From stgraber at ubuntu.com Mon Jan 2 17:17:09 2012 From: stgraber at ubuntu.com (Stephane Graber) Date: Mon, 02 Jan 2012 17:17:09 -0000 Subject: [ubuntu/natty-proposed] opencryptoki 2.2.8+dfsg-4ubuntu0.11.04.1 (Accepted) Message-ID: <20120102171709.31948.73980.launchpad@gac.canonical.com> opencryptoki (2.2.8+dfsg-4ubuntu0.11.04.1) natty-proposed; urgency=low * Cherry-pick patch from Deibna to reset TPM datastructures on init and not just logout, fixes TPM token reinitialization failure on reload. Thanks to David Smith for the patch (LP: #645576) Date: Wed, 07 Dec 2011 11:25:22 -0500 Changed-By: Stéphane Graber Maintainer: Ubuntu Developers https://launchpad.net/ubuntu/natty/+source/opencryptoki/2.2.8+dfsg-4ubuntu0.11.04.1 -------------- next part -------------- Format: 1.8 Date: Wed, 07 Dec 2011 11:25:22 -0500 Source: opencryptoki Binary: opencryptoki opencryptoki-dbg libopencryptoki0 libopencryptoki-dev Architecture: source Version: 2.2.8+dfsg-4ubuntu0.11.04.1 Distribution: natty-proposed Urgency: low Maintainer: Ubuntu Developers Changed-By: Stéphane Graber Description: libopencryptoki-dev - PKCS#11 implementation for Linux (development) libopencryptoki0 - PKCS#11 implementation for Linux (library) opencryptoki - PKCS#11 implementation for Linux (daemon) opencryptoki-dbg - PKCS#11 implementation for Linux (debug) Launchpad-Bugs-Fixed: 645576 Changes: opencryptoki (2.2.8+dfsg-4ubuntu0.11.04.1) natty-proposed; urgency=low . * Cherry-pick patch from Deibna to reset TPM datastructures on init and not just logout, fixes TPM token reinitialization failure on reload. Thanks to David Smith for the patch (LP: #645576) Checksums-Sha1: 99adb706f3def222d3f5653e3ec6cb7466c896f8 2109 opencryptoki_2.2.8+dfsg-4ubuntu0.11.04.1.dsc dd478605b335b0da2d45c22bbc806d2d47234fa3 13909 opencryptoki_2.2.8+dfsg-4ubuntu0.11.04.1.diff.gz Checksums-Sha256: b9b868bc88941df412db0b5e27375b05daba2f555e25b687d8defc83cdf7e47f 2109 opencryptoki_2.2.8+dfsg-4ubuntu0.11.04.1.dsc 15689cb47bd28b14e43eeefcb8830230ae65aa8cc46176b1a8f6e830fff6ae74 13909 opencryptoki_2.2.8+dfsg-4ubuntu0.11.04.1.diff.gz Files: aad91552ed842edb1738fb09b2b5cc6b 2109 admin optional opencryptoki_2.2.8+dfsg-4ubuntu0.11.04.1.dsc 9ddf1794ec3540027454e59c706734e7 13909 admin optional opencryptoki_2.2.8+dfsg-4ubuntu0.11.04.1.diff.gz Original-Maintainer: Debian QA Group From jamie at ubuntu.com Wed Jan 4 00:03:22 2012 From: jamie at ubuntu.com (Jamie Strandboge) Date: Wed, 04 Jan 2012 00:03:22 -0000 Subject: [ubuntu/natty-security] selinux 1:0.10~11.04.1 (Accepted) Message-ID: <20120104000322.6684.73801.launchpad@cocoplum.canonical.com> selinux (1:0.10~11.04.1) natty-security; urgency=low * Fix unsafe lockfile creation. The scope of this is limited by when this script is run. On Ubuntu 10.10 and higher, Yama blocks exploitation of this issue, but we want to fix this on Ubuntu 10.04 LTS (which doesn't have Yama) and so this package is provided for upgrades. (LP: #876994) Date: Wed, 21 Dec 2011 12:19:08 -0600 Changed-By: Jamie Strandboge Maintainer: Ubuntu Hardened Developers https://launchpad.net/ubuntu/natty/+source/selinux/1:0.10~11.04.1 -------------- next part -------------- Format: 1.8 Date: Wed, 21 Dec 2011 12:19:08 -0600 Source: selinux Binary: selinux Architecture: source Version: 1:0.10~11.04.1 Distribution: natty-security Urgency: low Maintainer: Ubuntu Hardened Developers Changed-By: Jamie Strandboge Description: selinux - Security-Enhanced Linux runtime support Launchpad-Bugs-Fixed: 876994 Changes: selinux (1:0.10~11.04.1) natty-security; urgency=low . * Fix unsafe lockfile creation. The scope of this is limited by when this script is run. On Ubuntu 10.10 and higher, Yama blocks exploitation of this issue, but we want to fix this on Ubuntu 10.04 LTS (which doesn't have Yama) and so this package is provided for upgrades. (LP: #876994) Checksums-Sha1: c5a30bc12b30460a81227c47db552461796e0a38 1445 selinux_0.10~11.04.1.dsc b430fdf05b1b22885041c9e774eec094fd989e79 10096 selinux_0.10~11.04.1.tar.gz Checksums-Sha256: 1c47231fa317ffaa88a6ca17325d7c6381d329095bc3c0610eb5cb244a519b41 1445 selinux_0.10~11.04.1.dsc 53b6d20778a8c6636db45af4e8b30582da10536ae694767eaee6c96badd94e3a 10096 selinux_0.10~11.04.1.tar.gz Files: 01a7ed8fdee29c2c6cbdc7256f215933 1445 admin optional selinux_0.10~11.04.1.dsc 7dd8aa5a2e4fbd30e9e1e65eb678947f 10096 admin optional selinux_0.10~11.04.1.tar.gz Original-Maintainer: J. Tang From martin.pitt at ubuntu.com Thu Jan 5 12:38:42 2012 From: martin.pitt at ubuntu.com (Martin Pitt) Date: Thu, 05 Jan 2012 12:38:42 -0000 Subject: [ubuntu/natty-proposed] postgresql-8.4 8.4.10-0ubuntu0.11.04.1 (Accepted) Message-ID: <20120105123842.29099.71918.launchpad@gac.canonical.com> postgresql-8.4 (8.4.10-0ubuntu0.11.04.1) natty-proposed; urgency=low * Add 00git_inet_cidr_unpack.patch: Revert the behavior of inet/cidr functions to not unpack the arguments. This fixes the memory leak when sorting inet values. Patch taken from upstream git HEAD. Spotted during testing in LP #904631. * 01-armel-tas.patch: Turn slock_t datatype into an int, and define S_UNLOCK() to call __sync_lock_release() instead of using the default implementation. This complies to the gcc built-in atomic operations specifiction more strictly and now also works on the Panda boards. (LP: #904828) postgresql-8.4 (8.4.10-0ubuntu0.11.04) natty-proposed; urgency=low * New upstream release (LP: #904631): - Fix bugs in information_schema.referential_constraints view. This view was being insufficiently careful about matching the foreign-key constraint to the depended-on primary or unique key constraint. That could result in failure to show a foreign key constraint at all, or showing it multiple times, or claiming that it depends on a different constraint than the one it really does. Since the view definition is installed by initdb, merely upgrading will not fix the problem. If you need to fix this in an existing installation, you can (as a superuser) drop the information_schema schema then re-create it by sourcing "SHAREDIR/information_schema.sql". (Run pg_config --sharedir if you're uncertain where "SHAREDIR" is.) This must be repeated in each database to be fixed. - Fix incorrect replay of WAL records for GIN index updates. This could result in transiently failing to find index entries after a crash, or on a hot-standby server. The problem would be repaired by the next "VACUUM" of the index, however. - Fix TOAST-related data corruption during CREATE TABLE dest AS SELECT - FROM src or INSERT INTO dest SELECT * FROM src. If a table has been modified by "ALTER TABLE ADD COLUMN", attempts to copy its data verbatim to another table could produce corrupt results in certain corner cases. The problem can only manifest in this precise form in 8.4 and later, but we patched earlier versions as well in case there are other code paths that could trigger the same bug. - Fix race condition during toast table access from stale syscache entries. - Track dependencies of functions on items used in parameter default expressions. Previously, a referenced object could be dropped without having dropped or modified the function, leading to misbehavior when the function was used. Note that merely installing this update will not fix the missing dependency entries; to do that, you'd need to "CREATE OR REPLACE" each such function afterwards. If you have functions whose defaults depend on non-built-in objects, doing so is recommended. - Allow inlining of set-returning SQL functions with multiple OUT parameters. - Make DatumGetInetP() unpack inet datums that have a 1-byte header, and add a new macro, DatumGetInetPP(), that does not. - Improve locale support in money type's input and output. Aside from not supporting all standard lc_monetary formatting options, the input and output functions were inconsistent, meaning there were locales in which dumped money values could not be re-read. - Don't let transform_null_equals affect CASE foo WHEN NULL ... constructs. transform_null_equals is only supposed to affect foo = NULL expressions written directly by the user, not equality checks generated internally by this form of CASE. - Change foreign-key trigger creation order to better support self-referential foreign keys. For a cascading foreign key that references its own table, a row update will fire both the ON UPDATE trigger and the CHECK trigger as one event. The ON UPDATE trigger must execute first, else the CHECK will check a non-final state of the row and possibly throw an inappropriate error. However, the firing order of these triggers is determined by their names, which generally sort in creation order since the triggers have auto-generated names following the convention "RI_ConstraintTrigger_NNNN". A proper fix would require modifying that convention, which we will do in 9.2, but it seems risky to change it in existing releases. So this patch just changes the creation order of the triggers. Users encountering this type of error should drop and re-create the foreign key constraint to get its triggers into the right order. - Avoid floating-point underflow while tracking buffer allocation rate. - Preserve blank lines within commands in psql's command history. The former behavior could cause problems if an empty line was removed from within a string literal, for example. - Fix pg_dump to dump user-defined casts between auto-generated types, such as table rowtypes. - Use the preferred version of xsubpp to build PL/Perl, not necessarily the operating system's main copy. - Fix incorrect coding in "contrib/dict_int" and "contrib/dict_xsyn". - Honor query cancel interrupts promptly in pgstatindex(). - Ensure VPATH builds properly install all server header files. - Shorten file names reported in verbose error messages. Regular builds have always reported just the name of the C file containing the error message call, but VPATH builds formerly reported an absolute path name. Date: Thu, 05 Jan 2012 13:09:44 +0100 Changed-By: Martin Pitt Maintainer: Ubuntu Developers https://launchpad.net/ubuntu/natty/+source/postgresql-8.4/8.4.10-0ubuntu0.11.04.1 -------------- next part -------------- Format: 1.8 Date: Thu, 05 Jan 2012 13:09:44 +0100 Source: postgresql-8.4 Binary: libpq-dev libpq5 libecpg6 libecpg-dev libecpg-compat3 libpgtypes3 postgresql-8.4 postgresql-client-8.4 postgresql-server-dev-8.4 postgresql-doc-8.4 postgresql-contrib-8.4 postgresql-plperl-8.4 postgresql-plpython-8.4 postgresql-pltcl-8.4 postgresql postgresql-client postgresql-doc postgresql-contrib Architecture: source Version: 8.4.10-0ubuntu0.11.04.1 Distribution: natty-proposed Urgency: low Maintainer: Ubuntu Developers Changed-By: Martin Pitt Description: libecpg-compat3 - older version of run-time library for ECPG programs libecpg-dev - development files for ECPG (Embedded PostgreSQL for C) libecpg6 - run-time library for ECPG programs libpgtypes3 - shared library libpgtypes for PostgreSQL 8.4 libpq-dev - header files for libpq5 (PostgreSQL library) libpq5 - PostgreSQL C client library postgresql - object-relational SQL database (supported version) postgresql-8.4 - object-relational SQL database, version 8.4 server postgresql-client - front-end programs for PostgreSQL (supported version) postgresql-client-8.4 - front-end programs for PostgreSQL 8.4 postgresql-contrib - additional facilities for PostgreSQL (supported version) postgresql-contrib-8.4 - additional facilities for PostgreSQL postgresql-doc - documentation for the PostgreSQL database management system postgresql-doc-8.4 - documentation for the PostgreSQL database management system postgresql-plperl-8.4 - PL/Perl procedural language for PostgreSQL 8.4 postgresql-plpython-8.4 - PL/Python procedural language for PostgreSQL 8.4 postgresql-pltcl-8.4 - PL/Tcl procedural language for PostgreSQL 8.4 postgresql-server-dev-8.4 - development files for PostgreSQL 8.4 server-side programming Launchpad-Bugs-Fixed: 904631 904828 Changes: postgresql-8.4 (8.4.10-0ubuntu0.11.04.1) natty-proposed; urgency=low . * Add 00git_inet_cidr_unpack.patch: Revert the behavior of inet/cidr functions to not unpack the arguments. This fixes the memory leak when sorting inet values. Patch taken from upstream git HEAD. Spotted during testing in LP #904631. * 01-armel-tas.patch: Turn slock_t datatype into an int, and define S_UNLOCK() to call __sync_lock_release() instead of using the default implementation. This complies to the gcc built-in atomic operations specifiction more strictly and now also works on the Panda boards. (LP: #904828) . postgresql-8.4 (8.4.10-0ubuntu0.11.04) natty-proposed; urgency=low . * New upstream release (LP: #904631): - Fix bugs in information_schema.referential_constraints view. This view was being insufficiently careful about matching the foreign-key constraint to the depended-on primary or unique key constraint. That could result in failure to show a foreign key constraint at all, or showing it multiple times, or claiming that it depends on a different constraint than the one it really does. Since the view definition is installed by initdb, merely upgrading will not fix the problem. If you need to fix this in an existing installation, you can (as a superuser) drop the information_schema schema then re-create it by sourcing "SHAREDIR/information_schema.sql". (Run pg_config --sharedir if you're uncertain where "SHAREDIR" is.) This must be repeated in each database to be fixed. - Fix incorrect replay of WAL records for GIN index updates. This could result in transiently failing to find index entries after a crash, or on a hot-standby server. The problem would be repaired by the next "VACUUM" of the index, however. - Fix TOAST-related data corruption during CREATE TABLE dest AS SELECT - FROM src or INSERT INTO dest SELECT * FROM src. If a table has been modified by "ALTER TABLE ADD COLUMN", attempts to copy its data verbatim to another table could produce corrupt results in certain corner cases. The problem can only manifest in this precise form in 8.4 and later, but we patched earlier versions as well in case there are other code paths that could trigger the same bug. - Fix race condition during toast table access from stale syscache entries. - Track dependencies of functions on items used in parameter default expressions. Previously, a referenced object could be dropped without having dropped or modified the function, leading to misbehavior when the function was used. Note that merely installing this update will not fix the missing dependency entries; to do that, you'd need to "CREATE OR REPLACE" each such function afterwards. If you have functions whose defaults depend on non-built-in objects, doing so is recommended. - Allow inlining of set-returning SQL functions with multiple OUT parameters. - Make DatumGetInetP() unpack inet datums that have a 1-byte header, and add a new macro, DatumGetInetPP(), that does not. - Improve locale support in money type's input and output. Aside from not supporting all standard lc_monetary formatting options, the input and output functions were inconsistent, meaning there were locales in which dumped money values could not be re-read. - Don't let transform_null_equals affect CASE foo WHEN NULL ... constructs. transform_null_equals is only supposed to affect foo = NULL expressions written directly by the user, not equality checks generated internally by this form of CASE. - Change foreign-key trigger creation order to better support self-referential foreign keys. For a cascading foreign key that references its own table, a row update will fire both the ON UPDATE trigger and the CHECK trigger as one event. The ON UPDATE trigger must execute first, else the CHECK will check a non-final state of the row and possibly throw an inappropriate error. However, the firing order of these triggers is determined by their names, which generally sort in creation order since the triggers have auto-generated names following the convention "RI_ConstraintTrigger_NNNN". A proper fix would require modifying that convention, which we will do in 9.2, but it seems risky to change it in existing releases. So this patch just changes the creation order of the triggers. Users encountering this type of error should drop and re-create the foreign key constraint to get its triggers into the right order. - Avoid floating-point underflow while tracking buffer allocation rate. - Preserve blank lines within commands in psql's command history. The former behavior could cause problems if an empty line was removed from within a string literal, for example. - Fix pg_dump to dump user-defined casts between auto-generated types, such as table rowtypes. - Use the preferred version of xsubpp to build PL/Perl, not necessarily the operating system's main copy. - Fix incorrect coding in "contrib/dict_int" and "contrib/dict_xsyn". - Honor query cancel interrupts promptly in pgstatindex(). - Ensure VPATH builds properly install all server header files. - Shorten file names reported in verbose error messages. Regular builds have always reported just the name of the C file containing the error message call, but VPATH builds formerly reported an absolute path name. Checksums-Sha1: 3e85cfb2ff9144ca49d86eaa19290d78071bbaf0 3321 postgresql-8.4_8.4.10-0ubuntu0.11.04.1.dsc f9b5ad2cbc7304b4b0f284fbf4b8f876af87af54 48711 postgresql-8.4_8.4.10-0ubuntu0.11.04.1.diff.gz Checksums-Sha256: 9335f9162892f601bfe9a97bc56be2fcd898605065f3e535dd1fc42d7b78c09f 3321 postgresql-8.4_8.4.10-0ubuntu0.11.04.1.dsc d7e325e85908fb660836b560720fb15dc403b40a0d1c0755ab31516dff314154 48711 postgresql-8.4_8.4.10-0ubuntu0.11.04.1.diff.gz Files: 87a6597899f753aedd5e2cead16348f6 3321 database optional postgresql-8.4_8.4.10-0ubuntu0.11.04.1.dsc af1e5936b421362490ee12878a319412 48711 database optional postgresql-8.4_8.4.10-0ubuntu0.11.04.1.diff.gz Original-Maintainer: Martin Pitt From forest.bond at rapidrollout.com Thu Jan 12 16:27:55 2012 From: forest.bond at rapidrollout.com (Forest Bond) Date: Thu, 12 Jan 2012 16:27:55 -0000 Subject: [ubuntu/natty-proposed] python-tz 2010b-1ubuntu0.11.04.1 (Accepted) Message-ID: <20120112162755.11222.70945.launchpad@wampee.canonical.com> python-tz (2010b-1ubuntu0.11.04.1) natty-proposed; urgency=low * Add patch samoa-idl (LP: #885163). Date: Mon, 09 Jan 2012 22:05:30 +0200 Changed-By: Forest Bond Maintainer: Ubuntu Developers Signed-By: Stefano Rivera https://launchpad.net/ubuntu/natty/+source/python-tz/2010b-1ubuntu0.11.04.1 -------------- next part -------------- Format: 1.8 Date: Mon, 09 Jan 2012 22:05:30 +0200 Source: python-tz Binary: python-tz Architecture: source Version: 2010b-1ubuntu0.11.04.1 Distribution: natty-proposed Urgency: low Maintainer: Ubuntu Developers Changed-By: Forest Bond Description: python-tz - Python version of the Olson timezone database Launchpad-Bugs-Fixed: 885163 Changes: python-tz (2010b-1ubuntu0.11.04.1) natty-proposed; urgency=low . * Add patch samoa-idl (LP: #885163). Checksums-Sha1: ee0dee01a05a0a78ef981400dfa2c3c74c5e5d2f 2177 python-tz_2010b-1ubuntu0.11.04.1.dsc 95fd98a0af84afdcc9060a581d487a018c4bb2cc 5112 python-tz_2010b-1ubuntu0.11.04.1.diff.gz Checksums-Sha256: 40b4ab84e5989bcc2593c161e9a6fcce3d04064736b2e0ac9b9565fe8955c99b 2177 python-tz_2010b-1ubuntu0.11.04.1.dsc dfbbd711b5a55818a8b26e0b11084046d9dbeb85875097a7e92a0067f4008ab5 5112 python-tz_2010b-1ubuntu0.11.04.1.diff.gz Files: 074eaa18c25552daf2d945dc7660a938 2177 python optional python-tz_2010b-1ubuntu0.11.04.1.dsc eb72a47f7f59128d97e661bdf1b2677e 5112 python optional python-tz_2010b-1ubuntu0.11.04.1.diff.gz Original-Maintainer: Debian/Ubuntu Zope Team From cjwatson at ubuntu.com Fri Jan 13 17:11:30 2012 From: cjwatson at ubuntu.com (Colin Watson) Date: Fri, 13 Jan 2012 17:11:30 -0000 Subject: [ubuntu/natty-proposed] debian-installer-utils 1.82ubuntu1.2 (Accepted) Message-ID: <20120113171130.18659.74143.launchpad@chaenomeles.canonical.com> debian-installer-utils (1.82ubuntu1.2) natty-proposed; urgency=low [ Scott Moser ] * Add --quiet to dpkg-divert calls in chroot_setup. debian-installer-utils (1.82ubuntu1.1) natty-proposed; urgency=low * chroot_setup.sh: Divert start-stop-daemon and initctl rather than simply moving them aside (LP: #900526). Date: Fri, 06 Jan 2012 12:29:11 +0000 Changed-By: Colin Watson Maintainer: Ubuntu Installer Team https://launchpad.net/ubuntu/natty/+source/debian-installer-utils/1.82ubuntu1.2 -------------- next part -------------- Format: 1.8 Date: Fri, 06 Jan 2012 12:29:11 +0000 Source: debian-installer-utils Binary: di-utils-shell di-utils-reboot di-utils-exit-installer di-utils di-utils-mapdevfs di-utils-terminfo Architecture: source Version: 1.82ubuntu1.2 Distribution: natty-proposed Urgency: low Maintainer: Ubuntu Installer Team Changed-By: Colin Watson Description: di-utils - Miscellaneous utilities for the debian installer (udeb) di-utils-exit-installer - Exit installer (udeb) di-utils-mapdevfs - mapdevfs utility for the debian installer (udeb) di-utils-reboot - Reboot (udeb) di-utils-shell - Execute a shell (udeb) di-utils-terminfo - Terminfo entries needed by newt/slang in debian installer (udeb) Launchpad-Bugs-Fixed: 900526 Changes: debian-installer-utils (1.82ubuntu1.2) natty-proposed; urgency=low . [ Scott Moser ] * Add --quiet to dpkg-divert calls in chroot_setup. . debian-installer-utils (1.82ubuntu1.1) natty-proposed; urgency=low . * chroot_setup.sh: Divert start-stop-daemon and initctl rather than simply moving them aside (LP: #900526). Checksums-Sha1: ea6fab708cc3ab043ebc6fc87dd9f102d49bf60f 2328 debian-installer-utils_1.82ubuntu1.2.dsc 129b435e0c5f1f7ccb76268cb57ab019d75f58ea 106448 debian-installer-utils_1.82ubuntu1.2.tar.gz Checksums-Sha256: 2a83c0ff7ee49ad3ae1ba968ab3079a792409c444d8eb411fef6be31cfca2d0f 2328 debian-installer-utils_1.82ubuntu1.2.dsc 2bb2b599760f8ee15fd610fbd02b00ed3712121d2522d8f1ff63e1e95cd70bd0 106448 debian-installer-utils_1.82ubuntu1.2.tar.gz Files: 3defed2eb7772286659177aee0efd961 2328 debian-installer standard debian-installer-utils_1.82ubuntu1.2.dsc 5971a8e5780701ffbf0eaa0ae99a3a67 106448 debian-installer standard debian-installer-utils_1.82ubuntu1.2.tar.gz Original-Maintainer: Debian Install System Team From gary.lasker at canonical.com Tue Jan 17 05:33:27 2012 From: gary.lasker at canonical.com (Gary Lasker) Date: Tue, 17 Jan 2012 05:33:27 -0000 Subject: [ubuntu/natty-proposed] software-center 4.0.7 (Accepted) Message-ID: <20120117053327.6550.11632.launchpad@gac.canonical.com> software-center (4.0.7) natty-proposed; urgency=low * lp:~gary-lasker/software-center/icon-data-for-4.0: - remove the need for inline icon data from the agent, instead download icons directly using the provided URL (LP: #914054) Date: Wed, 11 Jan 2012 18:25:49 -0500 Changed-By: Gary Lasker Maintainer: Michael Vogt Signed-By: Michael Vogt https://launchpad.net/ubuntu/natty/+source/software-center/4.0.7 -------------- next part -------------- Format: 1.8 Date: Wed, 11 Jan 2012 18:25:49 -0500 Source: software-center Binary: software-center Architecture: source Version: 4.0.7 Distribution: natty-proposed Urgency: low Maintainer: Michael Vogt Changed-By: Gary Lasker Description: software-center - Utility for browsing, installing, and removing applications Launchpad-Bugs-Fixed: 914054 Changes: software-center (4.0.7) natty-proposed; urgency=low . * lp:~gary-lasker/software-center/icon-data-for-4.0: - remove the need for inline icon data from the agent, instead download icons directly using the provided URL (LP: #914054) Checksums-Sha1: acb6f7e49e03ac7a19921f6dd186495769273266 1034 software-center_4.0.7.dsc 913c6ab78ae19d0671020e1020a12d73cd28ecfa 775238 software-center_4.0.7.tar.gz Checksums-Sha256: b17eafcd5be86f54c211a7942dd767e4274cb734995750ebd0f8e4bd3e51cee9 1034 software-center_4.0.7.dsc 3f935eebcce9fc4b7a9b81f87cce62927d92b31a0cefd44dfb6f61cba2ed3dc0 775238 software-center_4.0.7.tar.gz Files: 83a8dd356bf89e475ecedb8d32dbd937 1034 gnome optional software-center_4.0.7.dsc b01364a3c7d8abd529e43aff264c88c6 775238 gnome optional software-center_4.0.7.tar.gz From evan at ebroder.net Tue Jan 17 05:33:53 2012 From: evan at ebroder.net (Evan Broder) Date: Tue, 17 Jan 2012 05:33:53 -0000 Subject: [ubuntu/natty-proposed] youtube-dl 2011.08.04-1~natty0.1 (Accepted) Message-ID: <20120117053353.19195.93220.launchpad@soybean.canonical.com> youtube-dl (2011.08.04-1~natty0.1) natty-proposed; urgency=low * Backport new upstream release to Natty to fix changes in Youtube. (LP: #915029) Date: Wed, 11 Jan 2012 15:53:50 -0500 Changed-By: Evan Broder Maintainer: Rogério Brito https://launchpad.net/ubuntu/natty/+source/youtube-dl/2011.08.04-1~natty0.1 -------------- next part -------------- Format: 1.8 Date: Wed, 11 Jan 2012 15:53:50 -0500 Source: youtube-dl Binary: youtube-dl Architecture: source Version: 2011.08.04-1~natty0.1 Distribution: natty-proposed Urgency: low Maintainer: Rogério Brito Changed-By: Evan Broder Description: youtube-dl - download videos from youtube Launchpad-Bugs-Fixed: 915029 Changes: youtube-dl (2011.08.04-1~natty0.1) natty-proposed; urgency=low . * Backport new upstream release to Natty to fix changes in Youtube. (LP: #915029) Checksums-Sha1: 9b904fd7a62896b029aa3591bd2d90c904ffc884 1803 youtube-dl_2011.08.04-1~natty0.1.dsc 0923b9ca5b4d3307c8bc65addcd9b7895804b111 12644 youtube-dl_2011.08.04-1~natty0.1.debian.tar.gz Checksums-Sha256: 5d617cb2733c8e2cbaf545133cf048b0bd75b1e496482ee354137a6b36130e24 1803 youtube-dl_2011.08.04-1~natty0.1.dsc 5637d3ca6f36b0be8a1b89cbbb9b7b02d723563582288e063c90f826a8305e97 12644 youtube-dl_2011.08.04-1~natty0.1.debian.tar.gz Files: 73f276a041b2e64f6e79087732640b0a 1803 web extra youtube-dl_2011.08.04-1~natty0.1.dsc 55efd4ab56af71629693c5912453ac8b 12644 web extra youtube-dl_2011.08.04-1~natty0.1.debian.tar.gz From mgariepy at ubuntu.com Tue Jan 17 05:34:51 2012 From: mgariepy at ubuntu.com (Marc Gariepy) Date: Tue, 17 Jan 2012 05:34:51 -0000 Subject: [ubuntu/natty-proposed] chemtool 1.6.12-1ubuntu1.11.04.1 (Accepted) Message-ID: <20120117053451.17744.71893.launchpad@soybean.canonical.com> chemtool (1.6.12-1ubuntu1.11.04.1) natty-proposed; urgency=low * Cherry-pick bugfixes from Debian - Fix gettext support initialization (LP: #839745) * Move existing in-line changes to Makefile.in to a patch * Add quilt patch system Date: Wed, 07 Dec 2011 14:56:16 -0500 Changed-By: Marc Gariépy Maintainer: Ubuntu Developers Signed-By: =?utf-8?q?St=C3=A9phane_Graber?= https://launchpad.net/ubuntu/natty/+source/chemtool/1.6.12-1ubuntu1.11.04.1 -------------- next part -------------- Format: 1.8 Date: Wed, 07 Dec 2011 14:56:16 -0500 Source: chemtool Binary: chemtool Architecture: source Version: 1.6.12-1ubuntu1.11.04.1 Distribution: natty-proposed Urgency: low Maintainer: Ubuntu Developers Changed-By: Marc Gariépy Description: chemtool - Chemical structures drawing program Launchpad-Bugs-Fixed: 839745 Changes: chemtool (1.6.12-1ubuntu1.11.04.1) natty-proposed; urgency=low . * Cherry-pick bugfixes from Debian - Fix gettext support initialization (LP: #839745) * Move existing in-line changes to Makefile.in to a patch * Add quilt patch system Checksums-Sha1: cc59d285258bf806b69099aaaa28507ffd1c16b5 2171 chemtool_1.6.12-1ubuntu1.11.04.1.dsc d3275f5ce2a1884161ebd66bd031b4858350571e 9037 chemtool_1.6.12-1ubuntu1.11.04.1.diff.gz Checksums-Sha256: b1da2f1730f8019562a0ae3662f2e5a5b2b7b360578a6c6086bb29eb7860e2dd 2171 chemtool_1.6.12-1ubuntu1.11.04.1.dsc bb5223ad26cf8fd4288a45dbcbedc18f171d065171ed10f13ca469c8911873c0 9037 chemtool_1.6.12-1ubuntu1.11.04.1.diff.gz Files: 69a543dbf89e8300356daaa289686412 2171 science optional chemtool_1.6.12-1ubuntu1.11.04.1.dsc e566eef0a9f0da4eb302e1af0bc3a866 9037 science optional chemtool_1.6.12-1ubuntu1.11.04.1.diff.gz Original-Maintainer: Debichem Team From serge.hallyn at ubuntu.com Tue Jan 17 05:35:13 2012 From: serge.hallyn at ubuntu.com (Serge Hallyn) Date: Tue, 17 Jan 2012 05:35:13 -0000 Subject: [ubuntu/natty-proposed] libvirt 0.8.8-1ubuntu6.8 (Accepted) Message-ID: <20120117053513.5238.79391.launchpad@gac.canonical.com> libvirt (0.8.8-1ubuntu6.8) natty-proposed; urgency=low * add parted to build-depends (LP: #697046) Date: Wed, 14 Dec 2011 09:37:48 -0600 Changed-By: Serge Hallyn Maintainer: Ubuntu Developers https://launchpad.net/ubuntu/natty/+source/libvirt/0.8.8-1ubuntu6.8 -------------- next part -------------- Format: 1.8 Date: Wed, 14 Dec 2011 09:37:48 -0600 Source: libvirt Binary: libvirt-bin libvirt0 libvirt0-dbg libvirt-doc libvirt-dev python-libvirt Architecture: source Version: 0.8.8-1ubuntu6.8 Distribution: natty-proposed Urgency: low Maintainer: Ubuntu Developers Changed-By: Serge Hallyn Description: libvirt-bin - the programs for the libvirt library libvirt-dev - development files for the libvirt library libvirt-doc - documentation for the libvirt library libvirt0 - library for interfacing with different virtualization systems libvirt0-dbg - library for interfacing with different virtualization systems python-libvirt - libvirt Python bindings Launchpad-Bugs-Fixed: 697046 Changes: libvirt (0.8.8-1ubuntu6.8) natty-proposed; urgency=low . * add parted to build-depends (LP: #697046) Checksums-Sha1: 4ef145477e74c3ac988b43bd15a6054947e337f0 2325 libvirt_0.8.8-1ubuntu6.8.dsc a521fa89e23ff955acba2d52695e78228deb6e48 71352 libvirt_0.8.8-1ubuntu6.8.debian.tar.gz Checksums-Sha256: 7fe29fbf6fd353310127be49adaed3c9bd78e65e74afed25e82232fd5dccf8e4 2325 libvirt_0.8.8-1ubuntu6.8.dsc b79f79c6fdf63b082731293bb19e96626723cba27370c1af6b5a72dfc92cb81e 71352 libvirt_0.8.8-1ubuntu6.8.debian.tar.gz Files: dc7848aeb50d9b927722b9796a0daac6 2325 libs optional libvirt_0.8.8-1ubuntu6.8.dsc 47190527f4462d3c568c84078c81d568 71352 libs optional libvirt_0.8.8-1ubuntu6.8.debian.tar.gz Original-Maintainer: Debian Libvirt Maintainers From raphink at ubuntu.com Tue Jan 17 05:36:21 2012 From: raphink at ubuntu.com (Raphael Pinson) Date: Tue, 17 Jan 2012 05:36:21 -0000 Subject: [ubuntu/natty-proposed] augeas 0.8.0-0ubuntu5 (Accepted) Message-ID: <20120117053621.17646.51639.launchpad@soybean.canonical.com> augeas (0.8.0-0ubuntu5) natty-proposed; urgency=low * Add patches (LP: #807675): - LP807675_sudoers_include.patch - LP807675_sudoers_runas.patch Date: Sun, 18 Dec 2011 22:48:46 +0100 Changed-By: Raphaël Pinson Maintainer: Ubuntu Developers https://launchpad.net/ubuntu/natty/+source/augeas/0.8.0-0ubuntu5 -------------- next part -------------- Format: 1.8 Date: Sun, 18 Dec 2011 22:48:46 +0100 Source: augeas Binary: augeas-tools libaugeas-dev libaugeas0 augeas-dbg augeas-lenses augeas-doc Architecture: source Version: 0.8.0-0ubuntu5 Distribution: natty-proposed Urgency: low Maintainer: Ubuntu Developers Changed-By: Raphaël Pinson Description: augeas-dbg - Debugging symbols for libaugeas0 augeas-doc - Augeas lenses documentation augeas-lenses - Set of lenses needed by libaugeas0 to parse config files augeas-tools - Augeas command line tools libaugeas-dev - Development files for writing applications based on libaugeas0 libaugeas0 - The augeas configuration editing library and API Launchpad-Bugs-Fixed: 807675 Changes: augeas (0.8.0-0ubuntu5) natty-proposed; urgency=low . * Add patches (LP: #807675): - LP807675_sudoers_include.patch - LP807675_sudoers_runas.patch Checksums-Sha1: 39e8dde45b5bbcf6a9c6f05bd6862538d0390c2e 1504 augeas_0.8.0-0ubuntu5.dsc eeda5dfb53b289b58fb82f5e91aac46d8624053a 1439109 augeas_0.8.0.orig.tar.gz 4e10880b9728f1d542741c4c646784af2369de26 9617 augeas_0.8.0-0ubuntu5.debian.tar.gz Checksums-Sha256: 9e1b038effe8bc020d645c10266abd746859d88c7e851badbf16886d3e540066 1504 augeas_0.8.0-0ubuntu5.dsc a89bce5cd22a40bb46a767005bf8dddf86673f23d768574101ad743ca8a03d31 1439109 augeas_0.8.0.orig.tar.gz 45e67d286eac607c2a64275183fa125ba11806776c6601985b0ff47d9510ad34 9617 augeas_0.8.0-0ubuntu5.debian.tar.gz Files: a7f0db0c9e6534bb499011e2b4fd8f38 1504 libs optional augeas_0.8.0-0ubuntu5.dsc e425bcfc46fd5b18473a4ff47c2878d3 1439109 libs optional augeas_0.8.0.orig.tar.gz 9467b7cbd8dc2ba91eacf2c377637a70 9617 libs optional augeas_0.8.0-0ubuntu5.debian.tar.gz Original-Maintainer: Nicolas Valcárcel Scerpella (Canonical) From james.hunt at ubuntu.com Tue Jan 17 05:36:40 2012 From: james.hunt at ubuntu.com (James Hunt) Date: Tue, 17 Jan 2012 05:36:40 -0000 Subject: [ubuntu/natty-proposed] procps 1:3.2.8-10ubuntu3.2 (Accepted) Message-ID: <20120117053640.28716.52626.launchpad@wampee.canonical.com> procps (1:3.2.8-10ubuntu3.2) natty-proposed; urgency=low * Make procps job run twice: as early as possible (for kernel parameters such as kernel.printk) and then after all network interfaces are up (to account for any kernel parameters relating to recently loaded networking modules) (LP: #771372). procps (1:3.2.8-10ubuntu3.1) natty-proposed; urgency=low [ James Hunt ] * Make procps job run twice: as early as possible (for kernel parameters such as kernel.printk) and then after all network interfaces are up (to account for any kernel parameters relating to recently loaded networking modules) (LP: #771372). Date: Wed, 07 Dec 2011 14:53:24 +0000 Changed-By: James Hunt Maintainer: Ubuntu Developers Signed-By: Steve Langasek https://launchpad.net/ubuntu/natty/+source/procps/1:3.2.8-10ubuntu3.2 -------------- next part -------------- Format: 1.8 Date: Wed, 07 Dec 2011 14:53:24 +0000 Source: procps Binary: procps libproc-dev Architecture: source Version: 1:3.2.8-10ubuntu3.2 Distribution: natty-proposed Urgency: low Maintainer: Ubuntu Developers Changed-By: James Hunt Description: libproc-dev - library for accessing process information from /proc procps - /proc file system utilities Launchpad-Bugs-Fixed: 771372 Changes: procps (1:3.2.8-10ubuntu3.2) natty-proposed; urgency=low . * Make procps job run twice: as early as possible (for kernel parameters such as kernel.printk) and then after all network interfaces are up (to account for any kernel parameters relating to recently loaded networking modules) (LP: #771372). . procps (1:3.2.8-10ubuntu3.1) natty-proposed; urgency=low . [ James Hunt ] * Make procps job run twice: as early as possible (for kernel parameters such as kernel.printk) and then after all network interfaces are up (to account for any kernel parameters relating to recently loaded networking modules) (LP: #771372). Checksums-Sha1: b8b8a5767707795dd1abf1186ae7fb53021eecb3 2006 procps_3.2.8-10ubuntu3.2.dsc 291d35934b687e9c041a502cc5726e42eade89e5 103759 procps_3.2.8-10ubuntu3.2.debian.tar.gz Checksums-Sha256: a03061366e647817cc431b6d71fdfcd4faabbd1acc6d7974a01cf2a7e87a9d30 2006 procps_3.2.8-10ubuntu3.2.dsc fbe26ebd95c6de38e750e36d6e071aab61faa2ee086178e1eb352b8350b5b3cc 103759 procps_3.2.8-10ubuntu3.2.debian.tar.gz Files: d91c391d5e04caaf05949f6a363765d1 2006 admin important procps_3.2.8-10ubuntu3.2.dsc 9d4f25a1c10b16dc8ccc8a98767374d1 103759 admin important procps_3.2.8-10ubuntu3.2.debian.tar.gz Original-Maintainer: Craig Small From micahg at ubuntu.com Tue Jan 17 05:38:16 2012 From: micahg at ubuntu.com (Micah Gersten) Date: Tue, 17 Jan 2012 05:38:16 -0000 Subject: [ubuntu/natty-proposed] python-kinterbasdb 3.3.0-2build1.11.04.1 (Accepted) Message-ID: <20120117053816.19093.70971.launchpad@soybean.canonical.com> python-kinterbasdb (3.3.0-2build1.11.04.1) natty-proposed; urgency=low * No change rebuild to bring back the non-i386 archs (LP: #904593) Date: Sun, 01 Jan 2012 04:12:18 -0600 Changed-By: Micah Gersten Maintainer: Debian Python Modules Team https://launchpad.net/ubuntu/natty/+source/python-kinterbasdb/3.3.0-2build1.11.04.1 -------------- next part -------------- Format: 1.8 Date: Sun, 01 Jan 2012 04:12:18 -0600 Source: python-kinterbasdb Binary: python-kinterbasdb python-kinterbasdb-dbg Architecture: source Version: 3.3.0-2build1.11.04.1 Distribution: natty-proposed Urgency: low Maintainer: Debian Python Modules Team Changed-By: Micah Gersten Description: python-kinterbasdb - Python DB API 2.0 extension for Firebird and Interbase python-kinterbasdb-dbg - Python DB API 2.0 extension for Firebird and Interbase (debug ext Launchpad-Bugs-Fixed: 904593 Changes: python-kinterbasdb (3.3.0-2build1.11.04.1) natty-proposed; urgency=low . * No change rebuild to bring back the non-i386 archs (LP: #904593) Checksums-Sha1: a0b04fb3e022e41b4cd85b41273e5d8678700968 1602 python-kinterbasdb_3.3.0-2build1.11.04.1.dsc da56cc4061cafc161c2c87d23fe52ead8307a048 6062 python-kinterbasdb_3.3.0-2build1.11.04.1.diff.gz Checksums-Sha256: 876bcbfaf544f7575a0c09eb96ec68c821e8ec1c3ac805cd84676dc4d3c84056 1602 python-kinterbasdb_3.3.0-2build1.11.04.1.dsc 0cb64968e0a9731fb3d1178c1610f132c90363f0995e9142858cc70d4fa1bffa 6062 python-kinterbasdb_3.3.0-2build1.11.04.1.diff.gz Files: ba5acf0ca4a138435f88ecaeb9415ce9 1602 python optional python-kinterbasdb_3.3.0-2build1.11.04.1.dsc 795f26c4486ec19dffd5befa1cc9788b 6062 python optional python-kinterbasdb_3.3.0-2build1.11.04.1.diff.gz From udienz at ubuntu.com Tue Jan 17 16:33:46 2012 From: udienz at ubuntu.com (Mahyuddin Susanto) Date: Tue, 17 Jan 2012 16:33:46 -0000 Subject: [ubuntu/natty-security] squid3 3.1.11-1ubuntu0.1 (Accepted) Message-ID: <20120117163346.31768.19244.launchpad@cocoplum.canonical.com> squid3 (3.1.11-1ubuntu0.1) natty-security; urgency=low * SECURITY UPDATE: Fix DoS (memory corruption and daemon restart) or possibly have unspecified other impact via a long line in a response by remote Gopher servers. (LP: #907687) - debian/patches/CVE-2011-3205.dpatch: patch derived from upstream. - CVE-2011-3205 * SECURITY UPDATE: Fix DoS (daemon abort) via DNS reply containing a CNAME record that references another CNAME record that contains an empty A record. - debian/patches/CVE-2011-4096.dpatch - CVE-2011-4096 Date: Thu, 22 Dec 2011 21:54:02 +0700 Changed-By: Mahyuddin Susanto Maintainer: Ubuntu Developers https://launchpad.net/ubuntu/natty/+source/squid3/3.1.11-1ubuntu0.1 -------------- next part -------------- Format: 1.8 Date: Thu, 22 Dec 2011 21:54:02 +0700 Source: squid3 Binary: squid3 squid3-dbg squid3-common squidclient squid-cgi Architecture: source Version: 3.1.11-1ubuntu0.1 Distribution: natty-security Urgency: low Maintainer: Ubuntu Developers Changed-By: Mahyuddin Susanto Description: squid-cgi - A full featured Web Proxy cache (HTTP proxy) - control CGI squid3 - A full featured Web Proxy cache (HTTP proxy) squid3-common - A full featured Web Proxy cache (HTTP proxy) - common files squid3-dbg - A full featured Web Proxy cache (HTTP proxy) - Debug symbols squidclient - A full featured Web Proxy cache (HTTP proxy) - control utility Launchpad-Bugs-Fixed: 907687 Changes: squid3 (3.1.11-1ubuntu0.1) natty-security; urgency=low . * SECURITY UPDATE: Fix DoS (memory corruption and daemon restart) or possibly have unspecified other impact via a long line in a response by remote Gopher servers. (LP: #907687) - debian/patches/CVE-2011-3205.dpatch: patch derived from upstream. - CVE-2011-3205 * SECURITY UPDATE: Fix DoS (daemon abort) via DNS reply containing a CNAME record that references another CNAME record that contains an empty A record. - debian/patches/CVE-2011-4096.dpatch - CVE-2011-4096 Checksums-Sha1: 853bbf65d0cfee6f7c52bb37f23050cfb3eab696 2023 squid3_3.1.11-1ubuntu0.1.dsc 7134eb105c2c1bded06dcab82fa0e9dc0c881500 21013 squid3_3.1.11-1ubuntu0.1.diff.gz Checksums-Sha256: 4ce22ff15bbeca96955fef12fb5aa23e911cb38b9e2702d1e661cb3e5b5cb892 2023 squid3_3.1.11-1ubuntu0.1.dsc c22e729241e8715a481a21ca4e6f0b52219eac818e9ce7ed8e5598f42ba9af98 21013 squid3_3.1.11-1ubuntu0.1.diff.gz Files: a9b819198f1a820b22cbadccc46c030e 2023 web optional squid3_3.1.11-1ubuntu0.1.dsc 67c9c433cc0848416ca545ca1d240869 21013 web optional squid3_3.1.11-1ubuntu0.1.diff.gz Original-Maintainer: Luigi Gangitano From l3on at ubuntu.com Wed Jan 18 06:27:02 2012 From: l3on at ubuntu.com (Leo Iannacone) Date: Wed, 18 Jan 2012 06:27:02 -0000 Subject: [ubuntu/natty-proposed] mrtg 2.16.3-3ubuntu1.1 (Accepted) Message-ID: <20120118062702.25786.13658.launchpad@soybean.canonical.com> mrtg (2.16.3-3ubuntu1.1) natty-proposed; urgency=low * Explicitly import Socket6 routines in SNMP_Session (LP: #899460) Patch cherry-picked from upstream (r330) Date: Mon, 09 Jan 2012 12:44:12 +0100 Changed-By: Leo Iannacone Maintainer: Ubuntu Developers Signed-By: Mahyuddin Susanto https://launchpad.net/ubuntu/natty/+source/mrtg/2.16.3-3ubuntu1.1 -------------- next part -------------- Format: 1.8 Date: Mon, 09 Jan 2012 12:44:12 +0100 Source: mrtg Binary: mrtg mrtg-contrib Architecture: source Version: 2.16.3-3ubuntu1.1 Distribution: natty-proposed Urgency: low Maintainer: Ubuntu Developers Changed-By: Leo Iannacone Description: mrtg - multi router traffic grapher mrtg-contrib - multi router traffic grapher (contributed files) Launchpad-Bugs-Fixed: 899460 Changes: mrtg (2.16.3-3ubuntu1.1) natty-proposed; urgency=low . * Explicitly import Socket6 routines in SNMP_Session (LP: #899460) Patch cherry-picked from upstream (r330) Checksums-Sha1: 1def2777c53794c98abc78cc2214a4967ea32b50 2053 mrtg_2.16.3-3ubuntu1.1.dsc 4b6a1db521af2a162f4ccb0dcb808651262b73bd 34731 mrtg_2.16.3-3ubuntu1.1.diff.gz Checksums-Sha256: b8814d8c9d2c602fa47ffc51ad4fd8e835567b331eea699488c156f0ac09465d 2053 mrtg_2.16.3-3ubuntu1.1.dsc 873cf9e3d08be150c1cc591ccff791cad931030d79c4e49fcc283ae3d2b0e8ac 34731 mrtg_2.16.3-3ubuntu1.1.diff.gz Files: cfba9d88af72dc5f35d4546fdcb7ed27 2053 net extra mrtg_2.16.3-3ubuntu1.1.dsc dc2aac8181757c4b97c130e2c0456af6 34731 net extra mrtg_2.16.3-3ubuntu1.1.diff.gz Original-Maintainer: Adam Majer From jamie at ubuntu.com Thu Jan 19 17:33:46 2012 From: jamie at ubuntu.com (Jamie Strandboge) Date: Thu, 19 Jan 2012 17:33:46 -0000 Subject: [ubuntu/natty-security] libxml2 2.7.8.dfsg-2ubuntu0.2 (Accepted) Message-ID: <20120119173346.5507.25507.launchpad@cocoplum.canonical.com> libxml2 (2.7.8.dfsg-2ubuntu0.2) natty-security; urgency=low * SECURITY UPDATE: fix off-by-one leading to denial of service - encoding.c: adjust calculation of space available - 69f04562f75212bfcabecd190ea8b06ace28ece2 - CVE-2011-0216 * SECURITY UPDATE: fix double free in XPath evaluation - xpath.h, xpath.c: add a mechanism of frame for XPath evaluation when entering a function or a scoped evaluation - f5048b3e71fc30ad096970b8df6e7af073bae4cb - CVE-2011-2821 * SECURITY UPDATE: fix double free in XPath evaluation - xpath.c: fix missing error status in XPath evaluation - 1d4526f6f4ec8d18c40e2a09b387652a6c1aa2cd - CVE-2011-2834 * SECURITY UPDATE: fix out of bounds read - parser.c: make sure the parser returns when getting a Stop order - 77404b8b69bc122d12231807abf1a837d121b551 - CVE-2011-3905 * SECURITY UPDATE: fix heap overflow - parser.c: fix an allocation error when copying entities - 5bd3c061823a8499b27422aee04ea20aae24f03e - CVE-2011-3919 Date: Wed, 18 Jan 2012 13:40:28 -0600 Changed-By: Jamie Strandboge Maintainer: Ubuntu Developers https://launchpad.net/ubuntu/natty/+source/libxml2/2.7.8.dfsg-2ubuntu0.2 -------------- next part -------------- Format: 1.8 Date: Wed, 18 Jan 2012 13:40:28 -0600 Source: libxml2 Binary: libxml2 libxml2-utils libxml2-dev libxml2-dbg libxml2-doc python-libxml2 python-libxml2-dbg libxml2-udeb Architecture: source Version: 2.7.8.dfsg-2ubuntu0.2 Distribution: natty-security Urgency: low Maintainer: Ubuntu Developers Changed-By: Jamie Strandboge Description: libxml2 - GNOME XML library libxml2-dbg - Debugging symbols for the GNOME XML library libxml2-dev - Development files for the GNOME XML library libxml2-doc - Documentation for the GNOME XML library libxml2-udeb - GNOME XML library - minimal runtime (udeb) libxml2-utils - XML utilities python-libxml2 - Python bindings for the GNOME XML library python-libxml2-dbg - Python bindings for the GNOME XML library (debug extension) Changes: libxml2 (2.7.8.dfsg-2ubuntu0.2) natty-security; urgency=low . * SECURITY UPDATE: fix off-by-one leading to denial of service - encoding.c: adjust calculation of space available - 69f04562f75212bfcabecd190ea8b06ace28ece2 - CVE-2011-0216 * SECURITY UPDATE: fix double free in XPath evaluation - xpath.h, xpath.c: add a mechanism of frame for XPath evaluation when entering a function or a scoped evaluation - f5048b3e71fc30ad096970b8df6e7af073bae4cb - CVE-2011-2821 * SECURITY UPDATE: fix double free in XPath evaluation - xpath.c: fix missing error status in XPath evaluation - 1d4526f6f4ec8d18c40e2a09b387652a6c1aa2cd - CVE-2011-2834 * SECURITY UPDATE: fix out of bounds read - parser.c: make sure the parser returns when getting a Stop order - 77404b8b69bc122d12231807abf1a837d121b551 - CVE-2011-3905 * SECURITY UPDATE: fix heap overflow - parser.c: fix an allocation error when copying entities - 5bd3c061823a8499b27422aee04ea20aae24f03e - CVE-2011-3919 Checksums-Sha1: 7b2a4909595f850e473ab7cb6e73c39698db2afd 2287 libxml2_2.7.8.dfsg-2ubuntu0.2.dsc 37fa64bfd3d577e2bd111d2e5e0a52df2bd71509 114315 libxml2_2.7.8.dfsg-2ubuntu0.2.diff.gz Checksums-Sha256: f08f6dde4f33cddb9e74ecc093f3678f05cdcb396cb0a44b2afad7fa83035532 2287 libxml2_2.7.8.dfsg-2ubuntu0.2.dsc 633995d7950027e834818586d2e016c3d8f6ee41b75ef7c9bbf275d95b794192 114315 libxml2_2.7.8.dfsg-2ubuntu0.2.diff.gz Files: 89cdd8aba11f8d0c8eb6906b0366e581 2287 libs optional libxml2_2.7.8.dfsg-2ubuntu0.2.dsc c2f9c4333c1c599a96f938f7444bd54c 114315 libs optional libxml2_2.7.8.dfsg-2ubuntu0.2.diff.gz Original-Maintainer: Debian XML/SGML Group From jamie at ubuntu.com Thu Jan 19 17:33:58 2012 From: jamie at ubuntu.com (Jamie Strandboge) Date: Thu, 19 Jan 2012 17:33:58 -0000 Subject: [ubuntu/natty-security] t1lib 5.1.2-3ubuntu0.11.04.2 (Accepted) Message-ID: <20120119173358.5507.52171.launchpad@cocoplum.canonical.com> t1lib (5.1.2-3ubuntu0.11.04.2) natty-security; urgency=low * SECURITY UPDATE: fix denial of service via oversized fonts - debian/patches/CVE-2011-1552_1553_1554.patch: add additional tests to address remaining crashes - CVE-2011-1552 - CVE-2011-1553 - CVE-2011-1554 * SECURITY UPDATE: fix heap-based buffer overflow via AFM font parser - debian/patches/CVE-2010-2642_2011-0433.patch: verify array boundaries in lib/t1lib/parseAFM.c - CVE-2010-2642 - CVE-2011-0433 Date: Tue, 17 Jan 2012 14:35:45 -0600 Changed-By: Jamie Strandboge Maintainer: Ubuntu Developers https://launchpad.net/ubuntu/natty/+source/t1lib/5.1.2-3ubuntu0.11.04.2 -------------- next part -------------- Format: 1.8 Date: Tue, 17 Jan 2012 14:35:45 -0600 Source: t1lib Binary: libt1-5 libt1-dev t1lib-bin libt1-doc libt1-5-dbg Architecture: source Version: 5.1.2-3ubuntu0.11.04.2 Distribution: natty-security Urgency: low Maintainer: Ubuntu Developers Changed-By: Jamie Strandboge Description: libt1-5 - Type 1 font rasterizer library - runtime libt1-5-dbg - Type 1 font rasterizer library - debugging runtime libt1-dev - Type 1 font rasterizer library - development libt1-doc - Type 1 font rasterizer library - developers documentation t1lib-bin - Type 1 font rasterizer library - user binaries Changes: t1lib (5.1.2-3ubuntu0.11.04.2) natty-security; urgency=low . * SECURITY UPDATE: fix denial of service via oversized fonts - debian/patches/CVE-2011-1552_1553_1554.patch: add additional tests to address remaining crashes - CVE-2011-1552 - CVE-2011-1553 - CVE-2011-1554 * SECURITY UPDATE: fix heap-based buffer overflow via AFM font parser - debian/patches/CVE-2010-2642_2011-0433.patch: verify array boundaries in lib/t1lib/parseAFM.c - CVE-2010-2642 - CVE-2011-0433 Checksums-Sha1: 61510d6351bac659ab62643ec1144e619e62472c 1906 t1lib_5.1.2-3ubuntu0.11.04.2.dsc 8ae8ed4dbe0c677b50399b9e31e270d63d15658a 20432 t1lib_5.1.2-3ubuntu0.11.04.2.diff.gz Checksums-Sha256: e6f80243709aebd1edc0b38fce27d84955dc85dfe9533903d331d3a2bce879ef 1906 t1lib_5.1.2-3ubuntu0.11.04.2.dsc a3c0bbe4fbcda95ed7aa9896a59b004101b6fe7dde0435942a77a8646193794f 20432 t1lib_5.1.2-3ubuntu0.11.04.2.diff.gz Files: 401adcab21c35839ac6e4aef198dc1d0 1906 libs optional t1lib_5.1.2-3ubuntu0.11.04.2.dsc aa4c14ece0d0dc4a79ead35e46a59eed 20432 libs optional t1lib_5.1.2-3ubuntu0.11.04.2.diff.gz Original-Maintainer: Ruben Molina From jamie at ubuntu.com Mon Jan 23 20:33:42 2012 From: jamie at ubuntu.com (Jamie Strandboge) Date: Mon, 23 Jan 2012 20:33:42 -0000 Subject: [ubuntu/natty-security] rsyslog 4.6.4-2ubuntu4.2 (Accepted) Message-ID: <20120123203342.19049.4636.launchpad@cocoplum.canonical.com> rsyslog (4.6.4-2ubuntu4.2) natty-security; urgency=low * SECURITY UPDATE: fix denial of service when using imfile and processing lines longer than 64KiB - debian/patches/04-CVE-2011-4623.patch: use size_t instead of unsigned short for iNewSize in rsCStrExtendBuf() from runtime/stringbuf.c - CVE-2011-4623 Date: Wed, 18 Jan 2012 12:09:20 -0600 Changed-By: Jamie Strandboge Maintainer: Ubuntu Developers https://launchpad.net/ubuntu/natty/+source/rsyslog/4.6.4-2ubuntu4.2 -------------- next part -------------- Format: 1.8 Date: Wed, 18 Jan 2012 12:09:20 -0600 Source: rsyslog Binary: rsyslog rsyslog-doc rsyslog-mysql rsyslog-pgsql rsyslog-gssapi rsyslog-gnutls rsyslog-relp Architecture: source Version: 4.6.4-2ubuntu4.2 Distribution: natty-security Urgency: low Maintainer: Ubuntu Developers Changed-By: Jamie Strandboge Description: rsyslog - enhanced multi-threaded syslogd rsyslog-doc - documentation for rsyslog rsyslog-gnutls - TLS protocol support for rsyslog rsyslog-gssapi - GSSAPI authentication and encryption support for rsyslog rsyslog-mysql - MySQL output plugin for rsyslog rsyslog-pgsql - PostgreSQL output plugin for rsyslog rsyslog-relp - RELP protocol support for rsyslog Changes: rsyslog (4.6.4-2ubuntu4.2) natty-security; urgency=low . * SECURITY UPDATE: fix denial of service when using imfile and processing lines longer than 64KiB - debian/patches/04-CVE-2011-4623.patch: use size_t instead of unsigned short for iNewSize in rsCStrExtendBuf() from runtime/stringbuf.c - CVE-2011-4623 Checksums-Sha1: 3a4648b9124ff4b7e312fe35febb06a110052e3b 2140 rsyslog_4.6.4-2ubuntu4.2.dsc 41e0082d3e4bb4e740b4f8aea85142a7c2442ba9 28659 rsyslog_4.6.4-2ubuntu4.2.debian.tar.gz Checksums-Sha256: 455afe130c78f4e07a1a54a3aaf0e64db63000070c5214b5860f6672a476ce56 2140 rsyslog_4.6.4-2ubuntu4.2.dsc 264ed6ccadb865377ae7654a75568f10ed568459107faba607c1220521ef1537 28659 rsyslog_4.6.4-2ubuntu4.2.debian.tar.gz Files: 77ec27b26620fced4243938c97c08c89 2140 admin important rsyslog_4.6.4-2ubuntu4.2.dsc 9dd250384f3df6aa5d7368344c0ba59b 28659 admin important rsyslog_4.6.4-2ubuntu4.2.debian.tar.gz Original-Maintainer: Michael Biebl Original-Vcs-Browser: http://git.debian.org/?p=collab-maint/rsyslog.git;a=summary Original-Vcs-Git: git://git.debian.org/git/collab-maint/rsyslog.git From jamie at ubuntu.com Mon Jan 23 22:33:32 2012 From: jamie at ubuntu.com (Jamie Strandboge) Date: Mon, 23 Jan 2012 22:33:32 -0000 Subject: [ubuntu/natty-security] qemu-kvm 0.14.0+noroms-0ubuntu4.5 (Accepted) Message-ID: <20120123223332.3627.49770.launchpad@cocoplum.canonical.com> qemu-kvm (0.14.0+noroms-0ubuntu4.5) natty-security; urgency=low * SECURITY UPDATE: fix heap overflow in e1000 driver with crafted legacy mode packets - debian/patches/CVE-2012-0029.patch: check for overflow whenever issuing PCI dma reads - CVE-2012-0029 Date: Tue, 17 Jan 2012 13:40:39 -0600 Changed-By: Jamie Strandboge Maintainer: Ubuntu Developers https://launchpad.net/ubuntu/natty/+source/qemu-kvm/0.14.0+noroms-0ubuntu4.5 -------------- next part -------------- Format: 1.8 Date: Tue, 17 Jan 2012 13:40:39 -0600 Source: qemu-kvm Binary: qemu-kvm qemu-common kvm qemu Architecture: source Version: 0.14.0+noroms-0ubuntu4.5 Distribution: natty-security Urgency: low Maintainer: Ubuntu Developers Changed-By: Jamie Strandboge Description: kvm - dummy transitional package from kvm to qemu-kvm qemu - dummy transitional package from qemu to qemu-kvm qemu-common - qemu common functionality (bios, documentation, etc) qemu-kvm - Full virtualization on i386 and amd64 hardware Changes: qemu-kvm (0.14.0+noroms-0ubuntu4.5) natty-security; urgency=low . * SECURITY UPDATE: fix heap overflow in e1000 driver with crafted legacy mode packets - debian/patches/CVE-2012-0029.patch: check for overflow whenever issuing PCI dma reads - CVE-2012-0029 Checksums-Sha1: 85e006f7ee8a3399b00398fc780678425952ed1c 2099 qemu-kvm_0.14.0+noroms-0ubuntu4.5.dsc 7c7afd89046bfabb1d9a6573a27ccb948c6dd87d 60403 qemu-kvm_0.14.0+noroms-0ubuntu4.5.diff.gz Checksums-Sha256: 99ae6ee796a5d28644b2a1596183280ef0a4b322daaeee726727965b3c00289c 2099 qemu-kvm_0.14.0+noroms-0ubuntu4.5.dsc 5a1d1e31ad36df79ce8729d5c021fdee3b61412e4cc299bd9fee8ec8e24960c0 60403 qemu-kvm_0.14.0+noroms-0ubuntu4.5.diff.gz Files: 04245bb05580f0725f7ef2af42c66b4b 2099 misc optional qemu-kvm_0.14.0+noroms-0ubuntu4.5.dsc 3fa90dae64531e0b1ca584fa61f67da5 60403 misc optional qemu-kvm_0.14.0+noroms-0ubuntu4.5.diff.gz From marc.deslauriers at ubuntu.com Tue Jan 24 21:03:34 2012 From: marc.deslauriers at ubuntu.com (Marc Deslauriers) Date: Tue, 24 Jan 2012 21:03:34 -0000 Subject: [ubuntu/natty-security] curl 7.21.3-1ubuntu1.5 (Accepted) Message-ID: <20120124210334.19846.71975.launchpad@cocoplum.canonical.com> curl (7.21.3-1ubuntu1.5) natty-security; urgency=low * SECURITY UPDATE: URL sanitization vulnerability - debian/patches/CVE-2012-0036.patch: reject URLs with embedded control codes in lib/{escape.h,escape.c,imap.c,pop3.c,smtp.c}. - CVE-2012-0036 Date: Tue, 24 Jan 2012 08:28:19 -0500 Changed-By: Marc Deslauriers Maintainer: Ubuntu Developers https://launchpad.net/ubuntu/natty/+source/curl/7.21.3-1ubuntu1.5 -------------- next part -------------- Format: 1.8 Date: Tue, 24 Jan 2012 08:28:19 -0500 Source: curl Binary: curl libcurl3 libcurl3-gnutls libcurl3-nss libcurl4-openssl-dev libcurl4-gnutls-dev libcurl4-nss-dev libcurl3-dbg Architecture: source Version: 7.21.3-1ubuntu1.5 Distribution: natty-security Urgency: low Maintainer: Ubuntu Developers Changed-By: Marc Deslauriers Description: curl - Get a file from an HTTP, HTTPS or FTP server libcurl3 - Multi-protocol file transfer library (OpenSSL) libcurl3-dbg - libcurl compiled with debug symbols libcurl3-gnutls - Multi-protocol file transfer library (GnuTLS) libcurl3-nss - Multi-protocol file transfer library (NSS) libcurl4-gnutls-dev - Development files and documentation for libcurl (GnuTLS) libcurl4-nss-dev - Development files and documentation for libcurl (NSS) libcurl4-openssl-dev - Development files and documentation for libcurl (OpenSSL) Changes: curl (7.21.3-1ubuntu1.5) natty-security; urgency=low . * SECURITY UPDATE: URL sanitization vulnerability - debian/patches/CVE-2012-0036.patch: reject URLs with embedded control codes in lib/{escape.h,escape.c,imap.c,pop3.c,smtp.c}. - CVE-2012-0036 Checksums-Sha1: 33113bac4b3de4b2e3b4535661c27c84d97eb356 2269 curl_7.21.3-1ubuntu1.5.dsc dd6324895d2f7c83b46c5762a2a289b29df4b68c 100135 curl_7.21.3-1ubuntu1.5.debian.tar.gz Checksums-Sha256: daa3d0daca5188c09bc04bbd944364128320bad7da8317d409ae974cd8c8a019 2269 curl_7.21.3-1ubuntu1.5.dsc 5c82b86453ad0d9259921fb99d433e341952e2562dcfca8cfe38005ca03eb100 100135 curl_7.21.3-1ubuntu1.5.debian.tar.gz Files: 48bff0b404ee947ec0f1d3b98b663565 2269 web optional curl_7.21.3-1ubuntu1.5.dsc 82ada76141457a63c255d55d166941fb 100135 web optional curl_7.21.3-1ubuntu1.5.debian.tar.gz Original-Maintainer: Ramakrishnan Muthukrishnan From sbeattie at ubuntu.com Tue Jan 24 22:05:09 2012 From: sbeattie at ubuntu.com (Steve Beattie) Date: Tue, 24 Jan 2012 22:05:09 -0000 Subject: [ubuntu/natty-security] openjdk-6b18 6b18-1.8.10-0ubuntu1~11.04.2 (Accepted) Message-ID: <20120124220509.11887.54624.launchpad@cocoplum.canonical.com> openjdk-6b18 (6b18-1.8.10-0ubuntu1~11.04.2) natty-security; urgency=low * debian/patches/openjdk-7103725-ssl_beast_regression.patch: Add regression fix for broken ssl connectivity when using TLS_DH_anon_WITH_AES_128_CBC_SHA (LP: #891761) Date: Fri, 20 Jan 2012 15:26:34 -0800 Changed-By: Steve Beattie Maintainer: Ubuntu Developers https://launchpad.net/ubuntu/natty/+source/openjdk-6b18/6b18-1.8.10-0ubuntu1~11.04.2 -------------- next part -------------- Format: 1.8 Date: Fri, 20 Jan 2012 15:26:34 -0800 Source: openjdk-6b18 Binary: openjdk-6-jdk openjdk-6-jre-headless openjdk-6-jre openjdk-6-demo openjdk-6-dbg icedtea-6-jre-cacao icedtea-6-jre-jamvm openjdk-6-jre-zero Architecture: source Version: 6b18-1.8.10-0ubuntu1~11.04.2 Distribution: natty-security Urgency: low Maintainer: Ubuntu Developers Changed-By: Steve Beattie Description: icedtea-6-jre-cacao - Alternative JVM for OpenJDK, using Cacao icedtea-6-jre-jamvm - Alternative JVM for OpenJDK, using JamVM openjdk-6-dbg - Java runtime based on OpenJDK (debugging symbols) openjdk-6-demo - Java runtime based on OpenJDK (demos and examples) openjdk-6-jdk - OpenJDK Development Kit (JDK) openjdk-6-jre - OpenJDK Java runtime, using ${vm:Name} openjdk-6-jre-headless - OpenJDK Java runtime, using ${vm:Name} (headless) openjdk-6-jre-zero - Alternative JVM for OpenJDK, using Zero/Shark Launchpad-Bugs-Fixed: 891761 Changes: openjdk-6b18 (6b18-1.8.10-0ubuntu1~11.04.2) natty-security; urgency=low . * debian/patches/openjdk-7103725-ssl_beast_regression.patch: Add regression fix for broken ssl connectivity when using TLS_DH_anon_WITH_AES_128_CBC_SHA (LP: #891761) Checksums-Sha1: ae732ddb335734bcdccfdafdaed45a601f5cb8d1 3094 openjdk-6b18_6b18-1.8.10-0ubuntu1~11.04.2.dsc 13738c98f2082a1025a9d420f5936f43be6b380f 174979 openjdk-6b18_6b18-1.8.10-0ubuntu1~11.04.2.diff.gz Checksums-Sha256: 76d12f3e43ab6638fc0d55dbefd43ec7fbb313cfcba69f7f44202d9b8d9df87b 3094 openjdk-6b18_6b18-1.8.10-0ubuntu1~11.04.2.dsc a9fd4d86025edf9c6a18d65403849391ff52f8c8e3372a64ab5c1ff4b105473a 174979 openjdk-6b18_6b18-1.8.10-0ubuntu1~11.04.2.diff.gz Files: ed2548cda4be09e18860ae77969152e4 3094 java optional openjdk-6b18_6b18-1.8.10-0ubuntu1~11.04.2.dsc 095b2ecb556de78b9d98ea7005139fc4 174979 java optional openjdk-6b18_6b18-1.8.10-0ubuntu1~11.04.2.diff.gz Original-Maintainer: OpenJDK Team From sbeattie at ubuntu.com Tue Jan 24 22:05:37 2012 From: sbeattie at ubuntu.com (Steve Beattie) Date: Tue, 24 Jan 2012 22:05:37 -0000 Subject: [ubuntu/natty-security] openjdk-6 6b22-1.10.4-0ubuntu1~11.04.2 (Accepted) Message-ID: <20120124220537.11887.11312.launchpad@cocoplum.canonical.com> openjdk-6 (6b22-1.10.4-0ubuntu1~11.04.2) natty-security; urgency=low * debian/patches/openjdk-7103725-ssl_beast_regression.patch: Add regression fix for broken ssl connectivity when using TLS_DH_anon_WITH_AES_128_CBC_SHA (LP: #891761) Date: Thu, 19 Jan 2012 15:59:06 -0800 Changed-By: Steve Beattie Maintainer: Ubuntu Developers https://launchpad.net/ubuntu/natty/+source/openjdk-6/6b22-1.10.4-0ubuntu1~11.04.2 -------------- next part -------------- Format: 1.8 Date: Thu, 19 Jan 2012 15:59:06 -0800 Source: openjdk-6 Binary: openjdk-6-jdk openjdk-6-jre-headless openjdk-6-jre openjdk-6-jre-lib openjdk-6-demo openjdk-6-source openjdk-6-doc openjdk-6-dbg icedtea-6-jre-cacao icedtea-6-jre-jamvm openjdk-6-jre-zero Architecture: source Version: 6b22-1.10.4-0ubuntu1~11.04.2 Distribution: natty-security Urgency: low Maintainer: Ubuntu Developers Changed-By: Steve Beattie Description: icedtea-6-jre-cacao - Alternative JVM for OpenJDK, using Cacao icedtea-6-jre-jamvm - Alternative JVM for OpenJDK, using JamVM openjdk-6-dbg - Java runtime based on OpenJDK (debugging symbols) openjdk-6-demo - Java runtime based on OpenJDK (demos and examples) openjdk-6-doc - OpenJDK Development Kit (JDK) documentation openjdk-6-jdk - OpenJDK Development Kit (JDK) openjdk-6-jre - OpenJDK Java runtime, using ${vm:Name} openjdk-6-jre-headless - OpenJDK Java runtime, using ${vm:Name} (headless) openjdk-6-jre-lib - OpenJDK Java runtime (architecture independent libraries) openjdk-6-jre-zero - Alternative JVM for OpenJDK, using Zero/Shark openjdk-6-source - OpenJDK Development Kit (JDK) source files Launchpad-Bugs-Fixed: 891761 Changes: openjdk-6 (6b22-1.10.4-0ubuntu1~11.04.2) natty-security; urgency=low . * debian/patches/openjdk-7103725-ssl_beast_regression.patch: Add regression fix for broken ssl connectivity when using TLS_DH_anon_WITH_AES_128_CBC_SHA (LP: #891761) Checksums-Sha1: 1a7d7282b792e21539a0fa007d21698719c606b6 3082 openjdk-6_6b22-1.10.4-0ubuntu1~11.04.2.dsc 9a262c5efb903b32224f928cee532b4f35a7096d 138590 openjdk-6_6b22-1.10.4-0ubuntu1~11.04.2.diff.gz Checksums-Sha256: 07920b851b382a71e503197595b37053d0b4b236f20e402351ee3bc667570a82 3082 openjdk-6_6b22-1.10.4-0ubuntu1~11.04.2.dsc b8d160983ddf04bdfceffb9541a923da5b305d7aaec64f38742334b92869166e 138590 openjdk-6_6b22-1.10.4-0ubuntu1~11.04.2.diff.gz Files: 4082b32c8caae0aae434e64acbb02398 3082 java optional openjdk-6_6b22-1.10.4-0ubuntu1~11.04.2.dsc 0ff55ea923a5b12882737e072e063394 138590 java optional openjdk-6_6b22-1.10.4-0ubuntu1~11.04.2.diff.gz Original-Maintainer: OpenJDK Team From jamie at ubuntu.com Wed Jan 25 19:34:08 2012 From: jamie at ubuntu.com (Jamie Strandboge) Date: Wed, 25 Jan 2012 19:34:08 -0000 Subject: [ubuntu/natty-security] evince_2.32.0-0ubuntu12.4_static_translations.tar.gz, evince_2.32.0-0ubuntu12.4_armel_translations.tar.gz, evince_2.32.0-0ubuntu12.4_powerpc_translations.tar.gz, evince, evince_2.32.0-0ubuntu12.4_amd64_translations.tar.gz, evince_2.32.0-0ubuntu12.4_i386_translations.tar.gz 2.32.0-0ubuntu12.4 (Accepted) Message-ID: <20120125193408.26373.97058.launchpad@cocoplum.canonical.com> evince (2.32.0-0ubuntu12.4) natty-security; urgency=low * SECURITY UPDATE: fix heap-based buffer overflow - debian/patches/08_CVE-2011-0433.patch: add more bounds checking in backend/dvi/mdvi-lib/afmparse.c - CVE-2011-0433 * rename 0001-libview-Make-sure-we-have-a-valid-page-range-before-.patch to 07_libview-Make-sure-we-have-a-valid-page-range-before-.patch and adjust series file accordingly Date: Thu, 19 Jan 2012 09:31:57 -0600 Changed-By: Jamie Strandboge Maintainer: Ubuntu Developers https://launchpad.net/ubuntu/natty/+source/evince/2.32.0-0ubuntu12.4 -------------- next part -------------- Format: 1.8 Date: Thu, 19 Jan 2012 09:31:57 -0600 Source: evince Binary: evince evince-dbg evince-gtk libevview-dev libevview3 libevdocument-dev libevdocument3 evince-common gir1.2-evince-2.32 Architecture: source Version: 2.32.0-0ubuntu12.4 Distribution: natty-security Urgency: low Maintainer: Ubuntu Developers Changed-By: Jamie Strandboge Description: evince - Document (postscript, pdf) viewer evince-common - Document (postscript, pdf) viewer - common files evince-dbg - Document (postscript, pdf) viewer - debugging symbols evince-gtk - Document (postscript, pdf) viewer (GTK+ version) gir1.2-evince-2.32 - GObject introspection data for the libevince library libevdocument-dev - GNOME document viewer backend library - development headers libevdocument3 - GNOME document viewer backend library libevview-dev - GNOME document viewer view library - development headers libevview3 - GNOME document viewer view library Changes: evince (2.32.0-0ubuntu12.4) natty-security; urgency=low . * SECURITY UPDATE: fix heap-based buffer overflow - debian/patches/08_CVE-2011-0433.patch: add more bounds checking in backend/dvi/mdvi-lib/afmparse.c - CVE-2011-0433 * rename 0001-libview-Make-sure-we-have-a-valid-page-range-before-.patch to 07_libview-Make-sure-we-have-a-valid-page-range-before-.patch and adjust series file accordingly Checksums-Sha1: 40fe793ff98056ae9c60e7143366fee9ce95d2a5 2835 evince_2.32.0-0ubuntu12.4.dsc cf2cd7f66519d6736bbc64558010550d13b67594 33306 evince_2.32.0-0ubuntu12.4.debian.tar.gz Checksums-Sha256: fddfec7d631042b73065d781c20614e225548b424b6f37dedca0c3421459a76d 2835 evince_2.32.0-0ubuntu12.4.dsc b4b0d8a729f2a3edf77a71a5f8d0f1c3d64a1fe09b29326612ebbc557b83916c 33306 evince_2.32.0-0ubuntu12.4.debian.tar.gz Files: c89ad5621938651ea26a41f94ad6bee4 2835 gnome optional evince_2.32.0-0ubuntu12.4.dsc 3b8bc56a088362e7e020f0d58145a45e 33306 gnome optional evince_2.32.0-0ubuntu12.4.debian.tar.gz Original-Maintainer: Debian GNOME Maintainers From marc.deslauriers at ubuntu.com Thu Jan 26 14:33:44 2012 From: marc.deslauriers at ubuntu.com (Marc Deslauriers) Date: Thu, 26 Jan 2012 14:33:44 -0000 Subject: [ubuntu/natty-security] icu 4.4.2-2ubuntu0.11.04.1 (Accepted) Message-ID: <20120126143344.16958.68078.launchpad@cocoplum.canonical.com> icu (4.4.2-2ubuntu0.11.04.1) natty-security; urgency=low * SECURITY UPDATE: denial of service and possible code execution via out of bounds access - debian/patches/CVE-2011-4599.patch: add bounds checks in source/common/uloc.c. - CVE-2011-4599 Date: Wed, 25 Jan 2012 14:39:39 -0500 Changed-By: Marc Deslauriers Maintainer: Ubuntu Developers https://launchpad.net/ubuntu/natty/+source/icu/4.4.2-2ubuntu0.11.04.1 -------------- next part -------------- Format: 1.8 Date: Wed, 25 Jan 2012 14:39:39 -0500 Source: icu Binary: libicu44 libicu44-dbg libicu-dev lib32icu44 lib32icu-dev icu-doc Architecture: source Version: 4.4.2-2ubuntu0.11.04.1 Distribution: natty-security Urgency: low Maintainer: Ubuntu Developers Changed-By: Marc Deslauriers Description: icu-doc - API documentation for ICU classes and functions lib32icu-dev - Development files for International Components for Unicode (32-bi lib32icu44 - International Components for Unicode (32-bit) libicu-dev - Development files for International Components for Unicode libicu44 - International Components for Unicode libicu44-dbg - International Components for Unicode Changes: icu (4.4.2-2ubuntu0.11.04.1) natty-security; urgency=low . * SECURITY UPDATE: denial of service and possible code execution via out of bounds access - debian/patches/CVE-2011-4599.patch: add bounds checks in source/common/uloc.c. - CVE-2011-4599 Checksums-Sha1: 73da5abd1c31f0934f93e1b4a516d763aed103ec 2123 icu_4.4.2-2ubuntu0.11.04.1.dsc 164e5b3ee2e9a5365e37adb903b419a302575431 18841 icu_4.4.2-2ubuntu0.11.04.1.debian.tar.gz Checksums-Sha256: c845bdfb6f69fa302bc7089d01d0ed7ab4b35485ff5efc3f4789b462ce8f84e9 2123 icu_4.4.2-2ubuntu0.11.04.1.dsc f8e0b441d175a2ddb054719c28fcbf2960b64571248441bb4456fb336e4e0e67 18841 icu_4.4.2-2ubuntu0.11.04.1.debian.tar.gz Files: 17e471bb2984aea29be88ec9c1537b2f 2123 libs optional icu_4.4.2-2ubuntu0.11.04.1.dsc 72da58ec7aba03eb3d3aed82f3875cd4 18841 libs optional icu_4.4.2-2ubuntu0.11.04.1.debian.tar.gz Original-Maintainer: Jay Berkenbilt From sbeattie at ubuntu.com Mon Jan 30 09:35:50 2012 From: sbeattie at ubuntu.com (Steve Beattie) Date: Mon, 30 Jan 2012 09:35:50 -0000 Subject: [ubuntu/natty-security] super 3.30.0-3+squeeze1build0.11.04.1 (Accepted) Message-ID: <20120130093550.19855.92093.launchpad@cocoplum.canonical.com> super (3.30.0-3+squeeze1build0.11.04.1) natty-security; urgency=low * fake sync from Debian super (3.30.0-3+squeeze1) stable-security; urgency=high * Add 12-Use-vsnprintf.patch to fix buffer overflow error occurring when logging via syslog is enabled (CVE-2011-2776). * Add 13-Potential-format-string-vulnerability.patch to fix a vulnerability that might occur if the user of file name or file name used in the tag contains a '%' character. Date: Fri, 27 Jan 2012 16:33:55 -0800 Changed-By: Steve Beattie Maintainer: Robert Luberda https://launchpad.net/ubuntu/natty/+source/super/3.30.0-3+squeeze1build0.11.04.1 -------------- next part -------------- Format: 1.8 Date: Fri, 27 Jan 2012 16:33:55 -0800 Source: super Binary: super Architecture: source Version: 3.30.0-3+squeeze1build0.11.04.1 Distribution: natty-security Urgency: high Maintainer: Robert Luberda Changed-By: Steve Beattie Description: super - Execute commands setuid root Changes: super (3.30.0-3+squeeze1build0.11.04.1) natty-security; urgency=low . * fake sync from Debian . super (3.30.0-3+squeeze1) stable-security; urgency=high . * Add 12-Use-vsnprintf.patch to fix buffer overflow error occurring when logging via syslog is enabled (CVE-2011-2776). * Add 13-Potential-format-string-vulnerability.patch to fix a vulnerability that might occur if the user of file name or file name used in the tag contains a '%' character. Checksums-Sha1: f4c1197ce9794be7242bd704c799b1f5e71d1528 1762 super_3.30.0-3+squeeze1build0.11.04.1.dsc e67bae34924674f4d6fd993aa80be8b1b9edf4bf 13558 super_3.30.0-3+squeeze1build0.11.04.1.diff.gz Checksums-Sha256: efe859807c5bb482af71dfdc62862b415a152b295bbd1a2683627660fe8e4e06 1762 super_3.30.0-3+squeeze1build0.11.04.1.dsc 38adce3eafae49100c6bbccc9d966734146864ac7ee8332bf4fe8d93e011359f 13558 super_3.30.0-3+squeeze1build0.11.04.1.diff.gz Files: fda2faef17898940490687e3df0da237 1762 admin optional super_3.30.0-3+squeeze1build0.11.04.1.dsc 3c0103423abbf8c84786502bc9e83617 13558 admin optional super_3.30.0-3+squeeze1build0.11.04.1.diff.gz From sbeattie at ubuntu.com Mon Jan 30 17:34:01 2012 From: sbeattie at ubuntu.com (Steve Beattie) Date: Mon, 30 Jan 2012 17:34:01 -0000 Subject: [ubuntu/natty-security] typo3-src 4.3.9+dfsg1-1+squeeze1build0.11.04.1 (Accepted) Message-ID: <20120130173401.12130.71612.launchpad@cocoplum.canonical.com> typo3-src (4.3.9+dfsg1-1+squeeze1build0.11.04.1) natty-security; urgency=low * fake sync from Debian typo3-src (4.3.9+dfsg1-1+squeeze1) squeeze-security; urgency=high * Security patch from new upstream release 4.3.12: - fixes: "TYPO3 Security Bulletin TYPO3-CORE-SA-2011-001: Multiple vulnerabilities in TYPO3 Core" (Closes: 635937) Date: Sun, 29 Jan 2012 13:10:59 -0800 Changed-By: Steve Beattie Maintainer: Christian Welzel https://launchpad.net/ubuntu/natty/+source/typo3-src/4.3.9+dfsg1-1+squeeze1build0.11.04.1 -------------- next part -------------- Format: 1.8 Date: Sun, 29 Jan 2012 13:10:59 -0800 Source: typo3-src Binary: typo3-src-4.3 typo3-database typo3 Architecture: source Version: 4.3.9+dfsg1-1+squeeze1build0.11.04.1 Distribution: natty-security Urgency: high Maintainer: Christian Welzel Changed-By: Steve Beattie Description: typo3 - The enterprise level open source WebCMS (Meta) typo3-database - TYPO3 - The enterprise level open source WebCMS (Database) typo3-src-4.3 - TYPO3 - The enterprise level open source WebCMS (Core) Closes: 635937 Changes: typo3-src (4.3.9+dfsg1-1+squeeze1build0.11.04.1) natty-security; urgency=low . * fake sync from Debian . typo3-src (4.3.9+dfsg1-1+squeeze1) squeeze-security; urgency=high . * Security patch from new upstream release 4.3.12: - fixes: "TYPO3 Security Bulletin TYPO3-CORE-SA-2011-001: Multiple vulnerabilities in TYPO3 Core" (Closes: 635937) Checksums-Sha1: 62e69c7ba2cd368d922348f98899269f70424b85 1804 typo3-src_4.3.9+dfsg1-1+squeeze1build0.11.04.1.dsc 31f197bc9cac5dde2a13706abe028d1d8a3040fe 128595 typo3-src_4.3.9+dfsg1-1+squeeze1build0.11.04.1.debian.tar.gz Checksums-Sha256: bfe7bc8396c800e0dff1021e4ea6b565b2352be331bf40f1ab4bf284a2c0130b 1804 typo3-src_4.3.9+dfsg1-1+squeeze1build0.11.04.1.dsc 9da86c8533b710ba1efd9a0e73526c60b6b2c54ac1439825481dfb42fc45341e 128595 typo3-src_4.3.9+dfsg1-1+squeeze1build0.11.04.1.debian.tar.gz Files: 89b616cc9707bda90a678bd6ae72de27 1804 web optional typo3-src_4.3.9+dfsg1-1+squeeze1build0.11.04.1.dsc efffa0570a9cb486a69dae5da3862bb0 128595 web optional typo3-src_4.3.9+dfsg1-1+squeeze1build0.11.04.1.debian.tar.gz From sbeattie at ubuntu.com Mon Jan 30 17:34:11 2012 From: sbeattie at ubuntu.com (Steve Beattie) Date: Mon, 30 Jan 2012 17:34:11 -0000 Subject: [ubuntu/natty-security] openswan_2.6.28+dfsg-5squeeze1build0.11.04.1_amd64_translations.tar.gz, openswan_2.6.28+dfsg-5squeeze1build0.11.04.1_powerpc_translations.tar.gz, openswan_2.6.28+dfsg-5squeeze1build0.11.04.1_i386_translations.tar.gz, openswan_2.6.28+dfsg-5squeeze1build0.11.04.1_armel_translations.tar.gz, openswan 1:2.6.28+dfsg-5squeeze1build0.11.04.1 (Accepted) Message-ID: <20120130173411.12130.6471.launchpad@cocoplum.canonical.com> openswan (1:2.6.28+dfsg-5squeeze1build0.11.04.1) natty-security; urgency=low * fake sync from Debian openswan (1:2.6.28+dfsg-5+squeeze1) stable-security; urgency=high [Harald Jenny] * Fix pluto crypto helper handler vulnerability (CVE-2011-4073). Thanks to Paul Wouters for the patch. Closes: #650674: [CVE-2011-4073] Openswan crypto helper crasher Date: Mon, 30 Jan 2012 01:12:15 -0800 Changed-By: Steve Beattie Maintainer: Rene Mayrhofer https://launchpad.net/ubuntu/natty/+source/openswan/1:2.6.28+dfsg-5squeeze1build0.11.04.1 -------------- next part -------------- Format: 1.8 Date: Mon, 30 Jan 2012 01:12:15 -0800 Source: openswan Binary: openswan openswan-dbg openswan-doc openswan-modules-source openswan-modules-dkms Architecture: source Version: 1:2.6.28+dfsg-5squeeze1build0.11.04.1 Distribution: natty-security Urgency: high Maintainer: Rene Mayrhofer Changed-By: Steve Beattie Description: openswan - Internet Key Exchange daemon openswan-dbg - Internet Key Exchange daemon - debugging symbols openswan-doc - Internet Key Exchange daemon - documentation openswan-modules-dkms - Internet Key Exchange daemon - DKMS source openswan-modules-source - Internet Key Exchange daemon - kernel module source Closes: 650674 Changes: openswan (1:2.6.28+dfsg-5squeeze1build0.11.04.1) natty-security; urgency=low . * fake sync from Debian . openswan (1:2.6.28+dfsg-5+squeeze1) stable-security; urgency=high . [Harald Jenny] * Fix pluto crypto helper handler vulnerability (CVE-2011-4073). Thanks to Paul Wouters for the patch. Closes: #650674: [CVE-2011-4073] Openswan crypto helper crasher Checksums-Sha1: 96cf39708a97d3eaf88544a8f33de34b229068b6 2238 openswan_2.6.28+dfsg-5squeeze1build0.11.04.1.dsc 18ebb7933d017caf0f62b9c7fcac00b01b380117 122194 openswan_2.6.28+dfsg-5squeeze1build0.11.04.1.debian.tar.gz Checksums-Sha256: 9662f3b2521adca9ec5273698b1b188b82b814a1b549c9e75613a0e17b51439e 2238 openswan_2.6.28+dfsg-5squeeze1build0.11.04.1.dsc ef427bb2cd521b5e6f664d657c99d606fb3fd59b17852f1f52ed67668a39ee2e 122194 openswan_2.6.28+dfsg-5squeeze1build0.11.04.1.debian.tar.gz Files: 0805296a01dc7d3541d39621fcaca5ec 2238 net optional openswan_2.6.28+dfsg-5squeeze1build0.11.04.1.dsc 875728e264e1b2d25eb61187c2d4a4fc 122194 net optional openswan_2.6.28+dfsg-5squeeze1build0.11.04.1.debian.tar.gz From marc.deslauriers at ubuntu.com Tue Jan 31 13:34:07 2012 From: marc.deslauriers at ubuntu.com (Marc Deslauriers) Date: Tue, 31 Jan 2012 13:34:07 -0000 Subject: [ubuntu/natty-security] software-properties, software-properties_0.80.9.1_i386_translations.tar.gz 0.80.9.1 (Accepted) Message-ID: <20120131133407.15196.49773.launchpad@cocoplum.canonical.com> software-properties (0.80.9.1) natty-security; urgency=low * SECURITY UPDATE: incorrect ssl certificate validation (LP: #915210) - softwareproperties/ppa.py: use pycurl to download the signing key fingerprint. - debian/control: add python-pycurl dependency. - CVE-2011-4407 Date: Thu, 26 Jan 2012 10:59:59 -0500 Changed-By: Marc Deslauriers Maintainer: Michael Vogt https://launchpad.net/ubuntu/natty/+source/software-properties/0.80.9.1 -------------- next part -------------- Format: 1.8 Date: Thu, 26 Jan 2012 10:59:59 -0500 Source: software-properties Binary: python-software-properties software-properties-gtk software-properties-kde Architecture: source Version: 0.80.9.1 Distribution: natty-security Urgency: low Maintainer: Michael Vogt Changed-By: Marc Deslauriers Description: python-software-properties - manage the repositories that you install software from software-properties-gtk - manage the repositories that you install software from software-properties-kde - manage the repositories that you install software from Launchpad-Bugs-Fixed: 915210 Changes: software-properties (0.80.9.1) natty-security; urgency=low . * SECURITY UPDATE: incorrect ssl certificate validation (LP: #915210) - softwareproperties/ppa.py: use pycurl to download the signing key fingerprint. - debian/control: add python-pycurl dependency. - CVE-2011-4407 Checksums-Sha1: f66a06b35a0f11e5d6a8597f8b9a1c301f08763f 1710 software-properties_0.80.9.1.dsc 4d42a967765dab64b1ac51c04c054fcf5a78dcf5 1410449 software-properties_0.80.9.1.tar.gz Checksums-Sha256: 92d105055656c16089469a715a337ccf516b5a909ff7e42d5d1b024a515b76cf 1710 software-properties_0.80.9.1.dsc 423955b257859e50350416936d7891c2f3aeab7e987f6f0efee62415f428d291 1410449 software-properties_0.80.9.1.tar.gz Files: 7eba7f47706e2b6a38461f4006c31e49 1710 admin optional software-properties_0.80.9.1.dsc 0d145310b414b3a9d2ee391e23822c71 1410449 admin optional software-properties_0.80.9.1.tar.gz