From martin.pitt at ubuntu.com Mon Oct 1 13:20:32 2012 From: martin.pitt at ubuntu.com (Martin Pitt) Date: Mon, 01 Oct 2012 13:20:32 -0000 Subject: [ubuntu/natty-updates] postgresql-8.4 8.4.14-0ubuntu11.04 (Accepted) Message-ID: <20121001132032.28887.70355.launchpad@ackee.canonical.com> postgresql-8.4 (8.4.14-0ubuntu11.04) natty-proposed; urgency=low * New upstream bug fix release: (LP: #1055944) - Fix planner's assignment of executor parameters, and fix executor's rescan logic for CTE plan nodes. These errors could result in wrong answers from queries that scan the same WITH subquery multiple times. - Improve page-splitting decisions in GiST indexes. Multi-column GiST indexes might suffer unexpected bloat due to this error. - Fix cascading privilege revoke to stop if privileges are still held. If we revoke a grant option from some role "X", but "X" still holds that option via a grant from someone else, we should not recursively revoke the corresponding privilege from role(s) "Y" that "X" had granted it to. - Fix handling of SIGFPE when PL/Perl is in use. Perl resets the process's SIGFPE handler to SIG_IGN, which could result in crashes later on. Restore the normal Postgres signal handler after initializing PL/Perl. - Prevent PL/Perl from crashing if a recursive PL/Perl function is redefined while being executed. - Work around possible misoptimization in PL/Perl. Some Linux distributions contain an incorrect version of "pthread.h" that results in incorrect compiled code in PL/Perl, leading to crashes if a PL/Perl function calls another one that throws an error. Date: 2012-09-25 05:40:12.168726+00:00 Changed-By: Martin Pitt https://launchpad.net/ubuntu/natty/+source/postgresql-8.4/8.4.14-0ubuntu11.04 -------------- next part -------------- Sorry, changesfile not available. From marc.deslauriers at canonical.com Mon Oct 1 17:10:31 2012 From: marc.deslauriers at canonical.com (Marc Deslauriers) Date: Mon, 01 Oct 2012 17:10:31 -0000 Subject: [ubuntu/natty-security] software-properties 0.80.9.2 (Accepted) Message-ID: <20121001171031.31200.5338.launchpad@ackee.canonical.com> software-properties (0.80.9.2) natty-security; urgency=low * SECURITY UPDATE: improve gpg key validation to prevent MITM attack (LP: #1016643) - softwareproperties/ppa.py: download gpg key to temporary keyring, and validate using v4 fingerprint before importing to apt keyring. Date: 2012-09-28 13:55:43.361206+00:00 Changed-By: Marc Deslauriers Maintainer: Michael Vogt https://launchpad.net/ubuntu/natty/+source/software-properties/0.80.9.2 -------------- next part -------------- Sorry, changesfile not available. From cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk Mon Oct 1 17:59:16 2012 From: cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk (Ubuntu Archive Robot) Date: Mon, 01 Oct 2012 17:59:16 -0000 Subject: [ubuntu/natty-updates] software-properties 0.80.9.2 (Accepted) Message-ID: <20121001175916.14662.38831.launchpad@ackee.canonical.com> software-properties (0.80.9.2) natty-security; urgency=low * SECURITY UPDATE: improve gpg key validation to prevent MITM attack (LP: #1016643) - softwareproperties/ppa.py: download gpg key to temporary keyring, and validate using v4 fingerprint before importing to apt keyring. Date: 2012-09-28 13:55:43.361206+00:00 Changed-By: Marc Deslauriers Maintainer: Michael Vogt Signed-By: Ubuntu Archive Robot https://launchpad.net/ubuntu/natty/+source/software-properties/0.80.9.2 -------------- next part -------------- Sorry, changesfile not available. From adconrad at 0c3.net Tue Oct 2 02:31:16 2012 From: adconrad at 0c3.net (Adam Conrad) Date: Tue, 02 Oct 2012 02:31:16 -0000 Subject: [ubuntu/natty] vmware-view-client 1.6.0-0ubuntu0.11.04 (Accepted) Message-ID: <20121002023116.14766.83876.launchpad@chaenomeles.canonical.com> vmware-view-client (1.6.0-0ubuntu0.11.04) natty; urgency=low * New upstream release (1.6.0 GA, build 844387) Date: Mon, 01 Oct 2012 20:04:57 -0600 Changed-By: Adam Conrad Maintainer: Adam Conrad https://launchpad.net/ubuntu/natty/+source/vmware-view-client/1.6.0-0ubuntu0.11.04 -------------- next part -------------- Format: 1.8 Date: Mon, 01 Oct 2012 20:04:57 -0600 Source: vmware-view-client Binary: vmware-view-client Architecture: source Version: 1.6.0-0ubuntu0.11.04 Distribution: natty Urgency: low Maintainer: Adam Conrad Changed-By: Adam Conrad Description: vmware-view-client - Deliver rich, personalized virtual desktops with VMware View 5 Changes: vmware-view-client (1.6.0-0ubuntu0.11.04) natty; urgency=low . * New upstream release (1.6.0 GA, build 844387) Checksums-Sha1: 65bd306493efad35bc004cf08617c64922afba72 1402 vmware-view-client_1.6.0-0ubuntu0.11.04.dsc 90070909ac5bc83d96343e08d0273e6daea1b2ff 11686543 vmware-view-client_1.6.0.orig.tar.gz 38bb004be5c1c3c222fd42d682850346edee3c95 12803 vmware-view-client_1.6.0-0ubuntu0.11.04.debian.tar.gz Checksums-Sha256: c5271afd5793e9f76db63fbd761685df2b4f34bec7b4ccb68b12372d4e19c923 1402 vmware-view-client_1.6.0-0ubuntu0.11.04.dsc fc73133d8750bd06ea40d791470971ba2aacb65189c096a330efaa2e9e225703 11686543 vmware-view-client_1.6.0.orig.tar.gz 650dcd93acba46a0ac67b877865cc690493648442fd73092b34c916c3dba1b8b 12803 vmware-view-client_1.6.0-0ubuntu0.11.04.debian.tar.gz Files: a5ddb5750c6aa986db898ff17c4b9a5e 1402 partner/net extra vmware-view-client_1.6.0-0ubuntu0.11.04.dsc 1780f36cd8a9c7a7b6d14d7278ec4524 11686543 partner/net extra vmware-view-client_1.6.0.orig.tar.gz 1637b946990d9807b3a52dbada9d1824 12803 partner/net extra vmware-view-client_1.6.0-0ubuntu0.11.04.debian.tar.gz From sbeattie at ubuntu.com Tue Oct 2 04:15:32 2012 From: sbeattie at ubuntu.com (Steve Beattie) Date: Tue, 02 Oct 2012 04:15:32 -0000 Subject: [ubuntu/natty-security] eglibc 2.13-0ubuntu13.2 (Accepted) Message-ID: <20121002041532.6148.71956.launchpad@ackee.canonical.com> eglibc (2.13-0ubuntu13.2) natty-security; urgency=low * SECURITY UPDATE: buffer overflow in vfprintf handling - debian/patches/any/CVE-2012-3404.patch: Fix allocation when handling positional parameters in printf. - CVE-2012-3404 * SECURITY UPDATE: buffer overflow in vfprintf handling - debian/patches/any/CVE-2012-3405.patch: fix extension of array - CVE-2012-3405 * SECURITY UPDATE: stack buffer overflow in vfprintf handling (LP: #1031301) - debian/patches/any/CVE-2012-3406.patch: switch to malloc when array grows too large to handle via alloca extension - CVE-2012-3406 * SECURITY UPDATE: stdlib strtod integer/buffer overflows - debian/patches/any/CVE-2012-3480.patch: rearrange calculations and modify types to void integer overflows - CVE-2012-3480 Date: 2012-09-21 05:55:23.747218+00:00 Changed-By: Steve Beattie https://launchpad.net/ubuntu/natty/+source/eglibc/2.13-0ubuntu13.2 -------------- next part -------------- Sorry, changesfile not available. From cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk Tue Oct 2 04:59:24 2012 From: cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk (Ubuntu Archive Robot) Date: Tue, 02 Oct 2012 04:59:24 -0000 Subject: [ubuntu/natty-updates] eglibc 2.13-0ubuntu13.2 (Accepted) Message-ID: <20121002045924.20606.72759.launchpad@ackee.canonical.com> eglibc (2.13-0ubuntu13.2) natty-security; urgency=low * SECURITY UPDATE: buffer overflow in vfprintf handling - debian/patches/any/CVE-2012-3404.patch: Fix allocation when handling positional parameters in printf. - CVE-2012-3404 * SECURITY UPDATE: buffer overflow in vfprintf handling - debian/patches/any/CVE-2012-3405.patch: fix extension of array - CVE-2012-3405 * SECURITY UPDATE: stack buffer overflow in vfprintf handling (LP: #1031301) - debian/patches/any/CVE-2012-3406.patch: switch to malloc when array grows too large to handle via alloca extension - CVE-2012-3406 * SECURITY UPDATE: stdlib strtod integer/buffer overflows - debian/patches/any/CVE-2012-3480.patch: rearrange calculations and modify types to void integer overflows - CVE-2012-3480 Date: 2012-09-21 05:55:23.747218+00:00 Changed-By: Steve Beattie Signed-By: Ubuntu Archive Robot https://launchpad.net/ubuntu/natty/+source/eglibc/2.13-0ubuntu13.2 -------------- next part -------------- Sorry, changesfile not available. From marc.deslauriers at canonical.com Tue Oct 2 13:23:18 2012 From: marc.deslauriers at canonical.com (Marc Deslauriers) Date: Tue, 02 Oct 2012 13:23:18 -0000 Subject: [ubuntu/natty-security] qemu-kvm 0.14.0+noroms-0ubuntu4.7 (Accepted) Message-ID: <20121002132318.13569.60473.launchpad@ackee.canonical.com> qemu-kvm (0.14.0+noroms-0ubuntu4.7) natty-security; urgency=low * SECURITY UPDATE: privilege escalation via VT100 sequences - debian/patches/CVE-2012-3515.patch: check bounds in console.c. - CVE-2012-3515 Date: 2012-09-25 15:30:18.102184+00:00 Changed-By: Marc Deslauriers https://launchpad.net/ubuntu/natty/+source/qemu-kvm/0.14.0+noroms-0ubuntu4.7 -------------- next part -------------- Sorry, changesfile not available. From cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk Tue Oct 2 13:59:16 2012 From: cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk (Ubuntu Archive Robot) Date: Tue, 02 Oct 2012 13:59:16 -0000 Subject: [ubuntu/natty-updates] qemu-kvm 0.14.0+noroms-0ubuntu4.7 (Accepted) Message-ID: <20121002135916.25628.40266.launchpad@ackee.canonical.com> qemu-kvm (0.14.0+noroms-0ubuntu4.7) natty-security; urgency=low * SECURITY UPDATE: privilege escalation via VT100 sequences - debian/patches/CVE-2012-3515.patch: check bounds in console.c. - CVE-2012-3515 Date: 2012-09-25 15:30:18.102184+00:00 Changed-By: Marc Deslauriers Signed-By: Ubuntu Archive Robot https://launchpad.net/ubuntu/natty/+source/qemu-kvm/0.14.0+noroms-0ubuntu4.7 -------------- next part -------------- Sorry, changesfile not available. From jamie at ubuntu.com Tue Oct 2 19:28:13 2012 From: jamie at ubuntu.com (Jamie Strandboge) Date: Tue, 02 Oct 2012 19:28:13 -0000 Subject: [ubuntu/natty-security] python2.7 2.7.1-5ubuntu2.2 (Accepted) Message-ID: <20121002192813.31358.64863.launchpad@ackee.canonical.com> python2.7 (2.7.1-5ubuntu2.2) natty-security; urgency=low * SECURITY UPDATE: fix hash randomization DoS - debian/patches/CVE-2012-1150.diff: add -R command-line option and PYTHONHASHSEED environment variable, to provide an opt-in way to protect against denial of service attacks due to hash collisions within the dict and set types. - CVE-2012-1150 * SECURITY UPDATE: xmlrpc: Fix an endless loop in SimpleXMLRPCServer upon malformed POST request - debian/patches/CVE-2012-0845.diff: break if don't receive EOF in Lib/SimpleXMLRPCServer.py - CVE-2012-0845 * SECURITY UPDATE: update urllib and urllib2 for invalid redirections - debian/patches/CVE-2011-1521.diff: only process Location headers for http, https, and ftp - http://bugs.python.org/issue11662 - CVE-2011-1521 * SECURITY UPDATE: fix XSS in SimpleHTTPServer - debian/patches/CVE-2011-4940.diff: add a charset parameter to the Content-type - CVE-2011-4940 * SECURE UPDATE: http://bugs.python.org/issue13512 - debian/patches/CVE-2011-4944.diff: create ~/.pypirc securely - CVE-2011-4944 Date: 2012-09-27 20:50:10.898416+00:00 Changed-By: Jamie Strandboge https://launchpad.net/ubuntu/natty/+source/python2.7/2.7.1-5ubuntu2.2 -------------- next part -------------- Sorry, changesfile not available. From cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk Tue Oct 2 19:59:11 2012 From: cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk (Ubuntu Archive Robot) Date: Tue, 02 Oct 2012 19:59:11 -0000 Subject: [ubuntu/natty-updates] python2.7 2.7.1-5ubuntu2.2 (Accepted) Message-ID: <20121002195911.8243.11727.launchpad@ackee.canonical.com> python2.7 (2.7.1-5ubuntu2.2) natty-security; urgency=low * SECURITY UPDATE: fix hash randomization DoS - debian/patches/CVE-2012-1150.diff: add -R command-line option and PYTHONHASHSEED environment variable, to provide an opt-in way to protect against denial of service attacks due to hash collisions within the dict and set types. - CVE-2012-1150 * SECURITY UPDATE: xmlrpc: Fix an endless loop in SimpleXMLRPCServer upon malformed POST request - debian/patches/CVE-2012-0845.diff: break if don't receive EOF in Lib/SimpleXMLRPCServer.py - CVE-2012-0845 * SECURITY UPDATE: update urllib and urllib2 for invalid redirections - debian/patches/CVE-2011-1521.diff: only process Location headers for http, https, and ftp - http://bugs.python.org/issue11662 - CVE-2011-1521 * SECURITY UPDATE: fix XSS in SimpleHTTPServer - debian/patches/CVE-2011-4940.diff: add a charset parameter to the Content-type - CVE-2011-4940 * SECURE UPDATE: http://bugs.python.org/issue13512 - debian/patches/CVE-2011-4944.diff: create ~/.pypirc securely - CVE-2011-4944 Date: 2012-09-27 20:50:10.898416+00:00 Changed-By: Jamie Strandboge Signed-By: Ubuntu Archive Robot https://launchpad.net/ubuntu/natty/+source/python2.7/2.7.1-5ubuntu2.2 -------------- next part -------------- Sorry, changesfile not available. From marc.deslauriers at canonical.com Tue Oct 2 20:13:16 2012 From: marc.deslauriers at canonical.com (Marc Deslauriers) Date: Tue, 02 Oct 2012 20:13:16 -0000 Subject: [ubuntu/natty-security] devscripts 2.10.69ubuntu2.2 (Accepted) Message-ID: <20121002201316.13715.24889.launchpad@ackee.canonical.com> devscripts (2.10.69ubuntu2.2) natty-security; urgency=low * SECURITY UPDATE: arbitrary code execution via insufficient validation in dscverify - scripts/dscverify.pl: perform better validation. - 22881936e53e6b585d3dc60f3161e9d704c5138d - CVE-2012-2240 * SECURITY UPDATE: arbitrary file deletion via insufficient validation in dget - scripts/dget.pl: strip invalid characters. - 79d27778321f7bb778097cfb7a724ae976fb4fbd - CVE-2012-2241 * SECURITY UPDATE: arbitrary code execution via improper argument escaping in dget - scripts/dget.pl: escape $file better, and call system() with proper arguments. - db49f493baaac2387a4dd76370c1018109e31dfc - CVE-2012-2242 * SECURITY UPDATE: file alteration via TOCTOU in annotate-output - scripts/annotate-output.sh: prevent symlink attack. - 1bbe2163987c53064a4cd57712927f4b06c01032 - CVE-2012-3500 * REGRESSION FIX: improper exit code in CVE-2012-0212 debdiff.pl fix - 252a42d225f489e398f3c0402c1f7d1e9a4451c0 Date: 2012-09-26 19:30:12.063834+00:00 Changed-By: Marc Deslauriers https://launchpad.net/ubuntu/natty/+source/devscripts/2.10.69ubuntu2.2 -------------- next part -------------- Sorry, changesfile not available. From cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk Tue Oct 2 20:59:14 2012 From: cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk (Ubuntu Archive Robot) Date: Tue, 02 Oct 2012 20:59:14 -0000 Subject: [ubuntu/natty-updates] devscripts 2.10.69ubuntu2.2 (Accepted) Message-ID: <20121002205914.26960.84196.launchpad@ackee.canonical.com> devscripts (2.10.69ubuntu2.2) natty-security; urgency=low * SECURITY UPDATE: arbitrary code execution via insufficient validation in dscverify - scripts/dscverify.pl: perform better validation. - 22881936e53e6b585d3dc60f3161e9d704c5138d - CVE-2012-2240 * SECURITY UPDATE: arbitrary file deletion via insufficient validation in dget - scripts/dget.pl: strip invalid characters. - 79d27778321f7bb778097cfb7a724ae976fb4fbd - CVE-2012-2241 * SECURITY UPDATE: arbitrary code execution via improper argument escaping in dget - scripts/dget.pl: escape $file better, and call system() with proper arguments. - db49f493baaac2387a4dd76370c1018109e31dfc - CVE-2012-2242 * SECURITY UPDATE: file alteration via TOCTOU in annotate-output - scripts/annotate-output.sh: prevent symlink attack. - 1bbe2163987c53064a4cd57712927f4b06c01032 - CVE-2012-3500 * REGRESSION FIX: improper exit code in CVE-2012-0212 debdiff.pl fix - 252a42d225f489e398f3c0402c1f7d1e9a4451c0 Date: 2012-09-26 19:30:12.063834+00:00 Changed-By: Marc Deslauriers Signed-By: Ubuntu Archive Robot https://launchpad.net/ubuntu/natty/+source/devscripts/2.10.69ubuntu2.2 -------------- next part -------------- Sorry, changesfile not available. From jamie at ubuntu.com Tue Oct 2 21:12:15 2012 From: jamie at ubuntu.com (Jamie Strandboge) Date: Tue, 02 Oct 2012 21:12:15 -0000 Subject: [ubuntu/natty-security] python-distutils-extra 2.26-2ubuntu0.3 (Accepted) Message-ID: <20121002211215.30652.94795.launchpad@ackee.canonical.com> python-distutils-extra (2.26-2ubuntu0.3) natty-security; urgency=low * Fix installation of symlinks in data/ dir (LP: #770566): - test/auto.py: Add test for installing a symlink which points to a nonexisting target directory/file. This reproduces the gist of the problem. - test/auto.py: Preserve symlinks in copytree() calls, so that we can actually verify that symlinks are preserved properly. - test/auto.py: Drop requirement that diff throws no error messages, as it will complain about the broken symlink. - DistUtilsExtra/auto.py, install_auto: Use os.walk() instead of distutils.filelist.findall() to pick out symlinks, as the latter fails badly with broken symlinks. - DistUtilsExtra/command/build_icons.py: Ignore symbolic links. distutils breaks on them when they point to a nonexisting target, and we handle them in auto.py. - http://bazaar.launchpad.net/~python-distutils-extra-hackers/python-distutils-extra/debian/revision/250 Date: 2012-09-06 03:15:17.337119+00:00 Changed-By: Jamie Strandboge https://launchpad.net/ubuntu/natty/+source/python-distutils-extra/2.26-2ubuntu0.3 -------------- next part -------------- Sorry, changesfile not available. From cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk Tue Oct 2 21:59:14 2012 From: cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk (Ubuntu Archive Robot) Date: Tue, 02 Oct 2012 21:59:14 -0000 Subject: [ubuntu/natty-updates] python-distutils-extra 2.26-2ubuntu0.3 (Accepted) Message-ID: <20121002215914.13167.97064.launchpad@ackee.canonical.com> python-distutils-extra (2.26-2ubuntu0.3) natty-security; urgency=low * Fix installation of symlinks in data/ dir (LP: #770566): - test/auto.py: Add test for installing a symlink which points to a nonexisting target directory/file. This reproduces the gist of the problem. - test/auto.py: Preserve symlinks in copytree() calls, so that we can actually verify that symlinks are preserved properly. - test/auto.py: Drop requirement that diff throws no error messages, as it will complain about the broken symlink. - DistUtilsExtra/auto.py, install_auto: Use os.walk() instead of distutils.filelist.findall() to pick out symlinks, as the latter fails badly with broken symlinks. - DistUtilsExtra/command/build_icons.py: Ignore symbolic links. distutils breaks on them when they point to a nonexisting target, and we handle them in auto.py. - http://bazaar.launchpad.net/~python-distutils-extra-hackers/python-distutils-extra/debian/revision/250 Date: 2012-09-06 03:15:17.337119+00:00 Changed-By: Jamie Strandboge Signed-By: Ubuntu Archive Robot https://launchpad.net/ubuntu/natty/+source/python-distutils-extra/2.26-2ubuntu0.3 -------------- next part -------------- Sorry, changesfile not available. From marc.deslauriers at canonical.com Thu Oct 4 11:47:37 2012 From: marc.deslauriers at canonical.com (Marc Deslauriers) Date: Thu, 04 Oct 2012 11:47:37 -0000 Subject: [ubuntu/natty-security] dbus 1.4.6-1ubuntu6.4 (Accepted) Message-ID: <20121004114737.13136.79857.launchpad@ackee.canonical.com> dbus (1.4.6-1ubuntu6.4) natty-security; urgency=low * REGRESSION FIX: some applications launched with the activation helper may need DBUS_STARTER_ADDRESS. (LP: #1058343) - debian/patches/CVE-2012-3524-regression-fix.patch: hardcode the starter address to the default system bus address. * REGRESSION FIX: unclean shutdown after dbus upgrade (LP: #740390) - debian/libdbus-1-3.postinst: trigger an upstart re-exec before shutdown or reboot so that it can safely unmount the root filesystem. Date: 2012-10-03 18:15:11.471131+00:00 Changed-By: Marc Deslauriers https://launchpad.net/ubuntu/natty/+source/dbus/1.4.6-1ubuntu6.4 -------------- next part -------------- Sorry, changesfile not available. From cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk Thu Oct 4 12:29:18 2012 From: cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk (Ubuntu Archive Robot) Date: Thu, 04 Oct 2012 12:29:18 -0000 Subject: [ubuntu/natty-updates] dbus 1.4.6-1ubuntu6.4 (Accepted) Message-ID: <20121004122918.31768.77733.launchpad@ackee.canonical.com> dbus (1.4.6-1ubuntu6.4) natty-security; urgency=low * REGRESSION FIX: some applications launched with the activation helper may need DBUS_STARTER_ADDRESS. (LP: #1058343) - debian/patches/CVE-2012-3524-regression-fix.patch: hardcode the starter address to the default system bus address. * REGRESSION FIX: unclean shutdown after dbus upgrade (LP: #740390) - debian/libdbus-1-3.postinst: trigger an upstart re-exec before shutdown or reboot so that it can safely unmount the root filesystem. Date: 2012-10-03 18:15:11.471131+00:00 Changed-By: Marc Deslauriers Signed-By: Ubuntu Archive Robot https://launchpad.net/ubuntu/natty/+source/dbus/1.4.6-1ubuntu6.4 -------------- next part -------------- Sorry, changesfile not available. From marc.deslauriers at canonical.com Thu Oct 4 17:00:30 2012 From: marc.deslauriers at canonical.com (Marc Deslauriers) Date: Thu, 04 Oct 2012 17:00:30 -0000 Subject: [ubuntu/natty-security] libxslt 1.1.26-6ubuntu0.1 (Accepted) Message-ID: <20121004170030.814.92057.launchpad@ackee.canonical.com> libxslt (1.1.26-6ubuntu0.1) natty-security; urgency=low * SECURITY UPDATE: information disclosure via generate-id XPath function - libxslt/functions.c: do not expose object addresses directly. - ecb6bcb8d1b7e44842edde3929f412d46b40c89f - CVE-2011-1202 * SECURITY UPDATE: denial of service via out-of-bounds read - libxslt/pattern.c: fix improper loop exit. - fe5a4fa33eb85bce3253ed3742b1ea6c4b59b41b - CVE-2011-3970 * SECURITY UPDATE: denial of service via out-of-bounds read - libxslt/xsltutils.h: check for XML_ELEMENT_NODE - e6a0bc8081271f33b9899eb78e1da1a2a0428419 - CVE-2012-2825 * SECURITY UPDATE: denial of service via crafted XSLT expression - harden code in libexslt/functions.c, libxslt/attributes.c, libxslt/functions.c, libxslt/pattern.c, libxslt/preproc.c, libxslt/templates.c, libxslt/transform.c, libxslt/variables.c, libxslt/xslt.c, libxslt/xsltutils.c. - 8566ab4a10158d195adb5f1f61afe1ee8bfebd12 - 4da0f7e207f14a03daad4663865c285eb27f93e9 - 24653072221e76d2f1f06aa71225229b532f8946 - 1564b30e994602a95863d9716be83612580a2fed - CVE-2012-2870 * SECURITY UPDATE: denial of service and possible code execution during handling of XSL transforms - libxslt/transform.c: check for XML_NAMESPACE_DECL - 937ba2a3eb42d288f53c8adc211bd1122869f0bf - CVE-2012-2871 * SECURITY UPDATE: denial of service and possible code execution via double free during XSL transforms - libxslt/templates.c: Fix dictionary string usage - 54977ed7966847e305a2008cb18892df26eeb065 - CVE-2012-2893 Date: 2012-09-28 20:20:21.398846+00:00 Changed-By: Marc Deslauriers https://launchpad.net/ubuntu/natty/+source/libxslt/1.1.26-6ubuntu0.1 -------------- next part -------------- Sorry, changesfile not available. From cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk Thu Oct 4 17:29:14 2012 From: cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk (Ubuntu Archive Robot) Date: Thu, 04 Oct 2012 17:29:14 -0000 Subject: [ubuntu/natty-updates] libxslt 1.1.26-6ubuntu0.1 (Accepted) Message-ID: <20121004172914.15454.34217.launchpad@ackee.canonical.com> libxslt (1.1.26-6ubuntu0.1) natty-security; urgency=low * SECURITY UPDATE: information disclosure via generate-id XPath function - libxslt/functions.c: do not expose object addresses directly. - ecb6bcb8d1b7e44842edde3929f412d46b40c89f - CVE-2011-1202 * SECURITY UPDATE: denial of service via out-of-bounds read - libxslt/pattern.c: fix improper loop exit. - fe5a4fa33eb85bce3253ed3742b1ea6c4b59b41b - CVE-2011-3970 * SECURITY UPDATE: denial of service via out-of-bounds read - libxslt/xsltutils.h: check for XML_ELEMENT_NODE - e6a0bc8081271f33b9899eb78e1da1a2a0428419 - CVE-2012-2825 * SECURITY UPDATE: denial of service via crafted XSLT expression - harden code in libexslt/functions.c, libxslt/attributes.c, libxslt/functions.c, libxslt/pattern.c, libxslt/preproc.c, libxslt/templates.c, libxslt/transform.c, libxslt/variables.c, libxslt/xslt.c, libxslt/xsltutils.c. - 8566ab4a10158d195adb5f1f61afe1ee8bfebd12 - 4da0f7e207f14a03daad4663865c285eb27f93e9 - 24653072221e76d2f1f06aa71225229b532f8946 - 1564b30e994602a95863d9716be83612580a2fed - CVE-2012-2870 * SECURITY UPDATE: denial of service and possible code execution during handling of XSL transforms - libxslt/transform.c: check for XML_NAMESPACE_DECL - 937ba2a3eb42d288f53c8adc211bd1122869f0bf - CVE-2012-2871 * SECURITY UPDATE: denial of service and possible code execution via double free during XSL transforms - libxslt/templates.c: Fix dictionary string usage - 54977ed7966847e305a2008cb18892df26eeb065 - CVE-2012-2893 Date: 2012-09-28 20:20:21.398846+00:00 Changed-By: Marc Deslauriers Signed-By: Ubuntu Archive Robot https://launchpad.net/ubuntu/natty/+source/libxslt/1.1.26-6ubuntu0.1 -------------- next part -------------- Sorry, changesfile not available. From jamie at ubuntu.com Thu Oct 4 21:22:16 2012 From: jamie at ubuntu.com (Jamie Strandboge) Date: Thu, 04 Oct 2012 21:22:16 -0000 Subject: [ubuntu/natty-security] python2.6 2.6.6-6ubuntu7.1 (Accepted) Message-ID: <20121004212216.31841.94045.launchpad@ackee.canonical.com> python2.6 (2.6.6-6ubuntu7.1) natty-security; urgency=low * SECURITY UPDATE: fix hash randomization DoS - debian/patches/CVE-2012-1150.diff: add -R command-line option and PYTHONHASHSEED environment variable, to provide an opt-in way to protect against denial of service attacks due to hash collisions within the dict and set types. - CVE-2012-1150 * SECURITY UPDATE: xmlrpc: Fix an endless loop in SimpleXMLRPCServer upon malformed POST request - debian/patches/CVE-2012-0845.diff: break if don't receive EOF in Lib/SimpleXMLRPCServer.py - CVE-2012-0845 * SECURE UPDATE: http://bugs.python.org/issue13512 - debian/patches/CVE-2011-4944.diff: create ~/.pypirc securely - CVE-2011-4944 * SECURITY UPDATE: Fix CGIHTTPServer information disclosure. - debian/patches/CVE-2011-1015.diff: Relative paths are now collapsed within the url properly before looking in cgi_directories. - CVE-2011-1015 * SECURITY UPDATE: fix XSS in SimpleHTTPServer - debian/patches/CVE-2011-4940.diff: add a charset parameter to the Content-type - CVE-2011-4940 * SECURITY UPDATE: update urllib and urllib2 for invalid redirections - debian/patches/CVE-2011-1521.diff: only process Location headers for http, https, and ftp - http://bugs.python.org/issue11662 - CVE-2011-1521 Date: 2012-10-01 21:50:17.372339+00:00 Changed-By: Jamie Strandboge https://launchpad.net/ubuntu/natty/+source/python2.6/2.6.6-6ubuntu7.1 -------------- next part -------------- Sorry, changesfile not available. From cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk Thu Oct 4 21:58:15 2012 From: cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk (Ubuntu Archive Robot) Date: Thu, 04 Oct 2012 21:58:15 -0000 Subject: [ubuntu/natty-updates] python2.6 2.6.6-6ubuntu7.1 (Accepted) Message-ID: <20121004215815.16075.55298.launchpad@ackee.canonical.com> python2.6 (2.6.6-6ubuntu7.1) natty-security; urgency=low * SECURITY UPDATE: fix hash randomization DoS - debian/patches/CVE-2012-1150.diff: add -R command-line option and PYTHONHASHSEED environment variable, to provide an opt-in way to protect against denial of service attacks due to hash collisions within the dict and set types. - CVE-2012-1150 * SECURITY UPDATE: xmlrpc: Fix an endless loop in SimpleXMLRPCServer upon malformed POST request - debian/patches/CVE-2012-0845.diff: break if don't receive EOF in Lib/SimpleXMLRPCServer.py - CVE-2012-0845 * SECURE UPDATE: http://bugs.python.org/issue13512 - debian/patches/CVE-2011-4944.diff: create ~/.pypirc securely - CVE-2011-4944 * SECURITY UPDATE: Fix CGIHTTPServer information disclosure. - debian/patches/CVE-2011-1015.diff: Relative paths are now collapsed within the url properly before looking in cgi_directories. - CVE-2011-1015 * SECURITY UPDATE: fix XSS in SimpleHTTPServer - debian/patches/CVE-2011-4940.diff: add a charset parameter to the Content-type - CVE-2011-4940 * SECURITY UPDATE: update urllib and urllib2 for invalid redirections - debian/patches/CVE-2011-1521.diff: only process Location headers for http, https, and ftp - http://bugs.python.org/issue11662 - CVE-2011-1521 Date: 2012-10-01 21:50:17.372339+00:00 Changed-By: Jamie Strandboge Signed-By: Ubuntu Archive Robot https://launchpad.net/ubuntu/natty/+source/python2.6/2.6.6-6ubuntu7.1 -------------- next part -------------- Sorry, changesfile not available. From chris.coulson at canonical.com Tue Oct 9 13:26:22 2012 From: chris.coulson at canonical.com (Chris Coulson) Date: Tue, 09 Oct 2012 13:26:22 -0000 Subject: [ubuntu/natty] adobe-flashplugin 11.2.202.243-0natty1 (Accepted) Message-ID: <20121009132622.478.58258.launchpad@soybean.canonical.com> adobe-flashplugin (11.2.202.243-0natty1) natty; urgency=low * New upstream release v11.2.202.243 Date: Tue, 09 Oct 2012 13:27:40 +0100 Changed-By: Chris Coulson Maintainer: DL-Flash Player Ubuntu https://launchpad.net/ubuntu/natty/+source/adobe-flashplugin/11.2.202.243-0natty1 -------------- next part -------------- Format: 1.8 Date: Tue, 09 Oct 2012 13:27:40 +0100 Source: adobe-flashplugin Binary: adobe-flashplugin adobe-flash-properties-gtk adobe-flash-properties-kde Architecture: source Version: 11.2.202.243-0natty1 Distribution: natty Urgency: low Maintainer: DL-Flash Player Ubuntu Changed-By: Chris Coulson Description: adobe-flash-properties-gtk - GTK+ control panel for Adobe Flash Player plugin version 11 adobe-flash-properties-kde - KDE control panel Adobe Flash Player plugin version 11 adobe-flashplugin - Adobe Flash Player plugin version 11 Changes: adobe-flashplugin (11.2.202.243-0natty1) natty; urgency=low . * New upstream release v11.2.202.243 Checksums-Sha1: 977d166232effc6e625dd17c44fe386057180f3b 1731 adobe-flashplugin_11.2.202.243-0natty1.dsc 7a9ab50b4ea424b02b1db4a0cc2f4bfa6b42b4e3 5146 adobe-flashplugin_11.2.202.243-0natty1.diff.gz Checksums-Sha256: 7118741b4c3a9aa04a268669d0982ce7043645295a369540af335c9e722cf089 1731 adobe-flashplugin_11.2.202.243-0natty1.dsc 923965ac2026ca60bb025c2535336411d8d39683476776ebd790f80806d42f9a 5146 adobe-flashplugin_11.2.202.243-0natty1.diff.gz Files: ecb063f74961cfd291a6935fea4067b0 1731 partner/web optional adobe-flashplugin_11.2.202.243-0natty1.dsc 7a5a76533523f309733df0eb5df58be6 5146 partner/web optional adobe-flashplugin_11.2.202.243-0natty1.diff.gz From jamie at ubuntu.com Tue Oct 9 21:40:21 2012 From: jamie at ubuntu.com (Jamie Strandboge) Date: Tue, 09 Oct 2012 21:40:21 -0000 Subject: [ubuntu/natty-security] flashplugin-nonfree 11.2.202.243ubuntu0.11.04.1 (Accepted) Message-ID: <20121009214021.25377.2615.launchpad@ackee.canonical.com> flashplugin-nonfree (11.2.202.243ubuntu0.11.04.1) natty-security; urgency=low * New upstream release 11.2.202.243 - debian/{config,postinst.in}: Updated version and sha256sum. Date: 2012-10-09 13:05:19.075550+00:00 Changed-By: Chris Coulson Signed-By: Jamie Strandboge https://launchpad.net/ubuntu/natty/+source/flashplugin-nonfree/11.2.202.243ubuntu0.11.04.1 -------------- next part -------------- Sorry, changesfile not available. From jamie at ubuntu.com Tue Oct 9 21:44:37 2012 From: jamie at ubuntu.com (Jamie Strandboge) Date: Tue, 09 Oct 2012 21:44:37 -0000 Subject: [ubuntu/natty-security] firefox 16.0+build1-0ubuntu0.11.04.1 (Accepted) Message-ID: <20121009214437.27526.2874.launchpad@ackee.canonical.com> firefox (16.0+build1-0ubuntu0.11.04.1) natty-security; urgency=low * New upstream stable release (FIREFOX_16_0_BUILD1) - see LP: #1062611 for USN information * Update globalmenu-extension to 3.5.4 - Fix LP: #1051152 - Crash in nsIContent::SetAttr with greasemonkey installed - Improve handling of radio items, and work correctly for radio items without a name (fixes the View -> Page Style submenu) - Stop causing nested DOM mutations. There is a big warning about doing this in nsIMutationObserver.h - Delay processing of DOM mutations during code sections when we are dispatching events. This should prevent a recurrence of reentrancy-triggered crashes such as LP: #1025011, LP: #1035305 and LP: #1051152, which have been exposed by updates of third-party addons recently and caused because our view of the menu changes during event delivery - Fix crash in uGlobalMenuDocListener::HandleMutations * Fix for bmo: #795395 - add debian/patches/fix-for-bmo795395.patch - update debian/patches/series * Refresh patches after merging of nsILocalFile in to nsIFile - update debian/patches/firefox-kde.patch - update debian/patches/mozilla-kde.patch * Drop StartupWMClass from the desktop file, as it isn't actually required by gnome shell or unity - update debian/firefox.desktop.in * Refresh patches - update debian/patches/ubuntu-ua-string-changes.patch - update debian/patches/mozilla-kde.patch - update debian/patches/dont-override-general-useragent-locale.patch - update debian/patches/firefox-kde.patch * Drop compare-locales from the packaging, and just check out the current version when we create the tarball - update debian/build/mozbuild.mk - update debian/build/create-tarball.py - remove debian/build/compare-locales * Generate a list of the search engines that we modify and store this in bzr, rather than determining this list at build time. We refresh the list in the clean target and fail the build if anything changes. This ensures that any upstream changes to the search engine list for any locale will not go unnoticed and will force a manual check to ensure that we are shipping correctly modified search engines - add debian/build/refresh-search-modifications.pl - update debian/build/mozbuild.mk - add debian/config/search-mods.list - rename debian/build/check-search-overrides.pl => debian/build/verify-search-overrides.pl * Drop obsolete autocomplete-theme-tweak patch now - remove debian/patches/autocomplete-theme-tweak.patch - update debian/patches/series Date: 2012-10-06 05:56:57.620191+00:00 Changed-By: Chris Coulson Signed-By: Jamie Strandboge https://launchpad.net/ubuntu/natty/+source/firefox/16.0+build1-0ubuntu0.11.04.1 -------------- next part -------------- Sorry, changesfile not available. From cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk Tue Oct 9 22:34:16 2012 From: cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk (Ubuntu Archive Robot) Date: Tue, 09 Oct 2012 22:34:16 -0000 Subject: [ubuntu/natty-updates] flashplugin-nonfree 11.2.202.243ubuntu0.11.04.1 (Accepted) Message-ID: <20121009223416.11046.79461.launchpad@ackee.canonical.com> flashplugin-nonfree (11.2.202.243ubuntu0.11.04.1) natty-security; urgency=low * New upstream release 11.2.202.243 - debian/{config,postinst.in}: Updated version and sha256sum. Date: 2012-10-09 13:05:19.075550+00:00 Changed-By: Chris Coulson Signed-By: Ubuntu Archive Robot https://launchpad.net/ubuntu/natty/+source/flashplugin-nonfree/11.2.202.243ubuntu0.11.04.1 -------------- next part -------------- Sorry, changesfile not available. From cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk Tue Oct 9 22:35:00 2012 From: cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk (Ubuntu Archive Robot) Date: Tue, 09 Oct 2012 22:35:00 -0000 Subject: [ubuntu/natty-updates] firefox 16.0+build1-0ubuntu0.11.04.1 (Accepted) Message-ID: <20121009223500.11046.15836.launchpad@ackee.canonical.com> firefox (16.0+build1-0ubuntu0.11.04.1) natty-security; urgency=low * New upstream stable release (FIREFOX_16_0_BUILD1) - see LP: #1062611 for USN information * Update globalmenu-extension to 3.5.4 - Fix LP: #1051152 - Crash in nsIContent::SetAttr with greasemonkey installed - Improve handling of radio items, and work correctly for radio items without a name (fixes the View -> Page Style submenu) - Stop causing nested DOM mutations. There is a big warning about doing this in nsIMutationObserver.h - Delay processing of DOM mutations during code sections when we are dispatching events. This should prevent a recurrence of reentrancy-triggered crashes such as LP: #1025011, LP: #1035305 and LP: #1051152, which have been exposed by updates of third-party addons recently and caused because our view of the menu changes during event delivery - Fix crash in uGlobalMenuDocListener::HandleMutations * Fix for bmo: #795395 - add debian/patches/fix-for-bmo795395.patch - update debian/patches/series * Refresh patches after merging of nsILocalFile in to nsIFile - update debian/patches/firefox-kde.patch - update debian/patches/mozilla-kde.patch * Drop StartupWMClass from the desktop file, as it isn't actually required by gnome shell or unity - update debian/firefox.desktop.in * Refresh patches - update debian/patches/ubuntu-ua-string-changes.patch - update debian/patches/mozilla-kde.patch - update debian/patches/dont-override-general-useragent-locale.patch - update debian/patches/firefox-kde.patch * Drop compare-locales from the packaging, and just check out the current version when we create the tarball - update debian/build/mozbuild.mk - update debian/build/create-tarball.py - remove debian/build/compare-locales * Generate a list of the search engines that we modify and store this in bzr, rather than determining this list at build time. We refresh the list in the clean target and fail the build if anything changes. This ensures that any upstream changes to the search engine list for any locale will not go unnoticed and will force a manual check to ensure that we are shipping correctly modified search engines - add debian/build/refresh-search-modifications.pl - update debian/build/mozbuild.mk - add debian/config/search-mods.list - rename debian/build/check-search-overrides.pl => debian/build/verify-search-overrides.pl * Drop obsolete autocomplete-theme-tweak patch now - remove debian/patches/autocomplete-theme-tweak.patch - update debian/patches/series Date: 2012-10-06 05:56:57.620191+00:00 Changed-By: Chris Coulson Signed-By: Ubuntu Archive Robot https://launchpad.net/ubuntu/natty/+source/firefox/16.0+build1-0ubuntu0.11.04.1 -------------- next part -------------- Sorry, changesfile not available. From marc.deslauriers at canonical.com Wed Oct 10 12:04:26 2012 From: marc.deslauriers at canonical.com (Marc Deslauriers) Date: Wed, 10 Oct 2012 12:04:26 -0000 Subject: [ubuntu/natty-security] bind9 1:9.7.3.dfsg-1ubuntu2.7 (Accepted) Message-ID: <20121010120426.21494.71840.launchpad@ackee.canonical.com> bind9 (1:9.7.3.dfsg-1ubuntu2.7) natty-security; urgency=low * SECURITY UPDATE: denial of service via specific combinations of RDATA - bin/named/query.c: fix logic - Patch backported from 9.8.3-P4 - CVE-2012-5166 Date: 2012-10-09 13:25:11.627830+00:00 Changed-By: Marc Deslauriers https://launchpad.net/ubuntu/natty/+source/bind9/1:9.7.3.dfsg-1ubuntu2.7 -------------- next part -------------- Sorry, changesfile not available. From cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk Wed Oct 10 12:59:20 2012 From: cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk (Ubuntu Archive Robot) Date: Wed, 10 Oct 2012 12:59:20 -0000 Subject: [ubuntu/natty-updates] bind9 1:9.7.3.dfsg-1ubuntu2.7 (Accepted) Message-ID: <20121010125920.5546.84463.launchpad@ackee.canonical.com> bind9 (1:9.7.3.dfsg-1ubuntu2.7) natty-security; urgency=low * SECURITY UPDATE: denial of service via specific combinations of RDATA - bin/named/query.c: fix logic - Patch backported from 9.8.3-P4 - CVE-2012-5166 Date: 2012-10-09 13:25:11.627830+00:00 Changed-By: Marc Deslauriers Signed-By: Ubuntu Archive Robot https://launchpad.net/ubuntu/natty/+source/bind9/1:9.7.3.dfsg-1ubuntu2.7 -------------- next part -------------- Sorry, changesfile not available. From tyhicks at canonical.com Wed Oct 10 22:01:19 2012 From: tyhicks at canonical.com (Tyler Hicks) Date: Wed, 10 Oct 2012 22:01:19 -0000 Subject: [ubuntu/natty-security] ruby1.8 1.8.7.302-2ubuntu0.2 (Accepted) Message-ID: <20121010220119.2626.86556.launchpad@ackee.canonical.com> ruby1.8 (1.8.7.302-2ubuntu0.2) natty-security; urgency=low * SECURITY UPDATE: Safe level bypasses - debian/patches/CVE-2012-4466_CVE-2012-4481.patch: Remove incorrect string taints in exception handling methods. Based on upstream patch. - CVE-2012-4466 - CVE-2012-4481 Date: 2012-10-10 11:15:30.646779+00:00 Changed-By: Tyler Hicks https://launchpad.net/ubuntu/natty/+source/ruby1.8/1.8.7.302-2ubuntu0.2 -------------- next part -------------- Sorry, changesfile not available. From cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk Wed Oct 10 22:28:16 2012 From: cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk (Ubuntu Archive Robot) Date: Wed, 10 Oct 2012 22:28:16 -0000 Subject: [ubuntu/natty-updates] ruby1.8 1.8.7.302-2ubuntu0.2 (Accepted) Message-ID: <20121010222816.6819.63624.launchpad@ackee.canonical.com> ruby1.8 (1.8.7.302-2ubuntu0.2) natty-security; urgency=low * SECURITY UPDATE: Safe level bypasses - debian/patches/CVE-2012-4466_CVE-2012-4481.patch: Remove incorrect string taints in exception handling methods. Based on upstream patch. - CVE-2012-4466 - CVE-2012-4481 Date: 2012-10-10 11:15:30.646779+00:00 Changed-By: Tyler Hicks Signed-By: Ubuntu Archive Robot https://launchpad.net/ubuntu/natty/+source/ruby1.8/1.8.7.302-2ubuntu0.2 -------------- next part -------------- Sorry, changesfile not available. From marc.deslauriers at canonical.com Thu Oct 11 11:49:13 2012 From: marc.deslauriers at canonical.com (Marc Deslauriers) Date: Thu, 11 Oct 2012 11:49:13 -0000 Subject: [ubuntu/natty-security] moin 1.9.3-1ubuntu1.11.04.1 (Accepted) Message-ID: <20121011114913.11579.43058.launchpad@ackee.canonical.com> moin (1.9.3-1ubuntu1.11.04.1) natty-security; urgency=low * SECURITY UPDATE: cross-site scripting issue in reStructuredText parser - debian/patches/CVE-2011-1058.patch: remove javascript support in MoinMoin/parser/text_rst.py. - CVE-2011-1058 * SECURITY UPDATE: incorrect permissions due to broken virtual group names handling - debian/patches/CVE-2012-4404.patch: fix group test in MoinMoin/security/__init__.py, added test in MoinMoin/security/_tests/test_security.py. - CVE-2012-4404 Date: 2012-10-10 16:00:20.512654+00:00 Changed-By: Marc Deslauriers https://launchpad.net/ubuntu/natty/+source/moin/1.9.3-1ubuntu1.11.04.1 -------------- next part -------------- Sorry, changesfile not available. From cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk Thu Oct 11 12:28:13 2012 From: cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk (Ubuntu Archive Robot) Date: Thu, 11 Oct 2012 12:28:13 -0000 Subject: [ubuntu/natty-updates] moin 1.9.3-1ubuntu1.11.04.1 (Accepted) Message-ID: <20121011122813.23141.98114.launchpad@ackee.canonical.com> moin (1.9.3-1ubuntu1.11.04.1) natty-security; urgency=low * SECURITY UPDATE: cross-site scripting issue in reStructuredText parser - debian/patches/CVE-2011-1058.patch: remove javascript support in MoinMoin/parser/text_rst.py. - CVE-2011-1058 * SECURITY UPDATE: incorrect permissions due to broken virtual group names handling - debian/patches/CVE-2012-4404.patch: fix group test in MoinMoin/security/__init__.py, added test in MoinMoin/security/_tests/test_security.py. - CVE-2012-4404 Date: 2012-10-10 16:00:20.512654+00:00 Changed-By: Marc Deslauriers Signed-By: Ubuntu Archive Robot https://launchpad.net/ubuntu/natty/+source/moin/1.9.3-1ubuntu1.11.04.1 -------------- next part -------------- Sorry, changesfile not available. From marc.deslauriers at canonical.com Thu Oct 11 18:00:30 2012 From: marc.deslauriers at canonical.com (Marc Deslauriers) Date: Thu, 11 Oct 2012 18:00:30 -0000 Subject: [ubuntu/natty-security] quagga 0.99.20.1-0ubuntu0.11.04.3 (Accepted) Message-ID: <20121011180030.27117.76858.launchpad@ackee.canonical.com> quagga (0.99.20.1-0ubuntu0.11.04.3) natty-security; urgency=low * SECURITY UPDATE: denial of service via malformed ORF capability TLV (LP: #1018052) - debian/patches/CVE-2012-1820.patch: correctly follow spec in bgpd/bgp_open.c. - CVE-2012-1820 Date: 2012-10-11 15:50:21.046576+00:00 Changed-By: Marc Deslauriers https://launchpad.net/ubuntu/natty/+source/quagga/0.99.20.1-0ubuntu0.11.04.3 -------------- next part -------------- Sorry, changesfile not available. From launchpad at micahscomputing.com Thu Oct 11 18:20:53 2012 From: launchpad at micahscomputing.com (Micah Gersten) Date: Thu, 11 Oct 2012 18:20:53 -0000 Subject: [ubuntu/natty-security] firefox 16.0.1+build1-0ubuntu0.11.04.1 (Accepted) Message-ID: <20121011182053.930.95630.launchpad@ackee.canonical.com> firefox (16.0.1+build1-0ubuntu0.11.04.1) natty-security; urgency=low * New upstream stable release (FIREFOX_16_0_1_BUILD1) - see LP: #1065285 for USN information Date: 2012-10-10 23:06:22.948400+00:00 Changed-By: Chris Coulson Signed-By: Micah Gersten https://launchpad.net/ubuntu/natty/+source/firefox/16.0.1+build1-0ubuntu0.11.04.1 -------------- next part -------------- Sorry, changesfile not available. From cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk Thu Oct 11 18:28:16 2012 From: cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk (Ubuntu Archive Robot) Date: Thu, 11 Oct 2012 18:28:16 -0000 Subject: [ubuntu/natty-updates] quagga 0.99.20.1-0ubuntu0.11.04.3 (Accepted) Message-ID: <20121011182816.2576.33918.launchpad@ackee.canonical.com> quagga (0.99.20.1-0ubuntu0.11.04.3) natty-security; urgency=low * SECURITY UPDATE: denial of service via malformed ORF capability TLV (LP: #1018052) - debian/patches/CVE-2012-1820.patch: correctly follow spec in bgpd/bgp_open.c. - CVE-2012-1820 Date: 2012-10-11 15:50:21.046576+00:00 Changed-By: Marc Deslauriers Signed-By: Ubuntu Archive Robot https://launchpad.net/ubuntu/natty/+source/quagga/0.99.20.1-0ubuntu0.11.04.3 -------------- next part -------------- Sorry, changesfile not available. From cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk Thu Oct 11 20:05:27 2012 From: cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk (Ubuntu Archive Robot) Date: Thu, 11 Oct 2012 20:05:27 -0000 Subject: [ubuntu/natty-updates] firefox 16.0.1+build1-0ubuntu0.11.04.1 (Accepted) Message-ID: <20121011200527.32471.61453.launchpad@ackee.canonical.com> firefox (16.0.1+build1-0ubuntu0.11.04.1) natty-security; urgency=low * New upstream stable release (FIREFOX_16_0_1_BUILD1) - see LP: #1065285 for USN information Date: 2012-10-10 23:06:22.948400+00:00 Changed-By: Chris Coulson Signed-By: Ubuntu Archive Robot https://launchpad.net/ubuntu/natty/+source/firefox/16.0.1+build1-0ubuntu0.11.04.1 -------------- next part -------------- Sorry, changesfile not available. From scott at kitterman.com Thu Oct 11 22:14:25 2012 From: scott at kitterman.com (Scott Kitterman) Date: Thu, 11 Oct 2012 22:14:25 -0000 Subject: [ubuntu/natty-proposed] clamav 0.97.6+dfsg-1ubuntu0.11.04.1 (Accepted) Message-ID: <20121011221425.27050.69252.launchpad@soybean.canonical.com> clamav (0.97.6+dfsg-1ubuntu0.11.04.1) natty-proposed; urgency=low * Microversion update to latest clamav release for natty (LP: #1064096) clamav (0.97.6+dfsg-1ubuntu1) quantal; urgency=low * Merge from Debian unstable. Remaining changes: - Drop build-dep on electric-fence (in Universe) - Add apparmor profiles for clamd and freshclam along with maintainer script changes clamav (0.97.6+dfsg-1) unstable; urgency=low * New upstream release (Closes: #689487) * Update libclamav6 lintian override to match updated soversion Date: Mon, 08 Oct 2012 18:11:31 -0400 Changed-By: Scott Kitterman Maintainer: Ubuntu Developers https://launchpad.net/ubuntu/natty/+source/clamav/0.97.6+dfsg-1ubuntu0.11.04.1 -------------- next part -------------- Format: 1.8 Date: Mon, 08 Oct 2012 18:11:31 -0400 Source: clamav Binary: clamav-base clamav-docs clamav-dbg clamav libclamav-dev libclamav6 clamav-daemon clamav-testfiles clamav-freshclam clamav-milter Architecture: source Version: 0.97.6+dfsg-1ubuntu0.11.04.1 Distribution: natty-proposed Urgency: low Maintainer: Ubuntu Developers Changed-By: Scott Kitterman Description: clamav - anti-virus utility for Unix - command-line interface clamav-base - anti-virus utility for Unix - base package clamav-daemon - anti-virus utility for Unix - scanner daemon clamav-dbg - debug symbols for ClamAV clamav-docs - anti-virus utility for Unix - documentation clamav-freshclam - anti-virus utility for Unix - virus database update utility clamav-milter - anti-virus utility for Unix - sendmail integration clamav-testfiles - anti-virus utility for Unix - test files libclamav-dev - anti-virus utility for Unix - development files libclamav6 - anti-virus utility for Unix - library Closes: 689487 Launchpad-Bugs-Fixed: 1064096 Changes: clamav (0.97.6+dfsg-1ubuntu0.11.04.1) natty-proposed; urgency=low . * Microversion update to latest clamav release for natty (LP: #1064096) . clamav (0.97.6+dfsg-1ubuntu1) quantal; urgency=low . * Merge from Debian unstable. Remaining changes: - Drop build-dep on electric-fence (in Universe) - Add apparmor profiles for clamd and freshclam along with maintainer script changes . clamav (0.97.6+dfsg-1) unstable; urgency=low . * New upstream release (Closes: #689487) * Update libclamav6 lintian override to match updated soversion Checksums-Sha1: 9fa0b73861ad366ae27caacf1a8f1625b7ae9c78 2056 clamav_0.97.6+dfsg-1ubuntu0.11.04.1.dsc 1d4a48a48585e3290bf5a8f09d5758bad020ecda 301691 clamav_0.97.6+dfsg-1ubuntu0.11.04.1.diff.gz Checksums-Sha256: 0a7565d0ab4033d5b7f21d59080f1e5e3b79c2bee63a99ed1c939517b7e035bc 2056 clamav_0.97.6+dfsg-1ubuntu0.11.04.1.dsc d72ab11cb58785b3486cc4c6bb46b48a191318daf8b8162d2efe9c98acb6a1e5 301691 clamav_0.97.6+dfsg-1ubuntu0.11.04.1.diff.gz Files: a974c3243437989a4260f54ff6bc7b09 2056 utils optional clamav_0.97.6+dfsg-1ubuntu0.11.04.1.dsc 6a5ab26ffc8b91d1cccd65f5c267be7b 301691 utils optional clamav_0.97.6+dfsg-1ubuntu0.11.04.1.diff.gz Original-Maintainer: ClamAV Team From launchpad at micahscomputing.com Fri Oct 12 09:16:38 2012 From: launchpad at micahscomputing.com (Micah Gersten) Date: Fri, 12 Oct 2012 09:16:38 -0000 Subject: [ubuntu/natty-security] thunderbird 16.0.1+build1-0ubuntu0.11.04.1 (Accepted) Message-ID: <20121012091638.19891.91771.launchpad@ackee.canonical.com> thunderbird (16.0.1+build1-0ubuntu0.11.04.1) natty-security; urgency=low * New upstream stable release (THUNDERBIRD_16_0_1_BUILD1) - see LP: #1065292 for USN information thunderbird (16.0+build1-0ubuntu0.11.04.1) natty-security; urgency=low * New upstream stable release (THUNDERBIRD_16_0_BUILD1) - see LP: #1062587 for USN information * Update globalmenu-extension to 3.5.4 - Fix LP: #1045196 - "Messages->Move To" menu is empty - Fix LP: #1051152 - Crash in nsIContent::SetAttr - Improve handling of radio items, and work correctly for radio items without a name - Stop causing nested DOM mutations. There is a big warning about doing this in nsIMutationObserver.h - Delay processing of DOM mutations during code sections when we are dispatching events. This should prevent a recurrence of reentrancy-triggered crashes such as LP: #1025011, LP: #1035305 and LP: #1051152, which have been exposed by updates of third-party addons recently and caused because our view of the menu changes during event delivery - Fix crash in uGlobalMenuDocListener::HandleMutations * Fix for bmo: #795395 - add debian/patches/fix-for-bmo795395.patch - update debian/patches/series * Drop compare-locales from the packaging, and just check out the current version when we create the tarball - update debian/build/mozbuild.mk - update debian/build/create-tarball.py - remove debian/build/compare-locales * Ensure the Apport hook parses the system preferences - update debian/apport/source_thunderbird.py.in Date: 2012-10-10 23:15:17.382451+00:00 Changed-By: Chris Coulson Signed-By: Micah Gersten https://launchpad.net/ubuntu/natty/+source/thunderbird/16.0.1+build1-0ubuntu0.11.04.1 -------------- next part -------------- Sorry, changesfile not available. From launchpad at micahscomputing.com Fri Oct 12 09:16:52 2012 From: launchpad at micahscomputing.com (Micah Gersten) Date: Fri, 12 Oct 2012 09:16:52 -0000 Subject: [ubuntu/natty-security] lightning-extension 1.8+build1-0ubuntu0.11.04.1 (Accepted) Message-ID: <20121012091652.19891.52809.launchpad@ackee.canonical.com> lightning-extension (1.8+build1-0ubuntu0.11.04.1) natty-security; urgency=low * New upstream stable release to support Thunderbird 16 (CALENDAR_1_8_BUILD1) - LP: #1062587 * Add extra Makefiles that are needed for the build - update debian/rules Date: 2012-10-09 09:10:27.906911+00:00 Changed-By: Chris Coulson Signed-By: Micah Gersten https://launchpad.net/ubuntu/natty/+source/lightning-extension/1.8+build1-0ubuntu0.11.04.1 -------------- next part -------------- Sorry, changesfile not available. From launchpad at micahscomputing.com Fri Oct 12 09:16:59 2012 From: launchpad at micahscomputing.com (Micah Gersten) Date: Fri, 12 Oct 2012 09:16:59 -0000 Subject: [ubuntu/natty-security] enigmail 2:1.4.5-0ubuntu0.11.04.1 (Accepted) Message-ID: <20121012091659.19891.91943.launchpad@ackee.canonical.com> enigmail (2:1.4.5-0ubuntu0.11.04.1) natty-security; urgency=low * New upstream release v1.4.5 to support Thunderbird 16 - LP: #1062587 * Add patch to set the correct version number. The version was not changed from 1.5a1pre to 1.4.5 when the tarball was built from rev 24e938 - add debian/patches/correct-version-number.diff - update debian/patches/series Date: 2012-10-09 18:25:40.264550+00:00 Changed-By: Chris Coulson Signed-By: Micah Gersten https://launchpad.net/ubuntu/natty/+source/enigmail/2:1.4.5-0ubuntu0.11.04.1 -------------- next part -------------- Sorry, changesfile not available. From cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk Fri Oct 12 11:33:25 2012 From: cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk (Ubuntu Archive Robot) Date: Fri, 12 Oct 2012 11:33:25 -0000 Subject: [ubuntu/natty-updates] thunderbird 16.0.1+build1-0ubuntu0.11.04.1 (Accepted) Message-ID: <20121012113325.28075.66886.launchpad@ackee.canonical.com> thunderbird (16.0.1+build1-0ubuntu0.11.04.1) natty-security; urgency=low * New upstream stable release (THUNDERBIRD_16_0_1_BUILD1) - see LP: #1065292 for USN information thunderbird (16.0+build1-0ubuntu0.11.04.1) natty-security; urgency=low * New upstream stable release (THUNDERBIRD_16_0_BUILD1) - see LP: #1062587 for USN information * Update globalmenu-extension to 3.5.4 - Fix LP: #1045196 - "Messages->Move To" menu is empty - Fix LP: #1051152 - Crash in nsIContent::SetAttr - Improve handling of radio items, and work correctly for radio items without a name - Stop causing nested DOM mutations. There is a big warning about doing this in nsIMutationObserver.h - Delay processing of DOM mutations during code sections when we are dispatching events. This should prevent a recurrence of reentrancy-triggered crashes such as LP: #1025011, LP: #1035305 and LP: #1051152, which have been exposed by updates of third-party addons recently and caused because our view of the menu changes during event delivery - Fix crash in uGlobalMenuDocListener::HandleMutations * Fix for bmo: #795395 - add debian/patches/fix-for-bmo795395.patch - update debian/patches/series * Drop compare-locales from the packaging, and just check out the current version when we create the tarball - update debian/build/mozbuild.mk - update debian/build/create-tarball.py - remove debian/build/compare-locales * Ensure the Apport hook parses the system preferences - update debian/apport/source_thunderbird.py.in Date: 2012-10-10 23:15:17.382451+00:00 Changed-By: Chris Coulson Signed-By: Ubuntu Archive Robot https://launchpad.net/ubuntu/natty/+source/thunderbird/16.0.1+build1-0ubuntu0.11.04.1 -------------- next part -------------- Sorry, changesfile not available. From cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk Fri Oct 12 11:33:27 2012 From: cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk (Ubuntu Archive Robot) Date: Fri, 12 Oct 2012 11:33:27 -0000 Subject: [ubuntu/natty-updates] enigmail 2:1.4.5-0ubuntu0.11.04.1 (Accepted) Message-ID: <20121012113327.28075.68757.launchpad@ackee.canonical.com> enigmail (2:1.4.5-0ubuntu0.11.04.1) natty-security; urgency=low * New upstream release v1.4.5 to support Thunderbird 16 - LP: #1062587 * Add patch to set the correct version number. The version was not changed from 1.5a1pre to 1.4.5 when the tarball was built from rev 24e938 - add debian/patches/correct-version-number.diff - update debian/patches/series Date: 2012-10-09 18:25:40.264550+00:00 Changed-By: Chris Coulson Signed-By: Ubuntu Archive Robot https://launchpad.net/ubuntu/natty/+source/enigmail/2:1.4.5-0ubuntu0.11.04.1 -------------- next part -------------- Sorry, changesfile not available. From cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk Fri Oct 12 11:33:29 2012 From: cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk (Ubuntu Archive Robot) Date: Fri, 12 Oct 2012 11:33:29 -0000 Subject: [ubuntu/natty-updates] lightning-extension 1.8+build1-0ubuntu0.11.04.1 (Accepted) Message-ID: <20121012113329.28075.24009.launchpad@ackee.canonical.com> lightning-extension (1.8+build1-0ubuntu0.11.04.1) natty-security; urgency=low * New upstream stable release to support Thunderbird 16 (CALENDAR_1_8_BUILD1) - LP: #1062587 * Add extra Makefiles that are needed for the build - update debian/rules Date: 2012-10-09 09:10:27.906911+00:00 Changed-By: Chris Coulson Signed-By: Ubuntu Archive Robot https://launchpad.net/ubuntu/natty/+source/lightning-extension/1.8+build1-0ubuntu0.11.04.1 -------------- next part -------------- Sorry, changesfile not available. From tyhicks at canonical.com Mon Oct 15 16:41:14 2012 From: tyhicks at canonical.com (Tyler Hicks) Date: Mon, 15 Oct 2012 16:41:14 -0000 Subject: [ubuntu/natty-security] libgssglue 0.1-4ubuntu1.1 (Accepted) Message-ID: <20121015164114.6666.93695.launchpad@ackee.canonical.com> libgssglue (0.1-4ubuntu1.1) natty-security; urgency=low * SECURITY UPDATE: Privilege escalation via malicious environment variable - debian/patches/07-CVE_2011_2709.patch: Only read the GSSAPI_MECH_CONF environment variable in non-setuid situations. Based on upstream patch. - CVE-2011-2709 Date: 2012-09-28 09:00:33.237504+00:00 Changed-By: Tyler Hicks https://launchpad.net/ubuntu/natty/+source/libgssglue/0.1-4ubuntu1.1 -------------- next part -------------- Sorry, changesfile not available. From cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk Mon Oct 15 17:28:16 2012 From: cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk (Ubuntu Archive Robot) Date: Mon, 15 Oct 2012 17:28:16 -0000 Subject: [ubuntu/natty-updates] libgssglue 0.1-4ubuntu1.1 (Accepted) Message-ID: <20121015172816.21442.24807.launchpad@ackee.canonical.com> libgssglue (0.1-4ubuntu1.1) natty-security; urgency=low * SECURITY UPDATE: Privilege escalation via malicious environment variable - debian/patches/07-CVE_2011_2709.patch: Only read the GSSAPI_MECH_CONF environment variable in non-setuid situations. Based on upstream patch. - CVE-2011-2709 Date: 2012-09-28 09:00:33.237504+00:00 Changed-By: Tyler Hicks Signed-By: Ubuntu Archive Robot https://launchpad.net/ubuntu/natty/+source/libgssglue/0.1-4ubuntu1.1 -------------- next part -------------- Sorry, changesfile not available. From ubuntu at kitterman.com Fri Oct 19 02:44:23 2012 From: ubuntu at kitterman.com (Scott Kitterman) Date: Fri, 19 Oct 2012 02:44:23 -0000 Subject: [ubuntu/natty-updates] clamav 0.97.6+dfsg-1ubuntu0.11.04.1 (Accepted) Message-ID: <20121019024423.8638.58677.launchpad@ackee.canonical.com> clamav (0.97.6+dfsg-1ubuntu0.11.04.1) natty-proposed; urgency=low * Microversion update to latest clamav release for natty (LP: #1064096) clamav (0.97.6+dfsg-1ubuntu1) quantal; urgency=low * Merge from Debian unstable. Remaining changes: - Drop build-dep on electric-fence (in Universe) - Add apparmor profiles for clamd and freshclam along with maintainer script changes clamav (0.97.6+dfsg-1) unstable; urgency=low * New upstream release (Closes: #689487) * Update libclamav6 lintian override to match updated soversion clamav (0.97.5+dfsg-6ubuntu2) quantal; urgency=low * debian/clamav-base.install, debian/source_clamav.py: Install apport hook so we can get AppArmor denials in bug reports. clamav (0.97.5+dfsg-6ubuntu1) quantal; urgency=low * Merge from Debian unstable (LP: #1015405). Remaining changes: - Drop build-dep on electric-fence (in Universe) - Add apparmor profiles for clamd and freshclam along with maintainer script changes clamav (0.97.5+dfsg-6) unstable; urgency=medium * Urgency medium for RC bug fix the addressess regression from 0.97.3 * Add changes from upstream commit 6a879ad98460303b23a6fc119769a3b463a902f8 to fix unpack errors for various compressed files including some .bz2, .xls, .doc, and PDF (Closes: #684697) clamav (0.97.5+dfsg-5) unstable; urgency=low * Drop /var/run/clamav from the directories shipped in clamav-base (policy 9.1.4) and trust it will get cleaned up on boot - Thanks to Andreas Beckmann for the cluebat clamav (0.97.5+dfsg-4) unstable; urgency=low * Drop postrm snippets from clamav-base, clamav-freshclam, clamav-daemon, and clamav-milter that remove /var/log/clamav, /var/lib/clamav, /var/run/clamav, and /etc/clamav and and let dpkg remove the directories once they are empty in order to fix problems with directory removal by a package that did not own the directory (Closes: #681960) * Add /var/run/clamav to directories shipped by clamav-base so dpkg cleanup will work for it too. clamav (0.97.5+dfsg-3ubuntu1) quantal; urgency=low * Merge from Debian unstable. Remaining changes: - Drop build-dep on electric-fence (in Universe) - Add apparmor profiles for clamd and freshclam along with maintainer script changes clamav (0.97.5+dfsg-3) unstable; urgency=low * Fix proxy port configuration handling in clamav-freshclam.postinst so that failure to specify port does not result in an invalid configuration (Closes: #678247), (LP: #784797) clamav (0.97.5+dfsg-2ubuntu1) quantal; urgency=low * Merge from Debian Unstable. Remaining Ubuntu changes: - Drop build-dep on electric-fence (in Universe) - Add apparmor profiles for clamd and freshclam along with maintainer script changes clamav (0.97.5+dfsg-2) unstable; urgency=medium * Medium urgency due to security fixes * Update debian/clamav-base.postinst.in to test for the existence of the actual .cvd files before trying to install them and not just the directory they should be in (Closes: #678019) * Remove /var/run/clamav on purge (LP: #829945) - Thanks to Imre Gergely for the patch * Add call to /sbin/restorecon in debian/common_functions make_directory to to label the /run directory for SE Linux (Closes: #677686) - Thanks to Russell Coker for the patch * Remove obsolete reference to clamav-data package in clamav-daemon init log failure message clamav (0.97.5+dfsg-1ubuntu1) quantal; urgency=low * Merge from Debian Unstable. Remaining Ubuntu changes: - Drop build-dep on electric-fence (in Universe) - Add apparmor profiles for clamd and freshclam along with maintainer script changes * New upstream version no longer includes virus definition files (LP: #460316) Date: 2012-10-09 19:40:14.602776+00:00 Changed-By: Scott Kitterman https://launchpad.net/ubuntu/natty/+source/clamav/0.97.6+dfsg-1ubuntu0.11.04.1 -------------- next part -------------- Sorry, changesfile not available. From cjwatson at canonical.com Fri Oct 19 17:27:15 2012 From: cjwatson at canonical.com (Colin Watson) Date: Fri, 19 Oct 2012 17:27:15 -0000 Subject: [ubuntu/natty-updates] pyabiword 0.8.0-6build2 (Accepted) Message-ID: <20121019172715.17999.68612.launchpad@ackee.canonical.com> pyabiword (0.8.0-6build2) natty-proposed; urgency=low * No-change rebuild against latest abiword. (LP: #774017) Date: 2011-07-07 03:45:11.676795+00:00 Changed-By: Luke Faraone Signed-By: Colin Watson https://launchpad.net/ubuntu/natty/+source/pyabiword/0.8.0-6build2 -------------- next part -------------- Sorry, changesfile not available. From jamie at ubuntu.com Fri Oct 19 20:15:16 2012 From: jamie at ubuntu.com (Jamie Strandboge) Date: Fri, 19 Oct 2012 20:15:16 -0000 Subject: [ubuntu/natty-security] hostapd 1:0.6.10-2+squeeze1build0.11.04.1 (Accepted) Message-ID: <20121019201516.4132.35448.launchpad@ackee.canonical.com> hostapd (1:0.6.10-2+squeeze1build0.11.04.1) natty-security; urgency=low * fake sync from Debian Date: 2012-10-19 19:15:12.022205+00:00 Changed-By: Jamie Strandboge https://launchpad.net/ubuntu/natty/+source/hostapd/1:0.6.10-2+squeeze1build0.11.04.1 -------------- next part -------------- Sorry, changesfile not available. From cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk Fri Oct 19 20:58:10 2012 From: cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk (Ubuntu Archive Robot) Date: Fri, 19 Oct 2012 20:58:10 -0000 Subject: [ubuntu/natty-updates] hostapd 1:0.6.10-2+squeeze1build0.11.04.1 (Accepted) Message-ID: <20121019205810.16780.73127.launchpad@ackee.canonical.com> hostapd (1:0.6.10-2+squeeze1build0.11.04.1) natty-security; urgency=low * fake sync from Debian Date: 2012-10-19 19:15:12.022205+00:00 Changed-By: Jamie Strandboge Signed-By: Ubuntu Archive Robot https://launchpad.net/ubuntu/natty/+source/hostapd/1:0.6.10-2+squeeze1build0.11.04.1 -------------- next part -------------- Sorry, changesfile not available. From jamie at ubuntu.com Tue Oct 23 18:34:20 2012 From: jamie at ubuntu.com (Jamie Strandboge) Date: Tue, 23 Oct 2012 18:34:20 -0000 Subject: [ubuntu/natty-security] python3.2 3.2-1ubuntu1.2 (Accepted) Message-ID: <20121023183420.2304.62632.launchpad@ackee.canonical.com> python3.2 (3.2-1ubuntu1.2) natty-security; urgency=low * SECURITY UPDATE: http://bugs.python.org/issue13512 - debian/patches/CVE-2011-4944.diff: create ~/.pypirc securely - CVE-2011-4944 * SECURITY UPDATE: xmlrpc: Fix an endless loop in SimpleXMLRPCServer upon malformed POST request - debian/patches/CVE-2012-0845.diff: break if don't receive EOF in Lib/SimpleXMLRPCServer.py - CVE-2012-0845 * SECURITY UPDATE: fix hash randomization DoS - debian/patches/CVE-2012-1150.diff: add -R command-line option and PYTHONHASHSEED environment variable, to provide an opt-in way to protect against denial of service attacks due to hash collisions within the dict and set types. - CVE-2012-1150 * SECURITY UPDATE: http://bugs.python.org/issue14579 - debian/patches/CVE-2012-2135.diff: fix vulnerability in the utf-16 decoder after error handling - CVE-2012-2135 Date: 2012-10-20 14:00:12.448856+00:00 Changed-By: Jamie Strandboge https://launchpad.net/ubuntu/natty/+source/python3.2/3.2-1ubuntu1.2 -------------- next part -------------- Sorry, changesfile not available. From cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk Tue Oct 23 19:29:13 2012 From: cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk (Ubuntu Archive Robot) Date: Tue, 23 Oct 2012 19:29:13 -0000 Subject: [ubuntu/natty-updates] python3.2 3.2-1ubuntu1.2 (Accepted) Message-ID: <20121023192913.18718.49420.launchpad@ackee.canonical.com> python3.2 (3.2-1ubuntu1.2) natty-security; urgency=low * SECURITY UPDATE: http://bugs.python.org/issue13512 - debian/patches/CVE-2011-4944.diff: create ~/.pypirc securely - CVE-2011-4944 * SECURITY UPDATE: xmlrpc: Fix an endless loop in SimpleXMLRPCServer upon malformed POST request - debian/patches/CVE-2012-0845.diff: break if don't receive EOF in Lib/SimpleXMLRPCServer.py - CVE-2012-0845 * SECURITY UPDATE: fix hash randomization DoS - debian/patches/CVE-2012-1150.diff: add -R command-line option and PYTHONHASHSEED environment variable, to provide an opt-in way to protect against denial of service attacks due to hash collisions within the dict and set types. - CVE-2012-1150 * SECURITY UPDATE: http://bugs.python.org/issue14579 - debian/patches/CVE-2012-2135.diff: fix vulnerability in the utf-16 decoder after error handling - CVE-2012-2135 Date: 2012-10-20 14:00:12.448856+00:00 Changed-By: Jamie Strandboge Signed-By: Ubuntu Archive Robot https://launchpad.net/ubuntu/natty/+source/python3.2/3.2-1ubuntu1.2 -------------- next part -------------- Sorry, changesfile not available. From jamie at ubuntu.com Wed Oct 24 15:37:14 2012 From: jamie at ubuntu.com (Jamie Strandboge) Date: Wed, 24 Oct 2012 15:37:14 -0000 Subject: [ubuntu/natty-security] python3.1 3.1.3-1ubuntu1.2 (Accepted) Message-ID: <20121024153714.29966.45922.launchpad@ackee.canonical.com> python3.1 (3.1.3-1ubuntu1.2) natty-security; urgency=low * SECURE UPDATE: http://bugs.python.org/issue13512 - debian/patches/CVE-2011-4944.diff: create ~/.pypirc securely - CVE-2011-4944 * SECURITY UPDATE: xmlrpc: Fix an endless loop in SimpleXMLRPCServer upon malformed POST request - debian/patches/CVE-2012-0845.diff: break if don't receive EOF in Lib/SimpleXMLRPCServer.py - CVE-2012-0845 * SECURITY UPDATE: fix hash randomization DoS - debian/patches/CVE-2012-1150.diff: add -R command-line option and PYTHONHASHSEED environment variable, to provide an opt-in way to protect against denial of service attacks due to hash collisions within the dict and set types. - CVE-2012-1150 * SECURITY UPDATE: http://bugs.python.org/issue14579 - debian/patches/CVE-2012-2135.diff: fix vulnerability in the utf-16 decoder after error handling - CVE-2012-2135 Date: 2012-10-23 20:05:13.640939+00:00 Changed-By: Jamie Strandboge https://launchpad.net/ubuntu/natty/+source/python3.1/3.1.3-1ubuntu1.2 -------------- next part -------------- Sorry, changesfile not available. From cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk Wed Oct 24 16:28:16 2012 From: cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk (Ubuntu Archive Robot) Date: Wed, 24 Oct 2012 16:28:16 -0000 Subject: [ubuntu/natty-updates] python3.1 3.1.3-1ubuntu1.2 (Accepted) Message-ID: <20121024162816.14600.11889.launchpad@ackee.canonical.com> python3.1 (3.1.3-1ubuntu1.2) natty-security; urgency=low * SECURE UPDATE: http://bugs.python.org/issue13512 - debian/patches/CVE-2011-4944.diff: create ~/.pypirc securely - CVE-2011-4944 * SECURITY UPDATE: xmlrpc: Fix an endless loop in SimpleXMLRPCServer upon malformed POST request - debian/patches/CVE-2012-0845.diff: break if don't receive EOF in Lib/SimpleXMLRPCServer.py - CVE-2012-0845 * SECURITY UPDATE: fix hash randomization DoS - debian/patches/CVE-2012-1150.diff: add -R command-line option and PYTHONHASHSEED environment variable, to provide an opt-in way to protect against denial of service attacks due to hash collisions within the dict and set types. - CVE-2012-1150 * SECURITY UPDATE: http://bugs.python.org/issue14579 - debian/patches/CVE-2012-2135.diff: fix vulnerability in the utf-16 decoder after error handling - CVE-2012-2135 Date: 2012-10-23 20:05:13.640939+00:00 Changed-By: Jamie Strandboge Signed-By: Ubuntu Archive Robot https://launchpad.net/ubuntu/natty/+source/python3.1/3.1.3-1ubuntu1.2 -------------- next part -------------- Sorry, changesfile not available. From marc.deslauriers at canonical.com Fri Oct 26 11:46:28 2012 From: marc.deslauriers at canonical.com (Marc Deslauriers) Date: Fri, 26 Oct 2012 11:46:28 -0000 Subject: [ubuntu/natty-security] exim4 4.74-1ubuntu1.3 (Accepted) Message-ID: <20121026114628.30689.75242.launchpad@ackee.canonical.com> exim4 (4.74-1ubuntu1.3) natty-security; urgency=low * SECURITY UPDATE: arbitrary code execution via dns decode logic - debian/patches/CVE-2012-5671.patch: adjust max length and validate against it in src/pdkim/pdkim.h, src/dkim.c. - CVE-2012-5671 Date: 2012-10-25 14:10:10.767522+00:00 Changed-By: Marc Deslauriers https://launchpad.net/ubuntu/natty/+source/exim4/4.74-1ubuntu1.3 -------------- next part -------------- Sorry, changesfile not available. From cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk Fri Oct 26 12:28:16 2012 From: cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk (Ubuntu Archive Robot) Date: Fri, 26 Oct 2012 12:28:16 -0000 Subject: [ubuntu/natty-updates] exim4 4.74-1ubuntu1.3 (Accepted) Message-ID: <20121026122816.11156.85178.launchpad@ackee.canonical.com> exim4 (4.74-1ubuntu1.3) natty-security; urgency=low * SECURITY UPDATE: arbitrary code execution via dns decode logic - debian/patches/CVE-2012-5671.patch: adjust max length and validate against it in src/pdkim/pdkim.h, src/dkim.c. - CVE-2012-5671 Date: 2012-10-25 14:10:10.767522+00:00 Changed-By: Marc Deslauriers Signed-By: Ubuntu Archive Robot https://launchpad.net/ubuntu/natty/+source/exim4/4.74-1ubuntu1.3 -------------- next part -------------- Sorry, changesfile not available. From jamie at ubuntu.com Fri Oct 26 14:39:27 2012 From: jamie at ubuntu.com (Jamie Strandboge) Date: Fri, 26 Oct 2012 14:39:27 -0000 Subject: [ubuntu/natty-security] openjdk-6 6b24-1.11.5-0ubuntu1~11.04.1 (Accepted) Message-ID: <20121026143927.17837.69943.launchpad@ackee.canonical.com> openjdk-6 (6b24-1.11.5-0ubuntu1~11.04.1) natty-security; urgency=low * Build for natty. openjdk-6 (6b24-1.11.5-0ubuntu1) quantal-security; urgency=low * IcedTea 1.11.5 release. * Security fixes - S6631398, CVE-2012-3216: FilePermission improved path checking. - S7093490: adjust package access in rmiregistry. - S7143535, CVE-2012-5068: ScriptEngine corrected permissions. - S7167656, CVE-2012-5077: Multiple Seeders are being created. - S7169884, CVE-2012-5073: LogManager checks do not work correctly for sub-types. - S7169888, CVE-2012-5075: Narrowing resource definitions in JMX RMI connector. - S7172522, CVE-2012-5072: Improve DomainCombiner checking. - S7186286, CVE-2012-5081: TLS implementation to better adhere to RFC. - S7189103, CVE-2012-5069: Executors needs to maintain state. - S7189490: More improvements to DomainCombiner checking. - S7189567, CVE-2012-5085: java net obselete protocol. - S7192975, CVE-2012-5071: Conditional usage check is wrong. - S7195194, CVE-2012-5084: Better data validation for Swing. - S7195917, CVE-2012-5086: XMLDecoder parsing at close-time should be improved. - S7195919, CVE-2012-5079: (sl) ServiceLoader can throw CCE without needing to create instance. - S7198296, CVE-2012-5089: Refactor classloader usage. - S7158800: Improve storage of symbol tables. - S7158801: Improve VM CompileOnly option. - S7158804: Improve config file parsing. - S7176337: Additional changes needed for 7158801 fix. - S7198606, CVE-2012-4416: Improve VM optimization. * Bug fixes - S7175845: "jar uf" changes file permissions unexpectedly. - S7177216: native2ascii changes file permissions of input file. - S7199153: TEST_BUG: try-with-resources syntax pushed to 6-open repo. openjdk-6 (6b24-1.11.4-3ubuntu1) quantal; urgency=low * Merge with Debian. openjdk-6 (6b24-1.11.4-3) unstable; urgency=low * Regenerate the control file to fix build dependencies on mips/mipsel. openjdk-6 (6b24-1.11.4-2) unstable; urgency=low * Remove the autoconf Xp check. Date: 2012-10-24 20:40:17.485508+00:00 Changed-By: Matthias Klose Maintainer: OpenJDK Signed-By: Jamie Strandboge https://launchpad.net/ubuntu/natty/+source/openjdk-6/6b24-1.11.5-0ubuntu1~11.04.1 -------------- next part -------------- Sorry, changesfile not available. From cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk Fri Oct 26 15:29:26 2012 From: cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk (Ubuntu Archive Robot) Date: Fri, 26 Oct 2012 15:29:26 -0000 Subject: [ubuntu/natty-updates] openjdk-6 6b24-1.11.5-0ubuntu1~11.04.1 (Accepted) Message-ID: <20121026152926.888.94100.launchpad@ackee.canonical.com> openjdk-6 (6b24-1.11.5-0ubuntu1~11.04.1) natty-security; urgency=low * Build for natty. openjdk-6 (6b24-1.11.5-0ubuntu1) quantal-security; urgency=low * IcedTea 1.11.5 release. * Security fixes - S6631398, CVE-2012-3216: FilePermission improved path checking. - S7093490: adjust package access in rmiregistry. - S7143535, CVE-2012-5068: ScriptEngine corrected permissions. - S7167656, CVE-2012-5077: Multiple Seeders are being created. - S7169884, CVE-2012-5073: LogManager checks do not work correctly for sub-types. - S7169888, CVE-2012-5075: Narrowing resource definitions in JMX RMI connector. - S7172522, CVE-2012-5072: Improve DomainCombiner checking. - S7186286, CVE-2012-5081: TLS implementation to better adhere to RFC. - S7189103, CVE-2012-5069: Executors needs to maintain state. - S7189490: More improvements to DomainCombiner checking. - S7189567, CVE-2012-5085: java net obselete protocol. - S7192975, CVE-2012-5071: Conditional usage check is wrong. - S7195194, CVE-2012-5084: Better data validation for Swing. - S7195917, CVE-2012-5086: XMLDecoder parsing at close-time should be improved. - S7195919, CVE-2012-5079: (sl) ServiceLoader can throw CCE without needing to create instance. - S7198296, CVE-2012-5089: Refactor classloader usage. - S7158800: Improve storage of symbol tables. - S7158801: Improve VM CompileOnly option. - S7158804: Improve config file parsing. - S7176337: Additional changes needed for 7158801 fix. - S7198606, CVE-2012-4416: Improve VM optimization. * Bug fixes - S7175845: "jar uf" changes file permissions unexpectedly. - S7177216: native2ascii changes file permissions of input file. - S7199153: TEST_BUG: try-with-resources syntax pushed to 6-open repo. openjdk-6 (6b24-1.11.4-3ubuntu1) quantal; urgency=low * Merge with Debian. openjdk-6 (6b24-1.11.4-3) unstable; urgency=low * Regenerate the control file to fix build dependencies on mips/mipsel. openjdk-6 (6b24-1.11.4-2) unstable; urgency=low * Remove the autoconf Xp check. Date: 2012-10-24 20:40:17.485508+00:00 Changed-By: Matthias Klose Maintainer: OpenJDK Signed-By: Ubuntu Archive Robot https://launchpad.net/ubuntu/natty/+source/openjdk-6/6b24-1.11.5-0ubuntu1~11.04.1 -------------- next part -------------- Sorry, changesfile not available. From jamie at ubuntu.com Fri Oct 26 20:47:06 2012 From: jamie at ubuntu.com (Jamie Strandboge) Date: Fri, 26 Oct 2012 20:47:06 -0000 Subject: [ubuntu/natty-security] firefox 16.0.2+build1-0ubuntu0.11.04.1 (Accepted) Message-ID: <20121026204706.2082.51339.launchpad@ackee.canonical.com> firefox (16.0.2+build1-0ubuntu0.11.04.1) natty-security; urgency=low * New upstream stable release (FIREFOX_16_0_2_BUILD1) - see LP: #1071392 for USN information Date: 2012-10-25 21:30:11.040787+00:00 Changed-By: Micah Gersten Signed-By: Jamie Strandboge https://launchpad.net/ubuntu/natty/+source/firefox/16.0.2+build1-0ubuntu0.11.04.1 -------------- next part -------------- Sorry, changesfile not available. From cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk Fri Oct 26 22:06:28 2012 From: cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk (Ubuntu Archive Robot) Date: Fri, 26 Oct 2012 22:06:28 -0000 Subject: [ubuntu/natty-updates] firefox 16.0.2+build1-0ubuntu0.11.04.1 (Accepted) Message-ID: <20121026220628.25247.85793.launchpad@ackee.canonical.com> firefox (16.0.2+build1-0ubuntu0.11.04.1) natty-security; urgency=low * New upstream stable release (FIREFOX_16_0_2_BUILD1) - see LP: #1071392 for USN information Date: 2012-10-25 21:30:11.040787+00:00 Changed-By: Micah Gersten Signed-By: Ubuntu Archive Robot https://launchpad.net/ubuntu/natty/+source/firefox/16.0.2+build1-0ubuntu0.11.04.1 -------------- next part -------------- Sorry, changesfile not available. From andreas at canonical.com Tue Oct 30 13:40:32 2012 From: andreas at canonical.com (Andreas Hasenack) Date: Tue, 30 Oct 2012 13:40:32 -0000 Subject: [ubuntu/natty-proposed] landscape-client 12.05-0ubuntu1.11.04 (Accepted) Message-ID: <20121030134032.22269.49371.launchpad@wampee.canonical.com> landscape-client (12.05-0ubuntu1.11.04) natty-proposed; urgency=low * Added fix for lshw storm when the client was talking to an old Landscape server which was then upgraded (LP: #1053057). Date: Tue, 25 Sep 2012 06:08:42 -0700 Changed-By: Andreas Hasenack Maintainer: Ubuntu Developers Signed-By: Clint Byrum https://launchpad.net/ubuntu/natty/+source/landscape-client/12.05-0ubuntu1.11.04 -------------- next part -------------- Format: 1.8 Date: Tue, 25 Sep 2012 06:08:42 -0700 Source: landscape-client Binary: landscape-common landscape-client landscape-client-ui landscape-client-ui-install Architecture: source Version: 12.05-0ubuntu1.11.04 Distribution: natty-proposed Urgency: low Maintainer: Ubuntu Developers Changed-By: Andreas Hasenack Description: landscape-client - The Landscape administration system client landscape-client-ui - The Landscape administration system client - UI configuration landscape-client-ui-install - The Landscape administration system client - UI installer landscape-common - The Landscape administration system client - Common files Launchpad-Bugs-Fixed: 1053057 Changes: landscape-client (12.05-0ubuntu1.11.04) natty-proposed; urgency=low . * Added fix for lshw storm when the client was talking to an old Landscape server which was then upgraded (LP: #1053057). Checksums-Sha1: 268771cb3edbb86babed81e0bab4e137fde62303 1875 landscape-client_12.05-0ubuntu1.11.04.dsc 7b9d9374e2d16c6e61a7f17a332592c5cf749798 27878 landscape-client_12.05-0ubuntu1.11.04.debian.tar.gz Checksums-Sha256: 3d7dd167b18314614674d5143724f9dc5d5e8d0441d6e05b908c1ae851e90efa 1875 landscape-client_12.05-0ubuntu1.11.04.dsc f48842bbafc3c070cc4d2027639a3d0f7afed10edca55ecc8fb220a42bae08c7 27878 landscape-client_12.05-0ubuntu1.11.04.debian.tar.gz Files: e3d3a302197a15df0113e94061b87809 1875 admin optional landscape-client_12.05-0ubuntu1.11.04.dsc 9e9634f3d14084fc70fc894d4f210f54 27878 admin optional landscape-client_12.05-0ubuntu1.11.04.debian.tar.gz Original-Maintainer: Landscape Team