Branches for Raring

Name Status Last Modified Last Commit
lp:~qtjambi-community/ubuntu/raring/qtjambi-snapshot/debian Development 2015-06-02 17:16:44 UTC
266. maint/bzr_push.sh Auto copy, commit a...

Author: Darryl L. Miles
Revision Date: 2015-06-02 17:16:44 UTC

maint/bzr_push.sh Auto copy, commit and push for: control.snapshot (snapshot)

lp:~ubuntu-multiseat/ubuntu/raring/xorg-server/bug1209008 bug Development 2014-12-01 20:05:21 UTC
271. convert to 3.0 (quilt) format

Author: Richard Hansen
Revision Date: 2013-08-08 05:40:17 UTC

convert to 3.0 (quilt) format

lp:ubuntu/raring-proposed/initramfs-tools bug Mature 2014-05-13 09:12:07 UTC
275. src/wait-for-root.c: udev_monitor_rec...

Author: Chris J Arges
Revision Date: 2013-09-05 16:20:14 UTC

src/wait-for-root.c: udev_monitor_receive_device() might still
return NULL even with a blocking socket if recvmsg() fails with
ENOBUFS. Retry every second in that case. Thanks to Tetsuo Handa for
debugging this and the patch! (LP: #1215911)

lp:ubuntu/raring-proposed/autopilot Development 2014-05-06 08:30:17 UTC
71. Automatic snapshot from revision 158

Author: PS Jenkins bot
Revision Date: 2013-04-09 00:02:08 UTC

Automatic snapshot from revision 158

lp:ubuntu/raring-proposed/gnu-efi bug Mature 2014-05-05 23:50:36 UTC
20. Backport gnu-efi from saucy to raring...

Author: Steve Langasek
Revision Date: 2013-09-24 14:21:08 UTC

Backport gnu-efi from saucy to raring to support new versions of
shim. LP: #1229572.

lp:ubuntu/raring-updates/kickseed Mature 2014-01-24 10:01:32 UTC
14. Preseed netcfg/disable_autoconfig rat...

Author: Colin Watson
Revision Date: 2013-11-08 12:45:44 UTC

Preseed netcfg/disable_autoconfig rather than deprecated
netcfg/disable_dhcp (LP: #879605).

lp:ubuntu/raring-updates/network-manager-applet Mature 2014-01-23 22:20:03 UTC
107. debian/patches/lp330608_dxteam_gsm_co...

Author: Mathieu Trudel-Lapierre
Revision Date: 2013-12-02 08:56:17 UTC

debian/patches/lp330608_dxteam_gsm_connect_text.patch: refresh patch:
remove some additional g_free() calls that were being made on a const
string for a NM internal pointer containing the connection ID, which should
not be freed. Thanks to Jean-Pierre Rupp for the fix. (LP: #1185330)

lp:ubuntu/raring-updates/devscripts Mature 2014-01-21 14:41:49 UTC
135. * SECURITY UPDATE: arbitrary code exe...

Author: Marc Deslauriers
Revision Date: 2014-01-10 12:46:09 UTC

* SECURITY UPDATE: arbitrary code execution in uscan via crafted tarball
  - scripts/uscan.pl: improve tarball handling.
  - 02c6850d973e3e1246fde72edab27f03d63acc52
  - 4b7e58ee6000cdefac0682601cec6ecce0137467
  - CVE-2013-6888

lp:ubuntu/raring-security/devscripts Mature 2014-01-21 14:20:09 UTC
135. * SECURITY UPDATE: arbitrary code exe...

Author: Marc Deslauriers
Revision Date: 2014-01-10 12:46:09 UTC

* SECURITY UPDATE: arbitrary code execution in uscan via crafted tarball
  - scripts/uscan.pl: improve tarball handling.
  - 02c6850d973e3e1246fde72edab27f03d63acc52
  - 4b7e58ee6000cdefac0682601cec6ecce0137467
  - CVE-2013-6888

lp:ubuntu/raring-updates/libotr2 Mature 2014-01-16 21:33:43 UTC
3. * SECURITY UPDATE: disable insecure O...

Author: Felix Geyer
Revision Date: 2014-01-04 16:18:48 UTC

* SECURITY UPDATE: disable insecure OTRv1 protocol to prevent downgrade
  attacks (LP: #1266016)
  - Add disable_otr_v1.patch, patch taken from Debian

lp:ubuntu/raring-security/libotr2 bug Mature 2014-01-16 21:23:32 UTC
3. * SECURITY UPDATE: disable insecure O...

Author: Felix Geyer
Revision Date: 2014-01-04 16:18:48 UTC

* SECURITY UPDATE: disable insecure OTRv1 protocol to prevent downgrade
  attacks (LP: #1266016)
  - Add disable_otr_v1.patch, patch taken from Debian

lp:ubuntu/raring-updates/graphviz Mature 2014-01-16 14:10:28 UTC
51. * SECURITY UPDATE: buffer overflow in...

Author: Marc Deslauriers
Revision Date: 2014-01-14 13:34:59 UTC

* SECURITY UPDATE: buffer overflow in yyerror()
  - debian/patches/CVE-2014-0978.patch: don't overflow buf in
    lib/cgraph/scan.l.
  - CVE-2014-0978
* SECURITY UPDATE: buffer overflow in yyerror() security fix
  - debian/patches/CVE-2014-1235.patch: once again, don't overflow buf
    in lib/cgraph/scan.l.
  - CVE-2014-1235
* SECURITY UPDATE: buffer overflow in chkNum of scanner
  - debian/patches/CVE-2014-1236.patch: don't overflow buf in
    lib/cgraph/scan.l.
  - CVE-2014-1236

lp:ubuntu/raring-security/graphviz Mature 2014-01-16 13:51:17 UTC
51. * SECURITY UPDATE: buffer overflow in...

Author: Marc Deslauriers
Revision Date: 2014-01-14 13:34:59 UTC

* SECURITY UPDATE: buffer overflow in yyerror()
  - debian/patches/CVE-2014-0978.patch: don't overflow buf in
    lib/cgraph/scan.l.
  - CVE-2014-0978
* SECURITY UPDATE: buffer overflow in yyerror() security fix
  - debian/patches/CVE-2014-1235.patch: once again, don't overflow buf
    in lib/cgraph/scan.l.
  - CVE-2014-1235
* SECURITY UPDATE: buffer overflow in chkNum of scanner
  - debian/patches/CVE-2014-1236.patch: don't overflow buf in
    lib/cgraph/scan.l.
  - CVE-2014-1236

lp:ubuntu/raring-proposed/gnome-bluetooth bug Development 2014-01-15 15:01:18 UTC
86. debian/patches/99_add_microsoft_mice....

Author: Daniel Holbach
Revision Date: 2013-08-05 11:08:21 UTC

debian/patches/99_add_microsoft_mice.patch: add Microsoft Sculpt/Wedge
mouse (LP: #1094744, LP: #1158462). Thanks, Marcos Barbosa, Anton Anikin
and Anthony Wong for the patch.

lp:ubuntu/raring-updates/mapserver Mature 2014-01-14 16:37:57 UTC
36. [ Johan Van de Wauw ] * Add patch to ...

Author: Marc Deslauriers
Revision Date: 2014-01-14 08:23:26 UTC

[ Johan Van de Wauw ]
* Add patch to fix CVE-2013-7262, an SQL injection vulnerability in the
  msPostGISLayerSetTimeFilter function in mappostgis.c. (LP: #1267616)

[ Marc Deslauriers ]
* Fix FTBFS by linking executables with -ldl.

lp:ubuntu/raring-security/mapserver bug Mature 2014-01-14 16:37:47 UTC
36. [ Johan Van de Wauw ] * Add patch to ...

Author: Marc Deslauriers
Revision Date: 2014-01-14 08:23:26 UTC

[ Johan Van de Wauw ]
* Add patch to fix CVE-2013-7262, an SQL injection vulnerability in the
  msPostGISLayerSetTimeFilter function in mappostgis.c. (LP: #1267616)

[ Marc Deslauriers ]
* Fix FTBFS by linking executables with -ldl.

lp:ubuntu/raring-updates/znc Mature 2014-01-14 16:17:25 UTC
37. * SECURITY UPDATE: null pointer deref...

Author: Thomas Ward
Revision Date: 2014-01-13 12:20:57 UTC

* SECURITY UPDATE: null pointer dereference in webadmin (LP: #1268658)
  - debian/patches/CVE-2013-2130.diff: Patch from Debian based on upstream to
    fix null pointer dereferences.
  - CVE-2013-2130

lp:ubuntu/raring-security/znc bug Mature 2014-01-14 16:17:12 UTC
37. * SECURITY UPDATE: null pointer deref...

Author: Thomas Ward
Revision Date: 2014-01-13 12:20:57 UTC

* SECURITY UPDATE: null pointer dereference in webadmin (LP: #1268658)
  - debian/patches/CVE-2013-2130.diff: Patch from Debian based on upstream to
    fix null pointer dereferences.
  - CVE-2013-2130

lp:ubuntu/raring-backports/ansible bug Mature 2014-01-10 17:43:59 UTC
5. No-change backport to raring (LP: #12...

Author: Felix Geyer
Revision Date: 2014-01-10 18:09:14 UTC

No-change backport to raring (LP: #1247541)

lp:ubuntu/raring-security/distro-info-data Mature 2014-01-10 17:10:04 UTC
12. * Update data from distro-info-data 0...

Author: Stefano Rivera
Revision Date: 2013-10-18 17:37:59 UTC

* Update data from distro-info-data 0.17
  - Add Ubuntu 14.04, Trusty Tahr LP: (Closes: #726696, LP: #1241673)

lp:ubuntu/raring-security/bind9 Mature 2014-01-10 09:42:41 UTC
59. * SECURITY UPDATE: denial of service ...

Author: Marc Deslauriers
Revision Date: 2014-01-10 09:42:41 UTC

* SECURITY UPDATE: denial of service when processing NSEC3-signed zone
  queries
  - debian/patches/CVE-2014-0591.patch: don't call memcpy with
    overlapping ranges in bin/named/query.c.
  - patch backported from 9.9.4-P2.
  - CVE-2014-0591

lp:ubuntu/raring-updates/bind9 Mature 2014-01-10 09:42:41 UTC
59. * SECURITY UPDATE: denial of service ...

Author: Marc Deslauriers
Revision Date: 2014-01-10 09:42:41 UTC

* SECURITY UPDATE: denial of service when processing NSEC3-signed zone
  queries
  - debian/patches/CVE-2014-0591.patch: don't call memcpy with
    overlapping ranges in bin/named/query.c.
  - patch backported from 9.9.4-P2.
  - CVE-2014-0591

lp:ubuntu/raring-updates/puppet bug Mature 2014-01-09 17:02:41 UTC
71. * SECURITY REGRESSION: Incorrect defa...

Author: Marc Deslauriers
Revision Date: 2014-01-09 07:54:31 UTC

* SECURITY REGRESSION: Incorrect default file mode (LP: #1267385)
  - debian/patches/CVE-2013-4969-regression.patch: fix incorrect file
    mode in lib/puppet/type/file.rb, lib/puppet/util.rb,
    spec/unit/type/file_spec.rb.
  - CVE-2013-4969

lp:ubuntu/raring-security/puppet bug Mature 2014-01-09 16:09:43 UTC
71. * SECURITY REGRESSION: Incorrect defa...

Author: Marc Deslauriers
Revision Date: 2014-01-09 07:54:31 UTC

* SECURITY REGRESSION: Incorrect default file mode (LP: #1267385)
  - debian/patches/CVE-2013-4969-regression.patch: fix incorrect file
    mode in lib/puppet/type/file.rb, lib/puppet/util.rb,
    spec/unit/type/file_spec.rb.
  - CVE-2013-4969

lp:ubuntu/raring-security/openssl bug Mature 2014-01-08 14:55:58 UTC
95. * SECURITY UPDATE: denial of service ...

Author: Marc Deslauriers
Revision Date: 2014-01-08 14:55:58 UTC

* SECURITY UPDATE: denial of service via invalid TLS handshake
  - debian/patches/CVE-2013-4353.patch: handle no new cipher setup in
    ssl/s3_both.c.
  - CVE-2013-4353
* SECURITY UPDATE: denial of service via incorrect data structure
  - debian/patches/CVE-2013-6449.patch: check for handshake digests in
    ssl/s3_both.c,ssl/s3_pkt.c,ssl/t1_enc.c, use proper version in
    ssl/s3_lib.c.
  - CVE-2013-6449
* SECURITY UPDATE: denial of service via DTLS retransmission
  - debian/patches/CVE-2013-6450.patch: fix DTLS retransmission in
    crypto/evp/digest.c,ssl/d1_both.c,ssl/s3_pkt.c,ssl/s3_srvr.c,
    ssl/ssl_locl.h,ssl/t1_enc.c.
  - CVE-2013-6450
* debian/patches/no_default_rdrand.patch: Don't use rdrand engine as
  default unless explicitly requested.

lp:ubuntu/raring-updates/openssl Mature 2014-01-08 14:55:58 UTC
95. * SECURITY UPDATE: denial of service ...

Author: Marc Deslauriers
Revision Date: 2014-01-08 14:55:58 UTC

* SECURITY UPDATE: denial of service via invalid TLS handshake
  - debian/patches/CVE-2013-4353.patch: handle no new cipher setup in
    ssl/s3_both.c.
  - CVE-2013-4353
* SECURITY UPDATE: denial of service via incorrect data structure
  - debian/patches/CVE-2013-6449.patch: check for handshake digests in
    ssl/s3_both.c,ssl/s3_pkt.c,ssl/t1_enc.c, use proper version in
    ssl/s3_lib.c.
  - CVE-2013-6449
* SECURITY UPDATE: denial of service via DTLS retransmission
  - debian/patches/CVE-2013-6450.patch: fix DTLS retransmission in
    crypto/evp/digest.c,ssl/d1_both.c,ssl/s3_pkt.c,ssl/s3_srvr.c,
    ssl/ssl_locl.h,ssl/t1_enc.c.
  - CVE-2013-6450
* debian/patches/no_default_rdrand.patch: Don't use rdrand engine as
  default unless explicitly requested.

lp:ubuntu/raring-updates/libxfont Mature 2014-01-07 19:08:49 UTC
31. * SECURITY UPDATE: denial of service ...

Author: Marc Deslauriers
Revision Date: 2013-12-30 17:35:09 UTC

* SECURITY UPDATE: denial of service and possible code execution via
  stack overflow
  - debian/patches/CVE-2013-6462.patch: limit sscanf field in
    src/bitmap/bdfread.c.
  - CVE-2013-6462

lp:ubuntu/raring-security/libxfont Mature 2014-01-07 18:50:00 UTC
31. * SECURITY UPDATE: denial of service ...

Author: Marc Deslauriers
Revision Date: 2013-12-30 17:35:09 UTC

* SECURITY UPDATE: denial of service and possible code execution via
  stack overflow
  - debian/patches/CVE-2013-6462.patch: limit sscanf field in
    src/bitmap/bdfread.c.
  - CVE-2013-6462

lp:ubuntu/raring-updates/gdm Mature 2014-01-07 17:35:02 UTC
273. * Merge changes from lightdm to fix p...

Author: Tim Lunn
Revision Date: 2013-05-23 17:45:44 UTC

* Merge changes from lightdm to fix plymouth race (LP: #982889)
  - lightdm.upstart: Add a start condition on plymouth-ready, and
    drop conditions already handled by plymouth-splash.
  - control: Depend on the new plymouth version that provides plymouth-ready.

lp:ubuntu/raring-updates/iproute Mature 2014-01-07 16:07:47 UTC
42. Fix ip netns delete failures. (LP: #1...

Author: Chris J Arges
Revision Date: 2013-10-15 14:50:33 UTC

Fix ip netns delete failures. (LP: #1238981)

lp:ubuntu/raring-updates/pixman bug Mature 2014-01-06 13:45:41 UTC
33. Copy saucy package back to raring. (L...

Author: Maarten Lankhorst
Revision Date: 2013-12-10 13:26:08 UTC

Copy saucy package back to raring. (LP: #1253041)

lp:ubuntu/raring-proposed/linux-meta-ppc bug Mature 2013-12-22 12:06:13 UTC
26. Bump ABI

Author: Ben Collins
Revision Date: 2013-12-22 12:06:13 UTC

Bump ABI

lp:ubuntu/raring-security/linux-meta-ppc Mature 2013-12-22 12:06:13 UTC
26. Bump ABI

Author: Ben Collins
Revision Date: 2013-12-22 12:06:13 UTC

Bump ABI

lp:ubuntu/raring-updates/linux-meta-ppc Mature 2013-12-22 12:06:13 UTC
26. Bump ABI

Author: Ben Collins
Revision Date: 2013-12-22 12:06:13 UTC

Bump ABI

lp:ubuntu/raring-security/nss bug Mature 2013-12-20 18:57:29 UTC
44. * SECURITY UPDATE: New upstream relea...

Author: Marc Deslauriers
Revision Date: 2013-12-20 10:39:43 UTC

* SECURITY UPDATE: New upstream release (LP: #1263135)
  - Distrusts AC DG Tresor SSL CA

lp:ubuntu/raring-updates/nss Mature 2013-12-20 10:39:43 UTC
44. * SECURITY UPDATE: New upstream relea...

Author: Marc Deslauriers
Revision Date: 2013-12-20 10:39:43 UTC

* SECURITY UPDATE: New upstream release (LP: #1263135)
  - Distrusts AC DG Tresor SSL CA

lp:ubuntu/raring-security/horizon bug Mature 2013-12-19 23:06:33 UTC
47. * SECURITY UPDATE: XSS in Volumes and...

Author: Jamie Strandboge
Revision Date: 2013-12-03 16:07:28 UTC

* SECURITY UPDATE: XSS in Volumes and Network Topology pages
  - debian/patches/CVE-2013-6406: html.escape() various items in
    volumes/tables.py and volume_snapshots/tables.py
  - CVE-2013-6406 (also referred to as CVE-2013-6858)
  - LP: #1247675

lp:ubuntu/raring-updates/libjpeg6b Mature 2013-12-19 20:07:00 UTC
19. * SECURITY UPDATE: information disclo...

Author: Marc Deslauriers
Revision Date: 2013-11-22 08:58:58 UTC

* SECURITY UPDATE: information disclosure via uninitialized memory in
  the get_sos function (LP: #1252912)
  - debian/patches/CVE-2013-6629.patch: check for duplications in
    jdmarker.c.
  - CVE-2013-6629
* SECURITY UPDATE: information disclosure via uninitialized memory in
  the get_dht function (LP: #1252912)
  - debian/patches/CVE-2013-6630.patch: properly clear out memory in
    jdmarker.c.
  - CVE-2013-6630

lp:ubuntu/raring-updates/libjpeg-turbo Mature 2013-12-19 20:04:58 UTC
10. * SECURITY UPDATE: information disclo...

Author: Marc Deslauriers
Revision Date: 2013-11-22 09:59:18 UTC

* SECURITY UPDATE: information disclosure via uninitialized memory in
  the get_sos function (LP: #1252912)
  - debian/patches/CVE-2013-6629.patch: check for duplications in
    jdmarker.c.
  - CVE-2013-6629
* SECURITY UPDATE: information disclosure via uninitialized memory in
  the get_dht function (LP: #1252912)
  - debian/patches/CVE-2013-6630.patch: properly clear out memory in
    jdmarker.c.
  - CVE-2013-6630

lp:ubuntu/raring-security/libjpeg6b bug Mature 2013-12-19 19:53:27 UTC
19. * SECURITY UPDATE: information disclo...

Author: Marc Deslauriers
Revision Date: 2013-11-22 08:58:58 UTC

* SECURITY UPDATE: information disclosure via uninitialized memory in
  the get_sos function (LP: #1252912)
  - debian/patches/CVE-2013-6629.patch: check for duplications in
    jdmarker.c.
  - CVE-2013-6629
* SECURITY UPDATE: information disclosure via uninitialized memory in
  the get_dht function (LP: #1252912)
  - debian/patches/CVE-2013-6630.patch: properly clear out memory in
    jdmarker.c.
  - CVE-2013-6630

lp:ubuntu/raring-security/libjpeg-turbo bug Mature 2013-12-19 19:39:24 UTC
10. * SECURITY UPDATE: information disclo...

Author: Marc Deslauriers
Revision Date: 2013-11-22 09:59:18 UTC

* SECURITY UPDATE: information disclosure via uninitialized memory in
  the get_sos function (LP: #1252912)
  - debian/patches/CVE-2013-6629.patch: check for duplications in
    jdmarker.c.
  - CVE-2013-6629
* SECURITY UPDATE: information disclosure via uninitialized memory in
  the get_dht function (LP: #1252912)
  - debian/patches/CVE-2013-6630.patch: properly clear out memory in
    jdmarker.c.
  - CVE-2013-6630

lp:ubuntu/raring-security/gnupg Mature 2013-12-18 11:14:22 UTC
44. * SECURITY UPDATE: RSA Key Extraction...

Author: Marc Deslauriers
Revision Date: 2013-12-18 11:14:22 UTC

* SECURITY UPDATE: RSA Key Extraction via Low-Bandwidth Acoustic
  Cryptanalysis attack
  - debian/patches/CVE-2013-4576.patch: Use blinding for the RSA secret
    operation in cipher/random.*, cipher/rsa.c, g10/gpgv.c. Normalize the
    MPIs used as input to secret key functions in cipher/dsa.c,
    cipher/elgamal.c, cipher/rsa.c.
  - CVE-2013-4576

lp:ubuntu/raring-updates/gnupg Mature 2013-12-18 11:14:22 UTC
44. * SECURITY UPDATE: RSA Key Extraction...

Author: Marc Deslauriers
Revision Date: 2013-12-18 11:14:22 UTC

* SECURITY UPDATE: RSA Key Extraction via Low-Bandwidth Acoustic
  Cryptanalysis attack
  - debian/patches/CVE-2013-4576.patch: Use blinding for the RSA secret
    operation in cipher/random.*, cipher/rsa.c, g10/gpgv.c. Normalize the
    MPIs used as input to secret key functions in cipher/dsa.c,
    cipher/elgamal.c, cipher/rsa.c.
  - CVE-2013-4576

lp:ubuntu/raring-security/curl Mature 2013-12-17 12:47:31 UTC
71. * SECURITY UPDATE: missing CN verific...

Author: Marc Deslauriers
Revision Date: 2013-12-17 12:47:31 UTC

* SECURITY UPDATE: missing CN verification when signature verification is
  disabled in GnuTLS backend.
  - debian/patches/CVE-2013-6422.patch: still verify host when
    CURLOPT_SSL_VERIFYPEER isn't set in lib/gtls.c.
  - CVE-2013-6422

lp:ubuntu/raring-updates/curl Mature 2013-12-17 12:47:31 UTC
71. * SECURITY UPDATE: missing CN verific...

Author: Marc Deslauriers
Revision Date: 2013-12-17 12:47:31 UTC

* SECURITY UPDATE: missing CN verification when signature verification is
  disabled in GnuTLS backend.
  - debian/patches/CVE-2013-6422.patch: still verify host when
    CURLOPT_SSL_VERIFYPEER isn't set in lib/gtls.c.
  - CVE-2013-6422

lp:ubuntu/raring-proposed/libdrm bug Mature 2013-12-17 12:29:14 UTC
72. * Copy package from saucy. (LP: #1253...

Author: Maarten Lankhorst
Revision Date: 2013-11-27 14:02:28 UTC

* Copy package from saucy. (LP: #1253041)
* Drop pci-id patches, upstream.

lp:ubuntu/raring-proposed/pixman bug Mature 2013-12-17 10:53:23 UTC
32. Copy saucy package back to raring. (L...

Author: Maarten Lankhorst
Revision Date: 2013-12-10 13:26:08 UTC

Copy saucy package back to raring. (LP: #1253041)

lp:ubuntu/raring-updates/usb-creator Mature 2013-12-16 15:46:54 UTC
75. [ Chris Wulff ] Initialise threads, b...

Author: Brian Murray
Revision Date: 2013-12-16 15:46:54 UTC

[ Chris Wulff ]
Initialise threads, before starting background task thread. (LP:
#915626)

lp:ubuntu/raring-proposed/usb-creator bug Development 2013-12-16 15:46:54 UTC
75. [ Chris Wulff ] Initialise threads, b...

Author: Brian Murray
Revision Date: 2013-12-16 15:46:54 UTC

[ Chris Wulff ]
Initialise threads, before starting background task thread. (LP:
#915626)

lp:ubuntu/raring-proposed/armel-cross-toolchain-base Mature 2013-12-14 00:51:30 UTC
210. * Merge packaging from armhf-cross-to...

Author: Colin Watson
Revision Date: 2013-02-08 20:39:31 UTC

* Merge packaging from armhf-cross-toolchain-base 1.101:
  - Bump eglibc to 2.17.

lp:ubuntu/raring-updates/eglibc Mature 2013-12-13 13:43:44 UTC
327. * SECURITY UPDATE: denial of service ...

Author: Marc Deslauriers
Revision Date: 2013-09-27 09:07:13 UTC

* SECURITY UPDATE: denial of service and possible code execution via
  strcoll overflows
  - debian/patches/any/CVE-2012-44xx.diff: fix overflows in
    string/strcoll_l.c, add test to string/tst-strcoll-overflow.c,
    string/Makefile.
  - CVE-2012-4412
  - CVE-2012-4424
* SECURITY UPDATE: denial of service in regular expression matcher
  - debian/patches/any/CVE-2013-0242.diff: fix buffer overrun in
    posix/regexec.c, add test to posix/bug-regex34.c, posix/Makefile.
  - CVE-2013-0242
* SECURITY UPDATE: denial of service in getaddrinfo
  - debian/patches/any/CVE-2013-1914.diff: fix overflow in
    sysdeps/posix/getaddrinfo.c.
  - CVE-2013-1914
* SECURITY UPDATE: denial of service and possible code execution via
  readdir_r
  - debian/patches/any/CVE-2013-4237.diff: enforce NAME_MAX limit in
    sysdeps/posix/readdir_r.c, add errcode to sysdeps/posix/dirstream.h,
    sysdeps/posix/opendir.c, sysdeps/posix/rewinddir.c, remove
    GETDENTS_64BIT_ALIGNED from
    sysdeps/unix/sysv/linux/i386/readdir64_r.c,
    sysdeps/unix/sysv/linux/wordsize-64/readdir_r.c.
  - CVE-2013-4237
* SECURITY UPDATE: denial of service and possible code execution via
  overflows in memory allocator
  - debian/patches/any/CVE-2013-4332.diff: check for overflows in
    malloc/malloc.c.
  - CVE-2013-4332

lp:ubuntu/raring-security/eglibc Mature 2013-12-13 13:43:40 UTC
327. * SECURITY UPDATE: denial of service ...

Author: Marc Deslauriers
Revision Date: 2013-09-27 09:07:13 UTC

* SECURITY UPDATE: denial of service and possible code execution via
  strcoll overflows
  - debian/patches/any/CVE-2012-44xx.diff: fix overflows in
    string/strcoll_l.c, add test to string/tst-strcoll-overflow.c,
    string/Makefile.
  - CVE-2012-4412
  - CVE-2012-4424
* SECURITY UPDATE: denial of service in regular expression matcher
  - debian/patches/any/CVE-2013-0242.diff: fix buffer overrun in
    posix/regexec.c, add test to posix/bug-regex34.c, posix/Makefile.
  - CVE-2013-0242
* SECURITY UPDATE: denial of service in getaddrinfo
  - debian/patches/any/CVE-2013-1914.diff: fix overflow in
    sysdeps/posix/getaddrinfo.c.
  - CVE-2013-1914
* SECURITY UPDATE: denial of service and possible code execution via
  readdir_r
  - debian/patches/any/CVE-2013-4237.diff: enforce NAME_MAX limit in
    sysdeps/posix/readdir_r.c, add errcode to sysdeps/posix/dirstream.h,
    sysdeps/posix/opendir.c, sysdeps/posix/rewinddir.c, remove
    GETDENTS_64BIT_ALIGNED from
    sysdeps/unix/sysv/linux/i386/readdir64_r.c,
    sysdeps/unix/sysv/linux/wordsize-64/readdir_r.c.
  - CVE-2013-4237
* SECURITY UPDATE: denial of service and possible code execution via
  overflows in memory allocator
  - debian/patches/any/CVE-2013-4332.diff: check for overflows in
    malloc/malloc.c.
  - CVE-2013-4332

lp:ubuntu/raring-proposed/anacron Mature 2013-12-13 11:24:30 UTC
28. Respect DEB_HOST_GNU_TYPE when select...

Author: Dimitri John Ledkov
Revision Date: 2012-12-20 11:28:01 UTC

Respect DEB_HOST_GNU_TYPE when selecting CC for cross-compiling.

lp:ubuntu/raring-proposed/synaptiks bug Mature 2013-12-12 21:29:26 UTC
16. Add kubuntu_fix_udev_property_access....

Author: Harald Sitter
Revision Date: 2013-12-10 15:28:24 UTC

Add kubuntu_fix_udev_property_access.patch to fix a crash when accessing
the NAME property of mice (LP: #737856)

lp:ubuntu/raring-proposed/acl2 Mature 2013-12-11 19:27:32 UTC
26. HOME="/tmp" environment for make DOC

Author: Camm Maguire
Revision Date: 2013-01-13 17:54:15 UTC

HOME="/tmp" environment for make DOC

lp:ubuntu/raring-proposed/openssl Mature 2013-12-11 06:24:52 UTC
94. * SECURITY UPDATE: Disable compressio...

Author: Seth Arnold
Revision Date: 2013-06-03 18:13:47 UTC

* SECURITY UPDATE: Disable compression to avoid CRIME systemwide
  (LP: #1187195)
  - CVE-2012-4929
  - debian/patches/openssl-1.0.1e-env-zlib.patch: disable default use of
    zlib to compress SSL/TLS unless the environment variable
    OPENSSL_DEFAULT_ZLIB is set in the environment during library
    initialization.
  - Introduced to assist with programs not yet updated to provide their own
    controls on compression, such as Postfix
  - http://pkgs.fedoraproject.org/cgit/openssl.git/plain/openssl-1.0.1e-env-zlib.patch

lp:ubuntu/raring-proposed/dnsmasq Mature 2013-12-11 03:47:36 UTC
31. * Fix local resolving when used with ...

Author: Marc Deslauriers
Revision Date: 2013-02-15 15:27:58 UTC

* Fix local resolving when used with libvirt and bind-dynamic (LP: #1126488)
  - debian/patches/fix_tcp_queries.patch: Correct behaviour for TCP
    queries to allowed address via banned interface in src/dnsmasq.*,
    src/network.c.
  - debian/patches/fix_wrong_interface.patch: Handle wrong interface for
    locally-routed packets in src/dnsmasq.*, src/forward.c, src/network.c,
    src/tftp.

lp:ubuntu/raring-proposed/zutils Mature 2013-12-11 02:38:41 UTC
9. * Adding patch from upstream to make ...

Author: Daniel Baumann
Revision Date: 2012-12-10 11:23:06 UTC

* Adding patch from upstream to make filenames not prefixed to output by
  default when searching one file (Closes: #694024).
* Updating to standards version 3.9.4.

lp:ubuntu/raring-proposed/rpcbind Mature 2013-12-11 02:37:38 UTC
28. * Merge from Debian unstable, remain...

Author: Steve Langasek
Revision Date: 2012-11-05 00:48:07 UTC

 * Merge from Debian unstable, remaining changes:
   - Handle removal of obsolete init script on upgrade.
   - Convert rpcbind to Upstart
   - Fix to look directly in /run instead of via the /var/run symlink
 * Dropped changes:
   - No dpkg pre-depends needed post-LTS, versioned dep also satisfied
     already in Debian stable.

lp:~ubuntu-branches/ubuntu/raring/zutils/raring-201312110231 (Has a merge proposal) Development 2013-12-11 02:31:47 UTC
8. * Using compression level 9 also for ...

Author: Daniel Baumann
Revision Date: 2012-06-30 15:02:50 UTC

* Using compression level 9 also for binary packages.
* Switching to xz compression.
* Updating copyright file to format version 1.0.
* Updating to debhelper version 9.
* Updating to standards version 3.9.3.

lp:ubuntu/raring-proposed/mountall Mature 2013-12-11 02:05:22 UTC
23. No-change rebuild against libudev1

Author: Martin Pitt
Revision Date: 2013-03-13 07:02:07 UTC

No-change rebuild against libudev1

lp:ubuntu/raring-updates/synaptiks Mature 2013-12-10 15:28:24 UTC
16. Add kubuntu_fix_udev_property_access....

Author: Harald Sitter
Revision Date: 2013-12-10 15:28:24 UTC

Add kubuntu_fix_udev_property_access.patch to fix a crash when accessing
the NAME property of mice (LP: #737856)

lp:ubuntu/raring-proposed/eog Mature 2013-12-09 20:56:07 UTC
141. New upstream release

Author: Robert Ancell
Revision Date: 2012-11-13 10:26:43 UTC

New upstream release

lp:ubuntu/raring-proposed/gnome-online-accounts Mature 2013-12-09 17:30:20 UTC
30. * SECURITY UPDATE: incorrect ssl cert...

Author: Marc Deslauriers
Revision Date: 2013-03-21 13:22:10 UTC

* SECURITY UPDATE: incorrect ssl cert validation (LP: #1117411)
  - debian/patches/CVE-2013-0240.patch: properly validate ssl certs and
    fix cancellation in src/goa/goaenums.h, src/goa/goaerror.c,
    src/goabackend/goaewsclient.c, src/goabackend/goaewsclient.h,
    src/goabackend/goaexchangeprovider.c,
    src/goabackend/goagoogleprovider.c,
    src/goabackend/goahttpclient.*, src/goabackend/goautils.*,
    src/goabackend/goawebview.c.
  - debian/libgoa-1.0-0.symbols: updated with new symbol.
  - CVE-2013-0240
  - CVE-2013-1799

lp:ubuntu/raring-updates/gimp Mature 2013-12-09 14:23:02 UTC
78. * SECURITY UPDATE: denial of service ...

Author: Marc Deslauriers
Revision Date: 2013-12-06 13:26:35 UTC

* SECURITY UPDATE: denial of service and possible code execution via
  huge color maps in xwd plugin
  - debian/patches/CVE-2013-1913.patch: limit number of color map entries
    in plug-ins/common/file-xwd.c.
  - CVE-2013-1913
* SECURITY UPDATE: denial of service and possible code execution via
  large number of color map entries in xwd plugin
  - debian/patches/CVE-2013-1978.patch: validate number of color map
    entries in plug-ins/common/file-xwd.c
  - CVE-2013-1978

lp:ubuntu/raring-security/gimp Mature 2013-12-09 14:00:57 UTC
78. * SECURITY UPDATE: denial of service ...

Author: Marc Deslauriers
Revision Date: 2013-12-06 13:26:35 UTC

* SECURITY UPDATE: denial of service and possible code execution via
  huge color maps in xwd plugin
  - debian/patches/CVE-2013-1913.patch: limit number of color map entries
    in plug-ins/common/file-xwd.c.
  - CVE-2013-1913
* SECURITY UPDATE: denial of service and possible code execution via
  large number of color map entries in xwd plugin
  - debian/patches/CVE-2013-1978.patch: validate number of color map
    entries in plug-ins/common/file-xwd.c
  - CVE-2013-1978

lp:ubuntu/raring-security/linux-meta-lowlatency Mature 2013-12-08 19:04:19 UTC
51. Bump ABI

Author: Kaj Ailomaa
Revision Date: 2013-12-08 19:04:19 UTC

Bump ABI

lp:ubuntu/raring-updates/linux-meta-lowlatency Mature 2013-12-08 19:04:19 UTC
51. Bump ABI

Author: Kaj Ailomaa
Revision Date: 2013-12-08 19:04:19 UTC

Bump ABI

lp:ubuntu/raring-proposed/linux-meta-lowlatency bug Development 2013-12-08 19:04:19 UTC
51. Bump ABI

Author: Kaj Ailomaa
Revision Date: 2013-12-08 19:04:19 UTC

Bump ABI

lp:ubuntu/raring-proposed/network-manager-applet bug Mature 2013-12-05 20:20:40 UTC
107. debian/patches/lp330608_dxteam_gsm_co...

Author: Mathieu Trudel-Lapierre
Revision Date: 2013-12-02 08:56:17 UTC

debian/patches/lp330608_dxteam_gsm_connect_text.patch: refresh patch:
remove some additional g_free() calls that were being made on a const
string for a NM internal pointer containing the connection ID, which should
not be freed. Thanks to Jean-Pierre Rupp for the fix. (LP: #1185330)

lp:ubuntu/raring-security/linux-meta-ti-omap4 Mature 2013-12-04 11:44:31 UTC
68. Ubuntu-3.5.0-237.53

Author: Brad Figg
Revision Date: 2013-12-04 11:44:31 UTC

Ubuntu-3.5.0-237.53

lp:ubuntu/raring-updates/linux-meta-ti-omap4 Mature 2013-12-04 11:44:31 UTC
68. Ubuntu-3.5.0-237.53

Author: Brad Figg
Revision Date: 2013-12-04 11:44:31 UTC

Ubuntu-3.5.0-237.53

lp:ubuntu/raring-security/pixman bug Mature 2013-12-03 21:43:03 UTC
32. * SECURITY UPDATE: Fix underflow when...

Author: Jamie Strandboge
Revision Date: 2013-12-03 12:09:34 UTC

* SECURITY UPDATE: Fix underflow when bottom is close to MIN_INT
  - debian/patches/security-lp1197921.patch: verify (t)->bottom > (t)->top)
  - LP: #1197921
  - CVE-YYYY-NNNN

lp:ubuntu/raring-updates/horizon Mature 2013-12-03 16:07:28 UTC
47. * SECURITY UPDATE: XSS in Volumes and...

Author: Jamie Strandboge
Revision Date: 2013-12-03 16:07:28 UTC

* SECURITY UPDATE: XSS in Volumes and Network Topology pages
  - debian/patches/CVE-2013-6406: html.escape() various items in
    volumes/tables.py and volume_snapshots/tables.py
  - CVE-2013-6406 (also referred to as CVE-2013-6858)
  - LP: #1247675

lp:ubuntu/raring-proposed/linux-meta bug Mature 2013-12-02 18:00:12 UTC
342. linux ABI 3.8.0-35

Author: Steve Conklin
Revision Date: 2013-12-02 18:00:12 UTC

linux ABI 3.8.0-35

lp:ubuntu/raring-security/linux-meta Mature 2013-12-02 18:00:12 UTC
342. linux ABI 3.8.0-35

Author: Steve Conklin
Revision Date: 2013-12-02 18:00:12 UTC

linux ABI 3.8.0-35

lp:ubuntu/raring-updates/linux-meta Mature 2013-12-02 18:00:12 UTC
342. linux ABI 3.8.0-35

Author: Steve Conklin
Revision Date: 2013-12-02 18:00:12 UTC

linux ABI 3.8.0-35

lp:ubuntu/raring-security/linux-signed Mature 2013-12-02 17:55:50 UTC
64. Version 3.8.0-35.50

Author: Steve Conklin
Revision Date: 2013-12-02 17:55:50 UTC

Version 3.8.0-35.50

lp:ubuntu/raring-updates/linux-signed Mature 2013-12-02 17:55:50 UTC
64. Version 3.8.0-35.50

Author: Steve Conklin
Revision Date: 2013-12-02 17:55:50 UTC

Version 3.8.0-35.50

lp:ubuntu/raring-proposed/linux-signed bug Development 2013-12-02 17:55:50 UTC
64. Version 3.8.0-35.50

Author: Steve Conklin
Revision Date: 2013-12-02 17:55:50 UTC

Version 3.8.0-35.50

lp:ubuntu/raring-updates/joyent-mdata-client Mature 2013-12-02 17:55:25 UTC
4. Backport from trusty to raring for Jo...

Author: Ben Howard
Revision Date: 2013-11-22 12:14:36 UTC

Backport from trusty to raring for Joyent IaaS (LP: #1248000).

lp:ubuntu/raring-updates/plymouth Mature 2013-11-30 04:03:44 UTC
1448. debian/patches/Fix-missing-prototype-...

Author: Steve Langasek
Revision Date: 2013-08-01 09:13:34 UTC

debian/patches/Fix-missing-prototype-of-ply_get_timestamp.patch:
Fix missing prototype of ply_get_timestamp(). LP: #1187318.

lp:ubuntu/raring-proposed/plymouth bug Mature 2013-11-30 04:03:36 UTC
1448. debian/patches/Fix-missing-prototype-...

Author: Steve Langasek
Revision Date: 2013-08-01 09:13:34 UTC

debian/patches/Fix-missing-prototype-of-ply_get_timestamp.patch:
Fix missing prototype of ply_get_timestamp(). LP: #1187318.

lp:ubuntu/raring-backports/jq bug Mature 2013-11-27 12:06:36 UTC
3. No-change backport to raring (LP: #12...

Author: Iain Lane
Revision Date: 2013-11-27 11:45:09 UTC

No-change backport to raring (LP: #1252729)

lp:ubuntu/raring-security/ruby1.9.1 Mature 2013-11-26 11:36:50 UTC
29. * SECURITY UPDATE: safe level restric...

Author: Marc Deslauriers
Revision Date: 2013-11-26 11:36:50 UTC

* SECURITY UPDATE: safe level restriction bypass via DL and Fiddle
  - debian/patches/CVE-2013-2065.patch: perform taint checking in
    ext/dl/lib/dl/func.rb, ext/fiddle/function.c.
  - CVE-2013-2065
* SECURITY UPDATE: denial of service and possible code execution via
  heap overflow in floating point parsing.
  - debian/patches/CVE-2013-4164.patch: check lengths in util.c, added
    test to test/ruby/test_float.rb.
  - CVE-2013-4164

lp:ubuntu/raring-updates/ruby1.9.1 Mature 2013-11-26 11:36:50 UTC
29. * SECURITY UPDATE: safe level restric...

Author: Marc Deslauriers
Revision Date: 2013-11-26 11:36:50 UTC

* SECURITY UPDATE: safe level restriction bypass via DL and Fiddle
  - debian/patches/CVE-2013-2065.patch: perform taint checking in
    ext/dl/lib/dl/func.rb, ext/fiddle/function.c.
  - CVE-2013-2065
* SECURITY UPDATE: denial of service and possible code execution via
  heap overflow in floating point parsing.
  - debian/patches/CVE-2013-4164.patch: check lengths in util.c, added
    test to test/ruby/test_float.rb.
  - CVE-2013-4164

lp:ubuntu/raring-updates/unzip Mature 2013-11-25 21:30:11 UTC
25. Fix incorrectly displayed file names ...

Author: Brian Murray
Revision Date: 2013-11-06 09:40:08 UTC

Fix incorrectly displayed file names with UTF-8 characters.
Add -DNO_WORKING_ISPRINT to build flags. (LP: #1199239, LP: #580961)

lp:ubuntu/raring-proposed/joyent-mdata-client bug Mature 2013-11-22 22:33:55 UTC
4. Backport from trusty to raring for Jo...

Author: Ben Howard
Revision Date: 2013-11-22 12:14:36 UTC

Backport from trusty to raring for Joyent IaaS (LP: #1248000).

lp:ubuntu/raring-updates/nginx bug Mature 2013-11-22 04:35:44 UTC
64. * SECURITY UPDATE: ACL bypass via spa...

Author: Thomas Ward
Revision Date: 2013-11-21 13:24:46 UTC

* SECURITY UPDATE: ACL bypass via space character (LP: #1253691)
  - debian/patches/cve-2013-4547.patch: modify src/http/ngx_http_parse.c
    to account for a space character, fixing an issue which could result in
    security restrictions being bypassed
  - CVE-2013-4547

lp:ubuntu/raring-proposed/duplicity bug Mature 2013-11-21 23:01:01 UTC
39. * debian/patches/03-dont-skip-first-c...

Author: Michael Terry
Revision Date: 2013-11-19 10:08:29 UTC

* debian/patches/03-dont-skip-first-chunk-on-restart.dpatch:
  - When restarting a backup, if the file we were in the middle of
    backing up is now deleted, don't skip the first 65k chunk of the
    next file. Patch backported from upstream trunk. LP: #1252484

lp:ubuntu/raring-security/nginx bug(Has a merge proposal) Mature 2013-11-21 13:24:46 UTC
64. * SECURITY UPDATE: ACL bypass via spa...

Author: Thomas Ward
Revision Date: 2013-11-21 13:24:46 UTC

* SECURITY UPDATE: ACL bypass via space character (LP: #1253691)
  - debian/patches/cve-2013-4547.patch: modify src/http/ngx_http_parse.c
    to account for a space character, fixing an issue which could result in
    security restrictions being bypassed
  - CVE-2013-4547

lp:ubuntu/raring-proposed/fcitx-cloudpinyin bug Development 2013-11-18 19:43:13 UTC
11. Go with Google by default, original d...

Author: Aron Xu
Revision Date: 2013-11-16 11:15:45 UTC

Go with Google by default, original default isn't available anymore.
(LP: #1251799)

lp:ubuntu/raring-backports/ipmitool bug Mature 2013-11-15 19:46:20 UTC
17. No-change backport to raring (LP: #12...

Author: Felix Geyer
Revision Date: 2013-11-15 19:39:26 UTC

No-change backport to raring (LP: #1251694)

lp:ubuntu/raring-proposed/popularity-contest bug Mature 2013-11-13 20:04:15 UTC
12. * Backport saucy fix to raring (lp: #...

Author: Sebastien Bacher
Revision Date: 2013-11-13 19:41:06 UTC

* Backport saucy fix to raring (lp: #1250975)
[ Dmitry Shachnev ]
* Re-add some parts of Ubuntu delta accidentally dropped in previous
  upload.

lp:ubuntu/raring-updates/libcommons-fileupload-java Mature 2013-11-13 15:37:33 UTC
15. * SECURITY UPDATE: arbitrary file ove...

Author: Marc Deslauriers
Revision Date: 2013-11-07 09:43:18 UTC

* SECURITY UPDATE: arbitrary file overwrite via poison null byte
  - debian/patches/CVE-2013-2186.patch: properly validate repository in
    src/java/org/apache/commons/fileupload/disk/DiskFileItem.java.
  - CVE-2013-2186

lp:ubuntu/raring-security/libcommons-fileupload-java Mature 2013-11-13 15:19:09 UTC
15. * SECURITY UPDATE: arbitrary file ove...

Author: Marc Deslauriers
Revision Date: 2013-11-07 09:43:18 UTC

* SECURITY UPDATE: arbitrary file overwrite via poison null byte
  - debian/patches/CVE-2013-2186.patch: properly validate repository in
    src/java/org/apache/commons/fileupload/disk/DiskFileItem.java.
  - CVE-2013-2186

lp:ubuntu/raring-proposed/kickseed bug Mature 2013-11-12 20:29:13 UTC
14. Preseed netcfg/disable_autoconfig rat...

Author: Colin Watson
Revision Date: 2013-11-08 12:45:44 UTC

Preseed netcfg/disable_autoconfig rather than deprecated
netcfg/disable_dhcp (LP: #879605).

lp:ubuntu/raring-updates/xpdf Mature 2013-11-12 19:29:04 UTC
33. Use GlobalParams module from Poppler ...

Author: Dmitry Shachnev
Revision Date: 2013-09-19 18:14:03 UTC

Use GlobalParams module from Poppler and move all settings that
are not available in Poppler to a separate file (LP: #943195).

lp:ubuntu/raring-security/libav bug Mature 2013-11-11 15:50:21 UTC
33. Update to 0.8.9 to fix multiple secur...

Author: Marc Deslauriers
Revision Date: 2013-11-09 10:48:01 UTC

Update to 0.8.9 to fix multiple security issues (LP: #1249621)

lp:ubuntu/raring-security/libav-extra Mature 2013-11-09 14:21:58 UTC
30. * Rebuild against new libav - debia...

Author: Marc Deslauriers
Revision Date: 2013-11-09 14:21:58 UTC

* Rebuild against new libav
  - debian/control: bump Build-Depends

1100 of 32605 results