ubuntu/+source/munin:ubuntu/quantal-security

Last commit made on 2014-01-27
Get this branch:
git clone -b ubuntu/quantal-security https://git.launchpad.net/ubuntu/+source/munin
Members of Ubuntu Server Dev import team can upload to this branch. Log in for directions.

Branch merges

Branch information

Name:
ubuntu/quantal-security
Repository:
lp:ubuntu/+source/munin

Recent commits

89b7b1e... by Marc Deslauriers on 2013-12-18

Import patches-unapplied version 2.0.2-1ubuntu2.3 to ubuntu/quantal-security

Imported using git-ubuntu import.

Changelog parent: 645e77e8c36b7f5eb490aaa7dd46a14baa9b2345

New changelog entries:
  * SECURITY UPDATE: multiple denial of service issues
    - debian/patches/CVE-2013-6xxx.patch: apply fixes from upstream to
      master/lib/Munin/Master/{HTMLConfig,Node}.pm.
    - CVE-2013-6048
    - CVE-2013-6359

645e77e... by Marc Deslauriers on 2012-10-17

Import patches-unapplied version 2.0.2-1ubuntu2.2 to ubuntu/quantal-proposed

Imported using git-ubuntu import.

Changelog parent: 6c5ab13b5f9bbfb07e668fc8f75f16bda8891f52

New changelog entries:
  * SECURITY UPDATE: privilege escalation via root running plugins
    - debian/patches/CVE-2012-3512.patch: run each plugin in their own
      state directory in Makefile, Makefile.config,
      node/lib/Munin/Node/{OS,Service}.pm, plugins/lib/Munin/Plugin.pm,
      plugins/node.d/*.in,plugins/node.d.linux/*.in.
    - CVE-2012-3512
  * SECURITY UPDATE: remote code exection via bad arguments
    - debian/patches/CVE-2012-3513.patch: use MUNIN_CONFIG env variable
      instead of @ARGV to specify alternate config file in
      master/_bin/munin-cgi-graph.in, master/_bin/munin-cgi-html.in.
    - debian/patches/CVE-2012-3512-regression.patch: Don't rely on
      MUNIN_PLUGSTATE being in the environment as these scripts also get
      run by a cron job in plugins/node.d.linux/apt_all.in,
      plugins/node.d.linux/apt.in.
    - CVE-2012-3513
  * debian/rules: actually apply quilt patches.
  * debian/Makefile.config: added new plugin state directory location.
  * debian/munin-node.{postinst,postrm}: Switch to new plugin state
    directory.

6c5ab13... by Petri Lehtinen on 2012-10-03

Import patches-unapplied version 2.0.2-1ubuntu2 to ubuntu/quantal

Imported using git-ubuntu import.

Changelog parent: 4856246d217a53cc7ffce7b55926d0d7e6cc93b6

New changelog entries:
  * debian/patches/fix_ran_out_of_children.patch:
    - Fix occasional "Ran out of children: No child processes" error messages
      (LP: #1009357).

4856246... by Logan Rosen on 2012-07-22

Import patches-unapplied version 2.0.2-1ubuntu1 to ubuntu/quantal

Imported using git-ubuntu import.

Changelog parent: f3086e3b89f4b2e90884306090beec89adb7e0c1

New changelog entries:
  * Merge from Debian unstable. Remaining changes:
    - d/munin-node.upstart,munin.upstart: Add upstart configurations.

f3086e3... by Holger Levsen <email address hidden> on 2012-07-21

Import patches-unapplied version 2.0.2-1 to debian/sid

Imported using git-ubuntu import.

Changelog parent: 514cfeaf70d04ca82dfa707884e8ca5bd14f8fea

New changelog entries:
  [ Holger Levsen ]
  * New upstream version, reintroducing munin-graph (Closes: #681674) and
    some bugfixes. The new munin book is added to the sources, but not yet
    build.
  * Add proper LSB headers to all init scripts. (Closes: #680223)
  [ Stig Sandbeck Mathisen ]
  * debian/control: Rename "munin-async-*" to munin-async and munin-asyncd.

514cfea... by Holger Levsen <email address hidden> on 2012-06-20

Import patches-unapplied version 2.0.1-1 to debian/sid

Imported using git-ubuntu import.

Changelog parent: e4e99cb75f06449d77ada69d806bf37e1326b7e5

New changelog entries:
  * New upstream version.
  * Update URL to upstream webpage in debian/copyright. (Closes: #676366)
  * Make munin-node depend on munin-plugins-core unconditionally and recommend
    munin-plugins-extra. (Closes: #677189)
  * debian/munin-node.postinst: chmod 775 /var/lib/munin/plugin-state
    (Closes: #675593)

e4e99cb... by Holger Levsen <email address hidden> on 2012-05-31

Import patches-unapplied version 2.0.0-1 to debian/sid

Imported using git-ubuntu import.

Changelog parent: f79940014ca345dd9c73c9ccdfbc3e66a12a791c

New changelog entries:
  * New upstream version. Roughly eight years after munin 1.0 there is now
    finally munin 2.0! See /usr/share/doc/munin/Announce-2.0 in the munin
    package for the full announcement. And/or previous debian/changelog
    entries too. Enjoy! And please report bugs, 2.0.1 shall be out soon.
    (Closes: #675153, #674148)
  * /etc/init/munin-node: chmod 755 /var/log/munin (Closes: #674747)
  * Make munin-node suggest munin-plugins-java and not munin-java-plugins.
  * Lower build-depends on debhelper to version 8. (Closes: #675209)

f799400... by Holger Levsen <email address hidden> on 2012-05-17

Import patches-unapplied version 2.0~rc6-3 to debian/sid

Imported using git-ubuntu import.

Changelog parent: 258d16a727a6967e651729966658023dd7d876e5

New changelog entries:
  * Make munin-node depend on munin-plugins-core | munin-plugins.
    (Closes: #673124)
  * munin-node.logroate: create munin-node.log owned by root.
    (Closes: #606216)

258d16a... by Holger Levsen <email address hidden> on 2012-05-14

Import patches-unapplied version 2.0~rc6-2 to debian/sid

Imported using git-ubuntu import.

Changelog parent: 1745a48268767c3fdfdb77fe0cca84321c261cec

New changelog entries:
  * munin.postinst: Fix typo breaking the chgrp of $cgitempdir.

1745a48... by Holger Levsen <email address hidden> on 2012-05-13

Import patches-unapplied version 2.0~rc6-1 to debian/sid

Imported using git-ubuntu import.

Changelog parent: 8f1d06e1d0f14148de63cdf75c6981541bf46fe5

New changelog entries:
  [ Holger Levsen ]
  * New upstream release candidate, quoting the upstream Changelog:
    - Many bugfixes in munin-cgi-graph:
      - if url parameters are not valid, send HTTP 404 instead of 500
      - move the generation of png via cgi under /var/lib/munin/cgi-tmp/
        (Closes: #668536)
      - don't cache URL with parameters anymore, and don't keep uncached URLs
        (Closes: #668667)
      - validate url characters (Closes: #668666)
      - add a max setting for cgi image size. (Closes: #670811)
    - Plugin fixes:
      - add explicit license for all plugins. (Closes: #670428)
      - hddtemp_smartctl: just use the device name as the labels
      - qmailscan: remove the use of tempfiles. (Closes: #668778)
  * munin.NEWS: document that "cgitmpdir /var/lib/munin/cgi-tmp" has to be
    set in munin.conf.
  * munin-node.postinst: chmod 755 /var/log/munin (Closes: #669230)
  * munin.postinst: make /var/lib/munin/cgi-tmp writable for group www-data.
  [ Matthias Schmitz ]
  * Add installation of apache configuration to /etc/apache2/conf-availble as
    needed by Apache 2.4. (Closes: #669816)