[Bug 1284841] [NEW] Sync libapache2-mod-nss 1.0.8-4 (universe) from Debian unstable (main)
Launchpad Bug Tracker
1284841 at bugs.launchpad.net
Tue Feb 25 21:01:28 UTC 2014
You have been subscribed to a public bug by Jackson Doak (noskcaj):
Please sync libapache2-mod-nss 1.0.8-4 (universe) from Debian unstable
(main)
Explanation of the Ubuntu delta and why it can be dropped:
* Merge from unreleased debian git.
- CVE fixes
* Fake sync due to mismatching orig tarball.
Fixed in debian, debian also has 2 CVE fixes
Changelog entries since current trusty version 1.0.8-3ubuntu1:
libapache2-mod-nss (1.0.8-4) unstable; urgency=medium
* mod_nss-clientauth.patch:
- Fix CVE-2011-4973: FakeBasicAuth authentication bypass.
(Closes: #729626)
* mod_nss-nssverifyclient.patch:
- Fix CVE-2013-4566: incorrect handling of NSSVerifyClient in
directory context. (Closes: #731627)
* control: Bump policy to 3.9.5, no changes.
-- Timo Aaltonen <tjaalton at ubuntu.com> Mon, 03 Feb 2014 11:23:58 +0200
** Affects: libapache2-mod-nss (Ubuntu)
Importance: Wishlist
Status: New
--
Sync libapache2-mod-nss 1.0.8-4 (universe) from Debian unstable (main)
https://bugs.launchpad.net/bugs/1284841
You received this bug notification because you are a member of Ubuntu Sponsors Team, which is subscribed to the bug report.
More information about the Ubuntu-sponsors
mailing list