Subversion Repositories

?revision_form?Rev ?revision_input??revision_submit??revision_endform?

Rev 31 | Rev 36 | Go to most recent revision | Only display areas with differences | Ignore whitespace | Details | Blame | Last modification | View Log | RSS feed

Rev 31 Rev 33
1
libtar (1.2.20-3) unstable; urgency=low
1
libtar (1.2.20-3) unstable; urgency=low
2
2
3
  * no_maxpathlen.patch: Fix two grave bugs in the patch. First,
3
  * no_maxpathlen.patch: Fix two grave bugs in the patch. First,
4
    th_get_pathname would only allocate as much memory as was needed for
4
    th_get_pathname would only allocate as much memory as was needed for
5
    the first filename encountered, causing heap corruption when/if
5
    the first filename encountered, causing heap corruption when/if
6
    encountering longer filenames later. Second, two variables were mixed
6
    encountering longer filenames later. Second, two variables were mixed
7
    up in tar_append_tree(). Also, fix a potential memory leak and trim
7
    up in tar_append_tree(). Also, fix a potential memory leak and trim
8
    the patch a bit.
8
    the patch a bit.
9
  * [SECURITY] CVE-2013-4420.patch: When the prefix field is in use, the
9
  * [SECURITY] CVE-2013-4420.patch: When the prefix field is in use, the
10
    safer_name_suffix() function should certainly be applied to the
10
    safer_name_suffix() function should certainly be applied to the
11
    combination of it and the name field, not just on the name field.
11
    combination of it and the name field, not just on the name field.
-
 
12
  * th_get_size-unsigned-int.patch: Make the th_get_size() macro cast the
-
 
13
    result from oct_to_int() to unsigned int. This is the right fix for
-
 
14
    bug #725938 on 64-bit systems, where a specially crafted tar file
-
 
15
    would not cause an integer overflow, but a memory allocation of almost
-
 
16
    16 exbibytes, which would certainly fail outright without harm.
12
17
13
 -- Magnus Holmgren <holmgren@debian.org>  Sat, 15 Feb 2014 23:21:56 +0100
18
 -- Magnus Holmgren <holmgren@debian.org>  Sat, 15 Feb 2014 23:51:51 +0100
14
19
15
libtar (1.2.20-2) unstable; urgency=low
20
libtar (1.2.20-2) unstable; urgency=low
16
21
17
  * no_static_buffers.patch: avoid using a static buffer in
22
  * no_static_buffers.patch: avoid using a static buffer in
18
    th_get_pathname(). Taken from upstream. Needed for no_maxpathlen.patch.
23
    th_get_pathname(). Taken from upstream. Needed for no_maxpathlen.patch.
19
  * no_maxpathlen.patch: Fix FTBFS on Hurd by dynamically allocating path
24
  * no_maxpathlen.patch: Fix FTBFS on Hurd by dynamically allocating path
20
    names (Closes: #657116). Thanks to Svante Signell and Petter
25
    names (Closes: #657116). Thanks to Svante Signell and Petter
21
    Reinholdtsen.
26
    Reinholdtsen.
22
  * [SECURITY] CVE-2013-4420.patch: Strip out leading slashes and any
27
  * [SECURITY] CVE-2013-4420.patch: Strip out leading slashes and any
23
    pathname prefix containing ".." components (Closes: #731860). This is
28
    pathname prefix containing ".." components (Closes: #731860). This is
24
    done in th_get_pathname() (as well as to symlink targets when
29
    done in th_get_pathname() (as well as to symlink targets when
25
    extracting symlinks), not merely when extracting files, which means
30
    extracting symlinks), not merely when extracting files, which means
26
    applications calling that function will not see the stored
31
    applications calling that function will not see the stored
27
    filename. There is no way to disable this behaviour, but it can be
32
    filename. There is no way to disable this behaviour, but it can be
28
    expected that one will be provided when the issue is solved upstream.
33
    expected that one will be provided when the issue is solved upstream.
29
  * Bump Standards-Version to 3.9.5.
34
  * Bump Standards-Version to 3.9.5.
30
35
31
 -- Magnus Holmgren <holmgren@debian.org>  Sat, 15 Feb 2014 21:49:37 +0100
36
 -- Magnus Holmgren <holmgren@debian.org>  Sat, 15 Feb 2014 21:49:37 +0100
32
37
33
libtar (1.2.20-1) unstable; urgency=high
38
libtar (1.2.20-1) unstable; urgency=high
34
39
35
  * [SECURITY] New upstream release. Fixes CVE-2013-4397: Integer
40
  * [SECURITY] New upstream release. Fixes CVE-2013-4397: Integer
36
    overflow (Closes: #725938).
41
    overflow (Closes: #725938).
37
  * Bump Standards-Version to 3.9.4.
42
  * Bump Standards-Version to 3.9.4.
38
43
39
 -- Magnus Holmgren <holmgren@debian.org>  Thu, 10 Oct 2013 19:20:49 +0200
44
 -- Magnus Holmgren <holmgren@debian.org>  Thu, 10 Oct 2013 19:20:49 +0200
40
45
41
libtar (1.2.19-1) unstable; urgency=low
46
libtar (1.2.19-1) unstable; urgency=low
42
47
43
  * New upstream release.
48
  * New upstream release.
44
49
45
 -- Magnus Holmgren <holmgren@debian.org>  Sun, 05 May 2013 17:59:29 +0200
50
 -- Magnus Holmgren <holmgren@debian.org>  Sun, 05 May 2013 17:59:29 +0200
46
51
47
libtar (1.2.16-1) unstable; urgency=low
52
libtar (1.2.16-1) unstable; urgency=low
48
53
49
  * New upstream: Chris Frey has stepped up with the consent of the
54
  * New upstream: Chris Frey has stepped up with the consent of the
50
    original author, Mark Roth, and published an "official unofficial" git
55
    original author, Mark Roth, and published an "official unofficial" git
51
    repo at http://repo.or.cz/w/libtar.git, which I will use for the time
56
    repo at http://repo.or.cz/w/libtar.git, which I will use for the time
52
    being.
57
    being.
53
  * Updated debian/watch to look for tags and corresponding snapshot
58
  * Updated debian/watch to look for tags and corresponding snapshot
54
    tarballs at above URL.
59
    tarballs at above URL.
55
  * All patches have been incorporated or (in the case of
60
  * All patches have been incorporated or (in the case of
56
    autoreconf.patch) made obsolete upstream.
61
    autoreconf.patch) made obsolete upstream.
57
  * debian/rules: Add build-indep and build-arch targets.
62
  * debian/rules: Add build-indep and build-arch targets.
58
  * Updated debian/copyright.
63
  * Updated debian/copyright.
59
  * Use dpkg-buildflags to set CFLAGS et al.
64
  * Use dpkg-buildflags to set CFLAGS et al.
60
  * debian/control: Add VCS fields; bump Standards-Version to 3.9.3.
65
  * debian/control: Add VCS fields; bump Standards-Version to 3.9.3.
61
66
62
 -- Magnus Holmgren <holmgren@debian.org>  Sat, 23 Jun 2012 01:03:41 +0200
67
 -- Magnus Holmgren <holmgren@debian.org>  Sat, 23 Jun 2012 01:03:41 +0200
63
68
64
libtar (1.2.11-8) unstable; urgency=low
69
libtar (1.2.11-8) unstable; urgency=low
65
70
66
  * libtool.patch: Set SHELL to the configured shell in those Makefile.in
71
  * libtool.patch: Set SHELL to the configured shell in those Makefile.in
67
    where libtool is used; otherwise libtool fails when /bin/sh is dash
72
    where libtool is used; otherwise libtool fails when /bin/sh is dash
68
    but bash is expected (Closes: #621935).
73
    but bash is expected (Closes: #621935).
69
  * man_hyphen_minus.patch (new): Escape hyphens that should be minus
74
  * man_hyphen_minus.patch (new): Escape hyphens that should be minus
70
    signs in man pages.
75
    signs in man pages.
71
  * Rename libtar as libtar0 to follow policy.
76
  * Rename libtar as libtar0 to follow policy.
72
77
73
 -- Magnus Holmgren <holmgren@debian.org>  Sun, 24 Apr 2011 21:11:52 +0200
78
 -- Magnus Holmgren <holmgren@debian.org>  Sun, 24 Apr 2011 21:11:52 +0200
74
79
75
libtar (1.2.11-7) unstable; urgency=low
80
libtar (1.2.11-7) unstable; urgency=low
76
81
77
  * New maintainer (Closes: #526618).
82
  * New maintainer (Closes: #526618).
78
  * Change source format to 3.0 (quilt), clean up Debian diff and split
83
  * Change source format to 3.0 (quilt), clean up Debian diff and split
79
    into several patches:
84
    into several patches:
80
    * libtool.patch: Using libtool to build dynamic library;
85
    * libtool.patch: Using libtool to build dynamic library;
81
    * autoreconf.patch: Changes needed to call autoreconf (bug 511741);
86
    * autoreconf.patch: Changes needed to call autoreconf (bug 511741);
82
    * memleak.patch: Fix memory leaks;
87
    * memleak.patch: Fix memory leaks;
83
    * bad_ptrtoint.patch: Document stupidity of tartype_t in libtar.c 
88
    * bad_ptrtoint.patch: Document stupidity of tartype_t in libtar.c 
84
      (bug 309945).
89
      (bug 309945).
85
  * Increase Debhelper compat level to 7.
90
  * Increase Debhelper compat level to 7.
86
  * Use dh_autoreconf to avoid having to keep track of files to clean.
91
  * Use dh_autoreconf to avoid having to keep track of files to clean.
87
  * memleak2.patch (new): Applied instead of memleak.patch. Fix memory
92
  * memleak2.patch (new): Applied instead of memleak.patch. Fix memory
88
    leak by making th_get_pathname() return a pointer to a static buffer
93
    leak by making th_get_pathname() return a pointer to a static buffer
89
    instead of a pointer to a copy of a local buffer (LP: #41804).
94
    instead of a pointer to a copy of a local buffer (LP: #41804).
90
  * Add homepage field and watch file (in case there is ever a new
95
  * Add homepage field and watch file (in case there is ever a new
91
    upstream release).
96
    upstream release).
92
  * Upgrade to Standards-Version 3.9.1.
97
  * Upgrade to Standards-Version 3.9.1.
93
98
94
 -- Magnus Holmgren <holmgren@debian.org>  Sat, 26 Mar 2011 23:10:25 +0100
99
 -- Magnus Holmgren <holmgren@debian.org>  Sat, 26 Mar 2011 23:10:25 +0100
95
100
96
libtar (1.2.11-6) unstable; urgency=low
101
libtar (1.2.11-6) unstable; urgency=low
97
102
98
  * Fix autotools usage (Closes: #511741)
103
  * Fix autotools usage (Closes: #511741)
99
104
100
 -- Julien Danjou <acid@debian.org>  Sat, 02 May 2009 11:33:06 +0200
105
 -- Julien Danjou <acid@debian.org>  Sat, 02 May 2009 11:33:06 +0200
101
106
102
libtar (1.2.11-5) unstable; urgency=low
107
libtar (1.2.11-5) unstable; urgency=low
103
108
104
  * New maintainer (Closes: #465889)
109
  * New maintainer (Closes: #465889)
105
  * Add missing binary-indep target in debian/rules (Closes: #395714)
110
  * Add missing binary-indep target in debian/rules (Closes: #395714)
106
  * Use ${binary:Version} instead of Source-Version
111
  * Use ${binary:Version} instead of Source-Version
107
  * Bump standard version
112
  * Bump standard version
108
  * Switch to debhelper 5
113
  * Switch to debhelper 5
109
114
110
 -- Julien Danjou <acid@debian.org>  Wed, 02 Apr 2008 07:06:55 +0200
115
 -- Julien Danjou <acid@debian.org>  Wed, 02 Apr 2008 07:06:55 +0200
111
116
112
libtar (1.2.11-4) unstable; urgency=low
117
libtar (1.2.11-4) unstable; urgency=low
113
118
114
  * Always include the newest libtool.m4.  (Closes: #313612)
119
  * Always include the newest libtool.m4.  (Closes: #313612)
115
120
116
 -- James Morrison <phython@debian.org>  Sun, 28 Aug 2005 09:41:47 -0700
121
 -- James Morrison <phython@debian.org>  Sun, 28 Aug 2005 09:41:47 -0700
117
122
118
libtar (1.2.11-3) unstable; urgency=low
123
libtar (1.2.11-3) unstable; urgency=low
119
124
120
  * Document stupidity of tartype_t in libtar.c.  (Closes: #309945)
125
  * Document stupidity of tartype_t in libtar.c.  (Closes: #309945)
121
126
122
 -- James Morrison <phython@debian.org>  Sat, 11 Jun 2005 18:23:15 -0400
127
 -- James Morrison <phython@debian.org>  Sat, 11 Jun 2005 18:23:15 -0400
123
128
124
libtar (1.2.11-2) unstable; urgency=low
129
libtar (1.2.11-2) unstable; urgency=low
125
130
126
  * Move libtar-dev to libdevel. (Closes: #188207)
131
  * Move libtar-dev to libdevel. (Closes: #188207)
127
  * Fix potential memory leak.
132
  * Fix potential memory leak.
128
133
129
 -- James Morrison <phython@debian.org>  Sun, 25 Jul 2004 12:59:08 -0700
134
 -- James Morrison <phython@debian.org>  Sun, 25 Jul 2004 12:59:08 -0700
130
135
131
libtar (1.2.11-1) unstable; urgency=low
136
libtar (1.2.11-1) unstable; urgency=low
132
137
133
  * New Upstream release.
138
  * New Upstream release.
134
139
135
 -- James Morrison <phython@debian.org>  Sat,  5 Apr 2003 14:03:19 -0500
140
 -- James Morrison <phython@debian.org>  Sat,  5 Apr 2003 14:03:19 -0500
136
141
137
libtar (1.2.10-1) unstable; urgency=low
142
libtar (1.2.10-1) unstable; urgency=low
138
143
139
  * New Upstream release.
144
  * New Upstream release.
140
     (Closes: #166602) New upstream uses autoconf 2.5x
145
     (Closes: #166602) New upstream uses autoconf 2.5x
141
  * Remove dependency on automake.  Hopefully upstream will except this
146
  * Remove dependency on automake.  Hopefully upstream will except this
142
    use of libtool.
147
    use of libtool.
143
  * Remove all -static and -shared targets from debian/rules.
148
  * Remove all -static and -shared targets from debian/rules.
144
  * Use dh_install instead of dh_movefiles.
149
  * Use dh_install instead of dh_movefiles.
145
  * -
150
  * -
146
151
147
 -- James Morrison <phython@debian.org>  Sat,  5 Apr 2003 14:03:16 -0500
152
 -- James Morrison <phython@debian.org>  Sat,  5 Apr 2003 14:03:16 -0500
148
153
149
libtar (1.2.5-4) unstable; urgency=low
154
libtar (1.2.5-4) unstable; urgency=low
150
155
151
  * New maintainer. (Closes: #154597)
156
  * New maintainer. (Closes: #154597)
152
  * WSG_ENCAP is now defined.  (Closes: #147764)
157
  * WSG_ENCAP is now defined.  (Closes: #147764)
153
  * libtar-dev depends on libc-dev instead of libc6-dev. 
158
  * libtar-dev depends on libc-dev instead of libc6-dev. 
154
159
155
 -- James Morrison <phython@debian.org>  Wed, 14 Aug 2002 23:44:16 -0400
160
 -- James Morrison <phython@debian.org>  Wed, 14 Aug 2002 23:44:16 -0400
156
161
157
libtar (1.2.5-3) unstable; urgency=low
162
libtar (1.2.5-3) unstable; urgency=low
158
163
159
  * Modify build commands to acomadate change in autoconf (Closes #147764)
164
  * Modify build commands to acomadate change in autoconf (Closes #147764)
160
165
161
 -- Glenn McGrath <bug1@debian.org>  Thu, 23 May 2002 01:06:16 +1000
166
 -- Glenn McGrath <bug1@debian.org>  Thu, 23 May 2002 01:06:16 +1000
162
167
163
libtar (1.2.5-2) unstable; urgency=low
168
libtar (1.2.5-2) unstable; urgency=low
164
169
165
  * Fix build problem (Closes #135360)
170
  * Fix build problem (Closes #135360)
166
171
167
 -- Glenn McGrath <bug1@debian.org>  Sun, 24 Feb 2002 06:29:31 +1100
172
 -- Glenn McGrath <bug1@debian.org>  Sun, 24 Feb 2002 06:29:31 +1100
168
173
169
libtar (1.2.5-1) unstable; urgency=low
174
libtar (1.2.5-1) unstable; urgency=low
170
175
171
  * New upstream version
176
  * New upstream version
172
  * Change section of libtar-dev to devel and libtar to libs
177
  * Change section of libtar-dev to devel and libtar to libs
173
178
174
 -- Glenn McGrath <bug1@debian.org>  Fri, 22 Feb 2002 04:23:15 +1100
179
 -- Glenn McGrath <bug1@debian.org>  Fri, 22 Feb 2002 04:23:15 +1100
175
180
176
libtar (1.2.4-2) unstable; urgency=low
181
libtar (1.2.4-2) unstable; urgency=low
177
182
178
  * Change section from devel to libs 
183
  * Change section from devel to libs 
179
184
180
 -- Glenn McGrath <bug1@debian.org>  Sat,  2 Feb 2002 12:12:32 +1100
185
 -- Glenn McGrath <bug1@debian.org>  Sat,  2 Feb 2002 12:12:32 +1100
181
186
182
libtar (1.2.4-1) unstable; urgency=low
187
libtar (1.2.4-1) unstable; urgency=low
183
188
184
  * Initial Release. (closes #128042)
189
  * Initial Release. (closes #128042)
185
190
186
 -- Glenn McGrath <bug1@debian.org>  Sat,  5 Jan 2002 13:24:37 +1100
191
 -- Glenn McGrath <bug1@debian.org>  Sat,  5 Jan 2002 13:24:37 +1100
187
192