Subversion Repositories

?revision_form?Rev ?revision_input??revision_submit??revision_endform?

Rev 30 | Rev 33 | Go to most recent revision | Only display areas with differences | Ignore whitespace | Details | Blame | Last modification | View Log | RSS feed

Rev 30 Rev 31
1
libtar (1.2.20-3) unstable; urgency=low
1
libtar (1.2.20-3) unstable; urgency=low
2
2
3
  * no_maxpathlen.patch: Fix two grave bugs in the patch. First,
3
  * no_maxpathlen.patch: Fix two grave bugs in the patch. First,
4
    th_get_pathname would only allocate as much memory as was needed for
4
    th_get_pathname would only allocate as much memory as was needed for
5
    the first filename encountered, causing heap corruption when/if
5
    the first filename encountered, causing heap corruption when/if
6
    encountering longer filenames later. Second, two variables were mixed
6
    encountering longer filenames later. Second, two variables were mixed
7
    up in tar_append_tree(). Also, fix a potential memory leak and trim
7
    up in tar_append_tree(). Also, fix a potential memory leak and trim
8
    the patch a bit.
8
    the patch a bit.
-
 
9
  * [SECURITY] CVE-2013-4420.patch: When the prefix field is in use, the
-
 
10
    safer_name_suffix() function should certainly be applied to the
-
 
11
    combination of it and the name field, not just on the name field.
9
12
10
 -- Magnus Holmgren <holmgren@debian.org>  Sat, 15 Feb 2014 21:54:56 +0100
13
 -- Magnus Holmgren <holmgren@debian.org>  Sat, 15 Feb 2014 23:21:56 +0100
11
14
12
libtar (1.2.20-2) unstable; urgency=low
15
libtar (1.2.20-2) unstable; urgency=low
13
16
14
  * no_static_buffers.patch: avoid using a static buffer in
17
  * no_static_buffers.patch: avoid using a static buffer in
15
    th_get_pathname(). Taken from upstream. Needed for no_maxpathlen.patch.
18
    th_get_pathname(). Taken from upstream. Needed for no_maxpathlen.patch.
16
  * no_maxpathlen.patch: Fix FTBFS on Hurd by dynamically allocating path
19
  * no_maxpathlen.patch: Fix FTBFS on Hurd by dynamically allocating path
17
    names (Closes: #657116). Thanks to Svante Signell and Petter
20
    names (Closes: #657116). Thanks to Svante Signell and Petter
18
    Reinholdtsen.
21
    Reinholdtsen.
19
  * [SECURITY] CVE-2013-4420.patch: Strip out leading slashes and any
22
  * [SECURITY] CVE-2013-4420.patch: Strip out leading slashes and any
20
    pathname prefix containing ".." components (Closes: #731860). This is
23
    pathname prefix containing ".." components (Closes: #731860). This is
21
    done in th_get_pathname() (as well as to symlink targets when
24
    done in th_get_pathname() (as well as to symlink targets when
22
    extracting symlinks), not merely when extracting files, which means
25
    extracting symlinks), not merely when extracting files, which means
23
    applications calling that function will not see the stored
26
    applications calling that function will not see the stored
24
    filename. There is no way to disable this behaviour, but it can be
27
    filename. There is no way to disable this behaviour, but it can be
25
    expected that one will be provided when the issue is solved upstream.
28
    expected that one will be provided when the issue is solved upstream.
26
  * Bump Standards-Version to 3.9.5.
29
  * Bump Standards-Version to 3.9.5.
27
30
28
 -- Magnus Holmgren <holmgren@debian.org>  Sat, 15 Feb 2014 21:49:37 +0100
31
 -- Magnus Holmgren <holmgren@debian.org>  Sat, 15 Feb 2014 21:49:37 +0100
29
32
30
libtar (1.2.20-1) unstable; urgency=high
33
libtar (1.2.20-1) unstable; urgency=high
31
34
32
  * [SECURITY] New upstream release. Fixes CVE-2013-4397: Integer
35
  * [SECURITY] New upstream release. Fixes CVE-2013-4397: Integer
33
    overflow (Closes: #725938).
36
    overflow (Closes: #725938).
34
  * Bump Standards-Version to 3.9.4.
37
  * Bump Standards-Version to 3.9.4.
35
38
36
 -- Magnus Holmgren <holmgren@debian.org>  Thu, 10 Oct 2013 19:20:49 +0200
39
 -- Magnus Holmgren <holmgren@debian.org>  Thu, 10 Oct 2013 19:20:49 +0200
37
40
38
libtar (1.2.19-1) unstable; urgency=low
41
libtar (1.2.19-1) unstable; urgency=low
39
42
40
  * New upstream release.
43
  * New upstream release.
41
44
42
 -- Magnus Holmgren <holmgren@debian.org>  Sun, 05 May 2013 17:59:29 +0200
45
 -- Magnus Holmgren <holmgren@debian.org>  Sun, 05 May 2013 17:59:29 +0200
43
46
44
libtar (1.2.16-1) unstable; urgency=low
47
libtar (1.2.16-1) unstable; urgency=low
45
48
46
  * New upstream: Chris Frey has stepped up with the consent of the
49
  * New upstream: Chris Frey has stepped up with the consent of the
47
    original author, Mark Roth, and published an "official unofficial" git
50
    original author, Mark Roth, and published an "official unofficial" git
48
    repo at http://repo.or.cz/w/libtar.git, which I will use for the time
51
    repo at http://repo.or.cz/w/libtar.git, which I will use for the time
49
    being.
52
    being.
50
  * Updated debian/watch to look for tags and corresponding snapshot
53
  * Updated debian/watch to look for tags and corresponding snapshot
51
    tarballs at above URL.
54
    tarballs at above URL.
52
  * All patches have been incorporated or (in the case of
55
  * All patches have been incorporated or (in the case of
53
    autoreconf.patch) made obsolete upstream.
56
    autoreconf.patch) made obsolete upstream.
54
  * debian/rules: Add build-indep and build-arch targets.
57
  * debian/rules: Add build-indep and build-arch targets.
55
  * Updated debian/copyright.
58
  * Updated debian/copyright.
56
  * Use dpkg-buildflags to set CFLAGS et al.
59
  * Use dpkg-buildflags to set CFLAGS et al.
57
  * debian/control: Add VCS fields; bump Standards-Version to 3.9.3.
60
  * debian/control: Add VCS fields; bump Standards-Version to 3.9.3.
58
61
59
 -- Magnus Holmgren <holmgren@debian.org>  Sat, 23 Jun 2012 01:03:41 +0200
62
 -- Magnus Holmgren <holmgren@debian.org>  Sat, 23 Jun 2012 01:03:41 +0200
60
63
61
libtar (1.2.11-8) unstable; urgency=low
64
libtar (1.2.11-8) unstable; urgency=low
62
65
63
  * libtool.patch: Set SHELL to the configured shell in those Makefile.in
66
  * libtool.patch: Set SHELL to the configured shell in those Makefile.in
64
    where libtool is used; otherwise libtool fails when /bin/sh is dash
67
    where libtool is used; otherwise libtool fails when /bin/sh is dash
65
    but bash is expected (Closes: #621935).
68
    but bash is expected (Closes: #621935).
66
  * man_hyphen_minus.patch (new): Escape hyphens that should be minus
69
  * man_hyphen_minus.patch (new): Escape hyphens that should be minus
67
    signs in man pages.
70
    signs in man pages.
68
  * Rename libtar as libtar0 to follow policy.
71
  * Rename libtar as libtar0 to follow policy.
69
72
70
 -- Magnus Holmgren <holmgren@debian.org>  Sun, 24 Apr 2011 21:11:52 +0200
73
 -- Magnus Holmgren <holmgren@debian.org>  Sun, 24 Apr 2011 21:11:52 +0200
71
74
72
libtar (1.2.11-7) unstable; urgency=low
75
libtar (1.2.11-7) unstable; urgency=low
73
76
74
  * New maintainer (Closes: #526618).
77
  * New maintainer (Closes: #526618).
75
  * Change source format to 3.0 (quilt), clean up Debian diff and split
78
  * Change source format to 3.0 (quilt), clean up Debian diff and split
76
    into several patches:
79
    into several patches:
77
    * libtool.patch: Using libtool to build dynamic library;
80
    * libtool.patch: Using libtool to build dynamic library;
78
    * autoreconf.patch: Changes needed to call autoreconf (bug 511741);
81
    * autoreconf.patch: Changes needed to call autoreconf (bug 511741);
79
    * memleak.patch: Fix memory leaks;
82
    * memleak.patch: Fix memory leaks;
80
    * bad_ptrtoint.patch: Document stupidity of tartype_t in libtar.c 
83
    * bad_ptrtoint.patch: Document stupidity of tartype_t in libtar.c 
81
      (bug 309945).
84
      (bug 309945).
82
  * Increase Debhelper compat level to 7.
85
  * Increase Debhelper compat level to 7.
83
  * Use dh_autoreconf to avoid having to keep track of files to clean.
86
  * Use dh_autoreconf to avoid having to keep track of files to clean.
84
  * memleak2.patch (new): Applied instead of memleak.patch. Fix memory
87
  * memleak2.patch (new): Applied instead of memleak.patch. Fix memory
85
    leak by making th_get_pathname() return a pointer to a static buffer
88
    leak by making th_get_pathname() return a pointer to a static buffer
86
    instead of a pointer to a copy of a local buffer (LP: #41804).
89
    instead of a pointer to a copy of a local buffer (LP: #41804).
87
  * Add homepage field and watch file (in case there is ever a new
90
  * Add homepage field and watch file (in case there is ever a new
88
    upstream release).
91
    upstream release).
89
  * Upgrade to Standards-Version 3.9.1.
92
  * Upgrade to Standards-Version 3.9.1.
90
93
91
 -- Magnus Holmgren <holmgren@debian.org>  Sat, 26 Mar 2011 23:10:25 +0100
94
 -- Magnus Holmgren <holmgren@debian.org>  Sat, 26 Mar 2011 23:10:25 +0100
92
95
93
libtar (1.2.11-6) unstable; urgency=low
96
libtar (1.2.11-6) unstable; urgency=low
94
97
95
  * Fix autotools usage (Closes: #511741)
98
  * Fix autotools usage (Closes: #511741)
96
99
97
 -- Julien Danjou <acid@debian.org>  Sat, 02 May 2009 11:33:06 +0200
100
 -- Julien Danjou <acid@debian.org>  Sat, 02 May 2009 11:33:06 +0200
98
101
99
libtar (1.2.11-5) unstable; urgency=low
102
libtar (1.2.11-5) unstable; urgency=low
100
103
101
  * New maintainer (Closes: #465889)
104
  * New maintainer (Closes: #465889)
102
  * Add missing binary-indep target in debian/rules (Closes: #395714)
105
  * Add missing binary-indep target in debian/rules (Closes: #395714)
103
  * Use ${binary:Version} instead of Source-Version
106
  * Use ${binary:Version} instead of Source-Version
104
  * Bump standard version
107
  * Bump standard version
105
  * Switch to debhelper 5
108
  * Switch to debhelper 5
106
109
107
 -- Julien Danjou <acid@debian.org>  Wed, 02 Apr 2008 07:06:55 +0200
110
 -- Julien Danjou <acid@debian.org>  Wed, 02 Apr 2008 07:06:55 +0200
108
111
109
libtar (1.2.11-4) unstable; urgency=low
112
libtar (1.2.11-4) unstable; urgency=low
110
113
111
  * Always include the newest libtool.m4.  (Closes: #313612)
114
  * Always include the newest libtool.m4.  (Closes: #313612)
112
115
113
 -- James Morrison <phython@debian.org>  Sun, 28 Aug 2005 09:41:47 -0700
116
 -- James Morrison <phython@debian.org>  Sun, 28 Aug 2005 09:41:47 -0700
114
117
115
libtar (1.2.11-3) unstable; urgency=low
118
libtar (1.2.11-3) unstable; urgency=low
116
119
117
  * Document stupidity of tartype_t in libtar.c.  (Closes: #309945)
120
  * Document stupidity of tartype_t in libtar.c.  (Closes: #309945)
118
121
119
 -- James Morrison <phython@debian.org>  Sat, 11 Jun 2005 18:23:15 -0400
122
 -- James Morrison <phython@debian.org>  Sat, 11 Jun 2005 18:23:15 -0400
120
123
121
libtar (1.2.11-2) unstable; urgency=low
124
libtar (1.2.11-2) unstable; urgency=low
122
125
123
  * Move libtar-dev to libdevel. (Closes: #188207)
126
  * Move libtar-dev to libdevel. (Closes: #188207)
124
  * Fix potential memory leak.
127
  * Fix potential memory leak.
125
128
126
 -- James Morrison <phython@debian.org>  Sun, 25 Jul 2004 12:59:08 -0700
129
 -- James Morrison <phython@debian.org>  Sun, 25 Jul 2004 12:59:08 -0700
127
130
128
libtar (1.2.11-1) unstable; urgency=low
131
libtar (1.2.11-1) unstable; urgency=low
129
132
130
  * New Upstream release.
133
  * New Upstream release.
131
134
132
 -- James Morrison <phython@debian.org>  Sat,  5 Apr 2003 14:03:19 -0500
135
 -- James Morrison <phython@debian.org>  Sat,  5 Apr 2003 14:03:19 -0500
133
136
134
libtar (1.2.10-1) unstable; urgency=low
137
libtar (1.2.10-1) unstable; urgency=low
135
138
136
  * New Upstream release.
139
  * New Upstream release.
137
     (Closes: #166602) New upstream uses autoconf 2.5x
140
     (Closes: #166602) New upstream uses autoconf 2.5x
138
  * Remove dependency on automake.  Hopefully upstream will except this
141
  * Remove dependency on automake.  Hopefully upstream will except this
139
    use of libtool.
142
    use of libtool.
140
  * Remove all -static and -shared targets from debian/rules.
143
  * Remove all -static and -shared targets from debian/rules.
141
  * Use dh_install instead of dh_movefiles.
144
  * Use dh_install instead of dh_movefiles.
142
  * -
145
  * -
143
146
144
 -- James Morrison <phython@debian.org>  Sat,  5 Apr 2003 14:03:16 -0500
147
 -- James Morrison <phython@debian.org>  Sat,  5 Apr 2003 14:03:16 -0500
145
148
146
libtar (1.2.5-4) unstable; urgency=low
149
libtar (1.2.5-4) unstable; urgency=low
147
150
148
  * New maintainer. (Closes: #154597)
151
  * New maintainer. (Closes: #154597)
149
  * WSG_ENCAP is now defined.  (Closes: #147764)
152
  * WSG_ENCAP is now defined.  (Closes: #147764)
150
  * libtar-dev depends on libc-dev instead of libc6-dev. 
153
  * libtar-dev depends on libc-dev instead of libc6-dev. 
151
154
152
 -- James Morrison <phython@debian.org>  Wed, 14 Aug 2002 23:44:16 -0400
155
 -- James Morrison <phython@debian.org>  Wed, 14 Aug 2002 23:44:16 -0400
153
156
154
libtar (1.2.5-3) unstable; urgency=low
157
libtar (1.2.5-3) unstable; urgency=low
155
158
156
  * Modify build commands to acomadate change in autoconf (Closes #147764)
159
  * Modify build commands to acomadate change in autoconf (Closes #147764)
157
160
158
 -- Glenn McGrath <bug1@debian.org>  Thu, 23 May 2002 01:06:16 +1000
161
 -- Glenn McGrath <bug1@debian.org>  Thu, 23 May 2002 01:06:16 +1000
159
162
160
libtar (1.2.5-2) unstable; urgency=low
163
libtar (1.2.5-2) unstable; urgency=low
161
164
162
  * Fix build problem (Closes #135360)
165
  * Fix build problem (Closes #135360)
163
166
164
 -- Glenn McGrath <bug1@debian.org>  Sun, 24 Feb 2002 06:29:31 +1100
167
 -- Glenn McGrath <bug1@debian.org>  Sun, 24 Feb 2002 06:29:31 +1100
165
168
166
libtar (1.2.5-1) unstable; urgency=low
169
libtar (1.2.5-1) unstable; urgency=low
167
170
168
  * New upstream version
171
  * New upstream version
169
  * Change section of libtar-dev to devel and libtar to libs
172
  * Change section of libtar-dev to devel and libtar to libs
170
173
171
 -- Glenn McGrath <bug1@debian.org>  Fri, 22 Feb 2002 04:23:15 +1100
174
 -- Glenn McGrath <bug1@debian.org>  Fri, 22 Feb 2002 04:23:15 +1100
172
175
173
libtar (1.2.4-2) unstable; urgency=low
176
libtar (1.2.4-2) unstable; urgency=low
174
177
175
  * Change section from devel to libs 
178
  * Change section from devel to libs 
176
179
177
 -- Glenn McGrath <bug1@debian.org>  Sat,  2 Feb 2002 12:12:32 +1100
180
 -- Glenn McGrath <bug1@debian.org>  Sat,  2 Feb 2002 12:12:32 +1100
178
181
179
libtar (1.2.4-1) unstable; urgency=low
182
libtar (1.2.4-1) unstable; urgency=low
180
183
181
  * Initial Release. (closes #128042)
184
  * Initial Release. (closes #128042)
182
185
183
 -- Glenn McGrath <bug1@debian.org>  Sat,  5 Jan 2002 13:24:37 +1100
186
 -- Glenn McGrath <bug1@debian.org>  Sat,  5 Jan 2002 13:24:37 +1100
184
187