From stgraber at ubuntu.com Fri Jun 1 00:13:00 2012 From: stgraber at ubuntu.com (Stephane Graber) Date: Fri, 01 Jun 2012 00:13:00 -0000 Subject: [ubuntu/natty-proposed] pastebinit 1.2-2ubuntu0.11.04.1 (Accepted) Message-ID: <20120601001300.18748.33765.launchpad@chaenomeles.canonical.com> pastebinit (1.2-2ubuntu0.11.04.1) natty-proposed; urgency=low * Cherry-pick new pastebin.com.conf file from pastebinit 1.3.1, this switches to the new pastebin.com API (now mandatory) (LP: #996242) Date: Wed, 30 May 2012 10:07:21 -0400 Changed-By: Stéphane Graber Maintainer: Ubuntu Developers https://launchpad.net/ubuntu/natty/+source/pastebinit/1.2-2ubuntu0.11.04.1 -------------- next part -------------- Format: 1.8 Date: Wed, 30 May 2012 10:07:21 -0400 Source: pastebinit Binary: pastebinit Architecture: source Version: 1.2-2ubuntu0.11.04.1 Distribution: natty-proposed Urgency: low Maintainer: Ubuntu Developers Changed-By: Stéphane Graber Description: pastebinit - command-line pastebin client Launchpad-Bugs-Fixed: 996242 Changes: pastebinit (1.2-2ubuntu0.11.04.1) natty-proposed; urgency=low . * Cherry-pick new pastebin.com.conf file from pastebinit 1.3.1, this switches to the new pastebin.com API (now mandatory) (LP: #996242) Checksums-Sha1: 9198057ab723757b11d6b243dda37ad7399d1d15 2105 pastebinit_1.2-2ubuntu0.11.04.1.dsc 61c8957b7afb66f47bcc56444e113730d3dc9bc4 5427 pastebinit_1.2-2ubuntu0.11.04.1.debian.tar.gz Checksums-Sha256: 7ded14facaddcfcb0dec752ff0ba87b727f7ef79231161ba08a496bb07576dc3 2105 pastebinit_1.2-2ubuntu0.11.04.1.dsc 4fb451085745a0103f2f5ae6568c752867648c9b0929e9615c39a5418c5139b2 5427 pastebinit_1.2-2ubuntu0.11.04.1.debian.tar.gz Files: 954b3a00b45770b2a249eaf64a846ce9 2105 misc optional pastebinit_1.2-2ubuntu0.11.04.1.dsc fa7aeaab90d8cc7f466614f8d0748532 5427 misc optional pastebinit_1.2-2ubuntu0.11.04.1.debian.tar.gz Original-Maintainer: Rolf Leggewie From marc.deslauriers at ubuntu.com Mon Jun 4 13:35:10 2012 From: marc.deslauriers at ubuntu.com (Marc Deslauriers) Date: Mon, 04 Jun 2012 13:35:10 -0000 Subject: [ubuntu/natty-security] update-manager_0.150.5.4_i386_translations.tar.gz, update-manager, update-manager_0.150.5.4_powerpc_translations.tar.gz, dist-upgrader_0.150.5.4_all.tar.gz, update-manager_0.150.5.4_armel_translations.tar.gz, update-manager_0.150.5.4_amd64_translations.tar.gz 1:0.150.5.4 (Accepted) Message-ID: <20120604133510.16227.35025.launchpad@cocoplum.canonical.com> update-manager (1:0.150.5.4) natty-security; urgency=low * SECURITY UPDATE: Incomplete fix for CVE-2012-0949 (LP: #1004503) - DistUpgrade/DistUpgradeApport.py: use a whitelist of files so we don't upload system_state archives. - tests/test_apport_crash.py: add test. - CVE-2012-0950 Date: Thu, 31 May 2012 13:10:34 -0400 Changed-By: Marc Deslauriers Maintainer: Michael Vogt https://launchpad.net/ubuntu/natty/+source/update-manager/1:0.150.5.4 -------------- next part -------------- Format: 1.8 Date: Thu, 31 May 2012 13:10:34 -0400 Source: update-manager Binary: update-manager-core update-manager update-manager-text update-manager-kde auto-upgrade-tester Architecture: source Version: 1:0.150.5.4 Distribution: natty-security Urgency: low Maintainer: Michael Vogt Changed-By: Marc Deslauriers Description: auto-upgrade-tester - Test release upgrades in a virtual environment update-manager - GNOME application that manages apt updates update-manager-core - manage release upgrades update-manager-kde - Support modules for KPackageKit update-manager-text - Text application that manages apt updates Launchpad-Bugs-Fixed: 1004503 Changes: update-manager (1:0.150.5.4) natty-security; urgency=low . * SECURITY UPDATE: Incomplete fix for CVE-2012-0949 (LP: #1004503) - DistUpgrade/DistUpgradeApport.py: use a whitelist of files so we don't upload system_state archives. - tests/test_apport_crash.py: add test. - CVE-2012-0950 Checksums-Sha1: 415eccb81b2e3abbc024a05ab7c1fcb197513fdc 1781 update-manager_0.150.5.4.dsc 9236a916e40d0faa18b3fca0c6f9a226f84dffb9 2941251 update-manager_0.150.5.4.tar.gz Checksums-Sha256: 002c945206f0648a0afc142021894540aa6b3d9b2c12c7f0060a09177a86fa5c 1781 update-manager_0.150.5.4.dsc efff9f5827a963bc8e7adefc67ffbfd688196ec006aaf061b32f3b520ecb43ae 2941251 update-manager_0.150.5.4.tar.gz Files: 18108737dc224f32e564bb5e1aa020bd 1781 gnome optional update-manager_0.150.5.4.dsc 3b8984d441008836167facf15af36d21 2941251 gnome optional update-manager_0.150.5.4.tar.gz From jamie at ubuntu.com Mon Jun 4 17:34:19 2012 From: jamie at ubuntu.com (Jamie Strandboge) Date: Mon, 04 Jun 2012 17:34:19 -0000 Subject: [ubuntu/natty-security] arpwatch 2.1a15-1.1+squeeze1build0.11.04.1 (Accepted) Message-ID: <20120604173419.23369.54406.launchpad@cocoplum.canonical.com> arpwatch (2.1a15-1.1+squeeze1build0.11.04.1) natty-security; urgency=low * fake sync from Debian arpwatch (2.1a15-1.1+squeeze1) stable-security; urgency=high * Non-maintainer upload by the Security Team. * Fix initgroups() adding the gid 0 group to the list. Instead of dropping privileges it was in fact adding it. This is CVE-2012-2653. closes: #674715 Date: Mon, 04 Jun 2012 08:25:36 -0500 Changed-By: Jamie Strandboge Maintainer: KELEMEN Péter https://launchpad.net/ubuntu/natty/+source/arpwatch/2.1a15-1.1+squeeze1build0.11.04.1 -------------- next part -------------- Format: 1.8 Date: Mon, 04 Jun 2012 08:25:36 -0500 Source: arpwatch Binary: arpwatch Architecture: source Version: 2.1a15-1.1+squeeze1build0.11.04.1 Distribution: natty-security Urgency: high Maintainer: KELEMEN Péter Changed-By: Jamie Strandboge Description: arpwatch - Ethernet/FDDI station activity monitor Closes: 674715 Changes: arpwatch (2.1a15-1.1+squeeze1build0.11.04.1) natty-security; urgency=low . * fake sync from Debian . arpwatch (2.1a15-1.1+squeeze1) stable-security; urgency=high . * Non-maintainer upload by the Security Team. * Fix initgroups() adding the gid 0 group to the list. Instead of dropping privileges it was in fact adding it. This is CVE-2012-2653. closes: #674715 Checksums-Sha1: cc3468b5b32b61b40b80c31504c7734682bc7425 1762 arpwatch_2.1a15-1.1+squeeze1build0.11.04.1.dsc e507b7884c2dc7d84b3d54deb54b029994157e57 150028 arpwatch_2.1a15-1.1+squeeze1build0.11.04.1.diff.gz Checksums-Sha256: d62398d215f86505319fed75f428fccde0c6698de3d4c66a3a6f1ae6ee5f70ad 1762 arpwatch_2.1a15-1.1+squeeze1build0.11.04.1.dsc 993607af377c7887457370a462267f08aff7bd0763b0867a26b20a7a44ffacc2 150028 arpwatch_2.1a15-1.1+squeeze1build0.11.04.1.diff.gz Files: d31862a1b4ee1161939125385bf6c930 1762 admin optional arpwatch_2.1a15-1.1+squeeze1build0.11.04.1.dsc 79a3c3b54d57f9eb70ae57f894641d55 150028 admin optional arpwatch_2.1a15-1.1+squeeze1build0.11.04.1.diff.gz From martin.pitt at ubuntu.com Tue Jun 5 14:39:10 2012 From: martin.pitt at ubuntu.com (Martin Pitt) Date: Tue, 05 Jun 2012 14:39:10 -0000 Subject: [ubuntu/natty-security] postgresql-8.4_8.4.12-0ubuntu11.04_powerpc_translations.tar.gz, postgresql-8.4, postgresql-8.4_8.4.12-0ubuntu11.04_armel_translations.tar.gz, postgresql-8.4_8.4.12-0ubuntu11.04_i386_translations.tar.gz, postgresql-8.4_8.4.12-0ubuntu11.04_amd64_translations.tar.gz 8.4.12-0ubuntu11.04 (Accepted) Message-ID: <20120605143910.8153.91606.launchpad@cocoplum.canonical.com> postgresql-8.4 (8.4.12-0ubuntu11.04) natty-security; urgency=low * New upstream security/bug fix release: (LP: #1008317) - Fix incorrect password transformation in "contrib/pgcrypto"'s DES crypt() function. If a password string contained the byte value 0x80, the remainder of the password was ignored, causing the password to be much weaker than it appeared. With this fix, the rest of the string is properly included in the DES hash. Any stored password values that are affected by this bug will thus no longer match, so the stored values may need to be updated. (CVE-2012-2143) - Ignore SECURITY DEFINER and SET attributes for a procedural language's call handler. Applying such attributes to a call handler could crash the server. (CVE-2012-2655) - Allow numeric timezone offsets in timestamp input to be up to 16 hours away from UTC. Some historical time zones have offsets larger than 15 hours, the previous limit. This could result in dumped data values being rejected during reload. - Fix timestamp conversion to cope when the given time is exactly the last DST transition time for the current timezone. This oversight has been there a long time, but was not noticed previously because most DST-using zones are presumed to have an indefinite sequence of future DST transitions. - Fix text to name and char to name casts to perform string truncation correctly in multibyte encodings. - Fix memory copying bug in to_tsquery(). - Fix planner's handling of outer PlaceHolderVars within subqueries. This bug concerns sub-SELECTs that reference variables coming from the nullable side of an outer join of the surrounding query. In 9.1, queries affected by this bug would fail with "ERROR: Upper-level PlaceHolderVar found where not expected". But in 9.0 and 8.4, you'd silently get possibly-wrong answers, since the value transmitted into the subquery wouldn't go to null when it should. - Fix slow session startup when pg_attribute is very large. If pg_attribute exceeds one-fourth of shared_buffers, cache rebuilding code that is sometimes needed during session start would trigger the synchronized-scan logic, causing it to take many times longer than normal. The problem was particularly acute if many new sessions were starting at once. - Ensure sequential scans check for query cancel reasonably often. A scan encountering many consecutive pages that contain no live tuples would not respond to interrupts meanwhile. - Ensure the Windows implementation of PGSemaphoreLock() clears ImmediateInterruptOK before returning. This oversight meant that a query-cancel interrupt received later in the same query could be accepted at an unsafe time, with unpredictable but not good consequences. - Show whole-row variables safely when printing views or rules. Corner cases involving ambiguous names (that is, the name could be either a table or column name of the query) were printed in an ambiguous way, risking that the view or rule would be interpreted differently after dump and reload. Avoid the ambiguous case by attaching a no-op cast. - Fix "COPY FROM" to properly handle null marker strings that correspond to invalid encoding. A null marker string such as E'\\0' should work, and did work in the past, but the case got broken in 8.4. - Ensure autovacuum worker processes perform stack depth checking properly. Previously, infinite recursion in a function invoked by auto-"ANALYZE" could crash worker processes. - Fix logging collector to not lose log coherency under high load. The collector previously could fail to reassemble large messages if it got too busy. - Fix logging collector to ensure it will restart file rotation after receiving SIGHUP. - Fix WAL replay logic for GIN indexes to not fail if the index was subsequently dropped> - Fix memory leak in PL/pgSQL's "RETURN NEXT" command. - Fix PL/pgSQL's "GET DIAGNOSTICS" command when the target is the function's first variable. - Fix potential access off the end of memory in psql's expanded display ("\x") mode. - Fix several performance problems in pg_dump when the database contains many objects. pg_dump could get very slow if the database contained many schemas, or if many objects are in dependency loops, or if there are many owned sequences. - Fix "contrib/dblink"'s dblink_exec() to not leak temporary database connections upon error. - Fix "contrib/dblink" to report the correct connection name in error messages. Date: Mon, 04 Jun 2012 08:33:03 +0200 Changed-By: Martin Pitt Maintainer: Ubuntu Developers https://launchpad.net/ubuntu/natty/+source/postgresql-8.4/8.4.12-0ubuntu11.04 -------------- next part -------------- Format: 1.8 Date: Mon, 04 Jun 2012 08:33:03 +0200 Source: postgresql-8.4 Binary: libpq-dev libpq5 libecpg6 libecpg-dev libecpg-compat3 libpgtypes3 postgresql-8.4 postgresql-client-8.4 postgresql-server-dev-8.4 postgresql-doc-8.4 postgresql-contrib-8.4 postgresql-plperl-8.4 postgresql-plpython-8.4 postgresql-pltcl-8.4 postgresql postgresql-client postgresql-doc postgresql-contrib Architecture: source Version: 8.4.12-0ubuntu11.04 Distribution: natty-security Urgency: low Maintainer: Ubuntu Developers Changed-By: Martin Pitt Description: libecpg-compat3 - older version of run-time library for ECPG programs libecpg-dev - development files for ECPG (Embedded PostgreSQL for C) libecpg6 - run-time library for ECPG programs libpgtypes3 - shared library libpgtypes for PostgreSQL 8.4 libpq-dev - header files for libpq5 (PostgreSQL library) libpq5 - PostgreSQL C client library postgresql - object-relational SQL database (supported version) postgresql-8.4 - object-relational SQL database, version 8.4 server postgresql-client - front-end programs for PostgreSQL (supported version) postgresql-client-8.4 - front-end programs for PostgreSQL 8.4 postgresql-contrib - additional facilities for PostgreSQL (supported version) postgresql-contrib-8.4 - additional facilities for PostgreSQL postgresql-doc - documentation for the PostgreSQL database management system postgresql-doc-8.4 - documentation for the PostgreSQL database management system postgresql-plperl-8.4 - PL/Perl procedural language for PostgreSQL 8.4 postgresql-plpython-8.4 - PL/Python procedural language for PostgreSQL 8.4 postgresql-pltcl-8.4 - PL/Tcl procedural language for PostgreSQL 8.4 postgresql-server-dev-8.4 - development files for PostgreSQL 8.4 server-side programming Launchpad-Bugs-Fixed: 1008317 Changes: postgresql-8.4 (8.4.12-0ubuntu11.04) natty-security; urgency=low . * New upstream security/bug fix release: (LP: #1008317) - Fix incorrect password transformation in "contrib/pgcrypto"'s DES crypt() function. If a password string contained the byte value 0x80, the remainder of the password was ignored, causing the password to be much weaker than it appeared. With this fix, the rest of the string is properly included in the DES hash. Any stored password values that are affected by this bug will thus no longer match, so the stored values may need to be updated. (CVE-2012-2143) - Ignore SECURITY DEFINER and SET attributes for a procedural language's call handler. Applying such attributes to a call handler could crash the server. (CVE-2012-2655) - Allow numeric timezone offsets in timestamp input to be up to 16 hours away from UTC. Some historical time zones have offsets larger than 15 hours, the previous limit. This could result in dumped data values being rejected during reload. - Fix timestamp conversion to cope when the given time is exactly the last DST transition time for the current timezone. This oversight has been there a long time, but was not noticed previously because most DST-using zones are presumed to have an indefinite sequence of future DST transitions. - Fix text to name and char to name casts to perform string truncation correctly in multibyte encodings. - Fix memory copying bug in to_tsquery(). - Fix planner's handling of outer PlaceHolderVars within subqueries. This bug concerns sub-SELECTs that reference variables coming from the nullable side of an outer join of the surrounding query. In 9.1, queries affected by this bug would fail with "ERROR: Upper-level PlaceHolderVar found where not expected". But in 9.0 and 8.4, you'd silently get possibly-wrong answers, since the value transmitted into the subquery wouldn't go to null when it should. - Fix slow session startup when pg_attribute is very large. If pg_attribute exceeds one-fourth of shared_buffers, cache rebuilding code that is sometimes needed during session start would trigger the synchronized-scan logic, causing it to take many times longer than normal. The problem was particularly acute if many new sessions were starting at once. - Ensure sequential scans check for query cancel reasonably often. A scan encountering many consecutive pages that contain no live tuples would not respond to interrupts meanwhile. - Ensure the Windows implementation of PGSemaphoreLock() clears ImmediateInterruptOK before returning. This oversight meant that a query-cancel interrupt received later in the same query could be accepted at an unsafe time, with unpredictable but not good consequences. - Show whole-row variables safely when printing views or rules. Corner cases involving ambiguous names (that is, the name could be either a table or column name of the query) were printed in an ambiguous way, risking that the view or rule would be interpreted differently after dump and reload. Avoid the ambiguous case by attaching a no-op cast. - Fix "COPY FROM" to properly handle null marker strings that correspond to invalid encoding. A null marker string such as E'\\0' should work, and did work in the past, but the case got broken in 8.4. - Ensure autovacuum worker processes perform stack depth checking properly. Previously, infinite recursion in a function invoked by auto-"ANALYZE" could crash worker processes. - Fix logging collector to not lose log coherency under high load. The collector previously could fail to reassemble large messages if it got too busy. - Fix logging collector to ensure it will restart file rotation after receiving SIGHUP. - Fix WAL replay logic for GIN indexes to not fail if the index was subsequently dropped> - Fix memory leak in PL/pgSQL's "RETURN NEXT" command. - Fix PL/pgSQL's "GET DIAGNOSTICS" command when the target is the function's first variable. - Fix potential access off the end of memory in psql's expanded display ("\x") mode. - Fix several performance problems in pg_dump when the database contains many objects. pg_dump could get very slow if the database contained many schemas, or if many objects are in dependency loops, or if there are many owned sequences. - Fix "contrib/dblink"'s dblink_exec() to not leak temporary database connections upon error. - Fix "contrib/dblink" to report the correct connection name in error messages. Checksums-Sha1: 23a1f969df3865303cbf0b0efe07b0202b9b751a 2600 postgresql-8.4_8.4.12-0ubuntu11.04.dsc 53a17cd0f104bcad112925d3c6fc2e29e1f89c8e 18193373 postgresql-8.4_8.4.12.orig.tar.gz 05729f0d595253062ea497274d00535c8c541d3c 105193 postgresql-8.4_8.4.12-0ubuntu11.04.diff.gz Checksums-Sha256: 49d604e66ce6a49f6b31f9e7672a52aa8c60cb4f6bea65fc1c8f457dbd841f4c 2600 postgresql-8.4_8.4.12-0ubuntu11.04.dsc 0cd614f0f0f149d683aa1fbdefd7d873282cfdefada5a687d2644457c855d4f2 18193373 postgresql-8.4_8.4.12.orig.tar.gz 439cd70f236bbcfd4e43cd5f88131c8147aaabff42a9699be119a56883a8bca8 105193 postgresql-8.4_8.4.12-0ubuntu11.04.diff.gz Files: 59b8785d9c78e9de090d8b5956322c4e 2600 database optional postgresql-8.4_8.4.12-0ubuntu11.04.dsc 2e7c6e16fe19e9597e2882fe47c7d3fd 18193373 database optional postgresql-8.4_8.4.12.orig.tar.gz 3180b3fa8c5b7ab4c347002d674be744 105193 database optional postgresql-8.4_8.4.12-0ubuntu11.04.diff.gz Original-Maintainer: Martin Pitt From marc.deslauriers at ubuntu.com Tue Jun 5 18:33:54 2012 From: marc.deslauriers at ubuntu.com (Marc Deslauriers) Date: Tue, 05 Jun 2012 18:33:54 -0000 Subject: [ubuntu/natty-security] bind9_9.7.3.dfsg-1ubuntu2.4_armel_translations.tar.gz, bind9_9.7.3.dfsg-1ubuntu2.4_i386_translations.tar.gz, bind9, bind9_9.7.3.dfsg-1ubuntu2.4_amd64_translations.tar.gz, bind9_9.7.3.dfsg-1ubuntu2.4_powerpc_translations.tar.gz 1:9.7.3.dfsg-1ubuntu2.4 (Accepted) Message-ID: <20120605183354.15091.11656.launchpad@cocoplum.canonical.com> bind9 (1:9.7.3.dfsg-1ubuntu2.4) natty-security; urgency=low * SECURITY UPDATE: ghost domain names attack - lib/dns/rbtdb.c: Restrict the TTL of NS RRset to no more than that of the old NS RRset when replacing it. - Patch backported from 9.7.5. - CVE-2012-1033 * SECURITY UPDATE: denial of service via zero length rdata handling - lib/dns/rdata.c,lib/dns/rdataslab.c: use sentinel pointer for duplicate rdata. - Patch backported from 9.7.6-P1. - CVE-2012-1667 Date: Mon, 04 Jun 2012 13:27:50 -0400 Changed-By: Marc Deslauriers Maintainer: Ubuntu Developers https://launchpad.net/ubuntu/natty/+source/bind9/1:9.7.3.dfsg-1ubuntu2.4 -------------- next part -------------- Format: 1.8 Date: Mon, 04 Jun 2012 13:27:50 -0400 Source: bind9 Binary: bind9 bind9utils bind9-doc host bind9-host libbind-dev libbind9-60 libdns69 libisc62 liblwres60 libisccc60 libisccfg62 dnsutils lwresd Architecture: source Version: 1:9.7.3.dfsg-1ubuntu2.4 Distribution: natty-security Urgency: low Maintainer: Ubuntu Developers Changed-By: Marc Deslauriers Description: bind9 - Internet Domain Name Server bind9-doc - Documentation for BIND bind9-host - Version of 'host' bundled with BIND 9.X bind9utils - Utilities for BIND dnsutils - Clients provided with BIND host - Transitional package libbind-dev - Static Libraries and Headers used by BIND libbind9-60 - BIND9 Shared Library used by BIND libdns69 - DNS Shared Library used by BIND libisc62 - ISC Shared Library used by BIND libisccc60 - Command Channel Library used by BIND libisccfg62 - Config File Handling Library used by BIND liblwres60 - Lightweight Resolver Library used by BIND lwresd - Lightweight Resolver Daemon Changes: bind9 (1:9.7.3.dfsg-1ubuntu2.4) natty-security; urgency=low . * SECURITY UPDATE: ghost domain names attack - lib/dns/rbtdb.c: Restrict the TTL of NS RRset to no more than that of the old NS RRset when replacing it. - Patch backported from 9.7.5. - CVE-2012-1033 * SECURITY UPDATE: denial of service via zero length rdata handling - lib/dns/rdata.c,lib/dns/rdataslab.c: use sentinel pointer for duplicate rdata. - Patch backported from 9.7.6-P1. - CVE-2012-1667 Checksums-Sha1: e0b59135ae3c96a3567954b2ae5d07bcbb3084d7 2267 bind9_9.7.3.dfsg-1ubuntu2.4.dsc de8d7da35386f64e3828f86b35dbaa347aa48bbc 519371 bind9_9.7.3.dfsg-1ubuntu2.4.diff.gz Checksums-Sha256: 354a13d15cbc649cff7ecf1c3c2ce2cecec8a3545b1f679921942b82f8d8054e 2267 bind9_9.7.3.dfsg-1ubuntu2.4.dsc f9582447e93d93848fe09bd31fdc611b8280a4db533365ad8aa85b38fed19567 519371 bind9_9.7.3.dfsg-1ubuntu2.4.diff.gz Files: 679086ff39f335b195f5fc25762869f2 2267 net optional bind9_9.7.3.dfsg-1ubuntu2.4.dsc f22daa388326e6ef27ec058306db2b71 519371 net optional bind9_9.7.3.dfsg-1ubuntu2.4.diff.gz Original-Maintainer: LaMont Jones From launchpad at micahscomputing.com Wed Jun 6 08:45:04 2012 From: launchpad at micahscomputing.com (Micah Gersten) Date: Wed, 06 Jun 2012 08:45:04 -0000 Subject: [ubuntu/natty-security] firefox 13.0+build1-0ubuntu0.11.04.1 (Accepted) Message-ID: <20120606084504.23256.59235.launchpad@ackee.canonical.com> firefox (13.0+build1-0ubuntu0.11.04.1) natty-security; urgency=low * New upstream stable release (FIREFOX_13_0_BUILD1) - see LP: #1007495 for USN information [ Chris Coulson ] * Update globalmenu-extension to 3.2.3 - Reduce our memory footprint a bit, which wasn't really a lot anyway - Avoid the use of the component manager for accessing commonly used services, where "commonly used" means "accessed when building every menu item". This should save some CPU cycles when building or refreshing menus - Try to recycle menuitems when they are removed from a menu by adding contiguous blocks of removed items to a "free list" which is emptied asynchronously, and reusing the items in this list when new items are added in place of the removed items. This means that refreshing the history menu contents when the menu is opened no longer alters the menu structure, but results in a shifting of properties between existing nodes instead. This has a few benefits: + With no layout changes, unity-panel-service doesn't request the entire menu structure, which significantly reduces dbus traffic and makes it much faster to refresh the menu contents + The size of the menu doesn't change when it is refreshed, which eliminates the flicker that used to occur when opening the history menu. - Remove all use of the global observer service for sending our own internal notifications around - Clean up the way we ensure that the correct edit commands are enabled by just installing our own onpopupshowing handler rather than using an additional notification to fix things up after the default handler runs - Get rid of a static initializer - Don't support older than Firefox 11 - Fix some GError leaks - Hide the internal menu when creating a native menu, rather than waiting for confirmation that the native menu is registered successfully. We don't try to create a native menu if we don't find a menu service to register the menu with anyway - Keep menu contents updated whilst the menu is open, rather than just whilst it is opening - Fix LP: #915888 - Handling of checkbox menuitems with a command node is wrong * Refresh build-depends: - Bump minimum GTK version to 2.14 as we build with GIO support - Add minimum requirement for glib (2.18) - Drop libidl-dev, this doesn't appear to be needed now - Bump minimum NSPR version to 4.9.0 for --enable-system-nspr builds - Bump minimum sqlite version to 3.7.10 for --enable-system-sqlite builds - Bump minimum NSS version to 3.13.2 for --enable-system-nss builds * Refresh patches: - update debian/patches/ubuntu-ua-string-changes.patch - update debian/patches/ubuntu-codes-google.patch - update debian/patches/firefox-kde.patch - update debian/patches/mozilla-kde.patch - update debian/patches/dont-include-hyphenation-patterns.patch * Clean up the file exclude list and add comments for excluded files - update debian/build/create-tarball.py * Make it easy to run Firefox in valgrind for builds that are compiled with explicit valgrind support - update debian/firefox.sh.in * Bump debhelper compat to 7 - update debian/apport/blacklist.in - update debian/apport/source_firefox.py.in - update debian/compat - update debian/config/mozconfig.in - update debian/control.in - update debian/firefox-dev.install.in - update debian/firefox-dev.links.in - update debian/firefox-globalmenu.dirs.in - update debian/firefox-gnome-support.install.in - update debian/firefox.dirs.in - update debian/firefox.install.in - update debian/firefox.links.in - update debian/firefox.postinst.in - update debian/firefox.preinst.in - update debian/firefox.sh.in - update debian/pkgconfig/libxul.pc.in - update debian/pkgconfig/mozilla-nspr.pc.in - update debian/pkgconfig/mozilla-plugin.pc.in - update debian/rules - update debian/usr.bin.firefox.apparmor.10.04 - update debian/usr.bin.firefox.apparmor.10.10 - update debian/usr.bin.firefox.apparmor.11.04 - update debian/usr.bin.firefox.apparmor.9.10 * Override 2 embedded-library lintian errors - update debian/firefox.lintian-overrides.in * Drop debian/patches/distro-locale-searchplugins after landing of bmo: #515232 * Don't hardcode general.useragent.locale to en-US, now that it's used for searchplugin localization. This means we can drop this pref from ubufox - add debian/patches/dont-override-general-useragent-locale.patch - update debian/patches/series * Drop patches fixed upstream - remove debian/patches/no-sps-profiler-on-unsupported-archs.patch - remove debian/patches/avoid-dbus-roundtrip-for-httpchannel.patch - update debian/patches/series * Apport hook improvements: - Add support for reporting preference defaults that are set by extensions - When reporting preferences, record the source of each preference - Report plugin packages for plugins that are installed with the package manager - Add some addon manager related prefs to the whitelist - Display additional metadata in the extensions report - Take "default-to-compatible" in to account when determining whether the user is running incompatible addons - Attach submitted crash ID's to bug reports - Report if files in the profile folder have broken permissions * Update compare-locales to 0.9.5 * Fix make-makefile test failure when the build directory contains perl regexp control characters - add debian/patches/make-makefile-test-fix.patch - update debian/patches/series * Fix for NSS libs not being signed, breaking FIPS - update debian/rules [ Jamie Strandboge ] * adjust apparmor profile to deny reads to @{PROC}/[0-9]*/net/dev. Patch thanks to James Troup (LP: #955066) * adjust apparmor profile to deny reads to @{PROC}/[0-9]*/net/wireless. Patch thanks to James Troup (LP: #974141) Date: 2012-06-01 17:52:20.468449+00:00 Changed-By: Chris Coulson Signed-By: Micah Gersten https://launchpad.net/ubuntu/natty/+source/firefox/13.0+build1-0ubuntu0.11.04.1 -------------- next part -------------- Sorry, changesfile not available. From marc.deslauriers at ubuntu.com Wed Jun 6 13:34:13 2012 From: marc.deslauriers at ubuntu.com (Marc Deslauriers) Date: Wed, 06 Jun 2012 13:34:13 -0000 Subject: [ubuntu/natty-security] ubuntuone-storage-protocol 1.6.1-0ubuntu1.2 (Accepted) Message-ID: <20120606133413.24813.73443.launchpad@cocoplum.canonical.com> ubuntuone-storage-protocol (1.6.1-0ubuntu1.2) natty-security; urgency=low * SECURITY UPDATE: MITM via incorrect ssl cert validation (LP: #882062) - debian/patches/CVE-2011-4409.patch: validate hostname in ubuntuone/storageprotocol/context.py, add test to tests/test_context.py. - CVE-2011-4409 Date: Tue, 29 May 2012 15:34:32 -0400 Changed-By: Marc Deslauriers Maintainer: Ubuntu Developers https://launchpad.net/ubuntu/natty/+source/ubuntuone-storage-protocol/1.6.1-0ubuntu1.2 -------------- next part -------------- Format: 1.8 Date: Tue, 29 May 2012 15:34:32 -0400 Source: ubuntuone-storage-protocol Binary: python-ubuntuone-storageprotocol Architecture: source Version: 1.6.1-0ubuntu1.2 Distribution: natty-security Urgency: low Maintainer: Ubuntu Developers Changed-By: Marc Deslauriers Description: python-ubuntuone-storageprotocol - Python library for Ubuntu One file storage and sharing service Launchpad-Bugs-Fixed: 882062 Changes: ubuntuone-storage-protocol (1.6.1-0ubuntu1.2) natty-security; urgency=low . * SECURITY UPDATE: MITM via incorrect ssl cert validation (LP: #882062) - debian/patches/CVE-2011-4409.patch: validate hostname in ubuntuone/storageprotocol/context.py, add test to tests/test_context.py. - CVE-2011-4409 Checksums-Sha1: b8e62dbc1452c6ccdf7f0024c790702b87e4c584 2149 ubuntuone-storage-protocol_1.6.1-0ubuntu1.2.dsc 38a63c2943e7067c08961e3672fff31234a3745e 7063 ubuntuone-storage-protocol_1.6.1-0ubuntu1.2.debian.tar.gz Checksums-Sha256: ce42957eb0163b9a83f255b30ec52c57efe1edacac67bed66bbed9b252cc75d6 2149 ubuntuone-storage-protocol_1.6.1-0ubuntu1.2.dsc 164dc8be057f12460016a9bff970381af1c17224693fc9670eacce49977dbffb 7063 ubuntuone-storage-protocol_1.6.1-0ubuntu1.2.debian.tar.gz Files: 0f95547ab64c86385f747dde5c2a6123 2149 python optional ubuntuone-storage-protocol_1.6.1-0ubuntu1.2.dsc 44562d8ac2d53ef31296872ee9865c2e 7063 python optional ubuntuone-storage-protocol_1.6.1-0ubuntu1.2.debian.tar.gz Original-Maintainer: Rick McBride From marc.deslauriers at ubuntu.com Wed Jun 6 13:34:33 2012 From: marc.deslauriers at ubuntu.com (Marc Deslauriers) Date: Wed, 06 Jun 2012 13:34:33 -0000 Subject: [ubuntu/natty-security] ubuntuone-client, ubuntuone-client_1.6.2-0ubuntu2.1_amd64_translations.tar.gz, ubuntuone-client_1.6.2-0ubuntu2.1_i386_translations.tar.gz, ubuntuone-client_1.6.2-0ubuntu2.1_armel_translations.tar.gz, ubuntuone-client_1.6.2-0ubuntu2.1_powerpc_translations.tar.gz 1.6.2-0ubuntu2.1 (Accepted) Message-ID: <20120606133433.24813.38384.launchpad@cocoplum.canonical.com> ubuntuone-client (1.6.2-0ubuntu2.1) natty-security; urgency=low * SECURITY UPDATE: MITM via incorrect ssl cert validation (LP: #882062) - debian/patches/CVE-2011-4409.patch: use pycurl instead of urllib2 and send hostname for validation in ubuntuone/syncdaemon/action_queue.py, use correct URL in data/syncdaemon.conf, use pycurl instead of urllib2 in tests/syncdaemon/test_action_queue.py. - debian/control: bump python-ubuntuone-storageprotocol and ubuntu-sso-client dependencies to security updates. - CVE-2011-4409 Date: Tue, 29 May 2012 15:39:24 -0400 Changed-By: Marc Deslauriers Maintainer: Ubuntu Developers https://launchpad.net/ubuntu/natty/+source/ubuntuone-client/1.6.2-0ubuntu2.1 -------------- next part -------------- Format: 1.8 Date: Tue, 29 May 2012 15:39:24 -0400 Source: ubuntuone-client Binary: ubuntuone-client ubuntuone-client-gnome python-ubuntuone-client libsyncdaemon-1.0-1 libsyncdaemon-1.0-dev gir1.2-syncdaemon-1.0 ubuntuone-client-dbg Architecture: source Version: 1.6.2-0ubuntu2.1 Distribution: natty-security Urgency: low Maintainer: Ubuntu Developers Changed-By: Marc Deslauriers Description: gir1.2-syncdaemon-1.0 - Ubuntu One synchronization daemon library libsyncdaemon-1.0-1 - Ubuntu One synchronization daemon library libsyncdaemon-1.0-dev - Ubuntu One synchronization daemon library python-ubuntuone-client - Ubuntu One client Python libraries ubuntuone-client - Ubuntu One client ubuntuone-client-dbg - Debugging symbols for ubuntuone-client ubuntuone-client-gnome - Ubuntu One client GNOME integration Launchpad-Bugs-Fixed: 882062 Changes: ubuntuone-client (1.6.2-0ubuntu2.1) natty-security; urgency=low . * SECURITY UPDATE: MITM via incorrect ssl cert validation (LP: #882062) - debian/patches/CVE-2011-4409.patch: use pycurl instead of urllib2 and send hostname for validation in ubuntuone/syncdaemon/action_queue.py, use correct URL in data/syncdaemon.conf, use pycurl instead of urllib2 in tests/syncdaemon/test_action_queue.py. - debian/control: bump python-ubuntuone-storageprotocol and ubuntu-sso-client dependencies to security updates. - CVE-2011-4409 Checksums-Sha1: cc0e9d7fefb95f8a441d2ede88ded3fbf15f27d2 2366 ubuntuone-client_1.6.2-0ubuntu2.1.dsc 65c834cd4be3593be30e8ca831b0cacb9fd99c4b 24941 ubuntuone-client_1.6.2-0ubuntu2.1.debian.tar.gz Checksums-Sha256: 6fe99445457ba0684bb54def73ad1b4229c0deff896b3a1187adb936cf79e18b 2366 ubuntuone-client_1.6.2-0ubuntu2.1.dsc 6983c20ad2fe9e6578aad79b8c1b55b90230a008f14b0327ca22889bdb578722 24941 ubuntuone-client_1.6.2-0ubuntu2.1.debian.tar.gz Files: fad57cf0524cdd1f6d5c58a3ec6a93d3 2366 net optional ubuntuone-client_1.6.2-0ubuntu2.1.dsc 56913d463c0bbe00d5cca319613ccdd1 24941 net optional ubuntuone-client_1.6.2-0ubuntu2.1.debian.tar.gz Original-Maintainer: Rick McBride From marc.deslauriers at ubuntu.com Wed Jun 6 13:34:41 2012 From: marc.deslauriers at ubuntu.com (Marc Deslauriers) Date: Wed, 06 Jun 2012 13:34:41 -0000 Subject: [ubuntu/natty-security] ubuntu-sso-client_1.2.1-0ubuntu2.1_i386_translations.tar.gz, ubuntu-sso-client 1.2.1-0ubuntu2.1 (Accepted) Message-ID: <20120606133441.24813.36081.launchpad@cocoplum.canonical.com> ubuntu-sso-client (1.2.1-0ubuntu2.1) natty-security; urgency=low * SECURITY UPDATE: MITM via incorrect ssl cert validation (LP: #882055) - debian/patches/CVE-2011-4408.patch: use pycurl instead of urllib2 in ubuntu_sso/account.py, ubuntu_sso/credentials.py, ubuntu_sso/tests/test_credentials.py, ubuntu_sso/utils/curllib.py, ubuntu_sso/utils/tests/test_curllib.py. - debian/control: add python-pycurl dependency. - CVE-2011-4408 Date: Tue, 31 Jan 2012 14:01:31 -0500 Changed-By: Marc Deslauriers Maintainer: Ubuntu Developers https://launchpad.net/ubuntu/natty/+source/ubuntu-sso-client/1.2.1-0ubuntu2.1 -------------- next part -------------- Format: 1.8 Date: Tue, 31 Jan 2012 14:01:31 -0500 Source: ubuntu-sso-client Binary: ubuntu-sso-client Architecture: source Version: 1.2.1-0ubuntu2.1 Distribution: natty-security Urgency: low Maintainer: Ubuntu Developers Changed-By: Marc Deslauriers Description: ubuntu-sso-client - Ubuntu Single Sign-On client Launchpad-Bugs-Fixed: 882055 Changes: ubuntu-sso-client (1.2.1-0ubuntu2.1) natty-security; urgency=low . * SECURITY UPDATE: MITM via incorrect ssl cert validation (LP: #882055) - debian/patches/CVE-2011-4408.patch: use pycurl instead of urllib2 in ubuntu_sso/account.py, ubuntu_sso/credentials.py, ubuntu_sso/tests/test_credentials.py, ubuntu_sso/utils/curllib.py, ubuntu_sso/utils/tests/test_curllib.py. - debian/control: add python-pycurl dependency. - CVE-2011-4408 Checksums-Sha1: a418392cefe2f1b6fda42807e7ce827d74f50a61 1926 ubuntu-sso-client_1.2.1-0ubuntu2.1.dsc f71c28c6d0789ea88a8b4f4ba9dd94ad3a3739ce 12530 ubuntu-sso-client_1.2.1-0ubuntu2.1.debian.tar.gz Checksums-Sha256: e1c456c197d8c55ed82e5864cb0f5a0cbe1459e5ce8a53e650a374bc1d280559 1926 ubuntu-sso-client_1.2.1-0ubuntu2.1.dsc fe681f8bfbc45cadf5f494689a521c1ed3f24be7c4d83c1f7ecbfbc77542517d 12530 ubuntu-sso-client_1.2.1-0ubuntu2.1.debian.tar.gz Files: 46eaa6ba83ba4ffae4a6856ead72d75e 1926 python extra ubuntu-sso-client_1.2.1-0ubuntu2.1.dsc 8b194ecc34b6bd72f85e5d6e95458ad7 12530 python extra ubuntu-sso-client_1.2.1-0ubuntu2.1.debian.tar.gz Original-Maintainer: Natalia Bidart From cjwatson at canonical.com Fri Jun 8 11:13:18 2012 From: cjwatson at canonical.com (Colin Watson) Date: Fri, 08 Jun 2012 11:13:18 -0000 Subject: [ubuntu/natty-updates] pastebinit 1.2-2ubuntu0.11.04.1 (Accepted) Message-ID: <20120608111318.1672.40387.launchpad@ackee.canonical.com> pastebinit (1.2-2ubuntu0.11.04.1) natty-proposed; urgency=low * Cherry-pick new pastebin.com.conf file from pastebinit 1.3.1, this switches to the new pastebin.com API (now mandatory) (LP: #996242) Date: 2012-05-30 14:15:16.405478+00:00 Changed-By: Stéphane Graber Signed-By: Colin Watson https://launchpad.net/ubuntu/natty/+source/pastebinit/1.2-2ubuntu0.11.04.1 -------------- next part -------------- Sorry, changesfile not available. From jamie at ubuntu.com Fri Jun 8 21:33:31 2012 From: jamie at ubuntu.com (Jamie Strandboge) Date: Fri, 08 Jun 2012 21:33:31 -0000 Subject: [ubuntu/natty-security] flashplugin-nonfree, flashplugin-nonfree_11.2.202.236ubuntu0.11.04.1_amd64_translations.tar.gz, flashplugin-nonfree_11.2.202.236ubuntu0.11.04.1_i386_translations.tar.gz 11.2.202.236ubuntu0.11.04.1 (Accepted) Message-ID: <20120608213331.29868.96498.launchpad@cocoplum.canonical.com> flashplugin-nonfree (11.2.202.236ubuntu0.11.04.1) natty-security; urgency=low * New upstream release 11.2.202.236 - debian/{config,postinst.in}: Updated version and sha256sum. Date: Fri, 08 Jun 2012 14:40:58 -0500 Changed-By: Jamie Strandboge Maintainer: Ubuntu Developers https://launchpad.net/ubuntu/natty/+source/flashplugin-nonfree/11.2.202.236ubuntu0.11.04.1 -------------- next part -------------- Format: 1.8 Date: Fri, 08 Jun 2012 14:40:58 -0500 Source: flashplugin-nonfree Binary: flashplugin-installer flashplugin-nonfree Architecture: source Version: 11.2.202.236ubuntu0.11.04.1 Distribution: natty-security Urgency: low Maintainer: Ubuntu Developers Changed-By: Jamie Strandboge Description: flashplugin-installer - Adobe Flash Player plugin installer flashplugin-nonfree - Adobe Flash Player plugin installer (transitional package) Changes: flashplugin-nonfree (11.2.202.236ubuntu0.11.04.1) natty-security; urgency=low . * New upstream release 11.2.202.236 - debian/{config,postinst.in}: Updated version and sha256sum. Checksums-Sha1: 6a768a6d86b8d5ee2b84c2a2c6ddc635d6acd827 1649 flashplugin-nonfree_11.2.202.236ubuntu0.11.04.1.dsc 23daff128983aae38306819ec3db48ab4fbdd2b4 27393 flashplugin-nonfree_11.2.202.236ubuntu0.11.04.1.tar.gz Checksums-Sha256: 1ae4c87731b5235c6cd6d2647068dc561cfc5415657177d66566fab2dfed21dc 1649 flashplugin-nonfree_11.2.202.236ubuntu0.11.04.1.dsc 323b28a83628aab5f3f6c5408fe9dfd9d5a5ee0367d7a4b0868f41e5e9fbb8c4 27393 flashplugin-nonfree_11.2.202.236ubuntu0.11.04.1.tar.gz Files: ded5b2ab8b344fc253613c473f49e284 1649 contrib/web optional flashplugin-nonfree_11.2.202.236ubuntu0.11.04.1.dsc 4a4aa6d2aabe5cae005b0e9774bd6591 27393 contrib/web optional flashplugin-nonfree_11.2.202.236ubuntu0.11.04.1.tar.gz Original-Maintainer: Bart Martens From chris.coulson at canonical.com Mon Jun 11 19:45:27 2012 From: chris.coulson at canonical.com (Chris Coulson) Date: Mon, 11 Jun 2012 19:45:27 -0000 Subject: [ubuntu/natty] adobe-flashplugin 11.2.202.236-0natty1 (Accepted) Message-ID: <20120611194527.29326.37072.launchpad@cocoplum.canonical.com> adobe-flashplugin (11.2.202.236-0natty1) natty; urgency=low * New upstream release Date: Fri, 08 Jun 2012 19:48:30 +0100 Changed-By: Chris Coulson Maintainer: DL-Flash Player Ubuntu https://launchpad.net/ubuntu/natty/+source/adobe-flashplugin/11.2.202.236-0natty1 -------------- next part -------------- Format: 1.8 Date: Fri, 08 Jun 2012 19:48:30 +0100 Source: adobe-flashplugin Binary: adobe-flashplugin adobe-flash-properties-gtk adobe-flash-properties-kde Architecture: source Version: 11.2.202.236-0natty1 Distribution: natty Urgency: low Maintainer: DL-Flash Player Ubuntu Changed-By: Chris Coulson Description: adobe-flash-properties-gtk - GTK+ control panel for Adobe Flash Player plugin version 11 adobe-flash-properties-kde - KDE control panel Adobe Flash Player plugin version 11 adobe-flashplugin - Adobe Flash Player plugin version 11 Changes: adobe-flashplugin (11.2.202.236-0natty1) natty; urgency=low . * New upstream release Checksums-Sha1: 097adf9758738c34f0fa9d3a346eeeef79dcd46f 1731 adobe-flashplugin_11.2.202.236-0natty1.dsc eb3aa349acf8d332f472c57ae4a36b433244b412 5116 adobe-flashplugin_11.2.202.236-0natty1.diff.gz Checksums-Sha256: 6e5e6a4d9cb1035498404838801f8a8a8aaf63b8827defa720107fb0df236f18 1731 adobe-flashplugin_11.2.202.236-0natty1.dsc 5db8ec2ebfbd6a149c8a58a24f0ce4001b94544ee600e033298d0a022118bf5c 5116 adobe-flashplugin_11.2.202.236-0natty1.diff.gz Files: 7a0b9e93496e5855303c613ac85acadb 1731 partner/web optional adobe-flashplugin_11.2.202.236-0natty1.dsc 0b764a5e1c9137547dd18e5883bcaa76 5116 partner/web optional adobe-flashplugin_11.2.202.236-0natty1.diff.gz From marc.deslauriers at ubuntu.com Mon Jun 11 21:05:48 2012 From: marc.deslauriers at ubuntu.com (Marc Deslauriers) Date: Mon, 11 Jun 2012 21:05:48 -0000 Subject: [ubuntu/natty-security] mysql-5.1_5.1.63-0ubuntu0.11.04.1_amd64_translations.tar.gz, mysql-5.1_5.1.63-0ubuntu0.11.04.1_i386_translations.tar.gz, mysql-5.1_5.1.63-0ubuntu0.11.04.1_armel_translations.tar.gz, mysql-5.1, mysql-5.1_5.1.63-0ubuntu0.11.04.1_powerpc_translations.tar.gz 5.1.63-0ubuntu0.11.04.1 (Accepted) Message-ID: <20120611210548.17318.11875.launchpad@cocoplum.canonical.com> mysql-5.1 (5.1.63-0ubuntu0.11.04.1) natty-security; urgency=low * SECURITY UPDATE: Update to 5.1.63 to fix security issues (LP: #1011371) - http://dev.mysql.com/doc/refman/5.1/en/news-5-1-63.html Date: Mon, 11 Jun 2012 07:25:44 -0400 Changed-By: Marc Deslauriers Maintainer: Ubuntu Developers https://launchpad.net/ubuntu/natty/+source/mysql-5.1/5.1.63-0ubuntu0.11.04.1 -------------- next part -------------- Format: 1.8 Date: Mon, 11 Jun 2012 07:25:44 -0400 Source: mysql-5.1 Binary: libmysqlclient16 libmysqlclient16-dev libmysqld-pic libmysqld-dev libmysqlclient-dev mysql-common mysql-client-core-5.1 mysql-client-5.1 mysql-server-core-5.1 mysql-server-5.1 mysql-server mysql-client mysql-testsuite mysql-source-5.1 Architecture: source Version: 5.1.63-0ubuntu0.11.04.1 Distribution: natty-security Urgency: low Maintainer: Ubuntu Developers Changed-By: Marc Deslauriers Description: libmysqlclient-dev - MySQL database development files libmysqlclient16 - MySQL database client library libmysqlclient16-dev - MySQL database development files - empty transitional package libmysqld-dev - MySQL embedded database development files libmysqld-pic - MySQL database development files mysql-client - MySQL database client (metapackage depending on the latest versio mysql-client-5.1 - MySQL database client binaries mysql-client-core-5.1 - MySQL database core client binaries mysql-common - MySQL database common files, e.g. /etc/mysql/my.cnf mysql-server - MySQL database server (metapackage depending on the latest versio mysql-server-5.1 - MySQL database server binaries and system database setup mysql-server-core-5.1 - MySQL database server binaries mysql-source-5.1 - MySQL source mysql-testsuite - MySQL testsuite Launchpad-Bugs-Fixed: 1011371 Changes: mysql-5.1 (5.1.63-0ubuntu0.11.04.1) natty-security; urgency=low . * SECURITY UPDATE: Update to 5.1.63 to fix security issues (LP: #1011371) - http://dev.mysql.com/doc/refman/5.1/en/news-5-1-63.html Checksums-Sha1: fc3d2971e7adfb4822031d3bf7d651776416d77a 2557 mysql-5.1_5.1.63-0ubuntu0.11.04.1.dsc 490d3a485d2f9cbd7fa3b1010d82aa6b5c1260a8 21484787 mysql-5.1_5.1.63.orig.tar.gz d8c06c2185c4712853dfa4aff66ffdd4e9340405 302356 mysql-5.1_5.1.63-0ubuntu0.11.04.1.diff.gz Checksums-Sha256: 752feea4d53dfc85a7a8e61ff6aeafa7a7a883b9504f1cf09de98f76aabc3567 2557 mysql-5.1_5.1.63-0ubuntu0.11.04.1.dsc d549937c8cbb447d22824b872afbc1e8b9ab035861102e7e116404855c6e9d15 21484787 mysql-5.1_5.1.63.orig.tar.gz 9c48fdc572533faad7847c128063552b2e626b4bce12095df042748ffcfda6ed 302356 mysql-5.1_5.1.63-0ubuntu0.11.04.1.diff.gz Files: d912ab4811b8c25b5e52f615ab3a642b 2557 database optional mysql-5.1_5.1.63-0ubuntu0.11.04.1.dsc 420f296ee3259d82005a78bf7039c860 21484787 database optional mysql-5.1_5.1.63.orig.tar.gz 51e8c4a47ffe8456fb7a558b64c06333 302356 database optional mysql-5.1_5.1.63-0ubuntu0.11.04.1.diff.gz Original-Maintainer: Debian MySQL Maintainers From launchpad at micahscomputing.com Tue Jun 12 23:10:44 2012 From: launchpad at micahscomputing.com (Micah Gersten) Date: Tue, 12 Jun 2012 23:10:44 -0000 Subject: [ubuntu/natty-security] apparmor 2.6.1-0ubuntu3.1 (Accepted) Message-ID: <20120612231044.6446.84859.launchpad@ackee.canonical.com> apparmor (2.6.1-0ubuntu3.1) natty-security; urgency=low * fix LP: #989184 - Firefox 12's launcher script is not allowed in abstractions/ubuntu-browsers; This was a regression from the firefox path changing to a non-versioned path in the Firefox 12 packaging - add debian/patches/0016-lp989184.patch - update debian/patches/series * fix LP: #990931 - Thunderbird is being blocked by apparmor from Firefox; This was a regression from the Thunderbird path changing to a non-versioned path in the Thunderbird 12 packaging - add debian/patches/0015-lp990931.patch - update debian/patches/series Date: 2012-06-05 07:02:43.304512+00:00 Changed-By: Micah Gersten https://launchpad.net/ubuntu/natty/+source/apparmor/2.6.1-0ubuntu3.1 -------------- next part -------------- Sorry, changesfile not available. From trekcaptainusa-tw at ubuntu.com Wed Jun 13 17:33:36 2012 From: trekcaptainusa-tw at ubuntu.com (Thomas Ward) Date: Wed, 13 Jun 2012 17:33:36 -0000 Subject: [ubuntu/natty-security] nginx 0.8.54-4ubuntu0.1 (Accepted) Message-ID: <20120613173336.14862.42859.launchpad@cocoplum.canonical.com> nginx (0.8.54-4ubuntu0.1) natty-security; urgency=low * Security update (closes LP: #956150): * Patch to fix 'Use-after-free vulnerability' (CVE-2012-1180). * Patch to fix 'Heap-based buffer overflow in compression-pointer processing in core/ngx_resolver.c' (CVE-2011-4315). Date: Sun, 20 May 2012 13:05:42 -0400 Changed-By: Thomas Ward Maintainer: Ubuntu Developers https://launchpad.net/ubuntu/natty/+source/nginx/0.8.54-4ubuntu0.1 -------------- next part -------------- Format: 1.8 Date: Sun, 20 May 2012 13:05:42 -0400 Source: nginx Binary: nginx nginx-doc nginx-common nginx-full nginx-full-dbg nginx-light nginx-light-dbg nginx-extras nginx-extras-dbg Architecture: source Version: 0.8.54-4ubuntu0.1 Distribution: natty-security Urgency: low Maintainer: Ubuntu Developers Changed-By: Thomas Ward Description: nginx - small, but very powerful and efficient web server and mail proxy nginx-common - small, but very powerful and efficient web server (common files) nginx-doc - small, but very powerful and efficient web server (documentation) nginx-extras - nginx web server with full set of core modules and extras nginx-extras-dbg - Debugging symbols for nginx (extras) nginx-full - nginx web server with full set of core modules nginx-full-dbg - Debugging symbols for nginx (full) nginx-light - nginx web server with minimal set of core modules nginx-light-dbg - Debugging symbols for nginx (light) Launchpad-Bugs-Fixed: 956150 Changes: nginx (0.8.54-4ubuntu0.1) natty-security; urgency=low . * Security update (closes LP: #956150): * Patch to fix 'Use-after-free vulnerability' (CVE-2012-1180). * Patch to fix 'Heap-based buffer overflow in compression-pointer processing in core/ngx_resolver.c' (CVE-2011-4315). Checksums-Sha1: 373155d078f757137cc4288f88a4d32814054c0a 2263 nginx_0.8.54-4ubuntu0.1.dsc 81add69ff5887affdec780095805e4d5114866df 236358 nginx_0.8.54-4ubuntu0.1.debian.tar.gz Checksums-Sha256: e292988b10963b4b260f2d72a69880b6b2af608dfa7aa492216100d9d92d0f98 2263 nginx_0.8.54-4ubuntu0.1.dsc 1e6ae1cc1e01244edf6d732f52c1bb1283125d70e91b7b8d3377c14764e6eb11 236358 nginx_0.8.54-4ubuntu0.1.debian.tar.gz Files: 29ee35ad00d2009df047bb6da70b5d5f 2263 httpd optional nginx_0.8.54-4ubuntu0.1.dsc 1fafa5112a38596e30c0eefa0c9c542d 236358 httpd optional nginx_0.8.54-4ubuntu0.1.debian.tar.gz Original-Maintainer: Jose Parrella From jamie at ubuntu.com Fri Jun 15 02:35:33 2012 From: jamie at ubuntu.com (Jamie Strandboge) Date: Fri, 15 Jun 2012 02:35:33 -0000 Subject: [ubuntu/natty-security] apt_0.8.13.2ubuntu4.5_armel_translations.tar.gz, apt_0.8.13.2ubuntu4.5_powerpc_translations.tar.gz, apt_0.8.13.2ubuntu4.5_i386_translations.tar.gz, apt, apt_0.8.13.2ubuntu4.5_amd64_translations.tar.gz 0.8.13.2ubuntu4.5 (Accepted) Message-ID: <20120615023533.31809.62082.launchpad@cocoplum.canonical.com> apt (0.8.13.2ubuntu4.5) natty-security; urgency=low * adjust apt-key to ensure no collisions on subkeys too. Patch thanks to Marc Deslauriers. (LP: #1013128) Date: Thu, 14 Jun 2012 11:32:34 -0500 Changed-By: Jamie Strandboge Maintainer: Ubuntu Developers https://launchpad.net/ubuntu/natty/+source/apt/0.8.13.2ubuntu4.5 -------------- next part -------------- Format: 1.8 Date: Thu, 14 Jun 2012 11:32:34 -0500 Source: apt Binary: apt apt-doc libapt-pkg-dev libapt-pkg-doc apt-utils apt-transport-https Architecture: source Version: 0.8.13.2ubuntu4.5 Distribution: natty-security Urgency: low Maintainer: Ubuntu Developers Changed-By: Jamie Strandboge Description: apt - Advanced front-end for dpkg apt-doc - Documentation for APT apt-transport-https - APT https transport apt-utils - APT utility programs libapt-pkg-dev - Development files for APT's libapt-pkg and libapt-inst libapt-pkg-doc - Documentation for APT development Launchpad-Bugs-Fixed: 1013128 Changes: apt (0.8.13.2ubuntu4.5) natty-security; urgency=low . * adjust apt-key to ensure no collisions on subkeys too. Patch thanks to Marc Deslauriers. (LP: #1013128) Checksums-Sha1: f44c5669ac11d2260a9586f3a342b411ecc3eafe 2113 apt_0.8.13.2ubuntu4.5.dsc 4a13a14d35604a5c7fb2758e3fc149a2f895b7db 3398121 apt_0.8.13.2ubuntu4.5.tar.gz Checksums-Sha256: 0271d4bdb38f3adcd8080e170ba9f039c3d40c2cbb874ae6badbf8ec30a46ea3 2113 apt_0.8.13.2ubuntu4.5.dsc e84faf08a7d887741f943a73d13b0d4d9d4b420c7814106549054d33dd15a324 3398121 apt_0.8.13.2ubuntu4.5.tar.gz Files: 451f8eb56e493f6441e3975283978a2d 2113 admin important apt_0.8.13.2ubuntu4.5.dsc 186c8d2845776ceaab282415fbd8b629 3398121 admin important apt_0.8.13.2ubuntu4.5.tar.gz Original-Maintainer: APT Development Team From launchpad at micahscomputing.com Fri Jun 15 04:38:22 2012 From: launchpad at micahscomputing.com (Micah Gersten) Date: Fri, 15 Jun 2012 04:38:22 -0000 Subject: [ubuntu/natty-security] unity-2d 3.8.4.1-0ubuntu1.1 (Accepted) Message-ID: <20120615043822.16288.38655.launchpad@ackee.canonical.com> unity-2d (3.8.4.1-0ubuntu1.1) natty-security; urgency=low [ Łukasz 'sil2100' Zemczak ] * Fix issue with unity-2d sending the wrong event timestamp when closing an application window; This bug was exposed by a recent Firefox update which changed the way Firefox handled windows based on timestamps. (LP: #1010466) - panel/applets/appname/windowhelper.cpp [ Micah Gersten ] * Switch back to source format 1.0 as this is in line with how the unity devs prefer to update their packages - update debian/source/format Date: 2012-06-14 19:37:41.484422+00:00 Changed-By: Łukasz Zemczak Signed-By: Micah Gersten https://launchpad.net/ubuntu/natty/+source/unity-2d/3.8.4.1-0ubuntu1.1 -------------- next part -------------- Sorry, changesfile not available. From brad.figg at canonical.com Fri Jun 15 17:49:47 2012 From: brad.figg at canonical.com (Brad Figg) Date: Fri, 15 Jun 2012 17:49:47 -0000 Subject: [ubuntu/natty-proposed] linux 2.6.38-15.61 (Accepted) Message-ID: <20120615174947.21680.44856.launchpad@ackee.canonical.com> linux (2.6.38-15.61) natty-proposed; urgency=low [Luis Henriques] * Release Tracking Bug - LP: #1012033 [ Herton Ronaldo Krzesinski ] * SAUCE: async_populate_rootfs: fix build warnings - LP: #1003417 [ Upstream Kernel Changes ] * dl2k: Clean up rio_ioctl - CVE-2012-2313 * hfsplus: Fix potential buffer overflows - CVE-2012-2319 * Avoid reading past buffer when calling GETACL - LP: #1002505 - CVE-2012-2375 * Avoid beyond bounds copy while caching ACL - LP: #1002505 - CVE-2012-2375 * Fix length of buffer copied in __nfs4_get_acl_uncached - LP: #1002505 - CVE-2012-2375 Date: 2012-06-12 19:09:50.040905+00:00 Changed-By: Luis Henriques Signed-By: Brad Figg https://launchpad.net/ubuntu/natty/+source/linux/2.6.38-15.61 -------------- next part -------------- Sorry, changesfile not available. From jamie at ubuntu.com Fri Jun 15 21:07:34 2012 From: jamie at ubuntu.com (Jamie Strandboge) Date: Fri, 15 Jun 2012 21:07:34 -0000 Subject: [ubuntu/natty-security] apt_0.8.13.2ubuntu4.6_amd64_translations.tar.gz, apt_0.8.13.2ubuntu4.6_powerpc_translations.tar.gz, apt_0.8.13.2ubuntu4.6_i386_translations.tar.gz, apt_0.8.13.2ubuntu4.6_armel_translations.tar.gz, apt 0.8.13.2ubuntu4.6 (Accepted) Message-ID: <20120615210734.26340.3880.launchpad@cocoplum.canonical.com> apt (0.8.13.2ubuntu4.6) natty-security; urgency=low * SECURITY UPDATE: Disable apt-key net-update for now, as validation code is still insecure - cmdline/apt-key: exit 1 immediately in net_update() - CVE-2012-0954 - LP: #1013639 Date: Fri, 15 Jun 2012 07:59:17 -0500 Changed-By: Jamie Strandboge Maintainer: Ubuntu Developers https://launchpad.net/ubuntu/natty/+source/apt/0.8.13.2ubuntu4.6 -------------- next part -------------- Format: 1.8 Date: Fri, 15 Jun 2012 07:59:17 -0500 Source: apt Binary: apt apt-doc libapt-pkg-dev libapt-pkg-doc apt-utils apt-transport-https Architecture: source Version: 0.8.13.2ubuntu4.6 Distribution: natty-security Urgency: low Maintainer: Ubuntu Developers Changed-By: Jamie Strandboge Description: apt - Advanced front-end for dpkg apt-doc - Documentation for APT apt-transport-https - APT https transport apt-utils - APT utility programs libapt-pkg-dev - Development files for APT's libapt-pkg and libapt-inst libapt-pkg-doc - Documentation for APT development Launchpad-Bugs-Fixed: 1013639 Changes: apt (0.8.13.2ubuntu4.6) natty-security; urgency=low . * SECURITY UPDATE: Disable apt-key net-update for now, as validation code is still insecure - cmdline/apt-key: exit 1 immediately in net_update() - CVE-2012-0954 - LP: #1013639 Checksums-Sha1: be2d6869a8857607b6ff5e1d3c20d091dd0aa103 2113 apt_0.8.13.2ubuntu4.6.dsc cd78870d02eb538815319867892495b6725cf17b 3397014 apt_0.8.13.2ubuntu4.6.tar.gz Checksums-Sha256: 629a066b7c3f847007d1fa2b8721c0c634dfc925c3d39f168b40e85b4cd2a3c9 2113 apt_0.8.13.2ubuntu4.6.dsc b32c44036f66b0ca651c84204795b08236698c87c3e3383f6a2e7e1f19856498 3397014 apt_0.8.13.2ubuntu4.6.tar.gz Files: 5d8dad4092bc410b1e7284e5c7cf0045 2113 admin important apt_0.8.13.2ubuntu4.6.dsc 92b2b999ecd3bcf4a5b36d3d0fa0c802 3397014 admin important apt_0.8.13.2ubuntu4.6.tar.gz Original-Maintainer: APT Development Team From marc.deslauriers at ubuntu.com Mon Jun 18 12:35:24 2012 From: marc.deslauriers at ubuntu.com (Marc Deslauriers) Date: Mon, 18 Jun 2012 12:35:24 -0000 Subject: [ubuntu/natty-security] libav-extra 4:0.6.6-1ubuntu1 (Accepted) Message-ID: <20120618123524.24898.76314.launchpad@cocoplum.canonical.com> libav-extra (4:0.6.6-1ubuntu1) natty-security; urgency=low * Rebuild against libav security update Date: Wed, 13 Jun 2012 14:57:45 -0400 Changed-By: Marc Deslauriers Maintainer: Ubuntu Developers https://launchpad.net/ubuntu/natty/+source/libav-extra/4:0.6.6-1ubuntu1 -------------- next part -------------- Format: 1.8 Date: Wed, 13 Jun 2012 14:57:45 -0400 Source: libav-extra Binary: libavutil-extra-50 libavcodec-extra-52 libavdevice-extra-52 libavfilter-extra-1 libpostproc-extra-51 libavformat-extra-52 libswscale-extra-0 Architecture: source Version: 4:0.6.6-1ubuntu1 Distribution: natty-security Urgency: low Maintainer: Ubuntu Developers Changed-By: Marc Deslauriers Description: libavcodec-extra-52 - Libav codec library libavdevice-extra-52 - Libav device handling library libavfilter-extra-1 - Libav video postprocessing library libavformat-extra-52 - Libav file format library libavutil-extra-50 - Libav utility library libpostproc-extra-51 - Libav video postprocessing library libswscale-extra-0 - Libav video scaling library Changes: libav-extra (4:0.6.6-1ubuntu1) natty-security; urgency=low . * Rebuild against libav security update Checksums-Sha1: 3948256719d92b063d03f2b54806805f7d336f5b 2791 libav-extra_0.6.6-1ubuntu1.dsc 89fc2047e2cd63af2f9d5f17d7d3c1ac3d7c6447 37527 libav-extra_0.6.6-1ubuntu1.tar.gz Checksums-Sha256: bf868bf5d87c8ca78e2e5c8ef4a9d47212ecdf2fd513dc308332e1fb1446c403 2791 libav-extra_0.6.6-1ubuntu1.dsc 158e38530ed7111b63ca12a7313c63380a7cdd9f08d3c91da12f037e59737523 37527 libav-extra_0.6.6-1ubuntu1.tar.gz Files: 39c81a2d08ead66125e8a302b3311803 2791 libs optional libav-extra_0.6.6-1ubuntu1.dsc 68696f19ae96acab5c963b0073cec301 37527 libs optional libav-extra_0.6.6-1ubuntu1.tar.gz Original-Maintainer: Debian multimedia packages maintainers From marc.deslauriers at ubuntu.com Mon Jun 18 12:35:41 2012 From: marc.deslauriers at ubuntu.com (Marc Deslauriers) Date: Mon, 18 Jun 2012 12:35:41 -0000 Subject: [ubuntu/natty-security] libav 4:0.6.6-0ubuntu0.11.04.1 (Accepted) Message-ID: <20120618123541.24898.61235.launchpad@cocoplum.canonical.com> libav (4:0.6.6-0ubuntu0.11.04.1) natty-security; urgency=low * Update to 0.7.6 to fix multiple security issues. (LP: #1012132) - CVE-2011-3929 - CVE-2011-3936 - CVE-2011-3940 - CVE-2011-3945 - CVE-2011-3947 - CVE-2011-3951 - CVE-2011-3952 - CVE-2012-0850 - CVE-2012-0851 - CVE-2012-0852 - CVE-2012-0853 - CVE-2012-0858 - CVE-2012-0859 - CVE-2012-0947 Date: Tue, 12 Jun 2012 10:26:36 -0400 Changed-By: Marc Deslauriers Maintainer: Ubuntu Developers https://launchpad.net/ubuntu/natty/+source/libav/4:0.6.6-0ubuntu0.11.04.1 -------------- next part -------------- Format: 1.8 Date: Tue, 12 Jun 2012 10:26:36 -0400 Source: libav Binary: ffmpeg ffmpeg-dbg libav-dbg libav-source ffmpeg-doc libav-doc libavutil50 libavcodec52 libavdevice52 libavformat52 libavfilter1 libpostproc51 libswscale0 libavutil-dev libavcodec-dev libavdevice-dev libavformat-dev libavfilter-dev libpostproc-dev libswscale-dev Architecture: source Version: 4:0.6.6-0ubuntu0.11.04.1 Distribution: natty-security Urgency: low Maintainer: Ubuntu Developers Changed-By: Marc Deslauriers Description: ffmpeg - Multimedia player, server, encoder and transcoder ffmpeg-dbg - Debug symbols for Libav related packages ffmpeg-doc - Documentation of the Libav API (transitional package) libav-dbg - Debug symbols for Libav related packages libav-doc - Documentation of the Libav API libav-source - Patched Libav sources libavcodec-dev - Development files for libavcodec libavcodec52 - Libav codec library libavdevice-dev - Development files for libavdevice libavdevice52 - Libav device handling library libavfilter-dev - Development files for libavfilter libavfilter1 - Libav video filtering library libavformat-dev - Development files for libavformat libavformat52 - Libav file format library libavutil-dev - Development files for libavutil libavutil50 - Libav utility library libpostproc-dev - Development files for libpostproc libpostproc51 - Libav video postprocessing library libswscale-dev - Development files for libswscale libswscale0 - Libav video scaling library Launchpad-Bugs-Fixed: 1012132 Changes: libav (4:0.6.6-0ubuntu0.11.04.1) natty-security; urgency=low . * Update to 0.7.6 to fix multiple security issues. (LP: #1012132) - CVE-2011-3929 - CVE-2011-3936 - CVE-2011-3940 - CVE-2011-3945 - CVE-2011-3947 - CVE-2011-3951 - CVE-2011-3952 - CVE-2012-0850 - CVE-2012-0851 - CVE-2012-0852 - CVE-2012-0853 - CVE-2012-0858 - CVE-2012-0859 - CVE-2012-0947 Checksums-Sha1: 78f58ac57f0b16e72658299cc42cace109b03edf 2994 libav_0.6.6-0ubuntu0.11.04.1.dsc 8b4a6394458a799a34544f68241915e1ca434130 4538860 libav_0.6.6.orig.tar.gz bf21cbbaf698dbef24330f82a3f75e0557572428 35842 libav_0.6.6-0ubuntu0.11.04.1.diff.gz Checksums-Sha256: a408188361bbe64477fc011c7801acdd6ebb7f24922271775179c3452e4fe046 2994 libav_0.6.6-0ubuntu0.11.04.1.dsc a0b72aa9e19cdac290af04bcf8157dd3396d5f47b51cb7d671eeeb9c58d78bcf 4538860 libav_0.6.6.orig.tar.gz 0d0e824484904386256cd077561599d5fd49c5fad29317e76206d687c48052e0 35842 libav_0.6.6-0ubuntu0.11.04.1.diff.gz Files: bfdd31643e0ccea0fb3dca787d5b6ba3 2994 libs optional libav_0.6.6-0ubuntu0.11.04.1.dsc 9523de523c162be622d62e58373c1d07 4538860 libs optional libav_0.6.6.orig.tar.gz 753ff4bee20ce4118f68dcb2d5e4068b 35842 libs optional libav_0.6.6-0ubuntu0.11.04.1.diff.gz Original-Maintainer: Debian multimedia packages maintainers From jamie at ubuntu.com Mon Jun 18 15:34:28 2012 From: jamie at ubuntu.com (Jamie Strandboge) Date: Mon, 18 Jun 2012 15:34:28 -0000 Subject: [ubuntu/natty-security] raptor 1.4.21-2ubuntu0.1 (Accepted) Message-ID: <20120618153428.9075.17468.launchpad@cocoplum.canonical.com> raptor (1.4.21-2ubuntu0.1) natty-security; urgency=low * SECURITY UPDATE: Fix XML External Entity (XXE) attack - debian/patches/02-CVE-2012-0037.patch: Enforce entity loading policy in raptor_libxml_resolveEntity and raptor_libxml_getEntity by checking for file URIs and network URIs. - CVE-2012-0037 Date: Fri, 08 Jun 2012 11:27:50 -0500 Changed-By: Jamie Strandboge Maintainer: Ubuntu Developers https://launchpad.net/ubuntu/natty/+source/raptor/1.4.21-2ubuntu0.1 -------------- next part -------------- Format: 1.8 Date: Fri, 08 Jun 2012 11:27:50 -0500 Source: raptor Binary: libraptor1-dev libraptor1 raptor-utils libraptor1-doc libraptor1-dbg Architecture: source Version: 1.4.21-2ubuntu0.1 Distribution: natty-security Urgency: low Maintainer: Ubuntu Developers Changed-By: Jamie Strandboge Description: libraptor1 - Raptor RDF parser and serializer library libraptor1-dbg - Raptor RDF parser and serializer library - debugging symbols libraptor1-dev - Raptor RDF parser and serializer development libraries and header libraptor1-doc - Documentation for the Raptor RDF parser and serializer library raptor-utils - Raptor RDF parser and serializer utilities Changes: raptor (1.4.21-2ubuntu0.1) natty-security; urgency=low . * SECURITY UPDATE: Fix XML External Entity (XXE) attack - debian/patches/02-CVE-2012-0037.patch: Enforce entity loading policy in raptor_libxml_resolveEntity and raptor_libxml_getEntity by checking for file URIs and network URIs. - CVE-2012-0037 Checksums-Sha1: f6bee192e046f9509d8c8b74b99823c12d5891c0 1911 raptor_1.4.21-2ubuntu0.1.dsc aeaf2022e3ebb9313b14e80d005d3097187a80c6 9696 raptor_1.4.21-2ubuntu0.1.diff.gz Checksums-Sha256: 30f419865da683bd2e54e58f5232694991fcda84739a4c9c36897c04413b2d52 1911 raptor_1.4.21-2ubuntu0.1.dsc b27e38ba9d4dce3c95b220c754ed82b64dc5eae7346ebbd63db785dd05f67770 9696 raptor_1.4.21-2ubuntu0.1.diff.gz Files: 3557e4b4d838b395b7fbf7993a366b83 1911 devel optional raptor_1.4.21-2ubuntu0.1.dsc 01eedd98414eabd211f5234f9dddecf4 9696 devel optional raptor_1.4.21-2ubuntu0.1.diff.gz Original-Maintainer: Dave Beckett From sbeattie at ubuntu.com Tue Jun 19 05:04:04 2012 From: sbeattie at ubuntu.com (Steve Beattie) Date: Tue, 19 Jun 2012 05:04:04 -0000 Subject: [ubuntu/natty-security] openconnect 2.25-0.1+squeeze1build0.11.04.1 (Accepted) Message-ID: <20120619050404.2385.21626.launchpad@cocoplum.canonical.com> openconnect (2.25-0.1+squeeze1build0.11.04.1) natty-security; urgency=low * fake sync from Debian openconnect (2.25-0.1+squeeze1) stable-security; urgency=high * Apply patch from upstream to fix buffer overflow (CVE-2012-3291) Date: Mon, 18 Jun 2012 16:53:32 -0700 Changed-By: Steve Beattie Maintainer: Mike Miller https://launchpad.net/ubuntu/natty/+source/openconnect/2.25-0.1+squeeze1build0.11.04.1 -------------- next part -------------- Format: 1.8 Date: Mon, 18 Jun 2012 16:53:32 -0700 Source: openconnect Binary: openconnect Architecture: source Version: 2.25-0.1+squeeze1build0.11.04.1 Distribution: natty-security Urgency: high Maintainer: Mike Miller Changed-By: Steve Beattie Description: openconnect - Open client for Cisco AnyConnect VPN Changes: openconnect (2.25-0.1+squeeze1build0.11.04.1) natty-security; urgency=low . * fake sync from Debian . openconnect (2.25-0.1+squeeze1) stable-security; urgency=high . * Apply patch from upstream to fix buffer overflow (CVE-2012-3291) Checksums-Sha1: 44df6eaa40221bcf0cb5a09027077ce1acfaec6e 1857 openconnect_2.25-0.1+squeeze1build0.11.04.1.dsc 0a042bab158a2375bc33deed15bc3e308c1ca371 2726 openconnect_2.25-0.1+squeeze1build0.11.04.1.diff.gz Checksums-Sha256: feebfcf592e8a5906072288d8c6e50a22420c258b30cf01f97c6d64fbc07bf8c 1857 openconnect_2.25-0.1+squeeze1build0.11.04.1.dsc 05a01d0af3a259fa9d10010565e7e65aabcff021220bb0f4b07e7dfcabbe8deb 2726 openconnect_2.25-0.1+squeeze1build0.11.04.1.diff.gz Files: 0c79a036b73bce61a744ab05a2700b93 1857 net optional openconnect_2.25-0.1+squeeze1build0.11.04.1.dsc e0c67fe16594c59bc93cc5a6e7d18ec9 2726 net optional openconnect_2.25-0.1+squeeze1build0.11.04.1.diff.gz From marc.deslauriers at ubuntu.com Tue Jun 19 14:35:06 2012 From: marc.deslauriers at ubuntu.com (Marc Deslauriers) Date: Tue, 19 Jun 2012 14:35:06 -0000 Subject: [ubuntu/natty-security] php5, php5_5.3.5-1ubuntu7.10_powerpc_translations.tar.gz, php5_5.3.5-1ubuntu7.10_i386_translations.tar.gz, php5_5.3.5-1ubuntu7.10_amd64_translations.tar.gz, php5_5.3.5-1ubuntu7.10_armel_translations.tar.gz 5.3.5-1ubuntu7.10 (Accepted) Message-ID: <20120619143506.26705.99965.launchpad@cocoplum.canonical.com> php5 (5.3.5-1ubuntu7.10) natty-security; urgency=low * SECURITY UPDATE: denial of service via invalid tidy objects - debian/patches/CVE-2012-0781.patch: track initialization in ext/tidy/tidy.c, added tests to ext/tidy/tests/004.phpt, ext/tidy/tests/bug54682.phpt. - CVE-2012-0781 * SECURITY UPDATE: denial of service or possible directory traversal via invalid filename. - debian/patches/CVE-2012-1172.patch: ensure brackets get closed in main/rfc1867.c, add test to tests/basic/bug55500.phpt. - CVE-2012-1172 * SECURITY UPDATE: password truncation via invalid byte - debian/patches/CVE-2012-2143.patch: improve logic in ext/standard/crypt_freesec.c, add test to ext/standard/tests/strings/crypt_chars.phpt. - CVE-2012-2143 * SECURITY UPDATE: crypto() empty salt string issue - debian/patches/{php_crypt_revamped,use_system_crypt_fixes}.patch: Return fail string on invalid Blowfish salt rounds, fix regression when the salt is empty. - CVE-2012-2317 * SECURITY UPDATE: improve php5-cgi query string parameter parsing - debian/patches/CVE-2012-233x.patch: improve parsing in sapi/cgi/cgi_main.c. - CVE-2012-2335 - CVE-2012-2336 * SECURITY UPDATE: phar extension heap overflow - debian/patches/CVE-2012-2386.patch: check for overflow in ext/phar/tar.c. - CVE-2012-2386 Date: Tue, 12 Jun 2012 15:38:21 -0400 Changed-By: Marc Deslauriers Maintainer: Ubuntu Developers https://launchpad.net/ubuntu/natty/+source/php5/5.3.5-1ubuntu7.10 -------------- next part -------------- Format: 1.8 Date: Tue, 12 Jun 2012 15:38:21 -0400 Source: php5 Binary: php5 php5-common libapache2-mod-php5 libapache2-mod-php5filter php5-cgi php5-cli php5-fpm php5-dev php5-dbg php-pear php5-curl php5-enchant php5-gd php5-gmp php5-intl php5-ldap php5-mysql php5-odbc php5-pgsql php5-pspell php5-recode php5-snmp php5-sqlite php5-sybase php5-tidy php5-xmlrpc php5-xsl Architecture: source Version: 5.3.5-1ubuntu7.10 Distribution: natty-security Urgency: low Maintainer: Ubuntu Developers Changed-By: Marc Deslauriers Description: libapache2-mod-php5 - server-side, HTML-embedded scripting language (Apache 2 module) libapache2-mod-php5filter - server-side, HTML-embedded scripting language (apache 2 filter mo php-pear - PEAR - PHP Extension and Application Repository php5 - server-side, HTML-embedded scripting language (metapackage) php5-cgi - server-side, HTML-embedded scripting language (CGI binary) php5-cli - command-line interpreter for the php5 scripting language php5-common - Common files for packages built from the php5 source php5-curl - CURL module for php5 php5-dbg - Debug symbols for PHP5 php5-dev - Files for PHP5 module development php5-enchant - Enchant module for php5 php5-fpm - server-side, HTML-embedded scripting language (FPM-CGI binary) php5-gd - GD module for php5 php5-gmp - GMP module for php5 php5-intl - internationalisation module for php5 php5-ldap - LDAP module for php5 php5-mysql - MySQL module for php5 php5-odbc - ODBC module for php5 php5-pgsql - PostgreSQL module for php5 php5-pspell - pspell module for php5 php5-recode - recode module for php5 php5-snmp - SNMP module for php5 php5-sqlite - SQLite module for php5 php5-sybase - Sybase / MS SQL Server module for php5 php5-tidy - tidy module for php5 php5-xmlrpc - XML-RPC module for php5 php5-xsl - XSL module for php5 Changes: php5 (5.3.5-1ubuntu7.10) natty-security; urgency=low . * SECURITY UPDATE: denial of service via invalid tidy objects - debian/patches/CVE-2012-0781.patch: track initialization in ext/tidy/tidy.c, added tests to ext/tidy/tests/004.phpt, ext/tidy/tests/bug54682.phpt. - CVE-2012-0781 * SECURITY UPDATE: denial of service or possible directory traversal via invalid filename. - debian/patches/CVE-2012-1172.patch: ensure brackets get closed in main/rfc1867.c, add test to tests/basic/bug55500.phpt. - CVE-2012-1172 * SECURITY UPDATE: password truncation via invalid byte - debian/patches/CVE-2012-2143.patch: improve logic in ext/standard/crypt_freesec.c, add test to ext/standard/tests/strings/crypt_chars.phpt. - CVE-2012-2143 * SECURITY UPDATE: crypto() empty salt string issue - debian/patches/{php_crypt_revamped,use_system_crypt_fixes}.patch: Return fail string on invalid Blowfish salt rounds, fix regression when the salt is empty. - CVE-2012-2317 * SECURITY UPDATE: improve php5-cgi query string parameter parsing - debian/patches/CVE-2012-233x.patch: improve parsing in sapi/cgi/cgi_main.c. - CVE-2012-2335 - CVE-2012-2336 * SECURITY UPDATE: phar extension heap overflow - debian/patches/CVE-2012-2386.patch: check for overflow in ext/phar/tar.c. - CVE-2012-2386 Checksums-Sha1: 608ab0c6944e9150b8cc5dc493908e8a71c7e1a3 3272 php5_5.3.5-1ubuntu7.10.dsc c2e5bc5e33e66f913435fc97817497b7f7781741 245035 php5_5.3.5-1ubuntu7.10.diff.gz Checksums-Sha256: 3794ba8c728480af423929be9f6df533adca8e17ba820fea56d22362acb533ce 3272 php5_5.3.5-1ubuntu7.10.dsc 9ea2f061add3800cca0560b1679978d400dd0ea60b726d766f9a1e447a87b7f2 245035 php5_5.3.5-1ubuntu7.10.diff.gz Files: f4b259eef33e77cb039daf46b2b3dbcf 3272 php optional php5_5.3.5-1ubuntu7.10.dsc 5d2269a2d0fa0fcdac94c0a06343069c 245035 php optional php5_5.3.5-1ubuntu7.10.diff.gz Original-Maintainer: Debian PHP Maintainers From marc.deslauriers at ubuntu.com Tue Jun 19 18:04:45 2012 From: marc.deslauriers at ubuntu.com (Marc Deslauriers) Date: Tue, 19 Jun 2012 18:04:45 -0000 Subject: [ubuntu/natty-security] clamav_0.97.5+dfsg-1ubuntu0.11.04.1_amd64_translations.tar.gz, clamav_0.97.5+dfsg-1ubuntu0.11.04.1_i386_translations.tar.gz, clamav, clamav_0.97.5+dfsg-1ubuntu0.11.04.1_powerpc_translations.tar.gz, clamav_0.97.5+dfsg-1ubuntu0.11.04.1_armel_translations.tar.gz 0.97.5+dfsg-1ubuntu0.11.04.1 (Accepted) Message-ID: <20120619180445.27417.56629.launchpad@cocoplum.canonical.com> clamav (0.97.5+dfsg-1ubuntu0.11.04.1) natty-security; urgency=low * SECURITY UPDATE: Updated to 0.97.5 to fix multiple security issues with malformed files. - CVE-2012-1457 - CVE-2012-1458 - CVE-2012-1459 Date: Mon, 18 Jun 2012 09:37:17 -0400 Changed-By: Marc Deslauriers Maintainer: Ubuntu Developers https://launchpad.net/ubuntu/natty/+source/clamav/0.97.5+dfsg-1ubuntu0.11.04.1 -------------- next part -------------- Format: 1.8 Date: Mon, 18 Jun 2012 09:37:17 -0400 Source: clamav Binary: clamav-base clamav-docs clamav-dbg clamav libclamav-dev libclamav6 clamav-daemon clamav-testfiles clamav-freshclam clamav-milter Architecture: source Version: 0.97.5+dfsg-1ubuntu0.11.04.1 Distribution: natty-security Urgency: low Maintainer: Ubuntu Developers Changed-By: Marc Deslauriers Description: clamav - anti-virus utility for Unix - command-line interface clamav-base - anti-virus utility for Unix - base package clamav-daemon - anti-virus utility for Unix - scanner daemon clamav-dbg - debug symbols for ClamAV clamav-docs - anti-virus utility for Unix - documentation clamav-freshclam - anti-virus utility for Unix - virus database update utility clamav-milter - anti-virus utility for Unix - sendmail integration clamav-testfiles - anti-virus utility for Unix - test files libclamav-dev - anti-virus utility for Unix - development files libclamav6 - anti-virus utility for Unix - library Changes: clamav (0.97.5+dfsg-1ubuntu0.11.04.1) natty-security; urgency=low . * SECURITY UPDATE: Updated to 0.97.5 to fix multiple security issues with malformed files. - CVE-2012-1457 - CVE-2012-1458 - CVE-2012-1459 Checksums-Sha1: ccc19089c365bccfda3659097c6297df0942380e 2354 clamav_0.97.5+dfsg-1ubuntu0.11.04.1.dsc 25730c4f012e27069d170e8cfb213af6c0af9595 306637 clamav_0.97.5+dfsg-1ubuntu0.11.04.1.diff.gz Checksums-Sha256: 7ef8bb29d15e08ca5fcb70862e12e45b1e3313707cfe0d9fe01460987659dc8b 2354 clamav_0.97.5+dfsg-1ubuntu0.11.04.1.dsc 966cbd0739cb451be9c70f655c7ed256391cf231af103475c3a4d28c1134b73b 306637 clamav_0.97.5+dfsg-1ubuntu0.11.04.1.diff.gz Files: 48beea121f04c91d375e6300f700c157 2354 utils optional clamav_0.97.5+dfsg-1ubuntu0.11.04.1.dsc 32b53b29c6674bbcba874a36be0279e4 306637 utils optional clamav_0.97.5+dfsg-1ubuntu0.11.04.1.diff.gz Original-Maintainer: ClamAV Team From marc.deslauriers at ubuntu.com Wed Jun 20 02:35:07 2012 From: marc.deslauriers at ubuntu.com (Marc Deslauriers) Date: Wed, 20 Jun 2012 02:35:07 -0000 Subject: [ubuntu/natty-security] clamav_0.97.5+dfsg-1ubuntu0.11.04.2_powerpc_translations.tar.gz, clamav_0.97.5+dfsg-1ubuntu0.11.04.2_amd64_translations.tar.gz, clamav, clamav_0.97.5+dfsg-1ubuntu0.11.04.2_i386_translations.tar.gz, clamav_0.97.5+dfsg-1ubuntu0.11.04.2_armel_translations.tar.gz 0.97.5+dfsg-1ubuntu0.11.04.2 (Accepted) Message-ID: <20120620023507.9671.85138.launchpad@cocoplum.canonical.com> clamav (0.97.5+dfsg-1ubuntu0.11.04.2) natty-security; urgency=low * SECURITY REGRESSION: Fix installation issue. (LP: #1015337) - debian/clamav-base.postinst.in: Since we no longer ship daily.cvd and main.cvd anymore, don't try and install them in the postinst. Date: Tue, 19 Jun 2012 20:08:18 -0400 Changed-By: Marc Deslauriers Maintainer: Ubuntu Developers https://launchpad.net/ubuntu/natty/+source/clamav/0.97.5+dfsg-1ubuntu0.11.04.2 -------------- next part -------------- Format: 1.8 Date: Tue, 19 Jun 2012 20:08:18 -0400 Source: clamav Binary: clamav-base clamav-docs clamav-dbg clamav libclamav-dev libclamav6 clamav-daemon clamav-testfiles clamav-freshclam clamav-milter Architecture: source Version: 0.97.5+dfsg-1ubuntu0.11.04.2 Distribution: natty-security Urgency: low Maintainer: Ubuntu Developers Changed-By: Marc Deslauriers Description: clamav - anti-virus utility for Unix - command-line interface clamav-base - anti-virus utility for Unix - base package clamav-daemon - anti-virus utility for Unix - scanner daemon clamav-dbg - debug symbols for ClamAV clamav-docs - anti-virus utility for Unix - documentation clamav-freshclam - anti-virus utility for Unix - virus database update utility clamav-milter - anti-virus utility for Unix - sendmail integration clamav-testfiles - anti-virus utility for Unix - test files libclamav-dev - anti-virus utility for Unix - development files libclamav6 - anti-virus utility for Unix - library Launchpad-Bugs-Fixed: 1015337 Changes: clamav (0.97.5+dfsg-1ubuntu0.11.04.2) natty-security; urgency=low . * SECURITY REGRESSION: Fix installation issue. (LP: #1015337) - debian/clamav-base.postinst.in: Since we no longer ship daily.cvd and main.cvd anymore, don't try and install them in the postinst. Checksums-Sha1: 4a3c759ad032785922c836fbe84ebeb1bcdfb32a 2354 clamav_0.97.5+dfsg-1ubuntu0.11.04.2.dsc 2d31172740864eef089785b91119d52f3fe27b3e 306682 clamav_0.97.5+dfsg-1ubuntu0.11.04.2.diff.gz Checksums-Sha256: bec9bc1c367ecf4bd38651fa4b89fbd8a4d47eb9b5768078286646df69abadf4 2354 clamav_0.97.5+dfsg-1ubuntu0.11.04.2.dsc 6c8c37f62442589b8e3e9c205719b1b8ccfa7a743f531b80fe71a0ba307be19b 306682 clamav_0.97.5+dfsg-1ubuntu0.11.04.2.diff.gz Files: a68cb0c867b8f37dfc50f0b2e83f039a 2354 utils optional clamav_0.97.5+dfsg-1ubuntu0.11.04.2.dsc 330a1a6b344e4bc708ea16f77300d219 306682 utils optional clamav_0.97.5+dfsg-1ubuntu0.11.04.2.diff.gz Original-Maintainer: ClamAV Team From launchpad at micahscomputing.com Wed Jun 20 10:17:29 2012 From: launchpad at micahscomputing.com (Micah Gersten) Date: Wed, 20 Jun 2012 10:17:29 -0000 Subject: [ubuntu/natty-security] firefox 13.0.1+build1-0ubuntu0.11.04.1 (Accepted) Message-ID: <20120620101729.5340.86434.launchpad@ackee.canonical.com> firefox (13.0.1+build1-0ubuntu0.11.04.1) natty-security; urgency=low * New upstream stable release (FIREFOX_13_0_1_BUILD1) - see LP: #1013425 for USN information Date: 2012-06-15 05:01:49.830585+00:00 Changed-By: Micah Gersten https://launchpad.net/ubuntu/natty/+source/firefox/13.0.1+build1-0ubuntu0.11.04.1 -------------- next part -------------- Sorry, changesfile not available. From launchpad at micahscomputing.com Wed Jun 27 02:50:45 2012 From: launchpad at micahscomputing.com (Micah Gersten) Date: Wed, 27 Jun 2012 02:50:45 -0000 Subject: [ubuntu/natty-security] unity-2d 3.8.4.1-0ubuntu1.2 (Accepted) Message-ID: <20120627025045.26067.13093.launchpad@ackee.canonical.com> unity-2d (3.8.4.1-0ubuntu1.2) natty-security; urgency=low [ Chris Coulson ] * Set the correct startup timestamp when launching applications; This an additional fix for the issue of Firefox/Thunderbird changing the way that they handle windows based on timestamps (LP: #1016386) - update launcher/UnityApplications/launcherapplication.cpp Date: 2012-06-25 18:36:45.419141+00:00 Changed-By: Micah Gersten https://launchpad.net/ubuntu/natty/+source/unity-2d/3.8.4.1-0ubuntu1.2 -------------- next part -------------- Sorry, changesfile not available. From launchpad at micahscomputing.com Wed Jun 27 02:51:29 2012 From: launchpad at micahscomputing.com (Micah Gersten) Date: Wed, 27 Jun 2012 02:51:29 -0000 Subject: [ubuntu/natty-security] thunderbird 13.0.1+build1-0ubuntu0.11.04.1 (Accepted) Message-ID: <20120627025129.26067.3100.launchpad@ackee.canonical.com> thunderbird (13.0.1+build1-0ubuntu0.11.04.1) natty-security; urgency=low * New upstream stable release (THUNDERBIRD_13_0_1_BUILD1) - see LP: #1007556 for USN information * Update globalmenu-extension to v3.2.3 - Reduce our memory footprint a bit, which wasn't really a lot anyway - Avoid the use of the component manager for accessing commonly used services, where "commonly used" means "accessed when building every menu item". This should save some CPU cycles when building or refreshing menus - Try to recycle menuitems when they are removed from a menu by adding contiguous blocks of removed items to a "free list" which is emptied asynchronously, and reusing the items in this list when new items are added in place of the removed items. This means that menus which fully refresh on opening no longer alter the menu structure, but instead just update properties on existing nodes. This has a few benefits: + With no layout changes, unity-panel-service doesn't request the entire menu structure, which significantly reduces dbus traffic and makes it much faster to refresh the menu contents + The size of the menu doesn't change when it is refreshed, which eliminates the flicker that used to occur when opening some menus - Remove all use of the global observer service for sending our own internal notifications around - Get rid of a static initializer - Don't support older than Thunderbird 11 - Fix some GError leaks - Hide the internal menu when creating a native menu, rather than waiting for confirmation that the native menu is registered successfully. We don't try to create a native menu if we don't find a menu service to register the menu with anyway - Keep menu contents updated whilst the menu is open, rather than just whilst it is opening - Fix LP: #915888 - Formatting toolbar menu entry is inverted * Refresh build-depends: - Bump minimum GTK version to 2.14 as we build with GIO support - Add minimum requirement for glib (2.18) - Drop libidl-dev, this doesn't appear to be needed now - Bump minimum NSPR version to 4.9.0 for --enable-system-nspr builds - Bump minimum sqlite version to 3.7.10 for --enable-system-sqlite builds - Bump minimum NSS version to 3.13.2 for --enable-system-nss builds * Clean up the file exclude list and add comments for excluded files - update debian/build/create-tarball.py * Make it easy to run Thunderbird in valgrind for builds that are compiled with explicit valgrind support - update debian/thunderbird.sh.in * Refresh patches: - update debian/patches/revert-bmo621446-investigation.patch - update debian/patches/dont-include-hyphenation-patterns.patch * Drop patches fixed upstream: - remove debian/patches/use-menubar-text-colour-on-tabbar.patch - remove debian/patches/no-sps-profiler-on-unsupported-archs.patch - remove debian/patches/distro-locale-searchplugins.patch - remove debian/patches/avoid-dbus-roundtrip-for-httpchannel.patch - update debian/patches/series * Bump debhelper compat to 7 - update debian/apport/blacklist.in - update debian/appoty/source_thunderbird.py.in - update debian/compat - update debian/config/mozconfig.in - update debian/control.in - update debian/rules - update debian/thunderbird-dev.install.in - update debian/thunderbird-dev.links.in - update debian/thunderbird-globalmenu.dirs.in - update debian/thunderbird-gnome-support.install.in - update debian/thunderbird.dirs.in - update debian/thunderbird.install.in - update debian/thunderbird.links.in - update debian/thunderbird.lintian-overrides.in - update debian/thunderbird.sh.in * Use "general.useragent.locale" to select the searchengine locale - update debian/patches/distro-locale-searchplugins.patch - add debian/patches/dont-override-general-useragent-locale.patch - update debian/patches/series * Drop no-dynamic-nss-softokn.patch. This patch has no documentation and it doesn't look like it's actually useful for anything * Apport hook improvements: - Add support for reporting preference defaults that are set by extensions - When reporting preferences, record the source of each preference - Report plugin packages for plugins that are installed with the package manager - Add some addon manager related prefs to the whitelist - Display additional metadata in the extensions report - Take "default-to-compatible" in to account when determining whether the user is running incompatible addons - Attach submitted crash ID's to bug reports - Report if files in the profile folder have broken permissions * Update compare-locales to 0.9.5 * Fix for NSS libs not being signed, breaking FIPS - update debian/rules * Update StartupWMClass to the correct name - update debian/thunderbird.desktop.in - update debian/rules Date: 2012-06-15 07:02:32.631806+00:00 Changed-By: Chris Coulson Signed-By: Micah Gersten https://launchpad.net/ubuntu/natty/+source/thunderbird/13.0.1+build1-0ubuntu0.11.04.1 -------------- next part -------------- Sorry, changesfile not available. From launchpad at micahscomputing.com Wed Jun 27 02:51:34 2012 From: launchpad at micahscomputing.com (Micah Gersten) Date: Wed, 27 Jun 2012 02:51:34 -0000 Subject: [ubuntu/natty-security] enigmail 2:1.4.2-0ubuntu0.11.04.1 (Accepted) Message-ID: <20120627025134.26067.88902.launchpad@ackee.canonical.com> enigmail (2:1.4.2-0ubuntu0.11.04.1) natty-security; urgency=low * New upstream release v1.4.2 - LP: #1007556 Date: 2012-06-06 08:56:19.420654+00:00 Changed-By: Chris Coulson Signed-By: Micah Gersten https://launchpad.net/ubuntu/natty/+source/enigmail/2:1.4.2-0ubuntu0.11.04.1 -------------- next part -------------- Sorry, changesfile not available. From launchpad at micahscomputing.com Wed Jun 27 02:51:41 2012 From: launchpad at micahscomputing.com (Micah Gersten) Date: Wed, 27 Jun 2012 02:51:41 -0000 Subject: [ubuntu/natty-security] lightning-extension 1.5~b2+build1-0ubuntu0.11.04.1 (Accepted) Message-ID: <20120627025141.26067.79560.launchpad@ackee.canonical.com> lightning-extension (1.5~b2+build1-0ubuntu0.11.04.1) natty-security; urgency=low * New upstream release from the beta channel (CALENDAR_1_5b2_BUILD1) - LP: #1007556 * fix LP: #996817 - Add a transitional package to remove the old lightning-extension package which still has files installed in /usr/lib/thunderbird/extensions - update debian/control Date: 2012-06-08 06:01:22.612509+00:00 Changed-By: Micah Gersten https://launchpad.net/ubuntu/natty/+source/lightning-extension/1.5~b2+build1-0ubuntu0.11.04.1 -------------- next part -------------- Sorry, changesfile not available. From marc.deslauriers at canonical.com Wed Jun 27 12:45:19 2012 From: marc.deslauriers at canonical.com (Marc Deslauriers) Date: Wed, 27 Jun 2012 12:45:19 -0000 Subject: [ubuntu/natty-security] network-manager 0.8.4~git.20110319t175609.d14809b-0ubuntu3.1 (Accepted) Message-ID: <20120627124519.7142.47512.launchpad@ackee.canonical.com> network-manager (0.8.4~git.20110319t175609.d14809b-0ubuntu3.1) natty-security; urgency=low * SECURITY UPDATE: Insecure WPA AdHoc network creation (LP: #905748) - debian/patches/CVE-2012-2736.patch: disable WPA-secured adhoc wireless networks in libnm-util/nm-utils.c, src/nm-device-wifi.c, src/system-settings/nm-sysconfig-settings.c. - CVE-2012-2736 Date: 2012-06-22 18:11:06.865592+00:00 Changed-By: Marc Deslauriers https://launchpad.net/ubuntu/natty/+source/network-manager/0.8.4~git.20110319t175609.d14809b-0ubuntu3.1 -------------- next part -------------- Sorry, changesfile not available. From marc.deslauriers at ubuntu.com Wed Jun 27 13:33:30 2012 From: marc.deslauriers at ubuntu.com (Marc Deslauriers) Date: Wed, 27 Jun 2012 13:33:30 -0000 Subject: [ubuntu/natty-security] network-manager-applet_0.8.4~git.20110318t152954.9c4c9a0-0ubuntu1.1_amd64_translations.tar.gz, network-manager-applet_0.8.4~git.20110318t152954.9c4c9a0-0ubuntu1.1_powerpc_translations.tar.gz, network-manager-applet_0.8.4~git.20110318t152954.9c4c9a0-0ubuntu1.1_i386_translations.tar.gz, network-manager-applet_0.8.4~git.20110318t152954.9c4c9a0-0ubuntu1.1_armel_translations.tar.gz, network-manager-applet 0.8.4~git.20110318t152954.9c4c9a0-0ubuntu1.1 (Accepted) Message-ID: <20120627133330.4572.96672.launchpad@cocoplum.canonical.com> network-manager-applet (0.8.4~git.20110318t152954.9c4c9a0-0ubuntu1.1) natty-security; urgency=low * SECURITY UPDATE: Insecure WPA AdHoc network creation (LP: #905748) - debian/patches/CVE-2012-2736.patch: disable WPA-secured adhoc wireless networks. - CVE-2012-2736 Date: Fri, 22 Jun 2012 08:48:31 -0400 Changed-By: Marc Deslauriers Maintainer: Ubuntu Developers https://launchpad.net/ubuntu/natty/+source/network-manager-applet/0.8.4~git.20110318t152954.9c4c9a0-0ubuntu1.1 -------------- next part -------------- Format: 1.8 Date: Fri, 22 Jun 2012 08:48:31 -0400 Source: network-manager-applet Binary: network-manager-gnome Architecture: source Version: 0.8.4~git.20110318t152954.9c4c9a0-0ubuntu1.1 Distribution: natty-security Urgency: low Maintainer: Ubuntu Developers Changed-By: Marc Deslauriers Description: network-manager-gnome - network management framework (GNOME frontend) Launchpad-Bugs-Fixed: 905748 Changes: network-manager-applet (0.8.4~git.20110318t152954.9c4c9a0-0ubuntu1.1) natty-security; urgency=low . * SECURITY UPDATE: Insecure WPA AdHoc network creation (LP: #905748) - debian/patches/CVE-2012-2736.patch: disable WPA-secured adhoc wireless networks. - CVE-2012-2736 Checksums-Sha1: 7ccf09f90061f7a2cda9e500b6a0c5476a10c6e8 2506 network-manager-applet_0.8.4~git.20110318t152954.9c4c9a0-0ubuntu1.1.dsc d6e7dac7c122fb97f6d99e55b0019ae93c621c01 59593 network-manager-applet_0.8.4~git.20110318t152954.9c4c9a0-0ubuntu1.1.diff.gz Checksums-Sha256: ca50898123f6911c3eb95c6f0b1c2a1c65b03ba0eabda84dfdfe92dbad18962b 2506 network-manager-applet_0.8.4~git.20110318t152954.9c4c9a0-0ubuntu1.1.dsc 69df8b4b3df68bc24d2122f9da00d090fa387b0e79409e47deb8a6bc3a434d56 59593 network-manager-applet_0.8.4~git.20110318t152954.9c4c9a0-0ubuntu1.1.diff.gz Files: ccc8acf85889a52894780cf991577dd5 2506 gnome optional network-manager-applet_0.8.4~git.20110318t152954.9c4c9a0-0ubuntu1.1.dsc 2e90440312424e50c1757f60404a9c23 59593 gnome optional network-manager-applet_0.8.4~git.20110318t152954.9c4c9a0-0ubuntu1.1.diff.gz From adconrad at 0c3.net Thu Jun 28 16:39:49 2012 From: adconrad at 0c3.net (Adam Conrad) Date: Thu, 28 Jun 2012 16:39:49 -0000 Subject: [ubuntu/natty-updates] linux 2.6.38-15.61 (Accepted) Message-ID: <20120628163949.563.61197.launchpad@ackee.canonical.com> linux (2.6.38-15.61) natty-proposed; urgency=low [Luis Henriques] * Release Tracking Bug - LP: #1012033 [ Herton Ronaldo Krzesinski ] * SAUCE: async_populate_rootfs: fix build warnings - LP: #1003417 [ Upstream Kernel Changes ] * dl2k: Clean up rio_ioctl - CVE-2012-2313 * hfsplus: Fix potential buffer overflows - CVE-2012-2319 * Avoid reading past buffer when calling GETACL - LP: #1002505 - CVE-2012-2375 * Avoid beyond bounds copy while caching ACL - LP: #1002505 - CVE-2012-2375 * Fix length of buffer copied in __nfs4_get_acl_uncached - LP: #1002505 - CVE-2012-2375 Date: 2012-06-12 19:09:50.040905+00:00 Changed-By: Luis Henriques Signed-By: Adam Conrad https://launchpad.net/ubuntu/natty/+source/linux/2.6.38-15.61 -------------- next part -------------- Sorry, changesfile not available. From adconrad at 0c3.net Thu Jun 28 16:40:07 2012 From: adconrad at 0c3.net (Adam Conrad) Date: Thu, 28 Jun 2012 16:40:07 -0000 Subject: [ubuntu/natty-security] linux 2.6.38-15.61 (Accepted) Message-ID: <20120628164007.563.82346.launchpad@ackee.canonical.com> linux (2.6.38-15.61) natty-proposed; urgency=low [Luis Henriques] * Release Tracking Bug - LP: #1012033 [ Herton Ronaldo Krzesinski ] * SAUCE: async_populate_rootfs: fix build warnings - LP: #1003417 [ Upstream Kernel Changes ] * dl2k: Clean up rio_ioctl - CVE-2012-2313 * hfsplus: Fix potential buffer overflows - CVE-2012-2319 * Avoid reading past buffer when calling GETACL - LP: #1002505 - CVE-2012-2375 * Avoid beyond bounds copy while caching ACL - LP: #1002505 - CVE-2012-2375 * Fix length of buffer copied in __nfs4_get_acl_uncached - LP: #1002505 - CVE-2012-2375 Date: 2012-06-12 19:09:50.040905+00:00 Changed-By: Luis Henriques Signed-By: Adam Conrad https://launchpad.net/ubuntu/natty/+source/linux/2.6.38-15.61 -------------- next part -------------- Sorry, changesfile not available. From adconrad at 0c3.net Thu Jun 28 17:58:19 2012 From: adconrad at 0c3.net (Adam Conrad) Date: Thu, 28 Jun 2012 17:58:19 -0000 Subject: [ubuntu/natty-updates] linux-firmware 1.52.4 (Accepted) Message-ID: <20120628175819.24773.59128.launchpad@ackee.canonical.com> linux-firmware (1.52.4) natty-proposed; urgency=low * no change upload with version difference. Date: 2011-09-13 01:40:11.642657+00:00 Changed-By: Tim Gardner Signed-By: Adam Conrad https://launchpad.net/ubuntu/natty/+source/linux-firmware/1.52.4 -------------- next part -------------- Sorry, changesfile not available. From adconrad at 0c3.net Thu Jun 28 17:58:21 2012 From: adconrad at 0c3.net (Adam Conrad) Date: Thu, 28 Jun 2012 17:58:21 -0000 Subject: [ubuntu/natty-security] linux-firmware 1.52.4 (Accepted) Message-ID: <20120628175821.24773.98178.launchpad@ackee.canonical.com> linux-firmware (1.52.4) natty-proposed; urgency=low * no change upload with version difference. Date: 2011-09-13 01:40:11.642657+00:00 Changed-By: Tim Gardner Signed-By: Adam Conrad https://launchpad.net/ubuntu/natty/+source/linux-firmware/1.52.4 -------------- next part -------------- Sorry, changesfile not available. From marc.deslauriers at ubuntu.com Thu Jun 28 18:05:14 2012 From: marc.deslauriers at ubuntu.com (Marc Deslauriers) Date: Thu, 28 Jun 2012 18:05:14 -0000 Subject: [ubuntu/natty-security] python-crypto 2.1.0-2ubuntu1.1 (Accepted) Message-ID: <20120628180514.10103.61926.launchpad@cocoplum.canonical.com> python-crypto (2.1.0-2ubuntu1.1) natty-security; urgency=low * SECURITY UPDATE: incorrect ElGamal key generation - debian/patches/CVE-2012-2417.patch: generate safe prime numbers in lib/Crypto/PublicKey/ElGamal.py, backport getRandomRange() to lib/Crypto/Util/number.py. - CVE-2012-2417 Date: Wed, 27 Jun 2012 15:24:10 -0400 Changed-By: Marc Deslauriers Maintainer: Ubuntu Developers https://launchpad.net/ubuntu/natty/+source/python-crypto/2.1.0-2ubuntu1.1 -------------- next part -------------- Format: 1.8 Date: Wed, 27 Jun 2012 15:24:10 -0400 Source: python-crypto Binary: python-crypto python-crypto-dbg Architecture: source Version: 2.1.0-2ubuntu1.1 Distribution: natty-security Urgency: low Maintainer: Ubuntu Developers Changed-By: Marc Deslauriers Description: python-crypto - cryptographic algorithms and protocols for Python python-crypto-dbg - cryptographic algorithms and protocols for Python (debug extensio Changes: python-crypto (2.1.0-2ubuntu1.1) natty-security; urgency=low . * SECURITY UPDATE: incorrect ElGamal key generation - debian/patches/CVE-2012-2417.patch: generate safe prime numbers in lib/Crypto/PublicKey/ElGamal.py, backport getRandomRange() to lib/Crypto/Util/number.py. - CVE-2012-2417 Checksums-Sha1: 76f0822ec74f8e7738c4a9a13241c92fd54825d4 2015 python-crypto_2.1.0-2ubuntu1.1.dsc b97f05db4face456547c603b9ddab57a50945764 9218 python-crypto_2.1.0-2ubuntu1.1.diff.gz Checksums-Sha256: d1463d2f092d819c771be858cd6d79ae21064efad32ae650729a812fae6eef52 2015 python-crypto_2.1.0-2ubuntu1.1.dsc cbd3f9233ec28cc0cda694838337a18e721a39eaa6ab9c3368d51f34b001b856 9218 python-crypto_2.1.0-2ubuntu1.1.diff.gz Files: 31216f4ac8239fc434307b6dafbc7947 2015 python optional python-crypto_2.1.0-2ubuntu1.1.dsc ad4fb70f42e748734e3e646a7923ff8e 9218 python optional python-crypto_2.1.0-2ubuntu1.1.diff.gz Original-Maintainer: James Cook From jamie at ubuntu.com Fri Jun 29 15:58:10 2012 From: jamie at ubuntu.com (Jamie Strandboge) Date: Fri, 29 Jun 2012 15:58:10 -0000 Subject: [ubuntu/natty-security] mantis 1.1.8+dfsg-10squeeze2build0.11.04.1 (Accepted) Message-ID: <20120629155810.29754.66603.launchpad@ackee.canonical.com> mantis (1.1.8+dfsg-10squeeze2build0.11.04.1) natty-security; urgency=low * fake sync from Debian mantis (1.1.8+dfsg-10squeeze2) stable-security; urgency=high * Urgency high: Fixes some CVE's - CVE-2011-3578: Added this note as history update. This issue was really fixed in '1.1.8+dfsg-10squeeze1' upload (via 12-Fix-640297-LFI-XSS-injection-bug-action-group-1.diff patch) but there were no CVE ID assigned in that moment, so there are no references to in the changelog. The issue on the Security Tracker was manually updated thanks to Thijs Kinkhorst . - CVE-2012-1118: Array value for $g_private_bug_threshold configuration option allows bypass of access. (Closes: #669924) - CVE-2012-1119: copy/clone bug report action failed to leave an audit trail. (Closes: #669928) - CVE-2012-1120: Delete_bug_threshold/bugnote_allow_user_edit_delete access check bypass. (Closes: #669925) - CVE-2012-1121: mantis 1.1.8 is not affected by this issue. (Closes: #669926) - CVE-2012-1122: Incorrect access checks performed when moving bugs between projects. (Closes: #669927) - CVE-2012-1123: SOAP API null password authentication bypass (Closes: #669930) - CVE-2012-2691: Reporters can update notes of other users by using SOAP API. This bug does not affect mantis package in squeeze. Affected function 'mc_issue_note_update' is not implemented in mantis 1.1.8 version. - CVE-2012-2692: delete_attachments_threshold not checked on attachment deletion. Thanks to David Hicks Date: 2012-06-29 12:36:30.547288+00:00 Changed-By: Jamie Strandboge https://launchpad.net/ubuntu/natty/+source/mantis/1.1.8+dfsg-10squeeze2build0.11.04.1 -------------- next part -------------- Sorry, changesfile not available.