Subversion Repositories

?revision_form?Rev ?revision_input??revision_submit??revision_endform?

Rev 36 | Details | Compare with Previous | Last modification | View Log | RSS feed

Rev Author Line No. Line
36 magnus 1
libtar (1.2.20-4) unstable; urgency=high
2
 
3
  * no_maxpathlen.patch: Half of the part of the patch modifying
4
    compat/dirname.c was missing, causing libtar's dirname to always
5
    return NULL (except in special circumstances). Actually make it work
6
    (Closes: #745352). (The reason that libtar doesn't use libc's
7
    dirname() and basename() on some or most platforms is that the code
8
    doesn't work with destructive versions of these functions).
9
 
10
 -- Magnus Holmgren <holmgren@debian.org>  Sat, 03 May 2014 20:39:02 +0200
11
 
30 magnus 12
libtar (1.2.20-3) unstable; urgency=low
13
 
14
  * no_maxpathlen.patch: Fix two grave bugs in the patch. First,
15
    th_get_pathname would only allocate as much memory as was needed for
16
    the first filename encountered, causing heap corruption when/if
17
    encountering longer filenames later. Second, two variables were mixed
18
    up in tar_append_tree(). Also, fix a potential memory leak and trim
19
    the patch a bit.
31 magnus 20
  * [SECURITY] CVE-2013-4420.patch: When the prefix field is in use, the
21
    safer_name_suffix() function should certainly be applied to the
22
    combination of it and the name field, not just on the name field.
33 magnus 23
  * th_get_size-unsigned-int.patch: Make the th_get_size() macro cast the
24
    result from oct_to_int() to unsigned int. This is the right fix for
25
    bug #725938 on 64-bit systems, where a specially crafted tar file
26
    would not cause an integer overflow, but a memory allocation of almost
27
    16 exbibytes, which would certainly fail outright without harm.
30 magnus 28
 
33 magnus 29
 -- Magnus Holmgren <holmgren@debian.org>  Sat, 15 Feb 2014 23:51:51 +0100
30 magnus 30
 
23 magnus 31
libtar (1.2.20-2) unstable; urgency=low
32
 
33
  * no_static_buffers.patch: avoid using a static buffer in
34
    th_get_pathname(). Taken from upstream. Needed for no_maxpathlen.patch.
29 magnus 35
  * no_maxpathlen.patch: Fix FTBFS on Hurd by dynamically allocating path
23 magnus 36
    names (Closes: #657116). Thanks to Svante Signell and Petter
37
    Reinholdtsen.
24 magnus 38
  * [SECURITY] CVE-2013-4420.patch: Strip out leading slashes and any
39
    pathname prefix containing ".." components (Closes: #731860). This is
40
    done in th_get_pathname() (as well as to symlink targets when
41
    extracting symlinks), not merely when extracting files, which means
42
    applications calling that function will not see the stored
43
    filename. There is no way to disable this behaviour, but it can be
44
    expected that one will be provided when the issue is solved upstream.
25 magnus 45
  * Bump Standards-Version to 3.9.5.
23 magnus 46
 
25 magnus 47
 -- Magnus Holmgren <holmgren@debian.org>  Sat, 15 Feb 2014 21:49:37 +0100
23 magnus 48
 
18 magnus 49
libtar (1.2.20-1) unstable; urgency=high
50
 
51
  * [SECURITY] New upstream release. Fixes CVE-2013-4397: Integer
52
    overflow (Closes: #725938).
19 magnus 53
  * Bump Standards-Version to 3.9.4.
18 magnus 54
 
55
 -- Magnus Holmgren <holmgren@debian.org>  Thu, 10 Oct 2013 19:20:49 +0200
56
 
15 magnus 57
libtar (1.2.19-1) unstable; urgency=low
58
 
59
  * New upstream release.
60
 
61
 -- Magnus Holmgren <holmgren@debian.org>  Sun, 05 May 2013 17:59:29 +0200
62
 
10 magnus 63
libtar (1.2.16-1) unstable; urgency=low
8 magnus 64
 
65
  * New upstream: Chris Frey has stepped up with the consent of the
66
    original author, Mark Roth, and published an "official unofficial" git
67
    repo at http://repo.or.cz/w/libtar.git, which I will use for the time
68
    being.
10 magnus 69
  * Updated debian/watch to look for tags and corresponding snapshot
70
    tarballs at above URL.
8 magnus 71
  * All patches have been incorporated or (in the case of
72
    autoreconf.patch) made obsolete upstream.
9 magnus 73
  * debian/rules: Add build-indep and build-arch targets.
11 magnus 74
  * Updated debian/copyright.
12 magnus 75
  * Use dpkg-buildflags to set CFLAGS et al.
13 magnus 76
  * debian/control: Add VCS fields; bump Standards-Version to 3.9.3.
8 magnus 77
 
13 magnus 78
 -- Magnus Holmgren <holmgren@debian.org>  Sat, 23 Jun 2012 01:03:41 +0200
8 magnus 79
 
6 magnus 80
libtar (1.2.11-8) unstable; urgency=low
81
 
82
  * libtool.patch: Set SHELL to the configured shell in those Makefile.in
83
    where libtool is used; otherwise libtool fails when /bin/sh is dash
84
    but bash is expected (Closes: #621935).
85
  * man_hyphen_minus.patch (new): Escape hyphens that should be minus
86
    signs in man pages.
87
  * Rename libtar as libtar0 to follow policy.
88
 
89
 -- Magnus Holmgren <holmgren@debian.org>  Sun, 24 Apr 2011 21:11:52 +0200
90
 
5 magnus 91
libtar (1.2.11-7) unstable; urgency=low
92
 
93
  * New maintainer (Closes: #526618).
94
  * Change source format to 3.0 (quilt), clean up Debian diff and split
95
    into several patches:
96
    * libtool.patch: Using libtool to build dynamic library;
97
    * autoreconf.patch: Changes needed to call autoreconf (bug 511741);
98
    * memleak.patch: Fix memory leaks;
99
    * bad_ptrtoint.patch: Document stupidity of tartype_t in libtar.c
100
      (bug 309945).
101
  * Increase Debhelper compat level to 7.
102
  * Use dh_autoreconf to avoid having to keep track of files to clean.
103
  * memleak2.patch (new): Applied instead of memleak.patch. Fix memory
104
    leak by making th_get_pathname() return a pointer to a static buffer
105
    instead of a pointer to a copy of a local buffer (LP: #41804).
106
  * Add homepage field and watch file (in case there is ever a new
107
    upstream release).
108
  * Upgrade to Standards-Version 3.9.1.
109
 
110
 -- Magnus Holmgren <holmgren@debian.org>  Sat, 26 Mar 2011 23:10:25 +0100
111
 
3 magnus 112
libtar (1.2.11-6) unstable; urgency=low
113
 
114
  * Fix autotools usage (Closes: #511741)
115
 
116
 -- Julien Danjou <acid@debian.org>  Sat, 02 May 2009 11:33:06 +0200
117
 
118
libtar (1.2.11-5) unstable; urgency=low
119
 
120
  * New maintainer (Closes: #465889)
121
  * Add missing binary-indep target in debian/rules (Closes: #395714)
122
  * Use ${binary:Version} instead of Source-Version
123
  * Bump standard version
124
  * Switch to debhelper 5
125
 
126
 -- Julien Danjou <acid@debian.org>  Wed, 02 Apr 2008 07:06:55 +0200
127
 
128
libtar (1.2.11-4) unstable; urgency=low
129
 
130
  * Always include the newest libtool.m4.  (Closes: #313612)
131
 
132
 -- James Morrison <phython@debian.org>  Sun, 28 Aug 2005 09:41:47 -0700
133
 
134
libtar (1.2.11-3) unstable; urgency=low
135
 
136
  * Document stupidity of tartype_t in libtar.c.  (Closes: #309945)
137
 
138
 -- James Morrison <phython@debian.org>  Sat, 11 Jun 2005 18:23:15 -0400
139
 
140
libtar (1.2.11-2) unstable; urgency=low
141
 
142
  * Move libtar-dev to libdevel. (Closes: #188207)
143
  * Fix potential memory leak.
144
 
145
 -- James Morrison <phython@debian.org>  Sun, 25 Jul 2004 12:59:08 -0700
146
 
147
libtar (1.2.11-1) unstable; urgency=low
148
 
149
  * New Upstream release.
150
 
151
 -- James Morrison <phython@debian.org>  Sat,  5 Apr 2003 14:03:19 -0500
152
 
153
libtar (1.2.10-1) unstable; urgency=low
154
 
155
  * New Upstream release.
156
     (Closes: #166602) New upstream uses autoconf 2.5x
157
  * Remove dependency on automake.  Hopefully upstream will except this
158
    use of libtool.
159
  * Remove all -static and -shared targets from debian/rules.
160
  * Use dh_install instead of dh_movefiles.
161
  * -
162
 
163
 -- James Morrison <phython@debian.org>  Sat,  5 Apr 2003 14:03:16 -0500
164
 
165
libtar (1.2.5-4) unstable; urgency=low
166
 
167
  * New maintainer. (Closes: #154597)
168
  * WSG_ENCAP is now defined.  (Closes: #147764)
169
  * libtar-dev depends on libc-dev instead of libc6-dev.
170
 
171
 -- James Morrison <phython@debian.org>  Wed, 14 Aug 2002 23:44:16 -0400
172
 
173
libtar (1.2.5-3) unstable; urgency=low
174
 
175
  * Modify build commands to acomadate change in autoconf (Closes #147764)
176
 
177
 -- Glenn McGrath <bug1@debian.org>  Thu, 23 May 2002 01:06:16 +1000
178
 
179
libtar (1.2.5-2) unstable; urgency=low
180
 
181
  * Fix build problem (Closes #135360)
182
 
183
 -- Glenn McGrath <bug1@debian.org>  Sun, 24 Feb 2002 06:29:31 +1100
184
 
185
libtar (1.2.5-1) unstable; urgency=low
186
 
187
  * New upstream version
188
  * Change section of libtar-dev to devel and libtar to libs
189
 
190
 -- Glenn McGrath <bug1@debian.org>  Fri, 22 Feb 2002 04:23:15 +1100
191
 
192
libtar (1.2.4-2) unstable; urgency=low
193
 
194
  * Change section from devel to libs
195
 
196
 -- Glenn McGrath <bug1@debian.org>  Sat,  2 Feb 2002 12:12:32 +1100
197
 
198
libtar (1.2.4-1) unstable; urgency=low
199
 
200
  * Initial Release. (closes #128042)
201
 
202
 -- Glenn McGrath <bug1@debian.org>  Sat,  5 Jan 2002 13:24:37 +1100
203