Ubuntu Installer | 30 Apr 00:03
Favicon

[ubuntu/intrepid-security] netpbm-free, netpbm-free (delayed) 2:10.0-12ubuntu0.8.10.1 (Accepted)

netpbm-free (2:10.0-12ubuntu0.8.10.1) intrepid-security; urgency=low

  * SECURITY UPDATE: fix stack-based overflow in ppm/xpmtoppm.c
    - http://netpbm.svn.sourceforge.net/viewvc/netpbm/stable/converter/ppm/xpmtoppm.c?view=patch&r1=995&r2=1076&pathrev=1076
    - CVE-2009-4274

Date: Fri, 16 Apr 2010 17:16:08 -0500
Changed-By: Jamie Strandboge <jamie@...>
Maintainer: Ubuntu Core Developers <ubuntu-devel-discuss@...>
https://launchpad.net/ubuntu/intrepid/+source/netpbm-free/2:10.0-12ubuntu0.8.10.1
Format: 1.8
Date: Fri, 16 Apr 2010 17:16:08 -0500
Source: netpbm-free
Binary: netpbm libnetpbm10 libnetpbm10-dev libnetpbm9 libnetpbm9-dev
Architecture: source
Version: 2:10.0-12ubuntu0.8.10.1
Distribution: intrepid-security
Urgency: low
Maintainer: Ubuntu Core Developers <ubuntu-devel-discuss@...>
Changed-By: Jamie Strandboge <jamie@...>
Description: 
 libnetpbm10 - Shared libraries for netpbm
 libnetpbm10-dev - Development libraries and header files
 libnetpbm9 - Shared libraries for netpbm
 libnetpbm9-dev - Development libraries and header files
 netpbm     - Graphics conversion tools
Changes: 
 netpbm-free (2:10.0-12ubuntu0.8.10.1) intrepid-security; urgency=low
(Continue reading)

Ubuntu Installer | 26 Apr 15:20
Favicon

[ubuntu/intrepid-security] ffmpeg-debian, ffmpeg-debian (delayed) 3:0.svn20080206-12ubuntu3.3 (Accepted)

ffmpeg-debian (3:0.svn20080206-12ubuntu3.3) intrepid-security; urgency=low

  * debian/patches/CVE-2009-46XX/security-issue22.patch: removed this
    patch as it was causing a regression. (LP: #567913)

Date: Fri, 23 Apr 2010 08:13:39 -0400
Changed-By: Marc Deslauriers <marc.deslauriers@...>
Maintainer: Reinhard Tartler <siretart@...>
https://launchpad.net/ubuntu/intrepid/+source/ffmpeg-debian/3:0.svn20080206-12ubuntu3.3
Format: 1.8
Date: Fri, 23 Apr 2010 08:13:39 -0400
Source: ffmpeg-debian
Binary: ffmpeg ffmpeg-dbg ffmpeg-doc libavutil49 libavcodec51 libavdevice52 libpostproc51
libavformat52 libswscale0 libavutil-dev libavcodec-dev libavdevice-dev libpostproc-dev
libavformat-dev libswscale-dev
Architecture: source
Version: 3:0.svn20080206-12ubuntu3.3
Distribution: intrepid-security
Urgency: low
Maintainer: Reinhard Tartler <siretart@...>
Changed-By: Marc Deslauriers <marc.deslauriers@...>
Description: 
 ffmpeg     - multimedia player, server and encoder
 ffmpeg-dbg - Debug symbols for ffmpeg related packages
 ffmpeg-doc - documentation of the ffmpeg API
 libavcodec-dev - development files for libavcodec
 libavcodec51 - ffmpeg codec library
 libavdevice-dev - development files for libavdevice
(Continue reading)

Ubuntu Installer | 20 Apr 19:03
Favicon

[ubuntu/intrepid-security] irssi (delayed), irssi 0.8.12-4ubuntu2.3 (Accepted)

irssi (0.8.12-4ubuntu2.3) intrepid-security; urgency=low

  * debian/patches/91_ssl_proxy.patch: when we have a proxy setting, we expect
    the CN to match the proxy hostname, not the server hostname. Patch thanks
    to Steve Langasek. (LP: #565182)

Date: Mon, 19 Apr 2010 13:02:15 -0500
Changed-By: Jamie Strandboge <jamie@...>
Maintainer: Ubuntu Core Developers <ubuntu-devel-discuss@...>
https://launchpad.net/ubuntu/intrepid/+source/irssi/0.8.12-4ubuntu2.3
Format: 1.8
Date: Mon, 19 Apr 2010 13:02:15 -0500
Source: irssi
Binary: irssi irssi-dev
Architecture: source
Version: 0.8.12-4ubuntu2.3
Distribution: intrepid-security
Urgency: low
Maintainer: Ubuntu Core Developers <ubuntu-devel-discuss@...>
Changed-By: Jamie Strandboge <jamie@...>
Description: 
 irssi      - terminal based IRC client
 irssi-dev  - text-mode version of the irssi IRC client development files
Launchpad-Bugs-Fixed: 565182
Changes: 
 irssi (0.8.12-4ubuntu2.3) intrepid-security; urgency=low
 .
   * debian/patches/91_ssl_proxy.patch: when we have a proxy setting, we expect
(Continue reading)

Ubuntu Installer | 20 Apr 00:05
Favicon

[ubuntu/intrepid-security] kdebase-workspace_4.1.4-0ubuntu1~intrepid3.2_powerpc_translations.tar.gz, kdebase-workspace_4.1.4-0ubuntu1~intrepid3.2_i386_translations.tar.gz, kdebase-workspace, kdebase-workspace_4.1.4-0ubuntu1~intrepid3.2_amd64_translations.tar.gz, kdebase-workspace_4.1.4-0ubuntu1~intrepid3.2_ia64_translations.tar.gz, kdebase-workspace_4.1.4-0ubuntu1~intrepid3.2_sparc_translations.tar.gz (delayed) 4:4.1.4-0ubuntu1~intrepid3.2 (Accepted)

kdebase-workspace (4:4.1.4-0ubuntu1~intrepid3.2) intrepid-security; urgency=low

  * SECURITY UPDATE: KDM Local Privilege Escalation Vulnerability (LP: #562440).
   - Add debian/patches/CVE-2010-0436_fix_kdm_local_exploit.diff
   - kdm/backend/ctrl.c: prevent race condition during user login which could
     allow execution of arbitrary code as root
   - CVE-2010-0436
   - http://www.kde.org/info/security/advisory-20100413-1.txt

Date: Fri, 16 Apr 2010 19:19:37 +0100
Changed-By: Jonathan Riddell <jriddell@...>
Maintainer: Kubuntu Developers <kubuntu-devel@...>
https://launchpad.net/ubuntu/intrepid/+source/kdebase-workspace/4:4.1.4-0ubuntu1~intrepid3.2
Format: 1.8
Date: Fri, 16 Apr 2010 19:19:37 +0100
Source: kdebase-workspace
Binary: kdebase-workspace kdebase-workspace-bin kdebase-workspace-libs4+5
kdebase-workspace-data kdebase-workspace-wallpapers kdebase-workspace-dev kdm klipper
ksysguardd ksysguard kde-window-manager libkdecorations4 libkwineffects1 systemsettings
kdebase-workspace-dbg libplasma2 libplasma-dev kwin python-plasma python-plasma-examples
Architecture: source
Version: 4:4.1.4-0ubuntu1~intrepid3.2
Distribution: intrepid-security
Urgency: low
Maintainer: Kubuntu Developers <kubuntu-devel@...>
Changed-By: Jonathan Riddell <jriddell@...>
Description: 
 kde-window-manager - the KDE 4 window manager (KWin)
(Continue reading)

Ubuntu Installer | 19 Apr 20:04
Favicon

[ubuntu/intrepid-security] ffmpeg-debian, ffmpeg-debian (delayed) 3:0.svn20080206-12ubuntu3.2 (Accepted)

ffmpeg-debian (3:0.svn20080206-12ubuntu3.2) intrepid-security; urgency=low

  * SECURITY UPDATE: Fix a multitude of security issues
    - debian/patches/CVE-2009-46XX/security-issue03.patch: check stream
      existence before assignment
    - debian/patches/CVE-2009-46XX/security-issue04.patch: check submap
      indexes
    - debian/patches/CVE-2009-46XX/security-issue05.patch: check classbook
      value
    - debian/patches/CVE-2009-46XX/security-issue06.patch: add checks for
      per-packet mode indexes and per-header mode mapping indexes
    - debian/patches/CVE-2009-46XX/security-issue07.patch: check masterbook
      index and subclass book index.
    - debian/patches/CVE-2009-46XX/security-issue08.patch: check
      res_setup->books
    - debian/patches/CVE-2009-46XX/security-issue09.patch: check
      begin/end/partition_size
    - debian/patches/CVE-2009-46XX/security-issue10.patch: check validity
      of channels & samplerate
    - debian/patches/CVE-2009-46XX/security-issue11.patch: fix book_idx
      check
    - debian/patches/CVE-2009-46XX/security-issue12.patch: sanity checks
      for magnitude and angle
    - debian/patches/CVE-2009-46XX/security-issue13.patch: fix = -> == typo
    - debian/patches/CVE-2009-46XX/security-issue14.patch: check dimensions
      against 0 too
    - debian/patches/CVE-2009-46XX/security-issue15.patch: fix
      init_get_bits() buffer size
    - debian/patches/CVE-2009-46XX/security-issue17.patch: make sure that
      all memory allocations succeed
(Continue reading)

Ubuntu Installer | 16 Apr 01:03
Favicon

[ubuntu/intrepid-security] irssi (delayed), irssi 0.8.12-4ubuntu2.2 (Accepted)

irssi (0.8.12-4ubuntu2.2) intrepid-security; urgency=low

  * SECURITY UPDATE: perform certificate host validation
    - debian/patches/91_CVE-2010-1155.patch: adjust to verify hostname against
      CN. Also use one SSL_CTX per connection and use default trusted CAs if
      nothing specified.
    - CVE-2010-1155
  * SECURITY UPDATE: fix crash when checking for fuzzy nick match when not on
    the channel
    - debian/patches/91_CVE-2010-1156.patch: verify channel is non-NULL in
      src/core/nicklist.c
    - CVE-2010-1156
  * debian/patches/92_disable_sslv2.patch: do not use SSLv2 protocol

Date: Wed, 14 Apr 2010 15:15:07 -0500
Changed-By: Jamie Strandboge <jamie@...>
Maintainer: Ubuntu Core Developers <ubuntu-devel-discuss@...>
https://launchpad.net/ubuntu/intrepid/+source/irssi/0.8.12-4ubuntu2.2
Format: 1.8
Date: Wed, 14 Apr 2010 15:15:07 -0500
Source: irssi
Binary: irssi irssi-dev
Architecture: source
Version: 0.8.12-4ubuntu2.2
Distribution: intrepid-security
Urgency: low
Maintainer: Ubuntu Core Developers <ubuntu-devel-discuss@...>
Changed-By: Jamie Strandboge <jamie@...>
(Continue reading)

Ubuntu Installer | 15 Apr 21:05
Favicon

[ubuntu/intrepid-security] cmake, cmake (delayed) 2.6.0-4ubuntu2.1 (Accepted)

cmake (2.6.0-4ubuntu2.1) intrepid-security; urgency=low

  * SECURITY UPDATE: fix DoS via malformed XML
    - debian/patches/CVE_2009_3720.patch: xmltok_impl.c to not access beyond
      end of input string
    - CVE-2009-3720
  * SECURITY UPDATE: fix DoS via malformed UTF-8 sequences
    - debian/patches/CVE_2009_3560.patch: update xmlparse.c to properly
      recognize the end of a token
    - CVE-2009-3560

Date: Tue, 13 Apr 2010 20:56:53 -0500
Changed-By: Jamie Strandboge <jamie@...>
Maintainer: Ubuntu Core Developers <ubuntu-devel-discuss@...>
https://launchpad.net/ubuntu/intrepid/+source/cmake/2.6.0-4ubuntu2.1
Format: 1.8
Date: Tue, 13 Apr 2010 20:56:53 -0500
Source: cmake
Binary: cmake cmake-gui
Architecture: source
Version: 2.6.0-4ubuntu2.1
Distribution: intrepid-security
Urgency: low
Maintainer: Ubuntu Core Developers <ubuntu-devel-discuss@...>
Changed-By: Jamie Strandboge <jamie@...>
Description: 
 cmake      - A cross-platform, open-source make system
 cmake-gui  - GUI for cmake cross-platform make system
(Continue reading)

Ubuntu Installer | 15 Apr 18:04
Favicon

[ubuntu/intrepid-security] sudo, sudo (delayed) 1.6.9p17-1ubuntu2.3 (Accepted)

sudo (1.6.9p17-1ubuntu2.3) intrepid-security; urgency=low

  * SECURITY UPDATE: properly verify path in find_path.c for the 'sudoedit'
    pseudo-command when running from the current working directory and
    secure_path is disabled
    - CVE-2010-XXXX

Date: Wed, 07 Apr 2010 15:49:07 -0500
Changed-By: Jamie Strandboge <jamie@...>
Maintainer: Martin Pitt <martin.pitt@...>
https://launchpad.net/ubuntu/intrepid/+source/sudo/1.6.9p17-1ubuntu2.3
Format: 1.8
Date: Wed, 07 Apr 2010 15:49:07 -0500
Source: sudo
Binary: sudo sudo-ldap
Architecture: source
Version: 1.6.9p17-1ubuntu2.3
Distribution: intrepid-security
Urgency: low
Maintainer: Martin Pitt <martin.pitt@...>
Changed-By: Jamie Strandboge <jamie@...>
Description: 
 sudo       - Provide limited super user privileges to specific users
 sudo-ldap  - Provide limited super user privileges to specific users
Changes: 
 sudo (1.6.9p17-1ubuntu2.3) intrepid-security; urgency=low
 .
   * SECURITY UPDATE: properly verify path in find_path.c for the 'sudoedit'
(Continue reading)

Brian Thomason | 14 Apr 06:05
Favicon

[ubuntu/intrepid] acroread 9.3.2-intrepid1 (Accepted)

acroread (9.3.2-intrepid1) intrepid; urgency=low

  * Initial release of 9.3.2 for intrepid

Date: Tue, 13 Apr 2010 23:55:28 -0400
Changed-By: Brian Thomason <brian.thomason@...>
https://launchpad.net/ubuntu/intrepid/+source/acroread/9.3.2-intrepid1

Format: 1.8
Date: Tue, 13 Apr 2010 23:55:28 -0400
Source: acroread
Binary: acroread
Architecture: source
Version: 9.3.2-intrepid1
Distribution: intrepid
Urgency: low
Maintainer: Brian Thomason <brian.thomason@...>
Changed-By: Brian Thomason <brian.thomason@...>
Description: 
 acroread   - Adobe Reader
Changes: 
 acroread (9.3.2-intrepid1) intrepid; urgency=low
 .
   * Initial release of 9.3.2 for intrepid
Checksums-Sha1: 
 00570999b114ea02497da0650a13d85d2da5f1c2 1207 acroread_9.3.2-intrepid1.dsc
 543c66e73e0742f68c2f170f35f6a99fd41635d9 5572 acroread_9.3.2-intrepid1.diff.gz
Checksums-Sha256: 
(Continue reading)

Ubuntu Installer | 8 Apr 23:04
Favicon

[ubuntu/intrepid-security] havp_0.89-2ubuntu2~intrepid3_ia64_translations.tar.gz, havp_0.89-2ubuntu2~intrepid3_powerpc_translations.tar.gz, havp_0.89-2ubuntu2~intrepid3_i386_translations.tar.gz, havp, havp_0.89-2ubuntu2~intrepid3_sparc_translations.tar.gz (delayed), havp_0.89-2ubuntu2~intrepid3_lpia_translations.tar.gz, havp_0.89-2ubuntu2~intrepid3_amd64_translations.tar.gz, havp_0.89-2ubuntu2~intrepid3_hppa_translations.tar.gz 0.89-2ubuntu2~intrepid3 (Accepted)

havp (0.89-2ubuntu2~intrepid3) intrepid-security; urgency=low

  * No change rebuild against clamav 0.95

havp (0.89-2ubuntu2~intrepid2) intrepid-backports; urgency=low

  * No change rebuild to ensure build is against libclamav6

havp (0.89-2ubuntu2~intrepid1) intrepid-backports; urgency=low

  * Automated backport upload; no source changes.

havp (0.89-2ubuntu2) jaunty; urgency=low

  * updated to build with clamav 0.95
    - debian/patches/10_clamav095_support.dpatch

havp (0.89-2ubuntu1) jaunty; urgency=low

  * Merge from debian unstable (LP: #313755), remaining changes:
    - Under certain circumstances, the init script and/or postrm script
      will fail to umount loop-back devices (LP: #296499). This
      issue has been addressed by performing a lazy umount in these
      two scripts.

havp (0.89-2) unstable; urgency=low

  * Create /var/run/havp if it doesn't exist when running init script so
    that it can be used when /var/run is on tmpfs.
    Closes: #502048: havp: Havp init fails after reboot if /var/run is tempfs
(Continue reading)

Ubuntu Installer | 8 Apr 23:04
Favicon

[ubuntu/intrepid-security] clamav_0.95.3+dfsg-1ubuntu0.09.04~intrepid3_lpia_translations.tar.gz, clamav_0.95.3+dfsg-1ubuntu0.09.04~intrepid3_hppa_translations.tar.gz, clamav_0.95.3+dfsg-1ubuntu0.09.04~intrepid3_powerpc_translations.tar.gz, clamav_0.95.3+dfsg-1ubuntu0.09.04~intrepid3_ia64_translations.tar.gz, clamav, clamav_0.95.3+dfsg-1ubuntu0.09.04~intrepid3_sparc_translations.tar.gz (delayed), clamav_0.95.3+dfsg-1ubuntu0.09.04~intrepid3_i386_translations.tar.gz, clamav_0.95.3+dfsg-1ubuntu0.09.04~intrepid3_amd64_translations.tar.gz 0.95.3+dfsg-1ubuntu0.09.04~intrepid3 (Accepted)

clamav (0.95.3+dfsg-1ubuntu0.09.04~intrepid3) intrepid-security; urgency=low

  * SECURITY UPDATE: (LP: #553266)
  * References clamav bugs #1771 and #1826
  * libclamav/mspack.c: fix Quantum decompressor (bb#1771)
    - clamav git 224fee54dd6cd8933d7007331ec2bfca0398d4b4
  * libclamav/mspack.c: improve unpacking of malformed cabinets (bb#1826)
    - clamav git 31b77b3fb589ab07e7b4d84f8b3825178864ee51
  * patch based on work by Scott Kitterman

Date: Tue, 06 Apr 2010 13:09:52 -0500
Changed-By: Jamie Strandboge <jamie@...>
Maintainer: Ubuntu Developers <ubuntu-devel-discuss@...>
https://launchpad.net/ubuntu/intrepid/+source/clamav/0.95.3+dfsg-1ubuntu0.09.04~intrepid3
Format: 1.8
Date: Tue, 06 Apr 2010 13:09:52 -0500
Source: clamav
Binary: clamav-base clamav-docs clamav-dbg clamav libclamav-dev libclamav6 clamav-daemon
clamav-testfiles clamav-freshclam clamav-milter
Architecture: source
Version: 0.95.3+dfsg-1ubuntu0.09.04~intrepid3
Distribution: intrepid-security
Urgency: low
Maintainer: Ubuntu Developers <ubuntu-devel-discuss@...>
Changed-By: Jamie Strandboge <jamie@...>
Description: 
 clamav     - anti-virus utility for Unix - command-line interface
 clamav-base - anti-virus utility for Unix - base package
(Continue reading)


Gmane