[Bug 818569] [NEW] Sync libsoup2.4 2.34.3-1 (main) from Debian unstable (main)

Launchpad Bug Tracker 818569 at bugs.launchpad.net
Sat Jul 30 16:21:55 UTC 2011


You have been subscribed to a public bug by Rico Tzschichholz (ricotz):

Please sync libsoup2.4 2.34.3-1 (main) from Debian unstable (main)

Explanation of the Ubuntu delta and why it can be dropped:
The CVE patch was taken from upstream which is included in the new release

Changelog entries since current oneiric version 2.34.2-2ubuntu1:

libsoup2.4 (2.34.3-1) unstable; urgency=high

  * New upstream release.
    - Fixes CVE-2011-2524: SoupServer directory traversal vulnerability.
      Closes: #635837
  * debian/watch: Switch to .bz2 tarballs.
  * debian/patches/01_memleaks.patch: Remove, merged upstream.
  * Bump Standards-Version to 3.9.2. No further changes.
  * Bump debhelper compatibility level to 8.
    - Update Build-Depends on debhelper.
    - Strip debian/tmp/ from .install files.
  * Urgency high for the security fix.

 -- Michael Biebl <biebl at debian.org>  Fri, 29 Jul 2011 03:44:00 +0200

** Affects: libsoup2.4 (Ubuntu)
     Importance: Undecided
         Status: New

-- 
Sync libsoup2.4 2.34.3-1 (main) from Debian unstable (main)
https://bugs.launchpad.net/bugs/818569
You received this bug notification because you are a member of Ubuntu Sponsors Team, which is subscribed to the bug report.



More information about the Ubuntu-sponsors mailing list