Content-Type: text/plain
debian-changes-digest Digest Volume 2007 : Issue 125
Today's Topics:
Accepted gforge 3.1-31sarge3 (source [ Roland Mas ]
Accepted wesnoth 1.2-2 (source all p [ Gerfried Fuchs ]
Accepted gforge 4.5.14-22etch2 (sour [ Roland Mas ]
Accepted openssl097 0.9.7k-3.1etch1 [ Kurt Roeckx ]
Accepted librpcsecgss 0.14-2etch2 (s [ Florian Weimer ]
Accepted openssl 0.9.7e-3sarge5 (sou [ Kurt Roeckx ]
Accepted zoph 0.6-2.1etch1 (source a [ Thijs Kinkhorst ]
Accepted t1lib 5.1.0-2etch1 (source [ Noah Meyerhans ]
Accepted dhcp 2.0pl5-19.5etch1 (sour [ Steve Kemp ]
Date: Tue, 16 Oct 2007 19:56:54 +0000
From: Roland Mas <lolando@debian.org>
To: debian-changes@lists.debian.org
Subject: Accepted gforge 3.1-31sarge3 (source all)
Message-Id: <E1IhsX8-0005fr-TI@ries.debian.org>
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Format: 1.7
Date: Wed, 03 Oct 2007 09:11:05 +0200
Source: gforge
Binary: gforge-lists-mailman gforge-db-postgresql sourceforge gforge-mta-postfix gforge-sourceforge-transition gforge-shell-ldap gforge gforge-common gforge-web-apache gforge-mta-exim gforge-cvs gforge-ftp-proftpd gforge-mta-exim4 gforge-dns-bind9 gforge-ldap-openldap
Architecture: source all
Version: 3.1-31sarge3
Distribution: oldstable-security
Urgency: high
Maintainer: Roland Mas <lolando@debian.org>
Changed-By: Roland Mas <lolando@debian.org>
Description:
gforge - Collaborative development tool - meta-package
gforge-common - Collaborative development tool - shared files
gforge-cvs - Collaborative development tool - CVS management
gforge-db-postgresql - Collaborative development tool - database (using PostgreSQL)
gforge-dns-bind9 - Collaborative development tool - DNS management (using Bind9)
gforge-ftp-proftpd - Collaborative development tool - FTP management (using ProFTPd)
gforge-ldap-openldap - Collaborative development tool - LDAP directory (using OpenLDAP)
gforge-lists-mailman - Collaborative development tool - mailing-lists (using Mailman)
gforge-mta-exim - Collaborative development tool - mail tools (using Exim)
gforge-mta-exim4 - Collaborative development tool - mail tools (using Exim 4)
gforge-mta-postfix - Collaborative development tool - mail tools (using Postfix)
gforge-shell-ldap - Collaborative development tool - shell accounts (using LDAP)
gforge-sourceforge-transition - Sourceforge to Gforge data transition
gforge-web-apache - Collaborative development tool - web part (using Apache)
sourceforge - Empty package to help with Sourceforge to Gforge transition
Changes:
gforge (3.1-31sarge3) oldstable-security; urgency=high
.
- Fixed cross-site scripting vulnerability (CVE-2007-3918).
Files:
69c3e965dc5dde5d723065adabe0d8ef 868 devel optional gforge_3.1-31sarge3.dsc
4042064560aebe5bb362c8c27eca43aa 297388 devel optional gforge_3.1-31sarge3.diff.gz
dc9f0e70035b35d0be20846c315868ba 56198 devel optional gforge_3.1-31sarge3_all.deb
3a6dcb3aae1b42b68940288df05a146a 93672 devel optional gforge-common_3.1-31sarge3_all.deb
d7e9acb372f8c90f4b549fc5f1eb1f1f 1107774 devel optional gforge-web-apache_3.1-31sarge3_all.deb
caa025909a3b719608bae0cdcebea798 148176 devel optional gforge-db-postgresql_3.1-31sarge3_all.deb
4d601e4e58617c41cf272f7640e27bdf 64954 devel optional gforge-mta-exim4_3.1-31sarge3_all.deb
2951ddcc2e3b7be2b3e10cfef23d7836 64492 devel optional gforge-mta-exim_3.1-31sarge3_all.deb
19b15a64e86bdbebd8bb61f171b4cdf8 64598 devel optional gforge-mta-postfix_3.1-31sarge3_all.deb
219625b5e7ef4d3c0e125bc17c70f67e 60816 devel optional gforge-shell-ldap_3.1-31sarge3_all.deb
1152e31238e82b096cd602dc56ab12d2 99006 devel optional gforge-cvs_3.1-31sarge3_all.deb
2694a85328d558c84cec81b76e9f4a12 59682 devel optional gforge-ftp-proftpd_3.1-31sarge3_all.deb
a11b2ed9cb6bad85ea2d630f0fbf0f3f 70574 devel optional gforge-ldap-openldap_3.1-31sarge3_all.deb
935844a363b4c5342bf77184898cf727 72272 devel optional gforge-dns-bind9_3.1-31sarge3_all.deb
18bb360d94099e5a1e1fabf96af525d2 58070 devel optional gforge-lists-mailman_3.1-31sarge3_all.deb
4451cef4aa7a1e889ba1fb9352c1edfd 59142 devel optional gforge-sourceforge-transition_3.1-31sarge3_all.deb
6ade2bbc273a180a5c0cd9b936fafb83 55628 devel extra sourceforge_3.1-31sarge3_all.deb
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)
iD8DBQFHA0UDDqdWtRRIQ/URAhdxAKCOxpmjsmGyQhi4iO8gPjgaTiPF3wCdG67I
DtIG1Vql8tYQR/rbKlmDTTw=
=j7TP
-----END PGP SIGNATURE-----
Accepted:
gforge-common_3.1-31sarge3_all.deb
to pool/main/g/gforge/gforge-common_3.1-31sarge3_all.deb
gforge-cvs_3.1-31sarge3_all.deb
to pool/main/g/gforge/gforge-cvs_3.1-31sarge3_all.deb
gforge-db-postgresql_3.1-31sarge3_all.deb
to pool/main/g/gforge/gforge-db-postgresql_3.1-31sarge3_all.deb
gforge-dns-bind9_3.1-31sarge3_all.deb
to pool/main/g/gforge/gforge-dns-bind9_3.1-31sarge3_all.deb
gforge-ftp-proftpd_3.1-31sarge3_all.deb
to pool/main/g/gforge/gforge-ftp-proftpd_3.1-31sarge3_all.deb
gforge-ldap-openldap_3.1-31sarge3_all.deb
to pool/main/g/gforge/gforge-ldap-openldap_3.1-31sarge3_all.deb
gforge-lists-mailman_3.1-31sarge3_all.deb
to pool/main/g/gforge/gforge-lists-mailman_3.1-31sarge3_all.deb
gforge-mta-exim4_3.1-31sarge3_all.deb
to pool/main/g/gforge/gforge-mta-exim4_3.1-31sarge3_all.deb
gforge-mta-exim_3.1-31sarge3_all.deb
to pool/main/g/gforge/gforge-mta-exim_3.1-31sarge3_all.deb
gforge-mta-postfix_3.1-31sarge3_all.deb
to pool/main/g/gforge/gforge-mta-postfix_3.1-31sarge3_all.deb
gforge-shell-ldap_3.1-31sarge3_all.deb
to pool/main/g/gforge/gforge-shell-ldap_3.1-31sarge3_all.deb
gforge-sourceforge-transition_3.1-31sarge3_all.deb
to pool/main/g/gforge/gforge-sourceforge-transition_3.1-31sarge3_all.deb
gforge-web-apache_3.1-31sarge3_all.deb
to pool/main/g/gforge/gforge-web-apache_3.1-31sarge3_all.deb
gforge_3.1-31sarge3.diff.gz
to pool/main/g/gforge/gforge_3.1-31sarge3.diff.gz
gforge_3.1-31sarge3.dsc
to pool/main/g/gforge/gforge_3.1-31sarge3.dsc
gforge_3.1-31sarge3_all.deb
to pool/main/g/gforge/gforge_3.1-31sarge3_all.deb
sourceforge_3.1-31sarge3_all.deb
to pool/main/g/gforge/sourceforge_3.1-31sarge3_all.deb
Date: Tue, 16 Oct 2007 19:56:29 +0000
From: Gerfried Fuchs <rhonda@debian.at>
To: debian-changes@lists.debian.org
Subject: Accepted wesnoth 1.2-2 (source all powerpc)
Message-Id: <E1IhsWj-0005d8-1x@ries.debian.org>
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Format: 1.7
Date: Mon, 08 Oct 2007 22:12:04 +0200
Source: wesnoth
Binary: wesnoth-utbs wesnoth-httt wesnoth-ttb wesnoth-data wesnoth wesnoth-server wesnoth-editor wesnoth-trow wesnoth-music wesnoth-tsg wesnoth-ei
Architecture: source all powerpc
Version: 1.2-2
Distribution: stable-security
Urgency: high
Maintainer: Isaac Clerencia <isaac@debian.org>
Changed-By: Gerfried Fuchs <rhonda@debian.at>
Description:
wesnoth - fantasy turn-based strategy game
wesnoth-data - data files for Wesnoth
wesnoth-editor - map editor for Wesnoth
wesnoth-ei - Eastern Invasion official campaign for Wesnoth
wesnoth-httt - Heir to the Throne official campaign for Wesnoth
wesnoth-music - music files for Wesnoth
wesnoth-server - multiplayer network server for Wesnoth
wesnoth-trow - The Rise of Wesnoth official campaign for Wesnoth
wesnoth-tsg - The South Guard official campaign for Wesnoth
wesnoth-ttb - A Tale of Two Brothers official campaign for Wesnoth
wesnoth-utbs - Under the Burning Suns official campaign for Wesnoth
Changes:
wesnoth (1.2-2) stable-security; urgency=high
.
- Fix insecure truncate of a multibyte chat message that can lead to invalid
utf-8 and throw an uncaught exception. Both wesnoth client and server are
affected [CVE-2007-3917]. Patch CVE-2007-3917 was pulled from upstream
svn (revisions 20786, 20802, 20809, 20862).
Files:
9cc6980d04b201a3a7cf313e7ea88352 886 games optional wesnoth_1.2-2.dsc
651be8966f4be3228039ec55e0281773 36830 games optional wesnoth_1.2-2.diff.gz
722a459282abe6d04dbe228d031c088e 74823113 games optional wesnoth_1.2.orig.tar.gz
d95db2fcdf56bc6dd4fa4cf48d8fcded 24524112 games optional wesnoth-data_1.2-2_all.deb
87c74cd4519e180dbcd44a31befe0768 25574902 games optional wesnoth-music_1.2-2_all.deb
e8513a5f8521f7cf908d6a9d308af8ff 4853576 games optional wesnoth-httt_1.2-2_all.deb
f300c6adaacfe2ad2925602436953c76 1452670 games optional wesnoth-tsg_1.2-2_all.deb
aa65d4cb47a22b3f16aed5c7a1d5afed 4095152 games optional wesnoth-trow_1.2-2_all.deb
34c1ff868361622844f8751c1a5e26a0 343872 games optional wesnoth-ttb_1.2-2_all.deb
af054c466eea76ad123d2c07f1ad799d 1016494 games optional wesnoth-ei_1.2-2_all.deb
86cb4d8ebf5ed53a1ce2167ef37cee1f 4827554 games optional wesnoth-utbs_1.2-2_all.deb
1151dc45cfc97968e808c473f16587ec 2003284 games optional wesnoth_1.2-2_powerpc.deb
b38852aa6abe023c4ccb705b1551a618 319738 games optional wesnoth-server_1.2-2_powerpc.deb
557b59779635342bec32f872ed65296a 1556962 games optional wesnoth-editor_1.2-2_powerpc.deb
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)
iD8DBQFHCzk0ELuA/Ba9d8YRAsyjAJ4rhahNrdvGanCFAzlV6OEMg8/uwACgj/7G
KBCDtc0AmE6p2yq+WwfFxTg=
=U3yp
-----END PGP SIGNATURE-----
Accepted:
wesnoth-data_1.2-2_all.deb
to pool/main/w/wesnoth/wesnoth-data_1.2-2_all.deb
wesnoth-editor_1.2-2_powerpc.deb
to pool/main/w/wesnoth/wesnoth-editor_1.2-2_powerpc.deb
wesnoth-ei_1.2-2_all.deb
to pool/main/w/wesnoth/wesnoth-ei_1.2-2_all.deb
wesnoth-httt_1.2-2_all.deb
to pool/main/w/wesnoth/wesnoth-httt_1.2-2_all.deb
wesnoth-music_1.2-2_all.deb
to pool/main/w/wesnoth/wesnoth-music_1.2-2_all.deb
wesnoth-server_1.2-2_powerpc.deb
to pool/main/w/wesnoth/wesnoth-server_1.2-2_powerpc.deb
wesnoth-trow_1.2-2_all.deb
to pool/main/w/wesnoth/wesnoth-trow_1.2-2_all.deb
wesnoth-tsg_1.2-2_all.deb
to pool/main/w/wesnoth/wesnoth-tsg_1.2-2_all.deb
wesnoth-ttb_1.2-2_all.deb
to pool/main/w/wesnoth/wesnoth-ttb_1.2-2_all.deb
wesnoth-utbs_1.2-2_all.deb
to pool/main/w/wesnoth/wesnoth-utbs_1.2-2_all.deb
wesnoth_1.2-2.diff.gz
to pool/main/w/wesnoth/wesnoth_1.2-2.diff.gz
wesnoth_1.2-2.dsc
to pool/main/w/wesnoth/wesnoth_1.2-2.dsc
wesnoth_1.2-2_powerpc.deb
to pool/main/w/wesnoth/wesnoth_1.2-2_powerpc.deb
Date: Tue, 16 Oct 2007 19:56:43 +0000
From: Roland Mas <lolando@debian.org>
To: debian-changes@lists.debian.org
Subject: Accepted gforge 4.5.14-22etch2 (source all)
Message-Id: <E1IhsWx-0005eV-GT@ries.debian.org>
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Format: 1.7
Date: Wed, 03 Oct 2007 09:10:55 +0200
Source: gforge
Binary: gforge-lists-mailman gforge-db-postgresql gforge-mta-postfix gforge-shell-ldap gforge gforge-common gforge-web-apache gforge-mta-exim gforge-mta-courier gforge-ftp-proftpd gforge-shell-postgresql gforge-mta-exim4 gforge-dns-bind9 gforge-ldap-openldap
Architecture: source all
Version: 4.5.14-22etch2
Distribution: stable-security
Urgency: high
Maintainer: Roland Mas <lolando@debian.org>
Changed-By: Roland Mas <lolando@debian.org>
Description:
gforge - collaborative development tool - meta-package
gforge-common - collaborative development tool - shared files
gforge-db-postgresql - collaborative development tool - database (using PostgreSQL)
gforge-dns-bind9 - collaborative development tool - DNS management (using Bind9)
gforge-ftp-proftpd - collaborative development tool - FTP management (using ProFTPd)
gforge-ldap-openldap - collaborative development tool - LDAP directory (using OpenLDAP)
gforge-lists-mailman - collaborative development tool - mailing-lists (using Mailman)
gforge-mta-courier - collaborative development tool - mail tools (using Courier)
gforge-mta-exim - collaborative development tool - mail tools (using Exim)
gforge-mta-exim4 - collaborative development tool - mail tools (using Exim 4)
gforge-mta-postfix - collaborative development tool - mail tools (using Postfix)
gforge-shell-ldap - collaborative development tool - shell accounts (using LDAP)
gforge-shell-postgresql - collaborative development tool - shell accounts (using PostgreSQL
gforge-web-apache - collaborative development tool - web part (using Apache)
Changes:
gforge (4.5.14-22etch2) stable-security; urgency=high
.
- Fixed cross-site scripting vulnerability (CVE-2007-3918).
Files:
2f815829782a6ae85c7aa50ded442a0f 950 devel optional gforge_4.5.14-22etch2.dsc
2554956512ae443af28e98157689eab7 195119 devel optional gforge_4.5.14-22etch2.diff.gz
44bbdb91ddb19ddef8932c5209ef3226 79742 devel optional gforge_4.5.14-22etch2_all.deb
13d570003dc51d1215fb1b807725540d 1010290 devel optional gforge-common_4.5.14-22etch2_all.deb
6dcc527a9d813247e05b0c60f578897b 704278 devel optional gforge-web-apache_4.5.14-22etch2_all.deb
6d5e39eb4b24805eef6c7f934d5dbb95 211934 devel optional gforge-db-postgresql_4.5.14-22etch2_all.deb
d330ea7169c29a73002ec269b84b563b 88588 devel optional gforge-mta-exim4_4.5.14-22etch2_all.deb
0854914dc42cdede3edda7bcbc87ad8e 88086 devel optional gforge-mta-exim_4.5.14-22etch2_all.deb
e90c5cd1bfa0aa575609dc88abaf79e1 87988 devel optional gforge-mta-postfix_4.5.14-22etch2_all.deb
660a0f93b5a19be107a7dbedeb2f2377 75554 devel optional gforge-mta-courier_4.5.14-22etch2_all.deb
3f5b72fc86371e78aba0fd0d9c631148 85802 devel optional gforge-shell-ldap_4.5.14-22etch2_all.deb
e2e86ed40fee4db3e6c3d54f9fa07cac 86612 devel optional gforge-shell-postgresql_4.5.14-22etch2_all.deb
e16d4caee23d474afd52fd034c6d1772 85518 devel optional gforge-ftp-proftpd_4.5.14-22etch2_all.deb
aaf77b9e719611a26361255bc2852088 95140 devel optional gforge-ldap-openldap_4.5.14-22etch2_all.deb
79a08b078f5ad2b2b5ddc5aa0fa7bf59 103224 devel optional gforge-dns-bind9_4.5.14-22etch2_all.deb
b9eba01cb0b024ff51dd3f87200ff799 81550 devel optional gforge-lists-mailman_4.5.14-22etch2_all.deb
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)
iD8DBQFHA0UnDqdWtRRIQ/URAkM+AJ4mTgAHm6zrzKoKR0YZWKbNFu14ZACggTBm
qeMzDoQ/qt/JJ+rBVTVLQiE=
=elFV
-----END PGP SIGNATURE-----
Accepted:
gforge-common_4.5.14-22etch2_all.deb
to pool/main/g/gforge/gforge-common_4.5.14-22etch2_all.deb
gforge-db-postgresql_4.5.14-22etch2_all.deb
to pool/main/g/gforge/gforge-db-postgresql_4.5.14-22etch2_all.deb
gforge-dns-bind9_4.5.14-22etch2_all.deb
to pool/main/g/gforge/gforge-dns-bind9_4.5.14-22etch2_all.deb
gforge-ftp-proftpd_4.5.14-22etch2_all.deb
to pool/main/g/gforge/gforge-ftp-proftpd_4.5.14-22etch2_all.deb
gforge-ldap-openldap_4.5.14-22etch2_all.deb
to pool/main/g/gforge/gforge-ldap-openldap_4.5.14-22etch2_all.deb
gforge-lists-mailman_4.5.14-22etch2_all.deb
to pool/main/g/gforge/gforge-lists-mailman_4.5.14-22etch2_all.deb
gforge-mta-courier_4.5.14-22etch2_all.deb
to pool/main/g/gforge/gforge-mta-courier_4.5.14-22etch2_all.deb
gforge-mta-exim4_4.5.14-22etch2_all.deb
to pool/main/g/gforge/gforge-mta-exim4_4.5.14-22etch2_all.deb
gforge-mta-exim_4.5.14-22etch2_all.deb
to pool/main/g/gforge/gforge-mta-exim_4.5.14-22etch2_all.deb
gforge-mta-postfix_4.5.14-22etch2_all.deb
to pool/main/g/gforge/gforge-mta-postfix_4.5.14-22etch2_all.deb
gforge-shell-ldap_4.5.14-22etch2_all.deb
to pool/main/g/gforge/gforge-shell-ldap_4.5.14-22etch2_all.deb
gforge-shell-postgresql_4.5.14-22etch2_all.deb
to pool/main/g/gforge/gforge-shell-postgresql_4.5.14-22etch2_all.deb
gforge-web-apache_4.5.14-22etch2_all.deb
to pool/main/g/gforge/gforge-web-apache_4.5.14-22etch2_all.deb
gforge_4.5.14-22etch2.diff.gz
to pool/main/g/gforge/gforge_4.5.14-22etch2.diff.gz
gforge_4.5.14-22etch2.dsc
to pool/main/g/gforge/gforge_4.5.14-22etch2.dsc
gforge_4.5.14-22etch2_all.deb
to pool/main/g/gforge/gforge_4.5.14-22etch2_all.deb
Date: Tue, 16 Oct 2007 19:56:45 +0000
From: Kurt Roeckx <kurt@roeckx.be>
To: debian-changes@lists.debian.org
Subject: Accepted openssl097 0.9.7k-3.1etch1 (source i386)
Message-Id: <E1IhsWz-0005ea-8c@ries.debian.org>
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Format: 1.7
Date: Sat, 29 Sep 2007 11:39:38 +0200
Source: openssl097
Binary: libssl0.9.7-dbg libssl0.9.7
Architecture: source i386
Version: 0.9.7k-3.1etch1
Distribution: stable-security
Urgency: low
Maintainer: noahm@debian.org
Changed-By: Kurt Roeckx <kurt@roeckx.be>
Description:
libssl0.9.7 - SSL shared libraries
libssl0.9.7-dbg - Symbol tables for libssl and libcrypt
Closes: 444460
Changes:
openssl097 (0.9.7k-3.1etch1) stable-security; urgency=low
.
- CVE-2007-5135: Fix off by one error in SSL_get_shared_ciphers().
(Closes: #444460)
Files:
b7a4e535383394c3be009e3a1df09bdd 769 utils optional openssl097_0.9.7k-3.1etch1.dsc
be6bba1d67b26eabb48cf1774925416f 3292692 utils optional openssl097_0.9.7k.orig.tar.gz
dc2f489812286cecb705f5b77d523a1e 33285 utils optional openssl097_0.9.7k-3.1etch1.diff.gz
cded472858b38935b95aa798e72e0555 2284392 oldlibs extra libssl0.9.7_0.9.7k-3.1etch1_i386.deb
4f181f50322b488f9eed50fc167d0712 4642676 libdevel extra libssl0.9.7-dbg_0.9.7k-3.1etch1_i386.deb
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)
iD8DBQFG/laTYrVLjBFATsMRAo0yAJsExpmRPLuIlLQ5XFAK856eQbGHCQCeMYCI
u25c08lt1khFbn9Pruz643I=
=LZCJ
-----END PGP SIGNATURE-----
Accepted:
libssl0.9.7-dbg_0.9.7k-3.1etch1_i386.deb
to pool/main/o/openssl097/libssl0.9.7-dbg_0.9.7k-3.1etch1_i386.deb
libssl0.9.7_0.9.7k-3.1etch1_i386.deb
to pool/main/o/openssl097/libssl0.9.7_0.9.7k-3.1etch1_i386.deb
openssl097_0.9.7k-3.1etch1.diff.gz
to pool/main/o/openssl097/openssl097_0.9.7k-3.1etch1.diff.gz
openssl097_0.9.7k-3.1etch1.dsc
to pool/main/o/openssl097/openssl097_0.9.7k-3.1etch1.dsc
Date: Tue, 16 Oct 2007 19:56:49 +0000
From: Florian Weimer <fw@deneb.enyo.de>
To: debian-changes@lists.debian.org
Subject: Accepted librpcsecgss 0.14-2etch2 (source amd64)
Message-Id: <E1IhsX3-0005f0-SG@ries.debian.org>
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Format: 1.7
Date: Tue, 25 Sep 2007 21:30:40 +0200
Source: librpcsecgss
Binary: librpcsecgss-dev librpcsecgss3
Architecture: source amd64
Version: 0.14-2etch2
Distribution: stable-security
Urgency: high
Maintainer: Anibal Monsalve Salazar <anibal@debian.org>
Changed-By: Florian Weimer <fw@deneb.enyo.de>
Description:
librpcsecgss-dev - header files and docs for librpcsecgss
librpcsecgss3 - allows secure rpc communication using the rpcsec_gss protocol
Changes:
librpcsecgss (0.14-2etch2) stable-security; urgency=high
.
- Non-maintainer uploader by the security team
- Fix insufficient patch for CVE-2007-3799 (CVE-2007-4743)
Files:
054fbb57de1b15af0d71518993c73828 1038 libs optional librpcsecgss_0.14-2etch2.dsc
9af57e0a2ebb4edf9adb25ae82c91b8a 1803 libs optional librpcsecgss_0.14-2etch2.diff.gz
9e353957ce23934b3d964644716b0d8c 47942 libdevel optional librpcsecgss-dev_0.14-2etch2_amd64.deb
93ed17a3bfba156da5d8413994120148 34132 libs standard librpcsecgss3_0.14-2etch2_amd64.deb
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)
iQEVAwUBRvlmG797/wQC1SS+AQKL1ggAmekI+k6+mXl5rXPTyhMKlqS5Hy+IlMlT
TUrKcsbzMYkCEvfP7sxopEKOHtqX2kfso1txjasEZTFkeh1QYysknojNa8ubJHzq
z1kMR0T/JU2iNSctpJcDF2fDU5l9Sc3MxFSLUkEySM3wzISdDEl3K7icgCOfhJqO
AsgJGGWgwTXQE8SbRMSjfq4qz7V64UCpQf+RYwoK2qarHk0tF5M31fAAytQMqn1I
F0SbHfG13ShI020Vr+Q49RuAbUgyW3WXuq0cXf3qMXL8BLyQOw1g1r+LsQJCipzl
d7fh3wnuncZJGBg4zydw9Cy3hTKmkOQ6DG7k5iefHO7SEdmZq3F2KA==
=PPdr
-----END PGP SIGNATURE-----
Accepted:
librpcsecgss-dev_0.14-2etch2_amd64.deb
to pool/main/libr/librpcsecgss/librpcsecgss-dev_0.14-2etch2_amd64.deb
librpcsecgss3_0.14-2etch2_amd64.deb
to pool/main/libr/librpcsecgss/librpcsecgss3_0.14-2etch2_amd64.deb
librpcsecgss_0.14-2etch2.diff.gz
to pool/main/libr/librpcsecgss/librpcsecgss_0.14-2etch2.diff.gz
librpcsecgss_0.14-2etch2.dsc
to pool/main/libr/librpcsecgss/librpcsecgss_0.14-2etch2.dsc
Date: Tue, 16 Oct 2007 19:57:26 +0000
From: Kurt Roeckx <kurt@roeckx.be>
To: debian-changes@lists.debian.org
Subject: Accepted openssl 0.9.7e-3sarge5 (source i386)
Message-Id: <E1IhsXe-0005gr-5i@ries.debian.org>
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Format: 1.7
Date: Sat, 29 Sep 2007 11:21:18 +0200
Source: openssl
Binary: libssl-dev openssl libcrypto0.9.7-udeb libssl0.9.7
Architecture: source i386
Version: 0.9.7e-3sarge5
Distribution: oldstable-security
Urgency: low
Maintainer: noahm@debian.org
Changed-By: Kurt Roeckx <kurt@roeckx.be>
Description:
libcrypto0.9.7-udeb - crypto shared library - udeb (udeb)
libssl-dev - SSL development libraries, header files and documentation
libssl0.9.7 - SSL shared libraries
openssl - Secure Socket Layer (SSL) binary and related cryptographic tools
Closes: 444435
Changes:
openssl (0.9.7e-3sarge5) oldstable-security; urgency=low
.
- CVE-2007-5135: Fix off by one error in SSL_get_shared_ciphers().
(Closes: #444435)
- Call dh_fixperms before dh_strip so that stripping actually works.
Files:
d19d0a6a8faf12e7e2abe6b82409af05 639 utils optional openssl_0.9.7e-3sarge5.dsc
b64d10acf6285197d3ad8e923883b6d7 30634 utils optional openssl_0.9.7e-3sarge5.diff.gz
8e96029826588f227906f859bc60667d 916446 utils optional openssl_0.9.7e-3sarge5_i386.deb
337fe2d6a280d9a761c04c20d434fe9c 2194088 libs standard libssl0.9.7_0.9.7e-3sarge5_i386.deb
f97dde687e4bddebb7d87cebfb925058 452446 debian-installer optional libcrypto0.9.7-udeb_0.9.7e-3sarge5_i386.udeb
d104ace51eba364a5ce0a50989eee2a0 2560372 libdevel optional libssl-dev_0.9.7e-3sarge5_i386.deb
package-type: udeb
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)
iD8DBQFG/lWUYrVLjBFATsMRAjNhAJ43cL17ckp8Xv1fLP0DItAVDI5p2ACeOmt9
t+vdxUR1ilb9Z2MKfTemzbw=
=Afif
-----END PGP SIGNATURE-----
Accepted:
libcrypto0.9.7-udeb_0.9.7e-3sarge5_i386.udeb
to pool/main/o/openssl/libcrypto0.9.7-udeb_0.9.7e-3sarge5_i386.udeb
libssl-dev_0.9.7e-3sarge5_i386.deb
to pool/main/o/openssl/libssl-dev_0.9.7e-3sarge5_i386.deb
libssl0.9.7_0.9.7e-3sarge5_i386.deb
to pool/main/o/openssl/libssl0.9.7_0.9.7e-3sarge5_i386.deb
openssl_0.9.7e-3sarge5.diff.gz
to pool/main/o/openssl/openssl_0.9.7e-3sarge5.diff.gz
openssl_0.9.7e-3sarge5.dsc
to pool/main/o/openssl/openssl_0.9.7e-3sarge5.dsc
openssl_0.9.7e-3sarge5_i386.deb
to pool/main/o/openssl/openssl_0.9.7e-3sarge5_i386.deb
Date: Fri, 19 Oct 2007 19:56:17 +0000
From: Thijs Kinkhorst <thijs@debian.org>
To: debian-changes@lists.debian.org
Subject: Accepted zoph 0.6-2.1etch1 (source all)
Message-Id: <E1IixxB-0007Y9-1U@ries.debian.org>
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Format: 1.7
Date: Thu, 18 Oct 2007 00:02:35 +0200
Source: zoph
Binary: zoph
Architecture: source all
Version: 0.6-2.1etch1
Distribution: stable-security
Urgency: high
Maintainer: Edelhard Becker <edelhard@debian.org>
Changed-By: Thijs Kinkhorst <thijs@debian.org>
Description:
zoph - Web based digital image presentation and management system
Closes: 435711
Changes:
zoph (0.6-2.1etch1) stable-security; urgency=high
.
- Non-maintainer upload by the security team.
- Fix SQL injection vulnerability in edit_photos.php & photos.php
(CVE-2007-3905, closes: 435711)
Files:
a7bf5364534ae9fb38ba70dcc371e8c6 850 web optional zoph_0.6-2.1etch1.dsc
7e139b32bd477cccf43454cb4c07c16d 382577 web optional zoph_0.6.orig.tar.gz
c716e920cb6c9b19941af6359ecc697d 25826 web optional zoph_0.6-2.1etch1.diff.gz
147f75305b9b891fb2ab502a94be3e9e 394268 web optional zoph_0.6-2.1etch1_all.deb
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)
iQEVAwUBRxaZYmz0hbPcukPfAQIk0AgAwnHbtLdvYN6KvDT+AavEai5HNg0gtwkw
IGGHehOx+svj1Dvg8uQLXcFFicB4cic0BWJuDGovreBdWntf6/j/+guGL83hcj+P
sEhzCyQjWuXFyzIv3leHBEtP5DA4chL9B2DIkNiZrzbCRygX1C7yGLj40xQleG5S
oUqPdmzfJAg/U07fQ4k6dH5xnlYZstdJSxDj85psDdtleiawZT+BsGgJ0kNVsUGS
fLFWaXU34nTg5jhwCpsMxRCUuOXxO2gR8SPmwx2FyWoHG1IPWS5lWcZQrhyZ5D5k
rV4goOcMY9XvCf3QBQUDI9e/39QeYvqS35c8mRJ1ZsFLQVqhHX9k0g==
=ZF6z
-----END PGP SIGNATURE-----
Accepted:
zoph_0.6-2.1etch1.diff.gz
to pool/main/z/zoph/zoph_0.6-2.1etch1.diff.gz
zoph_0.6-2.1etch1.dsc
to pool/main/z/zoph/zoph_0.6-2.1etch1.dsc
zoph_0.6-2.1etch1_all.deb
to pool/main/z/zoph/zoph_0.6-2.1etch1_all.deb
Date: Fri, 19 Oct 2007 19:56:18 +0000
From: Noah Meyerhans <noahm@debian.org>
To: debian-changes@lists.debian.org
Subject: Accepted t1lib 5.1.0-2etch1 (source all i386)
Message-Id: <E1IixxC-0007YF-EL@ries.debian.org>
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Format: 1.7
Date: Mon, 17 Sep 2007 23:25:45 +0200
Source: t1lib
Binary: t1lib-bin libt1-5 libt1-doc libt1-dev
Architecture: source all i386
Version: 5.1.0-2etch1
Distribution: stable-security
Urgency: high
Maintainer: noahm@debian.org
Changed-By: Noah Meyerhans <noahm@debian.org>
Description:
libt1-5 - Type 1 font rasterizer library - runtime
libt1-dev - Type 1 font rasterizer library - development
libt1-doc - Type 1 font rasterizer library - developers documentation
t1lib-bin - Type 1 font rasterizer library - user binaries
Changes:
t1lib (5.1.0-2etch1) stable-security; urgency=high
.
- Non-maintainer upload by the security team.
- Apply patch from Artur R. Czechowski to fix CVE-2007-4033.
Files:
b7102b98ac02154dd4412e59b944e150 712 libs optional t1lib_5.1.0-2etch1.dsc
c2969c0da7ce6875925412faf96e60c1 13648 libs optional t1lib_5.1.0-2etch1.diff.gz
ad8fa2fd7fa2fd06f04c3a5351384ea4 608800 doc optional libt1-doc_5.1.0-2etch1_all.deb
e7069f1db9b00800a6e6d7f6224514de 146336 libs optional libt1-5_5.1.0-2etch1_i386.deb
7f8d112d1f7bf5adbf03c76546ffb73a 173816 libdevel optional libt1-dev_5.1.0-2etch1_i386.deb
09ffdbb73d67dce27e2e6fed44406287 53786 misc optional t1lib-bin_5.1.0-2etch1_i386.deb
a05bed4aa63637052e60690ccde70421 1838635 libs optional t1lib_5.1.0.orig.tar.gz
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)
iD8DBQFHETq5YrVLjBFATsMRAlO6AJ0RcYhzEujbkwCHbMpCmFDZoVhiPwCgh+v8
rbnkr0BhXIdlUzcGBRGizMY=
=zNoD
-----END PGP SIGNATURE-----
Accepted:
libt1-5_5.1.0-2etch1_i386.deb
to pool/main/t/t1lib/libt1-5_5.1.0-2etch1_i386.deb
libt1-dev_5.1.0-2etch1_i386.deb
to pool/main/t/t1lib/libt1-dev_5.1.0-2etch1_i386.deb
libt1-doc_5.1.0-2etch1_all.deb
to pool/main/t/t1lib/libt1-doc_5.1.0-2etch1_all.deb
t1lib-bin_5.1.0-2etch1_i386.deb
to pool/main/t/t1lib/t1lib-bin_5.1.0-2etch1_i386.deb
t1lib_5.1.0-2etch1.diff.gz
to pool/main/t/t1lib/t1lib_5.1.0-2etch1.diff.gz
t1lib_5.1.0-2etch1.dsc
to pool/main/t/t1lib/t1lib_5.1.0-2etch1.dsc
Date: Sun, 21 Oct 2007 19:56:19 +0000
From: Steve Kemp <skx@debian.org>
To: debian-changes@lists.debian.org
Subject: Accepted dhcp 2.0pl5-19.5etch1 (source amd64)
Message-Id: <E1IjguJ-00017F-6X@ries.debian.org>
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Format: 1.7
Date: Mon, 15 Oct 2007 21:19:32 +0000
Source: dhcp
Binary: dhcp dhcp-client dhcp-client-udeb dhcp-relay
Architecture: source amd64
Version: 2.0pl5-19.5etch1
Distribution: stable-security
Urgency: high
Maintainer: Eloy A. Paris <peloy@debian.org>
Changed-By: Steve Kemp <skx@debian.org>
Description:
dhcp - DHCP server for automatic IP address assignment
dhcp-client - DHCP Client
dhcp-client-udeb - DHCP Client for debian-installer (udeb)
dhcp-relay - DHCP Relay
Changes:
dhcp (2.0pl5-19.5etch1) stable-security; urgency=high
.
- Non-maintainer upload by the testing-security team
- Fix stack-based buffer overflow in options.c, which allows arbitrary
code execution or remote denial of service.
Fixes: CVE-2007-5365
Files:
07a1aaa5663007a56b3930bdf843a8a4 683 net optional dhcp_2.0pl5-19.5etch1.dsc
a44eace486ab768b3b73d22a9a64aa35 108226 net optional dhcp_2.0pl5-19.5etch1.diff.gz
e37484724dc8cc62279331552136b16b 115762 net optional dhcp_2.0pl5-19.5etch1_amd64.deb
afb0a5fac336ee590b529d229c134c37 109188 net optional dhcp-client_2.0pl5-19.5etch1_amd64.deb
5920da74cbbc629f67648da42bd5ac26 76090 net optional dhcp-relay_2.0pl5-19.5etch1_amd64.deb
460339f23ec8fc589262e47b4d476e6b 46720 debian-installer optional dhcp-client-udeb_2.0pl5-19.5etch1_amd64.udeb
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)
iD8DBQFHGiFqhuANDBmkLRkRAv/1AJ9tYUu5Uni0ButPCG8kQpR31hlhyACgkizb
LdEUfq1x8aP9PJ0VNJzpMLg=
=OIl6
-----END PGP SIGNATURE-----
Accepted:
dhcp-client-udeb_2.0pl5-19.5etch1_amd64.udeb
to pool/main/d/dhcp/dhcp-client-udeb_2.0pl5-19.5etch1_amd64.udeb
dhcp-client_2.0pl5-19.5etch1_amd64.deb
to pool/main/d/dhcp/dhcp-client_2.0pl5-19.5etch1_amd64.deb
dhcp-relay_2.0pl5-19.5etch1_amd64.deb
to pool/main/d/dhcp/dhcp-relay_2.0pl5-19.5etch1_amd64.deb
dhcp_2.0pl5-19.5etch1.diff.gz
to pool/main/d/dhcp/dhcp_2.0pl5-19.5etch1.diff.gz
dhcp_2.0pl5-19.5etch1.dsc
to pool/main/d/dhcp/dhcp_2.0pl5-19.5etch1.dsc
dhcp_2.0pl5-19.5etch1_amd64.deb
to pool/main/d/dhcp/dhcp_2.0pl5-19.5etch1_amd64.deb
End of debian-changes-digest Digest V2007 Issue #125
Received on Sun Oct 21 15:58:58 2007