[ubuntu/precise] zescrow 1.3-0ubuntu1 (Accepted)
Dustin Kirkland
kirkland at ubuntu.com
Sat Apr 7 22:41:44 UTC 2012
zescrow (1.3-0ubuntu1) precise; urgency=low
* debian/copyright, upload/go/index.html, upload/index.html,
usr/bin/zEscrow, www/deposit/go/index.html, www/deposit/index.html,
www/include/above.html, www/include/below.html,
www/include/credentials.html.CHANGE_ME, www/include/escrow.css,
www/include/functions.html, www/index.html, www/not-
found/index.html, www/openid/index.html, www/openid/return.html,
www/privacy.html, www/retrieve/go/index.html,
www/retrieve/index.html, www/terms.html:
- Copyright updated to include Gazzang, Inc.
* usr/bin/zEscrow:
- Multiple security fixes, according to line-by-line code audit by
Kees Cook <kees at ubuntu.com>
- use 'set -e' rather than sh -e, to ensure errors are caught if an
interpreter other than sh is used
- store the stty earlier and restore on trapped exits
- generate the tempfile with the required extensions
- drop redundant chmodding
- note specifically that the user's passphrase is NOT sent to the server
- remove one of the client/server roundtrips, fetching the key
fingerprint
- instead, use gpg's --status-fd to parse machine readable output and
retrieve the fingerprint from there
- catch curl errors
- catch gpg import errors
- validate the fingerprint
- drop use of wildcard in copying to tempdir
- make the $url more readable
- handle the browser launching prompt correctly
Date: Wed, 04 Apr 2012 12:02:31 -0500
Changed-By: Dustin Kirkland <kirkland at ubuntu.com>
https://launchpad.net/ubuntu/precise/+source/zescrow/1.3-0ubuntu1
-------------- next part --------------
Format: 1.8
Date: Wed, 04 Apr 2012 12:02:31 -0500
Source: zescrow
Binary: zescrow-client
Architecture: source
Version: 1.3-0ubuntu1
Distribution: precise
Urgency: low
Maintainer: Dustin Kirkland <kirkland at ubuntu.com>
Changed-By: Dustin Kirkland <kirkland at ubuntu.com>
Description:
zescrow-client - back up eCryptfs Encrypted Home or Encrypted Private Configuratio
Changes:
zescrow (1.3-0ubuntu1) precise; urgency=low
.
* debian/copyright, upload/go/index.html, upload/index.html,
usr/bin/zEscrow, www/deposit/go/index.html, www/deposit/index.html,
www/include/above.html, www/include/below.html,
www/include/credentials.html.CHANGE_ME, www/include/escrow.css,
www/include/functions.html, www/index.html, www/not-
found/index.html, www/openid/index.html, www/openid/return.html,
www/privacy.html, www/retrieve/go/index.html,
www/retrieve/index.html, www/terms.html:
- Copyright updated to include Gazzang, Inc.
* usr/bin/zEscrow:
- Multiple security fixes, according to line-by-line code audit by
Kees Cook <kees at ubuntu.com>
- use 'set -e' rather than sh -e, to ensure errors are caught if an
interpreter other than sh is used
- store the stty earlier and restore on trapped exits
- generate the tempfile with the required extensions
- drop redundant chmodding
- note specifically that the user's passphrase is NOT sent to the server
- remove one of the client/server roundtrips, fetching the key
fingerprint
- instead, use gpg's --status-fd to parse machine readable output and
retrieve the fingerprint from there
- catch curl errors
- catch gpg import errors
- validate the fingerprint
- drop use of wildcard in copying to tempdir
- make the $url more readable
- handle the browser launching prompt correctly
Checksums-Sha1:
b4363783b8a202c2f5202956da7581057cf6514d 1724 zescrow_1.3-0ubuntu1.dsc
850d18afe23511f8aca3d3815e653e2bbda0dfaa 78567 zescrow_1.3.orig.tar.gz
b2e3567f64067d735fd24cd3d02dce9fae18d2e7 2685 zescrow_1.3-0ubuntu1.debian.tar.gz
Checksums-Sha256:
104bc7e86dd92675cb67bdc0f3f8b1e234e85f0467c89eeb5495a11c46aa134c 1724 zescrow_1.3-0ubuntu1.dsc
e018c18dd85529e3d52dc65b800ca2f66dec8f500e92d8d6bf8eaa5869a88a8b 78567 zescrow_1.3.orig.tar.gz
6d512a89041e8d4c1798a8235d350ec5eb478ead7eb1cb820aea1257227358b4 2685 zescrow_1.3-0ubuntu1.debian.tar.gz
Files:
add5a18db4698bd2b0c88256f765c063 1724 misc optional zescrow_1.3-0ubuntu1.dsc
2ef7075aba653b409f077f9eed57607b 78567 misc optional zescrow_1.3.orig.tar.gz
de413fa6fe2268fe7c640c49e8343065 2685 misc optional zescrow_1.3-0ubuntu1.debian.tar.gz
More information about the Precise-changes
mailing list