lp:~jtaylor/ubuntu/lucid/gajim/multiple-CVE

Created by Julian Taylor and last modified
Get this branch:
bzr branch lp:~jtaylor/ubuntu/lucid/gajim/multiple-CVE
Only Julian Taylor can upload to this branch. If you are Julian Taylor please log in for upload directions.

Branch merges

Related bugs

Related blueprints

Branch information

Owner:
Julian Taylor
Status:
Merged

Recent revisions

55. By Julian Taylor

fix missing wait on process end

54. By Julian Taylor

fix missing jid tuple in patch

53. By Julian Taylor

nicen changelog

52. By Julian Taylor

fix error in patch, obj.command is only used in >= 0.14

51. By Julian Taylor

    Thanks to Nico Golde

50. By Julian Taylor

add lp bug numbers

49. By Julian Taylor

* SECURITY UPDATE: assisted code execution (LP: #XXX)
  - debian/patches/CVE-2012-2085.dpatch: fix subprocess call to prevent
    shell escape
    https://trac.gajim.org/changeset/bc296e96ac10
  - CVE-2012-2085
* SECURITY UPDATE: sql injection (LP: #XXX)
  - debian/patches/CVE-2012-2086.dpatch: use a prepated statement
    https://trac.gajim.org/changeset/bfd5f94489d8
  - CVE-2012-2086
* SECURITY UPDATE: insecure tmpfile creation(LP: #XXX)
  - debian/patches/CVE-2012-2093.dpatch: use safe tmpfile functions
  - CVE-2012-2093

48. By Chris Coulson

* debian/control:
  - Change python-gnome2-extras recommends to python-eggtrayicon.
    The former package has gone away in Lucid.

47. By Maia Kozheva <sikon@maia-desktop>

Removed installation for .so files

46. By Maia Kozheva <sikon@maia-desktop>

Removed obsolete patches

Branch metadata

Branch format:
Branch format 7
Repository format:
Bazaar repository format 2a (needs bzr 1.16 or later)
Stacked on:
lp:ubuntu/quantal/gajim
This branch contains Public information 
Everyone can see this information.

Subscribers