lp:ubuntu/edgy-updates/kvirc

Created by James Westby and last modified
Get this branch:
bzr branch lp:ubuntu/edgy-updates/kvirc
Members of Ubuntu branches can upload to this branch. Log in for directions.

Branch merges

Related bugs

Related blueprints

Branch information

Owner:
Ubuntu branches
Review team:
Ubuntu Development Team
Status:
Development

Recent revisions

7. By Rich Johnson

* SECURITY UPDATE: parseIrcUrl() do not properly sanitize parts of the URI
  when building the command for KVIrc's internet script system. This can
  be exploited to inject and execute commands for the KVIrc script system
  (including the "run" command, which can be leveraged to execute shell
  commands) by e.g. tricking a user into opening a specially crafted
  "irc://" or similar URI.
* Add debian/patches/09_parseIrcUrl_security_fix.patch: properly sanitizes
  URI strings, as done in upstream SVN. (Fixes LP: #123037)
* References:
  - http://www.kvirc.net/?id=news&story=2007.06.29.22.00.1.story&dir=latest
  - http://secunia.com/secunia_research/2007-56/advisory/
  - http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2951
  - https://svn.kvirc.de/kvirc/changeset/630/#file3 (fix to kvi_ircurl.cpp)

6. By Brandon Holtsclaw

Merge from debian unstable ( again ).

5. By Brandon Holtsclaw

* Merge from debian unstable.
* removed Bashisms from debain/rules

4. By Brandon Holtsclaw

added dh_iconcache.

3. By Robin Verduijn <email address hidden>

* Rebuild for current dependencies.
* Update FSF address.
* Bump Standards-Version to 3.6.2.0 (no changes).
* Fix invalid characters in manpage.

2. By Robin Verduijn <email address hidden>

* Change Recommends on xmms to a Suggests.
* Rebuild against KDE 3.3.1

1. By Robin Verduijn <email address hidden>

* #138169: The problem in bug #138169 is due to a bug in libtool. See
  bug #98342 for details. KVirc still doesn't build correctly even with
  the latest libtool (1.4.2-4). When this gets properly fixed I'll update
  kvirc's build dependency on libtool. In the mean time, I've applied a
  patch from that bug report which fixes it for me.
  (Closes: #138169)
* Redid debian/rules somewhat; no longer try to build differently
  depending on how KDE is installed. If the preferred configuration breaks
  for some platform, I'd rather know about it.
* Don't link versus qt-mt anymore.
* GNU config automated update: config.sub (20010907 to 20020307),
  config.guess (20010904 to 20020320)

Branch metadata

Branch format:
Branch format 7
Repository format:
Bazaar repository format 2a (needs bzr 1.16 or later)
Stacked on:
lp:ubuntu/karmic/kvirc
This branch contains Public information 
Everyone can see this information.

Subscribers