[ubuntu/precise] update-manager 1:0.154.5 (Accepted)

Michael Vogt michael.vogt at ubuntu.com
Tue Nov 29 09:20:28 UTC 2011


update-manager (1:0.154.5) precise; urgency=low

  [ Nicholas Skaggs ]
  * lp:~nskaggs/update-manager/fix-for-702418:
    - Removed gnome-power-manager dbus interface completely and
      only use freedesktop interface.
      Thanks to Nicholas Skaggs (LP: #702418)

  [ Gabor Kelemen ]
  * Replace gettext.install() with bindtextdomain() calls.
    Work around crash in OptionParser when displaying
    localized --help text, to not regress on bug LP: #557804
  * Extract strings for translation from u-m-t and u-s-s executables

  [ Marc Deslauriers ]
  * SECURITY UPDATE: arbitrary code execution via directory traversal
    (LP: #881548)
    - UpdateManager/Core/DistUpgradeFetcherCore.py: verify signature before
      unpacking the tarball.
    - CVE-2011-3152
  * SECURITY UPDATE: information leak via insecure temp file (LP: #881541)
    - DistUpgrade/DistUpgradeViewKDE.py: use mkstemp instead of mktemp.
    - CVE-2011-3154

  [ Michael Vogt ]
  * UpdateManager/UpdateManager.py:
    - ensure that the origin headers state of "select all/dselect all"
      is consistent

Date: Tue, 29 Nov 2011 09:58:15 +0100
Changed-By: Michael Vogt <michael.vogt at ubuntu.com>
https://launchpad.net/ubuntu/precise/+source/update-manager/1:0.154.5
-------------- next part --------------
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Format: 1.8
Date: Tue, 29 Nov 2011 09:58:15 +0100
Source: update-manager
Binary: update-manager-core update-manager update-manager-text update-manager-kde auto-upgrade-tester
Architecture: source
Version: 1:0.154.5
Distribution: precise
Urgency: low
Maintainer: Michael Vogt <michael.vogt at ubuntu.com>
Changed-By: Michael Vogt <michael.vogt at ubuntu.com>
Description: 
 auto-upgrade-tester - Test release upgrades in a virtual environment
 update-manager - GNOME application that manages apt updates
 update-manager-core - manage release upgrades
 update-manager-kde - Support modules for KPackageKit
 update-manager-text - Text application that manages apt updates
Launchpad-Bugs-Fixed: 557804 702418 881541 881548
Changes: 
 update-manager (1:0.154.5) precise; urgency=low
 .
   [ Nicholas Skaggs ]
   * lp:~nskaggs/update-manager/fix-for-702418:
     - Removed gnome-power-manager dbus interface completely and
       only use freedesktop interface.
       Thanks to Nicholas Skaggs (LP: #702418)
 .
   [ Gabor Kelemen ]
   * Replace gettext.install() with bindtextdomain() calls.
     Work around crash in OptionParser when displaying
     localized --help text, to not regress on bug LP: #557804
   * Extract strings for translation from u-m-t and u-s-s executables
 .
   [ Marc Deslauriers ]
   * SECURITY UPDATE: arbitrary code execution via directory traversal
     (LP: #881548)
     - UpdateManager/Core/DistUpgradeFetcherCore.py: verify signature before
       unpacking the tarball.
     - CVE-2011-3152
   * SECURITY UPDATE: information leak via insecure temp file (LP: #881541)
     - DistUpgrade/DistUpgradeViewKDE.py: use mkstemp instead of mktemp.
     - CVE-2011-3154
 .
   [ Michael Vogt ]
   * UpdateManager/UpdateManager.py:
     - ensure that the origin headers state of "select all/dselect all"
       is consistent
Checksums-Sha1: 
 37818be2768a23f52c445f0c4d6e4c888f598b62 1324 update-manager_0.154.5.dsc
 3a7a4609a098fe206383aa116385f51c00bfcd65 3186816 update-manager_0.154.5.tar.gz
Checksums-Sha256: 
 1f82fc7e15f4f8d99517da3f08b5be8d4c3a9970e74d18b54cac07d8d1c90922 1324 update-manager_0.154.5.dsc
 0c4533b9b46c5f308c9622f96b7f90dd6477df38421717e6dc7aa970ca549785 3186816 update-manager_0.154.5.tar.gz
Files: 
 15115a73855ffe349916b2964f2399b2 1324 gnome optional update-manager_0.154.5.dsc
 8b02cb63c166045c85ce249753380637 3186816 gnome optional update-manager_0.154.5.tar.gz

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.11 (GNU/Linux)

iEYEARECAAYFAk7UoZgACgkQliSD4VZixzT26ACgpFJmXTR47rVTpNyaB03GTpB/
INgAn2V+x5Z70tx5aM+fjI/1gIqTdID4
=PWYx
-----END PGP SIGNATURE-----


More information about the Precise-changes mailing list