lp:ubuntu/edgy-updates/kvirc
- Get this branch:
- bzr branch lp:ubuntu/edgy-updates/kvirc
Branch merges
Branch information
Recent revisions
- 7. By Rich Johnson
-
* SECURITY UPDATE: parseIrcUrl() do not properly sanitize parts of the URI
when building the command for KVIrc's internet script system. This can
be exploited to inject and execute commands for the KVIrc script system
(including the "run" command, which can be leveraged to execute shell
commands) by e.g. tricking a user into opening a specially crafted
"irc://" or similar URI.
* Add debian/patches/ 09_parseIrcUrl_ security_ fix.patch: properly sanitizes
URI strings, as done in upstream SVN. (Fixes LP: #123037)
* References:
- http://www.kvirc. net/?id= news&story= 2007.06. 29.22.00. 1.story& dir=latest
- http://secunia. com/secunia_ research/ 2007-56/ advisory/
- http://www.cve. mitre.org/ cgi-bin/ cvename. cgi?name= CVE-2007- 2951
- https://svn.kvirc. de/kvirc/ changeset/ 630/#file3 (fix to kvi_ircurl.cpp) - 3. By Robin Verduijn <email address hidden>
-
* Rebuild for current dependencies.
* Update FSF address.
* Bump Standards-Version to 3.6.2.0 (no changes).
* Fix invalid characters in manpage. - 2. By Robin Verduijn <email address hidden>
-
* Change Recommends on xmms to a Suggests.
* Rebuild against KDE 3.3.1 - 1. By Robin Verduijn <email address hidden>
-
* #138169: The problem in bug #138169 is due to a bug in libtool. See
bug #98342 for details. KVirc still doesn't build correctly even with
the latest libtool (1.4.2-4). When this gets properly fixed I'll update
kvirc's build dependency on libtool. In the mean time, I've applied a
patch from that bug report which fixes it for me.
(Closes: #138169)
* Redid debian/rules somewhat; no longer try to build differently
depending on how KDE is installed. If the preferred configuration breaks
for some platform, I'd rather know about it.
* Don't link versus qt-mt anymore.
* GNU config automated update: config.sub (20010907 to 20020307),
config.guess (20010904 to 20020320)
Branch metadata
- Branch format:
- Branch format 7
- Repository format:
- Bazaar repository format 2a (needs bzr 1.16 or later)
- Stacked on:
- lp:ubuntu/karmic/kvirc