[ubuntu-mono] [Bug 658997] Re: please update from 0.3.4-1 to 0.3.4-1.1 from Debian (unstable)

Stefan Ebner sebner at ubuntu.com
Wed Nov 24 13:14:34 GMT 2010


Upgrade, fresh-install works fine. Application works after the upgrade
/fresh-install without problems. (Sorry for the logs being in german)

meteyou at meteyou-G2SV:~/Desktop$ sudo dpkg -i bareftp_0.3.4-1.1ubuntu0.1_i386.deb 
(Lese Datenbank ... 203833 Dateien und Verzeichnisse sind derzeit installiert.)
Vorbereiten zum Ersetzen von bareftp 0.3.4-1 (durch bareftp_0.3.4-1.1ubuntu0.1_i386.deb) ...
Entpacke Ersatz für bareftp ...
Richte bareftp ein (0.3.4-1.1ubuntu0.1) ...
Verarbeite Trigger für hicolor-icon-theme ...
Verarbeite Trigger für man-db ...
Verarbeite Trigger für bamfdaemon ...
Rebuilding /usr/share/applications/bamf.index...
Verarbeite Trigger für desktop-file-utils ...
Verarbeite Trigger für python-gmenu ...
Rebuilding /usr/share/applications/desktop.de_AT.utf8.cache...
Verarbeite Trigger für python-support ...


and 

meteyou at meteyou-G2SV:~/Desktop$ sudo dpkg -i bareftp_0.3.4-1.1ubuntu0.1_i386.deb 
Wähle vormals abgewähltes Paket bareftp.
(Lese Datenbank ... 203795 Dateien und Verzeichnisse sind derzeit installiert.)
Entpacke bareftp (aus bareftp_0.3.4-1.1ubuntu0.1_i386.deb) ...
Richte bareftp ein (0.3.4-1.1ubuntu0.1) ...
Verarbeite Trigger für hicolor-icon-theme ...
Verarbeite Trigger für man-db ...
Verarbeite Trigger für bamfdaemon ...
Rebuilding /usr/share/applications/bamf.index...
Verarbeite Trigger für desktop-file-utils ...
Verarbeite Trigger für python-gmenu ...
Rebuilding /usr/share/applications/desktop.de_AT.utf8.cache...
Verarbeite Trigger für python-support ...

** Patch added: "bareftp_0.3.4-1.1ubuntu0.1.debdiff"
   https://bugs.launchpad.net/ubuntu/+source/bareftp/+bug/658997/+attachment/1743471/+files/bareftp_0.3.4-1.1ubuntu0.1.debdiff

** Patch removed: "bareftp_0.3.4-1.1ubuntu0.1.debdiff"
   https://bugs.launchpad.net/ubuntu/+source/bareftp/+bug/658997/+attachment/1743471/+files/bareftp_0.3.4-1.1ubuntu0.1.debdiff

-- 
please update from 0.3.4-1 to 0.3.4-1.1 from Debian (unstable)
https://bugs.launchpad.net/bugs/658997
You received this bug notification because you are a member of Ubuntu
CLI/Mono Uploaders, which is subscribed to bareftp in ubuntu.

Status in “bareftp” package in Ubuntu: Confirmed

Bug description:
Binary package hint: bareftp

There is a local exploit identified as release critical from Debian based on overriding LD_LIBRARY_PATH (http://bugs.debian.org/598284).  We do not carry any patch for this package, and the only change from -1 to -1.1 is explicitly for this vulnerability.  0.3.4-1.1 does build on Maverick.

http://security-tracker.debian.org/tracker/CVE-2010-3350





More information about the Ubuntu-mono mailing list