Content-Type: text/plain
debian-changes-digest Digest Volume 2007 : Issue 126
Today's Topics:
Accepted pam 0.79-5 (source i386 all [ Steve Langasek ]
Accepted icedove 1.5.0.13+1.5.0.14b. [ Alexander Sack ]
Accepted t1lib 5.0.2-3sarge1 (source [ Noah Meyerhans ]
Accepted dhcp 2.0pl5-19.1sarge3 (sou [ Steve Kemp ]
Accepted openssl096 0.9.6m-1sarge5 ( [ Kurt Roeckx ]
Date: Mon, 22 Oct 2007 07:56:31 +0000
From: Steve Langasek <vorlon@debian.org>
To: debian-changes@lists.debian.org
Subject: Accepted pam 0.79-5 (source i386 all amd64)
Message-Id: <E1Ijs9H-0001oR-Vq@ries.debian.org>
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Format: 1.7
Date: Sun, 21 Oct 2007 12:22:42 -0700
Source: pam
Binary: libpam0g-dev libpam0g libpam-modules libpam-doc libpam-runtime libpam-cracklib
Architecture: source i386 all amd64
Version: 0.79-5
Distribution: proposed-updates
Urgency: low
Maintainer: Sam Hartman <hartmans@debian.org>
Changed-By: Steve Langasek <vorlon@debian.org>
Description:
libpam-doc - Documentation of PAM
libpam-runtime - Runtime support for the PAM library
libpam-cracklib - PAM module to enable cracklib support
libpam-modules - Pluggable Authentication Modules for PAM
libpam0g - Pluggable Authentication Modules library
libpam0g-dev - Development files for PAM
Closes: 336344
Changes:
pam (0.79-5) proposed-updates; urgency=low
.
- CVE-2005-2977: only uid=0 is allowed to invoke unix_chkpwd with an
arbitrary username, and then only when SELinux is active. In all other
cases root should have privileges to access /etc/shadow directly, and
non-root users are not allowed access under the default security policy.
This fixes a low-impact brute-force vector when SELinux is enabled and
running in non-enforcing mode. Closes: #336344.
Files:
fb8dd31408dc01b4de4797f325390716 970 libs optional pam_0.79-5.dsc
1fe08210ba63698b513fcd71d3add1e6 134738 libs optional pam_0.79-5.diff.gz
5a7d3fcb4270887f917933389cffaaf7 64390 admin required libpam-runtime_0.79-5_all.deb
f4c37b306e83babaa9d603714de62a35 731484 doc optional libpam-doc_0.79-5_all.deb
e87e0ef694cd80679e916a8c924839a2 79792 libs required libpam0g_0.79-5_i386.deb
d5ce492bb5fb3c4f4ee2971c29fb4609 187654 libs required libpam-modules_0.79-5_i386.deb
3d3e54ee11622ba26d5aa1c766a6f1c0 118054 libdevel optional libpam0g-dev_0.79-5_i386.deb
aa6ed2ce912040786cb41c2800ffc21f 59690 libs optional libpam-cracklib_0.79-5_i386.deb
31fda3f61a23e0c413eca34eeac94e71 82152 libs required libpam0g_0.79-5_amd64.deb
b452ab01144449d85add0e726f5a0cc4 199470 libs required libpam-modules_0.79-5_amd64.deb
13125032cccc9323cf0f6084090e6b1e 119440 libdevel optional libpam0g-dev_0.79-5_amd64.deb
611e606a93eeed64c396eb63b8748269 59812 libs optional libpam-cracklib_0.79-5_amd64.deb
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)
iD8DBQFHG6swKN6ufymYLloRArX/AKCB5MWUBFW1v0pPWPF+wlTqQGqW5ACeP1aJ
+J2aEnMvkXrw5DyWQfPYoZw=
=5T5o
-----END PGP SIGNATURE-----
Accepted:
libpam-cracklib_0.79-5_amd64.deb
to pool/main/p/pam/libpam-cracklib_0.79-5_amd64.deb
libpam-cracklib_0.79-5_i386.deb
to pool/main/p/pam/libpam-cracklib_0.79-5_i386.deb
libpam-doc_0.79-5_all.deb
to pool/main/p/pam/libpam-doc_0.79-5_all.deb
libpam-modules_0.79-5_amd64.deb
to pool/main/p/pam/libpam-modules_0.79-5_amd64.deb
libpam-modules_0.79-5_i386.deb
to pool/main/p/pam/libpam-modules_0.79-5_i386.deb
libpam-runtime_0.79-5_all.deb
to pool/main/p/pam/libpam-runtime_0.79-5_all.deb
libpam0g-dev_0.79-5_amd64.deb
to pool/main/p/pam/libpam0g-dev_0.79-5_amd64.deb
libpam0g-dev_0.79-5_i386.deb
to pool/main/p/pam/libpam0g-dev_0.79-5_i386.deb
libpam0g_0.79-5_amd64.deb
to pool/main/p/pam/libpam0g_0.79-5_amd64.deb
libpam0g_0.79-5_i386.deb
to pool/main/p/pam/libpam0g_0.79-5_i386.deb
pam_0.79-5.diff.gz
to pool/main/p/pam/pam_0.79-5.diff.gz
pam_0.79-5.dsc
to pool/main/p/pam/pam_0.79-5.dsc
Date: Mon, 22 Oct 2007 07:56:40 +0000
From: Alexander Sack <asac@debian.org>
To: debian-changes@lists.debian.org
Subject: Accepted icedove 1.5.0.13+1.5.0.14b.dfsg1-0etch1 (source all amd64)
Message-Id: <E1Ijs9Q-0001oY-IV@ries.debian.org>
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Format: 1.7
Date: Thu, 18 Oct 2007 09:27:15 +0000
Source: icedove
Binary: icedove-inspector icedove-dev thunderbird-dbg thunderbird-inspector icedove-typeaheadfind mozilla-thunderbird-typeaheadfind icedove-dbg thunderbird-gnome-support thunderbird-typeaheadfind icedove mozilla-thunderbird-inspector icedove-gnome-support thunderbird mozilla-thunderbird-dev thunderbird-dev mozilla-thunderbird
Architecture: source amd64 all
Version: 1.5.0.13+1.5.0.14b.dfsg1-0etch1
Distribution: stable-security
Urgency: low
Maintainer: Alexander Sack <asac@debian.org>
Changed-By: Alexander Sack <asac@debian.org>
Description:
icedove - free/unbranded thunderbird mail client
icedove-dbg - debugging symbols for icedove/thunderbird
icedove-dev - development files for icedove/thunderbird
icedove-gnome-support - GNOME support package for icedove/thunderbird
icedove-inspector - DOM inspector extension for icedove/thunderbird
icedove-typeaheadfind - typeaheadfind extension for icedove/thunderbird
mozilla-thunderbird - Transition package for icedove rename
mozilla-thunderbird-dev - Transition package for icedove-dev rename
mozilla-thunderbird-inspector - Transition package for icedove-inspector rename
mozilla-thunderbird-typeaheadfind - Transition package for icedove-typeaheadfind rename
thunderbird - Transition package for icedove rename
thunderbird-dbg - Transition package for icedove-dbg rename
thunderbird-dev - Transition package for icedove-dev rename
thunderbird-gnome-support - Transition package for icedove-gnome-support rename
thunderbird-inspector - Transition package for icedove-inspector rename
thunderbird-typeaheadfind - Transition package for icedove-typeaheadfind rename
Changes:
icedove (1.5.0.13+1.5.0.14b.dfsg1-0etch1) stable-security; urgency=low
.
[ Alexander Sack ]
- security/stability update 1.5.0.13 + 1.5.0.14 (prepatch):
- tarball used to produce this tarball:
http://people.debian.org/~asac/mozilla-security/patches-ALL-1.8.0.14b.tar.gz
Fixed in 1.5.0.13:
- CVE-2007-3734, CVE-2007-3735 - MFSA 2007-18: Crashes with evidence of
memory corruption (rv:1.8.0.13/1.8.1.5)
- CVE-2007-3670 - MFSA 2007-23: Remote code execution by launching Firefox
from Internet Explorer.
- CVE-2007-3844 - MFSA 2007-26: Privilege escalation through chrome-loaded
about:blank windows.
- CVE-2007-3845 - MFSA 2007-27: Unescaped URIs passed to external
programs.
Fixed in 1.5.0.14b:
- advisories not yet public/final - will be documented on next upload:
CVE-2007-5339 (bulk memory corruption I), CVE-2007-5340 (bulk javascript
memory corruption), CVE-2007-5338 (XPCNativeWrapper code execution).
CVE-2007-5336 (mutation notify on text change), CVE-2007-5337 (sftp
protocol), CVE-2007-2292 (browser digest request splitting), CVE-2007-4841
(windows only).
Files:
5037f765746ad92c73e0e95ab4988272 1934 mail optional icedove_1.5.0.13+1.5.0.14b.dfsg1-0etch1.dsc
9cc1dca6142d6b1044e78026b53968c1 34229032 mail optional icedove_1.5.0.13+1.5.0.14b.dfsg1.orig.tar.gz
43c96d5fcdf34ebb5c069dc4378a965b 639834 mail optional icedove_1.5.0.13+1.5.0.14b.dfsg1-0etch1.diff.gz
dfc903a949bba53bd63f40fdc184e8e3 12169764 mail optional icedove_1.5.0.13+1.5.0.14b.dfsg1-0etch1_amd64.deb
24993c2fe872d47802ffb85aa216c3c1 195718 mail optional icedove-inspector_1.5.0.13+1.5.0.14b.dfsg1-0etch1_amd64.deb
4da21cca0d9fcb2194c0c87af58a0a47 52070 mail optional icedove-gnome-support_1.5.0.13+1.5.0.14b.dfsg1-0etch1_amd64.deb
2195e5213a818c01569199922f943178 28684 mail optional thunderbird-gnome-support_1.5.0.13+1.5.0.14b.dfsg1-0etch1_all.deb
daeca534072d6b581b8dda7157944925 61152 mail optional icedove-typeaheadfind_1.5.0.13+1.5.0.14b.dfsg1-0etch1_amd64.deb
e76acc39db8446c406acca7887be7f43 3676870 mail optional icedove-dev_1.5.0.13+1.5.0.14b.dfsg1-0etch1_amd64.deb
acef2a67aed70c9600d94b57863b77b7 51475050 mail optional icedove-dbg_1.5.0.13+1.5.0.14b.dfsg1-0etch1_amd64.deb
d0a07a5a35dda48ed3a521596ec3b620 28668 mail optional thunderbird-dbg_1.5.0.13+1.5.0.14b.dfsg1-0etch1_all.deb
2090a750ed666d208905b82d684668d3 28654 mail optional thunderbird_1.5.0.13+1.5.0.14b.dfsg1-0etch1_all.deb
7d12e5160a91e489bc481c5a05024776 28670 mail optional mozilla-thunderbird_1.5.0.13+1.5.0.14b.dfsg1-0etch1_all.deb
53bb2afe9384039094219bb14da3727a 28694 mail optional mozilla-thunderbird-inspector_1.5.0.13+1.5.0.14b.dfsg1-0etch1_all.deb
eadcb03b9cf28fdad9e0555e83c697a6 28678 mail optional thunderbird-inspector_1.5.0.13+1.5.0.14b.dfsg1-0etch1_all.deb
6df3bdfb10692d1057b64c49c8f93a5a 28698 mail optional mozilla-thunderbird-typeaheadfind_1.5.0.13+1.5.0.14b.dfsg1-0etch1_all.deb
b0c1366f5a530674ec66b578db206bde 28696 mail optional thunderbird-typeaheadfind_1.5.0.13+1.5.0.14b.dfsg1-0etch1_all.deb
96dc6c4e9629612f7f7fa5ba8276bb4e 28674 mail optional thunderbird-dev_1.5.0.13+1.5.0.14b.dfsg1-0etch1_all.deb
b7f1a7e3ea1149a9767539be1c19acbb 28682 mail optional mozilla-thunderbird-dev_1.5.0.13+1.5.0.14b.dfsg1-0etch1_all.deb
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)
iQIVAwUBRxc7dqBE/gcUDGZkAQL0zg/5ATXUto2rETExVLG57TwGXsiRzzucSxqI
mN2/Qn1036etmL0w4JV/kltdnLQaqAn5kpTA9WGBxm3FRfIu4V2vW3Y7j0IKlfgp
uPB/RLrC3P7GR2GMC+X9efjYiKgRy0UWykbQ6UK9CB+S4Bc8miytHCARBKkPtpE2
dJ8IPF4QNGFCk1J8xJMyDQSG5TQFQrA1MoIBWncx2IVR7MtT6zf5wbF787aZdNp0
8eCh3WKCa3c/fZJMZCN2f5AkqN204TjH+kGhiSx0HRbFalrwjbRfRyGP1h+upxyg
capnp89O0YVg1W1eHZQlG8pUKwSCL1PBGdDN9KWMZNGyra1Vv88qTW7heOR5LpS/
uhWXM9IH8O/X+kEhz6Dj8TaVc2A/YMv//cyNm4jdWNOWWAmN79vjC8Jv4jf6ogrz
5Y7feni/bVfLulPUKEFK7hZRsJb2WsygxGa1d8PnYQlRU/kSTY/rG1ID5pZWA2bJ
HUYuj+Zu1j16DvSlQw79yAZHppqpICQjQ+21qH/8MP4f3DVT6SJ4XAVwo9rhfWOL
y2sq5uSbtoOT9W2/bzcMZSUuSPD3gXLTQg520v95MxQrVjs39TW8ffhmhM5f8sr1
zjeTmKU1WhRdzCwnpfNU1CfelAHRWDro9USzvDk4sktFOUrPLlx64Bf6hzMWdXC8
ws7IyNtR3fE=
=choG
-----END PGP SIGNATURE-----
Accepted:
icedove-dbg_1.5.0.13+1.5.0.14b.dfsg1-0etch1_amd64.deb
to pool/main/i/icedove/icedove-dbg_1.5.0.13+1.5.0.14b.dfsg1-0etch1_amd64.deb
icedove-dev_1.5.0.13+1.5.0.14b.dfsg1-0etch1_amd64.deb
to pool/main/i/icedove/icedove-dev_1.5.0.13+1.5.0.14b.dfsg1-0etch1_amd64.deb
icedove-gnome-support_1.5.0.13+1.5.0.14b.dfsg1-0etch1_amd64.deb
to pool/main/i/icedove/icedove-gnome-support_1.5.0.13+1.5.0.14b.dfsg1-0etch1_amd64.deb
icedove-inspector_1.5.0.13+1.5.0.14b.dfsg1-0etch1_amd64.deb
to pool/main/i/icedove/icedove-inspector_1.5.0.13+1.5.0.14b.dfsg1-0etch1_amd64.deb
icedove-typeaheadfind_1.5.0.13+1.5.0.14b.dfsg1-0etch1_amd64.deb
to pool/main/i/icedove/icedove-typeaheadfind_1.5.0.13+1.5.0.14b.dfsg1-0etch1_amd64.deb
icedove_1.5.0.13+1.5.0.14b.dfsg1-0etch1.diff.gz
to pool/main/i/icedove/icedove_1.5.0.13+1.5.0.14b.dfsg1-0etch1.diff.gz
icedove_1.5.0.13+1.5.0.14b.dfsg1-0etch1.dsc
to pool/main/i/icedove/icedove_1.5.0.13+1.5.0.14b.dfsg1-0etch1.dsc
icedove_1.5.0.13+1.5.0.14b.dfsg1-0etch1_amd64.deb
to pool/main/i/icedove/icedove_1.5.0.13+1.5.0.14b.dfsg1-0etch1_amd64.deb
icedove_1.5.0.13+1.5.0.14b.dfsg1.orig.tar.gz
to pool/main/i/icedove/icedove_1.5.0.13+1.5.0.14b.dfsg1.orig.tar.gz
mozilla-thunderbird-dev_1.5.0.13+1.5.0.14b.dfsg1-0etch1_all.deb
to pool/main/i/icedove/mozilla-thunderbird-dev_1.5.0.13+1.5.0.14b.dfsg1-0etch1_all.deb
mozilla-thunderbird-inspector_1.5.0.13+1.5.0.14b.dfsg1-0etch1_all.deb
to pool/main/i/icedove/mozilla-thunderbird-inspector_1.5.0.13+1.5.0.14b.dfsg1-0etch1_all.deb
mozilla-thunderbird-typeaheadfind_1.5.0.13+1.5.0.14b.dfsg1-0etch1_all.deb
to pool/main/i/icedove/mozilla-thunderbird-typeaheadfind_1.5.0.13+1.5.0.14b.dfsg1-0etch1_all.deb
mozilla-thunderbird_1.5.0.13+1.5.0.14b.dfsg1-0etch1_all.deb
to pool/main/i/icedove/mozilla-thunderbird_1.5.0.13+1.5.0.14b.dfsg1-0etch1_all.deb
thunderbird-dbg_1.5.0.13+1.5.0.14b.dfsg1-0etch1_all.deb
to pool/main/i/icedove/thunderbird-dbg_1.5.0.13+1.5.0.14b.dfsg1-0etch1_all.deb
thunderbird-dev_1.5.0.13+1.5.0.14b.dfsg1-0etch1_all.deb
to pool/main/i/icedove/thunderbird-dev_1.5.0.13+1.5.0.14b.dfsg1-0etch1_all.deb
thunderbird-gnome-support_1.5.0.13+1.5.0.14b.dfsg1-0etch1_all.deb
to pool/main/i/icedove/thunderbird-gnome-support_1.5.0.13+1.5.0.14b.dfsg1-0etch1_all.deb
thunderbird-inspector_1.5.0.13+1.5.0.14b.dfsg1-0etch1_all.deb
to pool/main/i/icedove/thunderbird-inspector_1.5.0.13+1.5.0.14b.dfsg1-0etch1_all.deb
thunderbird-typeaheadfind_1.5.0.13+1.5.0.14b.dfsg1-0etch1_all.deb
to pool/main/i/icedove/thunderbird-typeaheadfind_1.5.0.13+1.5.0.14b.dfsg1-0etch1_all.deb
thunderbird_1.5.0.13+1.5.0.14b.dfsg1-0etch1_all.deb
to pool/main/i/icedove/thunderbird_1.5.0.13+1.5.0.14b.dfsg1-0etch1_all.deb
Date: Mon, 22 Oct 2007 19:56:18 +0000
From: Noah Meyerhans <noahm@debian.org>
To: debian-changes@lists.debian.org
Subject: Accepted t1lib 5.0.2-3sarge1 (source all i386)
Message-Id: <E1Ik3Nq-00077M-EC@ries.debian.org>
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Format: 1.7
Date: Sat, 13 Oct 2007 17:43:21 -0400
Source: t1lib
Binary: t1lib-bin libt1-5 libt1-doc libt1-dev
Architecture: source all i386
Version: 5.0.2-3sarge1
Distribution: oldstable-security
Urgency: high
Maintainer: noahm@debian.org
Changed-By: Noah Meyerhans <noahm@debian.org>
Description:
libt1-5 - Type 1 font rasterizer library - runtime
libt1-dev - Type 1 font rasterizer library - development
libt1-doc - Type 1 font rasterizer library - developers documentation
t1lib-bin - Type 1 font rasterizer library - user binaries
Closes: 439927
Changes:
t1lib (5.0.2-3sarge1) oldstable-security; urgency=high
.
- Non-maintainer upload by the security team
- Apply patch from Artur R. Czechowski to fix CVE-2007-4033.
(Closes: #439927)
Files:
d82a7a9aaeca3868a1c01f3588a59137 717 libs optional t1lib_5.0.2-3sarge1.dsc
cc5d4130b25bb8a1c930488b78930e9b 1697086 libs optional t1lib_5.0.2.orig.tar.gz
73b04c0083681da97813ced3783dbd02 315328 libs optional t1lib_5.0.2-3sarge1.diff.gz
9f58a16450cc7c2ccd7477cc04c30fac 607008 doc optional libt1-doc_5.0.2-3sarge1_all.deb
e65ca2e30180f0ed3d9eadc6cc62216d 144334 libs optional libt1-5_5.0.2-3sarge1_i386.deb
ad6838104a95c3a9f6933cdb072abaee 171504 libdevel optional libt1-dev_5.0.2-3sarge1_i386.deb
68660615bdbb04de7c79c56efcfe4e96 53630 misc optional t1lib-bin_5.0.2-3sarge1_i386.deb
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)
iD8DBQFHET0VYrVLjBFATsMRAsjMAJ9OgdyYZHyEll9Ymw2lQIL2psSDTQCfTF9e
AnThZYryTGfS3n3Gom2agSA=
=8OBx
-----END PGP SIGNATURE-----
Accepted:
libt1-5_5.0.2-3sarge1_i386.deb
to pool/main/t/t1lib/libt1-5_5.0.2-3sarge1_i386.deb
libt1-dev_5.0.2-3sarge1_i386.deb
to pool/main/t/t1lib/libt1-dev_5.0.2-3sarge1_i386.deb
libt1-doc_5.0.2-3sarge1_all.deb
to pool/main/t/t1lib/libt1-doc_5.0.2-3sarge1_all.deb
t1lib-bin_5.0.2-3sarge1_i386.deb
to pool/main/t/t1lib/t1lib-bin_5.0.2-3sarge1_i386.deb
t1lib_5.0.2-3sarge1.diff.gz
to pool/main/t/t1lib/t1lib_5.0.2-3sarge1.diff.gz
t1lib_5.0.2-3sarge1.dsc
to pool/main/t/t1lib/t1lib_5.0.2-3sarge1.dsc
Date: Mon, 22 Oct 2007 19:56:21 +0000
From: Steve Kemp <skx@debian.org>
To: debian-changes@lists.debian.org
Subject: Accepted dhcp 2.0pl5-19.1sarge3 (source i386)
Message-Id: <E1Ik3Nt-00077p-OX@ries.debian.org>
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Format: 1.7
Date: Mon, 15 Oct 2007 21:29:21 +0000
Source: dhcp
Binary: dhcp dhcp-client dhcp-client-udeb dhcp-relay
Architecture: source i386
Version: 2.0pl5-19.1sarge3
Distribution: oldstable-security
Urgency: high
Maintainer: Eloy A. Paris <peloy@debian.org>
Changed-By: Steve Kemp <skx@debian.org>
Description:
dhcp - DHCP server for automatic IP address assignment
dhcp-client - DHCP Client
dhcp-client-udeb - DHCP Client for debian-installer (udeb)
dhcp-relay - DHCP Relay
Changes:
dhcp (2.0pl5-19.1sarge3) oldstable-security; urgency=high
.
- Non-maintainer upload by the Security Team.
- Fix stack-based buffer overflow in options.c, which allows arbitrary
code execution or remote denial of service.
Fixes: CVE-2007-5365
Files:
b1e856949f5e8ce1c885b6451cebb236 687 net optional dhcp_2.0pl5-19.1sarge3.dsc
9a8f4a8219d0df0ea8d00a766afb1cb3 86946 net optional dhcp_2.0pl5-19.1sarge3.diff.gz
fc742b760b3130fc35fbdca1b543e9ab 108930 net optional dhcp_2.0pl5-19.1sarge3_i386.deb
c536a455a338b39df9e422f8014aee5c 102632 net optional dhcp-client_2.0pl5-19.1sarge3_i386.deb
e83e575491184c6e43311cbb9a3b7c76 71246 net optional dhcp-relay_2.0pl5-19.1sarge3_i386.deb
0521d5a40275999472be2c6adea13dcd 40786 debian-installer optional dhcp-client-udeb_2.0pl5-19.1sarge3_i386.udeb
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)
iD8DBQFHGQAohuANDBmkLRkRAnXUAJ9Z5pNvW50EzpMsPujRzJWQuaZ+qACdGPOh
LnVUBCnaZDc9HAEUkrGU8Bg=
=Q6wU
-----END PGP SIGNATURE-----
Accepted:
dhcp-client-udeb_2.0pl5-19.1sarge3_i386.udeb
to pool/main/d/dhcp/dhcp-client-udeb_2.0pl5-19.1sarge3_i386.udeb
dhcp-client_2.0pl5-19.1sarge3_i386.deb
to pool/main/d/dhcp/dhcp-client_2.0pl5-19.1sarge3_i386.deb
dhcp-relay_2.0pl5-19.1sarge3_i386.deb
to pool/main/d/dhcp/dhcp-relay_2.0pl5-19.1sarge3_i386.deb
dhcp_2.0pl5-19.1sarge3.diff.gz
to pool/main/d/dhcp/dhcp_2.0pl5-19.1sarge3.diff.gz
dhcp_2.0pl5-19.1sarge3.dsc
to pool/main/d/dhcp/dhcp_2.0pl5-19.1sarge3.dsc
dhcp_2.0pl5-19.1sarge3_i386.deb
to pool/main/d/dhcp/dhcp_2.0pl5-19.1sarge3_i386.deb
Date: Mon, 22 Oct 2007 19:56:24 +0000
From: Kurt Roeckx <kurt@roeckx.be>
To: debian-changes@lists.debian.org
Subject: Accepted openssl096 0.9.6m-1sarge5 (source i386)
Message-Id: <E1Ik3Nw-00078F-Mm@ries.debian.org>
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Format: 1.7
Date: Sat, 29 Sep 2007 10:22:20 +0000
Source: openssl096
Binary: libssl0.9.6
Architecture: source i386
Version: 0.9.6m-1sarge5
Distribution: oldstable-security
Urgency: low
Maintainer: noahm@debian.org
Changed-By: Kurt Roeckx <kurt@roeckx.be>
Description:
libssl0.9.6 - SSL shared libraries (old version)
Changes:
openssl096 (0.9.6m-1sarge5) oldstable-security; urgency=low
.
- CVE-2007-5135: Fix off by one error in SSL_get_shared_ciphers().
- Call dh_fixperms before dh_strip so that stripping actually works.
Files:
d5c107efd03887064c12ca3f3785eb22 617 utils optional openssl096_0.9.6m-1sarge5.dsc
3a9b336e6f7e1ecdb12b925928bf9061 21639 utils optional openssl096_0.9.6m-1sarge5.diff.gz
afcd7f2f3b9ceb67eda7a1b6008af9d1 1758424 oldlibs standard libssl0.9.6_0.9.6m-1sarge5_i386.deb
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)
iD8DBQFG/lkyYrVLjBFATsMRAjXWAJ9G6uRQwD1WkmWa8WYoUz2PGDcgaQCeKzo9
UvH4fxqWsicEnaymj95D9Qw=
=OolR
-----END PGP SIGNATURE-----
Accepted:
libssl0.9.6_0.9.6m-1sarge5_i386.deb
to pool/main/o/openssl096/libssl0.9.6_0.9.6m-1sarge5_i386.deb
openssl096_0.9.6m-1sarge5.diff.gz
to pool/main/o/openssl096/openssl096_0.9.6m-1sarge5.diff.gz
openssl096_0.9.6m-1sarge5.dsc
to pool/main/o/openssl096/openssl096_0.9.6m-1sarge5.dsc
End of debian-changes-digest Digest V2007 Issue #126
Received on Tue Oct 23 03:58:49 2007