Content-Type: text/plain
debian-changes-digest Digest Volume 2007 : Issue 91
Today's Topics:
Accepted tinymux 2.4.3.31-1etch1 (so [ Steve Kemp ]
Accepted poppler 0.4.5-5.1etch1 (sou [ Moritz Muehlenhoff ]
Accepted xfs 1:1.0.1-6 (source i386) [ Julien Cristau ]
Accepted postgresql-8.1 8.1.9-0etch2 [ Martin Pitt ]
Accepted tcpdump 3.8.3-5sarge3 (sour [ Moritz Muehlenhoff ]
Accepted findutils 4.2.28-1etch1 (so [ Andreas Metzler ]
Accepted fai-kernels 1.17+etch4 (sou [ dann frazier <dannf@debian.org> ]
Accepted rdesktop 1.4.0-2sarge1 (sou [ Laszlo Boszormenyi (GCS) <gcs@debia ]
Date: Thu, 16 Aug 2007 19:59:40 +0000
From: Steve Kemp <skx@debian.org>
To: debian-changes@lists.debian.org
Subject: Accepted tinymux 2.4.3.31-1etch1 (source amd64)
Message-Id: <E1ILlVM-0008St-RS@ries.debian.org>
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Format: 1.7
Date: Mon, 18 Jun 2007 12:17:35 +0000
Source: tinymux
Binary: tinymux
Architecture: source amd64
Version: 2.4.3.31-1etch1
Distribution: stable-security
Urgency: high
Maintainer: Ervin Hearn III <noltar@korongil.net>
Changed-By: Steve Kemp <skx@debian.org>
Description:
tinymux - text-based multi-user virtual world server
Changes:
tinymux (2.4.3.31-1etch1) stable-security; urgency=high
.
- Non-maintainer upload by The Security Team.
- Fixed a potential buffer overflow involving math operations.
[CVE-2007-1655]
Files:
43a81f38076f544c7d5dcee9b4805082 609 games optional tinymux_2.4.3.31-1etch1.dsc
7b149de6a1ef5c26b989f05f7f894ba0 925630 games optional tinymux_2.4.3.31.orig.tar.gz
5561f8f373ba594299fb08935d0d28b8 25768 games optional tinymux_2.4.3.31-1etch1.diff.gz
a715fedaa66a6656d413086c0c349c84 646318 games optional tinymux_2.4.3.31-1etch1_amd64.deb
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)
iD8DBQFGdmpbwM/Gs81MDZ0RAo4QAKCmdoETEVC+6f+zT2h3SxqOzrHK5QCfcesY
kn3jL76V5OHUwUPkbRHv8gY=
=kz0y
-----END PGP SIGNATURE-----
Accepted:
tinymux_2.4.3.31-1etch1.diff.gz
to pool/main/t/tinymux/tinymux_2.4.3.31-1etch1.diff.gz
tinymux_2.4.3.31-1etch1.dsc
to pool/main/t/tinymux/tinymux_2.4.3.31-1etch1.dsc
tinymux_2.4.3.31-1etch1_amd64.deb
to pool/main/t/tinymux/tinymux_2.4.3.31-1etch1_amd64.deb
Date: Thu, 16 Aug 2007 19:59:36 +0000
From: Moritz Muehlenhoff <jmm@debian.org>
To: debian-changes@lists.debian.org
Subject: Accepted poppler 0.4.5-5.1etch1 (source i386)
Message-Id: <E1ILlVI-0008SS-Lr@ries.debian.org>
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Format: 1.7
Date: Fri, 3 Aug 2007 17:47:47 +0200
Source: poppler
Binary: libpoppler-glib-dev poppler-utils libpoppler0c2-qt libpoppler-qt-dev libpoppler-dev libpoppler0c2-glib libpoppler0c2
Architecture: source i386
Version: 0.4.5-5.1etch1
Distribution: stable-security
Urgency: high
Maintainer: OndÅej Surý <ondrej@debian.org>
Changed-By: Moritz Muehlenhoff <jmm@debian.org>
Description:
libpoppler-dev - PDF rendering library -- development files
libpoppler-glib-dev - PDF rendering library -- development files (GLib interface)
libpoppler-qt-dev - PDF rendering library -- development files (Qt interface)
libpoppler0c2 - PDF rendering library
libpoppler0c2-glib - PDF rendering library (GLib-based shared library)
libpoppler0c2-qt - PDF rendering library (Qt-based shared library)
poppler-utils - PDF utilitites (based on libpoppler)
Changes:
poppler (0.4.5-5.1etch1) stable-security; urgency=high
.
- Fix integer overflow in stream predictor (CVE-2007-3387).
Files:
b1346c2cb4aee0ae1ca33ba060094007 749 devel optional poppler_0.4.5-5.1etch1.dsc
2bb1c75aa3f9c42f0ba48b5492e6d32c 783752 devel optional poppler_0.4.5.orig.tar.gz
2f989d0448c2692300bd751bf522f5bd 482690 devel optional poppler_0.4.5-5.1etch1.diff.gz
3c98ad946f941c338ce310c4dd58974f 443208 libs optional libpoppler0c2_0.4.5-5.1etch1_i386.deb
725e3b628ecfb382bfd9d75049d24f84 573554 libdevel optional libpoppler-dev_0.4.5-5.1etch1_i386.deb
1d30a6edbb90f4ce1c477ed5be4e66f0 40564 libs optional libpoppler0c2-glib_0.4.5-5.1etch1_i386.deb
93d59749719868c9e8e855ba5be957c1 44092 libdevel optional libpoppler-glib-dev_0.4.5-5.1etch1_i386.deb
ba2d26951c5f57b25319c00370f5d4d1 29336 libs optional libpoppler0c2-qt_0.4.5-5.1etch1_i386.deb
d867bd597db2deb7a818780addad7c46 30104 libdevel optional libpoppler-qt-dev_0.4.5-5.1etch1_i386.deb
4c162ed3aa37045dd23a9aaf97d62f7d 80734 utils optional poppler-utils_0.4.5-5.1etch1_i386.deb
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)
iD8DBQFGs0ymXm3vHE4uyloRAnX2AKDGX4idD4eUDDAZvhECDPTOJcuD4wCeNdIu
s8jp400DTm4kLEosn6O1N2Y=
=cbpI
-----END PGP SIGNATURE-----
Accepted:
libpoppler-dev_0.4.5-5.1etch1_i386.deb
to pool/main/p/poppler/libpoppler-dev_0.4.5-5.1etch1_i386.deb
libpoppler-glib-dev_0.4.5-5.1etch1_i386.deb
to pool/main/p/poppler/libpoppler-glib-dev_0.4.5-5.1etch1_i386.deb
libpoppler-qt-dev_0.4.5-5.1etch1_i386.deb
to pool/main/p/poppler/libpoppler-qt-dev_0.4.5-5.1etch1_i386.deb
libpoppler0c2-glib_0.4.5-5.1etch1_i386.deb
to pool/main/p/poppler/libpoppler0c2-glib_0.4.5-5.1etch1_i386.deb
libpoppler0c2-qt_0.4.5-5.1etch1_i386.deb
to pool/main/p/poppler/libpoppler0c2-qt_0.4.5-5.1etch1_i386.deb
libpoppler0c2_0.4.5-5.1etch1_i386.deb
to pool/main/p/poppler/libpoppler0c2_0.4.5-5.1etch1_i386.deb
poppler-utils_0.4.5-5.1etch1_i386.deb
to pool/main/p/poppler/poppler-utils_0.4.5-5.1etch1_i386.deb
poppler_0.4.5-5.1etch1.diff.gz
to pool/main/p/poppler/poppler_0.4.5-5.1etch1.diff.gz
poppler_0.4.5-5.1etch1.dsc
to pool/main/p/poppler/poppler_0.4.5-5.1etch1.dsc
Date: Thu, 16 Aug 2007 20:00:02 +0000
From: Julien Cristau <jcristau@debian.org>
To: debian-changes@lists.debian.org
Subject: Accepted xfs 1:1.0.1-6 (source i386)
Message-Id: <E1ILlVi-0008Ug-Qh@ries.debian.org>
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Format: 1.7
Date: Sat, 28 Jul 2007 19:28:37 +0200
Source: xfs
Binary: xfs
Architecture: source i386
Version: 1:1.0.1-6
Distribution: stable-security
Urgency: high
Maintainer: Debian X Strike Force <debian-x@lists.debian.org>
Changed-By: Julien Cristau <jcristau@debian.org>
Description:
xfs - X font server
Changes:
xfs (1:1.0.1-6) stable-security; urgency=high
.
- Security upload.
- Fix race condition in the xfs init script (CVE-2007-3103).
Files:
938a05eb2b1638fc49b4d7101084c69b 794 x11 optional xfs_1.0.1-6.dsc
32e8b6b24ec3d4c0de11d81061640cc2 174623 x11 optional xfs_1.0.1.orig.tar.gz
0eeacd5783c66b937eaa1dbde6145401 28440 x11 optional xfs_1.0.1-6.diff.gz
40191532dd37541d09a9ff62bf9e6189 56856 x11 optional xfs_1.0.1-6_i386.deb
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)
iD8DBQFGrImlmEvTgKxfcAwRAlUbAKDL1gQ2ZGD7jJO9Si/6OZzXWpV8tQCdFBOz
uee8BoRNZ1wgNP+pbmEgYBw=
=dH46
-----END PGP SIGNATURE-----
Accepted:
xfs_1.0.1-6.diff.gz
to pool/main/x/xfs/xfs_1.0.1-6.diff.gz
xfs_1.0.1-6.dsc
to pool/main/x/xfs/xfs_1.0.1-6.dsc
xfs_1.0.1-6_i386.deb
to pool/main/x/xfs/xfs_1.0.1-6_i386.deb
Date: Fri, 17 Aug 2007 07:56:22 +0000
From: Josselin Mouette <joss@debian.org>
To: debian-changes@lists.debian.org
Subject: Accepted gnome-hearts 0.1.3-2etch1 (source i386)
Message-Id: <E1ILwgw-00069W-BJ@ries.debian.org>
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Format: 1.7
Date: Tue, 26 Jun 2007 09:05:49 +0200
Source: gnome-hearts
Binary: gnome-hearts
Architecture: source i386
Version: 0.1.3-2etch1
Distribution: stable
Urgency: low
Maintainer: Sander Marechal <s.marechal@jejik.com>
Changed-By: Josselin Mouette <joss@debian.org>
Description:
gnome-hearts - The classic hearts card game for the GNOME desktop
Closes: 421372 430584
Changes:
gnome-hearts (0.1.3-2etch1) stable; urgency=low
.
- Depend on librsvg2-common (closes: #421372, #430584).
Files:
ffbf43be8c55ff9d4ad6f9126678821d 1616 games optional gnome-hearts_0.1.3-2etch1.dsc
c0debe76e533502e6cd72dcde47cc292 198442 games optional gnome-hearts_0.1.3-2etch1.diff.gz
542b895537b7493af52ec37e00683928 108668 games optional gnome-hearts_0.1.3-2etch1_i386.deb
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)
iD8DBQFGgL2nrSla4ddfhTMRAvlQAJ9Zyn7HO+cNjcWXWDdH/9cUI9FfpgCg8vmy
9grw9Cn/iPxzalMCDerYgGw=
=xMrY
-----END PGP SIGNATURE-----
Accepted:
gnome-hearts_0.1.3-2etch1.diff.gz
to pool/main/g/gnome-hearts/gnome-hearts_0.1.3-2etch1.diff.gz
gnome-hearts_0.1.3-2etch1.dsc
to pool/main/g/gnome-hearts/gnome-hearts_0.1.3-2etch1.dsc
gnome-hearts_0.1.3-2etch1_i386.deb
to pool/main/g/gnome-hearts/gnome-hearts_0.1.3-2etch1_i386.deb
Date: Fri, 17 Aug 2007 07:56:16 +0000
From: Martin Pitt <mpitt@debian.org>
To: debian-changes@lists.debian.org
Subject: Accepted postgresql-8.1 8.1.9-0etch2 (source i386 all)
Message-Id: <E1ILwgq-00068w-BP@ries.debian.org>
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Format: 1.7
Date: Sat, 23 Jun 2007 18:54:57 +0200
Source: postgresql-8.1
Binary: postgresql-8.1 postgresql-pltcl-8.1 postgresql-plperl-8.1 libpgtypes2 libpq-dev libpq4 postgresql-doc-8.1 postgresql-plpython-8.1 libecpg5 libecpg-compat2 libecpg-dev postgresql-client-8.1 postgresql-contrib-8.1 postgresql-server-dev-8.1
Architecture: source i386 all
Version: 8.1.9-0etch2
Distribution: stable
Urgency: high
Maintainer: Martin Pitt <mpitt@debian.org>
Changed-By: Martin Pitt <mpitt@debian.org>
Description:
libecpg-compat2 - older version of run-time library for ECPG programs
libecpg-dev - development files for ECPG (Embedded PostgreSQL for C)
libecpg5 - run-time library for ECPG programs
libpgtypes2 - shared library libpgtypes for PostgreSQL 8.1
libpq-dev - header files for libpq4 (PostgreSQL library)
libpq4 - PostgreSQL C client library
postgresql-8.1 - object-relational SQL database, version 8.1 server
postgresql-client-8.1 - front-end programs for PostgreSQL 8.1
postgresql-contrib-8.1 - additional facilities for PostgreSQL
postgresql-doc-8.1 - documentation for the PostgreSQL database management system
postgresql-plperl-8.1 - PL/Perl procedural language for PostgreSQL 8.1
postgresql-plpython-8.1 - PL/Python procedural language for PostgreSQL 8.1
postgresql-pltcl-8.1 - PL/Tcl procedural language for PostgreSQL 8.1
postgresql-server-dev-8.1 - development files for PostgreSQL 8.1 server-side programming
Closes: 429696
Changes:
postgresql-8.1 (8.1.9-0etch2) stable; urgency=high
.
- Add debian/patches/00upstream-01-polymorphic-functions.patch:
- Fix regression introduced in 8.1.9: Polymorphic SQL functions with an
"anyelement" return value stopped working.
- Patch taken from 8.1 branch of upstream CVS:
http://developer.postgresql.org/cvsweb.cgi/pgsql/src/backend/optimizer/util/clauses.c.diff?r1=1.201.2.3&r2=1.201.2.4
- Also backported the test cases for this. They only affect build time,
not the built .debs, and verify that the fix works, so this should be in
a stable update, too. Taken from upstream CVS:
http://developer.postgresql.org/cvsweb.cgi/pgsql/src/test/regress/expected/polymorphism.out.diff?r1=1.7&r2=1.7.2.1
http://developer.postgresql.org/cvsweb.cgi/pgsql/src/test/regress/sql/polymorphism.sql.diff?r1=1.1&r2=1.1.10.1
- Closes: #429696
Files:
188896a7db7fa168aa170af21f02675e 1168 misc optional postgresql-8.1_8.1.9-0etch2.dsc
cc784eaad3378103da5010698559d6d3 34991 misc optional postgresql-8.1_8.1.9-0etch2.diff.gz
b564d835fb10f43ce8006cf0b7d8b6f2 1577766 doc optional postgresql-doc-8.1_8.1.9-0etch2_all.deb
82dde8ed68cbdfdd30241e4fea8f97b4 325884 libdevel optional libpq-dev_8.1.9-0etch2_i386.deb
1a4cef1354dc444e0746834139b00d16 270060 libs optional libpq4_8.1.9-0etch2_i386.deb
0911e706c64ce454d3f87a26710d8cdd 179422 libs optional libecpg5_8.1.9-0etch2_i386.deb
f9beec0cc11ce130227ca3296ab2f0cb 346388 libdevel optional libecpg-dev_8.1.9-0etch2_i386.deb
9ea6cb582004bd0042483ab46c8be5bb 159086 libs optional libecpg-compat2_8.1.9-0etch2_i386.deb
2511339afe27825f9de6a53d786b517a 181628 libs optional libpgtypes2_8.1.9-0etch2_i386.deb
1d6adb9cb83b8acde64cc225b1324b3f 4376252 misc optional postgresql-8.1_8.1.9-0etch2_i386.deb
1ac351101ee838b83d2aefdd683c2e1b 1413224 misc optional postgresql-client-8.1_8.1.9-0etch2_i386.deb
7f788bdee960c6afa36f585778598714 605066 libdevel optional postgresql-server-dev-8.1_8.1.9-0etch2_i386.deb
6deb0d2dfb17e97937809cefeacf3d28 597126 misc optional postgresql-contrib-8.1_8.1.9-0etch2_i386.deb
478e428d5a8ef4108f0118c578b71b69 175320 misc optional postgresql-plperl-8.1_8.1.9-0etch2_i386.deb
a2453b14123d2f5a7f61eab5eb9cabcf 168100 misc optional postgresql-plpython-8.1_8.1.9-0etch2_i386.deb
290de778c0c1f3fa01b618d5a7c913f4 169798 misc optional postgresql-pltcl-8.1_8.1.9-0etch2_i386.deb
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)
iD8DBQFGfVfnDecnbV4Fd/IRApBiAJsFaTVJB9hMJ0+53u1+b13zALHjswCeJE4Z
ANAbt1pUZ2OV3qmfawJN+kg=
=3Guh
-----END PGP SIGNATURE-----
Accepted:
libecpg-compat2_8.1.9-0etch2_i386.deb
to pool/main/p/postgresql-8.1/libecpg-compat2_8.1.9-0etch2_i386.deb
libecpg-dev_8.1.9-0etch2_i386.deb
to pool/main/p/postgresql-8.1/libecpg-dev_8.1.9-0etch2_i386.deb
libecpg5_8.1.9-0etch2_i386.deb
to pool/main/p/postgresql-8.1/libecpg5_8.1.9-0etch2_i386.deb
libpgtypes2_8.1.9-0etch2_i386.deb
to pool/main/p/postgresql-8.1/libpgtypes2_8.1.9-0etch2_i386.deb
libpq-dev_8.1.9-0etch2_i386.deb
to pool/main/p/postgresql-8.1/libpq-dev_8.1.9-0etch2_i386.deb
libpq4_8.1.9-0etch2_i386.deb
to pool/main/p/postgresql-8.1/libpq4_8.1.9-0etch2_i386.deb
postgresql-8.1_8.1.9-0etch2.diff.gz
to pool/main/p/postgresql-8.1/postgresql-8.1_8.1.9-0etch2.diff.gz
postgresql-8.1_8.1.9-0etch2.dsc
to pool/main/p/postgresql-8.1/postgresql-8.1_8.1.9-0etch2.dsc
postgresql-8.1_8.1.9-0etch2_i386.deb
to pool/main/p/postgresql-8.1/postgresql-8.1_8.1.9-0etch2_i386.deb
postgresql-client-8.1_8.1.9-0etch2_i386.deb
to pool/main/p/postgresql-8.1/postgresql-client-8.1_8.1.9-0etch2_i386.deb
postgresql-contrib-8.1_8.1.9-0etch2_i386.deb
to pool/main/p/postgresql-8.1/postgresql-contrib-8.1_8.1.9-0etch2_i386.deb
postgresql-doc-8.1_8.1.9-0etch2_all.deb
to pool/main/p/postgresql-8.1/postgresql-doc-8.1_8.1.9-0etch2_all.deb
postgresql-plperl-8.1_8.1.9-0etch2_i386.deb
to pool/main/p/postgresql-8.1/postgresql-plperl-8.1_8.1.9-0etch2_i386.deb
postgresql-plpython-8.1_8.1.9-0etch2_i386.deb
to pool/main/p/postgresql-8.1/postgresql-plpython-8.1_8.1.9-0etch2_i386.deb
postgresql-pltcl-8.1_8.1.9-0etch2_i386.deb
to pool/main/p/postgresql-8.1/postgresql-pltcl-8.1_8.1.9-0etch2_i386.deb
postgresql-server-dev-8.1_8.1.9-0etch2_i386.deb
to pool/main/p/postgresql-8.1/postgresql-server-dev-8.1_8.1.9-0etch2_i386.deb
Date: Fri, 17 Aug 2007 07:57:02 +0000
From: Moritz Muehlenhoff <jmm@debian.org>
To: debian-changes@lists.debian.org
Subject: Accepted tcpdump 3.8.3-5sarge3 (source i386)
Message-Id: <E1ILwha-0006Be-RT@ries.debian.org>
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Format: 1.7
Date: Wed, 8 Aug 2007 00:19:32 +0200
Source: tcpdump
Binary: tcpdump
Architecture: source i386
Version: 3.8.3-5sarge3
Distribution: oldstable-security
Urgency: high
Maintainer: Romain Francoise <rfrancoise@debian.org>
Changed-By: Moritz Muehlenhoff <jmm@debian.org>
Description:
tcpdump - A powerful tool for network monitoring and data acquisition
Changes:
tcpdump (3.8.3-5sarge3) oldstable-security; urgency=high
.
- Fix buffer overflow in BGP dissector (CVE-2007-3798).
Files:
e32b72a8df4e27d5006154677c7b097b 666 net optional tcpdump_3.8.3-5sarge3.dsc
0e326644d730276bb4b815d9f37345d9 12704 net optional tcpdump_3.8.3-5sarge3.diff.gz
1d457b74f3c451d3386c0011c5d3d401 238936 net optional tcpdump_3.8.3-5sarge3_i386.deb
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.1 (GNU/Linux)
iD8DBQFGuiCeXm3vHE4uyloRAin4AKC2ZrQs1q+ASwnsS6anU5uVRGdsBgCfVSVW
glT0ZXf44gO51iUPV+Ct1SQ=
=rhyX
-----END PGP SIGNATURE-----
Accepted:
tcpdump_3.8.3-5sarge3.diff.gz
to pool/main/t/tcpdump/tcpdump_3.8.3-5sarge3.diff.gz
tcpdump_3.8.3-5sarge3.dsc
to pool/main/t/tcpdump/tcpdump_3.8.3-5sarge3.dsc
tcpdump_3.8.3-5sarge3_i386.deb
to pool/main/t/tcpdump/tcpdump_3.8.3-5sarge3_i386.deb
Date: Fri, 17 Aug 2007 07:56:19 +0000
From: Andreas Metzler <ametzler@debian.org>
To: debian-changes@lists.debian.org
Subject: Accepted findutils 4.2.28-1etch1 (source i386)
Message-Id: <E1ILwgt-00069G-FA@ries.debian.org>
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Format: 1.7
Date: Sat, 2 Jun 2007 11:19:57 +0200
Source: findutils
Binary: findutils
Architecture: source i386
Version: 4.2.28-1etch1
Distribution: stable
Urgency: low
Maintainer: Andreas Metzler <ametzler@debian.org>
Changed-By: Andreas Metzler <ametzler@debian.org>
Description:
findutils - utilities for finding files--find, xargs, and locate
Closes: 426862
Changes:
findutils (4.2.28-1etch1) stable; urgency=low
.
- Fixe locate heap buffer overflow when using databases in old format.
(CVE-2007-2452) Closes: #426862
Files:
e66a379f877524509e29e930ef0a2e3a 673 utils required findutils_4.2.28-1etch1.dsc
d8cec49d48263e64ed01398f30073ab8 17956 utils required findutils_4.2.28-1etch1.diff.gz
57e5ff463c362c17f1262d395793e798 350942 utils required findutils_4.2.28-1etch1_i386.deb
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)
iD8DBQFGriRYHTOcZYuNdmMRAmGOAJ4pIE8FEKo8RXsr3TC0phFxZhL1OwCeJ8Ux
Bcb9v/Fa8QuMKVy2HfNJHdE=
=FH+0
-----END PGP SIGNATURE-----
Accepted:
findutils_4.2.28-1etch1.diff.gz
to pool/main/f/findutils/findutils_4.2.28-1etch1.diff.gz
findutils_4.2.28-1etch1.dsc
to pool/main/f/findutils/findutils_4.2.28-1etch1.dsc
findutils_4.2.28-1etch1_i386.deb
to pool/main/f/findutils/findutils_4.2.28-1etch1_i386.deb
Date: Fri, 17 Aug 2007 07:56:56 +0000
From: Moritz Muehlenhoff <jmm@debian.org>
To: debian-changes@lists.debian.org
Subject: Accepted pdfkit.framework 0.8-2sarge4 (source i386)
Message-Id: <E1ILwhU-0006Ad-Ca@ries.debian.org>
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Format: 1.7
Date: Thu, 2 Aug 2007 23:50:57 +0200
Source: pdfkit.framework
Binary: pdfkit.framework
Architecture: source i386
Version: 0.8-2sarge4
Distribution: oldstable-security
Urgency: high
Maintainer: Brent A. Fulgham <bfulgham@debian.org>
Changed-By: Moritz Muehlenhoff <jmm@debian.org>
Description:
pdfkit.framework - Imaging-related GNUstep framework (PDF Component)
Changes:
pdfkit.framework (0.8-2sarge4) oldstable-security; urgency=high
.
- Fix integer overflow in stream predictor. (CVE-2007-3387)
Files:
bfe8bf57eeadaeeaa5ba33a458a8e185 725 libs optional pdfkit.framework_0.8-2sarge4.dsc
a9e6dc46fa95a2763e865999b3789e50 7077 libs optional pdfkit.framework_0.8-2sarge4.diff.gz
fd435c2d7270d324c74aa054c7230e96 1750926 libs optional pdfkit.framework_0.8-2sarge4_i386.deb
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.1 (GNU/Linux)
iD8DBQFGt3YkXm3vHE4uyloRAnVrAKCzRU3szjNPlflg9tzPkD9CpRSzOgCfcifS
jAEDJh07R5KjSF3rUkoJSK0=
=TNrR
-----END PGP SIGNATURE-----
Accepted:
pdfkit.framework_0.8-2sarge4.diff.gz
to pool/main/p/pdfkit.framework/pdfkit.framework_0.8-2sarge4.diff.gz
pdfkit.framework_0.8-2sarge4.dsc
to pool/main/p/pdfkit.framework/pdfkit.framework_0.8-2sarge4.dsc
pdfkit.framework_0.8-2sarge4_i386.deb
to pool/main/p/pdfkit.framework/pdfkit.framework_0.8-2sarge4_i386.deb
Date: Fri, 17 Aug 2007 07:56:18 +0000
From: dann frazier <dannf@debian.org>
To: debian-changes@lists.debian.org
Subject: Accepted fai-kernels 1.17+etch4 (source i386)
Message-Id: <E1ILwgs-000698-2I@ries.debian.org>
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Format: 1.7
Date: Wed, 15 Aug 2007 17:06:20 -0600
Source: fai-kernels
Binary: fai-kernels
Architecture: source i386
Version: 1.17+etch4
Distribution: stable-security
Urgency: high
Maintainer: Holger Levsen <holger@debian.org>
Changed-By: dann frazier <dannf@debian.org>
Description:
fai-kernels - special kernels for FAI (Fully Automatic Installation)
Changes:
fai-kernels (1.17+etch4) stable-security; urgency=high
.
- NMU by the Security Team
- Rebuild against linux-source-2.6.18 (2.6.18.dfsg.1-13etch1):
- Update abi reference files for ABI 5
- bugfix/bluetooth-l2cap-hci-info-leaks.patch
[SECURITY] Fix information leaks in setsockopt() implementations
See CVE-2007-1353
- bugfix/usblcd-limit-memory-consumption.patch
[SECURITY] limit memory consumption during write in the usblcd driver
See CVE-2007-3513
- bugfix/pppoe-socket-release-mem-leak.patch
[SECURITY] fix unpriveleged memory leak when a PPPoE socket is released
after connect but before PPPIOCGCHAN ioctl is called upon it
See CVE-2007-2525
- bugfix/nf_conntrack_h323-bounds-checking.patch
[SECURITY] nf_conntrack_h323: add checking of out-of-range on choices'
index values
See CVE-2007-3642
- bugfix/dn_fib-out-of-bounds.patch
[SECURITY] Fix out of bounds condition in dn_fib_props[]
See CVE-2007-2172
- bugfix/random-fix-seeding-with-zero-entropy.patch
bugfix/random-fix-error-in-entropy-extraction.patch
[SECURITY] Avoid seeding with the same values at boot time when a
system has no entropy source and fix a casting error in entropy
extraction that resulted in slightly less random numbers.
See CVE-2007-2453
- bugfix/nf_conntrack_sctp-null-deref.patch
[SECURITY] Fix remotely triggerable NULL pointer dereference
by sending an unknown chunk type.
See CVE-2007-2876
- bugfix/i965-secure-batchbuffer.patch
[SECURITY] Fix i965 secured batchbuffer usage
See CVE-2007-3851
- bugfix/reset-pdeathsig-on-suid.patch
[SECURITY] Fix potential privilege escalation caused by improper
clearing of the child process' pdeath signal.
Thanks to Marcel Holtmann for the patch.
See CVE-2007-3848
Files:
9a52e923d40532efcaf60f0048cb8bae 711 admin extra fai-kernels_1.17+etch4.dsc
83214996352214796bbf6c54042b7b0b 53600 admin extra fai-kernels_1.17+etch4.tar.gz
6f5d247feb6ecd8a1e8c8f76c0a54708 5500032 admin extra fai-kernels_1.17+etch4_i386.deb
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)
iD8DBQFGw5H0huANDBmkLRkRAut3AJsFcoKHTNi3Jx7MkE6StkUOK5qUJwCaAhO6
yplkE7mAspK1NzEFlfhE9k0=
=dM5b
-----END PGP SIGNATURE-----
Accepted:
fai-kernels_1.17+etch4.dsc
to pool/main/f/fai-kernels/fai-kernels_1.17+etch4.dsc
fai-kernels_1.17+etch4.tar.gz
to pool/main/f/fai-kernels/fai-kernels_1.17+etch4.tar.gz
fai-kernels_1.17+etch4_i386.deb
to pool/main/f/fai-kernels/fai-kernels_1.17+etch4_i386.deb
Date: Fri, 17 Aug 2007 07:57:04 +0000
From: Laszlo Boszormenyi (GCS) <gcs@debian.hu>
To: debian-changes@lists.debian.org
Subject: Accepted rdesktop 1.4.0-2sarge1 (source i386)
Message-Id: <E1ILwhc-0006C6-PW@ries.debian.org>
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Format: 1.7
Date: Mon, 23 Apr 2007 07:18:46 +0000
Source: rdesktop
Binary: rdesktop
Architecture: source i386
Version: 1.4.0-2sarge1
Distribution: oldstable-security
Urgency: low
Maintainer: Laszlo Boszormenyi (GCS) <gcs@debian.hu>
Changed-By: Laszlo Boszormenyi (GCS) <gcs@debian.hu>
Description:
rdesktop - RDP client for Windows NT/2000 Terminal Server
Changes:
rdesktop (1.4.0-2sarge1) oldstable-security; urgency=low
.
- Fix segfault regression caused by libx11-6 security fix.
Files:
95239010d328848d69bbcd59df29ee1b 623 x11 optional rdesktop_1.4.0-2sarge1.dsc
542cb9d9b4dd1ecaf3ed4ff753fea7b8 202531 x11 optional rdesktop_1.4.0.orig.tar.gz
ac732ace18f41e829a3c38730934fbc4 10664 x11 optional rdesktop_1.4.0-2sarge1.diff.gz
1c57e38030bc1c7311695cef03d2b560 94980 x11 optional rdesktop_1.4.0-2sarge1_i386.deb
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.1 (GNU/Linux)
iD8DBQFGSL+3Xm3vHE4uyloRAlJRAJ9lVs7W+0+o8JTk31b3BivyCKdXngCfVKM0
+P98KK/XuleD+u0LaR7VG3s=
=KMp3
-----END PGP SIGNATURE-----
Accepted:
rdesktop_1.4.0-2sarge1.diff.gz
to pool/main/r/rdesktop/rdesktop_1.4.0-2sarge1.diff.gz
rdesktop_1.4.0-2sarge1.dsc
to pool/main/r/rdesktop/rdesktop_1.4.0-2sarge1.dsc
rdesktop_1.4.0-2sarge1_i386.deb
to pool/main/r/rdesktop/rdesktop_1.4.0-2sarge1_i386.deb
End of debian-changes-digest Digest V2007 Issue #91
Received on Fri Aug 17 04:01:55 2007