From jamie at ubuntu.com Mon Jul 2 20:46:02 2012 From: jamie at ubuntu.com (Jamie Strandboge) Date: Mon, 02 Jul 2012 20:46:02 -0000 Subject: [ubuntu/natty-security] libreoffice 1:3.3.4-0ubuntu1.2 (Accepted) Message-ID: <20120702204602.19908.94538.launchpad@ackee.canonical.com> libreoffice (1:3.3.4-0ubuntu1.2) natty-security; urgency=low * SECURITY UPDATE: fix integer overflows in graphic loading code - debian/patches/CVE-2012-1149.patch: adjust vcl/source/gdi/pngread.cxx to fail earlier on oversized images and properly verify chunks. Also adjust basebmp/source/bitmapdevice.cxx to to properly verify height and width. Properly verify width and height in svtools/source/filter.vcl/jpeg/jpeg.cxx - CVE-2012-1149 * SECURITY UPDATE: fix integer overflow when processing Escher graphics records in PowerPoint documents - debian/patches/CVE-2012-2334.patch: properly verify record lengths in filter/source/msfilter/msdffimp.cxx and msdffimp.hxx - CVE-2012-2334 Date: 2012-06-20 16:36:43.209358+00:00 Changed-By: Jamie Strandboge https://launchpad.net/ubuntu/natty/+source/libreoffice/1:3.3.4-0ubuntu1.2 -------------- next part -------------- Sorry, changesfile not available. From jamie at ubuntu.com Mon Jul 2 20:47:17 2012 From: jamie at ubuntu.com (Jamie Strandboge) Date: Mon, 02 Jul 2012 20:47:17 -0000 Subject: [ubuntu/natty-security] libreoffice-l10n 1:3.3.3-1ubuntu1.2 (Accepted) Message-ID: <20120702204717.19908.13634.launchpad@ackee.canonical.com> libreoffice-l10n (1:3.3.3-1ubuntu1.2) natty-security; urgency=low * SECURITY UPDATE: fix integer overflows in graphic loading code - debian/patches/CVE-2012-1149.patch: adjust vcl/source/gdi/pngread.cxx to fail earlier on oversized images and properly verify chunks. Also adjust basebmp/source/bitmapdevice.cxx to to properly verify height and width. Properly verify width and height in svtools/source/filter.vcl/jpeg/jpeg.cxx - CVE-2012-1149 * SECURITY UPDATE: fix integer overflow when processing Escher graphics records in PowerPoint documents - debian/patches/CVE-2012-2334.patch: properly verify record lengths in filter/source/msfilter/msdffimp.cxx and msdffimp.hxx - CVE-2012-2334 Date: 2012-06-20 23:06:25.669126+00:00 Changed-By: Jamie Strandboge https://launchpad.net/ubuntu/natty/+source/libreoffice-l10n/1:3.3.3-1ubuntu1.2 -------------- next part -------------- Sorry, changesfile not available. From steve.langasek at ubuntu.com Tue Jul 3 18:44:58 2012 From: steve.langasek at ubuntu.com (Steve Langasek) Date: Tue, 03 Jul 2012 18:44:58 -0000 Subject: [ubuntu/natty-proposed] base-files 5.0.0ubuntu28.1 (Accepted) Message-ID: <20120703184458.11923.61204.launchpad@wampee.canonical.com> base-files (5.0.0ubuntu28.1) natty-proposed; urgency=low * Call date -s $(date -R) on upgrade, to resync any clocks that might be desynced (and causing pthread spinning in the kernel) due to the leap second. LP: #1020285. Date: Tue, 03 Jul 2012 10:37:13 -0700 Changed-By: Steve Langasek Maintainer: Ubuntu Developers https://launchpad.net/ubuntu/natty/+source/base-files/5.0.0ubuntu28.1 -------------- next part -------------- Format: 1.8 Date: Tue, 03 Jul 2012 10:37:13 -0700 Source: base-files Binary: base-files lsb-release-udeb Architecture: source Version: 5.0.0ubuntu28.1 Distribution: natty-proposed Urgency: low Maintainer: Ubuntu Developers Changed-By: Steve Langasek Description: base-files - Debian base system miscellaneous files lsb-release-udeb - LSB release information Launchpad-Bugs-Fixed: 1020285 Changes: base-files (5.0.0ubuntu28.1) natty-proposed; urgency=low . * Call date -s $(date -R) on upgrade, to resync any clocks that might be desynced (and causing pthread spinning in the kernel) due to the leap second. LP: #1020285. Checksums-Sha1: 255d0ddd8f1696034e648c36ed3e24e05298cd49 1549 base-files_5.0.0ubuntu28.1.dsc 16e16f15082480a8c5d55762abc19ea8f7ccaa0c 77919 base-files_5.0.0ubuntu28.1.tar.gz Checksums-Sha256: 1e65c1c426aacae958d4ab324fe4c99f8e86f57f0532e14bd07a66e71677ddc3 1549 base-files_5.0.0ubuntu28.1.dsc 248cfd26d18fec5eee1c98232dcd3a0358033efd8ea233412739a9f7086d6fd9 77919 base-files_5.0.0ubuntu28.1.tar.gz Files: 8104fc0face25360bec9f6eaccb2cc06 1549 admin required base-files_5.0.0ubuntu28.1.dsc 65f19d31045777da08d3139ff9a9a31d 77919 admin required base-files_5.0.0ubuntu28.1.tar.gz Original-Maintainer: Santiago Vila From cjwatson at ubuntu.com Wed Jul 4 09:11:29 2012 From: cjwatson at ubuntu.com (Colin Watson) Date: Wed, 04 Jul 2012 09:11:29 -0000 Subject: [ubuntu/natty-proposed] debian-installer 20101020ubuntu29.2 (Accepted) Message-ID: <20120704091129.5384.42524.launchpad@wampee.canonical.com> debian-installer (20101020ubuntu29.2) natty-proposed; urgency=low * Move to 2.6.38-15 kernels. Date: Wed, 04 Jul 2012 10:06:23 +0100 Changed-By: Colin Watson Maintainer: Ubuntu Installer Team https://launchpad.net/ubuntu/natty/+source/debian-installer/20101020ubuntu29.2 -------------- next part -------------- Format: 1.8 Date: Wed, 04 Jul 2012 10:06:23 +0100 Source: debian-installer Binary: debian-installer Architecture: source Version: 20101020ubuntu29.2 Distribution: natty-proposed Urgency: low Maintainer: Ubuntu Installer Team Changed-By: Colin Watson Description: debian-installer - Debian installer Changes: debian-installer (20101020ubuntu29.2) natty-proposed; urgency=low . * Move to 2.6.38-15 kernels. Checksums-Sha1: 52db24dd748841b8fab202de28e33fd943bc6f69 3555 debian-installer_20101020ubuntu29.2.dsc c18b828b7c4b4da0ffaa097481e42d13ce726a4c 1866541 debian-installer_20101020ubuntu29.2.tar.gz Checksums-Sha256: f9c60de724dba66596a2e6aeb5bb7ecfadf98c9ddcf1d07444bc7e933bd74b9b 3555 debian-installer_20101020ubuntu29.2.dsc 05a3acd54fffe5ebcd8e52038daa0fa5b265b0420a58c74be2055d901a4569b0 1866541 debian-installer_20101020ubuntu29.2.tar.gz Files: c60bd5ff497210000553567542144941 3555 devel optional debian-installer_20101020ubuntu29.2.dsc 0bdfa31b5c7defb52f296b0b367235bb 1866541 devel optional debian-installer_20101020ubuntu29.2.tar.gz Original-Maintainer: Debian Install System Team From cjwatson at canonical.com Wed Jul 4 12:31:13 2012 From: cjwatson at canonical.com (Colin Watson) Date: Wed, 04 Jul 2012 12:31:13 -0000 Subject: [ubuntu/natty-updates] base-installer 1.116ubuntu3 (Accepted) Message-ID: <20120704123113.15533.37555.launchpad@ackee.canonical.com> base-installer (1.116ubuntu3) natty-proposed; urgency=low * Honour apt-setup/security_path when constructing initial security entries in sources.list (LP: #820306). Date: 2011-08-16 10:40:11.848214+00:00 Changed-By: Colin Watson https://launchpad.net/ubuntu/natty/+source/base-installer/1.116ubuntu3 -------------- next part -------------- Sorry, changesfile not available. From cjwatson at canonical.com Wed Jul 4 15:54:17 2012 From: cjwatson at canonical.com (Colin Watson) Date: Wed, 04 Jul 2012 15:54:17 -0000 Subject: [ubuntu/natty-updates] debian-installer-utils 1.82ubuntu1.2 (Accepted) Message-ID: <20120704155417.9537.25862.launchpad@ackee.canonical.com> debian-installer-utils (1.82ubuntu1.2) natty-proposed; urgency=low [ Scott Moser ] * Add --quiet to dpkg-divert calls in chroot_setup. Date: 2012-01-06 12:35:11.887771+00:00 Changed-By: Colin Watson https://launchpad.net/ubuntu/natty/+source/debian-installer-utils/1.82ubuntu1.2 -------------- next part -------------- Sorry, changesfile not available. From marc.deslauriers at ubuntu.com Thu Jul 5 14:03:40 2012 From: marc.deslauriers at ubuntu.com (Marc Deslauriers) Date: Thu, 05 Jul 2012 14:03:40 -0000 Subject: [ubuntu/natty-security] tiff 3.9.4-5ubuntu6.2 (Accepted) Message-ID: <20120705140340.7718.84389.launchpad@cocoplum.canonical.com> tiff (3.9.4-5ubuntu6.2) natty-security; urgency=low * SECURITY UPDATE: possible arbitrary code execution via buffer overflow due to type-conversion flaw (LP: #1016324) - debian/patches/CVE-2012-2088.patch: check for overflows in libtiff/tif_strip.c and libtiff/tif_tile.c. - CVE-2012-2088 * SECURITY UPDATE: possible arbitrary code execution via integer overflows in tiff2pdf (LP: #1016324) - debian/patches/CVE-2012-2113.patch: check for overflows in tools/tiff2pdf.c. - CVE-2012-2113 Date: Wed, 04 Jul 2012 10:59:25 -0400 Changed-By: Marc Deslauriers Maintainer: Ubuntu Developers https://launchpad.net/ubuntu/natty/+source/tiff/3.9.4-5ubuntu6.2 -------------- next part -------------- Format: 1.8 Date: Wed, 04 Jul 2012 10:59:25 -0400 Source: tiff Binary: libtiff4 libtiffxx0c2 libtiff4-dev libtiff-tools libtiff-opengl libtiff-doc Architecture: source Version: 3.9.4-5ubuntu6.2 Distribution: natty-security Urgency: low Maintainer: Ubuntu Developers Changed-By: Marc Deslauriers Description: libtiff-doc - TIFF manipulation and conversion documentation libtiff-opengl - TIFF manipulation and conversion tools libtiff-tools - TIFF manipulation and conversion tools libtiff4 - Tag Image File Format (TIFF) library libtiff4-dev - Tag Image File Format library (TIFF), development files libtiffxx0c2 - Tag Image File Format (TIFF) library -- C++ interface Launchpad-Bugs-Fixed: 1016324 Changes: tiff (3.9.4-5ubuntu6.2) natty-security; urgency=low . * SECURITY UPDATE: possible arbitrary code execution via buffer overflow due to type-conversion flaw (LP: #1016324) - debian/patches/CVE-2012-2088.patch: check for overflows in libtiff/tif_strip.c and libtiff/tif_tile.c. - CVE-2012-2088 * SECURITY UPDATE: possible arbitrary code execution via integer overflows in tiff2pdf (LP: #1016324) - debian/patches/CVE-2012-2113.patch: check for overflows in tools/tiff2pdf.c. - CVE-2012-2113 Checksums-Sha1: c3031f0751010c2f1fac3769551e0ef1fba32b78 2002 tiff_3.9.4-5ubuntu6.2.dsc 1f80232b0058a63d08fc724dbaf09938ffeff67f 23903 tiff_3.9.4-5ubuntu6.2.debian.tar.gz Checksums-Sha256: 82b487cbb6f9d5f74229beb68aad0ff2dc3fe6d1369dbda032dd8f9009dff15d 2002 tiff_3.9.4-5ubuntu6.2.dsc f8c3554e0a714f1601bcff42b7ef2e5fdb4a6392e3664ad519cd24a507c60c4c 23903 tiff_3.9.4-5ubuntu6.2.debian.tar.gz Files: f9c8786b7e17f0796737849826a702e9 2002 libs optional tiff_3.9.4-5ubuntu6.2.dsc 3f2a4579bfa7d9b1fc55ab4361f5daf3 23903 libs optional tiff_3.9.4-5ubuntu6.2.debian.tar.gz Original-Maintainer: Jay Berkenbilt From brad.figg at canonical.com Sat Jul 7 21:46:28 2012 From: brad.figg at canonical.com (Brad Figg) Date: Sat, 07 Jul 2012 21:46:28 -0000 Subject: [ubuntu/natty-proposed] linux 2.6.38-15.64 (Accepted) Message-ID: <20120707214628.20541.11573.launchpad@ackee.canonical.com> linux (2.6.38-15.64) natty-proposed; urgency=low [ Andy Whitcroft ] * fix ABI directory naming [ Luis Henriques ] * Release Tracking Bug - LP: #1019992 Date: 2012-07-06 16:07:02.845334+00:00 Changed-By: Andy Whitcroft Signed-By: Brad Figg https://launchpad.net/ubuntu/natty/+source/linux/2.6.38-15.64 -------------- next part -------------- Sorry, changesfile not available. From jamie at ubuntu.com Wed Jul 11 21:37:22 2012 From: jamie at ubuntu.com (Jamie Strandboge) Date: Wed, 11 Jul 2012 21:37:22 -0000 Subject: [ubuntu/natty-security] qt4-x11 4:4.7.2-0ubuntu6.4 (Accepted) Message-ID: <20120711213722.30626.47075.launchpad@ackee.canonical.com> qt4-x11 (4:4.7.2-0ubuntu6.4) natty-security; urgency=low * SECURITY UPDATE: fix buffer overflow in HarfBuzz - debian/patches/CVE-2011-3193.patch: adjust Lookup_MarkMarkPos() in harfbuzz-gpos.c to properly perform input validation when processing certain fonts - CVE-2011-3193 * SECURITY UPDATE: fix potential buffer overflow and crash in TIFF reader - debian/patches/CVE-2011-3194.patch: adjust QTiffHandler::read() to properly calculate the bits per pixel for greyscale TIFF images - CVE-2011-3194 Date: 2012-07-10 16:18:05.490024+00:00 Changed-By: Jamie Strandboge Maintainer: Kubuntu Members https://launchpad.net/ubuntu/natty/+source/qt4-x11/4:4.7.2-0ubuntu6.4 -------------- next part -------------- Sorry, changesfile not available. From marc.deslauriers at ubuntu.com Thu Jul 12 17:03:37 2012 From: marc.deslauriers at ubuntu.com (Marc Deslauriers) Date: Thu, 12 Jul 2012 17:03:37 -0000 Subject: [ubuntu/natty-security] puppet 2.6.4-2ubuntu2.10 (Accepted) Message-ID: <20120712170337.24594.44792.launchpad@cocoplum.canonical.com> puppet (2.6.4-2ubuntu2.10) natty-security; urgency=low * SECURITY UPDATE: multiple July 2012 security issues - debian/patches/2.6.4-Puppet-July-2012-CVE-fixes.patch: fix multiple security issues. Patch from upstream, with an additional fix to lib/puppet/reports/store.rb. - CVE-2012-3864: arbitrary file read on master from authenticated clients - CVE-2012-3865: arbitrary file delete or denial of service on master from authenticated clients - CVE-2012-3867: insufficient input validation for agent cert hostnames Date: Tue, 10 Jul 2012 08:24:35 -0400 Changed-By: Marc Deslauriers Maintainer: Ubuntu Developers https://launchpad.net/ubuntu/natty/+source/puppet/2.6.4-2ubuntu2.10 -------------- next part -------------- Format: 1.8 Date: Tue, 10 Jul 2012 08:24:35 -0400 Source: puppet Binary: puppet-common puppet puppetmaster-common puppetmaster puppetmaster-passenger vim-puppet puppet-el puppet-testsuite Architecture: source Version: 2.6.4-2ubuntu2.10 Distribution: natty-security Urgency: low Maintainer: Ubuntu Developers Changed-By: Marc Deslauriers Description: puppet - Centralized configuration management - agent startup and compatib puppet-common - Centralized configuration management puppet-el - syntax highlighting for puppet manifests in emacs puppet-testsuite - Centralized configuration management - test suite puppetmaster - Centralized configuration management - master startup and compati puppetmaster-common - Puppet master common scripts puppetmaster-passenger - Centralised configuration management - master setup to run under vim-puppet - syntax highlighting for puppet manifests in vim Changes: puppet (2.6.4-2ubuntu2.10) natty-security; urgency=low . * SECURITY UPDATE: multiple July 2012 security issues - debian/patches/2.6.4-Puppet-July-2012-CVE-fixes.patch: fix multiple security issues. Patch from upstream, with an additional fix to lib/puppet/reports/store.rb. - CVE-2012-3864: arbitrary file read on master from authenticated clients - CVE-2012-3865: arbitrary file delete or denial of service on master from authenticated clients - CVE-2012-3867: insufficient input validation for agent cert hostnames Checksums-Sha1: 415663d97e1d24364a562679fe13e80798e19e34 2303 puppet_2.6.4-2ubuntu2.10.dsc 70b344f9382581de60327e15c034d06912c128b4 115305 puppet_2.6.4-2ubuntu2.10.debian.tar.gz Checksums-Sha256: 37f4bd832a0386dce079120a8d56e40c337b675e04571a52f9b6d9d3a4748e70 2303 puppet_2.6.4-2ubuntu2.10.dsc 22134e60ab25ea3e6d0633e310cfdd9d44745b1222217947d7b5651e50abbb08 115305 puppet_2.6.4-2ubuntu2.10.debian.tar.gz Files: 199c407c7510b95dd89564a65ee36832 2303 admin optional puppet_2.6.4-2ubuntu2.10.dsc 9c5c0acac90094d1be24bfd7f7b23d44 115305 admin optional puppet_2.6.4-2ubuntu2.10.debian.tar.gz Original-Maintainer: Puppet Package Maintainers From andreas at canonical.com Thu Jul 12 17:16:34 2012 From: andreas at canonical.com (Andreas Hasenack) Date: Thu, 12 Jul 2012 17:16:34 -0000 Subject: [ubuntu/natty-proposed] landscape-client 12.05-0ubuntu0.11.04 (Accepted) Message-ID: <20120712171634.28729.75585.launchpad@gac.canonical.com> landscape-client (12.05-0ubuntu0.11.04) natty-proposed; urgency=low * New upstream release 12.05 (r561 in trunk) (LP: #1004678). * Make all subpackages that depend on each other require the exact same version, instead of >= $version. * Added python-gi to client depends starting natty. * Make change-packages also handle package holds (LP: #972489). * Fix typo in glade file (LP: #983096). * Tidy up apt facade (LP: #985493). * Remove SmartFacade and its tests, no longer used (LP: #996269). * Remove check for apt version, since we won't release this for Hardy where that check matters (LP: #996837). * Remove methods that were smart specific. We no longer use smart (LP: #996841). * Remove smart-update helper binary. We no longer use smart (LP: #997408). * Remove test-mixins that were useful only during the apt-to-smart code migration. Now with smart gone, they are no longer necessary (LP: #997760). * Build the packages from precise onward, not just precise. * Assorted packaging fixes: - Switched to format 3.0 (quilt). - Added source lintian overrides, with comments. - Updated debian/rules: - Added build-arch and build-indep dummy target. - Build the GUI packages from precise onwards, and not just on precise. - Re-enable dh_lintian. - Strip the binaries (dh_strip), and also call dh_shlibdeps for the automatic shlibs dependency. - Added python-gi from natty onwards. - Used __Choices instead of _Choices in landscape-common.templates, it's better for translators. - Updated standard version to 3.8.2, the version from Lucid (oldest one we support) - Added shlibs depends. - Dropped deprecated ${Source-Version} and replaced it with ${binary:Version} - Require exact version of the sibling package instead of >=. Date: Tue, 19 Jun 2012 15:12:07 -0300 Changed-By: Andreas Hasenack Maintainer: Ubuntu Developers Signed-By: Sebastien Bacher https://launchpad.net/ubuntu/natty/+source/landscape-client/12.05-0ubuntu0.11.04 -------------- next part -------------- Format: 1.8 Date: Tue, 19 Jun 2012 15:12:07 -0300 Source: landscape-client Binary: landscape-common landscape-client landscape-client-ui landscape-client-ui-install Architecture: source Version: 12.05-0ubuntu0.11.04 Distribution: natty-proposed Urgency: low Maintainer: Ubuntu Developers Changed-By: Andreas Hasenack Description: landscape-client - The Landscape administration system client landscape-client-ui - The Landscape administration system client - UI configuration landscape-client-ui-install - The Landscape administration system client - UI installer landscape-common - The Landscape administration system client - Common files Launchpad-Bugs-Fixed: 972489 983096 985493 996269 996837 996841 997408 997760 1004678 Changes: landscape-client (12.05-0ubuntu0.11.04) natty-proposed; urgency=low . * New upstream release 12.05 (r561 in trunk) (LP: #1004678). * Make all subpackages that depend on each other require the exact same version, instead of >= $version. * Added python-gi to client depends starting natty. * Make change-packages also handle package holds (LP: #972489). * Fix typo in glade file (LP: #983096). * Tidy up apt facade (LP: #985493). * Remove SmartFacade and its tests, no longer used (LP: #996269). * Remove check for apt version, since we won't release this for Hardy where that check matters (LP: #996837). * Remove methods that were smart specific. We no longer use smart (LP: #996841). * Remove smart-update helper binary. We no longer use smart (LP: #997408). * Remove test-mixins that were useful only during the apt-to-smart code migration. Now with smart gone, they are no longer necessary (LP: #997760). * Build the packages from precise onward, not just precise. * Assorted packaging fixes: - Switched to format 3.0 (quilt). - Added source lintian overrides, with comments. - Updated debian/rules: - Added build-arch and build-indep dummy target. - Build the GUI packages from precise onwards, and not just on precise. - Re-enable dh_lintian. - Strip the binaries (dh_strip), and also call dh_shlibdeps for the automatic shlibs dependency. - Added python-gi from natty onwards. - Used __Choices instead of _Choices in landscape-common.templates, it's better for translators. - Updated standard version to 3.8.2, the version from Lucid (oldest one we support) - Added shlibs depends. - Dropped deprecated ${Source-Version} and replaced it with ${binary:Version} - Require exact version of the sibling package instead of >=. Checksums-Sha1: 214548594959e4adcb2003b00030914612ff9261 1583 landscape-client_12.05-0ubuntu0.11.04.dsc 8aa119395f756210bde2710a6b90a7f4a50a9a4a 519114 landscape-client_12.05.orig.tar.gz 8ea71821487d27bcbf6e7ecd33e236171680bafa 27102 landscape-client_12.05-0ubuntu0.11.04.debian.tar.gz Checksums-Sha256: 1e57b45c79d313f12d08a38fd27d3369d6d5d5efc7a0418246f081ca4a59cfc3 1583 landscape-client_12.05-0ubuntu0.11.04.dsc 8e5cf2edd60f56644d0a91f1f67233b6fcf599b80ec9d544188ac6e09d8797a0 519114 landscape-client_12.05.orig.tar.gz 1b9f228e15a350390b4ea5c31057ab311262697007d6860a6a83c05b468305da 27102 landscape-client_12.05-0ubuntu0.11.04.debian.tar.gz Files: 5215510992de5c33f769a55b71dc2b3d 1583 admin optional landscape-client_12.05-0ubuntu0.11.04.dsc c9cb509bed4ab04183cabf1c856eccb7 519114 admin optional landscape-client_12.05.orig.tar.gz a67ff2249c87c006736d0d94229d1b14 27102 admin optional landscape-client_12.05-0ubuntu0.11.04.debian.tar.gz Original-Maintainer: Landscape Team From jamie at ubuntu.com Thu Jul 12 20:39:19 2012 From: jamie at ubuntu.com (Jamie Strandboge) Date: Thu, 12 Jul 2012 20:39:19 -0000 Subject: [ubuntu/natty-updates] openjdk-6 6b24-1.11.3-1ubuntu0.11.04.1 (Accepted) Message-ID: <20120712203919.29155.69395.launchpad@ackee.canonical.com> openjdk-6 (6b24-1.11.3-1ubuntu0.11.04.1) natty-security; urgency=low * Backport OpenJDK 6b24/IcedTea 1.11.3 to natty. * debian/patches/java-access-bridge-security.patch: updated * debian/control.zero-jre: add powerpc arch back, to get empty transitional package * debian/rules: install README.Debian for openjdk-6-jre-zero to create empty transitional package and create package * debian/README.Debian: explain openjdk-6-jre-zero went away * regenerate debian/control openjdk-6 (6b24-1.11.3-1ubuntu0.12.04.1) precise-security; urgency=low * SECURITY UPDATE: update to IcedTea 6 1.11.3 - Security fixes: - S7079902, CVE-2012-1711: Refine CORBA data models - S7110720: Issue with vm config file loadingIssue with vm config file loading - S7143606, CVE-2012-1717: File.createTempFile should be improved for temporary files created by the platform. - S7143614, CVE-2012-1716: SynthLookAndFeel stability improvement - S7143617, CVE-2012-1713: Improve fontmanager layout lookup operations - S7143851, CVE-2012-1719: Improve IIOP stub and tie generation in RMIC - S7143872, CVE-2012-1718: Improve certificate extension processing - S7145239: Finetune package definition restriction - S7152811, CVE-2012-1723: Issues in client compiler - S7157609, CVE-2012-1724: Issues with loop - S7160677: missing else in fix for 7152811 - S7160757, CVE-2012-1725: Problem with hotspot/runtime_classfile - Bug fixes: - PR1018: JVM fails due to SEGV during rendering some Unicode characters (part of 6886358) * Changelog, Makefile.am, aclocal.m4, arm_port/hotspot/src/cpu/zero/vm/asm_helper.cpp, patches/idresolver_fix.patch, patches/openjdk/6792400-Avoid_loading_Normalizer_resources.patch: drop inline changes, applied upstream * debian/patches/atk-wrapper-security.patch: updated * Makefile.{am,in}: don't apply patches/jtreg-LastErrorString.patch as it causes the testsuite runner to fail. openjdk-6 (6b24-1.11.1-4ubuntu3) precise-proposed; urgency=low * Do not apply patches/revert-6885123.patch. Closes: #638805. LP: #981037. * Move hotspot-7020521.patch and hotspot-7026307.patch to debian/patches and reapply (accidentally disabled). openjdk-6 (6b24-1.11.1-4ubuntu2) precise; urgency=low * Use the /usr/bin path for the policytool desktop file. LP: #980205. openjdk-6 (6b24-1.11.1-4ubuntu1) precise; urgency=low * Regenerate the control file. openjdk-6 (6b24-1.11.1-4) unstable; urgency=low * Install desktop files again, using the common /usr/bin/java interpreter name. LP: #969322. Closes: #668213. * Build-depend on libpng-dev for newer releases. Closes: #662452. * Let dlopen handle finding the libpcsclite library. LP: #898689. Closes: #668356. * Build-depend on fonts-ipafont-mincho, fixing a build failure in the fontconfig compiler (find out why it breaks ...). * Build using gcc-4.7/gcj-4.7 for sid/wheezy. openjdk-6 (6b24-1.11.1-3ubuntu4) precise; urgency=low * Don't install the binary fontconfig file. openjdk-6 (6b24-1.11.1-3ubuntu3) precise; urgency=low * Revert the ARM inline math functions change, ony meant for a PPA build. openjdk-6 (6b24-1.11.1-3ubuntu2) precise; urgency=low * Disable running the jdk tests. openjdk-6 (6b24-1.11.1-3) unstable; urgency=low * Use NanumMyeongjo as the preferred korean font. LP: #792471. Closes: #655167. * Fix java path in jexec for multiarch builds. * Fix crash in java.net.NetworkInterface.getNetworkInterfaces() when ifr_ifindex exceeds 255. LP: #925218. S7078386. * Remove javaws and pluginappletviewer alternatives on upgrade from squeeze. Closes: #660604. * Use IPAfont as the preferred japanesse font. Closes: #646054. * Build using gcj on alpha and armel. Closes: #655750. * Drop build dependency on libxp-dev. Closes: #623667. openjdk-6 (6b24-1.11.1-2ubuntu2) precise; urgency=low * Make sure that the nss.cfg doesn't mention any library path. LP: #939361, #939419. * Disable the accessibility wrapper, doesn't work yet. LP: #935296. * ARM: Inline math functions, where asm instructions exist (taken from the trunk). openjdk-6 (6b24-1.11.1-2ubuntu1) precise; urgency=low * Regenerate the control file. openjdk-6 (6b24-1.11.1-2) unstable; urgency=medium * Update from the IcedTea6-1.12 branch (20120222). * Build using gcc/gcj-4.4 on mips and sparc again. * Remove build dependency on libxp-dev. openjdk-6 (6b24-1.11.1-1) unstable; urgency=medium * Build using gcj-4.4 on mips and mipsel again (raised on debian-mips). openjdk-6 (6b24-1.11.1-0ubuntu1) precise; urgency=low * IcedTea 1.11.1 release. * Security fixes: - S7082299, CVE-2011-3571: Fix in AtomicReferenceArray. - S7088367, CVE-2011-3563: Fix issues in java sound. - S7110683, CVE-2012-0502: Issues with some KeyboardFocusManager method. - S7110687, CVE-2012-0503: Issues with TimeZone class. - S7110700, CVE-2012-0505: Enhance exception throwing mechanism in ObjectStreamClass. - S7110704, CVE-2012-0506: Issues with some method in corba. - S7112642, CVE-2012-0497: Incorrect checking for graphics rendering object. - S7118283, CVE-2012-0501: Better input parameter checking in zip file processing. - S7126960, CVE-2011-5035: (httpserver) Add property to limit number of request headers to the HTTP Server. * Backport fixes for S7066307, S7020521 from OpenJDK7 (Xerxes Rånby). openjdk-6 (6b24-1.11-4) unstable; urgency=low * Build using gcj-4.6 on mips, mipsel, sparc, sparc64. openjdk-6 (6b24-1.11-3) unstable; urgency=low * Make doc files multi-arch installable. * JB-archive.applications.in: Use /usr/bin/java by default. Maybe should be moved to the default-jdk package. openjdk-6 (6b24-1.11-2ubuntu1) precise; urgency=low * Regenerate the control file. openjdk-6 (6b24-1.11-2) unstable; urgency=low * Make upgrades from non-multiarch to multiarch builds more silent. * Fix order of grant decls in java.policy. * Default to zero again on ARM with the update ARM assembler interpreter. openjdk-6 (6b24-1.11-1) unstable; urgency=low * Upload to unstable. openjdk-6 (6b24-1.11-0ubuntu1) precise; urgency=low * IcedTea6 1.11 release. [ Luke Yelavich ] * Use java-atk-wrapper instead of java-access-bridge for accessibility. LP: #790240. [ Matthias Klose ] * nss.cfg: Remove nssLibraryDirectory property, rely on the system library path. * Make the java.policy file multi-arch installable. LP: #924096. * Don't install desktop and menu files for multiarch builds. Needs a better solution. Closes: #658321 * Pass -n to gzip when compressing manpages to be Multi-Arch: same safe. * Don't install an alternative for the deprecated apt tool. * Make the upgrade from a non-multiarch installation location more robust; don't depend on version numbers, but check the path of the alternatives. LP: #887077. * Always use the internal copy of liblcms1; only OpenJDK 7 has the support to use a system liblcms2. * Build jamvm on powerpc. openjdk-6 (6b24~pre4-1ubuntu1) precise; urgency=low * Disable the jtreg tests for JamVM on ARM, issues on the buildds. openjdk-6 (6b24~pre4-1) unstable; urgency=low * Upload to unstable. openjdk-6 (6b24~pre4-0ubuntu1) precise; urgency=low * Update from the IcedTea6-1.11 branch (20120120). * Disable shark builds, broken for this release. * Fix some lintian warnings. openjdk-6 (6b24~pre3-0ubuntu1) precise; urgency=low * Update from the IcedTea6 branch (20120103). * Build shark using llvm-3.0. openjdk-6 (6b24~pre2-1) unstable; urgency=low * Regenerate the control file. openjdk-6 (6b24~pre2-0ubuntu2) precise; urgency=low * Build-depend on binutils-dev on armel and armhf. openjdk-6 (6b24~pre2-0ubuntu1) precise; urgency=low * Update from the IcedTea6 branch (20111216). * Enable CACAO on armhf. * Fix build flags for cppInterpreter_arm.o. * openjdk-6-jre-lib: Mark as Multi-Arch: foreign. * Fix plugin name in jinfo file. Closes: #650928. openjdk-6 (6b24~pre1-1) unstable; urgency=low * OpenJDK 6b24 release. * Update from the IcedTea6 branch (20111130). openjdk-6 (6b23~pre11-1) unstable; urgency=high * Build with jpeg8. Closes: #644070. * Tighten inter-package dependencies for Debian builds. Closes: #641240. openjdk-6 (6b23~pre11-0ubuntu1) precise; urgency=low * Update from the IcedTea6 branch (20111019). - Security fixes: - S7000600, CVE-2011-3547: InputStream skip() information leak. - S7019773, CVE-2011-3548: mutable static AWTKeyStroke.ctor. - S7023640, CVE-2011-3551: Java2D TransformHelper integer overflow. - S7032417, CVE-2011-3552: excessive default UDP socket limit under SecurityManager. - S7046794, CVE-2011-3553: JAX-WS stack-traces information leak. - S7046823, CVE-2011-3544: missing SecurityManager checks in scripting engine. - S7055902, CVE-2011-3521: IIOP deserialization code execution. - S7057857, CVE-2011-3554: insufficient pack200 JAR files uncompress error checks. - S7064341, CVE-2011-3389: HTTPS: block-wise chosen-plaintext attack against SSL/TLS (BEAST). - S7070134, CVE-2011-3558: HotSpot crashes with sigsegv from PorterStemmer. - S7077466, CVE-2011-3556: RMI DGC server remote code execution. - S7083012, CVE-2011-3557: RMI registry privileged code execution. - S7096936, CVE-2011-3560: missing checkSetFactory calls in HttpsURLConnection. - Update JamVM. - Implement classlibCheckIfOnLoad(). - Make thread states JVMTI compatible. - Handle 'g' when specifying memory + extra checks. - Make command line compatibility options table-driven. - Update CACAO. openjdk-6 (6b23~pre10-1) unstable; urgency=low [ Matthias Klose ] * Fix exception on trying to start PulseAudio playback on ARM (Xerxes Rånby, David Henningsson). LP: #862286. [ Damien Raude-Morvan ] * Add myself to Uploaders. * d/rules: Fix java.policy to include jre/lib/ext/* files (instead of non-existant ext/*). It'll restore privilegied access from sunpkcs11.jar to sun.* code. (Closes: #642734, #642598). openjdk-6 (6b23~pre10-0ubuntu4) oneiric; urgency=low [ Matthias Klose ] * Fix exception on trying to start PulseAudio playback on ARM (Xerxes Rånby, David Henningsson). LP: #862286. [ Damien Raude-Morvan ] * Add myself to Uploaders. * d/rules: Fix java.policy to include jre/lib/ext/* files (instead of non-existant ext/*). It'll restore privilegied access from sunpkcs11.jar to sun.* code. (Closes: #642734, #642598). openjdk-6 (6b23~pre10-0ubuntu3) oneiric; urgency=low * Don't use the broken symlink to build on armel. openjdk-6 (6b23~pre10-0ubuntu2) oneiric; urgency=low * Fix dangling java-1.6.0-openjdk symlink. openjdk-6 (6b23~pre10-0ubuntu1) oneiric; urgency=low * Update from the IcedTea6 branch (20110926). - OpenJDK: - S6826104: Getting a NullPointer exception when clicked on Application & Toolkit Modal dialog. - S5082756: Image I/O plug-ins set metadata boolean attributes to "true" or "false". - S6296893: BMP Writer handles TopDown property incorrectly for some of the compression types. - JamVM: - Add support for armhf. - Skip Java-reflection-related DelegatingClassLoaders, enables JamVM to run NetBeans. - Generic JNI stubs for common JNI method signatures. - Fix memory heap arguments in terms of gigabytes. - armhf: ensure stack is 8 byte aligned. - CACAO: - CA149: Used wrong class loader. - src/vm/javaobjects.cpp (java_lang_reflect_Method::invoke): [OPENJDK] stack - index of caller was off by one, causing many apt (Annotation Processing Tool) failures. * Default to JamVM on armhf. openjdk-6 (6b23~pre9-2) unstable; urgency=low [ Matthias Klose ] * openjdk-6-jre-lib: Break openjdk-6-jre-headless (<< 6b23~pre9-1~). Closes: #640476. [ Damien Raude-Morvan ] * d/patches/icc_loading_with_symlink.diff: Try to fix loading of ICC profile when jre/lib/cmm is a symlink. (Closes: #641530, #639883, #641240). openjdk-6 (6b23~pre9-1) unstable; urgency=low * Update from the IcedTea6 branch (20110830). * Move the -lib files into a different location so that the java-6-openjdk name can be used as a symlink. * Symlink the jre/cmm directory, instead of the files inside. Closes: #639883. openjdk-6 (6b23~pre8-2ubuntu1) oneiric; urgency=low * Regenerate the control file. openjdk-6 (6b23~pre8-2) unstable; urgency=low * Set plugin name for the jinfo file. Closes: #638548, * Disable the mauve testsuite on i386. * Make the installation multiarch aware. openjdk-6 (6b23~pre8-1ubuntu1) oneiric; urgency=low * Merge with Debian. openjdk-6 (6b23~pre8-1) unstable; urgency=low * Update from the IcedTea6 branch (20110820). - JamVM updates. * Build using GCC-4.4 on sparc and sparc64. * Enable testsuite runs in s390x. openjdk-6 (6b23~pre7-1) unstable; urgency=low * Update from the IcedTea6 branch (20110816). - JamVM updates. * Fix typo for s390x build. openjdk-6 (6b23~pre6-1) unstable; urgency=low * Update from the IcedTea6 branch (20110814). * Disable cacao for armhf. * Build using g++-4.5 on armhf. * Call dbus-launch --exit-with-session in testsuite. Closes: #612394. * Build for s390x using Zero. openjdk-6 (6b23~pre5-1) experimental; urgency=low * Build using GCC-4.4 on mips/mipsel. Closes: #628621. openjdk-6 (6b23~pre5-0ubuntu1) oneiric; urgency=low * Update from the IcedTea6 branch (20110810). openjdk-6 (6b23~pre4-2ubuntu1) oneiric; urgency=low * Regenerate the control file. openjdk-6 (6b23~pre4-2) experimental; urgency=low * openjdk-6-jre-headless: Depend on icedtea-6-jre-jamvm, if it's the default VM. * Use gcj-4.4 as the stage1 java VM on mips and mipsel. * Explicitly build-depend on xsltproc. openjdk-6 (6b23~pre4-1) experimental; urgency=low * Upload to experimental. openjdk-6 (6b23~pre4-0ubuntu1) oneiric; urgency=low * Update from the IcedTea6 branch (20110802). * Updated JamVM to the 2011-08-01 revision. * Make JamVM the default VM on Ubuntu oneiric/ARM. * Fix build on sparc. * Depend on libnss3 in multiarch location. Closes: #634058, #635111. openjdk-6 (6b23~pre3-0ubuntu2) oneiric; urgency=low * Build using g++-4.5 on oneiric/armel. openjdk-6 (6b23~pre3-0ubuntu1) oneiric; urgency=low * Update to the b23-05_jul_2011 tarball. - Includes fixes for security issues: - S6213702, CVE-2011-0872: (so) non-blocking sockets with TCP urgent disabled get still selected for read ops (win) - S6618658, CVE-2011-0865: Vulnerability in deserialization - S7012520, CVE-2011-0815: Heap overflow vulnerability in FileDialog.show() - S7013519, CVE-2011-0822, CVE-2011-0862: Integer overflows in 2D code - S7013969, CVE-2011-0867: NetworkInterface.toString can reveal bindings - S7013971, CVE-2011-0869: Vulnerability in SAAJ - S7016340, CVE-2011-0870: Vulnerability in SAAJ - S7016495, CVE-2011-0868: Crash in Java 2D transforming an image with scale close to zero - S7020198, CVE-2011-0871: ImageIcon creates Component with null acc - S7020373, CVE-2011-0864: JSR rewriting can overflow memory address size variables * Don't build with -Werror on sparc. * Build shark using llvm-2.9. openjdk-6 (6b23~pre2-2) experimental; urgency=low * Explicitly use GCC 4.6. openjdk-6 (6b23~pre2-1) experimental; urgency=low * Upload to experimental. openjdk-6 (6b23~pre2-0ubuntu2) oneiric; urgency=low * Don't run the jdk jtreg test with JamVM. openjdk-6 (6b23~pre2-0ubuntu1) oneiric; urgency=low * Fix non-bootstrap builds. * Depend against multiarch libnss3. LP: #779174. * Run jtreg tests using JamVM too. * Don't run the jtreg tests with the NSS security provider enabled. * Update JamVM to 20110528. openjdk-6 (6b23~pre1-0ubuntu2) oneiric; urgency=low * Build using g++-4.6 on oneiric. openjdk-6 (6b23~pre1-0ubuntu1) oneiric; urgency=low * Update from the IcedTea6 branch (20110517). * Add lcms configury. * Build on ARM using the zero port (without the ARM assembler interpreter). * Build-depend against multiarch libnss3. LP: #783941. Date: 2012-06-28 19:36:34.093762+00:00 Changed-By: Steve Beattie Signed-By: Jamie Strandboge https://launchpad.net/ubuntu/natty/+source/openjdk-6/6b24-1.11.3-1ubuntu0.11.04.1 -------------- next part -------------- Sorry, changesfile not available. From jamie at ubuntu.com Thu Jul 12 20:41:16 2012 From: jamie at ubuntu.com (Jamie Strandboge) Date: Thu, 12 Jul 2012 20:41:16 -0000 Subject: [ubuntu/natty-updates] icedtea-web 1.2-2ubuntu0.11.04.1 (Accepted) Message-ID: <20120712204116.29605.71739.launchpad@ackee.canonical.com> icedtea-web (1.2-2ubuntu0.11.04.1) natty-security; urgency=low * Backport IcedTea-web 1.2 to lucid in conjunction with OpenJDK 6/ IcedTea 1.11.3 backport * debian/rules: generate icedtea-plugin meta package * debian/icedtea-netx.postinst.in: skip update-alternatives on openjdk-7 binaries if they don't exist * Regenerate the control file. icedtea-web (1.2-2ubuntu1) precise; urgency=low * Regenerate the control file. icedtea-web (1.2-2) unstable; urgency=low * Fix interpreter path and classpath for OpenJDK7. Closes: #663895. * Update to the 1.2 release branch 20120409. - Fix PR895 (IcedTea-Web searches for missing classes on each loadClass or findClass). icedtea-web (1.2-1ubuntu1) precise; urgency=low * Regenerate the control file. icedtea-web (1.2-1) unstable; urgency=low * IcedTea-Web 1.2 release. * Make icedtea-netx-common multi-arch installable. icedtea-web (1.2~pre3-3) unstable; urgency=low * Really use OpenJDK 7 for the icedtea-7 plugin. Closes: #662239. icedtea-web (1.2~pre3-2) unstable; urgency=low * Fix another quoting issue. Closes: #662039. icedtea-web (1.2~pre3-1ubuntu1) precise; urgency=low * Regenerate the control file. icedtea-web (1.2~pre3-1) unstable; urgency=low * Update to hg 20120303, taken from the icedtea-web-1.2 release branch. icedtea-web (1.2~pre2-1ubuntu2) precise; urgency=low * debian/rules: Fix quoting issue. icedtea-web (1.2~pre2-1ubuntu1) precise; urgency=low * icedtea-netx-common: Drop dependency on OpenJDK. Closes: #661428. * Robustify maintainer scripts. Closes: #661424. icedtea-web (1.2~pre2-1) unstable; urgency=low * Regenerate the control file. icedtea-web (1.2~pre2-0ubuntu1) precise; urgency=low * Update to hg 20120226, taken from the icedtea-web-1.2 release branch. * Fix icedtea-7-plugin update. * Apply proposed patch for PR820, crashes with Firefox 10. icedtea-web (1.2~pre1-0ubuntu1) precise; urgency=low * Update to hg 20120203, taken from the icedtea-web-1.2 release branch. * Build separate plugin packages for OpenJDK 6 and OpenJDK 7, needed to provide the path to the runtime and the mime description in the plugin. Closes: #646843. * Use icedtea--plugin as the name for both plugin packages. * Remove icedtea-web-1.1.4-npapi-fix.patch, fixed upstream. * Pass -n to gzip when compressing manpages to be Multi-Arch: same safe. * Build multiarch packages. icedtea-web (1.1.4-1) unstable; urgency=medium * New upstream release with security fix : - RH742515, CVE-2011-3377: IcedTea-Web: second-level domain subdomains and suffix domain SOP bypass [ Sylvestre Ledru ] * Fix a typo in the description. (Closes: #644538) [ Damien Raude-Morvan ] * Compress manpages. (Closes: #642975) icedtea-web (1.1.3-2) unstable; urgency=low * Team upload * Sync from ubuntu * Explicit the dependency on the OpenJDK (Closes: #644045, #644094) * itweb-settings manpage added icedtea-web (1.1.3-1ubuntu1) oneiric; urgency=low * Fix non multiarch installation. icedtea-web (1.1.3-1) unstable; urgency=low * New upstream release: - Plug-in: PR782: Support building against npapi-sdk as well. - Common: PR794: IcedTea-Web does not work if a Web Start app jar has a Class-Path element in the manifest (e.g. Elluminate) * d/javaws.policy: Use AllPermission for netx.jar (as in Oracle JDK). * Add myself as Uploader. icedtea-web (1.1.2-1) unstable; urgency=low * Team upload * New upstream release: - PR769: IcedTea-Web does not work with some ssl sites with OpenJDK7. - Javaws cannot use proxy settings from Firefox. (Closes: #640748, #640736, #641038) * Drop the dependency on xulrunner (Closes: #636514, #606234, #601779) * Fix FTBFS due to the switch to multiarch (Closes: #641798) [ Damien Raude-Morvan ] * Switch to 3.0 (quilt) format. * d/javaws.policy: Allow RuntimePermission for javaws to access sun.security.util package. * d/patches/javaws_change_java_policy.diff: Loading of javaws.policy. * d/rules: Install javaws.policy into /etc/icedtea-web/. icedtea-web (1.1.1-1ubuntu2) oneiric; urgency=low * Updates from the 1.1 branch: - PR749: sun.applet.PluginStreamHandler#handleMessage(String) really slow. - PR768: Signed applets/Web Start apps don't work with OpenJDK7 and up. icedtea-web (1.1.1-1ubuntu1) oneiric; urgency=low * Rebuild the control file. icedtea-web (1.1.1-1) unstable; urgency=high * Upload to unstable. icedtea-web (1.1.1-0ubuntu1) natty-security; urgency=high * IcedTea-Web 1.1.1 release. - CVE-2011-2513: Home directory path disclosure to untrusted applications. - CVE-2011-2514: Java Web Start security warning dialog manipulation. Date: 2012-07-01 23:15:45.174375+00:00 Changed-By: Steve Beattie Signed-By: Jamie Strandboge https://launchpad.net/ubuntu/natty/+source/icedtea-web/1.2-2ubuntu0.11.04.1 -------------- next part -------------- Sorry, changesfile not available. From adconrad at 0c3.net Mon Jul 16 23:12:42 2012 From: adconrad at 0c3.net (Adam Conrad) Date: Mon, 16 Jul 2012 23:12:42 -0000 Subject: [ubuntu/natty-updates] linux 2.6.38-15.64 (Accepted) Message-ID: <20120716231242.24035.8305.launchpad@ackee.canonical.com> linux (2.6.38-15.64) natty-proposed; urgency=low [ Andy Whitcroft ] * fix ABI directory naming [ Luis Henriques ] * Release Tracking Bug - LP: #1019992 linux (2.6.38-15.63) natty-proposed; urgency=low [ Andy Whitcroft ] * No change upload to fix .ddeb generation in the PPA. [ Luis Henriques ] * Release Tracking Bug - LP: #1019992 linux (2.6.38-15.62) natty-proposed; urgency=low [Luis Henriques] * Release Tracking Bug - LP: #1019992 [ Upstream Kernel Changes ] * tun: reserves space for network in skb - LP: #905219 * KVM: VMX: do not overwrite uptodate vcpu->arch.cr3 on KVM_SET_SREGS - LP: #1018440 Date: 2012-07-06 16:07:02.845334+00:00 Changed-By: Andy Whitcroft Signed-By: Adam Conrad https://launchpad.net/ubuntu/natty/+source/linux/2.6.38-15.64 -------------- next part -------------- Sorry, changesfile not available. From launchpad at micahscomputing.com Tue Jul 17 17:28:55 2012 From: launchpad at micahscomputing.com (Micah Gersten) Date: Tue, 17 Jul 2012 17:28:55 -0000 Subject: [ubuntu/natty-security] firefox 14.0.1+build1-0ubuntu0.11.04.1 (Accepted) Message-ID: <20120717172855.21889.91002.launchpad@ackee.canonical.com> firefox (14.0.1+build1-0ubuntu0.11.04.1) natty-security; urgency=low * New upstream stable release (FIREFOX_14_0_1_BUILD1) - see LP: #1024562 for USN information [ Chris Coulson ] * Update globalmenu-extension to 3.2.5 - Fix LP: #1010580 - No choice of folder when adding a bookmark from the bookmark menu - Fix a crash in uGlobalMenu::RecycleList::~RecycleList() * Refresh patches - update debian/patches/ubuntu-codes-google.patch - update debian/patches/allow-lockPref-everywhere.patch - update debian/patches/plugin-for-mimetype-pref.patch - update debian/patches/firefox-kde.patch * Drop patches fixed upstream - remove debian/patches/revert-bmo-621446-investigation.patch - update debian/patches/series * Update desktop file translations - update debian/firefox.sh.in * Drop the application/vnd.mozilla.xul+xml mimetype from the desktop file. Firefox hasn't been able to view XUL files from non-chrome URI's since version 4.0 - update debian/firefox.desktop.in * Add application/x-xpinstall to the MimeType field of the desktop file - update debian/firefox.desktop.in * Drop the ability to select between tree/system libraries using a single option in debian/rules. It adds additional complexity and was never used - update debian/config/mozconfig.in - update debian/control.in - update debian/firefox-dev.install.in - update debian/firefox-dev.links.in - update debian/pkgconfig/libxul.pc.in - update debian/rules * Fix make-makefile test failure when the build directory contains perl regexp control characters - add debian/patches/make-makefile-test-fix.patch - update debian/patches/series * Shuffle the order of google-breakpad/src/common/dwarf/Makefile.in to fix a variable substitution issue, which was causing some objects to be built with the wrong compiler flags, resulting in dump_syms crashing (LP: #1002590) - add debian/patches/fix-makefile-substitution-bug.patch * Update StartupWMClass to the correct name - update debian/firefox.desktop.in - update debian/rules * Add search plugin for DuckDuckGo * Fix LP: #1000820 - firefox-dev conflicts with xulrunner-1.9-dev for people with the latter still installed - update debian/control{,.in} * Add Fulah to locales.blacklist * Fix LP: #1013186 - install our vendor preferences as application defaults rather than GRE defaults, so that they are loaded after the upstream defaults again. The upstream defaults were also moved as part of the webapp runtime work (which has it's own application defaults) - update debian/firefox.install.in - update debian/firefox.links.in * Apport hook improvements: - Sort preferences alphabetically in the apport data - Treat preferences set in default addons as default prefs so that they don't show up in apport data, unless the preference files have been modified - Support random pref files dropped in to the Firefox install folder, and preferences from application bundles - Fix ordering issues when loading preferences * Drop debian/patches/plugin-for-mimetype-pref.patch. The burden of carrying this is starting to outweigh the benefits of it [ Ben Collins ] * Cherry pick patch from aurora to use YARR interpreter on ppc - update debian/patches/fix-build-failure-without-yarr-jit.patch - update debian/patches/series * Fix ppc build due to new dtoa library - add debian/patches/fix-dtoa-build-on-ppc.patch - update debian/patches/series Date: 2012-07-13 22:56:01.460986+00:00 Changed-By: Chris Coulson Signed-By: Micah Gersten https://launchpad.net/ubuntu/natty/+source/firefox/14.0.1+build1-0ubuntu0.11.04.1 -------------- next part -------------- Sorry, changesfile not available. From launchpad at micahscomputing.com Tue Jul 17 17:43:28 2012 From: launchpad at micahscomputing.com (Micah Gersten) Date: Tue, 17 Jul 2012 17:43:28 -0000 Subject: [ubuntu/natty-security] lightning-extension 1.6+build1-0ubuntu0.11.04.2 (Accepted) Message-ID: <20120717174328.21889.61802.launchpad@ackee.canonical.com> lightning-extension (1.6+build1-0ubuntu0.11.04.2) natty-security; urgency=low * New upstream stable release (CALENDAR_1_6_BUILD1) (LP: #1024564) [ Chris Coulson ] * Fix LP: #995054 - Ensure the /usr/lib/thunderbird/extensions symlink exists on upgrade, which may not be the case when upgrading from a really old lightning version - add debian/lightning-extension.postinst [ Ben Collins ] * Fix LP: #1025387 - FTBFS: powerpc build fails - add debian/patches/fix-dtoa-build-on-ppc.patch - update debian/patches/series Date: 2012-07-16 19:36:40.365147+00:00 Changed-By: Chris Coulson Signed-By: Micah Gersten https://launchpad.net/ubuntu/natty/+source/lightning-extension/1.6+build1-0ubuntu0.11.04.2 -------------- next part -------------- Sorry, changesfile not available. From launchpad at micahscomputing.com Tue Jul 17 17:46:11 2012 From: launchpad at micahscomputing.com (Micah Gersten) Date: Tue, 17 Jul 2012 17:46:11 -0000 Subject: [ubuntu/natty-security] thunderbird 14.0+build1-0ubuntu0.11.04.1 (Accepted) Message-ID: <20120717174611.21889.11342.launchpad@ackee.canonical.com> thunderbird (14.0+build1-0ubuntu0.11.04.1) natty-security; urgency=low * New upstream stable release (THUNDERBIRD_14_0_BUILD1) - see LP: #1024564 for USN information [ Chris Coulson ] * Update globalmenu-extension to 3.2.5 - Fix a crash in uGlobalMenu::RecycleList::~RecycleList() - Fix LP: #1010580 - update the window event timestamp when handling menu events * Drop patches fixed upstream - remove debian/patches/revert-bmo621446-investigation.patch - update debian/patches/series * Refresh patches - update debian/patches/add-syspref-dir.patch * Update desktop file translations - update debian/thunderbird.desktop.in * Add application/x-xpinstall to the MimeType field of the desktop file - update debian/thunderbird.desktop.in * Drop almost all mimetypes from the desktop file. Thunderbird won't display any of them if you invoke it with files of these types. It will just open a Compose window and add the file as an attachment - update debian/thunderbird.desktop.in * Drop the ability to select between tree/system libraries using a single option in debian/rules. It adds additional complexity and was never used - update debian/config/mozconfig.in - update debian/control.in - update debian/thunderbird-dev.links.in - update debian/rules * Shuffle the order of google-breakpad/src/common/dwarf/Makefile.in to fix a variable substitution issue, which was causing some objects to be built with the wrong compiler flags, resulting in dump_syms crashing (LP: #1002590) - add debian/patches/fix-makefile-substitution-bug.patch * Don't set LD_LIBRARY_PATH in our shell wrapper, and install dependentlibs.list instead now - update debian/thunderbird.sh.in - update debian/thunderbird.install.in * Drop StartupWMClass from the desktop file now that WM_CLASS is the same as the binary name (also fixes LP: #1012158) - update debian/thunderbird.desktop.in - update debian/rules * Apport hook improvements: - Sort preferences alphabetically in the apport data - Treat preferences set in default addons as default prefs so that they don't show up in apport data, unless the preference files have been modified - Support random pref files dropped in to the Thunderbird install folder, and preferences from application bundles - Fix ordering issues when loading preferences * Update the Apport blacklist file after dropping thunderbird-bin - update debian/apport/blacklist.in [ Ben Collins ] * Cherry pick patch from aurora to use YARR interpreter on ppc - update debian/patches/fix-build-failure-without-yarr-jit.patch - update debian/patches/series * Fix ppc build due to new dtoa library - add debian/patches/fix-dtoa-build-on-ppc.patch - update debian/patches/series Date: 2012-07-13 23:16:05.043950+00:00 Changed-By: Chris Coulson Signed-By: Micah Gersten https://launchpad.net/ubuntu/natty/+source/thunderbird/14.0+build1-0ubuntu0.11.04.1 -------------- next part -------------- Sorry, changesfile not available. From launchpad at micahscomputing.com Tue Jul 17 17:46:13 2012 From: launchpad at micahscomputing.com (Micah Gersten) Date: Tue, 17 Jul 2012 17:46:13 -0000 Subject: [ubuntu/natty-security] enigmail 2:1.4.3-0ubuntu0.11.04.1 (Accepted) Message-ID: <20120717174613.21889.45444.launchpad@ackee.canonical.com> enigmail (2:1.4.3-0ubuntu0.11.04.1) natty-security; urgency=low * New upstream release v1.4.3 * Refresh patches - update debian/patches/makefile_depth.diff - update debian/patches/ipc-pipe_rename.diff - update debian/patches/dont_register_cids_multiple_times.diff Date: 2012-07-15 23:36:09.716905+00:00 Changed-By: Chris Coulson Signed-By: Micah Gersten https://launchpad.net/ubuntu/natty/+source/enigmail/2:1.4.3-0ubuntu0.11.04.1 -------------- next part -------------- Sorry, changesfile not available. From ubuntu at kitterman.com Wed Jul 18 04:00:27 2012 From: ubuntu at kitterman.com (Scott Kitterman) Date: Wed, 18 Jul 2012 04:00:27 -0000 Subject: [ubuntu/natty-updates] bluez 4.91-0ubuntu2 (Accepted) Message-ID: <20120718040027.25811.18837.launchpad@ackee.canonical.com> bluez (4.91-0ubuntu2) natty-proposed; urgency=low [ Keng-Yu Lin ] * Add patches/03-More-retries-when-initialising-the-device.patch - Fix the bug of bluetooth staying disabled on resume (LP: #812132) Date: 2011-08-16 02:30:12.670935+00:00 Changed-By: Robert Ancell Signed-By: Scott Kitterman https://launchpad.net/ubuntu/natty/+source/bluez/4.91-0ubuntu2 -------------- next part -------------- Sorry, changesfile not available. From ubuntu at kitterman.com Wed Jul 18 14:21:24 2012 From: ubuntu at kitterman.com (Scott Kitterman) Date: Wed, 18 Jul 2012 14:21:24 -0000 Subject: [ubuntu/natty-updates] insserv 1.14.0-2ubuntu0.11.04.2 (Accepted) Message-ID: <20120718142124.18253.93710.launchpad@ackee.canonical.com> insserv (1.14.0-2ubuntu0.11.04.2) natty-proposed; urgency=low * Only try to move links in /etc/rc{0,6}.d that match "S0*". LP: #941867. Date: 2012-04-14 05:20:17.343124+00:00 Changed-By: Steve Langasek Signed-By: Scott Kitterman https://launchpad.net/ubuntu/natty/+source/insserv/1.14.0-2ubuntu0.11.04.2 -------------- next part -------------- Sorry, changesfile not available. From clint at fewbar.com Wed Jul 18 16:35:15 2012 From: clint at fewbar.com (Clint Byrum) Date: Wed, 18 Jul 2012 16:35:15 -0000 Subject: [ubuntu/natty-updates] lfm 2.2-1ubuntu0.11.04.1 (Accepted) Message-ID: <20120718163515.25705.95253.launchpad@ackee.canonical.com> lfm (2.2-1ubuntu0.11.04.1) natty-proposed; urgency=low * Fix a crash at startup, because of UnicodeDecodeError (LP: #786491) Date: 2011-10-06 09:40:14.746406+00:00 Changed-By: Bruno Bigras Signed-By: Clint Byrum https://launchpad.net/ubuntu/natty/+source/lfm/2.2-1ubuntu0.11.04.1 -------------- next part -------------- Sorry, changesfile not available. From marc.deslauriers at ubuntu.com Thu Jul 19 12:41:29 2012 From: marc.deslauriers at ubuntu.com (Marc Deslauriers) Date: Thu, 19 Jul 2012 12:41:29 -0000 Subject: [ubuntu/natty-security] tiff 3.9.4-5ubuntu6.3 (Accepted) Message-ID: <20120719124129.12897.86130.launchpad@cocoplum.canonical.com> tiff (3.9.4-5ubuntu6.3) natty-security; urgency=low * SECURITY UPDATE: possible arbitrary code execution via heap overflow in tiff2pdf. - debian/patches/CVE-2012-3401.patch: properly set t2p->t2p_error in tools/tiff2pdf.c. - CVE-2012-3401 Date: Mon, 16 Jul 2012 09:50:58 -0400 Changed-By: Marc Deslauriers Maintainer: Ubuntu Developers https://launchpad.net/ubuntu/natty/+source/tiff/3.9.4-5ubuntu6.3 -------------- next part -------------- Format: 1.8 Date: Mon, 16 Jul 2012 09:50:58 -0400 Source: tiff Binary: libtiff4 libtiffxx0c2 libtiff4-dev libtiff-tools libtiff-opengl libtiff-doc Architecture: source Version: 3.9.4-5ubuntu6.3 Distribution: natty-security Urgency: low Maintainer: Ubuntu Developers Changed-By: Marc Deslauriers Description: libtiff-doc - TIFF manipulation and conversion documentation libtiff-opengl - TIFF manipulation and conversion tools libtiff-tools - TIFF manipulation and conversion tools libtiff4 - Tag Image File Format (TIFF) library libtiff4-dev - Tag Image File Format library (TIFF), development files libtiffxx0c2 - Tag Image File Format (TIFF) library -- C++ interface Changes: tiff (3.9.4-5ubuntu6.3) natty-security; urgency=low . * SECURITY UPDATE: possible arbitrary code execution via heap overflow in tiff2pdf. - debian/patches/CVE-2012-3401.patch: properly set t2p->t2p_error in tools/tiff2pdf.c. - CVE-2012-3401 Checksums-Sha1: 6c84ae42455d7c09b0892964b6415a1e72ded8a7 2002 tiff_3.9.4-5ubuntu6.3.dsc e3094b70e0ccee4820df68a0e2c4697c7919ec50 24346 tiff_3.9.4-5ubuntu6.3.debian.tar.gz Checksums-Sha256: f03a81e1e9cfc63e46dd37d58f4e6acc7f9bfb2dda7f201048e25eca332b11bc 2002 tiff_3.9.4-5ubuntu6.3.dsc 7393cf2ac70cef651294fc2f28b6bfcea7c9d7744334a2c3acbd9a665e5cfddd 24346 tiff_3.9.4-5ubuntu6.3.debian.tar.gz Files: 5959c9368cdd8493bd1b7ab287ea9e5e 2002 libs optional tiff_3.9.4-5ubuntu6.3.dsc 32fc7026f5e770b40bd0d2fe3dbb60aa 24346 libs optional tiff_3.9.4-5ubuntu6.3.debian.tar.gz Original-Maintainer: Jay Berkenbilt From marc.deslauriers at ubuntu.com Mon Jul 23 18:33:50 2012 From: marc.deslauriers at ubuntu.com (Marc Deslauriers) Date: Mon, 23 Jul 2012 18:33:50 -0000 Subject: [ubuntu/natty-security] libexif, libexif_0.6.20-0ubuntu1.1_armel_translations.tar.gz, libexif_0.6.20-0ubuntu1.1_powerpc_translations.tar.gz, libexif_0.6.20-0ubuntu1.1_amd64_translations.tar.gz, libexif_0.6.20-0ubuntu1.1_i386_translations.tar.gz 0.6.20-0ubuntu1.1 (Accepted) Message-ID: <20120723183350.3119.72552.launchpad@cocoplum.canonical.com> libexif (0.6.20-0ubuntu1.1) natty-security; urgency=low * SECURITY UPDATE: denial of service and possible info disclosure via corrupted EXIF_TAG_COPYRIGHT tag (LP: #1024213) - debian/patches/CVE-2012-2812.patch: fix reading tags that aren't NUL-terminated in libexif/exif-entry.c. - CVE-2012-2812 * SECURITY UPDATE: denial of service and possible info disclosure via UTF-16 tag (LP: #1024213) - debian/patches/CVE-2012-2813.patch: don't read past the end of a tag when converting from UTF-16 in libexif/exif-entry.c. - CVE-2012-2813 * SECURITY UPDATE: denial of service and possible code execution via crafted tags (LP: #1024213) - debian/patches/CVE-2012-2814.patch: fix buffer overflows in libexif/exif-entry.c. - CVE-2012-2814 * SECURITY UPDATE: denial of service and possible info disclosure via crafted tags (LP: #1024213) - debian/patches/CVE-2012-2836.patch: fix buffer overflows in libexif/exif-data.c - CVE-2012-2836 * SECURITY UPDATE: denial of service via crafted tags (LP: #1024213) - debian/patches/CVE-2012-2837.patch: fix some possible division-by-zeros in libexif/olympus/mnote-olympus-entry.c. - CVE-2012-2837 * SECURITY UPDATE: denial of service and possible code execution via crafted tags (LP: #1024213) - debian/patches/CVE-2012-2840.patch: fix off-by-one in libexif/exif-utils.c. - CVE-2012-2840 * SECURITY UPDATE: denial of service and possible code execution via incorrect buffer size (LP: #1024213) - debian/patches/CVE-2012-2841.patch: validate buffer length in libexif/exif-entry.c. - CVE-2012-2841 Date: Thu, 19 Jul 2012 13:46:27 -0400 Changed-By: Marc Deslauriers Maintainer: Ubuntu Developers https://launchpad.net/ubuntu/natty/+source/libexif/0.6.20-0ubuntu1.1 -------------- next part -------------- Format: 1.8 Date: Thu, 19 Jul 2012 13:46:27 -0400 Source: libexif Binary: libexif-dev libexif12 Architecture: source Version: 0.6.20-0ubuntu1.1 Distribution: natty-security Urgency: low Maintainer: Ubuntu Developers Changed-By: Marc Deslauriers Description: libexif-dev - library to parse EXIF files (development files) libexif12 - library to parse EXIF files Launchpad-Bugs-Fixed: 1024213 Changes: libexif (0.6.20-0ubuntu1.1) natty-security; urgency=low . * SECURITY UPDATE: denial of service and possible info disclosure via corrupted EXIF_TAG_COPYRIGHT tag (LP: #1024213) - debian/patches/CVE-2012-2812.patch: fix reading tags that aren't NUL-terminated in libexif/exif-entry.c. - CVE-2012-2812 * SECURITY UPDATE: denial of service and possible info disclosure via UTF-16 tag (LP: #1024213) - debian/patches/CVE-2012-2813.patch: don't read past the end of a tag when converting from UTF-16 in libexif/exif-entry.c. - CVE-2012-2813 * SECURITY UPDATE: denial of service and possible code execution via crafted tags (LP: #1024213) - debian/patches/CVE-2012-2814.patch: fix buffer overflows in libexif/exif-entry.c. - CVE-2012-2814 * SECURITY UPDATE: denial of service and possible info disclosure via crafted tags (LP: #1024213) - debian/patches/CVE-2012-2836.patch: fix buffer overflows in libexif/exif-data.c - CVE-2012-2836 * SECURITY UPDATE: denial of service via crafted tags (LP: #1024213) - debian/patches/CVE-2012-2837.patch: fix some possible division-by-zeros in libexif/olympus/mnote-olympus-entry.c. - CVE-2012-2837 * SECURITY UPDATE: denial of service and possible code execution via crafted tags (LP: #1024213) - debian/patches/CVE-2012-2840.patch: fix off-by-one in libexif/exif-utils.c. - CVE-2012-2840 * SECURITY UPDATE: denial of service and possible code execution via incorrect buffer size (LP: #1024213) - debian/patches/CVE-2012-2841.patch: validate buffer length in libexif/exif-entry.c. - CVE-2012-2841 Checksums-Sha1: b62da2e4f84434e5f362ced8e8b5d205b3c541bc 2106 libexif_0.6.20-0ubuntu1.1.dsc 862087dc31b380557f7acd4a2046e48ffe58b4db 11474 libexif_0.6.20-0ubuntu1.1.diff.gz Checksums-Sha256: 942ffa1aedde591e03dec518aeae3ed6942e2beb309b9ddc2f5baafc33d2eb52 2106 libexif_0.6.20-0ubuntu1.1.dsc 5272b09c5a98cd2ea20ee4c5fc3c5b77381bffe408eb9fdc2788dc836edbdbfa 11474 libexif_0.6.20-0ubuntu1.1.diff.gz Files: 6c1e4ceb90c73edb78ffd677c161b465 2106 libs optional libexif_0.6.20-0ubuntu1.1.dsc ded4d65cc3559031e55053cc9268c908 11474 libs optional libexif_0.6.20-0ubuntu1.1.diff.gz Original-Maintainer: Debian PhotoTools Maintainers From chris.j.arges at canonical.com Mon Jul 23 20:28:10 2012 From: chris.j.arges at canonical.com (Chris J Arges) Date: Mon, 23 Jul 2012 20:28:10 -0000 Subject: [ubuntu/natty-proposed] nss-pam-ldapd 0.7.13ubuntu0.11.04 (Accepted) Message-ID: <20120723202810.19156.15276.launchpad@wampee.canonical.com> nss-pam-ldapd (0.7.13ubuntu0.11.04) natty-proposed; urgency=low * increase buffer used for pam_authz_search (LP: #951343) Date: Mon, 16 Jul 2012 08:39:03 -0500 Changed-By: Chris J Arges Maintainer: Ubuntu Developers Signed-By: Adam Conrad https://launchpad.net/ubuntu/natty/+source/nss-pam-ldapd/0.7.13ubuntu0.11.04 -------------- next part -------------- Format: 1.8 Date: Mon, 16 Jul 2012 08:39:03 -0500 Source: nss-pam-ldapd Binary: nslcd libnss-ldapd libpam-ldapd Architecture: source Version: 0.7.13ubuntu0.11.04 Distribution: natty-proposed Urgency: low Maintainer: Ubuntu Developers Changed-By: Chris J Arges Description: libnss-ldapd - NSS module for using LDAP as a naming service libpam-ldapd - PAM module for using LDAP as an authentication service nslcd - Daemon for NSS and PAM lookups using LDAP Launchpad-Bugs-Fixed: 951343 Changes: nss-pam-ldapd (0.7.13ubuntu0.11.04) natty-proposed; urgency=low . * increase buffer used for pam_authz_search (LP: #951343) Checksums-Sha1: 6d42e279e6515ed8ff992a75e1aae5179d4954b7 1335 nss-pam-ldapd_0.7.13ubuntu0.11.04.dsc a932ae3947974def6cfe22385dff75c9a3e5a976 475667 nss-pam-ldapd_0.7.13ubuntu0.11.04.tar.gz Checksums-Sha256: 498cfbdca6da72a96b3006cf666749b21c75bbf9b1c6058394eaf474216f2bb1 1335 nss-pam-ldapd_0.7.13ubuntu0.11.04.dsc 466e5d38a1e534f8d8075f8f372953bc2dee8b77e58d156c168dde9981286db2 475667 nss-pam-ldapd_0.7.13ubuntu0.11.04.tar.gz Files: 89c982ecd76b403c25965b7db8b69dee 1335 admin extra nss-pam-ldapd_0.7.13ubuntu0.11.04.dsc f6b2eee675702bb15db51c161f482fc0 475667 admin extra nss-pam-ldapd_0.7.13ubuntu0.11.04.tar.gz Original-Maintainer: Arthur de Jong From chris at cooperteam.net Wed Jul 25 03:14:49 2012 From: chris at cooperteam.net (Chris Halse Rogers) Date: Wed, 25 Jul 2012 03:14:49 -0000 Subject: [ubuntu/natty-updates] landscape-client 12.05-0ubuntu0.11.04 (Accepted) Message-ID: <20120725031449.2388.86617.launchpad@ackee.canonical.com> landscape-client (12.05-0ubuntu0.11.04) natty-proposed; urgency=low * New upstream release 12.05 (r561 in trunk) (LP: #1004678). * Make all subpackages that depend on each other require the exact same version, instead of >= $version. * Added python-gi to client depends starting natty. * Make change-packages also handle package holds (LP: #972489). * Fix typo in glade file (LP: #983096). * Tidy up apt facade (LP: #985493). * Remove SmartFacade and its tests, no longer used (LP: #996269). * Remove check for apt version, since we won't release this for Hardy where that check matters (LP: #996837). * Remove methods that were smart specific. We no longer use smart (LP: #996841). * Remove smart-update helper binary. We no longer use smart (LP: #997408). * Remove test-mixins that were useful only during the apt-to-smart code migration. Now with smart gone, they are no longer necessary (LP: #997760). * Build the packages from precise onward, not just precise. * Assorted packaging fixes: - Switched to format 3.0 (quilt). - Added source lintian overrides, with comments. - Updated debian/rules: - Added build-arch and build-indep dummy target. - Build the GUI packages from precise onwards, and not just on precise. - Re-enable dh_lintian. - Strip the binaries (dh_strip), and also call dh_shlibdeps for the automatic shlibs dependency. - Added python-gi from natty onwards. - Used __Choices instead of _Choices in landscape-common.templates, it's better for translators. - Updated standard version to 3.8.2, the version from Lucid (oldest one we support) - Added shlibs depends. - Dropped deprecated ${Source-Version} and replaced it with ${binary:Version} - Require exact version of the sibling package instead of >=. Date: 2012-07-05 21:45:33.494271+00:00 Changed-By: Andreas Hasenack Signed-By: Chris Halse Rogers https://launchpad.net/ubuntu/natty/+source/landscape-client/12.05-0ubuntu0.11.04 -------------- next part -------------- Sorry, changesfile not available. From marc.deslauriers at ubuntu.com Wed Jul 25 18:35:43 2012 From: marc.deslauriers at ubuntu.com (Marc Deslauriers) Date: Wed, 25 Jul 2012 18:35:43 -0000 Subject: [ubuntu/natty-security] mono, mono_2.6.7-5ubuntu3.1_armel_translations.tar.gz, mono_2.6.7-5ubuntu3.1_powerpc_translations.tar.gz, mono_2.6.7-5ubuntu3.1_i386_translations.tar.gz, mono_2.6.7-5ubuntu3.1_amd64_translations.tar.gz 2.6.7-5ubuntu3.1 (Accepted) Message-ID: <20120725183543.20476.6635.launchpad@cocoplum.canonical.com> mono (2.6.7-5ubuntu3.1) natty-security; urgency=low * SECURITY UPDATE: cross-site scripting vulnerability - mcs/class/System.Web/System.Web/HttpForbiddenHandler.cs: properly escape error message. - CVE-2012-3382 Date: Tue, 24 Jul 2012 13:34:56 -0400 Changed-By: Marc Deslauriers Maintainer: Ubuntu Developers https://launchpad.net/ubuntu/natty/+source/mono/2.6.7-5ubuntu3.1 -------------- next part -------------- Format: 1.8 Date: Tue, 24 Jul 2012 13:34:56 -0400 Source: mono Binary: mono-runtime mono-runtime-dbg mono-utils mono-complete libmono0 libmono0-dbg libmono-dev libmono-profiler libmono-cil-dev libmono1.0-cil libmono2.0-cil libmono-posix1.0-cil libmono-posix2.0-cil libmono-getoptions1.0-cil libmono-getoptions2.0-cil libmono-cecil-private-cil libmono-data1.0-cil libmono-data2.0-cil libmono-c5-1.1-cil libmono-webbrowser0.5-cil libmono-management2.0-cil libmono-messaging2.0-cil libmono-messaging-rabbitmq2.0-cil libmono-rabbitmq2.0-cil libmono-simd2.0-cil libmono-corlib1.0-cil libmono-corlib2.0-cil libmono-i18n-west1.0-cil libmono-i18n-west2.0-cil libmono-i18n1.0-cil libmono-i18n2.0-cil libmono-system1.0-cil libmono-system2.0-cil libmono-system-messaging1.0-cil libmono-system-messaging2.0-cil libmono-security1.0-cil libmono-security2.0-cil libmono-data-tds1.0-cil libmono-data-tds2.0-cil libmono-system-data1.0-cil libmono-system-data2.0-cil libmono-system-data-linq2.0-cil libmono-system-web1.0-cil libmono-system-web2.0-cil libmono-system-web-mvc1.0-cil libmono-system-web-mvc2.0-cil libmono-wcf3.0-cil libmono-system-runtime1.0-cil libmono-system-runtime2.0-cil libmono-system-ldap1.0-cil libmono-system-ldap2.0-cil libmono-winforms1.0-cil libmono-winforms2.0-cil libmono-cairo1.0-cil libmono-cairo2.0-cil libmono-sharpzip0.6-cil libmono-sharpzip0.84-cil libmono-sharpzip2.6-cil libmono-sharpzip2.84-cil libmono-npgsql1.0-cil libmono-npgsql2.0-cil libmono-bytefx0.7.6.1-cil libmono-bytefx0.7.6.2-cil libmono-firebirdsql1.7-cil libmono-db2-1.0-cil libmono-oracle1.0-cil libmono-oracle2.0-cil libmono-sqlite1.0-cil libmono-sqlite2.0-cil libmono-accessibility1.0-cil libmono-accessibility2.0-cil libmono-cscompmgd7.0-cil libmono-cscompmgd8.0-cil libmono-ldap1.0-cil libmono-ldap2.0-cil libmono-microsoft-build2.0-cil libmono-microsoft7.0-cil libmono-microsoft8.0-cil libmono-peapi1.0-cil libmono-peapi2.0-cil libmono-relaxng1.0-cil libmono-relaxng2.0-cil libmono-debugger-soft0.0-cil libmono-tasklets2.0-cil libmono-windowsbase3.0-cil mono-dbg mono-mjs mono-mcs mono-gmcs mono-devel mono-1.0-devel mono-2.0-devel mono-1.0-service mono-2.0-service mono-xbuild mono-gac mono-1.0-gac mono-2.0-gac mono-jay prj2make-sharp mono-csharp-shell monodoc-base monodoc-manual Architecture: source Version: 2.6.7-5ubuntu3.1 Distribution: natty-security Urgency: low Maintainer: Ubuntu Developers Changed-By: Marc Deslauriers Description: libmono-accessibility1.0-cil - Mono Accessibility library (for CLI 1.0) libmono-accessibility2.0-cil - Mono Accessibility library (for CLI 2.0) libmono-bytefx0.7.6.1-cil - Mono ByteFX.Data library (for CLI 1.0) libmono-bytefx0.7.6.2-cil - Mono ByteFX.Data library (for CLI 2.0) libmono-c5-1.1-cil - Mono C5 library libmono-cairo1.0-cil - Mono Cairo library (for CLI 1.0) libmono-cairo2.0-cil - Mono Cairo library (for CLI 2.0) libmono-cecil-private-cil - Mono.Cecil library libmono-cil-dev - Mono Base Class Libraries (BCL) - Development files libmono-corlib1.0-cil - Mono core library (for CLI 1.0) libmono-corlib2.0-cil - Mono core library (for CLI 2.0) libmono-cscompmgd7.0-cil - Mono cscompmgd library (for CLI 1.0) libmono-cscompmgd8.0-cil - Mono cscompmgd library (for CLI 2.0) libmono-data-tds1.0-cil - Mono Data library (for CLI 1.0) libmono-data-tds2.0-cil - Mono Data Library (for CLI 2.0) libmono-data1.0-cil - Mono.Data.* libraries (for CLI 1.0) libmono-data2.0-cil - Mono.Data.* libraries (for CLI 2.0) libmono-db2-1.0-cil - Mono DB2 library libmono-debugger-soft0.0-cil - Mono Soft Debugger library (for CLI 2.0) libmono-dev - Mono JIT library - Development files libmono-firebirdsql1.7-cil - Mono FirebirdSql library libmono-getoptions1.0-cil - Mono.GetOptions library (for CLI 1.0) libmono-getoptions2.0-cil - Mono.GetOptions library (for CLI 2.0) libmono-i18n-west1.0-cil - Mono I18N.West library (for CLI 1.0) libmono-i18n-west2.0-cil - Mono I18N.West library (for CLI 2.0) libmono-i18n1.0-cil - Mono I18N libraries (for CLI 1.0) libmono-i18n2.0-cil - Mono I18N libraries (for CLI 2.0) libmono-ldap1.0-cil - Mono LDAP library (for CLI 1.0) libmono-ldap2.0-cil - Mono LDAP library (for CLI 2.0) libmono-management2.0-cil - Mono Management library (for CLI 2.0) libmono-messaging-rabbitmq2.0-cil - Mono Messaging RabbitMQ library (for CLI 2.0) libmono-messaging2.0-cil - Mono Messaging library (for CLI 2.0) libmono-microsoft-build2.0-cil - Mono Microsoft.Build libraries libmono-microsoft7.0-cil - Mono Microsoft libraries (for CLI 1.0) libmono-microsoft8.0-cil - Mono Microsoft libraries (for CLI 2.0) libmono-npgsql1.0-cil - Mono Npgsql library (for CLI 1.0) libmono-npgsql2.0-cil - Mono Npgsql library (for CLI 2.0) libmono-oracle1.0-cil - Mono Oracle library (for CLI 1.0) libmono-oracle2.0-cil - Mono Oracle library (for CLI 2.0) libmono-peapi1.0-cil - Mono PEAPI library (for CLI 1.0) libmono-peapi2.0-cil - Mono PEAPI library (for CLI 2.0) libmono-posix1.0-cil - Mono.Posix library (for CLI 1.0) libmono-posix2.0-cil - Mono.Posix library (for CLI 2.0) libmono-profiler - Mono profiler libraries libmono-rabbitmq2.0-cil - Mono RabbitMQ.Client library (for CLI 2.0) libmono-relaxng1.0-cil - Mono Relaxng library (for CLI 1.0) libmono-relaxng2.0-cil - Mono Relaxng library (for CLI 2.0) libmono-security1.0-cil - Mono Security library (for CLI 1.0) libmono-security2.0-cil - Mono Security library (for CLI 2.0) libmono-sharpzip0.6-cil - Mono SharpZipLib library (for CLI 1.0) libmono-sharpzip0.84-cil - Mono SharpZipLib library (for CLI 1.0) libmono-sharpzip2.6-cil - Mono SharpZipLib library (for CLI 2.0) libmono-sharpzip2.84-cil - Mono SharpZipLib library (for CLI 2.0) libmono-simd2.0-cil - Mono SIMD (for CLI 2.0) libmono-sqlite1.0-cil - Mono Sqlite library (for CLI 1.0) libmono-sqlite2.0-cil - Mono Sqlite library (for CLI 2.0) libmono-system-data-linq2.0-cil - Mono System.Data.Linq Library libmono-system-data1.0-cil - Mono System.Data library (for CLI 1.0) libmono-system-data2.0-cil - Mono System.Data Library (for CLI 2.0) libmono-system-ldap1.0-cil - Mono System.DirectoryServices library (for CLI 1.0) libmono-system-ldap2.0-cil - Mono System.DirectoryServices library (for CLI 2.0) libmono-system-messaging1.0-cil - Mono System.Messaging library (for CLI 1.0) libmono-system-messaging2.0-cil - Mono System.Messaging Library (for CLI 2.0) libmono-system-runtime1.0-cil - Mono System.Runtime library (for CLI 1.0) libmono-system-runtime2.0-cil - Mono System.Runtime Library (for CLI 2.0) libmono-system-web-mvc1.0-cil - Mono ASP.NET MVC Library libmono-system-web-mvc2.0-cil - Mono ASP.NET MVC 2.0 Library libmono-system-web1.0-cil - Mono System.Web library (for CLI 1.0) libmono-system-web2.0-cil - Mono System.Web Library (for CLI 2.0) libmono-system1.0-cil - Mono System libraries (for CLI 1.0) libmono-system2.0-cil - Mono System libraries (for CLI 2.0) libmono-tasklets2.0-cil - Mono Tasklets library (for CLI 2.0) libmono-wcf3.0-cil - Mono WCF libraries (for CLI 2.0) libmono-webbrowser0.5-cil - Mono Web Browser library libmono-windowsbase3.0-cil - Mono WindowsBase library (for CLI 2.0) libmono-winforms1.0-cil - Mono System.Windows.Forms library (for CLI 1.0) libmono-winforms2.0-cil - Mono System.Windows.Forms library (for CLI 2.0) libmono0 - Mono JIT library libmono0-dbg - Mono JIT library, debugging symbols libmono1.0-cil - Mono libraries (for CLI 1.0) libmono2.0-cil - Mono libraries (for CLI 2.0) mono-1.0-devel - Mono development tools for CLI 1.0 mono-1.0-gac - Mono GAC tool (for CLI 1.0) mono-1.0-service - Mono service manager for CLI 1.0 mono-2.0-devel - Mono development tools for CLI 2.0 mono-2.0-gac - Mono GAC tool (for CLI 2.0) mono-2.0-service - Mono service manager for CLI 2.0 mono-complete - complete Mono runtime, development tools and all libraries mono-csharp-shell - interactive C# shell mono-dbg - Mono debugging symbols mono-devel - Mono development tools mono-gac - Mono GAC tool mono-gmcs - Mono C# 2.0 and C# 3.0 compiler for CLI 2.0 mono-jay - LALR(1) parser generator oriented to Java/CLI mono-mcs - Mono C# 1.0 compiler for CLI 1.1 mono-mjs - Mono JScript compiler mono-runtime - Mono runtime mono-runtime-dbg - Mono runtime, debugging symbols mono-utils - Mono utilities mono-xbuild - MSBuild-compatible build system for Mono monodoc-base - shared MonoDoc binaries monodoc-manual - compiled XML documentation from the Mono project prj2make-sharp - Convert VS.NET solution files to Makefiles Changes: mono (2.6.7-5ubuntu3.1) natty-security; urgency=low . * SECURITY UPDATE: cross-site scripting vulnerability - mcs/class/System.Web/System.Web/HttpForbiddenHandler.cs: properly escape error message. - CVE-2012-3382 Checksums-Sha1: 36aa144841454986e714481dabe8468caa745bf4 4548 mono_2.6.7-5ubuntu3.1.dsc e1cc57e2186309d0a2a4a9dd791afdce488e63fd 124743 mono_2.6.7-5ubuntu3.1.diff.gz Checksums-Sha256: 6083f634abec8dd3156e580d154500bca42a534dd7dbe34ca6df9d6f1de0e86e 4548 mono_2.6.7-5ubuntu3.1.dsc 6dcd06b717f5e0fca2059ebfd091ec86291ced4372f85fe7ae97918f87ba9dcd 124743 mono_2.6.7-5ubuntu3.1.diff.gz Files: c4a4ec44da4a98df94c428057df236a3 4548 cli-mono optional mono_2.6.7-5ubuntu3.1.dsc 6447476d612f881a60a65f0e57bb5c49 124743 cli-mono optional mono_2.6.7-5ubuntu3.1.diff.gz Original-Maintainer: Debian Mono Group From ubuntu at kitterman.com Thu Jul 26 05:45:22 2012 From: ubuntu at kitterman.com (Scott Kitterman) Date: Thu, 26 Jul 2012 05:45:22 -0000 Subject: [ubuntu/natty-updates] hg-git 0.2.3-1ubuntu0.1 (Accepted) Message-ID: <20120726054522.15065.28999.launchpad@ackee.canonical.com> hg-git (0.2.3-1ubuntu0.1) natty-proposed; urgency=low * 000-fix-line-split-error-on-bad-data-from-rebase.diff: fix crash when bad data from rebase is in the log (LP: #986279) Date: 2012-04-30 16:55:34.312404+00:00 Changed-By: Julian Taylor Signed-By: Scott Kitterman https://launchpad.net/ubuntu/natty/+source/hg-git/0.2.3-1ubuntu0.1 -------------- next part -------------- Sorry, changesfile not available. From marc.deslauriers at ubuntu.com Thu Jul 26 13:34:16 2012 From: marc.deslauriers at ubuntu.com (Marc Deslauriers) Date: Thu, 26 Jul 2012 13:34:16 -0000 Subject: [ubuntu/natty-security] bind9_9.7.3.dfsg-1ubuntu2.5_powerpc_translations.tar.gz, bind9_9.7.3.dfsg-1ubuntu2.5_amd64_translations.tar.gz, bind9, bind9_9.7.3.dfsg-1ubuntu2.5_armel_translations.tar.gz, bind9_9.7.3.dfsg-1ubuntu2.5_i386_translations.tar.gz 1:9.7.3.dfsg-1ubuntu2.5 (Accepted) Message-ID: <20120726133416.5099.28766.launchpad@cocoplum.canonical.com> bind9 (1:9.7.3.dfsg-1ubuntu2.5) natty-security; urgency=low * SECURITY UPDATE: denial of service via dnssec validation load - lib/dns/resolver.c: don't use bad->expire before it has been set. - Patch backported from 9.7.6-P2. - CVE-2012-3817 Date: Wed, 25 Jul 2012 16:26:07 -0400 Changed-By: Marc Deslauriers Maintainer: Ubuntu Developers https://launchpad.net/ubuntu/natty/+source/bind9/1:9.7.3.dfsg-1ubuntu2.5 -------------- next part -------------- Format: 1.8 Date: Wed, 25 Jul 2012 16:26:07 -0400 Source: bind9 Binary: bind9 bind9utils bind9-doc host bind9-host libbind-dev libbind9-60 libdns69 libisc62 liblwres60 libisccc60 libisccfg62 dnsutils lwresd Architecture: source Version: 1:9.7.3.dfsg-1ubuntu2.5 Distribution: natty-security Urgency: low Maintainer: Ubuntu Developers Changed-By: Marc Deslauriers Description: bind9 - Internet Domain Name Server bind9-doc - Documentation for BIND bind9-host - Version of 'host' bundled with BIND 9.X bind9utils - Utilities for BIND dnsutils - Clients provided with BIND host - Transitional package libbind-dev - Static Libraries and Headers used by BIND libbind9-60 - BIND9 Shared Library used by BIND libdns69 - DNS Shared Library used by BIND libisc62 - ISC Shared Library used by BIND libisccc60 - Command Channel Library used by BIND libisccfg62 - Config File Handling Library used by BIND liblwres60 - Lightweight Resolver Library used by BIND lwresd - Lightweight Resolver Daemon Changes: bind9 (1:9.7.3.dfsg-1ubuntu2.5) natty-security; urgency=low . * SECURITY UPDATE: denial of service via dnssec validation load - lib/dns/resolver.c: don't use bad->expire before it has been set. - Patch backported from 9.7.6-P2. - CVE-2012-3817 Checksums-Sha1: 29583550a7a77185973270300349b826847dce9e 2267 bind9_9.7.3.dfsg-1ubuntu2.5.dsc 45b690102ab9635b7a129f5e8a0c55392c40191f 519677 bind9_9.7.3.dfsg-1ubuntu2.5.diff.gz Checksums-Sha256: 2dec3eb6b5d97e601c1301daf3de0542c9115ede27e92fd025be5e3d47a13184 2267 bind9_9.7.3.dfsg-1ubuntu2.5.dsc f1f9ac4804b911f04f9d09f22a94dcacc9ba1fbf30e5c21e9aca57dd52b85c2f 519677 bind9_9.7.3.dfsg-1ubuntu2.5.diff.gz Files: 46a46479e35bc24f1149fc70b6e503ff 2267 net optional bind9_9.7.3.dfsg-1ubuntu2.5.dsc f0dbb1d5050b56afab92db5cf033bacb 519677 net optional bind9_9.7.3.dfsg-1ubuntu2.5.diff.gz Original-Maintainer: LaMont Jones From marc.deslauriers at ubuntu.com Thu Jul 26 18:03:53 2012 From: marc.deslauriers at ubuntu.com (Marc Deslauriers) Date: Thu, 26 Jul 2012 18:03:53 -0000 Subject: [ubuntu/natty-security] isc-dhcp_4.1.1-P1-15ubuntu9.4_powerpc_translations.tar.gz, isc-dhcp, isc-dhcp_4.1.1-P1-15ubuntu9.4_armel_translations.tar.gz, isc-dhcp_4.1.1-P1-15ubuntu9.4_amd64_translations.tar.gz, isc-dhcp_4.1.1-P1-15ubuntu9.4_i386_translations.tar.gz 4.1.1-P1-15ubuntu9.4 (Accepted) Message-ID: <20120726180353.12734.41734.launchpad@cocoplum.canonical.com> isc-dhcp (4.1.1-P1-15ubuntu9.4) natty-security; urgency=low * SECURITY UPDATE: denial of service via malformed client identifiers - debian/patches/CVE-2012-3571.dpatch: validate packets in common/options.{c,h}. - CVE-2012-3571.dpatch * SECURITY UPDATE: denial of service via memory leaks - debian/patches/CVE-2012-3954.dpatch: properly manage memory in common/options.c and server/dhcpv6.c. - CVE-2012-3954 Date: Wed, 25 Jul 2012 17:28:23 -0400 Changed-By: Marc Deslauriers Maintainer: Ubuntu Developers https://launchpad.net/ubuntu/natty/+source/isc-dhcp/4.1.1-P1-15ubuntu9.4 -------------- next part -------------- Format: 1.8 Date: Wed, 25 Jul 2012 17:28:23 -0400 Source: isc-dhcp Binary: isc-dhcp-server isc-dhcp-server-dbg isc-dhcp-server-ldap isc-dhcp-common isc-dhcp-dev isc-dhcp-client isc-dhcp-client-dbg isc-dhcp-client-udeb isc-dhcp-relay isc-dhcp-relay-dbg dhcp3-server dhcp3-client dhcp3-relay dhcp3-common dhcp3-dev Architecture: source Version: 4.1.1-P1-15ubuntu9.4 Distribution: natty-security Urgency: low Maintainer: Ubuntu Developers Changed-By: Marc Deslauriers Description: dhcp3-client - ISC DHCP server (transitional package) dhcp3-common - ISC DHCP common files (transitional package) dhcp3-dev - ISC DHCP development files (transitional package) dhcp3-relay - ISC DHCP relay (transitional package) dhcp3-server - ISC DHCP server (transitional package) isc-dhcp-client - ISC DHCP client isc-dhcp-client-dbg - ISC DHCP client (debugging symbols) isc-dhcp-client-udeb - ISC DHCP Client for debian-installer (udeb) isc-dhcp-common - common files used by all the isc-dhcp* packages isc-dhcp-dev - API for accessing and modifying the DHCP server and client state isc-dhcp-relay - ISC DHCP relay daemon isc-dhcp-relay-dbg - DHCP relay daemon (debugging symbols) isc-dhcp-server - ISC DHCP server for automatic IP address assignment isc-dhcp-server-dbg - ISC DHCP server for automatic IP address assignment (debug) isc-dhcp-server-ldap - DHCP server able to use LDAP as backend Changes: isc-dhcp (4.1.1-P1-15ubuntu9.4) natty-security; urgency=low . * SECURITY UPDATE: denial of service via malformed client identifiers - debian/patches/CVE-2012-3571.dpatch: validate packets in common/options.{c,h}. - CVE-2012-3571.dpatch * SECURITY UPDATE: denial of service via memory leaks - debian/patches/CVE-2012-3954.dpatch: properly manage memory in common/options.c and server/dhcpv6.c. - CVE-2012-3954 Checksums-Sha1: 38ddb51111e03f37f7168f30c2baa62c89f6a85b 2348 isc-dhcp_4.1.1-P1-15ubuntu9.4.dsc 127df1f4774a35ebc34073f1dc81fd2516c040ad 154368 isc-dhcp_4.1.1-P1-15ubuntu9.4.diff.gz Checksums-Sha256: 564483517ee9a2067f05ab9f97e290cf0822eb3365288584aac72e658f9d1e3d 2348 isc-dhcp_4.1.1-P1-15ubuntu9.4.dsc 5697f061a7cafc7b1013ed300a877d1711d96dfebfbe40c1daeb44b6a592f6f9 154368 isc-dhcp_4.1.1-P1-15ubuntu9.4.diff.gz Files: 431ace35c8fe80ec3918e650cc1de3c1 2348 net important isc-dhcp_4.1.1-P1-15ubuntu9.4.dsc a08c62aafc08749d7d4ed9f0fdcbe928 154368 net important isc-dhcp_4.1.1-P1-15ubuntu9.4.diff.gz Original-Maintainer: Debian ISC DHCP maintainers From brad.figg at canonical.com Fri Jul 27 19:37:26 2012 From: brad.figg at canonical.com (Brad Figg) Date: Fri, 27 Jul 2012 19:37:26 -0000 Subject: [ubuntu/natty-proposed] linux 2.6.38-15.65 (Accepted) Message-ID: <20120727193726.26714.68960.launchpad@ackee.canonical.com> linux (2.6.38-15.65) natty-proposed; urgency=low [Luis Henriques] * Release Tracking Bug - LP: #1027821 [ Andy Whitcroft ] * SAUCE: rds_ib_send() -- prevent local pings triggering BUG_ON() - LP: #1016299 - CVE-2012-2372 [ Upstream Kernel Changes ] * hugetlb: fix resv_map leak in error path - LP: #1004621 - CVE-2012-2390 * mm: fix vma_resv_map() NULL pointer - LP: #1004621 - CVE-2012-2390 * net: sock: validate data_len before allocating skb in sock_alloc_send_pskb() - LP: #1006622 - CVE-2012-2136 Date: 2012-07-26 20:10:38.186781+00:00 Changed-By: Luis Henriques Signed-By: Brad Figg https://launchpad.net/ubuntu/natty/+source/linux/2.6.38-15.65 -------------- next part -------------- Sorry, changesfile not available. From steve.langasek at ubuntu.com Sat Jul 28 19:42:17 2012 From: steve.langasek at ubuntu.com (Steve Langasek) Date: Sat, 28 Jul 2012 19:42:17 -0000 Subject: [ubuntu/natty] skype 4.0.0.7-0natty1 (Accepted) Message-ID: <20120728194217.24476.99806.launchpad@cocoplum.canonical.com> skype (4.0.0.7-0natty1) natty; urgency=low * New upstream release * Update debian/copyright with the current EULA, and adjust debian/rules to ensure it remains up to date in the future. skype (2.2.0.35-0precise3) precise; urgency=low * Add a Recommends on libasound2-plugins, so that the necessary audio support is pulled in when installing on amd64. LP: #968302. skype (2.2.0.35-0oneiric2) oneiric; urgency=low * Added sni-qt as a Recommends for tray icon support Date: Mon, 18 Jun 2012 11:52:44 -0700 Changed-By: Steve Langasek Maintainer: Brian Thomason https://launchpad.net/ubuntu/natty/+source/skype/4.0.0.7-0natty1 -------------- next part -------------- Format: 1.8 Date: Mon, 18 Jun 2012 11:52:44 -0700 Source: skype Binary: skype Architecture: source Version: 4.0.0.7-0natty1 Distribution: natty Urgency: low Maintainer: Brian Thomason Changed-By: Steve Langasek Description: skype - VOIP and instant messaging client Launchpad-Bugs-Fixed: 968302 Changes: skype (4.0.0.7-0natty1) natty; urgency=low . * New upstream release * Update debian/copyright with the current EULA, and adjust debian/rules to ensure it remains up to date in the future. . skype (2.2.0.35-0precise3) precise; urgency=low . * Add a Recommends on libasound2-plugins, so that the necessary audio support is pulled in when installing on amd64. LP: #968302. . skype (2.2.0.35-0oneiric2) oneiric; urgency=low . * Added sni-qt as a Recommends for tray icon support Checksums-Sha1: 2b7b7190858c5a6515e03653da7cbf768f48db88 1817 skype_4.0.0.7-0natty1.dsc ee8fc5be0eb14b2f85b062b38b3bb4c639ba6489 29341277 skype_4.0.0.7.orig.tar.gz 78303a636dbb71e9d7139d67942c783681c27229 2421 skype_4.0.0.7-0natty1.diff.gz Checksums-Sha256: d21c36a40bf4dcf932b0cbbd69859281e68daf067acf5a0b41d58330e81888ed 1817 skype_4.0.0.7-0natty1.dsc ce30361ef6d016e4407658d9ab27d4d3fa001dcebffbb074b6941a6a4a870a8e 29341277 skype_4.0.0.7.orig.tar.gz f19186e81f2aee6a32552c478fd4be3667d831dfe543c3d79452ebb64cfe21bb 2421 skype_4.0.0.7-0natty1.diff.gz Files: ac3f677356165c54ee8465666a640edc 1817 partner/net extra skype_4.0.0.7-0natty1.dsc fa5f01e89fb5adeae7cd80a67d8e09a8 29341277 partner/net extra skype_4.0.0.7.orig.tar.gz c3a8893aae27d1bcc663ec8838c679b3 2421 partner/net extra skype_4.0.0.7-0natty1.diff.gz From chris.coulson at canonical.com Mon Jul 30 16:28:47 2012 From: chris.coulson at canonical.com (Chris Coulson) Date: Mon, 30 Jul 2012 16:28:47 -0000 Subject: [ubuntu/natty-proposed] firefox 14.0.1+build1-0ubuntu0.11.04.2 (Accepted) Message-ID: <20120730162847.11827.51314.launchpad@wampee.canonical.com> firefox (14.0.1+build1-0ubuntu0.11.04.2) natty-proposed; urgency=low * Update globalmenu-extension to 3.2.6 - Partial fix for LP: #1025011 - HUD search crashes Firefox when Firebug is installed. Make all menu nodes reference counted, and hold a strong ref when dispatching events, in case the event results in the removal of the target node. This fixes the crash, although the Firebug submenus may flicker or display duplicated entries Date: Thu, 26 Jul 2012 19:30:08 +0100 Changed-By: Chris Coulson Maintainer: Ubuntu Mozilla Team https://launchpad.net/ubuntu/natty/+source/firefox/14.0.1+build1-0ubuntu0.11.04.2 -------------- next part -------------- Format: 1.8 Date: Thu, 26 Jul 2012 19:30:08 +0100 Source: firefox Binary: firefox firefox-gnome-support firefox-dbg firefox-dev firefox-mozsymbols firefox-globalmenu abrowser firefox-branding abrowser-branding firefox-gnome-support-dbg firefox-locale-af firefox-locale-ar firefox-locale-as firefox-locale-ast firefox-locale-be firefox-locale-bg firefox-locale-bn firefox-locale-br firefox-locale-bs firefox-locale-ca firefox-locale-cs firefox-locale-csb firefox-locale-cy firefox-locale-da firefox-locale-de firefox-locale-el firefox-locale-en firefox-locale-eo firefox-locale-es firefox-locale-et firefox-locale-eu firefox-locale-fa firefox-locale-fi firefox-locale-fr firefox-locale-fy firefox-locale-ga firefox-locale-gd firefox-locale-gl firefox-locale-gu firefox-locale-he firefox-locale-hi firefox-locale-hr firefox-locale-hu firefox-locale-hy firefox-locale-id firefox-locale-is firefox-locale-it firefox-locale-ja firefox-locale-ka firefox-locale-kk firefox-locale-km firefox-locale-kn firefox-locale-ko firefox-locale-ku firefox-locale-lg firefox-locale-lt firefox-locale-lv firefox-locale-mai firefox-locale-mk firefox-locale-ml firefox-locale-mn firefox-locale-mr firefox-locale-nb firefox-locale-nl firefox-locale-nn firefox-locale-nso firefox-locale-oc firefox-locale-or firefox-locale-pa firefox-locale-pl firefox-locale-pt firefox-locale-ro firefox-locale-ru firefox-locale-si firefox-locale-sk firefox-locale-sl firefox-locale-sq firefox-locale-sr firefox-locale-sv firefox-locale-sw firefox-locale-ta firefox-locale-te firefox-locale-th firefox-locale-tr firefox-locale-uk firefox-locale-vi firefox-locale-zh-hans firefox-locale-zh-hant firefox-locale-zu Architecture: source Version: 14.0.1+build1-0ubuntu0.11.04.2 Distribution: natty-proposed Urgency: low Maintainer: Ubuntu Mozilla Team Changed-By: Chris Coulson Description: abrowser - Safe and easy web browser from Mozilla - transitional package abrowser-branding - Safe and easy web browser from Mozilla - transitional package firefox - Safe and easy web browser from Mozilla firefox-branding - Safe and easy web browser from Mozilla - transitional package firefox-dbg - Safe and easy web browser from Mozilla - debug symbols firefox-dev - Safe and easy web browser from Mozilla - development files firefox-globalmenu - Unity appmenu integration for Firefox firefox-gnome-support - Safe and easy web browser from Mozilla - GNOME support firefox-gnome-support-dbg - Safe and easy web browser from Mozilla - transitional package firefox-locale-af - Afrikaans language pack for Firefox firefox-locale-ar - Arabic language pack for Firefox firefox-locale-as - Assamese language pack for Firefox firefox-locale-ast - Asturian language pack for Firefox firefox-locale-be - Belarusian language pack for Firefox firefox-locale-bg - Bulgarian language pack for Firefox firefox-locale-bn - Bengali language pack for Firefox firefox-locale-br - Breton language pack for Firefox firefox-locale-bs - Bosnian language pack for Firefox firefox-locale-ca - Catalan; Valencian language pack for Firefox firefox-locale-cs - Czech language pack for Firefox firefox-locale-csb - Kashubian language pack for Firefox firefox-locale-cy - Welsh language pack for Firefox firefox-locale-da - Danish language pack for Firefox firefox-locale-de - German language pack for Firefox firefox-locale-el - Greek language pack for Firefox firefox-locale-en - English language pack for Firefox firefox-locale-eo - Esperanto language pack for Firefox firefox-locale-es - Spanish; Castilian language pack for Firefox firefox-locale-et - Estonian language pack for Firefox firefox-locale-eu - Basque language pack for Firefox firefox-locale-fa - Persian language pack for Firefox firefox-locale-fi - Finnish language pack for Firefox firefox-locale-fr - French language pack for Firefox firefox-locale-fy - Western Frisian language pack for Firefox firefox-locale-ga - Irish language pack for Firefox firefox-locale-gd - Gaelic; Scottish Gaelic language pack for Firefox firefox-locale-gl - Galician language pack for Firefox firefox-locale-gu - Gujarati language pack for Firefox firefox-locale-he - Hebrew language pack for Firefox firefox-locale-hi - Hindi language pack for Firefox firefox-locale-hr - Croatian language pack for Firefox firefox-locale-hu - Hungarian language pack for Firefox firefox-locale-hy - Armenian language pack for Firefox firefox-locale-id - Indonesian language pack for Firefox firefox-locale-is - Icelandic language pack for Firefox firefox-locale-it - Italian language pack for Firefox firefox-locale-ja - Japanese language pack for Firefox firefox-locale-ka - Transitional package for unavailable language firefox-locale-kk - Kazakh language pack for Firefox firefox-locale-km - Central Khmer language pack for Firefox firefox-locale-kn - Kannada language pack for Firefox firefox-locale-ko - Korean language pack for Firefox firefox-locale-ku - Kurdish language pack for Firefox firefox-locale-lg - Ganda language pack for Firefox firefox-locale-lt - Lithuanian language pack for Firefox firefox-locale-lv - Latvian language pack for Firefox firefox-locale-mai - Maithili language pack for Firefox firefox-locale-mk - Macedonian language pack for Firefox firefox-locale-ml - Malayalam language pack for Firefox firefox-locale-mn - Transitional package for unavailable language firefox-locale-mr - Marathi language pack for Firefox firefox-locale-nb - Bokmål, Norwegian; Norwegian Bokmål language pack for Firefox firefox-locale-nl - Dutch; Flemish language pack for Firefox firefox-locale-nn - Norwegian Nynorsk; Nynorsk, Norwegian language pack for Firefox firefox-locale-nso - Sotho, Northern language pack for Firefox firefox-locale-oc - Transitional package for unavailable language firefox-locale-or - Oriya language pack for Firefox firefox-locale-pa - Panjabi; Punjabi language pack for Firefox firefox-locale-pl - Polish language pack for Firefox firefox-locale-pt - Portuguese language pack for Firefox firefox-locale-ro - Romanian language pack for Firefox firefox-locale-ru - Russian language pack for Firefox firefox-locale-si - Sinhala; Sinhalese language pack for Firefox firefox-locale-sk - Slovak language pack for Firefox firefox-locale-sl - Slovenian language pack for Firefox firefox-locale-sq - Albanian language pack for Firefox firefox-locale-sr - Serbian language pack for Firefox firefox-locale-sv - Swedish language pack for Firefox firefox-locale-sw - Transitional package for unavailable language firefox-locale-ta - Tamil language pack for Firefox firefox-locale-te - Telugu language pack for Firefox firefox-locale-th - Thai language pack for Firefox firefox-locale-tr - Turkish language pack for Firefox firefox-locale-uk - Ukrainian language pack for Firefox firefox-locale-vi - Vietnamese language pack for Firefox firefox-locale-zh-hans - Simplified Chinese language pack for Firefox firefox-locale-zh-hant - Traditional Chinese language pack for Firefox firefox-locale-zu - Zulu language pack for Firefox firefox-mozsymbols - Safe and easy web browser from Mozilla - Breakpad symbols Launchpad-Bugs-Fixed: 1025011 Changes: firefox (14.0.1+build1-0ubuntu0.11.04.2) natty-proposed; urgency=low . * Update globalmenu-extension to 3.2.6 - Partial fix for LP: #1025011 - HUD search crashes Firefox when Firebug is installed. Make all menu nodes reference counted, and hold a strong ref when dispatching events, in case the event results in the removal of the target node. This fixes the crash, although the Firebug submenus may flicker or display duplicated entries Checksums-Sha1: 3c94ae17012e142776df92353b2602118da4fbe2 6903 firefox_14.0.1+build1-0ubuntu0.11.04.2.dsc cdddccf73dbd2c841eac468e9bde7b7d8bd4c9fa 270155 firefox_14.0.1+build1-0ubuntu0.11.04.2.diff.gz Checksums-Sha256: 9eeb42dc9dbd0094085081cd1c473a5ade2b75039c7fe50a256aeddbb4198934 6903 firefox_14.0.1+build1-0ubuntu0.11.04.2.dsc 6b8680df91fc6fefa5ce12d91da8804d4ace926298c627282986bdc7c381ed97 270155 firefox_14.0.1+build1-0ubuntu0.11.04.2.diff.gz Files: cf0faa3df9a743111d6348718d49ec28 6903 web optional firefox_14.0.1+build1-0ubuntu0.11.04.2.dsc c8e783a85a4948e76e9d850f9e00285c 270155 web optional firefox_14.0.1+build1-0ubuntu0.11.04.2.diff.gz From steve.langasek at canonical.com Mon Jul 30 22:36:11 2012 From: steve.langasek at canonical.com (Steve Langasek) Date: Mon, 30 Jul 2012 22:36:11 -0000 Subject: [ubuntu/natty] skype 4.0.0.8-0lucid1 (Accepted) Message-ID: <20120730223611.10461.80624.launchpad@ackee.canonical.com> skype (4.0.0.8-0lucid1) lucid; urgency=low * New upstream release. Date: 2012-07-30 21:15:18.001797+00:00 Changed-By: Steve Langasek Maintainer: Brian Thomason https://launchpad.net/ubuntu/natty/+source/skype/4.0.0.8-0lucid1 -------------- next part -------------- Sorry, changesfile not available. From herton.krzesinski at canonical.com Tue Jul 31 03:09:12 2012 From: herton.krzesinski at canonical.com (Herton R. Krzesinski) Date: Tue, 31 Jul 2012 03:09:12 -0000 Subject: [ubuntu/natty-proposed] linux-ti-omap4 2.6.38-1209.25 (Accepted) Message-ID: <20120731030912.26112.9027.launchpad@ackee.canonical.com> linux-ti-omap4 (2.6.38-1209.25) natty-proposed; urgency=low * Release Tracking Bug - LP: #1029784 [ Andy Whitcroft ] * SAUCE: rds_ib_send() -- prevent local pings triggering BUG_ON() - LP: #1016299 - CVE-2012-2372 [ Upstream Kernel Changes ] * fcaps: clear the same personality flags as suid when fcaps are used - LP: #987571 - CVE-2012-2123 * security: fix compile error in commoncap.c - LP: #987571 - CVE-2012-2123 * net: sock: validate data_len before allocating skb in sock_alloc_send_pskb() - LP: #1006622 - CVE-2012-2136 * dl2k: Clean up rio_ioctl - CVE-2012-2313 * hfsplus: Fix potential buffer overflows - CVE-2012-2319 * nfs: don't lose MS_SYNCHRONOUS on remount of noac mount - LP: #775809 * NFSv4.1: Ensure state manager thread dies on last umount - LP: #775809 * NFSv4: Handle expired stateids when the lease is still valid - LP: #793702 * NFSv4.1: Fix the handling of NFS4ERR_SEQ_MISORDERED errors - LP: #793702 * NFSv4: include bitmap in nfsv4 get acl data - LP: #893147 - CVE-2011-4131 * Avoid reading past buffer when calling GETACL - LP: #1002505 - CVE-2012-2375 * Avoid beyond bounds copy while caching ACL - LP: #1002505 - CVE-2012-2375 * Fix length of buffer copied in __nfs4_get_acl_uncached - LP: #1002505 - CVE-2012-2375 Date: 2012-07-30 17:11:14.911652+00:00 Changed-By: Paolo Pisati Signed-By: "Herton R. Krzesinski" https://launchpad.net/ubuntu/natty/+source/linux-ti-omap4/2.6.38-1209.25 -------------- next part -------------- Sorry, changesfile not available. From sbeattie at ubuntu.com Tue Jul 31 18:34:41 2012 From: sbeattie at ubuntu.com (Steve Beattie) Date: Tue, 31 Jul 2012 18:34:41 -0000 Subject: [ubuntu/natty-security] krb5, krb5_1.8.3+dfsg-5ubuntu2.3_armel_translations.tar.gz, krb5_1.8.3+dfsg-5ubuntu2.3_powerpc_translations.tar.gz, krb5_1.8.3+dfsg-5ubuntu2.3_amd64_translations.tar.gz, krb5_1.8.3+dfsg-5ubuntu2.3_i386_translations.tar.gz 1.8.3+dfsg-5ubuntu2.3 (Accepted) Message-ID: <20120731183441.7188.86532.launchpad@cocoplum.canonical.com> krb5 (1.8.3+dfsg-5ubuntu2.3) natty-security; urgency=low * SECURITY UPDATE: KDC heap corruption and crash vulnerabilities - src/kdc/kdc_preauth.c, src/kdc/kdc_util.c, src/lib/kdb/kdb_default.c: initialize pointers both at allocation and assignment time - CVE-2012-1015 * SECURITY UPDATE: denial of service in kadmind (LP: #1009422) - src/lib/kadm5/srv/svr_principal.c: check for null password - CVE-2012-1013 Date: Mon, 23 Jul 2012 22:15:03 -0700 Changed-By: Steve Beattie Maintainer: Ubuntu Developers https://launchpad.net/ubuntu/natty/+source/krb5/1.8.3+dfsg-5ubuntu2.3 -------------- next part -------------- Format: 1.8 Date: Mon, 23 Jul 2012 22:15:03 -0700 Source: krb5 Binary: krb5-user krb5-kdc krb5-kdc-ldap krb5-admin-server krb5-multidev libkrb5-dev libkrb5-dbg krb5-pkinit krb5-doc libkrb5-3 libgssapi-krb5-2 libgssrpc4 libkadm5srv-mit7 libkadm5clnt-mit7 libk5crypto3 libkdb5-4 libkrb5support0 libkrb53 Architecture: source Version: 1.8.3+dfsg-5ubuntu2.3 Distribution: natty-security Urgency: low Maintainer: Ubuntu Developers Changed-By: Steve Beattie Description: krb5-admin-server - MIT Kerberos master server (kadmind) krb5-doc - Documentation for MIT Kerberos krb5-kdc - MIT Kerberos key server (KDC) krb5-kdc-ldap - MIT Kerberos key server (KDC) LDAP plugin krb5-multidev - Development files for MIT Kerberos without Heimdal conflict krb5-pkinit - PKINIT plugin for MIT Kerberos krb5-user - Basic programs to authenticate using MIT Kerberos libgssapi-krb5-2 - MIT Kerberos runtime libraries - krb5 GSS-API Mechanism libgssrpc4 - MIT Kerberos runtime libraries - GSS enabled ONCRPC libk5crypto3 - MIT Kerberos runtime libraries - Crypto Library libkadm5clnt-mit7 - MIT Kerberos runtime libraries - Administration Clients libkadm5srv-mit7 - MIT Kerberos runtime libraries - KDC and Admin Server libkdb5-4 - MIT Kerberos runtime libraries - Kerberos database libkrb5-3 - MIT Kerberos runtime libraries libkrb5-dbg - Debugging files for MIT Kerberos libkrb5-dev - Headers and development libraries for MIT Kerberos libkrb53 - transitional package for MIT Kerberos libraries libkrb5support0 - MIT Kerberos runtime libraries - Support library Launchpad-Bugs-Fixed: 1009422 Changes: krb5 (1.8.3+dfsg-5ubuntu2.3) natty-security; urgency=low . * SECURITY UPDATE: KDC heap corruption and crash vulnerabilities - src/kdc/kdc_preauth.c, src/kdc/kdc_util.c, src/lib/kdb/kdb_default.c: initialize pointers both at allocation and assignment time - CVE-2012-1015 * SECURITY UPDATE: denial of service in kadmind (LP: #1009422) - src/lib/kadm5/srv/svr_principal.c: check for null password - CVE-2012-1013 Checksums-Sha1: 33f3913b6e882645137099a477a9eaf32c2b2c0c 2344 krb5_1.8.3+dfsg-5ubuntu2.3.dsc d25c129a70ab1e5ad7d332e1697e7a99ff22bb86 111903 krb5_1.8.3+dfsg-5ubuntu2.3.diff.gz Checksums-Sha256: 268e684e46382e9d8003624bc25c944a6b834e877430a130cd3f9c8cb2174b19 2344 krb5_1.8.3+dfsg-5ubuntu2.3.dsc da3451670f1eda273cc6a18a04c9d74621696c00e813fac1466dc41c89a92ea5 111903 krb5_1.8.3+dfsg-5ubuntu2.3.diff.gz Files: 7e3bfeb9a921938a34af85dec83813de 2344 net standard krb5_1.8.3+dfsg-5ubuntu2.3.dsc 4ed909284698b3992bd98e6aa1061547 111903 net standard krb5_1.8.3+dfsg-5ubuntu2.3.diff.gz Original-Maintainer: Sam Hartman From sbeattie at ubuntu.com Tue Jul 31 22:03:35 2012 From: sbeattie at ubuntu.com (Steve Beattie) Date: Tue, 31 Jul 2012 22:03:35 -0000 Subject: [ubuntu/natty-security] icedtea-web 1.2-2ubuntu0.11.04.2 (Accepted) Message-ID: <20120731220335.30833.23157.launchpad@cocoplum.canonical.com> icedtea-web (1.2-2ubuntu0.11.04.2) natty-security; urgency=low * SECURITY UPDATE: uninitialized pointer use flaw - debian/patches/icedtea-web-CVE-2012-3422.patch: check for empty instance_to_id_map hash and return error if so. - CVE-2012-3422 * SECURITY UPDATE: incorrect handling of non NULL terminated strings - debian/patches/icedtea-web-CVE-2012-3423.patch: ensure NPVariant NPStrings are NULL terminated. - CVE-2012-3423 Date: Sat, 28 Jul 2012 19:30:09 -0700 Changed-By: Steve Beattie Maintainer: Ubuntu Developers https://launchpad.net/ubuntu/natty/+source/icedtea-web/1.2-2ubuntu0.11.04.2 -------------- next part -------------- Format: 1.8 Date: Sat, 28 Jul 2012 19:30:09 -0700 Source: icedtea-web Binary: icedtea-netx icedtea6-plugin icedtea-plugin icedtea-6-plugin Architecture: source Version: 1.2-2ubuntu0.11.04.2 Distribution: natty-security Urgency: low Maintainer: Ubuntu Developers Changed-By: Steve Beattie Description: icedtea-6-plugin - web browser plugin based on OpenJDK and IcedTea to execute Java a icedtea-netx - NetX - implementation of the Java Network Launching Protocol (JNL icedtea-plugin - web browser plugin to execute Java applets (dependency package) icedtea6-plugin - web browser plugin to execute Java applets (dependency package) Changes: icedtea-web (1.2-2ubuntu0.11.04.2) natty-security; urgency=low . * SECURITY UPDATE: uninitialized pointer use flaw - debian/patches/icedtea-web-CVE-2012-3422.patch: check for empty instance_to_id_map hash and return error if so. - CVE-2012-3422 * SECURITY UPDATE: incorrect handling of non NULL terminated strings - debian/patches/icedtea-web-CVE-2012-3423.patch: ensure NPVariant NPStrings are NULL terminated. - CVE-2012-3423 Checksums-Sha1: c6ba7b39d7b65ac257ccc6ab58e15b4472e45856 2218 icedtea-web_1.2-2ubuntu0.11.04.2.dsc d71a97a61fcc0cae60425906b4367b0eace9b07b 25233 icedtea-web_1.2-2ubuntu0.11.04.2.debian.tar.gz Checksums-Sha256: dbe8e0b1fe1348a4cc1a07661abfcd829c24614608fc401d18b2b4e2050d1c77 2218 icedtea-web_1.2-2ubuntu0.11.04.2.dsc 8f5457effd4306f178e808eaf3bbc61dac692d4d1140e4032e6f12d9dc92b747 25233 icedtea-web_1.2-2ubuntu0.11.04.2.debian.tar.gz Files: 317549124b46169d22512452f5c6e1dc 2218 java extra icedtea-web_1.2-2ubuntu0.11.04.2.dsc 6e805d211fe2df771758672232698765 25233 java extra icedtea-web_1.2-2ubuntu0.11.04.2.debian.tar.gz Original-Maintainer: OpenJDK Team