From sbeattie at ubuntu.com Mon Sep 3 19:04:21 2012 From: sbeattie at ubuntu.com (Steve Beattie) Date: Mon, 03 Sep 2012 19:04:21 -0000 Subject: [ubuntu/natty-security] openjdk-6 6b24-1.11.4-1ubuntu0.11.04.1 (Accepted) Message-ID: <20120903190421.13467.7569.launchpad@ackee.canonical.com> openjdk-6 (6b24-1.11.4-1ubuntu0.11.04.1) natty-security; urgency=low * SECURITY UPDATE: Update to IcedTea 6 1.11.4 - Security fixes: - S7162476, CVE-2012-1682: XMLDecoder security issue via ClassFinder - S7163201, CVE-2012-0547: Simplify toolkit internals references - Bug fixes: - S7182135: Impossible to use some editors directly - S7185678: java/awt/Menu/NullMenuLabelTest/NullMenuLabelTest.java failed with NPE Date: 2012-09-01 07:05:22.265876+00:00 Changed-By: Steve Beattie https://launchpad.net/ubuntu/natty/+source/openjdk-6/6b24-1.11.4-1ubuntu0.11.04.1 -------------- next part -------------- Sorry, changesfile not available. From cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk Mon Sep 3 19:59:14 2012 From: cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk (Ubuntu Archive Robot) Date: Mon, 03 Sep 2012 19:59:14 -0000 Subject: [ubuntu/natty-updates] openjdk-6 6b24-1.11.4-1ubuntu0.11.04.1 (Accepted) Message-ID: <20120903195914.28919.8652.launchpad@ackee.canonical.com> openjdk-6 (6b24-1.11.4-1ubuntu0.11.04.1) natty-security; urgency=low * SECURITY UPDATE: Update to IcedTea 6 1.11.4 - Security fixes: - S7162476, CVE-2012-1682: XMLDecoder security issue via ClassFinder - S7163201, CVE-2012-0547: Simplify toolkit internals references - Bug fixes: - S7182135: Impossible to use some editors directly - S7185678: java/awt/Menu/NullMenuLabelTest/NullMenuLabelTest.java failed with NPE Date: 2012-09-01 07:05:22.265876+00:00 Changed-By: Steve Beattie Signed-By: Ubuntu Archive Robot https://launchpad.net/ubuntu/natty/+source/openjdk-6/6b24-1.11.4-1ubuntu0.11.04.1 -------------- next part -------------- Sorry, changesfile not available. From brad.figg at canonical.com Fri Sep 7 22:17:10 2012 From: brad.figg at canonical.com (Brad Figg) Date: Fri, 07 Sep 2012 22:17:10 -0000 Subject: [ubuntu/natty-proposed] linux-backports-modules-2.6.38 2.6.38-16.12 (Accepted) Message-ID: <20120907221710.20698.11768.launchpad@ackee.canonical.com> linux-backports-modules-2.6.38 (2.6.38-16.12) natty-proposed; urgency=low [ Luis Henriques ] * Bump ABI - Natty ABI 16 Date: 2012-09-07 10:05:11.383947+00:00 Changed-By: Luis Henriques Signed-By: Brad Figg https://launchpad.net/ubuntu/natty/+source/linux-backports-modules-2.6.38/2.6.38-16.12 -------------- next part -------------- Sorry, changesfile not available. From brad.figg at canonical.com Fri Sep 7 22:17:16 2012 From: brad.figg at canonical.com (Brad Figg) Date: Fri, 07 Sep 2012 22:17:16 -0000 Subject: [ubuntu/natty-proposed] linux-meta 2.6.38.16.31 (Accepted) Message-ID: <20120907221716.20698.40504.launchpad@ackee.canonical.com> linux-meta (2.6.38.16.31) natty-proposed; urgency=low [ Tim Gardner ] * Move all header meta packages into Section: metapackages - LP: #988447 * No meta packages belong in the restricted component - LP: #1016702 [ Luis Henriques ] * Fix Vcs-Git in linux-natty-meta - LP: #999726 * Bump ABI Date: 2012-09-06 17:55:41.244647+00:00 Changed-By: Luis Henriques Signed-By: Brad Figg https://launchpad.net/ubuntu/natty/+source/linux-meta/2.6.38.16.31 -------------- next part -------------- Sorry, changesfile not available. From brad.figg at canonical.com Fri Sep 7 22:17:26 2012 From: brad.figg at canonical.com (Brad Figg) Date: Fri, 07 Sep 2012 22:17:26 -0000 Subject: [ubuntu/natty-proposed] linux 2.6.38-16.67 (Accepted) Message-ID: <20120907221726.20698.19655.launchpad@ackee.canonical.com> linux (2.6.38-16.67) natty-proposed; urgency=low [Luis Henriques] * Release Tracking Bug - LP: #1045383 [ Upstream Kernel Changes ] * rds: set correct msg_namelen - LP: #1031112 - CVE-2012-3430 * eCryptfs: Initialize empty lower files when opening them - LP: #911507 * net: Allow driver to limit number of GSO segments per skb - LP: #1037456 - CVE-2012-3412 * tcp: do not scale TSO segment size with reordering degree - LP: #1037456 - CVE-2012-3412 * tcp: Apply device TSO segment limit earlier - LP: #1037456 - CVE-2012-3412 * sfc: Replace some literal constants with EFX_PAGE_SIZE/EFX_BUF_SIZE - LP: #1037456 - CVE-2012-3412 * sfc: Fix maximum number of TSO segments and minimum TX queue size - LP: #1037456 - CVE-2012-3412 * mm: Hold a file reference in madvise_remove - LP: #1042447 - CVE-2012-3511 * cred: copy_process() should clear child->replacement_session_keyring - LP: #1023535 - CVE-2012-2745 Date: 2012-09-06 17:55:11.507538+00:00 Changed-By: Luis Henriques Signed-By: Brad Figg https://launchpad.net/ubuntu/natty/+source/linux/2.6.38-16.67 -------------- next part -------------- Sorry, changesfile not available. From tyhicks at canonical.com Fri Sep 7 22:50:15 2012 From: tyhicks at canonical.com (Tyler Hicks) Date: Fri, 07 Sep 2012 22:50:15 -0000 Subject: [ubuntu/natty-security] otrs2 2.4.9+dfsg1-3+squeeze3build0.11.04.1 (Accepted) Message-ID: <20120907225015.30247.30673.launchpad@ackee.canonical.com> otrs2 (2.4.9+dfsg1-3+squeeze3build0.11.04.1) natty-security; urgency=low * fake sync from Debian otrs2 (2.4.9+dfsg1-3+squeeze3) stable-security; urgency=high * Add upstream patch 17-security-osa-2012-01 from OSA-2012-01, which fixes a XSS vulnerability described in CVE-2012-2582 when using the Internet Explorer on viewing e-mails. * Add upstream patch 18-security-tag-nesting to improve HTML security to detect tag nasting. Date: 2012-09-07 17:10:10.326633+00:00 Changed-By: Tyler Hicks https://launchpad.net/ubuntu/natty/+source/otrs2/2.4.9+dfsg1-3+squeeze3build0.11.04.1 -------------- next part -------------- Sorry, changesfile not available. From tyhicks at canonical.com Fri Sep 7 22:50:16 2012 From: tyhicks at canonical.com (Tyler Hicks) Date: Fri, 07 Sep 2012 22:50:16 -0000 Subject: [ubuntu/natty-security] typo3-src 4.3.9+dfsg1-1+squeeze5build0.11.04.1 (Accepted) Message-ID: <20120907225016.30247.86355.launchpad@ackee.canonical.com> typo3-src (4.3.9+dfsg1-1+squeeze5build0.11.04.1) natty-security; urgency=low * fake sync from Debian typo3-src (4.3.9+dfsg1-1+squeeze5) squeeze-security; urgency=medium * Security patch backported from new upstream release 4.5.19: - fixes: "TYPO3 Security Bulletin TYPO3-CORE-SA-2012-004: Several Vulnerabilities in TYPO3 Core" (Closes: 685011) Date: 2012-09-07 16:55:14.799568+00:00 Changed-By: Tyler Hicks Maintainer: Christian Welzel https://launchpad.net/ubuntu/natty/+source/typo3-src/4.3.9+dfsg1-1+squeeze5build0.11.04.1 -------------- next part -------------- Sorry, changesfile not available. From cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk Fri Sep 7 23:28:10 2012 From: cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk (Ubuntu Archive Robot) Date: Fri, 07 Sep 2012 23:28:10 -0000 Subject: [ubuntu/natty-updates] otrs2 2.4.9+dfsg1-3+squeeze3build0.11.04.1 (Accepted) Message-ID: <20120907232810.9898.27391.launchpad@ackee.canonical.com> otrs2 (2.4.9+dfsg1-3+squeeze3build0.11.04.1) natty-security; urgency=low * fake sync from Debian otrs2 (2.4.9+dfsg1-3+squeeze3) stable-security; urgency=high * Add upstream patch 17-security-osa-2012-01 from OSA-2012-01, which fixes a XSS vulnerability described in CVE-2012-2582 when using the Internet Explorer on viewing e-mails. * Add upstream patch 18-security-tag-nesting to improve HTML security to detect tag nasting. Date: 2012-09-07 17:10:10.326633+00:00 Changed-By: Tyler Hicks Signed-By: Ubuntu Archive Robot https://launchpad.net/ubuntu/natty/+source/otrs2/2.4.9+dfsg1-3+squeeze3build0.11.04.1 -------------- next part -------------- Sorry, changesfile not available. From cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk Fri Sep 7 23:28:11 2012 From: cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk (Ubuntu Archive Robot) Date: Fri, 07 Sep 2012 23:28:11 -0000 Subject: [ubuntu/natty-updates] typo3-src 4.3.9+dfsg1-1+squeeze5build0.11.04.1 (Accepted) Message-ID: <20120907232811.9898.28328.launchpad@ackee.canonical.com> typo3-src (4.3.9+dfsg1-1+squeeze5build0.11.04.1) natty-security; urgency=low * fake sync from Debian typo3-src (4.3.9+dfsg1-1+squeeze5) squeeze-security; urgency=medium * Security patch backported from new upstream release 4.5.19: - fixes: "TYPO3 Security Bulletin TYPO3-CORE-SA-2012-004: Several Vulnerabilities in TYPO3 Core" (Closes: 685011) Date: 2012-09-07 16:55:14.799568+00:00 Changed-By: Tyler Hicks Maintainer: Christian Welzel Signed-By: Ubuntu Archive Robot https://launchpad.net/ubuntu/natty/+source/typo3-src/4.3.9+dfsg1-1+squeeze5build0.11.04.1 -------------- next part -------------- Sorry, changesfile not available. From tyhicks at canonical.com Sat Sep 8 01:44:12 2012 From: tyhicks at canonical.com (Tyler Hicks) Date: Sat, 08 Sep 2012 01:44:12 -0000 Subject: [ubuntu/natty-security] beaker 1.5.4-4+squeeze1build0.11.04.1 (Accepted) Message-ID: <20120908014412.17140.64873.launchpad@ackee.canonical.com> beaker (1.5.4-4+squeeze1build0.11.04.1) natty-security; urgency=low * fake sync from Debian Date: 2012-09-08 00:55:10.377892+00:00 Changed-By: Tyler Hicks Maintainer: Debian Python Modules Team https://launchpad.net/ubuntu/natty/+source/beaker/1.5.4-4+squeeze1build0.11.04.1 -------------- next part -------------- Sorry, changesfile not available. From cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk Sat Sep 8 02:28:10 2012 From: cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk (Ubuntu Archive Robot) Date: Sat, 08 Sep 2012 02:28:10 -0000 Subject: [ubuntu/natty-updates] beaker 1.5.4-4+squeeze1build0.11.04.1 (Accepted) Message-ID: <20120908022810.31312.45399.launchpad@ackee.canonical.com> beaker (1.5.4-4+squeeze1build0.11.04.1) natty-security; urgency=low * fake sync from Debian Date: 2012-09-08 00:55:10.377892+00:00 Changed-By: Tyler Hicks Maintainer: Debian Python Modules Team Signed-By: Ubuntu Archive Robot https://launchpad.net/ubuntu/natty/+source/beaker/1.5.4-4+squeeze1build0.11.04.1 -------------- next part -------------- Sorry, changesfile not available. From marc.deslauriers at canonical.com Mon Sep 10 12:22:25 2012 From: marc.deslauriers at canonical.com (Marc Deslauriers) Date: Mon, 10 Sep 2012 12:22:25 -0000 Subject: [ubuntu/natty-security] gimp 2.6.11-1ubuntu6.3 (Accepted) Message-ID: <20120910122225.10695.46553.launchpad@ackee.canonical.com> gimp (2.6.11-1ubuntu6.3) natty-security; urgency=low * SECURITY UPDATE: denial of service via malformed .fit file header - debian/patches/CVE-2012-3236.patch: check for valid XTENSION header in plug-ins/file-fits/fits-io.c. - CVE-2012-3236 * SECURITY UPDATE: denial of service and possible code execution via crafted KiSS palette file - debian/patches/CVE-2012-3403.patch: validate return codes and header data in plug-ins/common/file-cel.c. - CVE-2012-3403 * SECURITY UPDATE: denial of service and possible code execution via crafted GIF image file - debian/patches/CVE-2012-3481.patch: validate sizes, and prevent overflows in plug-ins/common/file-gif-load.c. - CVE-2012-3481 Date: 2012-09-05 20:55:10.696439+00:00 Changed-By: Marc Deslauriers Maintainer: Ubuntu Desktop https://launchpad.net/ubuntu/natty/+source/gimp/2.6.11-1ubuntu6.3 -------------- next part -------------- Sorry, changesfile not available. From marc.deslauriers at canonical.com Mon Sep 10 12:35:23 2012 From: marc.deslauriers at canonical.com (Marc Deslauriers) Date: Mon, 10 Sep 2012 12:35:23 -0000 Subject: [ubuntu/natty-security] python-django 1.2.5-1ubuntu1.2 (Accepted) Message-ID: <20120910123523.12531.32349.launchpad@ackee.canonical.com> python-django (1.2.5-1ubuntu1.2) natty-security; urgency=low * SECURITY UPDATE: Cross-site scripting in authentication views (LP: #1031733) - debian/patches/16_fix_cross_site_scripting_in_authentication.diff: fix unsafe redirects indjango/http/__init__.py, add test case to tests/regressiontests/httpwrappers/tests.py. Patch backport taken from Debian Squeeze and fixed for python 2.4 compatibility. - CVE-2012-3442 * SECURITY UPDATE: Denial-of-service in image validation (LP: #1031733) - debian/patches/17_fix_dos_in_image_validation.diff: call verify() immediately after the constructor in django/forms/fields.py. - CVE-2012-3443 * SECURITY UPDATE: Denial-of-service via get_image_dimensions() (LP: #1031733) - debian/patches/18_fix_dos_via_get_image_dimensions.diff: don't limit chunk size in django/core/files/images.py. - CVE-2012-3444 Date: 2012-09-06 14:20:14.708305+00:00 Changed-By: Marc Deslauriers https://launchpad.net/ubuntu/natty/+source/python-django/1.2.5-1ubuntu1.2 -------------- next part -------------- Sorry, changesfile not available. From cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk Mon Sep 10 12:59:15 2012 From: cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk (Ubuntu Archive Robot) Date: Mon, 10 Sep 2012 12:59:15 -0000 Subject: [ubuntu/natty-updates] gimp 2.6.11-1ubuntu6.3 (Accepted) Message-ID: <20120910125915.20630.40210.launchpad@ackee.canonical.com> gimp (2.6.11-1ubuntu6.3) natty-security; urgency=low * SECURITY UPDATE: denial of service via malformed .fit file header - debian/patches/CVE-2012-3236.patch: check for valid XTENSION header in plug-ins/file-fits/fits-io.c. - CVE-2012-3236 * SECURITY UPDATE: denial of service and possible code execution via crafted KiSS palette file - debian/patches/CVE-2012-3403.patch: validate return codes and header data in plug-ins/common/file-cel.c. - CVE-2012-3403 * SECURITY UPDATE: denial of service and possible code execution via crafted GIF image file - debian/patches/CVE-2012-3481.patch: validate sizes, and prevent overflows in plug-ins/common/file-gif-load.c. - CVE-2012-3481 Date: 2012-09-05 20:55:10.696439+00:00 Changed-By: Marc Deslauriers Maintainer: Ubuntu Desktop Signed-By: Ubuntu Archive Robot https://launchpad.net/ubuntu/natty/+source/gimp/2.6.11-1ubuntu6.3 -------------- next part -------------- Sorry, changesfile not available. From cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk Mon Sep 10 13:29:13 2012 From: cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk (Ubuntu Archive Robot) Date: Mon, 10 Sep 2012 13:29:13 -0000 Subject: [ubuntu/natty-updates] python-django 1.2.5-1ubuntu1.2 (Accepted) Message-ID: <20120910132913.29673.99223.launchpad@ackee.canonical.com> python-django (1.2.5-1ubuntu1.2) natty-security; urgency=low * SECURITY UPDATE: Cross-site scripting in authentication views (LP: #1031733) - debian/patches/16_fix_cross_site_scripting_in_authentication.diff: fix unsafe redirects indjango/http/__init__.py, add test case to tests/regressiontests/httpwrappers/tests.py. Patch backport taken from Debian Squeeze and fixed for python 2.4 compatibility. - CVE-2012-3442 * SECURITY UPDATE: Denial-of-service in image validation (LP: #1031733) - debian/patches/17_fix_dos_in_image_validation.diff: call verify() immediately after the constructor in django/forms/fields.py. - CVE-2012-3443 * SECURITY UPDATE: Denial-of-service via get_image_dimensions() (LP: #1031733) - debian/patches/18_fix_dos_via_get_image_dimensions.diff: don't limit chunk size in django/core/files/images.py. - CVE-2012-3444 Date: 2012-09-06 14:20:14.708305+00:00 Changed-By: Marc Deslauriers Signed-By: Ubuntu Archive Robot https://launchpad.net/ubuntu/natty/+source/python-django/1.2.5-1ubuntu1.2 -------------- next part -------------- Sorry, changesfile not available. From tyhicks at canonical.com Mon Sep 10 20:43:13 2012 From: tyhicks at canonical.com (Tyler Hicks) Date: Mon, 10 Sep 2012 20:43:13 -0000 Subject: [ubuntu/natty-security] xmlrpc-c 1.16.32-0ubuntu3.1 (Accepted) Message-ID: <20120910204313.30034.71799.launchpad@ackee.canonical.com> xmlrpc-c (1.16.32-0ubuntu3.1) natty-security; urgency=low * Run the tests as part of the build process - debian/patches/FTBFS-tests.patch: Fix issues when running make check. Based on upstream patches. - debian/rules: Run make check after building * SECURITY UPDATE: Denial of service via hash collisions - debian/patches/CVE-2012-0876.patch: Add random salt value to hash inputs. Based on upstream patch. - CVE-2012-0876 * SECURITY UPDATE: Denial of service via memory leak - debian/patches/CVE-2012-1148.patch: Properly reallocate memory. Based on upstream patch. - CVE-2012-1148 Date: 2012-09-10 08:15:19.570321+00:00 Changed-By: Tyler Hicks https://launchpad.net/ubuntu/natty/+source/xmlrpc-c/1.16.32-0ubuntu3.1 -------------- next part -------------- Sorry, changesfile not available. From cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk Mon Sep 10 21:28:12 2012 From: cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk (Ubuntu Archive Robot) Date: Mon, 10 Sep 2012 21:28:12 -0000 Subject: [ubuntu/natty-updates] xmlrpc-c 1.16.32-0ubuntu3.1 (Accepted) Message-ID: <20120910212812.11620.79027.launchpad@ackee.canonical.com> xmlrpc-c (1.16.32-0ubuntu3.1) natty-security; urgency=low * Run the tests as part of the build process - debian/patches/FTBFS-tests.patch: Fix issues when running make check. Based on upstream patches. - debian/rules: Run make check after building * SECURITY UPDATE: Denial of service via hash collisions - debian/patches/CVE-2012-0876.patch: Add random salt value to hash inputs. Based on upstream patch. - CVE-2012-0876 * SECURITY UPDATE: Denial of service via memory leak - debian/patches/CVE-2012-1148.patch: Properly reallocate memory. Based on upstream patch. - CVE-2012-1148 Date: 2012-09-10 08:15:19.570321+00:00 Changed-By: Tyler Hicks Signed-By: Ubuntu Archive Robot https://launchpad.net/ubuntu/natty/+source/xmlrpc-c/1.16.32-0ubuntu3.1 -------------- next part -------------- Sorry, changesfile not available. From launchpad at micahscomputing.com Tue Sep 11 08:02:28 2012 From: launchpad at micahscomputing.com (Micah Gersten) Date: Tue, 11 Sep 2012 08:02:28 -0000 Subject: [ubuntu/natty-security] firefox 15.0.1+build1-0ubuntu0.11.04.1 (Accepted) Message-ID: <20120911080228.31327.82515.launchpad@ackee.canonical.com> firefox (15.0.1+build1-0ubuntu0.11.04.1) natty-security; urgency=low * New upstream stable release (FIREFOX_15_0_1_BUILD1) - see LP: #1047667 for USN information Date: 2012-09-07 23:25:10.713352+00:00 Changed-By: Micah Gersten https://launchpad.net/ubuntu/natty/+source/firefox/15.0.1+build1-0ubuntu0.11.04.1 -------------- next part -------------- Sorry, changesfile not available. From cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk Tue Sep 11 08:39:39 2012 From: cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk (Ubuntu Archive Robot) Date: Tue, 11 Sep 2012 08:39:39 -0000 Subject: [ubuntu/natty-updates] firefox 15.0.1+build1-0ubuntu0.11.04.1 (Accepted) Message-ID: <20120911083939.12553.9774.launchpad@ackee.canonical.com> firefox (15.0.1+build1-0ubuntu0.11.04.1) natty-security; urgency=low * New upstream stable release (FIREFOX_15_0_1_BUILD1) - see LP: #1047667 for USN information Date: 2012-09-07 23:25:10.713352+00:00 Changed-By: Micah Gersten Signed-By: Ubuntu Archive Robot https://launchpad.net/ubuntu/natty/+source/firefox/15.0.1+build1-0ubuntu0.11.04.1 -------------- next part -------------- Sorry, changesfile not available. From adconrad at 0c3.net Thu Sep 13 00:02:18 2012 From: adconrad at 0c3.net (Adam Conrad) Date: Thu, 13 Sep 2012 00:02:18 -0000 Subject: [ubuntu/natty-proposed] linux-ti-omap4 2.6.38-1209.26 (Accepted) Message-ID: <20120913000218.13774.68056.launchpad@ackee.canonical.com> linux-ti-omap4 (2.6.38-1209.26) natty-proposed; urgency=low * Release Tracking Bug - LP: #1047347 [ Upstream Kernel Changes ] * rds: set correct msg_namelen - LP: #1031112 - CVE-2012-3340 * KVM: unmap pages from the iommu when slots are removed - LP: #987569 - CVE-2012-2121 * net: Allow driver to limit number of GSO segments per skb - LP: #1037456 - CVE-2012-3412 * tcp: do not scale TSO segment size with reordering degree - LP: #1037456 - CVE-2012-3412 * tcp: Apply device TSO segment limit earlier - LP: #1037456 - CVE-2012-3412 * sfc: Replace some literal constants with EFX_PAGE_SIZE/EFX_BUF_SIZE - LP: #1037456 - CVE-2012-3412 * sfc: Fix maximum number of TSO segments and minimum TX queue size - LP: #1037456 - CVE-2012-3412 * mm: Hold a file reference in madvise_remove - LP: #1042447 - CVE-2012-3511 Date: 2012-09-12 17:50:13.836129+00:00 Changed-By: Paolo Pisati Signed-By: Adam Conrad https://launchpad.net/ubuntu/natty/+source/linux-ti-omap4/2.6.38-1209.26 -------------- next part -------------- Sorry, changesfile not available. From ubuntu at kitterman.com Thu Sep 13 04:40:25 2012 From: ubuntu at kitterman.com (Scott Kitterman) Date: Thu, 13 Sep 2012 04:40:25 -0000 Subject: [ubuntu/natty-updates] tzdata 2012e-0ubuntu0.11.04 (Accepted) Message-ID: <20120913044025.29768.21503.launchpad@ackee.canonical.com> tzdata (2012e-0ubuntu0.11.04) natty-proposed; urgency=low * New upstream release 2012e: - Fixes timezone data for Port-au-Prince, Haiti (LP: #1031836) * Update debian/copyright and debian/watch for new upstream. Date: 2012-08-14 22:25:48.462629+00:00 Changed-By: Adam Conrad Signed-By: Scott Kitterman https://launchpad.net/ubuntu/natty/+source/tzdata/2012e-0ubuntu0.11.04 -------------- next part -------------- Sorry, changesfile not available. From marc.deslauriers at canonical.com Thu Sep 13 16:50:24 2012 From: marc.deslauriers at canonical.com (Marc Deslauriers) Date: Thu, 13 Sep 2012 16:50:24 -0000 Subject: [ubuntu/natty-security] bind9 1:9.7.3.dfsg-1ubuntu2.6 (Accepted) Message-ID: <20120913165024.17665.56273.launchpad@ackee.canonical.com> bind9 (1:9.7.3.dfsg-1ubuntu2.6) natty-security; urgency=low * SECURITY UPDATE: denial of service via large crafted resource record - check length in lib/dns/include/dns/rdata.h, lib/dns/{master,rdata,rdataslab}.c. - Patch backported from 9.7.6-P3 - CVE-2012-4244 Date: 2012-09-13 12:25:26.239462+00:00 Changed-By: Marc Deslauriers https://launchpad.net/ubuntu/natty/+source/bind9/1:9.7.3.dfsg-1ubuntu2.6 -------------- next part -------------- Sorry, changesfile not available. From cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk Thu Sep 13 17:29:22 2012 From: cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk (Ubuntu Archive Robot) Date: Thu, 13 Sep 2012 17:29:22 -0000 Subject: [ubuntu/natty-updates] bind9 1:9.7.3.dfsg-1ubuntu2.6 (Accepted) Message-ID: <20120913172922.29569.99475.launchpad@ackee.canonical.com> bind9 (1:9.7.3.dfsg-1ubuntu2.6) natty-security; urgency=low * SECURITY UPDATE: denial of service via large crafted resource record - check length in lib/dns/include/dns/rdata.h, lib/dns/{master,rdata,rdataslab}.c. - Patch backported from 9.7.6-P3 - CVE-2012-4244 Date: 2012-09-13 12:25:26.239462+00:00 Changed-By: Marc Deslauriers Signed-By: Ubuntu Archive Robot https://launchpad.net/ubuntu/natty/+source/bind9/1:9.7.3.dfsg-1ubuntu2.6 -------------- next part -------------- Sorry, changesfile not available. From adconrad at 0c3.net Thu Sep 13 23:15:39 2012 From: adconrad at 0c3.net (Adam Conrad) Date: Thu, 13 Sep 2012 23:15:39 -0000 Subject: [ubuntu/natty-updates] linux 2.6.38-16.67 (Accepted) Message-ID: <20120913231539.2598.36472.launchpad@ackee.canonical.com> linux (2.6.38-16.67) natty-proposed; urgency=low [Luis Henriques] * Release Tracking Bug - LP: #1045383 [ Upstream Kernel Changes ] * rds: set correct msg_namelen - LP: #1031112 - CVE-2012-3430 * eCryptfs: Initialize empty lower files when opening them - LP: #911507 * net: Allow driver to limit number of GSO segments per skb - LP: #1037456 - CVE-2012-3412 * tcp: do not scale TSO segment size with reordering degree - LP: #1037456 - CVE-2012-3412 * tcp: Apply device TSO segment limit earlier - LP: #1037456 - CVE-2012-3412 * sfc: Replace some literal constants with EFX_PAGE_SIZE/EFX_BUF_SIZE - LP: #1037456 - CVE-2012-3412 * sfc: Fix maximum number of TSO segments and minimum TX queue size - LP: #1037456 - CVE-2012-3412 * mm: Hold a file reference in madvise_remove - LP: #1042447 - CVE-2012-3511 * cred: copy_process() should clear child->replacement_session_keyring - LP: #1023535 - CVE-2012-2745 Date: 2012-09-06 17:55:11.507538+00:00 Changed-By: Luis Henriques Signed-By: Adam Conrad https://launchpad.net/ubuntu/natty/+source/linux/2.6.38-16.67 -------------- next part -------------- Sorry, changesfile not available. From adconrad at 0c3.net Thu Sep 13 23:17:34 2012 From: adconrad at 0c3.net (Adam Conrad) Date: Thu, 13 Sep 2012 23:17:34 -0000 Subject: [ubuntu/natty-security] linux 2.6.38-16.67 (Accepted) Message-ID: <20120913231734.4472.88524.launchpad@ackee.canonical.com> linux (2.6.38-16.67) natty-proposed; urgency=low [Luis Henriques] * Release Tracking Bug - LP: #1045383 [ Upstream Kernel Changes ] * rds: set correct msg_namelen - LP: #1031112 - CVE-2012-3430 * eCryptfs: Initialize empty lower files when opening them - LP: #911507 * net: Allow driver to limit number of GSO segments per skb - LP: #1037456 - CVE-2012-3412 * tcp: do not scale TSO segment size with reordering degree - LP: #1037456 - CVE-2012-3412 * tcp: Apply device TSO segment limit earlier - LP: #1037456 - CVE-2012-3412 * sfc: Replace some literal constants with EFX_PAGE_SIZE/EFX_BUF_SIZE - LP: #1037456 - CVE-2012-3412 * sfc: Fix maximum number of TSO segments and minimum TX queue size - LP: #1037456 - CVE-2012-3412 * mm: Hold a file reference in madvise_remove - LP: #1042447 - CVE-2012-3511 * cred: copy_process() should clear child->replacement_session_keyring - LP: #1023535 - CVE-2012-2745 Date: 2012-09-06 17:55:11.507538+00:00 Changed-By: Luis Henriques Signed-By: Adam Conrad https://launchpad.net/ubuntu/natty/+source/linux/2.6.38-16.67 -------------- next part -------------- Sorry, changesfile not available. From adconrad at 0c3.net Thu Sep 13 23:18:08 2012 From: adconrad at 0c3.net (Adam Conrad) Date: Thu, 13 Sep 2012 23:18:08 -0000 Subject: [ubuntu/natty-updates] linux-meta 2.6.38.16.31 (Accepted) Message-ID: <20120913231808.4472.19186.launchpad@ackee.canonical.com> linux-meta (2.6.38.16.31) natty-proposed; urgency=low [ Tim Gardner ] * Move all header meta packages into Section: metapackages - LP: #988447 * No meta packages belong in the restricted component - LP: #1016702 [ Luis Henriques ] * Fix Vcs-Git in linux-natty-meta - LP: #999726 * Bump ABI Date: 2012-09-06 17:55:41.244647+00:00 Changed-By: Luis Henriques Signed-By: Adam Conrad https://launchpad.net/ubuntu/natty/+source/linux-meta/2.6.38.16.31 -------------- next part -------------- Sorry, changesfile not available. From adconrad at 0c3.net Thu Sep 13 23:19:25 2012 From: adconrad at 0c3.net (Adam Conrad) Date: Thu, 13 Sep 2012 23:19:25 -0000 Subject: [ubuntu/natty-security] linux-meta 2.6.38.16.31 (Accepted) Message-ID: <20120913231925.5056.19161.launchpad@ackee.canonical.com> linux-meta (2.6.38.16.31) natty-proposed; urgency=low [ Tim Gardner ] * Move all header meta packages into Section: metapackages - LP: #988447 * No meta packages belong in the restricted component - LP: #1016702 [ Luis Henriques ] * Fix Vcs-Git in linux-natty-meta - LP: #999726 * Bump ABI Date: 2012-09-06 17:55:41.244647+00:00 Changed-By: Luis Henriques Signed-By: Adam Conrad https://launchpad.net/ubuntu/natty/+source/linux-meta/2.6.38.16.31 -------------- next part -------------- Sorry, changesfile not available. From adconrad at 0c3.net Thu Sep 13 23:19:34 2012 From: adconrad at 0c3.net (Adam Conrad) Date: Thu, 13 Sep 2012 23:19:34 -0000 Subject: [ubuntu/natty-updates] linux-backports-modules-2.6.38 2.6.38-16.12 (Accepted) Message-ID: <20120913231934.5056.30414.launchpad@ackee.canonical.com> linux-backports-modules-2.6.38 (2.6.38-16.12) natty-proposed; urgency=low [ Luis Henriques ] * Bump ABI - Natty ABI 16 Date: 2012-09-07 10:05:11.383947+00:00 Changed-By: Luis Henriques Signed-By: Adam Conrad https://launchpad.net/ubuntu/natty/+source/linux-backports-modules-2.6.38/2.6.38-16.12 -------------- next part -------------- Sorry, changesfile not available. From adconrad at 0c3.net Thu Sep 13 23:19:35 2012 From: adconrad at 0c3.net (Adam Conrad) Date: Thu, 13 Sep 2012 23:19:35 -0000 Subject: [ubuntu/natty-security] linux-backports-modules-2.6.38 2.6.38-16.12 (Accepted) Message-ID: <20120913231935.5056.63883.launchpad@ackee.canonical.com> linux-backports-modules-2.6.38 (2.6.38-16.12) natty-proposed; urgency=low [ Luis Henriques ] * Bump ABI - Natty ABI 16 Date: 2012-09-07 10:05:11.383947+00:00 Changed-By: Luis Henriques Signed-By: Adam Conrad https://launchpad.net/ubuntu/natty/+source/linux-backports-modules-2.6.38/2.6.38-16.12 -------------- next part -------------- Sorry, changesfile not available. From marc.deslauriers at canonical.com Mon Sep 17 12:17:51 2012 From: marc.deslauriers at canonical.com (Marc Deslauriers) Date: Mon, 17 Sep 2012 12:17:51 -0000 Subject: [ubuntu/natty-security] php5 5.3.5-1ubuntu7.11 (Accepted) Message-ID: <20120917121751.5993.6204.launchpad@ackee.canonical.com> php5 (5.3.5-1ubuntu7.11) natty-security; urgency=low * SECURITY UPDATE: HTTP response-splitting issue with %0D sequences - debian/patches/CVE-2011-1398.patch: properly handle %0D and NUL in main/SAPI.c, added tests to ext/standard/tests/*, fix test suite failures in ext/phar/phar_object.c. - CVE-2011-1398 - CVE-2012-4388 * SECURITY UPDATE: denial of service and possible code execution via _php_stream_scandir function (LP: #1028064) - debian/patches/CVE-2012-2688.patch: prevent overflow in main/streams/streams.c. - CVE-2012-2688 * SECURITY UPDATE: denial of service via PDO extension crafted parameter - debian/patches/CVE-2012-3450.patch: improve logic in ext/pdo/pdo_sql_parser.re, regenerate ext/pdo/pdo_sql_parser.c, add test to ext/pdo_mysql/tests/bug_61755.phpt. - CVE-2012-3450 Date: 2012-09-12 18:35:18.952688+00:00 Changed-By: Marc Deslauriers https://launchpad.net/ubuntu/natty/+source/php5/5.3.5-1ubuntu7.11 -------------- next part -------------- Sorry, changesfile not available. From cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk Mon Sep 17 13:02:21 2012 From: cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk (Ubuntu Archive Robot) Date: Mon, 17 Sep 2012 13:02:21 -0000 Subject: [ubuntu/natty-updates] php5 5.3.5-1ubuntu7.11 (Accepted) Message-ID: <20120917130221.20533.18889.launchpad@ackee.canonical.com> php5 (5.3.5-1ubuntu7.11) natty-security; urgency=low * SECURITY UPDATE: HTTP response-splitting issue with %0D sequences - debian/patches/CVE-2011-1398.patch: properly handle %0D and NUL in main/SAPI.c, added tests to ext/standard/tests/*, fix test suite failures in ext/phar/phar_object.c. - CVE-2011-1398 - CVE-2012-4388 * SECURITY UPDATE: denial of service and possible code execution via _php_stream_scandir function (LP: #1028064) - debian/patches/CVE-2012-2688.patch: prevent overflow in main/streams/streams.c. - CVE-2012-2688 * SECURITY UPDATE: denial of service via PDO extension crafted parameter - debian/patches/CVE-2012-3450.patch: improve logic in ext/pdo/pdo_sql_parser.re, regenerate ext/pdo/pdo_sql_parser.c, add test to ext/pdo_mysql/tests/bug_61755.phpt. - CVE-2012-3450 Date: 2012-09-12 18:35:18.952688+00:00 Changed-By: Marc Deslauriers Signed-By: Ubuntu Archive Robot https://launchpad.net/ubuntu/natty/+source/php5/5.3.5-1ubuntu7.11 -------------- next part -------------- Sorry, changesfile not available. From jamie at ubuntu.com Mon Sep 17 13:40:15 2012 From: jamie at ubuntu.com (Jamie Strandboge) Date: Mon, 17 Sep 2012 13:40:15 -0000 Subject: [ubuntu/natty-security] gnupg2 2.0.14-2ubuntu1.2 (Accepted) Message-ID: <20120917134015.32155.15665.launchpad@ackee.canonical.com> gnupg2 (2.0.14-2ubuntu1.2) natty-security; urgency=low * debian/patches/long-keyids.diff: Use the longest key ID available when requesting a key from a key server. Date: 2012-08-14 19:21:22.082317+00:00 Changed-By: Marc Deslauriers Signed-By: Jamie Strandboge https://launchpad.net/ubuntu/natty/+source/gnupg2/2.0.14-2ubuntu1.2 -------------- next part -------------- Sorry, changesfile not available. From jamie at ubuntu.com Mon Sep 17 13:40:21 2012 From: jamie at ubuntu.com (Jamie Strandboge) Date: Mon, 17 Sep 2012 13:40:21 -0000 Subject: [ubuntu/natty-updates] gnupg 1.4.11-3ubuntu1.11.04.1 (Accepted) Message-ID: <20120917134021.32155.19052.launchpad@ackee.canonical.com> gnupg (1.4.11-3ubuntu1.11.04.1) natty-security; urgency=low * debian/patches/long-keyids.dpatch: Use the longest key ID available when requesting a key from a key server. Date: 2012-08-14 14:21:54.079826+00:00 Changed-By: Marc Deslauriers Signed-By: Jamie Strandboge https://launchpad.net/ubuntu/natty/+source/gnupg/1.4.11-3ubuntu1.11.04.1 -------------- next part -------------- Sorry, changesfile not available. From jamie at ubuntu.com Mon Sep 17 13:40:22 2012 From: jamie at ubuntu.com (Jamie Strandboge) Date: Mon, 17 Sep 2012 13:40:22 -0000 Subject: [ubuntu/natty-security] gnupg 1.4.11-3ubuntu1.11.04.1 (Accepted) Message-ID: <20120917134022.32155.45117.launchpad@ackee.canonical.com> gnupg (1.4.11-3ubuntu1.11.04.1) natty-security; urgency=low * debian/patches/long-keyids.dpatch: Use the longest key ID available when requesting a key from a key server. Date: 2012-08-14 14:21:54.079826+00:00 Changed-By: Marc Deslauriers Signed-By: Jamie Strandboge https://launchpad.net/ubuntu/natty/+source/gnupg/1.4.11-3ubuntu1.11.04.1 -------------- next part -------------- Sorry, changesfile not available. From jamie at ubuntu.com Mon Sep 17 13:40:25 2012 From: jamie at ubuntu.com (Jamie Strandboge) Date: Mon, 17 Sep 2012 13:40:25 -0000 Subject: [ubuntu/natty-updates] gnupg2 2.0.14-2ubuntu1.2 (Accepted) Message-ID: <20120917134025.32155.21712.launchpad@ackee.canonical.com> gnupg2 (2.0.14-2ubuntu1.2) natty-security; urgency=low * debian/patches/long-keyids.diff: Use the longest key ID available when requesting a key from a key server. Date: 2012-08-14 19:21:22.082317+00:00 Changed-By: Marc Deslauriers Signed-By: Jamie Strandboge https://launchpad.net/ubuntu/natty/+source/gnupg2/2.0.14-2ubuntu1.2 -------------- next part -------------- Sorry, changesfile not available. From marc.deslauriers at canonical.com Tue Sep 18 12:01:32 2012 From: marc.deslauriers at canonical.com (Marc Deslauriers) Date: Tue, 18 Sep 2012 12:01:32 -0000 Subject: [ubuntu/natty-security] isc-dhcp 4.1.1-P1-15ubuntu9.6 (Accepted) Message-ID: <20120918120132.8890.74891.launchpad@ackee.canonical.com> isc-dhcp (4.1.1-P1-15ubuntu9.6) natty-security; urgency=low [ Jamie Strandboge ] * debian/dhclient-script.linux: Explicitly set the PATH to that of ENV_SUPATH in /etc/login.defs and unset various other variables. We need to do this so /sbin/dhclient cannot abuse the environment to escape AppArmor confinement via this script. Don't worry about debian/dhclient-script.linux.udeb or debian/dhclient-script.kfreebsd* since AppArmor isn't used in these environments. - LP: #1045986 [ Marc Deslauriers ] * SECURITY UPDATE: denial of service via ipv6 lease expiration time reduction - debian/patches/CVE-2012-3955.patch: properly handle time reduction in server/dhcpv6.c, server/mdb6.c. - CVE-2012-3955 Date: 2012-09-14 17:50:23.188590+00:00 Changed-By: Marc Deslauriers https://launchpad.net/ubuntu/natty/+source/isc-dhcp/4.1.1-P1-15ubuntu9.6 -------------- next part -------------- Sorry, changesfile not available. From cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk Tue Sep 18 12:28:16 2012 From: cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk (Ubuntu Archive Robot) Date: Tue, 18 Sep 2012 12:28:16 -0000 Subject: [ubuntu/natty-updates] isc-dhcp 4.1.1-P1-15ubuntu9.6 (Accepted) Message-ID: <20120918122816.16882.9005.launchpad@ackee.canonical.com> isc-dhcp (4.1.1-P1-15ubuntu9.6) natty-security; urgency=low [ Jamie Strandboge ] * debian/dhclient-script.linux: Explicitly set the PATH to that of ENV_SUPATH in /etc/login.defs and unset various other variables. We need to do this so /sbin/dhclient cannot abuse the environment to escape AppArmor confinement via this script. Don't worry about debian/dhclient-script.linux.udeb or debian/dhclient-script.kfreebsd* since AppArmor isn't used in these environments. - LP: #1045986 [ Marc Deslauriers ] * SECURITY UPDATE: denial of service via ipv6 lease expiration time reduction - debian/patches/CVE-2012-3955.patch: properly handle time reduction in server/dhcpv6.c, server/mdb6.c. - CVE-2012-3955 Date: 2012-09-14 17:50:23.188590+00:00 Changed-By: Marc Deslauriers Signed-By: Ubuntu Archive Robot https://launchpad.net/ubuntu/natty/+source/isc-dhcp/4.1.1-P1-15ubuntu9.6 -------------- next part -------------- Sorry, changesfile not available. From marc.deslauriers at canonical.com Thu Sep 20 16:25:15 2012 From: marc.deslauriers at canonical.com (Marc Deslauriers) Date: Thu, 20 Sep 2012 16:25:15 -0000 Subject: [ubuntu/natty-security] dbus 1.4.6-1ubuntu6.2 (Accepted) Message-ID: <20120920162515.29619.67390.launchpad@ackee.canonical.com> dbus (1.4.6-1ubuntu6.2) natty-security; urgency=low * SECURITY UPDATE: privilege escalation via unsanitized environment - debian/patches/CVE-2012-3524-dbus.patch: Don't access environment variables or run dbus-launch when setuid in configure.in, dbus/dbus-keyring.c, dbus/dbus-sysdeps* - CVE-2012-3524 Date: 2012-09-14 15:30:10.804912+00:00 Changed-By: Marc Deslauriers https://launchpad.net/ubuntu/natty/+source/dbus/1.4.6-1ubuntu6.2 -------------- next part -------------- Sorry, changesfile not available. From cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk Thu Sep 20 16:59:20 2012 From: cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk (Ubuntu Archive Robot) Date: Thu, 20 Sep 2012 16:59:20 -0000 Subject: [ubuntu/natty-updates] dbus 1.4.6-1ubuntu6.2 (Accepted) Message-ID: <20120920165920.6878.64671.launchpad@ackee.canonical.com> dbus (1.4.6-1ubuntu6.2) natty-security; urgency=low * SECURITY UPDATE: privilege escalation via unsanitized environment - debian/patches/CVE-2012-3524-dbus.patch: Don't access environment variables or run dbus-launch when setuid in configure.in, dbus/dbus-keyring.c, dbus/dbus-sysdeps* - CVE-2012-3524 Date: 2012-09-14 15:30:10.804912+00:00 Changed-By: Marc Deslauriers Signed-By: Ubuntu Archive Robot https://launchpad.net/ubuntu/natty/+source/dbus/1.4.6-1ubuntu6.2 -------------- next part -------------- Sorry, changesfile not available. From brian at ubuntu.com Thu Sep 20 17:39:13 2012 From: brian at ubuntu.com (Brian Murray) Date: Thu, 20 Sep 2012 17:39:13 -0000 Subject: [ubuntu/natty-updates] nss-pam-ldapd 0.7.13ubuntu0.11.04 (Accepted) Message-ID: <20120920173913.18894.89163.launchpad@ackee.canonical.com> nss-pam-ldapd (0.7.13ubuntu0.11.04) natty-proposed; urgency=low * increase buffer used for pam_authz_search (LP: #951343) Date: 2012-07-23 20:25:12.634160+00:00 Changed-By: Chris J Arges Signed-By: Brian Murray https://launchpad.net/ubuntu/natty/+source/nss-pam-ldapd/0.7.13ubuntu0.11.04 -------------- next part -------------- Sorry, changesfile not available. From adconrad at 0c3.net Fri Sep 21 18:51:25 2012 From: adconrad at 0c3.net (Adam Conrad) Date: Fri, 21 Sep 2012 18:51:25 -0000 Subject: [ubuntu/natty-updates] linux-ti-omap4 2.6.38-1209.26 (Accepted) Message-ID: <20120921185125.26033.36118.launchpad@ackee.canonical.com> linux-ti-omap4 (2.6.38-1209.26) natty-proposed; urgency=low * Release Tracking Bug - LP: #1047347 [ Upstream Kernel Changes ] * rds: set correct msg_namelen - LP: #1031112 - CVE-2012-3340 * KVM: unmap pages from the iommu when slots are removed - LP: #987569 - CVE-2012-2121 * net: Allow driver to limit number of GSO segments per skb - LP: #1037456 - CVE-2012-3412 * tcp: do not scale TSO segment size with reordering degree - LP: #1037456 - CVE-2012-3412 * tcp: Apply device TSO segment limit earlier - LP: #1037456 - CVE-2012-3412 * sfc: Replace some literal constants with EFX_PAGE_SIZE/EFX_BUF_SIZE - LP: #1037456 - CVE-2012-3412 * sfc: Fix maximum number of TSO segments and minimum TX queue size - LP: #1037456 - CVE-2012-3412 * mm: Hold a file reference in madvise_remove - LP: #1042447 - CVE-2012-3511 Date: 2012-09-12 17:50:13.836129+00:00 Changed-By: Paolo Pisati Signed-By: Adam Conrad https://launchpad.net/ubuntu/natty/+source/linux-ti-omap4/2.6.38-1209.26 -------------- next part -------------- Sorry, changesfile not available. From adconrad at 0c3.net Fri Sep 21 18:52:12 2012 From: adconrad at 0c3.net (Adam Conrad) Date: Fri, 21 Sep 2012 18:52:12 -0000 Subject: [ubuntu/natty-security] linux-ti-omap4 2.6.38-1209.26 (Accepted) Message-ID: <20120921185212.26110.11772.launchpad@ackee.canonical.com> linux-ti-omap4 (2.6.38-1209.26) natty-proposed; urgency=low * Release Tracking Bug - LP: #1047347 [ Upstream Kernel Changes ] * rds: set correct msg_namelen - LP: #1031112 - CVE-2012-3340 * KVM: unmap pages from the iommu when slots are removed - LP: #987569 - CVE-2012-2121 * net: Allow driver to limit number of GSO segments per skb - LP: #1037456 - CVE-2012-3412 * tcp: do not scale TSO segment size with reordering degree - LP: #1037456 - CVE-2012-3412 * tcp: Apply device TSO segment limit earlier - LP: #1037456 - CVE-2012-3412 * sfc: Replace some literal constants with EFX_PAGE_SIZE/EFX_BUF_SIZE - LP: #1037456 - CVE-2012-3412 * sfc: Fix maximum number of TSO segments and minimum TX queue size - LP: #1037456 - CVE-2012-3412 * mm: Hold a file reference in madvise_remove - LP: #1042447 - CVE-2012-3511 Date: 2012-09-12 17:50:13.836129+00:00 Changed-By: Paolo Pisati Signed-By: Adam Conrad https://launchpad.net/ubuntu/natty/+source/linux-ti-omap4/2.6.38-1209.26 -------------- next part -------------- Sorry, changesfile not available. From marc.deslauriers at canonical.com Wed Sep 26 14:31:23 2012 From: marc.deslauriers at canonical.com (Marc Deslauriers) Date: Wed, 26 Sep 2012 14:31:23 -0000 Subject: [ubuntu/natty-security] freeradius 2.1.10+dfsg-2ubuntu2.1 (Accepted) Message-ID: <20120926143123.2638.96941.launchpad@ackee.canonical.com> freeradius (2.1.10+dfsg-2ubuntu2.1) natty-security; urgency=low * SECURITY UPDATE: denial of service and possible code execution via crafted client certificates - debian/patches/CVE-2012-3547.diff: use correct size in src/modules/rlm_eap/types/rlm_eap_tls/rlm_eap_tls.c. - CVE-2012-3547 Date: 2012-09-24 17:40:24.543664+00:00 Changed-By: Marc Deslauriers https://launchpad.net/ubuntu/natty/+source/freeradius/2.1.10+dfsg-2ubuntu2.1 -------------- next part -------------- Sorry, changesfile not available. From cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk Wed Sep 26 14:58:23 2012 From: cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk (Ubuntu Archive Robot) Date: Wed, 26 Sep 2012 14:58:23 -0000 Subject: [ubuntu/natty-updates] freeradius 2.1.10+dfsg-2ubuntu2.1 (Accepted) Message-ID: <20120926145823.11504.94323.launchpad@ackee.canonical.com> freeradius (2.1.10+dfsg-2ubuntu2.1) natty-security; urgency=low * SECURITY UPDATE: denial of service and possible code execution via crafted client certificates - debian/patches/CVE-2012-3547.diff: use correct size in src/modules/rlm_eap/types/rlm_eap_tls/rlm_eap_tls.c. - CVE-2012-3547 Date: 2012-09-24 17:40:24.543664+00:00 Changed-By: Marc Deslauriers Signed-By: Ubuntu Archive Robot https://launchpad.net/ubuntu/natty/+source/freeradius/2.1.10+dfsg-2ubuntu2.1 -------------- next part -------------- Sorry, changesfile not available. From martin.pitt at ubuntu.com Thu Sep 27 05:54:30 2012 From: martin.pitt at ubuntu.com (Martin Pitt) Date: Thu, 27 Sep 2012 05:54:30 -0000 Subject: [ubuntu/natty-proposed] postgresql-8.4 8.4.14-0ubuntu11.04 (Accepted) Message-ID: <20120927055430.9717.4650.launchpad@chaenomeles.canonical.com> postgresql-8.4 (8.4.14-0ubuntu11.04) natty-proposed; urgency=low * New upstream bug fix release: (LP: #1055944) - Fix planner's assignment of executor parameters, and fix executor's rescan logic for CTE plan nodes. These errors could result in wrong answers from queries that scan the same WITH subquery multiple times. - Improve page-splitting decisions in GiST indexes. Multi-column GiST indexes might suffer unexpected bloat due to this error. - Fix cascading privilege revoke to stop if privileges are still held. If we revoke a grant option from some role "X", but "X" still holds that option via a grant from someone else, we should not recursively revoke the corresponding privilege from role(s) "Y" that "X" had granted it to. - Fix handling of SIGFPE when PL/Perl is in use. Perl resets the process's SIGFPE handler to SIG_IGN, which could result in crashes later on. Restore the normal Postgres signal handler after initializing PL/Perl. - Prevent PL/Perl from crashing if a recursive PL/Perl function is redefined while being executed. - Work around possible misoptimization in PL/Perl. Some Linux distributions contain an incorrect version of "pthread.h" that results in incorrect compiled code in PL/Perl, leading to crashes if a PL/Perl function calls another one that throws an error. Date: Tue, 25 Sep 2012 07:34:06 +0200 Changed-By: Martin Pitt Maintainer: Ubuntu Developers https://launchpad.net/ubuntu/natty/+source/postgresql-8.4/8.4.14-0ubuntu11.04 -------------- next part -------------- Format: 1.8 Date: Tue, 25 Sep 2012 07:34:06 +0200 Source: postgresql-8.4 Binary: libpq-dev libpq5 libecpg6 libecpg-dev libecpg-compat3 libpgtypes3 postgresql-8.4 postgresql-client-8.4 postgresql-server-dev-8.4 postgresql-doc-8.4 postgresql-contrib-8.4 postgresql-plperl-8.4 postgresql-plpython-8.4 postgresql-pltcl-8.4 postgresql postgresql-client postgresql-doc postgresql-contrib Architecture: source Version: 8.4.14-0ubuntu11.04 Distribution: natty-proposed Urgency: low Maintainer: Ubuntu Developers Changed-By: Martin Pitt Description: libecpg-compat3 - older version of run-time library for ECPG programs libecpg-dev - development files for ECPG (Embedded PostgreSQL for C) libecpg6 - run-time library for ECPG programs libpgtypes3 - shared library libpgtypes for PostgreSQL 8.4 libpq-dev - header files for libpq5 (PostgreSQL library) libpq5 - PostgreSQL C client library postgresql - object-relational SQL database (supported version) postgresql-8.4 - object-relational SQL database, version 8.4 server postgresql-client - front-end programs for PostgreSQL (supported version) postgresql-client-8.4 - front-end programs for PostgreSQL 8.4 postgresql-contrib - additional facilities for PostgreSQL (supported version) postgresql-contrib-8.4 - additional facilities for PostgreSQL postgresql-doc - documentation for the PostgreSQL database management system postgresql-doc-8.4 - documentation for the PostgreSQL database management system postgresql-plperl-8.4 - PL/Perl procedural language for PostgreSQL 8.4 postgresql-plpython-8.4 - PL/Python procedural language for PostgreSQL 8.4 postgresql-pltcl-8.4 - PL/Tcl procedural language for PostgreSQL 8.4 postgresql-server-dev-8.4 - development files for PostgreSQL 8.4 server-side programming Launchpad-Bugs-Fixed: 1055944 Changes: postgresql-8.4 (8.4.14-0ubuntu11.04) natty-proposed; urgency=low . * New upstream bug fix release: (LP: #1055944) - Fix planner's assignment of executor parameters, and fix executor's rescan logic for CTE plan nodes. These errors could result in wrong answers from queries that scan the same WITH subquery multiple times. - Improve page-splitting decisions in GiST indexes. Multi-column GiST indexes might suffer unexpected bloat due to this error. - Fix cascading privilege revoke to stop if privileges are still held. If we revoke a grant option from some role "X", but "X" still holds that option via a grant from someone else, we should not recursively revoke the corresponding privilege from role(s) "Y" that "X" had granted it to. - Fix handling of SIGFPE when PL/Perl is in use. Perl resets the process's SIGFPE handler to SIG_IGN, which could result in crashes later on. Restore the normal Postgres signal handler after initializing PL/Perl. - Prevent PL/Perl from crashing if a recursive PL/Perl function is redefined while being executed. - Work around possible misoptimization in PL/Perl. Some Linux distributions contain an incorrect version of "pthread.h" that results in incorrect compiled code in PL/Perl, leading to crashes if a PL/Perl function calls another one that throws an error. Checksums-Sha1: 2254d0d395a5e1157650562006042c8fbf64eccb 3305 postgresql-8.4_8.4.14-0ubuntu11.04.dsc 1663bde3e4916a550a32062e99d3e1ad773488c7 18430079 postgresql-8.4_8.4.14.orig.tar.gz 1ae342eee037ca31e892d6c0e26d77605d0a42da 53000 postgresql-8.4_8.4.14-0ubuntu11.04.diff.gz Checksums-Sha256: 74479a80e7af093d2a193eae6d4c28b9a8e4e92db3a328e630d4130fa57ce6b2 3305 postgresql-8.4_8.4.14-0ubuntu11.04.dsc 7c3e9ca0e6a145afd4ab7c125bd7e6c3eb40a22cf08859934638484349205d07 18430079 postgresql-8.4_8.4.14.orig.tar.gz bf8646ad4edd7301274eafe69d0a216a8cd1db478f9853a811cf3af81e025406 53000 postgresql-8.4_8.4.14-0ubuntu11.04.diff.gz Files: 0f22b4ad30c273e96a9785107757936a 3305 database optional postgresql-8.4_8.4.14-0ubuntu11.04.dsc 4d3185a7974a709c57f20998fc41ba0d 18430079 database optional postgresql-8.4_8.4.14.orig.tar.gz 5e2073cc359a9de605543b64798ce487 53000 database optional postgresql-8.4_8.4.14-0ubuntu11.04.diff.gz Original-Maintainer: Martin Pitt From marc.deslauriers at canonical.com Thu Sep 27 17:21:19 2012 From: marc.deslauriers at canonical.com (Marc Deslauriers) Date: Thu, 27 Sep 2012 17:21:19 -0000 Subject: [ubuntu/natty-security] libxml2 2.7.8.dfsg-2ubuntu0.5 (Accepted) Message-ID: <20120927172119.8631.95225.launchpad@ackee.canonical.com> libxml2 (2.7.8.dfsg-2ubuntu0.5) natty-security; urgency=low * SECURITY UPDATE: denial of service and possible code execution via incorrect buffer sizes. - http://git.gnome.org/browse/libxml2/commit/?id=459eeb9dc752d5185f57ff6b135027f11981a626 - http://git.gnome.org/browse/libxml2/commit/?id=4f9fdc709c4861c390cd84e2ed1fd878b3442e28 - http://git.gnome.org/browse/libxml2/commit/?id=baaf03f80f817bb34c421421e6cb4d68c353ac9a - CVE-2012-2807 Date: 2012-09-26 17:50:11.636029+00:00 Changed-By: Marc Deslauriers https://launchpad.net/ubuntu/natty/+source/libxml2/2.7.8.dfsg-2ubuntu0.5 -------------- next part -------------- Sorry, changesfile not available. From cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk Thu Sep 27 17:59:31 2012 From: cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk (Ubuntu Archive Robot) Date: Thu, 27 Sep 2012 17:59:31 -0000 Subject: [ubuntu/natty-updates] libxml2 2.7.8.dfsg-2ubuntu0.5 (Accepted) Message-ID: <20120927175931.20495.15809.launchpad@ackee.canonical.com> libxml2 (2.7.8.dfsg-2ubuntu0.5) natty-security; urgency=low * SECURITY UPDATE: denial of service and possible code execution via incorrect buffer sizes. - http://git.gnome.org/browse/libxml2/commit/?id=459eeb9dc752d5185f57ff6b135027f11981a626 - http://git.gnome.org/browse/libxml2/commit/?id=4f9fdc709c4861c390cd84e2ed1fd878b3442e28 - http://git.gnome.org/browse/libxml2/commit/?id=baaf03f80f817bb34c421421e6cb4d68c353ac9a - CVE-2012-2807 Date: 2012-09-26 17:50:11.636029+00:00 Changed-By: Marc Deslauriers Signed-By: Ubuntu Archive Robot https://launchpad.net/ubuntu/natty/+source/libxml2/2.7.8.dfsg-2ubuntu0.5 -------------- next part -------------- Sorry, changesfile not available. From launchpad at micahscomputing.com Fri Sep 28 08:05:56 2012 From: launchpad at micahscomputing.com (Micah Gersten) Date: Fri, 28 Sep 2012 08:05:56 -0000 Subject: [ubuntu/natty-security] thunderbird 15.0.1+build1-0ubuntu0.11.04.1 (Accepted) Message-ID: <20120928080556.19559.49190.launchpad@ackee.canonical.com> thunderbird (15.0.1+build1-0ubuntu0.11.04.1) natty-security; urgency=low * New upstream stable release (THUNDERBIRD_15_0_1_BUILD1) - see LP: #1049428 for USN information * Update globalmenu-extension to 3.4.2 - Fix LP: #1045196 - "Messages->Move To" menu is empty Date: 2012-09-12 05:25:52.202627+00:00 Changed-By: Chris Coulson Signed-By: Micah Gersten https://launchpad.net/ubuntu/natty/+source/thunderbird/15.0.1+build1-0ubuntu0.11.04.1 -------------- next part -------------- Sorry, changesfile not available. From cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk Fri Sep 28 09:32:28 2012 From: cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk (Ubuntu Archive Robot) Date: Fri, 28 Sep 2012 09:32:28 -0000 Subject: [ubuntu/natty-updates] thunderbird 15.0.1+build1-0ubuntu0.11.04.1 (Accepted) Message-ID: <20120928093228.12163.97727.launchpad@ackee.canonical.com> thunderbird (15.0.1+build1-0ubuntu0.11.04.1) natty-security; urgency=low * New upstream stable release (THUNDERBIRD_15_0_1_BUILD1) - see LP: #1049428 for USN information * Update globalmenu-extension to 3.4.2 - Fix LP: #1045196 - "Messages->Move To" menu is empty Date: 2012-09-12 05:25:52.202627+00:00 Changed-By: Chris Coulson Signed-By: Ubuntu Archive Robot https://launchpad.net/ubuntu/natty/+source/thunderbird/15.0.1+build1-0ubuntu0.11.04.1 -------------- next part -------------- Sorry, changesfile not available.