Subversion Repositories

?revision_form?Rev ?revision_input??revision_submit??revision_endform?

Rev 33 | Rev 38 | Go to most recent revision | Only display areas with differences | Ignore whitespace | Details | Blame | Last modification | View Log | RSS feed

Rev 33 Rev 36
-
 
1
libtar (1.2.20-4) unstable; urgency=high
-
 
2
-
 
3
  * no_maxpathlen.patch: Half of the part of the patch modifying
-
 
4
    compat/dirname.c was missing, causing libtar's dirname to always
-
 
5
    return NULL (except in special circumstances). Actually make it work
-
 
6
    (Closes: #745352). (The reason that libtar doesn't use libc's
-
 
7
    dirname() and basename() on some or most platforms is that the code
-
 
8
    doesn't work with destructive versions of these functions).
-
 
9
-
 
10
 -- Magnus Holmgren <holmgren@debian.org>  Sat, 03 May 2014 20:39:02 +0200
-
 
11
1
libtar (1.2.20-3) unstable; urgency=low
12
libtar (1.2.20-3) unstable; urgency=low
2
13
3
  * no_maxpathlen.patch: Fix two grave bugs in the patch. First,
14
  * no_maxpathlen.patch: Fix two grave bugs in the patch. First,
4
    th_get_pathname would only allocate as much memory as was needed for
15
    th_get_pathname would only allocate as much memory as was needed for
5
    the first filename encountered, causing heap corruption when/if
16
    the first filename encountered, causing heap corruption when/if
6
    encountering longer filenames later. Second, two variables were mixed
17
    encountering longer filenames later. Second, two variables were mixed
7
    up in tar_append_tree(). Also, fix a potential memory leak and trim
18
    up in tar_append_tree(). Also, fix a potential memory leak and trim
8
    the patch a bit.
19
    the patch a bit.
9
  * [SECURITY] CVE-2013-4420.patch: When the prefix field is in use, the
20
  * [SECURITY] CVE-2013-4420.patch: When the prefix field is in use, the
10
    safer_name_suffix() function should certainly be applied to the
21
    safer_name_suffix() function should certainly be applied to the
11
    combination of it and the name field, not just on the name field.
22
    combination of it and the name field, not just on the name field.
12
  * th_get_size-unsigned-int.patch: Make the th_get_size() macro cast the
23
  * th_get_size-unsigned-int.patch: Make the th_get_size() macro cast the
13
    result from oct_to_int() to unsigned int. This is the right fix for
24
    result from oct_to_int() to unsigned int. This is the right fix for
14
    bug #725938 on 64-bit systems, where a specially crafted tar file
25
    bug #725938 on 64-bit systems, where a specially crafted tar file
15
    would not cause an integer overflow, but a memory allocation of almost
26
    would not cause an integer overflow, but a memory allocation of almost
16
    16 exbibytes, which would certainly fail outright without harm.
27
    16 exbibytes, which would certainly fail outright without harm.
17
28
18
 -- Magnus Holmgren <holmgren@debian.org>  Sat, 15 Feb 2014 23:51:51 +0100
29
 -- Magnus Holmgren <holmgren@debian.org>  Sat, 15 Feb 2014 23:51:51 +0100
19
30
20
libtar (1.2.20-2) unstable; urgency=low
31
libtar (1.2.20-2) unstable; urgency=low
21
32
22
  * no_static_buffers.patch: avoid using a static buffer in
33
  * no_static_buffers.patch: avoid using a static buffer in
23
    th_get_pathname(). Taken from upstream. Needed for no_maxpathlen.patch.
34
    th_get_pathname(). Taken from upstream. Needed for no_maxpathlen.patch.
24
  * no_maxpathlen.patch: Fix FTBFS on Hurd by dynamically allocating path
35
  * no_maxpathlen.patch: Fix FTBFS on Hurd by dynamically allocating path
25
    names (Closes: #657116). Thanks to Svante Signell and Petter
36
    names (Closes: #657116). Thanks to Svante Signell and Petter
26
    Reinholdtsen.
37
    Reinholdtsen.
27
  * [SECURITY] CVE-2013-4420.patch: Strip out leading slashes and any
38
  * [SECURITY] CVE-2013-4420.patch: Strip out leading slashes and any
28
    pathname prefix containing ".." components (Closes: #731860). This is
39
    pathname prefix containing ".." components (Closes: #731860). This is
29
    done in th_get_pathname() (as well as to symlink targets when
40
    done in th_get_pathname() (as well as to symlink targets when
30
    extracting symlinks), not merely when extracting files, which means
41
    extracting symlinks), not merely when extracting files, which means
31
    applications calling that function will not see the stored
42
    applications calling that function will not see the stored
32
    filename. There is no way to disable this behaviour, but it can be
43
    filename. There is no way to disable this behaviour, but it can be
33
    expected that one will be provided when the issue is solved upstream.
44
    expected that one will be provided when the issue is solved upstream.
34
  * Bump Standards-Version to 3.9.5.
45
  * Bump Standards-Version to 3.9.5.
35
46
36
 -- Magnus Holmgren <holmgren@debian.org>  Sat, 15 Feb 2014 21:49:37 +0100
47
 -- Magnus Holmgren <holmgren@debian.org>  Sat, 15 Feb 2014 21:49:37 +0100
37
48
38
libtar (1.2.20-1) unstable; urgency=high
49
libtar (1.2.20-1) unstable; urgency=high
39
50
40
  * [SECURITY] New upstream release. Fixes CVE-2013-4397: Integer
51
  * [SECURITY] New upstream release. Fixes CVE-2013-4397: Integer
41
    overflow (Closes: #725938).
52
    overflow (Closes: #725938).
42
  * Bump Standards-Version to 3.9.4.
53
  * Bump Standards-Version to 3.9.4.
43
54
44
 -- Magnus Holmgren <holmgren@debian.org>  Thu, 10 Oct 2013 19:20:49 +0200
55
 -- Magnus Holmgren <holmgren@debian.org>  Thu, 10 Oct 2013 19:20:49 +0200
45
56
46
libtar (1.2.19-1) unstable; urgency=low
57
libtar (1.2.19-1) unstable; urgency=low
47
58
48
  * New upstream release.
59
  * New upstream release.
49
60
50
 -- Magnus Holmgren <holmgren@debian.org>  Sun, 05 May 2013 17:59:29 +0200
61
 -- Magnus Holmgren <holmgren@debian.org>  Sun, 05 May 2013 17:59:29 +0200
51
62
52
libtar (1.2.16-1) unstable; urgency=low
63
libtar (1.2.16-1) unstable; urgency=low
53
64
54
  * New upstream: Chris Frey has stepped up with the consent of the
65
  * New upstream: Chris Frey has stepped up with the consent of the
55
    original author, Mark Roth, and published an "official unofficial" git
66
    original author, Mark Roth, and published an "official unofficial" git
56
    repo at http://repo.or.cz/w/libtar.git, which I will use for the time
67
    repo at http://repo.or.cz/w/libtar.git, which I will use for the time
57
    being.
68
    being.
58
  * Updated debian/watch to look for tags and corresponding snapshot
69
  * Updated debian/watch to look for tags and corresponding snapshot
59
    tarballs at above URL.
70
    tarballs at above URL.
60
  * All patches have been incorporated or (in the case of
71
  * All patches have been incorporated or (in the case of
61
    autoreconf.patch) made obsolete upstream.
72
    autoreconf.patch) made obsolete upstream.
62
  * debian/rules: Add build-indep and build-arch targets.
73
  * debian/rules: Add build-indep and build-arch targets.
63
  * Updated debian/copyright.
74
  * Updated debian/copyright.
64
  * Use dpkg-buildflags to set CFLAGS et al.
75
  * Use dpkg-buildflags to set CFLAGS et al.
65
  * debian/control: Add VCS fields; bump Standards-Version to 3.9.3.
76
  * debian/control: Add VCS fields; bump Standards-Version to 3.9.3.
66
77
67
 -- Magnus Holmgren <holmgren@debian.org>  Sat, 23 Jun 2012 01:03:41 +0200
78
 -- Magnus Holmgren <holmgren@debian.org>  Sat, 23 Jun 2012 01:03:41 +0200
68
79
69
libtar (1.2.11-8) unstable; urgency=low
80
libtar (1.2.11-8) unstable; urgency=low
70
81
71
  * libtool.patch: Set SHELL to the configured shell in those Makefile.in
82
  * libtool.patch: Set SHELL to the configured shell in those Makefile.in
72
    where libtool is used; otherwise libtool fails when /bin/sh is dash
83
    where libtool is used; otherwise libtool fails when /bin/sh is dash
73
    but bash is expected (Closes: #621935).
84
    but bash is expected (Closes: #621935).
74
  * man_hyphen_minus.patch (new): Escape hyphens that should be minus
85
  * man_hyphen_minus.patch (new): Escape hyphens that should be minus
75
    signs in man pages.
86
    signs in man pages.
76
  * Rename libtar as libtar0 to follow policy.
87
  * Rename libtar as libtar0 to follow policy.
77
88
78
 -- Magnus Holmgren <holmgren@debian.org>  Sun, 24 Apr 2011 21:11:52 +0200
89
 -- Magnus Holmgren <holmgren@debian.org>  Sun, 24 Apr 2011 21:11:52 +0200
79
90
80
libtar (1.2.11-7) unstable; urgency=low
91
libtar (1.2.11-7) unstable; urgency=low
81
92
82
  * New maintainer (Closes: #526618).
93
  * New maintainer (Closes: #526618).
83
  * Change source format to 3.0 (quilt), clean up Debian diff and split
94
  * Change source format to 3.0 (quilt), clean up Debian diff and split
84
    into several patches:
95
    into several patches:
85
    * libtool.patch: Using libtool to build dynamic library;
96
    * libtool.patch: Using libtool to build dynamic library;
86
    * autoreconf.patch: Changes needed to call autoreconf (bug 511741);
97
    * autoreconf.patch: Changes needed to call autoreconf (bug 511741);
87
    * memleak.patch: Fix memory leaks;
98
    * memleak.patch: Fix memory leaks;
88
    * bad_ptrtoint.patch: Document stupidity of tartype_t in libtar.c 
99
    * bad_ptrtoint.patch: Document stupidity of tartype_t in libtar.c 
89
      (bug 309945).
100
      (bug 309945).
90
  * Increase Debhelper compat level to 7.
101
  * Increase Debhelper compat level to 7.
91
  * Use dh_autoreconf to avoid having to keep track of files to clean.
102
  * Use dh_autoreconf to avoid having to keep track of files to clean.
92
  * memleak2.patch (new): Applied instead of memleak.patch. Fix memory
103
  * memleak2.patch (new): Applied instead of memleak.patch. Fix memory
93
    leak by making th_get_pathname() return a pointer to a static buffer
104
    leak by making th_get_pathname() return a pointer to a static buffer
94
    instead of a pointer to a copy of a local buffer (LP: #41804).
105
    instead of a pointer to a copy of a local buffer (LP: #41804).
95
  * Add homepage field and watch file (in case there is ever a new
106
  * Add homepage field and watch file (in case there is ever a new
96
    upstream release).
107
    upstream release).
97
  * Upgrade to Standards-Version 3.9.1.
108
  * Upgrade to Standards-Version 3.9.1.
98
109
99
 -- Magnus Holmgren <holmgren@debian.org>  Sat, 26 Mar 2011 23:10:25 +0100
110
 -- Magnus Holmgren <holmgren@debian.org>  Sat, 26 Mar 2011 23:10:25 +0100
100
111
101
libtar (1.2.11-6) unstable; urgency=low
112
libtar (1.2.11-6) unstable; urgency=low
102
113
103
  * Fix autotools usage (Closes: #511741)
114
  * Fix autotools usage (Closes: #511741)
104
115
105
 -- Julien Danjou <acid@debian.org>  Sat, 02 May 2009 11:33:06 +0200
116
 -- Julien Danjou <acid@debian.org>  Sat, 02 May 2009 11:33:06 +0200
106
117
107
libtar (1.2.11-5) unstable; urgency=low
118
libtar (1.2.11-5) unstable; urgency=low
108
119
109
  * New maintainer (Closes: #465889)
120
  * New maintainer (Closes: #465889)
110
  * Add missing binary-indep target in debian/rules (Closes: #395714)
121
  * Add missing binary-indep target in debian/rules (Closes: #395714)
111
  * Use ${binary:Version} instead of Source-Version
122
  * Use ${binary:Version} instead of Source-Version
112
  * Bump standard version
123
  * Bump standard version
113
  * Switch to debhelper 5
124
  * Switch to debhelper 5
114
125
115
 -- Julien Danjou <acid@debian.org>  Wed, 02 Apr 2008 07:06:55 +0200
126
 -- Julien Danjou <acid@debian.org>  Wed, 02 Apr 2008 07:06:55 +0200
116
127
117
libtar (1.2.11-4) unstable; urgency=low
128
libtar (1.2.11-4) unstable; urgency=low
118
129
119
  * Always include the newest libtool.m4.  (Closes: #313612)
130
  * Always include the newest libtool.m4.  (Closes: #313612)
120
131
121
 -- James Morrison <phython@debian.org>  Sun, 28 Aug 2005 09:41:47 -0700
132
 -- James Morrison <phython@debian.org>  Sun, 28 Aug 2005 09:41:47 -0700
122
133
123
libtar (1.2.11-3) unstable; urgency=low
134
libtar (1.2.11-3) unstable; urgency=low
124
135
125
  * Document stupidity of tartype_t in libtar.c.  (Closes: #309945)
136
  * Document stupidity of tartype_t in libtar.c.  (Closes: #309945)
126
137
127
 -- James Morrison <phython@debian.org>  Sat, 11 Jun 2005 18:23:15 -0400
138
 -- James Morrison <phython@debian.org>  Sat, 11 Jun 2005 18:23:15 -0400
128
139
129
libtar (1.2.11-2) unstable; urgency=low
140
libtar (1.2.11-2) unstable; urgency=low
130
141
131
  * Move libtar-dev to libdevel. (Closes: #188207)
142
  * Move libtar-dev to libdevel. (Closes: #188207)
132
  * Fix potential memory leak.
143
  * Fix potential memory leak.
133
144
134
 -- James Morrison <phython@debian.org>  Sun, 25 Jul 2004 12:59:08 -0700
145
 -- James Morrison <phython@debian.org>  Sun, 25 Jul 2004 12:59:08 -0700
135
146
136
libtar (1.2.11-1) unstable; urgency=low
147
libtar (1.2.11-1) unstable; urgency=low
137
148
138
  * New Upstream release.
149
  * New Upstream release.
139
150
140
 -- James Morrison <phython@debian.org>  Sat,  5 Apr 2003 14:03:19 -0500
151
 -- James Morrison <phython@debian.org>  Sat,  5 Apr 2003 14:03:19 -0500
141
152
142
libtar (1.2.10-1) unstable; urgency=low
153
libtar (1.2.10-1) unstable; urgency=low
143
154
144
  * New Upstream release.
155
  * New Upstream release.
145
     (Closes: #166602) New upstream uses autoconf 2.5x
156
     (Closes: #166602) New upstream uses autoconf 2.5x
146
  * Remove dependency on automake.  Hopefully upstream will except this
157
  * Remove dependency on automake.  Hopefully upstream will except this
147
    use of libtool.
158
    use of libtool.
148
  * Remove all -static and -shared targets from debian/rules.
159
  * Remove all -static and -shared targets from debian/rules.
149
  * Use dh_install instead of dh_movefiles.
160
  * Use dh_install instead of dh_movefiles.
150
  * -
161
  * -
151
162
152
 -- James Morrison <phython@debian.org>  Sat,  5 Apr 2003 14:03:16 -0500
163
 -- James Morrison <phython@debian.org>  Sat,  5 Apr 2003 14:03:16 -0500
153
164
154
libtar (1.2.5-4) unstable; urgency=low
165
libtar (1.2.5-4) unstable; urgency=low
155
166
156
  * New maintainer. (Closes: #154597)
167
  * New maintainer. (Closes: #154597)
157
  * WSG_ENCAP is now defined.  (Closes: #147764)
168
  * WSG_ENCAP is now defined.  (Closes: #147764)
158
  * libtar-dev depends on libc-dev instead of libc6-dev. 
169
  * libtar-dev depends on libc-dev instead of libc6-dev. 
159
170
160
 -- James Morrison <phython@debian.org>  Wed, 14 Aug 2002 23:44:16 -0400
171
 -- James Morrison <phython@debian.org>  Wed, 14 Aug 2002 23:44:16 -0400
161
172
162
libtar (1.2.5-3) unstable; urgency=low
173
libtar (1.2.5-3) unstable; urgency=low
163
174
164
  * Modify build commands to acomadate change in autoconf (Closes #147764)
175
  * Modify build commands to acomadate change in autoconf (Closes #147764)
165
176
166
 -- Glenn McGrath <bug1@debian.org>  Thu, 23 May 2002 01:06:16 +1000
177
 -- Glenn McGrath <bug1@debian.org>  Thu, 23 May 2002 01:06:16 +1000
167
178
168
libtar (1.2.5-2) unstable; urgency=low
179
libtar (1.2.5-2) unstable; urgency=low
169
180
170
  * Fix build problem (Closes #135360)
181
  * Fix build problem (Closes #135360)
171
182
172
 -- Glenn McGrath <bug1@debian.org>  Sun, 24 Feb 2002 06:29:31 +1100
183
 -- Glenn McGrath <bug1@debian.org>  Sun, 24 Feb 2002 06:29:31 +1100
173
184
174
libtar (1.2.5-1) unstable; urgency=low
185
libtar (1.2.5-1) unstable; urgency=low
175
186
176
  * New upstream version
187
  * New upstream version
177
  * Change section of libtar-dev to devel and libtar to libs
188
  * Change section of libtar-dev to devel and libtar to libs
178
189
179
 -- Glenn McGrath <bug1@debian.org>  Fri, 22 Feb 2002 04:23:15 +1100
190
 -- Glenn McGrath <bug1@debian.org>  Fri, 22 Feb 2002 04:23:15 +1100
180
191
181
libtar (1.2.4-2) unstable; urgency=low
192
libtar (1.2.4-2) unstable; urgency=low
182
193
183
  * Change section from devel to libs 
194
  * Change section from devel to libs 
184
195
185
 -- Glenn McGrath <bug1@debian.org>  Sat,  2 Feb 2002 12:12:32 +1100
196
 -- Glenn McGrath <bug1@debian.org>  Sat,  2 Feb 2002 12:12:32 +1100
186
197
187
libtar (1.2.4-1) unstable; urgency=low
198
libtar (1.2.4-1) unstable; urgency=low
188
199
189
  * Initial Release. (closes #128042)
200
  * Initial Release. (closes #128042)
190
201
191
 -- Glenn McGrath <bug1@debian.org>  Sat,  5 Jan 2002 13:24:37 +1100
202
 -- Glenn McGrath <bug1@debian.org>  Sat,  5 Jan 2002 13:24:37 +1100
192
203