marc Novak. - [91218] Low CVE-2011-3877: XSS in appcache internals page. Credit to Google Chrome Security Team (Tom Sepez) plus independent discovery by Juho Nurminen. - [94487] Medium CVE-2011-3878: Race condition in worker process initialization. Credit to miaubiz. - [95374] Low CVE-2011-3879: Avoid redirect to chrome scheme URIs. Credit to Masato Kinugawa. - [95992] Low CVE-2011-3880: Don’t permit as a HTTP header delimiter. Credit to Vladimir Vorontsov, ONsec company. - [96047] [96885] [98053] [99512] [99750] High CVE-2011-3881: Cross-origin policy violations. Credit to Sergey Glazunov. - [96292] High CVE-2011-3882: Use-after-free in media buffer handling. Credit to Google Chrome Security Team (Inferno). - [96902] High CVE-2011-3883: Use-after-free in counter handling. Credit to miaubiz. - [97148] High CVE-2011-3884: Timing issues in DOM traversal. Credit to Brian Ryner of the Chromium development community. - [97599] [98064] [98556] [99294] [99880] [100059] High CVE-2011-3885: Stale style bugs leading to use-after-free. Credit to miaubiz. - [98773] [99167] High CVE-2011-3886: Out of bounds writes in v8. Credit to Christian Holler. - [98407] Medium CVE-2011-3887: Cookie theft with javascript URIs. Credit to Sergey Glazunov. - [99138] High CVE-2011-3888: Use-after-free with plug-in and editing. Credit to miaubiz. - [99211] High CVE-2011-3889: Heap overflow in Web Audio. Credit to miaubiz. - [99553] High CVE-2011-3890: Use-after-free in video source handling. Credit to Ami Fischman of the Chromium development community. - [100332] High CVE-2011-3891: Exposure of internal v8 functions. Credit to Steven Keuchel of the Chromium development community plus independent discovery by Daniel Divricean. [ Chris Coulson ] * Refresh patches - update debian/patches/dlopen_sonamed_gl.patch - update debian/patches/webkit_rev_parser.patch [ Fabien Tassin ] * Disable NaCl until we figure out what to do with the private toolchain - update debian/rules * Do not install the pseudo_locales files in the debs - update debian/rules * Add python-simplejson to Build-depends. This is needed by NaCl even with NaCl disabled, so this is a temporary workaround to unbreak the build, it must be fixed upstream - update debian/control Date: 2012-01-30 06:15:45.960367+00:00 Changed-By: Micah Gersten Maintainer: Fabien Tassin Signed-By: Jamie Strandboge https://launchpad.net/ubuntu/natty/+source/chromium-browser/16.0.912.77~r118311-0ubuntu0.11.04.1 -------------- next part -------------- Sorry, changesfile not available. From martin.pitt at ubuntu.com Mon Feb 6 09:19:30 2012 From: martin.pitt at ubuntu.com (Martin Pitt) Date: Mon, 06 Feb 2012 09:19:30 -0000 Subject: [ubuntu/natty-updates] linux-ti-omap4 2.6.38-1209.21 (Accepted) Message-ID: <20120206091930.2115.14697.launchpad@ackee.canonical.com> linux-ti-omap4 (2.6.38-1209.21) natty-proposed; urgency=low * Release Tracking Bug - LP: #921724 [ Upstream Kernel Changes ] * xfs: validate acl count - LP: #917706 - CVE-2012-0038 * xfs: fix acl count validation in xfs_acl_from_disk() - LP: #917706 - CVE-2012-0038 * drm: integer overflow in drm_mode_dirtyfb_ioctl() - LP: #917838 - CVE-2012-0044 * igmp: Avoid zero delay when receiving odd mixture of IGMP queries - LP: #917848 - CVE-2012-0207 Date: 2012-01-26 15:01:36.251481+00:00 Changed-By: Paolo Pisati Signed-By: Martin Pitt https://launchpad.net/ubuntu/natty/+source/linux-ti-omap4/2.6.38-1209.21 -------------- next part -------------- Sorry, changesfile not available. From martin.pitt at ubuntu.com Mon Feb 6 09:19:34 2012 From: martin.pitt at ubuntu.com (Martin Pitt) Date: Mon, 06 Feb 2012 09:19:34 -0000 Subject: [ubuntu/natty-security] linux-ti-omap4 2.6.38-1209.21 (Accepted) Message-ID: <20120206091934.2115.90589.launchpad@ackee.canonical.com> linux-ti-omap4 (2.6.38-1209.21) natty-proposed; urgency=low * Release Tracking Bug - LP: #921724 [ Upstream Kernel Changes ] * xfs: validate acl count - LP: #917706 - CVE-2012-0038 * xfs: fix acl count validation in xfs_acl_from_disk() - LP: #917706 - CVE-2012-0038 * drm: integer overflow in drm_mode_dirtyfb_ioctl() - LP: #917838 - CVE-2012-0044 * igmp: Avoid zero delay when receiving odd mixture of IGMP queries - LP: #917848 - CVE-2012-0207 Date: 2012-01-26 15:01:36.251481+00:00 Changed-By: Paolo Pisati Signed-By: Martin Pitt https://launchpad.net/ubuntu/natty/+source/linux-ti-omap4/2.6.38-1209.21 -------------- next part -------------- Sorry, changesfile not available. From marc.deslauriers at ubuntu.com Wed Feb 8 18:21:06 2012 From: marc.deslauriers at ubuntu.com (Marc Deslauriers) Date: Wed, 08 Feb 2012 18:21:06 -0000 Subject: [ubuntu/natty] acroread 9.4.7-1natty1 (Accepted) Message-ID: <20120208182106.24867.61329.launchpad@cocoplum.canonical.com> acroread (9.4.7-1natty1) natty; urgency=low * New upstream release, addresses security issues: - http://www.adobe.com/support/security/bulletins/apsb11-30.html - CVE-2011-2462 - CVE-2011-4369 * This is an English only release. The -deu, -fra, -jpn packages still contain 9.4.2, as more recent versions are not available for those languages. Date: Tue, 07 Feb 2012 14:14:37 -0500 Changed-By: Marc Deslauriers Maintainer: Brian Thomason https://launchpad.net/ubuntu/natty/+source/acroread/9.4.7-1natty1 -------------- next part -------------- -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 07 Feb 2012 14:14:37 -0500 Source: acroread Binary: acroread adobereader-deu adobereader-fra adobereader-jpn acroread-common Architecture: source Version: 9.4.7-1natty1 Distribution: natty Urgency: low Maintainer: Brian Thomason Changed-By: Marc Deslauriers Description: acroread - Adobe Reader acroread-common - Adobe Reader - Common Files adobereader-deu - Adobe Reader adobereader-fra - Adobe Reader adobereader-jpn - Adobe Reader Changes: acroread (9.4.7-1natty1) natty; urgency=low . * New upstream release, addresses security issues: - http://www.adobe.com/support/security/bulletins/apsb11-30.html - CVE-2011-2462 - CVE-2011-4369 * This is an English only release. The -deu, -fra, -jpn packages still contain 9.4.2, as more recent versions are not available for those languages. Checksums-Sha1: 1a7ae049bff64445248e5cbcacf1f9bffb4c5b00 1943 acroread_9.4.7-1natty1.dsc e141c98897b71185fc27077fab99285ecfc52763 267218579 acroread_9.4.7.orig.tar.gz c111611fbcbbc9ef9a66f3f34b8c286154d592bb 20766 acroread_9.4.7-1natty1.debian.tar.gz Checksums-Sha256: 1aded280d22dc939507cb2157ca3b0588cde353b2094d781be312f77612120cd 1943 acroread_9.4.7-1natty1.dsc 7ae0879748f81f06ebdc217098bbebf0af2ab8530174720626d34069be3006b3 267218579 acroread_9.4.7.orig.tar.gz 177fcc125a65c2d903e118e56d2be6c2aa92f2bdc89cfac0711c1a66c54ac97a 20766 acroread_9.4.7-1natty1.debian.tar.gz Files: 9b8b99ca93fe636201acff0fb3dbb181 1943 partner/text extra acroread_9.4.7-1natty1.dsc d81ca67801f1cff258655797a554aed2 267218579 partner/text extra acroread_9.4.7.orig.tar.gz bfb973f7de95f868834d1a12f38084f3 20766 partner/text extra acroread_9.4.7-1natty1.debian.tar.gz -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.11 (GNU/Linux) iQIcBAEBCgAGBQJPMrbqAAoJEGVp2FWnRL6TLr8QAJ2/NaSs/jcgb8/L7wPqcGtl XpbTBwbCAzy/oZToYJt3gjssXovpxNjhLx3f/bNU8elpqlnRFe7k/pY2oZ3olR+s /yKym7VFyJTMWVbRMTLGBDeVVwwC7yQQeYL7DLRM1s4Zaj58z+Porgk2NVxvm9Q9 YQBbSlaRNuHniJfhV+4Hk3EumJWu72JxuaPE5ofMBiB1IDiUyaIWYgPcgDWOJEHQ j53hN9PqPSZ/FeKXrdaUBuFiefm4fh/+ncPI+i77c4qC3yja9tb51hKDAzGMK/6H gZVjMe9MhpqWHT4hvRju0rhxsPtD18Ac7F2St3mvl4RNWjMD6KpoA61kR188kTnO 92nccUpzQE4m30Rg9VEVX3LgXV+I/cqhdelv9oy3QZeQQ1XnjXaMuk02UBsJuTnP dZ3uDePTCJLJyrSxGxufuy/8lHGBACemiC8IZfuyK4VPmigi2rIBjvdmmC9GwBJa dvsyRzAEJBpqTAAtOfM/aOUVdvCafB1Y5LSZ/o5cfJ1Yt+djexrhCrDSUfTWAgcQ cYSpDdoXaD3KNRsfGILfe1IkTVZvjyaYPMSxk8nvmyVxsDGJuc1Cit9/Adgg7kfb HHabEzSYdinyeItALKfR+e4jTYWk0CwXCGLlmGMAMpGgUMe+ed48VgjU0R/8H1af YJQKyBXLY0x9A6arNM+C =F7FX -----END PGP SIGNATURE----- From sbeattie at ubuntu.com Thu Feb 9 21:35:01 2012 From: sbeattie at ubuntu.com (Steve Beattie) Date: Thu, 09 Feb 2012 21:35:01 -0000 Subject: [ubuntu/natty-security] php5_5.3.5-1ubuntu7.6_amd64_translations.tar.gz, php5, php5_5.3.5-1ubuntu7.6_powerpc_translations.tar.gz, php5_5.3.5-1ubuntu7.6_i386_translations.tar.gz, php5_5.3.5-1ubuntu7.6_armel_translations.tar.gz 5.3.5-1ubuntu7.6 (Accepted) Message-ID: <20120209213501.1766.90121.launchpad@cocoplum.canonical.com> php5 (5.3.5-1ubuntu7.6) natty-security; urgency=low * SECURITY UPDATE: memory allocation failure denial of service - debian/patches/php5-CVE-2011-4153.patch: check result of zend_strdup() and calloc() for failed allocations - CVE-2011-4153 * SECURITY UPDATE: predictable hash collision denial of service (LP: #910296) - debian/patches/php5-CVE-2011-4885.patch: add max_input_vars directive with default limit of 1000 - ATTENTION: this update changes previous php5 behavior by limiting the number of external input variables to 1000. This may be increased by adding a "max_input_vars" directive to the php.ini configuration file. See http://www.php.net/manual/en/info.configuration.php#ini.max-input-vars for more information. - CVE-2011-4885 * SECURITY UPDATE: remote code execution vulnerability introduced by the fix for CVE-2011-4885 (LP: #925772) - debian/patches/php5-CVE-2012-0830.patch: return rather than continuing if max_input_vars limit is reached - CVE-2012-0830 * SECURITY UPDATE: XSLT arbitrary file overwrite attack - debian/patches/php5-CVE-2012-0057.patch: add xsl.security_prefs ini option to define forbidden operations within XSLT stylesheets - CVE-2012-0057 * SECURITY UPDATE: PDORow session denial of service - debian/patches/php5-CVE-2012-0788.patch: fail gracefully when attempting to serialize PDORow instances - CVE-2012-0788 * SECURITY UPDATE: magic_quotes_gpc remote disable vulnerability - debian/patches/php5-CVE-2012-0831.patch: always restore magic_quote_gpc on request shutdown - CVE-2012-0831 Date: Wed, 08 Feb 2012 20:58:41 -0800 Changed-By: Steve Beattie Maintainer: Ubuntu Developers https://launchpad.net/ubuntu/natty/+source/php5/5.3.5-1ubuntu7.6 -------------- next part -------------- Format: 1.8 Date: Wed, 08 Feb 2012 20:58:41 -0800 Source: php5 Binary: php5 php5-common libapache2-mod-php5 libapache2-mod-php5filter php5-cgi php5-cli php5-fpm php5-dev php5-dbg php-pear php5-curl php5-enchant php5-gd php5-gmp php5-intl php5-ldap php5-mysql php5-odbc php5-pgsql php5-pspell php5-recode php5-snmp php5-sqlite php5-sybase php5-tidy php5-xmlrpc php5-xsl Architecture: source Version: 5.3.5-1ubuntu7.6 Distribution: natty-security Urgency: low Maintainer: Ubuntu Developers Changed-By: Steve Beattie Description: libapache2-mod-php5 - server-side, HTML-embedded scripting language (Apache 2 module) libapache2-mod-php5filter - server-side, HTML-embedded scripting language (apache 2 filter mo php-pear - PEAR - PHP Extension and Application Repository php5 - server-side, HTML-embedded scripting language (metapackage) php5-cgi - server-side, HTML-embedded scripting language (CGI binary) php5-cli - command-line interpreter for the php5 scripting language php5-common - Common files for packages built from the php5 source php5-curl - CURL module for php5 php5-dbg - Debug symbols for PHP5 php5-dev - Files for PHP5 module development php5-enchant - Enchant module for php5 php5-fpm - server-side, HTML-embedded scripting language (FPM-CGI binary) php5-gd - GD module for php5 php5-gmp - GMP module for php5 php5-intl - internationalisation module for php5 php5-ldap - LDAP module for php5 php5-mysql - MySQL module for php5 php5-odbc - ODBC module for php5 php5-pgsql - PostgreSQL module for php5 php5-pspell - pspell module for php5 php5-recode - recode module for php5 php5-snmp - SNMP module for php5 php5-sqlite - SQLite module for php5 php5-sybase - Sybase / MS SQL Server module for php5 php5-tidy - tidy module for php5 php5-xmlrpc - XML-RPC module for php5 php5-xsl - XSL module for php5 Launchpad-Bugs-Fixed: 910296 925772 Changes: php5 (5.3.5-1ubuntu7.6) natty-security; urgency=low . * SECURITY UPDATE: memory allocation failure denial of service - debian/patches/php5-CVE-2011-4153.patch: check result of zend_strdup() and calloc() for failed allocations - CVE-2011-4153 * SECURITY UPDATE: predictable hash collision denial of service (LP: #910296) - debian/patches/php5-CVE-2011-4885.patch: add max_input_vars directive with default limit of 1000 - ATTENTION: this update changes previous php5 behavior by limiting the number of external input variables to 1000. This may be increased by adding a "max_input_vars" directive to the php.ini configuration file. See http://www.php.net/manual/en/info.configuration.php#ini.max-input-vars for more information. - CVE-2011-4885 * SECURITY UPDATE: remote code execution vulnerability introduced by the fix for CVE-2011-4885 (LP: #925772) - debian/patches/php5-CVE-2012-0830.patch: return rather than continuing if max_input_vars limit is reached - CVE-2012-0830 * SECURITY UPDATE: XSLT arbitrary file overwrite attack - debian/patches/php5-CVE-2012-0057.patch: add xsl.security_prefs ini option to define forbidden operations within XSLT stylesheets - CVE-2012-0057 * SECURITY UPDATE: PDORow session denial of service - debian/patches/php5-CVE-2012-0788.patch: fail gracefully when attempting to serialize PDORow instances - CVE-2012-0788 * SECURITY UPDATE: magic_quotes_gpc remote disable vulnerability - debian/patches/php5-CVE-2012-0831.patch: always restore magic_quote_gpc on request shutdown - CVE-2012-0831 Checksums-Sha1: fa780095c3e0f012289edf4abb5c0f8675939383 3268 php5_5.3.5-1ubuntu7.6.dsc 8731889d3f2636bd53866b5e8a58ac88f6dcceba 239155 php5_5.3.5-1ubuntu7.6.diff.gz Checksums-Sha256: dbe4fc51b439a5c2a633980e733ab50a7b259ade1c8f19c406ff579d4343f350 3268 php5_5.3.5-1ubuntu7.6.dsc 8c8f5e0e230200f097189c722bff0a0e05de8d1d9abd3e627dbc9d87b01d6112 239155 php5_5.3.5-1ubuntu7.6.diff.gz Files: baa8cee20a0756af873ee90dcb131952 3268 php optional php5_5.3.5-1ubuntu7.6.dsc 59c94b6b34d625cd4a1874f98b2aa275 239155 php optional php5_5.3.5-1ubuntu7.6.diff.gz Original-Maintainer: Debian PHP Maintainers From sbeattie at ubuntu.com Thu Feb 9 21:35:42 2012 From: sbeattie at ubuntu.com (Steve Beattie) Date: Thu, 09 Feb 2012 21:35:42 -0000 Subject: [ubuntu/natty-security] openssl_0.9.8o-5ubuntu1.2_amd64_translations.tar.gz, openssl_0.9.8o-5ubuntu1.2_powerpc_translations.tar.gz, openssl_0.9.8o-5ubuntu1.2_i386_translations.tar.gz, openssl, openssl_0.9.8o-5ubuntu1.2_armel_translations.tar.gz 0.9.8o-5ubuntu1.2 (Accepted) Message-ID: <20120209213542.1766.87194.launchpad@cocoplum.canonical.com> openssl (0.9.8o-5ubuntu1.2) natty-security; urgency=low * SECURITY UPDATE: ECDSA private key timing attack - debian/patches/CVE-2011-1945.patch: compute with fixed scalar length - CVE-2011-1945 * SECURITY UPDATE: ECDH ciphersuite denial of service - debian/patches/CVE-2011-3210.patch: fix memory usage for thread safety - CVE-2011-3210 * SECURITY UPDATE: DTLS plaintext recovery attack - debian/patches/CVE-2011-4108.patch: perform all computations before discarding messages - CVE-2011-4108 * SECURITY UPDATE: policy check double free vulnerability - debian/patches/CVE-2011-4019.patch: only free domain policyin one location - CVE-2011-4019 * SECURITY UPDATE: SSL 3.0 block padding exposure - debian/patches/CVE-2011-4576.patch: clear bytes used for block padding of SSL 3.0 records. - CVE-2011-4576 * SECURITY UPDATE: malformed RFC 3779 data denial of service attack - debian/patches/CVE-2011-4577.patch: prevent malformed RFC3779 data from triggering an assertion failure - CVE-2011-4577 * SECURITY UPDATE: Server Gated Cryptography (SGC) denial of service - debian/patches/CVE-2011-4619.patch: Only allow one SGC handshake restart for SSL/TLS. - CVE-2011-4619 * SECURITY UPDATE: fix for CVE-2011-4108 denial of service attack - debian/patches/CVE-2012-0050.patch: improve handling of DTLS MAC - CVE-2012-0050 * debian/libssl0.9.8.postinst: Only issue the reboot notification for servers by testing that the X server is not running (LP: #244250) Date: Tue, 31 Jan 2012 01:27:53 -0800 Changed-By: Steve Beattie Maintainer: Ubuntu Developers https://launchpad.net/ubuntu/natty/+source/openssl/0.9.8o-5ubuntu1.2 -------------- next part -------------- Format: 1.8 Date: Tue, 31 Jan 2012 01:27:53 -0800 Source: openssl Binary: openssl openssl-doc libssl0.9.8 libcrypto0.9.8-udeb libssl0.9.8-udeb libssl-dev libssl0.9.8-dbg Architecture: source Version: 0.9.8o-5ubuntu1.2 Distribution: natty-security Urgency: low Maintainer: Ubuntu Developers Changed-By: Steve Beattie Description: libcrypto0.9.8-udeb - crypto shared library - udeb (udeb) libssl-dev - SSL development libraries, header files and documentation libssl0.9.8 - SSL shared libraries libssl0.9.8-dbg - Symbol tables for libssl and libcrypto libssl0.9.8-udeb - ssl shared library - udeb (udeb) openssl - Secure Socket Layer (SSL) binary and related cryptographic tools openssl-doc - Secure Socket Layer (SSL) documentation Launchpad-Bugs-Fixed: 244250 Changes: openssl (0.9.8o-5ubuntu1.2) natty-security; urgency=low . * SECURITY UPDATE: ECDSA private key timing attack - debian/patches/CVE-2011-1945.patch: compute with fixed scalar length - CVE-2011-1945 * SECURITY UPDATE: ECDH ciphersuite denial of service - debian/patches/CVE-2011-3210.patch: fix memory usage for thread safety - CVE-2011-3210 * SECURITY UPDATE: DTLS plaintext recovery attack - debian/patches/CVE-2011-4108.patch: perform all computations before discarding messages - CVE-2011-4108 * SECURITY UPDATE: policy check double free vulnerability - debian/patches/CVE-2011-4019.patch: only free domain policyin one location - CVE-2011-4019 * SECURITY UPDATE: SSL 3.0 block padding exposure - debian/patches/CVE-2011-4576.patch: clear bytes used for block padding of SSL 3.0 records. - CVE-2011-4576 * SECURITY UPDATE: malformed RFC 3779 data denial of service attack - debian/patches/CVE-2011-4577.patch: prevent malformed RFC3779 data from triggering an assertion failure - CVE-2011-4577 * SECURITY UPDATE: Server Gated Cryptography (SGC) denial of service - debian/patches/CVE-2011-4619.patch: Only allow one SGC handshake restart for SSL/TLS. - CVE-2011-4619 * SECURITY UPDATE: fix for CVE-2011-4108 denial of service attack - debian/patches/CVE-2012-0050.patch: improve handling of DTLS MAC - CVE-2012-0050 * debian/libssl0.9.8.postinst: Only issue the reboot notification for servers by testing that the X server is not running (LP: #244250) Checksums-Sha1: 08cb88371ee2f3169405c4f0ec03217d1912c371 2116 openssl_0.9.8o-5ubuntu1.2.dsc 7838480f00a248ea04436181726756c5db6eaa96 100211 openssl_0.9.8o-5ubuntu1.2.debian.tar.gz Checksums-Sha256: f0c805fee86649f49cc234ca9201253b37e63d400f30cac14483f82643c4726b 2116 openssl_0.9.8o-5ubuntu1.2.dsc 66fe97728e1b52aa5d7ca9b4644cc66a7ab009b14885609d2720fd35912dcf5c 100211 openssl_0.9.8o-5ubuntu1.2.debian.tar.gz Files: 9b191cf4d65ced89204093fd4dee96cb 2116 utils optional openssl_0.9.8o-5ubuntu1.2.dsc b72cc0920ea01c2a1436a3af259deb7b 100211 utils optional openssl_0.9.8o-5ubuntu1.2.debian.tar.gz Original-Maintainer: Debian OpenSSL Team From martin.pitt at ubuntu.com Fri Feb 10 06:40:22 2012 From: martin.pitt at ubuntu.com (Martin Pitt) Date: Fri, 10 Feb 2012 06:40:22 -0000 Subject: [ubuntu/natty-updates] lxc 0.7.4-0ubuntu7.2 (Accepted) Message-ID: <20120210064022.11607.2180.launchpad@ackee.canonical.com> lxc (0.7.4-0ubuntu7.2) natty-proposed; urgency=low [ Serge Hallyn ] * debian/rules: add -r (--no-restart-on-upgrade) to DEB_DH_INSTALLINIT_ARGS to prevent upgrading lxc from forcing lxc autostart containers to stop and restart. (LP: #753308) Date: 2011-09-13 00:35:12.615730+00:00 Changed-By: Clint Byrum Signed-By: Martin Pitt https://launchpad.net/ubuntu/natty/+source/lxc/0.7.4-0ubuntu7.2 -------------- next part -------------- Sorry, changesfile not available. From martin.pitt at ubuntu.com Fri Feb 10 06:44:12 2012 From: martin.pitt at ubuntu.com (Martin Pitt) Date: Fri, 10 Feb 2012 06:44:12 -0000 Subject: [ubuntu/natty-updates] python-kinterbasdb 3.3.0-2build1.11.04.1 (Accepted) Message-ID: <20120210064412.12637.64840.launchpad@ackee.canonical.com> python-kinterbasdb (3.3.0-2build1.11.04.1) natty-proposed; urgency=low * No change rebuild to bring back the non-i386 archs (LP: #904593) Date: 2012-01-01 10:15:15.633491+00:00 Changed-By: Micah Gersten Maintainer: Debian Python Modules Team Signed-By: Martin Pitt https://launchpad.net/ubuntu/natty/+source/python-kinterbasdb/3.3.0-2build1.11.04.1 -------------- next part -------------- Sorry, changesfile not available. From steve.langasek at canonical.com Fri Feb 10 17:53:50 2012 From: steve.langasek at canonical.com (Steve Langasek) Date: Fri, 10 Feb 2012 17:53:50 -0000 Subject: [ubuntu/natty-updates] linux 2.6.38-13.55 (Accepted) Message-ID: <20120210175350.28419.81494.launchpad@ackee.canonical.com> linux (2.6.38-13.55) natty-proposed; urgency=low [Brad Figg] * Release Tracking Bug - LP: #920790 [ Upstream Kernel Changes ] * fuse: check size of FUSE_NOTIFY_INVAL_ENTRY message, CVE-2011-3353 - LP: #905058 - CVE-2011-3353 * KVM: x86: Prevent starting PIT timers in the absence of irqchip support - LP: #911303 - CVE-2011-4622 * sched, x86: Avoid unnecessary overflow in sched_clock - LP: #805341 * use cache type functions for arch_get_unmapped_area - LP: #861296 * topdown mmap support - LP: #861296 * xfs: validate acl count - LP: #917706 - CVE-2012-0038 * xfs: fix acl count validation in xfs_acl_from_disk() - LP: #917706 - CVE-2012-0038 * drm: integer overflow in drm_mode_dirtyfb_ioctl() - LP: #917838 - CVE-2012-0044 * x86/PCI: amd: factor out MMCONFIG discovery - LP: #647043 * PNP: work around Dell 1536/1546 BIOS MMCONFIG bug that - LP: #647043 Date: 2012-01-24 14:10:58.804808+00:00 Changed-By: Brad Figg Signed-By: Steve Langasek https://launchpad.net/ubuntu/natty/+source/linux/2.6.38-13.55 -------------- next part -------------- Sorry, changesfile not available. From martin.pitt at ubuntu.com Mon Feb 13 06:28:18 2012 From: martin.pitt at ubuntu.com (Martin Pitt) Date: Mon, 13 Feb 2012 06:28:18 -0000 Subject: [ubuntu/natty-updates] youtube-dl 2011.08.04-1~natty0.1 (Accepted) Message-ID: <20120213062818.14875.26021.launchpad@ackee.canonical.com> youtube-dl (2011.08.04-1~natty0.1) natty-proposed; urgency=low * Backport new upstream release to Natty to fix changes in Youtube. (LP: #915029) Date: 2012-01-11 21:15:12.497112+00:00 Changed-By: Evan Broder Maintainer: =?utf-8?q?Rog=C3=A9rio_Theodoro_de_Brito?= Signed-By: Martin Pitt https://launchpad.net/ubuntu/natty/+source/youtube-dl/2011.08.04-1~natty0.1 -------------- next part -------------- Sorry, changesfile not available. From sbeattie at ubuntu.com Mon Feb 13 17:05:04 2012 From: sbeattie at ubuntu.com (Steve Beattie) Date: Mon, 13 Feb 2012 17:05:04 -0000 Subject: [ubuntu/natty-security] php5_5.3.5-1ubuntu7.7_armel_translations.tar.gz, php5, php5_5.3.5-1ubuntu7.7_powerpc_translations.tar.gz, php5_5.3.5-1ubuntu7.7_amd64_translations.tar.gz, php5_5.3.5-1ubuntu7.7_i386_translations.tar.gz 5.3.5-1ubuntu7.7 (Accepted) Message-ID: <20120213170504.17857.43554.launchpad@cocoplum.canonical.com> php5 (5.3.5-1ubuntu7.7) natty-security; urgency=low * debian/patches/php5-CVE-2012-0831-regression.patch: fix magic_quotes_gpc ini setting regression introduced by patch for CVE-2012-0831. Thanks to Ondřej Surý for the patch. (LP: #930115) Date: Fri, 10 Feb 2012 14:58:23 -0800 Changed-By: Steve Beattie Maintainer: Ubuntu Developers https://launchpad.net/ubuntu/natty/+source/php5/5.3.5-1ubuntu7.7 -------------- next part -------------- Format: 1.8 Date: Fri, 10 Feb 2012 14:58:23 -0800 Source: php5 Binary: php5 php5-common libapache2-mod-php5 libapache2-mod-php5filter php5-cgi php5-cli php5-fpm php5-dev php5-dbg php-pear php5-curl php5-enchant php5-gd php5-gmp php5-intl php5-ldap php5-mysql php5-odbc php5-pgsql php5-pspell php5-recode php5-snmp php5-sqlite php5-sybase php5-tidy php5-xmlrpc php5-xsl Architecture: source Version: 5.3.5-1ubuntu7.7 Distribution: natty-security Urgency: low Maintainer: Ubuntu Developers Changed-By: Steve Beattie Description: libapache2-mod-php5 - server-side, HTML-embedded scripting language (Apache 2 module) libapache2-mod-php5filter - server-side, HTML-embedded scripting language (apache 2 filter mo php-pear - PEAR - PHP Extension and Application Repository php5 - server-side, HTML-embedded scripting language (metapackage) php5-cgi - server-side, HTML-embedded scripting language (CGI binary) php5-cli - command-line interpreter for the php5 scripting language php5-common - Common files for packages built from the php5 source php5-curl - CURL module for php5 php5-dbg - Debug symbols for PHP5 php5-dev - Files for PHP5 module development php5-enchant - Enchant module for php5 php5-fpm - server-side, HTML-embedded scripting language (FPM-CGI binary) php5-gd - GD module for php5 php5-gmp - GMP module for php5 php5-intl - internationalisation module for php5 php5-ldap - LDAP module for php5 php5-mysql - MySQL module for php5 php5-odbc - ODBC module for php5 php5-pgsql - PostgreSQL module for php5 php5-pspell - pspell module for php5 php5-recode - recode module for php5 php5-snmp - SNMP module for php5 php5-sqlite - SQLite module for php5 php5-sybase - Sybase / MS SQL Server module for php5 php5-tidy - tidy module for php5 php5-xmlrpc - XML-RPC module for php5 php5-xsl - XSL module for php5 Launchpad-Bugs-Fixed: 930115 Changes: php5 (5.3.5-1ubuntu7.7) natty-security; urgency=low . * debian/patches/php5-CVE-2012-0831-regression.patch: fix magic_quotes_gpc ini setting regression introduced by patch for CVE-2012-0831. Thanks to Ondřej Surý for the patch. (LP: #930115) Checksums-Sha1: 555a45a8abb5606ce580f0003163592c24f209e4 3268 php5_5.3.5-1ubuntu7.7.dsc 6fa27723910588e77cddbf9c55a78064d7ba946c 239904 php5_5.3.5-1ubuntu7.7.diff.gz Checksums-Sha256: 345e8a7d428c1ce8ffec1a20746989d49589760c23f81a28dedf0649f9f35c2f 3268 php5_5.3.5-1ubuntu7.7.dsc 6b1424222f605cf9d9b54c1a21a93f056246c3196fc332a48ae502c664e66501 239904 php5_5.3.5-1ubuntu7.7.diff.gz Files: 628d8f2059bbe338393d6a771be971e5 3268 php optional php5_5.3.5-1ubuntu7.7.dsc 7f0f329eee0e39ad35d7f73907df3736 239904 php optional php5_5.3.5-1ubuntu7.7.diff.gz Original-Maintainer: Debian PHP Maintainers From jamie at ubuntu.com Tue Feb 14 16:33:25 2012 From: jamie at ubuntu.com (Jamie Strandboge) Date: Tue, 14 Feb 2012 16:33:25 -0000 Subject: [ubuntu/natty-security] puppet 2.6.4-2ubuntu2.7 (Accepted) Message-ID: <20120214163325.29823.45130.launchpad@cocoplum.canonical.com> puppet (2.6.4-2ubuntu2.7) natty-security; urgency=low * SECURITY UPDATE: fix access to remote resource when auth.conf is missing which was was reintroduced in 2.6.4-2ubuntu1. - debian/patches/CVE-2011-0528.patch: Disable remote ralsh by default - CVE-2011-0528 Date: Fri, 10 Feb 2012 05:58:07 -0600 Changed-By: Jamie Strandboge Maintainer: Ubuntu Developers https://launchpad.net/ubuntu/natty/+source/puppet/2.6.4-2ubuntu2.7 -------------- next part -------------- Format: 1.8 Date: Fri, 10 Feb 2012 05:58:07 -0600 Source: puppet Binary: puppet-common puppet puppetmaster-common puppetmaster puppetmaster-passenger vim-puppet puppet-el puppet-testsuite Architecture: source Version: 2.6.4-2ubuntu2.7 Distribution: natty-security Urgency: low Maintainer: Ubuntu Developers Changed-By: Jamie Strandboge Description: puppet - Centralized configuration management - agent startup and compatib puppet-common - Centralized configuration management puppet-el - syntax highlighting for puppet manifests in emacs puppet-testsuite - Centralized configuration management - test suite puppetmaster - Centralized configuration management - master startup and compati puppetmaster-common - Puppet master common scripts puppetmaster-passenger - Centralised configuration management - master setup to run under vim-puppet - syntax highlighting for puppet manifests in vim Changes: puppet (2.6.4-2ubuntu2.7) natty-security; urgency=low . * SECURITY UPDATE: fix access to remote resource when auth.conf is missing which was was reintroduced in 2.6.4-2ubuntu1. - debian/patches/CVE-2011-0528.patch: Disable remote ralsh by default - CVE-2011-0528 Checksums-Sha1: 09ca08bbde54904d9af58e6a7a505d77d9eb4902 2296 puppet_2.6.4-2ubuntu2.7.dsc 34646870a18eaa550238aaa2c3398e07e5aa293d 87734 puppet_2.6.4-2ubuntu2.7.debian.tar.gz Checksums-Sha256: 1ac13a8ab97d0b3379141519e1f11157897611f2eb2f6f6fd5a7ab049bed5004 2296 puppet_2.6.4-2ubuntu2.7.dsc 1f98c121ac03490e549d79978f56283975493aa509085959610b99f9347de224 87734 puppet_2.6.4-2ubuntu2.7.debian.tar.gz Files: c56eb063f842f7841dd86398e330e29e 2296 admin optional puppet_2.6.4-2ubuntu2.7.dsc 0f5a997b98056eb97e7e2e8cf8c1ed1f 87734 admin optional puppet_2.6.4-2ubuntu2.7.debian.tar.gz Original-Maintainer: Puppet Package Maintainers From amoog at ubuntu.com Wed Feb 15 16:03:58 2012 From: amoog at ubuntu.com (Andreas Moog) Date: Wed, 15 Feb 2012 16:03:58 -0000 Subject: [ubuntu/natty-security] gypsy 0.8-0ubuntu2.1 (Accepted) Message-ID: <20120215160358.7396.35860.launchpad@cocoplum.canonical.com> gypsy (0.8-0ubuntu2.1) natty-security; urgency=low * SECURITY UPDATE: "arbitrary file access and buffer overflows" A new config file, /etc/gypsy.conf, is added that specifies a whitelist of globs. By default, they are "/dev/tty*", "/dev/pgps", and "bluetooth" (which matches Bluetooth addresses). Thanks to Michael Leibowitz CVE-2011-0523 * SECURITY UPDATE: Prevent buffer overflows in NMEA parsing by using snprintf() instead of sprintf. Thanks to Bastien Nocera CVE-2011-0524 (LP: #690323) * Run autoreconf to include changes to configure.ac Date: Sat, 11 Feb 2012 15:59:26 +0100 Changed-By: Andreas Moog Maintainer: Ubuntu Developers https://launchpad.net/ubuntu/natty/+source/gypsy/0.8-0ubuntu2.1 -------------- next part -------------- Format: 1.8 Date: Sat, 11 Feb 2012 15:59:26 +0100 Source: gypsy Binary: gypsy-daemon libgypsy0 libgypsy-dev libgypsy-doc Architecture: source Version: 0.8-0ubuntu2.1 Distribution: natty-security Urgency: low Maintainer: Ubuntu Developers Changed-By: Andreas Moog Description: gypsy-daemon - A GPS Multiplexing Daemon libgypsy-dev - A GPS Multiplexing Daemon (Development Package) libgypsy-doc - A GPS Multiplexing Daemon (HTML API Docs) libgypsy0 - A GPS Multiplexing Daemon (Library Package) Launchpad-Bugs-Fixed: 690323 Changes: gypsy (0.8-0ubuntu2.1) natty-security; urgency=low . * SECURITY UPDATE: "arbitrary file access and buffer overflows" A new config file, /etc/gypsy.conf, is added that specifies a whitelist of globs. By default, they are "/dev/tty*", "/dev/pgps", and "bluetooth" (which matches Bluetooth addresses). Thanks to Michael Leibowitz CVE-2011-0523 * SECURITY UPDATE: Prevent buffer overflows in NMEA parsing by using snprintf() instead of sprintf. Thanks to Bastien Nocera CVE-2011-0524 (LP: #690323) * Run autoreconf to include changes to configure.ac Checksums-Sha1: 29dd6ea90a464536b03fed681184bec3240aad7b 1840 gypsy_0.8-0ubuntu2.1.dsc 4fa09fe43fe0afb43efe302b21504df9ffd837fb 22878 gypsy_0.8-0ubuntu2.1.debian.tar.gz Checksums-Sha256: 4b103e856cfbabfe5e261451a00a85fd9e67d2e1d1d8638bfe94f6d10c3cbf26 1840 gypsy_0.8-0ubuntu2.1.dsc e1182c6d2ca75be8e918bc5481edcef09adb998b45ae72273e975f5bff393321 22878 gypsy_0.8-0ubuntu2.1.debian.tar.gz Files: e05e5ad060c5c1b89067acd8b9633ae1 1840 utils optional gypsy_0.8-0ubuntu2.1.dsc 5b2a13209a85479af8980aaa49b13b6e 22878 utils optional gypsy_0.8-0ubuntu2.1.debian.tar.gz Original-Maintainer: Linaro User Platforms From zubin.mithra at gmail.com Wed Feb 15 16:04:06 2012 From: zubin.mithra at gmail.com (Zubin Mithra) Date: Wed, 15 Feb 2012 16:04:06 -0000 Subject: [ubuntu/natty-security] dhcpcd 1:3.2.3-7ubuntu0.11.04.1 (Accepted) Message-ID: <20120215160406.7396.74044.launchpad@cocoplum.canonical.com> dhcpcd (1:3.2.3-7ubuntu0.11.04.1) natty-security; urgency=high * SECURITY UPDATE: dhcpcd before 5.2.12 allows remote attackers to execute arbitrary commands via shell metacharacters in a hostname obtained from a DHCP message. (LP: #931036) - https://build.opensuse.org/package/view_file?file=dhcpcd-3.2.3-option-checks.diff&package=dhcpcd&project=network%3Adhcp&rev=52442e5c1d803d7c1818a920a0bae7f1 - above linked patch(without the additional support for NETBIOS type messages) has been added. - CVE-2011-0996 Date: Mon, 13 Feb 2012 14:27:54 +0530 Changed-By: Zubin Mithra Maintainer: Ubuntu Developers https://launchpad.net/ubuntu/natty/+source/dhcpcd/1:3.2.3-7ubuntu0.11.04.1 -------------- next part -------------- Format: 1.8 Date: Mon, 13 Feb 2012 14:27:54 +0530 Source: dhcpcd Binary: dhcpcd Architecture: source Version: 1:3.2.3-7ubuntu0.11.04.1 Distribution: natty-security Urgency: high Maintainer: Ubuntu Developers Changed-By: Zubin Mithra Description: dhcpcd - DHCP client for automatically configuring IPv4 networking Launchpad-Bugs-Fixed: 931036 Changes: dhcpcd (1:3.2.3-7ubuntu0.11.04.1) natty-security; urgency=high . * SECURITY UPDATE: dhcpcd before 5.2.12 allows remote attackers to execute arbitrary commands via shell metacharacters in a hostname obtained from a DHCP message. (LP: #931036) - https://build.opensuse.org/package/view_file?file=dhcpcd-3.2.3-option-checks.diff&package=dhcpcd&project=network%3Adhcp&rev=52442e5c1d803d7c1818a920a0bae7f1 - above linked patch(without the additional support for NETBIOS type messages) has been added. - CVE-2011-0996 Checksums-Sha1: 5c234a218f2929741f656eb83235cdf58fe059f9 1724 dhcpcd_3.2.3-7ubuntu0.11.04.1.dsc 06334ece16a319ac0c60135c13584d9aacd3acc9 19548 dhcpcd_3.2.3-7ubuntu0.11.04.1.diff.gz Checksums-Sha256: 4b58778747415291267ed2acb1369ed4eef976c1b57d00d91f031fb67eaa85da 1724 dhcpcd_3.2.3-7ubuntu0.11.04.1.dsc 90a452596d6daca89ee8c924ced5ca932348a7352591d37a2016bd96cacf8a0f 19548 dhcpcd_3.2.3-7ubuntu0.11.04.1.diff.gz Files: 6f29f7bc69ccabbec76a4519f410504e 1724 net optional dhcpcd_3.2.3-7ubuntu0.11.04.1.dsc cbdc6df86078379b663aebcfd8756d6e 19548 net optional dhcpcd_3.2.3-7ubuntu0.11.04.1.diff.gz Original-Maintainer: Simon Kelley From tyhicks at canonical.com Wed Feb 15 17:03:30 2012 From: tyhicks at canonical.com (Tyler Hicks) Date: Wed, 15 Feb 2012 17:03:30 -0000 Subject: [ubuntu/natty-security] devscripts_2.10.69ubuntu2.1_armel_translations.tar.gz, devscripts, devscripts_2.10.69ubuntu2.1_powerpc_translations.tar.gz, devscripts_2.10.69ubuntu2.1_i386_translations.tar.gz, devscripts_2.10.69ubuntu2.1_amd64_translations.tar.gz 2.10.69ubuntu2.1 (Accepted) Message-ID: <20120215170330.29188.23117.launchpad@cocoplum.canonical.com> devscripts (2.10.69ubuntu2.1) natty-security; urgency=low * SECURITY UPDATE: Arbitrary code execution via crafted filenames in .dsc and .changes files - scripts/debdiff.pl: Perform input sanitization on filenames. Thanks to Raphael Geissert for the original patch. - CVE-2012-0210 * SECURITY UPDATE: Arbitrary code execution via crafted filenames in the top level directory of the original upstream source tarball - scripts/debdiff.pl: Perform input sanitization on filenames. Thanks to Adam D. Barratt for the original patch. - CVE-2012-0211 * SECURITY UPDATE: Arbritray code execution via crafted filenames in arguments passed to debdiff - scripts/debdiff.pl: Perform input sanitization on filenames. Based on upstream patches. - http://anonscm.debian.org/gitweb/?p=devscripts/devscripts.git;a=commitdiff;h=87f88232eb643f0c118c6ba38db8e966915b450f - http://anonscm.debian.org/gitweb/?p=devscripts/devscripts.git;a=commitdiff;h=76227af1ee8d68f4844f642325eac903ca21e739 - CVE-2012-0212 * scripts/debdiff.pl: Remove undocumented functionality which treated files with extentionless filenames as packages. Thanks to Adam D. Barratt for the original patch. - http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=659559 Date: Wed, 15 Feb 2012 03:33:44 -0600 Changed-By: Tyler Hicks Maintainer: Ubuntu Developers https://launchpad.net/ubuntu/natty/+source/devscripts/2.10.69ubuntu2.1 -------------- next part -------------- Format: 1.8 Date: Wed, 15 Feb 2012 03:33:44 -0600 Source: devscripts Binary: devscripts Architecture: source Version: 2.10.69ubuntu2.1 Distribution: natty-security Urgency: low Maintainer: Ubuntu Developers Changed-By: Tyler Hicks Description: devscripts - scripts to make the life of a Debian Package maintainer easier Changes: devscripts (2.10.69ubuntu2.1) natty-security; urgency=low . * SECURITY UPDATE: Arbitrary code execution via crafted filenames in .dsc and .changes files - scripts/debdiff.pl: Perform input sanitization on filenames. Thanks to Raphael Geissert for the original patch. - CVE-2012-0210 * SECURITY UPDATE: Arbitrary code execution via crafted filenames in the top level directory of the original upstream source tarball - scripts/debdiff.pl: Perform input sanitization on filenames. Thanks to Adam D. Barratt for the original patch. - CVE-2012-0211 * SECURITY UPDATE: Arbritray code execution via crafted filenames in arguments passed to debdiff - scripts/debdiff.pl: Perform input sanitization on filenames. Based on upstream patches. - http://anonscm.debian.org/gitweb/?p=devscripts/devscripts.git;a=commitdiff;h=87f88232eb643f0c118c6ba38db8e966915b450f - http://anonscm.debian.org/gitweb/?p=devscripts/devscripts.git;a=commitdiff;h=76227af1ee8d68f4844f642325eac903ca21e739 - CVE-2012-0212 * scripts/debdiff.pl: Remove undocumented functionality which treated files with extentionless filenames as packages. Thanks to Adam D. Barratt for the original patch. - http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=659559 Checksums-Sha1: 991c033a5e7c7321e518a6a5cebe99ff0acb6de1 2220 devscripts_2.10.69ubuntu2.1.dsc c005960c80df7f0750bd427fd977107a9953472c 741257 devscripts_2.10.69ubuntu2.1.tar.gz Checksums-Sha256: 9ef44f2b409fe1b79807e3654c01ce39976af888ca2d76b69814147daa4f33fb 2220 devscripts_2.10.69ubuntu2.1.dsc c0bf85f4b07a865cc98644e8226cbe4e07562c88df92c14f881d57b24522df2e 741257 devscripts_2.10.69ubuntu2.1.tar.gz Files: 1b14686c2a16c342c9aee3b0043116e5 2220 devel optional devscripts_2.10.69ubuntu2.1.dsc d72687d8587860e4f8eb852a0c2612a1 741257 devel optional devscripts_2.10.69ubuntu2.1.tar.gz Original-Maintainer: Devscripts Devel Team From chris.coulson at canonical.com Wed Feb 15 22:00:56 2012 From: chris.coulson at canonical.com (Chris Coulson) Date: Wed, 15 Feb 2012 22:00:56 -0000 Subject: [ubuntu/natty] adobe-flashplugin 11.1.102.62-0natty1 (Accepted) Message-ID: <20120215220056.11200.63105.launchpad@cocoplum.canonical.com> adobe-flashplugin (11.1.102.62-0natty1) natty; urgency=low * Initial release of 11.1.102.62 for Natty Date: Wed, 15 Feb 2012 21:29:24 +0000 Changed-By: Chris Coulson Maintainer: DL-Flash Player Ubuntu https://launchpad.net/ubuntu/natty/+source/adobe-flashplugin/11.1.102.62-0natty1 -------------- next part -------------- -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Format: 1.8 Date: Wed, 15 Feb 2012 21:29:24 +0000 Source: adobe-flashplugin Binary: adobe-flashplugin adobe-flash-properties-gtk adobe-flash-properties-kde Architecture: source Version: 11.1.102.62-0natty1 Distribution: natty Urgency: low Maintainer: DL-Flash Player Ubuntu Changed-By: Chris Coulson Description: adobe-flash-properties-gtk - GTK+ control panel for Adobe Flash Player plugin version 11 adobe-flash-properties-kde - KDE control panel Adobe Flash Player plugin version 11 adobe-flashplugin - Adobe Flash Player plugin version 11 Changes: adobe-flashplugin (11.1.102.62-0natty1) natty; urgency=low . * Initial release of 11.1.102.62 for Natty Checksums-Sha1: 268477bc9a586c3962d6b1096cd9176e33895fad 1724 adobe-flashplugin_11.1.102.62-0natty1.dsc 07ba933fbd44828553191e01c1cd79a0e6ce398b 4687 adobe-flashplugin_11.1.102.62-0natty1.diff.gz Checksums-Sha256: 896ec7571f14f6301267582de5c91ca30b29c7d9834511303892d45541ca0bc5 1724 adobe-flashplugin_11.1.102.62-0natty1.dsc 4d776ee75839c2a8b5c610e20335b686d36b85005936ed9f9d083f484133933e 4687 adobe-flashplugin_11.1.102.62-0natty1.diff.gz Files: 579058410dea5f24e34913d745cef68e 1724 partner/web optional adobe-flashplugin_11.1.102.62-0natty1.dsc 8c5aab13ac82d383d3a8179c7035821b 4687 partner/web optional adobe-flashplugin_11.1.102.62-0natty1.diff.gz -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.11 (GNU/Linux) iQEcBAEBAgAGBQJPPCPeAAoJEGEfvezVlG4Pm6MH/1l1ijboq4h0fRMVMg3G9Ogu 6pG7iZoemCnN4hSk5AORZpFxfpEZGd9va6+nraqAD+/j0tVidXgM2TO4vFqwP6wY 9NWJx6lTLm6CLFdYoo4+u6YVhnMKGxEwhdMJNXNiBWhgtOFkfJV1JBMkIk15hV2n 5wR9ml9gUvCOwzp8WMqxwwDc0rl/1Ne9Kfrkzo+GDcFSDZhY45YG/9834dljxWcw kDfctKrOF4vOKVcz6suROZuLGtJ66ULJvx16Piz8HkSE+VaulL1haXCJsjI/jHAi MndGLFUDjMC7Pb414Yb4X837ypKSkHfrbyrJMKLkdKfms7P3qDp45XqlZThoIWY= =H1OY -----END PGP SIGNATURE----- From marc.deslauriers at ubuntu.com Thu Feb 16 01:33:54 2012 From: marc.deslauriers at ubuntu.com (Marc Deslauriers) Date: Thu, 16 Feb 2012 01:33:54 -0000 Subject: [ubuntu/natty-security] flashplugin-nonfree, flashplugin-nonfree_11.1.102.62ubuntu0.11.04.1_i386_translations.tar.gz, flashplugin-nonfree_11.1.102.62ubuntu0.11.04.1_amd64_translations.tar.gz 11.1.102.62ubuntu0.11.04.1 (Accepted) Message-ID: <20120216013354.28932.19529.launchpad@cocoplum.canonical.com> flashplugin-nonfree (11.1.102.62ubuntu0.11.04.1) natty-security; urgency=low * New upstream release 11.1.102.62 - debian/{config,postinst}: Updated version and sha256sums. - CVE-2012-0752 - CVE-2012-0753 - CVE-2012-0754 - CVE-2012-0755 - CVE-2012-0756 - CVE-2012-0757 * Add native amd64 support (LP: #870835): - debian/control: clean up depends, remove lpia, update description. Adjust Homepage. - debian/postinst: use $DPKG_MAINTSCRIPT_ARCH to copy the right binary, remove old nspluginwrapper alternatives. - debian/rules: remove nspluginwrapper files. - debian/{config,postinst,prerm}: remove flashplugin-installer-unpackdir directory migration, this was before hardy. Date: Wed, 15 Feb 2012 17:42:24 -0500 Changed-By: Marc Deslauriers Maintainer: Ubuntu Developers https://launchpad.net/ubuntu/natty/+source/flashplugin-nonfree/11.1.102.62ubuntu0.11.04.1 -------------- next part -------------- Format: 1.8 Date: Wed, 15 Feb 2012 17:42:24 -0500 Source: flashplugin-nonfree Binary: flashplugin-installer flashplugin-nonfree Architecture: source Version: 11.1.102.62ubuntu0.11.04.1 Distribution: natty-security Urgency: low Maintainer: Ubuntu Developers Changed-By: Marc Deslauriers Description: flashplugin-installer - Adobe Flash Player plugin installer flashplugin-nonfree - Adobe Flash Player plugin installer (transitional package) Launchpad-Bugs-Fixed: 870835 Changes: flashplugin-nonfree (11.1.102.62ubuntu0.11.04.1) natty-security; urgency=low . * New upstream release 11.1.102.62 - debian/{config,postinst}: Updated version and sha256sums. - CVE-2012-0752 - CVE-2012-0753 - CVE-2012-0754 - CVE-2012-0755 - CVE-2012-0756 - CVE-2012-0757 * Add native amd64 support (LP: #870835): - debian/control: clean up depends, remove lpia, update description. Adjust Homepage. - debian/postinst: use $DPKG_MAINTSCRIPT_ARCH to copy the right binary, remove old nspluginwrapper alternatives. - debian/rules: remove nspluginwrapper files. - debian/{config,postinst,prerm}: remove flashplugin-installer-unpackdir directory migration, this was before hardy. Checksums-Sha1: 8212e216dc36c3d48bc2e6a258009d64e2ad39c6 1645 flashplugin-nonfree_11.1.102.62ubuntu0.11.04.1.dsc 984d14cbda738221697b7b002a1fe4445fb7174a 27481 flashplugin-nonfree_11.1.102.62ubuntu0.11.04.1.tar.gz Checksums-Sha256: 9f282ce435512bdfd4026c6505c13dbab800425d333e458ceeebe650ece109c1 1645 flashplugin-nonfree_11.1.102.62ubuntu0.11.04.1.dsc 3e095022e18d7b757f0bd63283d077bf994804cb060f3a7dc280ee2815612804 27481 flashplugin-nonfree_11.1.102.62ubuntu0.11.04.1.tar.gz Files: 7401e6d4bd2654c2ad4759febaae545f 1645 contrib/web optional flashplugin-nonfree_11.1.102.62ubuntu0.11.04.1.dsc 0caddc2bb2adb7d9a903dde8865f4de4 27481 contrib/web optional flashplugin-nonfree_11.1.102.62ubuntu0.11.04.1.tar.gz Original-Maintainer: Bart Martens From jamie at ubuntu.com Thu Feb 16 18:34:19 2012 From: jamie at ubuntu.com (Jamie Strandboge) Date: Thu, 16 Feb 2012 18:34:19 -0000 Subject: [ubuntu/natty-security] libpng 1.2.44-1ubuntu3.2 (Accepted) Message-ID: <20120216183419.23778.35991.launchpad@cocoplum.canonical.com> libpng (1.2.44-1ubuntu3.2) natty-security; urgency=low * SECURITY UPDATE: fix integer overflow / truncation - debian/patches/05-CVE-2011-3026.patch: adjust pngrutil.c to verify size when allocating memory in png_decompress_chunk() - CVE-2011-3026 Date: Wed, 15 Feb 2012 21:16:54 -0600 Changed-By: Jamie Strandboge Maintainer: Ubuntu Developers https://launchpad.net/ubuntu/natty/+source/libpng/1.2.44-1ubuntu3.2 -------------- next part -------------- Format: 1.8 Date: Wed, 15 Feb 2012 21:16:54 -0600 Source: libpng Binary: libpng12-0 libpng12-dev libpng3 libpng12-0-udeb Architecture: source Version: 1.2.44-1ubuntu3.2 Distribution: natty-security Urgency: low Maintainer: Ubuntu Developers Changed-By: Jamie Strandboge Description: libpng12-0 - PNG library - runtime libpng12-0-udeb - PNG library - minimal runtime library (udeb) libpng12-dev - PNG library - development libpng3 - PNG library - runtime Changes: libpng (1.2.44-1ubuntu3.2) natty-security; urgency=low . * SECURITY UPDATE: fix integer overflow / truncation - debian/patches/05-CVE-2011-3026.patch: adjust pngrutil.c to verify size when allocating memory in png_decompress_chunk() - CVE-2011-3026 Checksums-Sha1: 845bc5f403723e303741a1c8303202b6ff579c96 1950 libpng_1.2.44-1ubuntu3.2.dsc 79aecebd52098f46af0171ffdb43b1343c050b0b 17094 libpng_1.2.44-1ubuntu3.2.debian.tar.bz2 Checksums-Sha256: 8e1cb3475fc7e4d8c8434bf5eea1b00f8530c830951702fd134cfe362dae102e 1950 libpng_1.2.44-1ubuntu3.2.dsc 0f0ed838756f7251a5db5f68390c78640940830a5236a2f5b93232d7de367e5d 17094 libpng_1.2.44-1ubuntu3.2.debian.tar.bz2 Files: 143f134fe43f19dc8920f378eadd8b1e 1950 libs optional libpng_1.2.44-1ubuntu3.2.dsc 5e9cca7451530e2c4cfe04170da0d154 17094 libs optional libpng_1.2.44-1ubuntu3.2.debian.tar.bz2 Original-Maintainer: Anibal Monsalve Salazar From marc.deslauriers at ubuntu.com Thu Feb 16 18:34:53 2012 From: marc.deslauriers at ubuntu.com (Marc Deslauriers) Date: Thu, 16 Feb 2012 18:34:53 -0000 Subject: [ubuntu/natty-security] update-manager, update-manager_0.150.5.2_i386_translations.tar.gz, update-manager_0.150.5.2_amd64_translations.tar.gz, update-manager_0.150.5.2_armel_translations.tar.gz, update-manager_0.150.5.2_powerpc_translations.tar.gz, dist-upgrader_0.150.5.2_all.tar.gz 1:0.150.5.2 (Accepted) Message-ID: <20120216183453.23778.29591.launchpad@cocoplum.canonical.com> update-manager (1:0.150.5.2) natty-security; urgency=low * REGRESSION FIX: - DistUpgrade/DistUpgradeViewKDE.py: fix regression caused by improper return value handling. (LP: #933225) Date: Wed, 15 Feb 2012 22:43:43 -0500 Changed-By: Marc Deslauriers Maintainer: Michael Vogt https://launchpad.net/ubuntu/natty/+source/update-manager/1:0.150.5.2 -------------- next part -------------- Format: 1.8 Date: Wed, 15 Feb 2012 22:43:43 -0500 Source: update-manager Binary: update-manager-core update-manager update-manager-text update-manager-kde auto-upgrade-tester Architecture: source Version: 1:0.150.5.2 Distribution: natty-security Urgency: low Maintainer: Michael Vogt Changed-By: Marc Deslauriers Description: auto-upgrade-tester - Test release upgrades in a virtual environment update-manager - GNOME application that manages apt updates update-manager-core - manage release upgrades update-manager-kde - Support modules for KPackageKit update-manager-text - Text application that manages apt updates Launchpad-Bugs-Fixed: 933225 Changes: update-manager (1:0.150.5.2) natty-security; urgency=low . * REGRESSION FIX: - DistUpgrade/DistUpgradeViewKDE.py: fix regression caused by improper return value handling. (LP: #933225) Checksums-Sha1: 61abd319af83d97853d2b89170aee751fe00d445 1781 update-manager_0.150.5.2.dsc b2dad7f52e4f9aba1ceeda1798205656aec7f14a 2940696 update-manager_0.150.5.2.tar.gz Checksums-Sha256: 7f354039bd6afe165d0748b685bd7762595f161fe59d71798eb980a0121e7f56 1781 update-manager_0.150.5.2.dsc 5c3f5d5b0d24b88997d7a6d206b65afc7886ed06b3ef8eac8aa0ff24943e6623 2940696 update-manager_0.150.5.2.tar.gz Files: 88924928ebece008028341b50c711ca5 1781 gnome optional update-manager_0.150.5.2.dsc 1e8a94970279233ab802956419dc0336 2940696 gnome optional update-manager_0.150.5.2.tar.gz From marc.deslauriers at ubuntu.com Thu Feb 16 19:34:15 2012 From: marc.deslauriers at ubuntu.com (Marc Deslauriers) Date: Thu, 16 Feb 2012 19:34:15 -0000 Subject: [ubuntu/natty-security] apache2 2.2.17-1ubuntu1.5 (Accepted) Message-ID: <20120216193415.14530.70094.launchpad@cocoplum.canonical.com> apache2 (2.2.17-1ubuntu1.5) natty-security; urgency=low * SECURITY UPDATE: arbitrary code execution via crafted SetEnvIf directive (LP: #811422) - debian/patches/215_CVE-2011-3607.dpatch: validate length in server/util.c. - CVE-2011-3607 * SECURITY UPDATE: another mod_proxy reverse proxy exposure - debian/patches/216_CVE-2011-4317.dpatch: validate additional URIs in modules/mappers/mod_rewrite.c, modules/proxy/mod_proxy.c, server/protocol.c. - CVE-2011-4317 * SECURITY UPDATE: denial of service via invalid cookie - debian/patches/217_CVE-2012-0021.dpatch: check name and value in modules/loggers/mod_log_config.c. - CVE-2012-0021 * SECURITY UPDATE: denial of service and possible code execution via type field modification within a scoreboard shared memory segment - debian/patches/218_CVE-2012-0031.dpatch: check type field in server/scoreboard.c. - CVE-2012-0031 * SECURITY UPDATE: cookie disclosure via Bad Request errors - debian/patches/219_CVE-2012-0053.dpatch: check lengths in server/protocol.c. - CVE-2012-0053 Date: Tue, 14 Feb 2012 10:02:26 -0500 Changed-By: Marc Deslauriers Maintainer: Ubuntu Developers https://launchpad.net/ubuntu/natty/+source/apache2/2.2.17-1ubuntu1.5 -------------- next part -------------- Format: 1.8 Date: Tue, 14 Feb 2012 10:02:26 -0500 Source: apache2 Binary: apache2.2-common apache2.2-bin apache2-mpm-worker apache2-mpm-prefork apache2-mpm-event apache2-mpm-itk apache2-utils apache2-suexec apache2-suexec-custom apache2 apache2-doc apache2-prefork-dev apache2-threaded-dev apache2-dbg Architecture: source Version: 2.2.17-1ubuntu1.5 Distribution: natty-security Urgency: low Maintainer: Ubuntu Developers Changed-By: Marc Deslauriers Description: apache2 - Apache HTTP Server metapackage apache2-dbg - Apache debugging symbols apache2-doc - Apache HTTP Server documentation apache2-mpm-event - Apache HTTP Server - event driven model apache2-mpm-itk - multiuser MPM for Apache 2.2 apache2-mpm-prefork - Apache HTTP Server - traditional non-threaded model apache2-mpm-worker - Apache HTTP Server - high speed threaded model apache2-prefork-dev - Apache development headers - non-threaded MPM apache2-suexec - Standard suexec program for Apache 2 mod_suexec apache2-suexec-custom - Configurable suexec program for Apache 2 mod_suexec apache2-threaded-dev - Apache development headers - threaded MPM apache2-utils - utility programs for webservers apache2.2-bin - Apache HTTP Server common binary files apache2.2-common - Apache HTTP Server common files Launchpad-Bugs-Fixed: 811422 Changes: apache2 (2.2.17-1ubuntu1.5) natty-security; urgency=low . * SECURITY UPDATE: arbitrary code execution via crafted SetEnvIf directive (LP: #811422) - debian/patches/215_CVE-2011-3607.dpatch: validate length in server/util.c. - CVE-2011-3607 * SECURITY UPDATE: another mod_proxy reverse proxy exposure - debian/patches/216_CVE-2011-4317.dpatch: validate additional URIs in modules/mappers/mod_rewrite.c, modules/proxy/mod_proxy.c, server/protocol.c. - CVE-2011-4317 * SECURITY UPDATE: denial of service via invalid cookie - debian/patches/217_CVE-2012-0021.dpatch: check name and value in modules/loggers/mod_log_config.c. - CVE-2012-0021 * SECURITY UPDATE: denial of service and possible code execution via type field modification within a scoreboard shared memory segment - debian/patches/218_CVE-2012-0031.dpatch: check type field in server/scoreboard.c. - CVE-2012-0031 * SECURITY UPDATE: cookie disclosure via Bad Request errors - debian/patches/219_CVE-2012-0053.dpatch: check lengths in server/protocol.c. - CVE-2012-0053 Checksums-Sha1: e4e1dc71cee170a0e160ed4108a9ef60135d57b1 2628 apache2_2.2.17-1ubuntu1.5.dsc 582c04c9ff7ab5b89df81973ee43cef4adad6bf3 223915 apache2_2.2.17-1ubuntu1.5.diff.gz Checksums-Sha256: aa5c0067fd08661fdfceb4962661374b6b6d2f6ce84df403f29ab672c26fd315 2628 apache2_2.2.17-1ubuntu1.5.dsc 897899394ed7508ef6bcfc9e4a2a9db986bf1690bb3d6e1388d6d6ea6dbbc2a5 223915 apache2_2.2.17-1ubuntu1.5.diff.gz Files: f7de2db659a2bc35b6715b0777bd326d 2628 httpd optional apache2_2.2.17-1ubuntu1.5.dsc 72bdf20cbd670e16cec108202461e189 223915 httpd optional apache2_2.2.17-1ubuntu1.5.diff.gz Original-Maintainer: Debian Apache Maintainers Original-Vcs-Browser: http://svn.debian.org/wsvn/pkg-apache/trunk/apache2 Original-Vcs-Svn: svn://svn.debian.org/pkg-apache/trunk/apache2 From marc.deslauriers at ubuntu.com Fri Feb 17 02:33:35 2012 From: marc.deslauriers at ubuntu.com (Marc Deslauriers) Date: Fri, 17 Feb 2012 02:33:35 -0000 Subject: [ubuntu/natty-security] flashplugin-nonfree, flashplugin-nonfree_11.1.102.62ubuntu0.11.04.2_i386_translations.tar.gz, flashplugin-nonfree_11.1.102.62ubuntu0.11.04.2_amd64_translations.tar.gz 11.1.102.62ubuntu0.11.04.2 (Accepted) Message-ID: <20120217023335.32154.22099.launchpad@cocoplum.canonical.com> flashplugin-nonfree (11.1.102.62ubuntu0.11.04.2) natty-security; urgency=low * Fix use of dpkg-reconfigure by not using $DPKG_MAINTSCRIPT_ARCH (LP: #933484) - debian/postinst.in: renamed from postinst and replaced $DPKG_MAINTSCRIPT_ARCH with #ARCH#. - debian/rules: replace #ARCH# in postinst.in with $DEB_HOST_ARCH during build. - debian/prerm: also clean out subdirectories in /var/cache/flashplugin-installer. * postinst.in: use "mega" style by default so we stop filling up log files. (LP: #872723) Date: Thu, 16 Feb 2012 18:56:47 -0500 Changed-By: Marc Deslauriers Maintainer: Ubuntu Developers https://launchpad.net/ubuntu/natty/+source/flashplugin-nonfree/11.1.102.62ubuntu0.11.04.2 -------------- next part -------------- Format: 1.8 Date: Thu, 16 Feb 2012 18:56:47 -0500 Source: flashplugin-nonfree Binary: flashplugin-installer flashplugin-nonfree Architecture: source Version: 11.1.102.62ubuntu0.11.04.2 Distribution: natty-security Urgency: low Maintainer: Ubuntu Developers Changed-By: Marc Deslauriers Description: flashplugin-installer - Adobe Flash Player plugin installer flashplugin-nonfree - Adobe Flash Player plugin installer (transitional package) Launchpad-Bugs-Fixed: 872723 933484 Changes: flashplugin-nonfree (11.1.102.62ubuntu0.11.04.2) natty-security; urgency=low . * Fix use of dpkg-reconfigure by not using $DPKG_MAINTSCRIPT_ARCH (LP: #933484) - debian/postinst.in: renamed from postinst and replaced $DPKG_MAINTSCRIPT_ARCH with #ARCH#. - debian/rules: replace #ARCH# in postinst.in with $DEB_HOST_ARCH during build. - debian/prerm: also clean out subdirectories in /var/cache/flashplugin-installer. * postinst.in: use "mega" style by default so we stop filling up log files. (LP: #872723) Checksums-Sha1: e4f66bc8dfce9d8b42f6a60eb3299fee283b2576 1645 flashplugin-nonfree_11.1.102.62ubuntu0.11.04.2.dsc ff5b4f474f73c9ae7bc49936d1d6f2cf07f3f528 27364 flashplugin-nonfree_11.1.102.62ubuntu0.11.04.2.tar.gz Checksums-Sha256: 69eb22cf50487140c1ae08245c2f152ff9c09d06b61fa11e89ca4438c1dd1358 1645 flashplugin-nonfree_11.1.102.62ubuntu0.11.04.2.dsc 049e7ec9352610de52f65b931138fa3ab900de30268eae95652d82c09773904b 27364 flashplugin-nonfree_11.1.102.62ubuntu0.11.04.2.tar.gz Files: 55009150a9e38b67ba8112cbb33c96bd 1645 contrib/web optional flashplugin-nonfree_11.1.102.62ubuntu0.11.04.2.dsc c57c90032d06b366e717aea3a8dce145 27364 contrib/web optional flashplugin-nonfree_11.1.102.62ubuntu0.11.04.2.tar.gz Original-Maintainer: Bart Martens From jtaylor at ubuntu.com Fri Feb 17 09:39:42 2012 From: jtaylor at ubuntu.com (Julian Taylor) Date: Fri, 17 Feb 2012 09:39:42 -0000 Subject: [ubuntu/natty-proposed] python-networkx 1.1-2ubuntu0.11.04.1 (Accepted) Message-ID: <20120217093942.20621.67821.launchpad@wampee.canonical.com> python-networkx (1.1-2ubuntu0.11.04.1) natty-proposed; urgency=low * debian/patches/30_no_setuptools_in_requires.txt - don't add setuptools to requires.txt; allows import with pkg_resources.require('networkx') like e.g. epigrass does (LP: #925744) * move python-numpy from Recommend to Depend - required to import networkx, used in current_flow_closeness.py Date: Fri, 03 Feb 2012 20:56:52 +0100 Changed-By: Julian Taylor Maintainer: Ubuntu Developers https://launchpad.net/ubuntu/natty/+source/python-networkx/1.1-2ubuntu0.11.04.1 -------------- next part -------------- Format: 1.8 Date: Fri, 03 Feb 2012 20:56:52 +0100 Source: python-networkx Binary: python-networkx Architecture: source Version: 1.1-2ubuntu0.11.04.1 Distribution: natty-proposed Urgency: low Maintainer: Ubuntu Developers Changed-By: Julian Taylor Description: python-networkx - tool to create, manipulate and study complex networks Launchpad-Bugs-Fixed: 925744 Changes: python-networkx (1.1-2ubuntu0.11.04.1) natty-proposed; urgency=low . * debian/patches/30_no_setuptools_in_requires.txt - don't add setuptools to requires.txt; allows import with pkg_resources.require('networkx') like e.g. epigrass does (LP: #925744) * move python-numpy from Recommend to Depend - required to import networkx, used in current_flow_closeness.py Checksums-Sha1: 1cb4592955001a3bc2c5b902e5ffe90b5958a868 2200 python-networkx_1.1-2ubuntu0.11.04.1.dsc 8194c1e735568874dbb8e91f8b8f3bc48c811737 10200 python-networkx_1.1-2ubuntu0.11.04.1.debian.tar.gz Checksums-Sha256: 97c6ed2326cdfa959247083589de552317a48643a9623b8bde1581468474cfd1 2200 python-networkx_1.1-2ubuntu0.11.04.1.dsc 9b7287d9371ad36254ce2d543812f1c27ac3969554160e1ab2860a425556332a 10200 python-networkx_1.1-2ubuntu0.11.04.1.debian.tar.gz Files: a98159def82b7eb54dd2a9c38100352a 2200 python optional python-networkx_1.1-2ubuntu0.11.04.1.dsc 41bcaa5bc54bb9a994dae060db68dd3c 10200 python optional python-networkx_1.1-2ubuntu0.11.04.1.debian.tar.gz Original-Maintainer: Debian Python Modules Team From l3on at ubuntu.com Fri Feb 17 09:40:03 2012 From: l3on at ubuntu.com (Leo Iannacone) Date: Fri, 17 Feb 2012 09:40:03 -0000 Subject: [ubuntu/natty-proposed] gdevilspie 1:0.5-1ubuntu0.11.04.1 (Accepted) Message-ID: <20120217094003.29608.92722.launchpad@soybean.canonical.com> gdevilspie (1:0.5-1ubuntu0.11.04.1) natty-proposed; urgency=low * Add depends on python-glade2, recommend python-xdg (LP: #783568, closes: #628492) Date: Tue, 17 Jan 2012 23:01:39 +0100 Changed-By: Leo Iannacone Maintainer: Ubuntu Developers Signed-By: Julian Taylor https://launchpad.net/ubuntu/natty/+source/gdevilspie/1:0.5-1ubuntu0.11.04.1 -------------- next part -------------- Format: 1.8 Date: Tue, 17 Jan 2012 23:01:39 +0100 Source: gdevilspie Binary: gdevilspie Architecture: source Version: 1:0.5-1ubuntu0.11.04.1 Distribution: natty-proposed Urgency: low Maintainer: Ubuntu Developers Changed-By: Leo Iannacone Description: gdevilspie - A user friendly interface for devilspie Closes: 628492 Launchpad-Bugs-Fixed: 783568 Changes: gdevilspie (1:0.5-1ubuntu0.11.04.1) natty-proposed; urgency=low . * Add depends on python-glade2, recommend python-xdg (LP: #783568, closes: #628492) Checksums-Sha1: 8839f5a56d64c4154ecde99c1c2ace5a19152fd9 1875 gdevilspie_0.5-1ubuntu0.11.04.1.dsc a05495589a4087f28fff7dd23bedd8d7c9b9b95d 3015 gdevilspie_0.5-1ubuntu0.11.04.1.debian.tar.gz Checksums-Sha256: 2563f3d1a2c0662667ff52b86ebf36904316d162b2f59b06ff9f28b839a69f1a 1875 gdevilspie_0.5-1ubuntu0.11.04.1.dsc 3e51e508419a6abea07d7af0eff6bc87f2a37b1266a1caa116d96616846f16fb 3015 gdevilspie_0.5-1ubuntu0.11.04.1.debian.tar.gz Files: f97b761f6540ace35df213ac986014d7 1875 gnome extra gdevilspie_0.5-1ubuntu0.11.04.1.dsc 186a13849488c60e73f8cd35f6d9922b 3015 gnome extra gdevilspie_0.5-1ubuntu0.11.04.1.debian.tar.gz Original-Maintainer: Chris Silva From stefanor at ubuntu.com Fri Feb 17 09:40:23 2012 From: stefanor at ubuntu.com (Stefano Rivera) Date: Fri, 17 Feb 2012 09:40:23 -0000 Subject: [ubuntu/natty-proposed] python-defaults 2.7.1-0ubuntu5.1 (Accepted) Message-ID: <20120217094023.8159.9052.launchpad@gac.canonical.com> python-defaults (2.7.1-0ubuntu5.1) natty-proposed; urgency=low * Backport patch from 2.6.6-11: (LP: #915167) - pycompile: use /usr/bin/pythonX.Y rather than pythonX.Y (to avoid /usr/local interpreters) Date: Wed, 15 Feb 2012 14:52:26 -0800 Changed-By: Stefano Rivera Maintainer: Ubuntu Developers Signed-By: Evan Broder https://launchpad.net/ubuntu/natty/+source/python-defaults/2.7.1-0ubuntu5.1 -------------- next part -------------- Format: 1.8 Date: Wed, 15 Feb 2012 14:52:26 -0800 Source: python-defaults Binary: python python-minimal python-examples python-dev idle python-doc python-dbg python-all python-all-dev python-all-dbg Architecture: source Version: 2.7.1-0ubuntu5.1 Distribution: natty-proposed Urgency: low Maintainer: Ubuntu Developers Changed-By: Stefano Rivera Description: idle - IDE for Python using Tkinter (default version) python - interactive high-level object-oriented language (default version) python-all - package depending on all supported Python runtime versions python-all-dbg - package depending on all supported Python debugging packages python-all-dev - package depending on all supported Python development packages python-dbg - debug build of the Python Interpreter (version 2.7) python-dev - header files and a static library for Python (default) python-doc - documentation for the high-level object-oriented language Python python-examples - examples for the Python language (default version) python-minimal - minimal subset of the Python language (default version) Launchpad-Bugs-Fixed: 915167 Changes: python-defaults (2.7.1-0ubuntu5.1) natty-proposed; urgency=low . * Backport patch from 2.6.6-11: (LP: #915167) - pycompile: use /usr/bin/pythonX.Y rather than pythonX.Y (to avoid /usr/local interpreters) Checksums-Sha1: 965a3fe7bb0f89cacbdb4fb1edc3bcf4f594ae13 1988 python-defaults_2.7.1-0ubuntu5.1.dsc b0c4888bb9e9588d3e40b2dc4d18aa0a1e1dff25 153900 python-defaults_2.7.1-0ubuntu5.1.tar.gz Checksums-Sha256: aa10a5beee18b43ce96b987b680e4dc1b3ba06e0de9b486fdd279357d00ff4f6 1988 python-defaults_2.7.1-0ubuntu5.1.dsc cbafa4aa348b5dcaf8b2cb5758e11a0222c8a296f9db252f9b61fc31f3073b4b 153900 python-defaults_2.7.1-0ubuntu5.1.tar.gz Files: 67be3a8e597072bb65c34a0b594e2b9c 1988 python optional python-defaults_2.7.1-0ubuntu5.1.dsc dbd92c311806cf50b7ac3f7a5d34bcb5 153900 python optional python-defaults_2.7.1-0ubuntu5.1.tar.gz Original-Maintainer: Matthias Klose From jamie at ubuntu.com Fri Feb 17 23:03:35 2012 From: jamie at ubuntu.com (Jamie Strandboge) Date: Fri, 17 Feb 2012 23:03:35 -0000 Subject: [ubuntu/natty-security] xulrunner-1.9.2_1.9.2.27+build1+nobinonly-0ubuntu0.11.04.1_armel_translations.tar.gz, xulrunner-1.9.2_1.9.2.27+build1+nobinonly-0ubuntu0.11.04.1_powerpc_translations.tar.gz, xulrunner-1.9.2_1.9.2.27+build1+nobinonly-0ubuntu0.11.04.1_i386_translations.tar.gz, xulrunner-1.9.2_1.9.2.27+build1+nobinonly-0ubuntu0.11.04.1_amd64_translations.tar.gz, xulrunner-1.9.2 1.9.2.27+build1+nobinonly-0ubuntu0.11.04.1 (Accepted) Message-ID: <20120217230335.21285.69708.launchpad@cocoplum.canonical.com> xulrunner-1.9.2 (1.9.2.27+build1+nobinonly-0ubuntu0.11.04.1) natty-security; urgency=low * SECURITY UPDATE: New upstream release v1.9.2.27 (FIREFOX_3_6_27_BUILD1) See the following for more information: - LP: #934073 - USN-1353-1 - USN-1251-1 - USN-1210-1 - LP: #838322 - LP: #837557 - USN-1184-1 - USN-1149-1 Date: Fri, 17 Feb 2012 08:04:19 -0600 Changed-By: Jamie Strandboge Maintainer: Ubuntu Mozilla Team https://launchpad.net/ubuntu/natty/+source/xulrunner-1.9.2/1.9.2.27+build1+nobinonly-0ubuntu0.11.04.1 -------------- next part -------------- Format: 1.8 Date: Fri, 17 Feb 2012 08:04:19 -0600 Source: xulrunner-1.9.2 Binary: xulrunner-1.9.2 xulrunner-1.9.2-dbg xulrunner-1.9.2-dev xulrunner-1.9.2-gnome-support xulrunner-1.9.2-testsuite xulrunner-1.9.2-testsuite-dev Architecture: source Version: 1.9.2.27+build1+nobinonly-0ubuntu0.11.04.1 Distribution: natty-security Urgency: low Maintainer: Ubuntu Mozilla Team Changed-By: Jamie Strandboge Description: xulrunner-1.9.2 - XUL + XPCOM application runner xulrunner-1.9.2-dbg - xulrunner-1.9.2 debug symbols xulrunner-1.9.2-dev - XUL + XPCOM development files xulrunner-1.9.2-gnome-support - Support for Gnome in xulrunner-1.9.2 applications xulrunner-1.9.2-testsuite - Test Suite from XULRunner 1.9.2 xulrunner-1.9.2-testsuite-dev - Test Suite development files for XULRunner 1.9.2 Launchpad-Bugs-Fixed: 837557 838322 934073 Changes: xulrunner-1.9.2 (1.9.2.27+build1+nobinonly-0ubuntu0.11.04.1) natty-security; urgency=low . * SECURITY UPDATE: New upstream release v1.9.2.27 (FIREFOX_3_6_27_BUILD1) See the following for more information: - LP: #934073 - USN-1353-1 - USN-1251-1 - USN-1210-1 - LP: #838322 - LP: #837557 - USN-1184-1 - USN-1149-1 Checksums-Sha1: 31fbd8161bc26b4212d105e55c2f8a1791786f75 2940 xulrunner-1.9.2_1.9.2.27+build1+nobinonly-0ubuntu0.11.04.1.dsc bdb512920b7e73db05acb6773c1ce943ca098e71 48459708 xulrunner-1.9.2_1.9.2.27+build1+nobinonly.orig.tar.gz 9c484efa382d120c89116982962cb106bef47671 70577 xulrunner-1.9.2_1.9.2.27+build1+nobinonly-0ubuntu0.11.04.1.diff.gz Checksums-Sha256: a4172186233930fe0e8070324e3657aaf0ceef96cc531fc80a3d10cbcfdadd89 2940 xulrunner-1.9.2_1.9.2.27+build1+nobinonly-0ubuntu0.11.04.1.dsc 6ef113cb0320d0d7e211f28797260b0d96322471de085e834d4b3d414506c4e9 48459708 xulrunner-1.9.2_1.9.2.27+build1+nobinonly.orig.tar.gz d560af18bc874141b6d88774c5e023a9ebd3dfe5f0c397f42619003c2dd10685 70577 xulrunner-1.9.2_1.9.2.27+build1+nobinonly-0ubuntu0.11.04.1.diff.gz Files: c60f02e21672306a435c158952a18287 2940 devel optional xulrunner-1.9.2_1.9.2.27+build1+nobinonly-0ubuntu0.11.04.1.dsc d3677109797f8f084db519f822a56eb6 48459708 devel optional xulrunner-1.9.2_1.9.2.27+build1+nobinonly.orig.tar.gz a2a487fe60488413742d3af01bad0c75 70577 devel optional xulrunner-1.9.2_1.9.2.27+build1+nobinonly-0ubuntu0.11.04.1.diff.gz From marc.deslauriers at ubuntu.com Mon Feb 20 01:03:50 2012 From: marc.deslauriers at ubuntu.com (Marc Deslauriers) Date: Mon, 20 Feb 2012 01:03:50 -0000 Subject: [ubuntu/natty-security] mumble_1.2.3-1ubuntu6.1_amd64_translations.tar.gz, mumble_1.2.3-1ubuntu6.1_powerpc_translations.tar.gz, mumble, mumble_1.2.3-1ubuntu6.1_armel_translations.tar.gz, mumble_1.2.3-1ubuntu6.1_i386_translations.tar.gz 1.2.3-1ubuntu6.1 (Accepted) Message-ID: <20120220010350.17368.35697.launchpad@cocoplum.canonical.com> mumble (1.2.3-1ubuntu6.1) natty-security; urgency=low * SECURITY UPDATE: credential disclosure via incorrect permissions (LP: #783405) - debian/patches/0004-set-file-permissions.patch: Set restrictive permissions on data files. - CVE-2012-0863 * debian/control: reorder Build-Depends so it builds in a schroot. Date: Fri, 17 Feb 2012 08:36:11 -0500 Changed-By: Marc Deslauriers Maintainer: Ubuntu Developers https://launchpad.net/ubuntu/natty/+source/mumble/1.2.3-1ubuntu6.1 -------------- next part -------------- Format: 1.8 Date: Fri, 17 Feb 2012 08:36:11 -0500 Source: mumble Binary: mumble mumble-11x mumble-server mumble-dbg mumble-server-web Architecture: source Version: 1.2.3-1ubuntu6.1 Distribution: natty-security Urgency: low Maintainer: Ubuntu Developers Changed-By: Marc Deslauriers Description: mumble - Low latency VoIP client mumble-11x - Low latency VoIP client (1.1.x) mumble-dbg - Low latency VoIP client (debugging symbols) mumble-server - Low latency VoIP server mumble-server-web - Web scripts for mumble-server Launchpad-Bugs-Fixed: 783405 Changes: mumble (1.2.3-1ubuntu6.1) natty-security; urgency=low . * SECURITY UPDATE: credential disclosure via incorrect permissions (LP: #783405) - debian/patches/0004-set-file-permissions.patch: Set restrictive permissions on data files. - CVE-2012-0863 * debian/control: reorder Build-Depends so it builds in a schroot. Checksums-Sha1: bff771cafe556094f099a49abac58b5d0582f05b 2773 mumble_1.2.3-1ubuntu6.1.dsc 75aace9cb9b851a8807ad411495a7df8055622a5 32677 mumble_1.2.3-1ubuntu6.1.debian.tar.gz Checksums-Sha256: 909aa3c18e64e31b68a14e60bd855c2446d3dee12861ef5c6577580f24486514 2773 mumble_1.2.3-1ubuntu6.1.dsc 9275c74db99f45152b774f0b889e3688990388068e24d0cb963bff2ec2b2fddf 32677 mumble_1.2.3-1ubuntu6.1.debian.tar.gz Files: 009e050d1701faa2e7e61d4dff187d33 2773 sound optional mumble_1.2.3-1ubuntu6.1.dsc 8e88d00dfdf8267d4cbcad88d385dd66 32677 sound optional mumble_1.2.3-1ubuntu6.1.debian.tar.gz Original-Maintainer: Debian VoIP Team From marc.deslauriers at ubuntu.com Mon Feb 20 18:03:59 2012 From: marc.deslauriers at ubuntu.com (Marc Deslauriers) Date: Mon, 20 Feb 2012 18:03:59 -0000 Subject: [ubuntu/natty-security] libvorbis 1.3.2-1ubuntu1.1 (Accepted) Message-ID: <20120220180359.12145.91713.launchpad@cocoplum.canonical.com> libvorbis (1.3.2-1ubuntu1.1) natty-security; urgency=low * SECURITY UPDATE: denial of service and possible code execution - lib/floor1.c: validate count. - https://trac.xiph.org/changeset/18151 - CVE-2012-0444 Date: Fri, 17 Feb 2012 15:19:38 -0500 Changed-By: Marc Deslauriers Maintainer: Ubuntu Developers https://launchpad.net/ubuntu/natty/+source/libvorbis/1.3.2-1ubuntu1.1 -------------- next part -------------- Format: 1.8 Date: Fri, 17 Feb 2012 15:19:38 -0500 Source: libvorbis Binary: libvorbis0a libvorbisenc2 libvorbisfile3 libvorbis-dev libvorbis-dbg Architecture: source Version: 1.3.2-1ubuntu1.1 Distribution: natty-security Urgency: low Maintainer: Ubuntu Developers Changed-By: Marc Deslauriers Description: libvorbis-dbg - The Vorbis General Audio Compression Codec (debug files) libvorbis-dev - The Vorbis General Audio Compression Codec (development files) libvorbis0a - The Vorbis General Audio Compression Codec (Decoder library) libvorbisenc2 - The Vorbis General Audio Compression Codec (Encoder library) libvorbisfile3 - The Vorbis General Audio Compression Codec (High Level API) Changes: libvorbis (1.3.2-1ubuntu1.1) natty-security; urgency=low . * SECURITY UPDATE: denial of service and possible code execution - lib/floor1.c: validate count. - https://trac.xiph.org/changeset/18151 - CVE-2012-0444 Checksums-Sha1: 7b3e24691ca0d781f0ee539a08797d8774429914 1988 libvorbis_1.3.2-1ubuntu1.1.dsc 7e05ac8491a7571aaa2cb1f9fcd86025d6e5179a 8395 libvorbis_1.3.2-1ubuntu1.1.diff.gz Checksums-Sha256: c2f9283b728d8d393f7c52af134b1c7ea1af495c95eea02b6d87179b48378e0a 1988 libvorbis_1.3.2-1ubuntu1.1.dsc 8cbbc8ba775dfe47b24c917bb42451f9ed4786ccc2fe565312a4b1e1c80ab43f 8395 libvorbis_1.3.2-1ubuntu1.1.diff.gz Files: c3a882ee26c376cf9772776e1db05eb2 1988 libs optional libvorbis_1.3.2-1ubuntu1.1.dsc 9e5f39fc7e82df1480a6c09212ec2868 8395 libs optional libvorbis_1.3.2-1ubuntu1.1.diff.gz Original-Maintainer: Debian Xiph.org Maintainers From mdke at ubuntu.com Tue Feb 21 11:44:40 2012 From: mdke at ubuntu.com (Matthew East) Date: Tue, 21 Feb 2012 11:44:40 -0000 Subject: [ubuntu/natty-proposed] gnome-user-docs 3.0.0+git20110406ubuntu12 (Accepted) Message-ID: <20120221114440.4458.13285.launchpad@wampee.canonical.com> gnome-user-docs (3.0.0+git20110406ubuntu12) natty-proposed; urgency=low * Update translations from Rosetta Date: Sun, 19 Feb 2012 21:49:38 +0000 Changed-By: Matthew East Maintainer: Ubuntu Documentation Team https://launchpad.net/ubuntu/natty/+source/gnome-user-docs/3.0.0+git20110406ubuntu12 -------------- next part -------------- Format: 1.8 Date: Sun, 19 Feb 2012 21:49:38 +0000 Source: gnome-user-docs Binary: gnome-user-guide Architecture: source Version: 3.0.0+git20110406ubuntu12 Distribution: natty-proposed Urgency: low Maintainer: Ubuntu Documentation Team Changed-By: Matthew East Description: gnome-user-guide - GNOME user's guide Changes: gnome-user-docs (3.0.0+git20110406ubuntu12) natty-proposed; urgency=low . * Update translations from Rosetta Checksums-Sha1: 95f472b3a210edc188739103b471f452bc5ec0aa 1078 gnome-user-docs_3.0.0+git20110406ubuntu12.dsc 745408cf40742796e700ebc6016fc8dfb77e00a4 23294940 gnome-user-docs_3.0.0+git20110406ubuntu12.tar.gz Checksums-Sha256: 38033320c02517fbba11a05e367e1d3be6e3f3ca74f1b9bba47389725ac54593 1078 gnome-user-docs_3.0.0+git20110406ubuntu12.dsc fe7f39c299a9b8f9f32fb4c6429733c34f112f4e07f7b8414552ec5b1e6f657f 23294940 gnome-user-docs_3.0.0+git20110406ubuntu12.tar.gz Files: 39f3cd8a7dbf547912072c513a345da8 1078 gnome optional gnome-user-docs_3.0.0+git20110406ubuntu12.dsc 8f0c35d4c073660c9cef15b370c6316f 23294940 gnome optional gnome-user-docs_3.0.0+git20110406ubuntu12.tar.gz Original-Maintainer: Jose Carlos Garcia Sogo From mdke at ubuntu.com Tue Feb 21 11:44:00 2012 From: mdke at ubuntu.com (Matthew East) Date: Tue, 21 Feb 2012 11:44:00 -0000 Subject: [ubuntu/natty-proposed] ubuntu-docs 11.04.4 (Accepted) Message-ID: <20120221114400.10207.3809.launchpad@gac.canonical.com> ubuntu-docs (11.04.4) natty-proposed; urgency=low * Update translations from Launchpad Date: Sun, 19 Feb 2012 20:43:37 +0000 Changed-By: Matthew East Maintainer: Ubuntu Documentation Team https://launchpad.net/ubuntu/natty/+source/ubuntu-docs/11.04.4 -------------- next part -------------- Format: 1.8 Date: Sun, 19 Feb 2012 20:43:37 +0000 Source: ubuntu-docs Binary: ubuntu-docs Architecture: source Version: 11.04.4 Distribution: natty-proposed Urgency: low Maintainer: Ubuntu Documentation Team Changed-By: Matthew East Description: ubuntu-docs - The Ubuntu Documentation Project Changes: ubuntu-docs (11.04.4) natty-proposed; urgency=low . * Update translations from Launchpad Checksums-Sha1: 0cb170f7168a52e9c1444108bc58d90874fd7eb4 902 ubuntu-docs_11.04.4.dsc 7166203e660ca0df33c72f73cd14b0b4dcf8dae5 10034182 ubuntu-docs_11.04.4.tar.gz Checksums-Sha256: 337e95350656ce28c64f4a36f7fca1a65971b1470663f8fe278bf8c2b16e0974 902 ubuntu-docs_11.04.4.dsc da27bcc6ddf83f86da7677e5f15f04d5e51fc6767c30fe7b68512217895ccd4d 10034182 ubuntu-docs_11.04.4.tar.gz Files: 84912e24f1b6d48e36efd0dffec9cad0 902 text optional ubuntu-docs_11.04.4.dsc 7924d16fd4d3a266a099d8eb3a47cd15 10034182 text optional ubuntu-docs_11.04.4.tar.gz From marc.deslauriers at ubuntu.com Wed Feb 22 15:33:30 2012 From: marc.deslauriers at ubuntu.com (Marc Deslauriers) Date: Wed, 22 Feb 2012 15:33:30 -0000 Subject: [ubuntu/natty-security] cvs_1.12.13-12ubuntu1.11.04.1_i386_translations.tar.gz, cvs_1.12.13-12ubuntu1.11.04.1_amd64_translations.tar.gz, cvs_1.12.13-12ubuntu1.11.04.1_armel_translations.tar.gz, cvs, cvs_1.12.13-12ubuntu1.11.04.1_powerpc_translations.tar.gz 1:1.12.13-12ubuntu1.11.04.1 (Accepted) Message-ID: <20120222153330.16482.53010.launchpad@cocoplum.canonical.com> cvs (1:1.12.13-12ubuntu1.11.04.1) natty-security; urgency=low * SECURITY UPDATE: arbitrary code execution via heap overflow - debian/patches/99ubuntu002-CVE-2012-0804.diff: remove use of write_buf in src/client.c. - CVE-2012-0804 Date: Mon, 13 Feb 2012 11:35:14 -0500 Changed-By: Marc Deslauriers Maintainer: Ubuntu Developers https://launchpad.net/ubuntu/natty/+source/cvs/1:1.12.13-12ubuntu1.11.04.1 -------------- next part -------------- Format: 1.8 Date: Mon, 13 Feb 2012 11:35:14 -0500 Source: cvs Binary: cvs Architecture: source Version: 1:1.12.13-12ubuntu1.11.04.1 Distribution: natty-security Urgency: low Maintainer: Ubuntu Developers Changed-By: Marc Deslauriers Description: cvs - Concurrent Versions System Changes: cvs (1:1.12.13-12ubuntu1.11.04.1) natty-security; urgency=low . * SECURITY UPDATE: arbitrary code execution via heap overflow - debian/patches/99ubuntu002-CVE-2012-0804.diff: remove use of write_buf in src/client.c. - CVE-2012-0804 Checksums-Sha1: 685ccde3955250b9d6f7cb028aa34eb92d7fdddd 1912 cvs_1.12.13-12ubuntu1.11.04.1.dsc f0078908c38e57e681a4a69c2bb083407e866295 108253 cvs_1.12.13-12ubuntu1.11.04.1.diff.gz Checksums-Sha256: df0f212ee947ff0844d52d29535c07ffc97d48e5c066a0a534c4d75ad5697560 1912 cvs_1.12.13-12ubuntu1.11.04.1.dsc 23052f0f712844c19a22f87dd581cdc6cd64f86457dfa4108bfa0358c65ef235 108253 cvs_1.12.13-12ubuntu1.11.04.1.diff.gz Files: 0110bd97daede62e1589a828f017098e 1912 devel optional cvs_1.12.13-12ubuntu1.11.04.1.dsc df16a9b114a653fbbe863ff055f1a8cc 108253 devel optional cvs_1.12.13-12ubuntu1.11.04.1.diff.gz Original-Maintainer: Steve McIntyre <93sam at debian.org> From lfaraone at ubuntu.com Wed Feb 22 20:15:47 2012 From: lfaraone at ubuntu.com (Luke Faraone) Date: Wed, 22 Feb 2012 20:15:47 -0000 Subject: [ubuntu/natty-proposed] pithos 0.3.9-1~ubuntu5 (Accepted) Message-ID: <20120222201547.6017.89446.launchpad@wampee.canonical.com> pithos (0.3.9-1~ubuntu5) natty-proposed; urgency=low * Sync clock to avoid "You have no chance to survive make your time" error from Pandora on start (LP: #743198) Date: Sun, 08 Jan 2012 16:26:16 -0500 Changed-By: Luke Faraone https://launchpad.net/ubuntu/natty/+source/pithos/0.3.9-1~ubuntu5 -------------- next part -------------- Format: 1.8 Date: Sun, 08 Jan 2012 16:26:16 -0500 Source: pithos Binary: pithos Architecture: source Version: 0.3.9-1~ubuntu5 Distribution: natty-proposed Urgency: low Maintainer: Luke Faraone Changed-By: Luke Faraone Description: pithos - Pandora Radio client for the GNOME desktop Launchpad-Bugs-Fixed: 743198 Changes: pithos (0.3.9-1~ubuntu5) natty-proposed; urgency=low . * Sync clock to avoid "You have no chance to survive make your time" error from Pandora on start (LP: #743198) Checksums-Sha1: 0516dfc9fb0e3a82e4a23f77827975e19f940a21 1908 pithos_0.3.9-1~ubuntu5.dsc 6d4810ba4f49c9bc44135567c2e489f908089e63 21382 pithos_0.3.9-1~ubuntu5.debian.tar.gz Checksums-Sha256: fbdfc2d55172b3be55d448bb4289dd883114fb5ed57d3827ca9f96bbb471611e 1908 pithos_0.3.9-1~ubuntu5.dsc 9b8d9dcdfc49ea19c9e6756eece0e23bb5239be7566af12c53448d580345737a 21382 pithos_0.3.9-1~ubuntu5.debian.tar.gz Files: cca78788b0c06ba7da1c9d663b2fe992 1908 gnome optional pithos_0.3.9-1~ubuntu5.dsc 994d1c317bfbd8687664d478e1cc6105 21382 gnome optional pithos_0.3.9-1~ubuntu5.debian.tar.gz From jamie at ubuntu.com Thu Feb 23 13:03:37 2012 From: jamie at ubuntu.com (Jamie Strandboge) Date: Thu, 23 Feb 2012 13:03:37 -0000 Subject: [ubuntu/natty-security] puppet 2.6.4-2ubuntu2.8 (Accepted) Message-ID: <20120223130337.19506.40102.launchpad@cocoplum.canonical.com> puppet (2.6.4-2ubuntu2.8) natty-security; urgency=low * SECURITY UPDATE: correctly drop group privileges - debian/patches/CVE-2012-1053_CVE-2012-1054.patch - CVE-2012-1053 * SECURITY UPDATE: properly handle symlinks with Klogin - debian/patches/CVE-2012-1053_CVE-2012-1054.patch - CVE-2012-1054 Date: Thu, 16 Feb 2012 13:15:07 -0600 Changed-By: Jamie Strandboge Maintainer: Ubuntu Developers https://launchpad.net/ubuntu/natty/+source/puppet/2.6.4-2ubuntu2.8 -------------- next part -------------- Format: 1.8 Date: Thu, 16 Feb 2012 13:15:07 -0600 Source: puppet Binary: puppet-common puppet puppetmaster-common puppetmaster puppetmaster-passenger vim-puppet puppet-el puppet-testsuite Architecture: source Version: 2.6.4-2ubuntu2.8 Distribution: natty-security Urgency: low Maintainer: Ubuntu Developers Changed-By: Jamie Strandboge Description: puppet - Centralized configuration management - agent startup and compatib puppet-common - Centralized configuration management puppet-el - syntax highlighting for puppet manifests in emacs puppet-testsuite - Centralized configuration management - test suite puppetmaster - Centralized configuration management - master startup and compati puppetmaster-common - Puppet master common scripts puppetmaster-passenger - Centralised configuration management - master setup to run under vim-puppet - syntax highlighting for puppet manifests in vim Changes: puppet (2.6.4-2ubuntu2.8) natty-security; urgency=low . * SECURITY UPDATE: correctly drop group privileges - debian/patches/CVE-2012-1053_CVE-2012-1054.patch - CVE-2012-1053 * SECURITY UPDATE: properly handle symlinks with Klogin - debian/patches/CVE-2012-1053_CVE-2012-1054.patch - CVE-2012-1054 Checksums-Sha1: f97f7308f96682a9a6a2c06feb18d51b594bb661 2296 puppet_2.6.4-2ubuntu2.8.dsc 509b1d20035a30948d0452bcf25cfa710bef7c87 98277 puppet_2.6.4-2ubuntu2.8.debian.tar.gz Checksums-Sha256: 6a4b10eea117da849796ea5d74bc287b798a5571ffce579e62feffa8179672d2 2296 puppet_2.6.4-2ubuntu2.8.dsc 95f4c9335d573f2a52cfe0b80cc057770b34217df9a71177a88ddaf65c4412ba 98277 puppet_2.6.4-2ubuntu2.8.debian.tar.gz Files: a33ce0018ca6e4de6f7dc50e8849ea38 2296 admin optional puppet_2.6.4-2ubuntu2.8.dsc a99fbf24cf133613744a2402113386c9 98277 admin optional puppet_2.6.4-2ubuntu2.8.debian.tar.gz Original-Maintainer: Puppet Package Maintainers From sbeattie at ubuntu.com Thu Feb 23 21:34:33 2012 From: sbeattie at ubuntu.com (Steve Beattie) Date: Thu, 23 Feb 2012 21:34:33 -0000 Subject: [ubuntu/natty-security] fex 20100208+debian1-1+squeeze2build0.11.04.1 (Accepted) Message-ID: <20120223213433.3278.26129.launchpad@cocoplum.canonical.com> fex (20100208+debian1-1+squeeze2build0.11.04.1) natty-security; urgency=low * fake sync from Debian fex (20100208+debian1-1+squeeze2) stable-security; urgency=high * Add debian/patches/08_xss.patch (backported from and by upstream) to fix XSS (Closes: #660621) - CVE-2012-0869 Date: Wed, 22 Feb 2012 09:49:39 -0800 Changed-By: Steve Beattie Maintainer: Giuseppe Iuculano https://launchpad.net/ubuntu/natty/+source/fex/20100208+debian1-1+squeeze2build0.11.04.1 -------------- next part -------------- Format: 1.8 Date: Wed, 22 Feb 2012 09:49:39 -0800 Source: fex Binary: fex fex-utils Architecture: source Version: 20100208+debian1-1+squeeze2build0.11.04.1 Distribution: natty-security Urgency: high Maintainer: Giuseppe Iuculano Changed-By: Steve Beattie Description: fex - web service for transfering very large files fex-utils - web service for transfering very large files (utils) Closes: 660621 Changes: fex (20100208+debian1-1+squeeze2build0.11.04.1) natty-security; urgency=low . * fake sync from Debian . fex (20100208+debian1-1+squeeze2) stable-security; urgency=high . * Add debian/patches/08_xss.patch (backported from and by upstream) to fix XSS (Closes: #660621) - CVE-2012-0869 Checksums-Sha1: 3c85a83a60a5885f0aaf21e958ccbca1c0e79af4 1951 fex_20100208+debian1-1+squeeze2build0.11.04.1.dsc de3bfc8e58b3b246f6bf601b59dbbe10c067bc1b 9491 fex_20100208+debian1-1+squeeze2build0.11.04.1.diff.gz Checksums-Sha256: 9c268945b058ff0efe6811760ab88646b654cb33b03913d2e926514b7c1f54e2 1951 fex_20100208+debian1-1+squeeze2build0.11.04.1.dsc 36fde51bf55f40972d79aea8376d578e90f5a8daf5956255ffe1b04a42fb79de 9491 fex_20100208+debian1-1+squeeze2build0.11.04.1.diff.gz Files: 20e861b1e715d0a0caeb0c91316627d2 1951 web optional fex_20100208+debian1-1+squeeze2build0.11.04.1.dsc 0bef8c36319154e86379088100623c07 9491 web optional fex_20100208+debian1-1+squeeze2build0.11.04.1.diff.gz From sbeattie at ubuntu.com Thu Feb 23 22:35:13 2012 From: sbeattie at ubuntu.com (Steve Beattie) Date: Thu, 23 Feb 2012 22:35:13 -0000 Subject: [ubuntu/natty-security] openjdk-6 6b22-1.10.6-0ubuntu1 (Accepted) Message-ID: <20120223223513.24934.1797.launchpad@cocoplum.canonical.com> openjdk-6 (6b22-1.10.6-0ubuntu1) natty-security; urgency=low * SECURITY UPDATE: update to IcedTea 6 1.10.6 - Security fixes: - S7082299, CVE-2011-3571: Fix in AtomicReferenceArray - S7088367, CVE-2011-3563: Fix issues in java sound - S7110683, CVE-2012-0502: Issues with some KeyboardFocusManager method - S7110687, CVE-2012-0503: Issues with TimeZone class - S7110700, CVE-2012-0505: Enhance exception throwing mechanism in ObjectStreamClass - S7110704, CVE-2012-0506: Issues with some method in corba - S7112642, CVE-2012-0497: Incorrect checking for graphics rendering object - S7118283, CVE-2012-0501: Better input parameter checking in zip file processing - S7126960, CVE-2011-5035: (httpserver) Add property to limit number of request headers to the HTTP Server - Bug fixes: - RH580478: Desktop files should not use hardcoded path - S7034464: Support transparent large pages on Linux - S7037939: NUMA: Disable adaptive resizing if SHM large pages are used - S7102369, RH751203: remove java.rmi.server.codebase property parsing from registyimpl - S7094468, RH751203: rmiregistry clean up - S6851973, PR830: ignore incoming channel binding if acceptor does not set one - S7091528: javadoc attempts to parse .class files * drop debian/patches/openjdk-7103725-ssl_beast_regression.patch as it's included in the upstream release. Date: Wed, 15 Feb 2012 10:15:59 -0800 Changed-By: Steve Beattie Maintainer: Ubuntu Developers https://launchpad.net/ubuntu/natty/+source/openjdk-6/6b22-1.10.6-0ubuntu1 -------------- next part -------------- Format: 1.8 Date: Wed, 15 Feb 2012 10:15:59 -0800 Source: openjdk-6 Binary: openjdk-6-jdk openjdk-6-jre-headless openjdk-6-jre openjdk-6-jre-lib openjdk-6-demo openjdk-6-source openjdk-6-doc openjdk-6-dbg icedtea-6-jre-cacao icedtea-6-jre-jamvm openjdk-6-jre-zero Architecture: source Version: 6b22-1.10.6-0ubuntu1 Distribution: natty-security Urgency: low Maintainer: Ubuntu Developers Changed-By: Steve Beattie Description: icedtea-6-jre-cacao - Alternative JVM for OpenJDK, using Cacao icedtea-6-jre-jamvm - Alternative JVM for OpenJDK, using JamVM openjdk-6-dbg - Java runtime based on OpenJDK (debugging symbols) openjdk-6-demo - Java runtime based on OpenJDK (demos and examples) openjdk-6-doc - OpenJDK Development Kit (JDK) documentation openjdk-6-jdk - OpenJDK Development Kit (JDK) openjdk-6-jre - OpenJDK Java runtime, using ${vm:Name} openjdk-6-jre-headless - OpenJDK Java runtime, using ${vm:Name} (headless) openjdk-6-jre-lib - OpenJDK Java runtime (architecture independent libraries) openjdk-6-jre-zero - Alternative JVM for OpenJDK, using Zero/Shark openjdk-6-source - OpenJDK Development Kit (JDK) source files Changes: openjdk-6 (6b22-1.10.6-0ubuntu1) natty-security; urgency=low . * SECURITY UPDATE: update to IcedTea 6 1.10.6 - Security fixes: - S7082299, CVE-2011-3571: Fix in AtomicReferenceArray - S7088367, CVE-2011-3563: Fix issues in java sound - S7110683, CVE-2012-0502: Issues with some KeyboardFocusManager method - S7110687, CVE-2012-0503: Issues with TimeZone class - S7110700, CVE-2012-0505: Enhance exception throwing mechanism in ObjectStreamClass - S7110704, CVE-2012-0506: Issues with some method in corba - S7112642, CVE-2012-0497: Incorrect checking for graphics rendering object - S7118283, CVE-2012-0501: Better input parameter checking in zip file processing - S7126960, CVE-2011-5035: (httpserver) Add property to limit number of request headers to the HTTP Server - Bug fixes: - RH580478: Desktop files should not use hardcoded path - S7034464: Support transparent large pages on Linux - S7037939: NUMA: Disable adaptive resizing if SHM large pages are used - S7102369, RH751203: remove java.rmi.server.codebase property parsing from registyimpl - S7094468, RH751203: rmiregistry clean up - S6851973, PR830: ignore incoming channel binding if acceptor does not set one - S7091528: javadoc attempts to parse .class files * drop debian/patches/openjdk-7103725-ssl_beast_regression.patch as it's included in the upstream release. Checksums-Sha1: a53eccc4cd5cbecfd66c66203e75823f7063e8f6 3050 openjdk-6_6b22-1.10.6-0ubuntu1.dsc 89d5dcf3414e6c9f166692538fae54fbe76a7a44 74304977 openjdk-6_6b22-1.10.6.orig.tar.gz 9dc0c37d1e2c0526b85c70a1120765d75b19b208 138635 openjdk-6_6b22-1.10.6-0ubuntu1.diff.gz Checksums-Sha256: b78e7f6508a410765d53ea1c71c52e554af88c1c8f8cea883ad19e0fe8210982 3050 openjdk-6_6b22-1.10.6-0ubuntu1.dsc f143884d4a2c89424858b760954da68915b3b43732f8f06a90c6dad08dd356fe 74304977 openjdk-6_6b22-1.10.6.orig.tar.gz df45a6f8fad87d03f5f45f98b2c872be180b949949438856a59ffdab11cc21b1 138635 openjdk-6_6b22-1.10.6-0ubuntu1.diff.gz Files: e186e96e26d7db657757283fd8bb7bb4 3050 java optional openjdk-6_6b22-1.10.6-0ubuntu1.dsc 4b6425377a2845f7fdf7965b1891073d 74304977 java optional openjdk-6_6b22-1.10.6.orig.tar.gz 68d81e7dfe18a05b501f99f013ed5183 138635 java optional openjdk-6_6b22-1.10.6-0ubuntu1.diff.gz Original-Maintainer: OpenJDK Team From evan at ebroder.net Sat Feb 25 07:21:35 2012 From: evan at ebroder.net (Evan Broder) Date: Sat, 25 Feb 2012 07:21:35 -0000 Subject: [ubuntu/natty-proposed] insserv 1.14.0-2ubuntu0.11.04.1 (Accepted) Message-ID: <20120225072135.22989.61756.launchpad@cocoplum.canonical.com> insserv (1.14.0-2ubuntu0.11.04.1) natty-proposed; urgency=low [ Adam Stokes ] * Add 200_hide_insserv_on_ubuntu.patch: Move insserv out of system path to disuade package maintainers from invoking it directly. (LP: #897390) [ Evan Broder ] * Fix the shutdown sequence if it was broken by insserv being run at some point in the past. Date: Thu, 23 Feb 2012 16:25:55 -0800 Changed-By: Evan Broder Maintainer: Ubuntu Developers https://launchpad.net/ubuntu/natty/+source/insserv/1.14.0-2ubuntu0.11.04.1 -------------- next part -------------- Format: 1.8 Date: Thu, 23 Feb 2012 16:25:55 -0800 Source: insserv Binary: insserv Architecture: source Version: 1.14.0-2ubuntu0.11.04.1 Distribution: natty-proposed Urgency: low Maintainer: Ubuntu Developers Changed-By: Evan Broder Description: insserv - Tool to organize boot sequence using LSB init.d script dependenci Launchpad-Bugs-Fixed: 897390 Changes: insserv (1.14.0-2ubuntu0.11.04.1) natty-proposed; urgency=low . [ Adam Stokes ] * Add 200_hide_insserv_on_ubuntu.patch: Move insserv out of system path to disuade package maintainers from invoking it directly. (LP: #897390) . [ Evan Broder ] * Fix the shutdown sequence if it was broken by insserv being run at some point in the past. Checksums-Sha1: 6eab65180abe92b3977b77ec984da79ad3168619 2026 insserv_1.14.0-2ubuntu0.11.04.1.dsc bf44360e4f62b2dbddd368cc4bfec607f1bfd5be 55437 insserv_1.14.0-2ubuntu0.11.04.1.diff.gz Checksums-Sha256: f38a4a659d6f2cc75f62c86f533fa9ea6a7b562abf9057d85f039eba6bc2deb5 2026 insserv_1.14.0-2ubuntu0.11.04.1.dsc 9517c28d0c14415b7e1fd9d0820ef095fd864a133aa006842cabb6cd4cb8cd07 55437 insserv_1.14.0-2ubuntu0.11.04.1.diff.gz Files: b5727e6c3c8763d7ed183a95f10103de 2026 misc optional insserv_1.14.0-2ubuntu0.11.04.1.dsc 41e6d36ecbc6f61087887660034ed0e2 55437 misc optional insserv_1.14.0-2ubuntu0.11.04.1.diff.gz Debian-Vcs-Browser: http://svn.debian.org/wsvn/initscripts-ng/trunk/src/insserv/ Debian-Vcs-Svn: svn://svn.debian.org/initscripts-ng/trunk/src/insserv Original-Maintainer: Petter Reinholdtsen From jamie at ubuntu.com Sun Feb 26 03:30:41 2012 From: jamie at ubuntu.com (Jamie Strandboge) Date: Sun, 26 Feb 2012 03:30:41 -0000 Subject: [ubuntu/natty-updates] chromium-browser 17.0.963.56~r121963-0ubuntu0.11.04.1 (Accepted) Message-ID: <20120226033041.904.71878.launchpad@ackee.canonical.com> chromium-browser (17.0.963.56~r121963-0ubuntu0.11.04.1) natty-security; urgency=low * New upstream release from the Stable Channel (LP: #931905, #933262) This release fixes the following security issues from 17.0.963.56: - [105803] High CVE-2011-3015: Integer overflows in PDF codecs. Credit to Google Chrome Security Team (scarybeasts). - [106336] Medium CVE-2011-3016: Read-after-free with counter nodes. Credit to miaubiz. - [108695] High CVE-2011-3017: Possible use-after-free in database handling. Credit to miaubiz. - [110172] High CVE-2011-3018: Heap overflow in path rendering. Credit to Aki Helin of OUSPG. - [110849] High CVE-2011-3019: Heap buffer overflow in MKV handling. Credit to Google Chrome Security Team (scarybeasts) and Mateusz Jurczyk of the Google Security Team. - [111575] Medium CVE-2011-3020: Native client validator error. Credit to Nick Bray of the Chromium development community. - [111779] High CVE-2011-3021: Use-after-free in subframe loading. Credit to Arthur Gerkis. - [112236] Medium CVE-2011-3022: Inappropriate use of http for translation script. Credit to Google Chrome Security Team (Jorge Obes). - [112259] Medium CVE-2011-3023: Use-after-free with drag and drop. Credit to pa_kt. - [112451] Low CVE-2011-3024: Browser crash with empty x509 certificate. Credit to chrometot. - [112670] Medium CVE-2011-3025: Out-of-bounds read in h.264 parsing. Credit to Sławomir Błażek. - [112822] High CVE-2011-3026: Integer overflow / truncation in libpng. Credit to Jüri Aedla. - [112847] High CVE-2011-3027: Bad cast in column handling. Credit to miaubiz. This release fixes the following security issues from 17.0.963.46: - [73478] Low CVE-2011-3953: Avoid clipboard monitoring after paste event. Credit to Daniel Cheng of the Chromium development community. - [92550] Low CVE-2011-3954: Crash with excessive database usage. Credit to Collin Payne. - [93106] High CVE-2011-3955: Crash aborting an IndexDB transaction. Credit to David Grogan of the Chromium development community. - [103630] Low CVE-2011-3956: Incorrect handling of sandboxed origins inside extensions. Credit to Devdatta Akhawe, UC Berkeley. - [104056] High CVE-2011-3957: Use-after-free in PDF garbage collection. Credit to Aki Helin of OUSPG. - [105459] High CVE-2011-3958: Bad casts with column spans. Credit to miaubiz. - [106441] High CVE-2011-3959: Buffer overflow in locale handling. Credit to Aki Helin of OUSPG. - [108416] Medium CVE-2011-3960: Out-of-bounds read in audio decoding. Credit to Aki Helin of OUSPG. - [108871] Critical CVE-2011-3961: Race condition after crash of utility process. Credit to Shawn Goertzen. - [108901] Medium CVE-2011-3962: Out-of-bounds read in path clipping. Credit to Aki Helin of OUSPG. - [109094] Medium CVE-2011-3963: Out-of-bounds read in PDF fax image handling. Credit to Atte Kettunen of OUSPG. - [109245] Low CVE-2011-3964: URL bar confusion after drag + drop. Credit to Code Audit Labs of VulnHunt.com. - [109664] Low CVE-2011-3965: Crash in signature check. Credit to Sławomir Błażek. - [109716] High CVE-2011-3966: Use-after-free in stylesheet error handling. Credit to Aki Helin of OUSPG. - [109717] Low CVE-2011-3967: Crash with unusual certificate. Credit to Ben Carrillo. - [109743] High CVE-2011-3968: Use-after-free in CSS handling. Credit to Arthur Gerkis. - [110112] High CVE-2011-3969: Use-after-free in SVG layout. Credit to Arthur Gerkis. - [110277] Medium CVE-2011-3970: Out-of-bounds read in libxslt. Credit to Aki Helin of OUSPG. - [110374] High CVE-2011-3971: Use-after-free with mousemove events. Credit to Arthur Gerkis. - [110559] Medium CVE-2011-3972: Out-of-bounds read in shader translator. Credit to Google Chrome Security Team (Inferno). * Rebase patch - update debian/patches/disable_dlog_and_dcheck_in_release_builds.patch * Update .install file to just install all .pak files instead of listing them by name - update debian/chromium-browser.install Date: 2012-02-21 07:35:59.866538+00:00 Changed-By: Micah Gersten Maintainer: Fabien Tassin Signed-By: Jamie Strandboge https://launchpad.net/ubuntu/natty/+source/chromium-browser/17.0.963.56~r121963-0ubuntu0.11.04.1 -------------- next part -------------- Sorry, changesfile not available. From jamie at ubuntu.com Sun Feb 26 03:30:48 2012 From: jamie at ubuntu.com (Jamie Strandboge) Date: Sun, 26 Feb 2012 03:30:48 -0000 Subject: [ubuntu/natty-security] chromium-browser 17.0.963.56~r121963-0ubuntu0.11.04.1 (Accepted) Message-ID: <20120226033048.904.66513.launchpad@ackee.canonical.com> chromium-browser (17.0.963.56~r121963-0ubuntu0.11.04.1) natty-security; urgency=low * New upstream release from the Stable Channel (LP: #931905, #933262) This release fixes the following security issues from 17.0.963.56: - [105803] High CVE-2011-3015: Integer overflows in PDF codecs. Credit to Google Chrome Security Team (scarybeasts). - [106336] Medium CVE-2011-3016: Read-after-free with counter nodes. Credit to miaubiz. - [108695] High CVE-2011-3017: Possible use-after-free in database handling. Credit to miaubiz. - [110172] High CVE-2011-3018: Heap overflow in path rendering. Credit to Aki Helin of OUSPG. - [110849] High CVE-2011-3019: Heap buffer overflow in MKV handling. Credit to Google Chrome Security Team (scarybeasts) and Mateusz Jurczyk of the Google Security Team. - [111575] Medium CVE-2011-3020: Native client validator error. Credit to Nick Bray of the Chromium development community. - [111779] High CVE-2011-3021: Use-after-free in subframe loading. Credit to Arthur Gerkis. - [112236] Medium CVE-2011-3022: Inappropriate use of http for translation script. Credit to Google Chrome Security Team (Jorge Obes). - [112259] Medium CVE-2011-3023: Use-after-free with drag and drop. Credit to pa_kt. - [112451] Low CVE-2011-3024: Browser crash with empty x509 certificate. Credit to chrometot. - [112670] Medium CVE-2011-3025: Out-of-bounds read in h.264 parsing. Credit to Sławomir Błażek. - [112822] High CVE-2011-3026: Integer overflow / truncation in libpng. Credit to Jüri Aedla. - [112847] High CVE-2011-3027: Bad cast in column handling. Credit to miaubiz. This release fixes the following security issues from 17.0.963.46: - [73478] Low CVE-2011-3953: Avoid clipboard monitoring after paste event. Credit to Daniel Cheng of the Chromium development community. - [92550] Low CVE-2011-3954: Crash with excessive database usage. Credit to Collin Payne. - [93106] High CVE-2011-3955: Crash aborting an IndexDB transaction. Credit to David Grogan of the Chromium development community. - [103630] Low CVE-2011-3956: Incorrect handling of sandboxed origins inside extensions. Credit to Devdatta Akhawe, UC Berkeley. - [104056] High CVE-2011-3957: Use-after-free in PDF garbage collection. Credit to Aki Helin of OUSPG. - [105459] High CVE-2011-3958: Bad casts with column spans. Credit to miaubiz. - [106441] High CVE-2011-3959: Buffer overflow in locale handling. Credit to Aki Helin of OUSPG. - [108416] Medium CVE-2011-3960: Out-of-bounds read in audio decoding. Credit to Aki Helin of OUSPG. - [108871] Critical CVE-2011-3961: Race condition after crash of utility process. Credit to Shawn Goertzen. - [108901] Medium CVE-2011-3962: Out-of-bounds read in path clipping. Credit to Aki Helin of OUSPG. - [109094] Medium CVE-2011-3963: Out-of-bounds read in PDF fax image handling. Credit to Atte Kettunen of OUSPG. - [109245] Low CVE-2011-3964: URL bar confusion after drag + drop. Credit to Code Audit Labs of VulnHunt.com. - [109664] Low CVE-2011-3965: Crash in signature check. Credit to Sławomir Błażek. - [109716] High CVE-2011-3966: Use-after-free in stylesheet error handling. Credit to Aki Helin of OUSPG. - [109717] Low CVE-2011-3967: Crash with unusual certificate. Credit to Ben Carrillo. - [109743] High CVE-2011-3968: Use-after-free in CSS handling. Credit to Arthur Gerkis. - [110112] High CVE-2011-3969: Use-after-free in SVG layout. Credit to Arthur Gerkis. - [110277] Medium CVE-2011-3970: Out-of-bounds read in libxslt. Credit to Aki Helin of OUSPG. - [110374] High CVE-2011-3971: Use-after-free with mousemove events. Credit to Arthur Gerkis. - [110559] Medium CVE-2011-3972: Out-of-bounds read in shader translator. Credit to Google Chrome Security Team (Inferno). * Rebase patch - update debian/patches/disable_dlog_and_dcheck_in_release_builds.patch * Update .install file to just install all .pak files instead of listing them by name - update debian/chromium-browser.install Date: 2012-02-21 07:35:59.866538+00:00 Changed-By: Micah Gersten Maintainer: Fabien Tassin Signed-By: Jamie Strandboge https://launchpad.net/ubuntu/natty/+source/chromium-browser/17.0.963.56~r121963-0ubuntu0.11.04.1 -------------- next part -------------- Sorry, changesfile not available. From jamie at ubuntu.com Mon Feb 27 23:33:34 2012 From: jamie at ubuntu.com (Jamie Strandboge) Date: Mon, 27 Feb 2012 23:33:34 -0000 Subject: [ubuntu/natty-security] libxml2 2.7.8.dfsg-2ubuntu0.3 (Accepted) Message-ID: <20120227233334.18460.58458.launchpad@cocoplum.canonical.com> libxml2 (2.7.8.dfsg-2ubuntu0.3) natty-security; urgency=low * SECURITY UPDATE: add randomization to dictionaries with hash tables help prevent denial of service via hash algorithm collision - configure.in: lookup for rand, srand and time - dict.c: add randomization to dictionaries hash tables - hash.c: add randomization to normal hash tables - 8973d58b7498fa5100a876815476b81fd1a2412a - CVE-2012-0841 Date: Fri, 24 Feb 2012 15:16:14 -0600 Changed-By: Jamie Strandboge Maintainer: Ubuntu Developers https://launchpad.net/ubuntu/natty/+source/libxml2/2.7.8.dfsg-2ubuntu0.3 -------------- next part -------------- Format: 1.8 Date: Fri, 24 Feb 2012 15:16:14 -0600 Source: libxml2 Binary: libxml2 libxml2-utils libxml2-dev libxml2-dbg libxml2-doc python-libxml2 python-libxml2-dbg libxml2-udeb Architecture: source Version: 2.7.8.dfsg-2ubuntu0.3 Distribution: natty-security Urgency: low Maintainer: Ubuntu Developers Changed-By: Jamie Strandboge Description: libxml2 - GNOME XML library libxml2-dbg - Debugging symbols for the GNOME XML library libxml2-dev - Development files for the GNOME XML library libxml2-doc - Documentation for the GNOME XML library libxml2-udeb - GNOME XML library - minimal runtime (udeb) libxml2-utils - XML utilities python-libxml2 - Python bindings for the GNOME XML library python-libxml2-dbg - Python bindings for the GNOME XML library (debug extension) Changes: libxml2 (2.7.8.dfsg-2ubuntu0.3) natty-security; urgency=low . * SECURITY UPDATE: add randomization to dictionaries with hash tables help prevent denial of service via hash algorithm collision - configure.in: lookup for rand, srand and time - dict.c: add randomization to dictionaries hash tables - hash.c: add randomization to normal hash tables - 8973d58b7498fa5100a876815476b81fd1a2412a - CVE-2012-0841 Checksums-Sha1: 5ac7509c4a444f87d1ab095e6d21334367c62894 2287 libxml2_2.7.8.dfsg-2ubuntu0.3.dsc 0bc1b7233575760ecfaf0d49f8ec9b9f57b96eb5 116548 libxml2_2.7.8.dfsg-2ubuntu0.3.diff.gz Checksums-Sha256: f8c9032512bfdfb5394b1ccd194037ae46936ff7e67266eb0708825643acc496 2287 libxml2_2.7.8.dfsg-2ubuntu0.3.dsc 6e0742adb25af1486aff37df926db9082a8ae9d16d426b955570cce3f46afb1c 116548 libxml2_2.7.8.dfsg-2ubuntu0.3.diff.gz Files: e3a7f7c7066cacadfc5af5dafca56e8c 2287 libs optional libxml2_2.7.8.dfsg-2ubuntu0.3.dsc 102707a47ef92c2678401b830889e27d 116548 libs optional libxml2_2.7.8.dfsg-2ubuntu0.3.diff.gz Original-Maintainer: Debian XML/SGML Group From jamie at ubuntu.com Mon Feb 27 23:33:45 2012 From: jamie at ubuntu.com (Jamie Strandboge) Date: Mon, 27 Feb 2012 23:33:45 -0000 Subject: [ubuntu/natty-security] fex 20100208+debian1-1+squeeze3build0.11.04.1 (Accepted) Message-ID: <20120227233345.18460.69413.launchpad@cocoplum.canonical.com> fex (20100208+debian1-1+squeeze3build0.11.04.1) natty-security; urgency=low * fake sync from Debian fex (20100208+debian1-1+squeeze3) stable-security; urgency=high * Fixup for last upload. (Missing initialization, Closes: #660828) Date: Mon, 27 Feb 2012 13:21:20 -0600 Changed-By: Jamie Strandboge Maintainer: Giuseppe Iuculano https://launchpad.net/ubuntu/natty/+source/fex/20100208+debian1-1+squeeze3build0.11.04.1 -------------- next part -------------- Format: 1.8 Date: Mon, 27 Feb 2012 13:21:20 -0600 Source: fex Binary: fex fex-utils Architecture: source Version: 20100208+debian1-1+squeeze3build0.11.04.1 Distribution: natty-security Urgency: high Maintainer: Giuseppe Iuculano Changed-By: Jamie Strandboge Description: fex - web service for transfering very large files fex-utils - web service for transfering very large files (utils) Closes: 660828 Changes: fex (20100208+debian1-1+squeeze3build0.11.04.1) natty-security; urgency=low . * fake sync from Debian . fex (20100208+debian1-1+squeeze3) stable-security; urgency=high . * Fixup for last upload. (Missing initialization, Closes: #660828) Checksums-Sha1: 57c2ee48105d404e023f6430317f60bfeeb3db5e 1951 fex_20100208+debian1-1+squeeze3build0.11.04.1.dsc 82f333c0f2a5c8744564754006c78b55059282df 9689 fex_20100208+debian1-1+squeeze3build0.11.04.1.diff.gz Checksums-Sha256: 0439366400358b7e1e29e170b9a4173dcf26c553d31dbedc996b85dc4aa8a759 1951 fex_20100208+debian1-1+squeeze3build0.11.04.1.dsc 8694cee5c73c1f351ea432dd7d79b305f4fb2aacb73f0daec06070cdb14cfa17 9689 fex_20100208+debian1-1+squeeze3build0.11.04.1.diff.gz Files: 433282b9a662a8a505722b2f802ad350 1951 web optional fex_20100208+debian1-1+squeeze3build0.11.04.1.dsc bec2d688e61de66b3d42342c86379ae0 9689 web optional fex_20100208+debian1-1+squeeze3build0.11.04.1.diff.gz From tyhicks at canonical.com Tue Feb 28 02:33:39 2012 From: tyhicks at canonical.com (Tyler Hicks) Date: Tue, 28 Feb 2012 02:33:39 -0000 Subject: [ubuntu/natty-security] ruby1.8 1.8.7.302-2ubuntu0.1 (Accepted) Message-ID: <20120228023339.14816.50618.launchpad@cocoplum.canonical.com> ruby1.8 (1.8.7.302-2ubuntu0.1) natty-security; urgency=low * SECURITY UPDATE: Arbitrary code execution and denial of service - debian/patches/CVE-2011-0188.patch: Remove cast to prevent memory corruption during allocation. Based on upstream patch. - CVE-2011-0188 * SECURITY UPDATE: Arbitrary file deletion due to symlink race - debian/patches/CVE-2011-1004.patch: Unlink the symlink rather than recursively removing everything underneath the symlink destination. Based on upstream patch. - CVE-2011-1004 * SECURITY UPDATE: Safe level bypass - debian/patches/CVE-2011-1005.patch: Remove incorrect string taint in exception handling methods. Based on upstream patch. - CVE-2011-1005 * SECURITY UPDATE: Predictable random number generation - debian/patches/CVE-2011-2686.patch: Reseed the random number generator each time a child process is created. Based on upstream patch. - CVE-2011-2686 * SECURITY UPDATE: Predicatable random number generation - debian/patches/CVE-2011-2705.patch: Reseed the random number generator with the pid number and the current time to prevent predictable random numbers in the case of pid number rollover. Based on upstream patch. - CVE-2011-2705 * SECURITY UPDATE: Denial of service via crafted hash table keys - debian/patches/CVE-2011-4815.patch: Add randomness to the key hashing algorithm to prevent predictable results when inserting objects into a hash table. Based on upstream patch. - CVE-2011-4815 Date: Tue, 21 Feb 2012 16:28:51 -0600 Changed-By: Tyler Hicks Maintainer: Ubuntu Developers https://launchpad.net/ubuntu/natty/+source/ruby1.8/1.8.7.302-2ubuntu0.1 -------------- next part -------------- Format: 1.8 Date: Tue, 21 Feb 2012 16:28:51 -0600 Source: ruby1.8 Binary: ruby1.8 libruby1.8 libruby1.8-dbg ruby1.8-dev libtcltk-ruby1.8 ruby1.8-examples ruby1.8-elisp ri1.8 Architecture: source Version: 1.8.7.302-2ubuntu0.1 Distribution: natty-security Urgency: low Maintainer: Ubuntu Developers Changed-By: Tyler Hicks Description: libruby1.8 - Libraries necessary to run Ruby 1.8 libruby1.8-dbg - Debugging symbols for Ruby 1.8 libtcltk-ruby1.8 - Tcl/Tk interface for Ruby 1.8 ri1.8 - Ruby Interactive reference (for Ruby 1.8) ruby1.8 - Interpreter of object-oriented scripting language Ruby 1.8 ruby1.8-dev - Header files for compiling extension modules for the Ruby 1.8 ruby1.8-elisp - ruby-mode for Emacsen ruby1.8-examples - Examples for Ruby 1.8 Changes: ruby1.8 (1.8.7.302-2ubuntu0.1) natty-security; urgency=low . * SECURITY UPDATE: Arbitrary code execution and denial of service - debian/patches/CVE-2011-0188.patch: Remove cast to prevent memory corruption during allocation. Based on upstream patch. - CVE-2011-0188 * SECURITY UPDATE: Arbitrary file deletion due to symlink race - debian/patches/CVE-2011-1004.patch: Unlink the symlink rather than recursively removing everything underneath the symlink destination. Based on upstream patch. - CVE-2011-1004 * SECURITY UPDATE: Safe level bypass - debian/patches/CVE-2011-1005.patch: Remove incorrect string taint in exception handling methods. Based on upstream patch. - CVE-2011-1005 * SECURITY UPDATE: Predictable random number generation - debian/patches/CVE-2011-2686.patch: Reseed the random number generator each time a child process is created. Based on upstream patch. - CVE-2011-2686 * SECURITY UPDATE: Predicatable random number generation - debian/patches/CVE-2011-2705.patch: Reseed the random number generator with the pid number and the current time to prevent predictable random numbers in the case of pid number rollover. Based on upstream patch. - CVE-2011-2705 * SECURITY UPDATE: Denial of service via crafted hash table keys - debian/patches/CVE-2011-4815.patch: Add randomness to the key hashing algorithm to prevent predictable results when inserting objects into a hash table. Based on upstream patch. - CVE-2011-4815 Checksums-Sha1: 0b68b20645131fe6fdfeafb2de91cfcd3e278c02 2276 ruby1.8_1.8.7.302-2ubuntu0.1.dsc 55f18bfe291058f8057a4ea46bdd8d8d5cae42c2 52989 ruby1.8_1.8.7.302-2ubuntu0.1.diff.gz Checksums-Sha256: 5d9138a18fb81b1c81c57fddca164867511f9ff3433c54e691573ac4c07020f9 2276 ruby1.8_1.8.7.302-2ubuntu0.1.dsc 0893dd5704bd796b26577287023ffc059fb4d32b4beade493313708a50c2beaa 52989 ruby1.8_1.8.7.302-2ubuntu0.1.diff.gz Files: 01d3fb473da80e386333174007cd506f 2276 ruby optional ruby1.8_1.8.7.302-2ubuntu0.1.dsc c36d0196330021d8be346a3adfc3baeb 52989 ruby optional ruby1.8_1.8.7.302-2ubuntu0.1.diff.gz Original-Maintainer: akira yamada From martin.pitt at ubuntu.com Tue Feb 28 13:51:35 2012 From: martin.pitt at ubuntu.com (Martin Pitt) Date: Tue, 28 Feb 2012 13:51:35 -0000 Subject: [ubuntu/natty-security] linux 2.6.38-13.56 (Accepted) Message-ID: <20120228135135.628.61675.launchpad@ackee.canonical.com> linux (2.6.38-13.56) natty-proposed; urgency=low [Herton R. Krzesinski] * Release Tracking Bug - LP: #931640 [ Upstream Kernel Changes ] * igmp: Avoid zero delay when receiving odd mixture of IGMP queries - LP: #917848 - CVE-2012-0207 * TOMOYO: Fix oops in tomoyo_mount_acl(). - LP: #922377 - CVE-2011-2518 * oom: fix integer overflow of points in oom_badness - LP: #922374 - CVE-2011-2498 Date: 2012-02-14 12:35:32.074642+00:00 Changed-By: "Herton R. Krzesinski" Signed-By: Martin Pitt https://launchpad.net/ubuntu/natty/+source/linux/2.6.38-13.56 -------------- next part -------------- Sorry, changesfile not available. From martin.pitt at ubuntu.com Tue Feb 28 13:51:54 2012 From: martin.pitt at ubuntu.com (Martin Pitt) Date: Tue, 28 Feb 2012 13:51:54 -0000 Subject: [ubuntu/natty-updates] linux 2.6.38-13.56 (Accepted) Message-ID: <20120228135154.628.23163.launchpad@ackee.canonical.com> linux (2.6.38-13.56) natty-proposed; urgency=low [Herton R. Krzesinski] * Release Tracking Bug - LP: #931640 [ Upstream Kernel Changes ] * igmp: Avoid zero delay when receiving odd mixture of IGMP queries - LP: #917848 - CVE-2012-0207 * TOMOYO: Fix oops in tomoyo_mount_acl(). - LP: #922377 - CVE-2011-2518 * oom: fix integer overflow of points in oom_badness - LP: #922374 - CVE-2011-2498 Date: 2012-02-14 12:35:32.074642+00:00 Changed-By: "Herton R. Krzesinski" Signed-By: Martin Pitt https://launchpad.net/ubuntu/natty/+source/linux/2.6.38-13.56 -------------- next part -------------- Sorry, changesfile not available. From martin.pitt at ubuntu.com Tue Feb 28 16:36:48 2012 From: martin.pitt at ubuntu.com (Martin Pitt) Date: Tue, 28 Feb 2012 16:36:48 -0000 Subject: [ubuntu/natty-security] postgresql-8.4, postgresql-8.4_8.4.11-0ubuntu0.11.04_armel_translations.tar.gz, postgresql-8.4_8.4.11-0ubuntu0.11.04_powerpc_translations.tar.gz, postgresql-8.4_8.4.11-0ubuntu0.11.04_amd64_translations.tar.gz, postgresql-8.4_8.4.11-0ubuntu0.11.04_i386_translations.tar.gz 8.4.11-0ubuntu0.11.04 (Accepted) Message-ID: <20120228163648.32011.56479.launchpad@cocoplum.canonical.com> postgresql-8.4 (8.4.11-0ubuntu0.11.04) natty-security; urgency=low * New upstream bug fix/security release: (LP: #941912) - Require execute permission on the trigger function for "CREATE TRIGGER". This missing check could allow another user to execute a trigger function with forged input data, by installing it on a table he owns. This is only of significance for trigger functions marked SECURITY DEFINER, since otherwise trigger functions run as the table owner anyway. (CVE-2012-0866) - Remove arbitrary limitation on length of common name in SSL certificates. Both libpq and the server truncated the common name extracted from an SSL certificate at 32 bytes. Normally this would cause nothing worse than an unexpected verification failure, but there are some rather-implausible scenarios in which it might allow one certificate holder to impersonate another. The victim would have to have a common name exactly 32 bytes long, and the attacker would have to persuade a trusted CA to issue a certificate in which the common name has that string as a prefix. Impersonating a server would also require some additional exploit to redirect client connections. (CVE-2012-0867) - Convert newlines to spaces in names written in pg_dump comments. pg_dump was incautious about sanitizing object names that are emitted within SQL comments in its output script. A name containing a newline would at least render the script syntactically incorrect. Maliciously crafted object names could present a SQL injection risk when the script is reloaded. (CVE-2012-0868) - Fix btree index corruption from insertions concurrent with vacuuming. An index page split caused by an insertion could sometimes cause a concurrently-running "VACUUM" to miss removing index entries that it should remove. After the corresponding table rows are removed, the dangling index entries would cause errors (such as "could not read block N in file ...") or worse, silently wrong query results after unrelated rows are re-inserted at the now-free table locations. This bug has been present since release 8.2, but occurs so infrequently that it was not diagnosed until now. If you have reason to suspect that it has happened in your database, reindexing the affected index will fix things. - Update per-column permissions, not only per-table permissions, when changing table owner. Failure to do this meant that any previously granted column permissions were still shown as having been granted by the old owner. This meant that neither the new owner nor a superuser could revoke the now-untraceable-to-table-owner permissions. - Allow non-existent values for some settings in "ALTER USER/DATABASE SET". Allow default_text_search_config, default_tablespace, and temp_tablespaces to be set to names that are not known. This is because they might be known in another database where the setting is intended to be used, or for the tablespace cases because the tablespace might not be created yet. The same issue was previously recognized for search_path, and these settings now act like that one. - Avoid crashing when we have problems deleting table files post-commit. Dropping a table should lead to deleting the underlying disk files only after the transaction commits. In event of failure then (for instance, because of wrong file permissions) the code is supposed to just emit a warning message and go on, since it's too late to abort the transaction. This logic got broken as of release 8.4, causing such situations to result in a PANIC and an unrestartable database. - Track the OID counter correctly during WAL replay, even when it wraps around. Previously the OID counter would remain stuck at a high value until the system exited replay mode. The practical consequences of that are usually nil, but there are scenarios wherein a standby server that's been promoted to master might take a long time to advance the OID counter to a reasonable value once values are needed. - Fix regular expression back-references with - attached. Rather than enforcing an exact string match, the code would effectively accept any string that satisfies the pattern sub-expression referenced by the back-reference symbol. A similar problem still afflicts back-references that are embedded in a larger quantified expression, rather than being the immediate subject of the quantifier. This will be addressed in a future PostgreSQL release. - Fix recently-introduced memory leak in processing of inet/cidr values. - Fix dangling pointer after "CREATE TABLE AS"/"SELECT INTO" in a SQL-language function. In most cases this only led to an assertion failure in assert-enabled builds, but worse consequences seem possible. - Fix I/O-conversion-related memory leaks in plpgsql. - Improve pg_dump's handling of inherited table columns. pg_dump mishandled situations where a child column has a different default expression than its parent column. If the default is textually identical to the parent's default, but not actually the same (for instance, because of schema search path differences) it would not be recognized as different, so that after dump and restore the child would be allowed to inherit the parent's default. Child columns that are NOT NULL where their parent is not could also be restored subtly incorrectly. - Fix pg_restore's direct-to-database mode for INSERT-style table data. Direct-to-database restores from archive files made with "--inserts" or "--column-inserts" options fail when using pg_restore from a release dated September or December 2011, as a result of an oversight in a fix for another problem. The archive file itself is not at fault, and text-mode output is okay. - Allow AT option in ecpg DEALLOCATE statements. The infrastructure to support this has been there for awhile, but through an oversight there was still an error check rejecting the case. - Fix error in "contrib/intarray"'s int[] & int[] operator. If the smallest integer the two input arrays have in common is 1, and there are smaller values in either array, then 1 would be incorrectly omitted from the result. - Fix error detection in "contrib/pgcrypto"'s encrypt_iv() and decrypt_iv(). These functions failed to report certain types of invalid-input errors, and would instead return random garbage values for incorrect input. - Fix one-byte buffer overrun in "contrib/test_parser". The code would try to read one more byte than it should, which would crash in corner cases. Since "contrib/test_parser" is only example code, this is not a security issue in itself, but bad example code is still bad. - Use __sync_lock_test_and_set() for spinlocks on ARM, if available. This function replaces our previous use of the SWPB instruction, which is deprecated and not available on ARMv6 and later. Reports suggest that the old code doesn't fail in an obvious way on recent ARM boards, but simply doesn't interlock concurrent accesses, leading to bizarre failures in multiprocess operation. - Use "-fexcess-precision=standard" option when building with gcc versions that accept it. This prevents assorted scenarios wherein recent versions of gcc will produce creative results. - Allow use of threaded Python on FreeBSD. Our configure script previously believed that this combination wouldn't work; but FreeBSD fixed the problem, so remove that error check. * Drop 00git_inet_cidr_unpack.patch, 04-armel-tas.patch, applied upstream. Date: Mon, 27 Feb 2012 15:05:31 +0100 Changed-By: Martin Pitt Maintainer: Ubuntu Developers https://launchpad.net/ubuntu/natty/+source/postgresql-8.4/8.4.11-0ubuntu0.11.04 -------------- next part -------------- Format: 1.8 Date: Mon, 27 Feb 2012 15:05:31 +0100 Source: postgresql-8.4 Binary: libpq-dev libpq5 libecpg6 libecpg-dev libecpg-compat3 libpgtypes3 postgresql-8.4 postgresql-client-8.4 postgresql-server-dev-8.4 postgresql-doc-8.4 postgresql-contrib-8.4 postgresql-plperl-8.4 postgresql-plpython-8.4 postgresql-pltcl-8.4 postgresql postgresql-client postgresql-doc postgresql-contrib Architecture: source Version: 8.4.11-0ubuntu0.11.04 Distribution: natty-security Urgency: low Maintainer: Ubuntu Developers Changed-By: Martin Pitt Description: libecpg-compat3 - older version of run-time library for ECPG programs libecpg-dev - development files for ECPG (Embedded PostgreSQL for C) libecpg6 - run-time library for ECPG programs libpgtypes3 - shared library libpgtypes for PostgreSQL 8.4 libpq-dev - header files for libpq5 (PostgreSQL library) libpq5 - PostgreSQL C client library postgresql - object-relational SQL database (supported version) postgresql-8.4 - object-relational SQL database, version 8.4 server postgresql-client - front-end programs for PostgreSQL (supported version) postgresql-client-8.4 - front-end programs for PostgreSQL 8.4 postgresql-contrib - additional facilities for PostgreSQL (supported version) postgresql-contrib-8.4 - additional facilities for PostgreSQL postgresql-doc - documentation for the PostgreSQL database management system postgresql-doc-8.4 - documentation for the PostgreSQL database management system postgresql-plperl-8.4 - PL/Perl procedural language for PostgreSQL 8.4 postgresql-plpython-8.4 - PL/Python procedural language for PostgreSQL 8.4 postgresql-pltcl-8.4 - PL/Tcl procedural language for PostgreSQL 8.4 postgresql-server-dev-8.4 - development files for PostgreSQL 8.4 server-side programming Launchpad-Bugs-Fixed: 941912 Changes: postgresql-8.4 (8.4.11-0ubuntu0.11.04) natty-security; urgency=low . * New upstream bug fix/security release: (LP: #941912) - Require execute permission on the trigger function for "CREATE TRIGGER". This missing check could allow another user to execute a trigger function with forged input data, by installing it on a table he owns. This is only of significance for trigger functions marked SECURITY DEFINER, since otherwise trigger functions run as the table owner anyway. (CVE-2012-0866) - Remove arbitrary limitation on length of common name in SSL certificates. Both libpq and the server truncated the common name extracted from an SSL certificate at 32 bytes. Normally this would cause nothing worse than an unexpected verification failure, but there are some rather-implausible scenarios in which it might allow one certificate holder to impersonate another. The victim would have to have a common name exactly 32 bytes long, and the attacker would have to persuade a trusted CA to issue a certificate in which the common name has that string as a prefix. Impersonating a server would also require some additional exploit to redirect client connections. (CVE-2012-0867) - Convert newlines to spaces in names written in pg_dump comments. pg_dump was incautious about sanitizing object names that are emitted within SQL comments in its output script. A name containing a newline would at least render the script syntactically incorrect. Maliciously crafted object names could present a SQL injection risk when the script is reloaded. (CVE-2012-0868) - Fix btree index corruption from insertions concurrent with vacuuming. An index page split caused by an insertion could sometimes cause a concurrently-running "VACUUM" to miss removing index entries that it should remove. After the corresponding table rows are removed, the dangling index entries would cause errors (such as "could not read block N in file ...") or worse, silently wrong query results after unrelated rows are re-inserted at the now-free table locations. This bug has been present since release 8.2, but occurs so infrequently that it was not diagnosed until now. If you have reason to suspect that it has happened in your database, reindexing the affected index will fix things. - Update per-column permissions, not only per-table permissions, when changing table owner. Failure to do this meant that any previously granted column permissions were still shown as having been granted by the old owner. This meant that neither the new owner nor a superuser could revoke the now-untraceable-to-table-owner permissions. - Allow non-existent values for some settings in "ALTER USER/DATABASE SET". Allow default_text_search_config, default_tablespace, and temp_tablespaces to be set to names that are not known. This is because they might be known in another database where the setting is intended to be used, or for the tablespace cases because the tablespace might not be created yet. The same issue was previously recognized for search_path, and these settings now act like that one. - Avoid crashing when we have problems deleting table files post-commit. Dropping a table should lead to deleting the underlying disk files only after the transaction commits. In event of failure then (for instance, because of wrong file permissions) the code is supposed to just emit a warning message and go on, since it's too late to abort the transaction. This logic got broken as of release 8.4, causing such situations to result in a PANIC and an unrestartable database. - Track the OID counter correctly during WAL replay, even when it wraps around. Previously the OID counter would remain stuck at a high value until the system exited replay mode. The practical consequences of that are usually nil, but there are scenarios wherein a standby server that's been promoted to master might take a long time to advance the OID counter to a reasonable value once values are needed. - Fix regular expression back-references with - attached. Rather than enforcing an exact string match, the code would effectively accept any string that satisfies the pattern sub-expression referenced by the back-reference symbol. A similar problem still afflicts back-references that are embedded in a larger quantified expression, rather than being the immediate subject of the quantifier. This will be addressed in a future PostgreSQL release. - Fix recently-introduced memory leak in processing of inet/cidr values. - Fix dangling pointer after "CREATE TABLE AS"/"SELECT INTO" in a SQL-language function. In most cases this only led to an assertion failure in assert-enabled builds, but worse consequences seem possible. - Fix I/O-conversion-related memory leaks in plpgsql. - Improve pg_dump's handling of inherited table columns. pg_dump mishandled situations where a child column has a different default expression than its parent column. If the default is textually identical to the parent's default, but not actually the same (for instance, because of schema search path differences) it would not be recognized as different, so that after dump and restore the child would be allowed to inherit the parent's default. Child columns that are NOT NULL where their parent is not could also be restored subtly incorrectly. - Fix pg_restore's direct-to-database mode for INSERT-style table data. Direct-to-database restores from archive files made with "--inserts" or "--column-inserts" options fail when using pg_restore from a release dated September or December 2011, as a result of an oversight in a fix for another problem. The archive file itself is not at fault, and text-mode output is okay. - Allow AT option in ecpg DEALLOCATE statements. The infrastructure to support this has been there for awhile, but through an oversight there was still an error check rejecting the case. - Fix error in "contrib/intarray"'s int[] & int[] operator. If the smallest integer the two input arrays have in common is 1, and there are smaller values in either array, then 1 would be incorrectly omitted from the result. - Fix error detection in "contrib/pgcrypto"'s encrypt_iv() and decrypt_iv(). These functions failed to report certain types of invalid-input errors, and would instead return random garbage values for incorrect input. - Fix one-byte buffer overrun in "contrib/test_parser". The code would try to read one more byte than it should, which would crash in corner cases. Since "contrib/test_parser" is only example code, this is not a security issue in itself, but bad example code is still bad. - Use __sync_lock_test_and_set() for spinlocks on ARM, if available. This function replaces our previous use of the SWPB instruction, which is deprecated and not available on ARMv6 and later. Reports suggest that the old code doesn't fail in an obvious way on recent ARM boards, but simply doesn't interlock concurrent accesses, leading to bizarre failures in multiprocess operation. - Use "-fexcess-precision=standard" option when building with gcc versions that accept it. This prevents assorted scenarios wherein recent versions of gcc will produce creative results. - Allow use of threaded Python on FreeBSD. Our configure script previously believed that this combination wouldn't work; but FreeBSD fixed the problem, so remove that error check. * Drop 00git_inet_cidr_unpack.patch, 04-armel-tas.patch, applied upstream. Checksums-Sha1: ffa89dcdc92d9b0290b4893bacc21df849350b5d 2605 postgresql-8.4_8.4.11-0ubuntu0.11.04.dsc b12084003937d8ed59287b6db2508e098ac52953 18178451 postgresql-8.4_8.4.11.orig.tar.gz efaa486fbb1d669026a410dbc1c6af0db03b34bc 49998 postgresql-8.4_8.4.11-0ubuntu0.11.04.diff.gz Checksums-Sha256: b6f354d82f49ac591f24e7fe5189c0f27222c71126d225eab2c128fc6fe8dac4 2605 postgresql-8.4_8.4.11-0ubuntu0.11.04.dsc 5d430fe7b72ad466d477867bad8ee428b25eeefbd161560dc13ac73d77b3541d 18178451 postgresql-8.4_8.4.11.orig.tar.gz d30d370e38829a26961470293dd26539c0688ac0064e83e1ee62ff989a92b557 49998 postgresql-8.4_8.4.11-0ubuntu0.11.04.diff.gz Files: fe25a0e8e0b10ed6b29f01fb20a4e640 2605 database optional postgresql-8.4_8.4.11-0ubuntu0.11.04.dsc 413b8ae9ae6e7f053e2a992e068af63e 18178451 database optional postgresql-8.4_8.4.11.orig.tar.gz 0fde7997f1f41d7186ccb15a411a7b88 49998 database optional postgresql-8.4_8.4.11-0ubuntu0.11.04.diff.gz Original-Maintainer: Martin Pitt From chris.j.arges at canonical.com Wed Feb 29 16:59:17 2012 From: chris.j.arges at canonical.com (Chris J Arges) Date: Wed, 29 Feb 2012 16:59:17 -0000 Subject: [ubuntu/natty-proposed] kexec-tools 1:2.0.1-2ubuntu5 (Accepted) Message-ID: <20120229165917.27761.51852.launchpad@cocoplum.canonical.com> kexec-tools (1:2.0.1-2ubuntu5) natty-proposed; urgency=low * Backport changes to fix kdump functionality. LP: #828731. - debian/kdump.initramfs: call /usr/bin/makedumpfile via a chroot command, so that if makedumpfile is statically linked, we get proper library resolution. Thanks to Louis Bouchard for the patch. LP: #785425. - debian/kdump.initramfs: handle the possibility that /usr, /boot, or /var is on a separate filesystem and needs to be manually mounted before calling makedumpfile. LP: #828731. - Depend on makedumpfile, without which the initramfs script doesn't work. - Fix an unnecessary bashism. - Only install the kdump initramfs script and depend on makedumpfile on architectures that makedumpfile supports. Date: Wed, 18 Jan 2012 17:05:10 -0600 Changed-By: Chris J Arges Maintainer: Ubuntu Developers Signed-By: Barry Warsaw https://launchpad.net/ubuntu/natty/+source/kexec-tools/1:2.0.1-2ubuntu5 -------------- next part -------------- Format: 1.8 Date: Wed, 18 Jan 2012 17:05:10 -0600 Source: kexec-tools Binary: kexec-tools Architecture: source Version: 1:2.0.1-2ubuntu5 Distribution: natty-proposed Urgency: low Maintainer: Ubuntu Developers Changed-By: Chris J Arges Description: kexec-tools - kexec tool for kexec reboots Launchpad-Bugs-Fixed: 785425 828731 Changes: kexec-tools (1:2.0.1-2ubuntu5) natty-proposed; urgency=low . * Backport changes to fix kdump functionality. LP: #828731. - debian/kdump.initramfs: call /usr/bin/makedumpfile via a chroot command, so that if makedumpfile is statically linked, we get proper library resolution. Thanks to Louis Bouchard for the patch. LP: #785425. - debian/kdump.initramfs: handle the possibility that /usr, /boot, or /var is on a separate filesystem and needs to be manually mounted before calling makedumpfile. LP: #828731. - Depend on makedumpfile, without which the initramfs script doesn't work. - Fix an unnecessary bashism. - Only install the kdump initramfs script and depend on makedumpfile on architectures that makedumpfile supports. Checksums-Sha1: 2123ca39dca8499c2b6002121da5e37bc371c298 1854 kexec-tools_2.0.1-2ubuntu5.dsc cce32544b158e19daf47d195c0cd387e58ed239f 19788 kexec-tools_2.0.1-2ubuntu5.diff.gz Checksums-Sha256: 0df02d9c76676daf56ce75192f9791e2895392e6010d5b51dbe0579a42aa1765 1854 kexec-tools_2.0.1-2ubuntu5.dsc 40dd6f7756669ee0bb47fd02d17f179df64575fdcce6a38dd288f870e53ed5eb 19788 kexec-tools_2.0.1-2ubuntu5.diff.gz Files: 3ab52dc5809d9c9b3d9be0bda7d856f7 1854 admin optional kexec-tools_2.0.1-2ubuntu5.dsc 9a2a3ee0d6fbd36a5810ceae4ba90c77 19788 admin optional kexec-tools_2.0.1-2ubuntu5.diff.gz Original-Maintainer: Khalid Aziz