Subversion Repositories

?revision_form?Rev ?revision_input??revision_submit??revision_endform?

Rev 36 | Rev 39 | Go to most recent revision | Only display areas with differences | Ignore whitespace | Details | Blame | Last modification | View Log | RSS feed

Rev 36 Rev 38
-
 
1
libtar (1.2.20-5) unstable; urgency=low
-
 
2
-
 
3
  * oldgnu_prefix.patch: Detect old-style GNU headers correctly (Closes:
-
 
4
    #763119). Those appear in incremental archives and use the bytes that
-
 
5
    the new-style headers use for the prefix field for other fields.
-
 
6
    Thanks to Steinar H. Gunderson.
-
 
7
-
 
8
 -- Magnus Holmgren <holmgren@debian.org>  Sun, 12 Oct 2014 21:45:42 +0200
-
 
9
1
libtar (1.2.20-4) unstable; urgency=high
10
libtar (1.2.20-4) unstable; urgency=high
2
11
3
  * no_maxpathlen.patch: Half of the part of the patch modifying
12
  * no_maxpathlen.patch: Half of the part of the patch modifying
4
    compat/dirname.c was missing, causing libtar's dirname to always
13
    compat/dirname.c was missing, causing libtar's dirname to always
5
    return NULL (except in special circumstances). Actually make it work
14
    return NULL (except in special circumstances). Actually make it work
6
    (Closes: #745352). (The reason that libtar doesn't use libc's
15
    (Closes: #745352). (The reason that libtar doesn't use libc's
7
    dirname() and basename() on some or most platforms is that the code
16
    dirname() and basename() on some or most platforms is that the code
8
    doesn't work with destructive versions of these functions).
17
    doesn't work with destructive versions of these functions).
9
18
10
 -- Magnus Holmgren <holmgren@debian.org>  Sat, 03 May 2014 20:39:02 +0200
19
 -- Magnus Holmgren <holmgren@debian.org>  Sat, 03 May 2014 20:39:02 +0200
11
20
12
libtar (1.2.20-3) unstable; urgency=low
21
libtar (1.2.20-3) unstable; urgency=low
13
22
14
  * no_maxpathlen.patch: Fix two grave bugs in the patch. First,
23
  * no_maxpathlen.patch: Fix two grave bugs in the patch. First,
15
    th_get_pathname would only allocate as much memory as was needed for
24
    th_get_pathname would only allocate as much memory as was needed for
16
    the first filename encountered, causing heap corruption when/if
25
    the first filename encountered, causing heap corruption when/if
17
    encountering longer filenames later. Second, two variables were mixed
26
    encountering longer filenames later. Second, two variables were mixed
18
    up in tar_append_tree(). Also, fix a potential memory leak and trim
27
    up in tar_append_tree(). Also, fix a potential memory leak and trim
19
    the patch a bit.
28
    the patch a bit.
20
  * [SECURITY] CVE-2013-4420.patch: When the prefix field is in use, the
29
  * [SECURITY] CVE-2013-4420.patch: When the prefix field is in use, the
21
    safer_name_suffix() function should certainly be applied to the
30
    safer_name_suffix() function should certainly be applied to the
22
    combination of it and the name field, not just on the name field.
31
    combination of it and the name field, not just on the name field.
23
  * th_get_size-unsigned-int.patch: Make the th_get_size() macro cast the
32
  * th_get_size-unsigned-int.patch: Make the th_get_size() macro cast the
24
    result from oct_to_int() to unsigned int. This is the right fix for
33
    result from oct_to_int() to unsigned int. This is the right fix for
25
    bug #725938 on 64-bit systems, where a specially crafted tar file
34
    bug #725938 on 64-bit systems, where a specially crafted tar file
26
    would not cause an integer overflow, but a memory allocation of almost
35
    would not cause an integer overflow, but a memory allocation of almost
27
    16 exbibytes, which would certainly fail outright without harm.
36
    16 exbibytes, which would certainly fail outright without harm.
28
37
29
 -- Magnus Holmgren <holmgren@debian.org>  Sat, 15 Feb 2014 23:51:51 +0100
38
 -- Magnus Holmgren <holmgren@debian.org>  Sat, 15 Feb 2014 23:51:51 +0100
30
39
31
libtar (1.2.20-2) unstable; urgency=low
40
libtar (1.2.20-2) unstable; urgency=low
32
41
33
  * no_static_buffers.patch: avoid using a static buffer in
42
  * no_static_buffers.patch: avoid using a static buffer in
34
    th_get_pathname(). Taken from upstream. Needed for no_maxpathlen.patch.
43
    th_get_pathname(). Taken from upstream. Needed for no_maxpathlen.patch.
35
  * no_maxpathlen.patch: Fix FTBFS on Hurd by dynamically allocating path
44
  * no_maxpathlen.patch: Fix FTBFS on Hurd by dynamically allocating path
36
    names (Closes: #657116). Thanks to Svante Signell and Petter
45
    names (Closes: #657116). Thanks to Svante Signell and Petter
37
    Reinholdtsen.
46
    Reinholdtsen.
38
  * [SECURITY] CVE-2013-4420.patch: Strip out leading slashes and any
47
  * [SECURITY] CVE-2013-4420.patch: Strip out leading slashes and any
39
    pathname prefix containing ".." components (Closes: #731860). This is
48
    pathname prefix containing ".." components (Closes: #731860). This is
40
    done in th_get_pathname() (as well as to symlink targets when
49
    done in th_get_pathname() (as well as to symlink targets when
41
    extracting symlinks), not merely when extracting files, which means
50
    extracting symlinks), not merely when extracting files, which means
42
    applications calling that function will not see the stored
51
    applications calling that function will not see the stored
43
    filename. There is no way to disable this behaviour, but it can be
52
    filename. There is no way to disable this behaviour, but it can be
44
    expected that one will be provided when the issue is solved upstream.
53
    expected that one will be provided when the issue is solved upstream.
45
  * Bump Standards-Version to 3.9.5.
54
  * Bump Standards-Version to 3.9.5.
46
55
47
 -- Magnus Holmgren <holmgren@debian.org>  Sat, 15 Feb 2014 21:49:37 +0100
56
 -- Magnus Holmgren <holmgren@debian.org>  Sat, 15 Feb 2014 21:49:37 +0100
48
57
49
libtar (1.2.20-1) unstable; urgency=high
58
libtar (1.2.20-1) unstable; urgency=high
50
59
51
  * [SECURITY] New upstream release. Fixes CVE-2013-4397: Integer
60
  * [SECURITY] New upstream release. Fixes CVE-2013-4397: Integer
52
    overflow (Closes: #725938).
61
    overflow (Closes: #725938).
53
  * Bump Standards-Version to 3.9.4.
62
  * Bump Standards-Version to 3.9.4.
54
63
55
 -- Magnus Holmgren <holmgren@debian.org>  Thu, 10 Oct 2013 19:20:49 +0200
64
 -- Magnus Holmgren <holmgren@debian.org>  Thu, 10 Oct 2013 19:20:49 +0200
56
65
57
libtar (1.2.19-1) unstable; urgency=low
66
libtar (1.2.19-1) unstable; urgency=low
58
67
59
  * New upstream release.
68
  * New upstream release.
60
69
61
 -- Magnus Holmgren <holmgren@debian.org>  Sun, 05 May 2013 17:59:29 +0200
70
 -- Magnus Holmgren <holmgren@debian.org>  Sun, 05 May 2013 17:59:29 +0200
62
71
63
libtar (1.2.16-1) unstable; urgency=low
72
libtar (1.2.16-1) unstable; urgency=low
64
73
65
  * New upstream: Chris Frey has stepped up with the consent of the
74
  * New upstream: Chris Frey has stepped up with the consent of the
66
    original author, Mark Roth, and published an "official unofficial" git
75
    original author, Mark Roth, and published an "official unofficial" git
67
    repo at http://repo.or.cz/w/libtar.git, which I will use for the time
76
    repo at http://repo.or.cz/w/libtar.git, which I will use for the time
68
    being.
77
    being.
69
  * Updated debian/watch to look for tags and corresponding snapshot
78
  * Updated debian/watch to look for tags and corresponding snapshot
70
    tarballs at above URL.
79
    tarballs at above URL.
71
  * All patches have been incorporated or (in the case of
80
  * All patches have been incorporated or (in the case of
72
    autoreconf.patch) made obsolete upstream.
81
    autoreconf.patch) made obsolete upstream.
73
  * debian/rules: Add build-indep and build-arch targets.
82
  * debian/rules: Add build-indep and build-arch targets.
74
  * Updated debian/copyright.
83
  * Updated debian/copyright.
75
  * Use dpkg-buildflags to set CFLAGS et al.
84
  * Use dpkg-buildflags to set CFLAGS et al.
76
  * debian/control: Add VCS fields; bump Standards-Version to 3.9.3.
85
  * debian/control: Add VCS fields; bump Standards-Version to 3.9.3.
77
86
78
 -- Magnus Holmgren <holmgren@debian.org>  Sat, 23 Jun 2012 01:03:41 +0200
87
 -- Magnus Holmgren <holmgren@debian.org>  Sat, 23 Jun 2012 01:03:41 +0200
79
88
80
libtar (1.2.11-8) unstable; urgency=low
89
libtar (1.2.11-8) unstable; urgency=low
81
90
82
  * libtool.patch: Set SHELL to the configured shell in those Makefile.in
91
  * libtool.patch: Set SHELL to the configured shell in those Makefile.in
83
    where libtool is used; otherwise libtool fails when /bin/sh is dash
92
    where libtool is used; otherwise libtool fails when /bin/sh is dash
84
    but bash is expected (Closes: #621935).
93
    but bash is expected (Closes: #621935).
85
  * man_hyphen_minus.patch (new): Escape hyphens that should be minus
94
  * man_hyphen_minus.patch (new): Escape hyphens that should be minus
86
    signs in man pages.
95
    signs in man pages.
87
  * Rename libtar as libtar0 to follow policy.
96
  * Rename libtar as libtar0 to follow policy.
88
97
89
 -- Magnus Holmgren <holmgren@debian.org>  Sun, 24 Apr 2011 21:11:52 +0200
98
 -- Magnus Holmgren <holmgren@debian.org>  Sun, 24 Apr 2011 21:11:52 +0200
90
99
91
libtar (1.2.11-7) unstable; urgency=low
100
libtar (1.2.11-7) unstable; urgency=low
92
101
93
  * New maintainer (Closes: #526618).
102
  * New maintainer (Closes: #526618).
94
  * Change source format to 3.0 (quilt), clean up Debian diff and split
103
  * Change source format to 3.0 (quilt), clean up Debian diff and split
95
    into several patches:
104
    into several patches:
96
    * libtool.patch: Using libtool to build dynamic library;
105
    * libtool.patch: Using libtool to build dynamic library;
97
    * autoreconf.patch: Changes needed to call autoreconf (bug 511741);
106
    * autoreconf.patch: Changes needed to call autoreconf (bug 511741);
98
    * memleak.patch: Fix memory leaks;
107
    * memleak.patch: Fix memory leaks;
99
    * bad_ptrtoint.patch: Document stupidity of tartype_t in libtar.c 
108
    * bad_ptrtoint.patch: Document stupidity of tartype_t in libtar.c 
100
      (bug 309945).
109
      (bug 309945).
101
  * Increase Debhelper compat level to 7.
110
  * Increase Debhelper compat level to 7.
102
  * Use dh_autoreconf to avoid having to keep track of files to clean.
111
  * Use dh_autoreconf to avoid having to keep track of files to clean.
103
  * memleak2.patch (new): Applied instead of memleak.patch. Fix memory
112
  * memleak2.patch (new): Applied instead of memleak.patch. Fix memory
104
    leak by making th_get_pathname() return a pointer to a static buffer
113
    leak by making th_get_pathname() return a pointer to a static buffer
105
    instead of a pointer to a copy of a local buffer (LP: #41804).
114
    instead of a pointer to a copy of a local buffer (LP: #41804).
106
  * Add homepage field and watch file (in case there is ever a new
115
  * Add homepage field and watch file (in case there is ever a new
107
    upstream release).
116
    upstream release).
108
  * Upgrade to Standards-Version 3.9.1.
117
  * Upgrade to Standards-Version 3.9.1.
109
118
110
 -- Magnus Holmgren <holmgren@debian.org>  Sat, 26 Mar 2011 23:10:25 +0100
119
 -- Magnus Holmgren <holmgren@debian.org>  Sat, 26 Mar 2011 23:10:25 +0100
111
120
112
libtar (1.2.11-6) unstable; urgency=low
121
libtar (1.2.11-6) unstable; urgency=low
113
122
114
  * Fix autotools usage (Closes: #511741)
123
  * Fix autotools usage (Closes: #511741)
115
124
116
 -- Julien Danjou <acid@debian.org>  Sat, 02 May 2009 11:33:06 +0200
125
 -- Julien Danjou <acid@debian.org>  Sat, 02 May 2009 11:33:06 +0200
117
126
118
libtar (1.2.11-5) unstable; urgency=low
127
libtar (1.2.11-5) unstable; urgency=low
119
128
120
  * New maintainer (Closes: #465889)
129
  * New maintainer (Closes: #465889)
121
  * Add missing binary-indep target in debian/rules (Closes: #395714)
130
  * Add missing binary-indep target in debian/rules (Closes: #395714)
122
  * Use ${binary:Version} instead of Source-Version
131
  * Use ${binary:Version} instead of Source-Version
123
  * Bump standard version
132
  * Bump standard version
124
  * Switch to debhelper 5
133
  * Switch to debhelper 5
125
134
126
 -- Julien Danjou <acid@debian.org>  Wed, 02 Apr 2008 07:06:55 +0200
135
 -- Julien Danjou <acid@debian.org>  Wed, 02 Apr 2008 07:06:55 +0200
127
136
128
libtar (1.2.11-4) unstable; urgency=low
137
libtar (1.2.11-4) unstable; urgency=low
129
138
130
  * Always include the newest libtool.m4.  (Closes: #313612)
139
  * Always include the newest libtool.m4.  (Closes: #313612)
131
140
132
 -- James Morrison <phython@debian.org>  Sun, 28 Aug 2005 09:41:47 -0700
141
 -- James Morrison <phython@debian.org>  Sun, 28 Aug 2005 09:41:47 -0700
133
142
134
libtar (1.2.11-3) unstable; urgency=low
143
libtar (1.2.11-3) unstable; urgency=low
135
144
136
  * Document stupidity of tartype_t in libtar.c.  (Closes: #309945)
145
  * Document stupidity of tartype_t in libtar.c.  (Closes: #309945)
137
146
138
 -- James Morrison <phython@debian.org>  Sat, 11 Jun 2005 18:23:15 -0400
147
 -- James Morrison <phython@debian.org>  Sat, 11 Jun 2005 18:23:15 -0400
139
148
140
libtar (1.2.11-2) unstable; urgency=low
149
libtar (1.2.11-2) unstable; urgency=low
141
150
142
  * Move libtar-dev to libdevel. (Closes: #188207)
151
  * Move libtar-dev to libdevel. (Closes: #188207)
143
  * Fix potential memory leak.
152
  * Fix potential memory leak.
144
153
145
 -- James Morrison <phython@debian.org>  Sun, 25 Jul 2004 12:59:08 -0700
154
 -- James Morrison <phython@debian.org>  Sun, 25 Jul 2004 12:59:08 -0700
146
155
147
libtar (1.2.11-1) unstable; urgency=low
156
libtar (1.2.11-1) unstable; urgency=low
148
157
149
  * New Upstream release.
158
  * New Upstream release.
150
159
151
 -- James Morrison <phython@debian.org>  Sat,  5 Apr 2003 14:03:19 -0500
160
 -- James Morrison <phython@debian.org>  Sat,  5 Apr 2003 14:03:19 -0500
152
161
153
libtar (1.2.10-1) unstable; urgency=low
162
libtar (1.2.10-1) unstable; urgency=low
154
163
155
  * New Upstream release.
164
  * New Upstream release.
156
     (Closes: #166602) New upstream uses autoconf 2.5x
165
     (Closes: #166602) New upstream uses autoconf 2.5x
157
  * Remove dependency on automake.  Hopefully upstream will except this
166
  * Remove dependency on automake.  Hopefully upstream will except this
158
    use of libtool.
167
    use of libtool.
159
  * Remove all -static and -shared targets from debian/rules.
168
  * Remove all -static and -shared targets from debian/rules.
160
  * Use dh_install instead of dh_movefiles.
169
  * Use dh_install instead of dh_movefiles.
161
  * -
170
  * -
162
171
163
 -- James Morrison <phython@debian.org>  Sat,  5 Apr 2003 14:03:16 -0500
172
 -- James Morrison <phython@debian.org>  Sat,  5 Apr 2003 14:03:16 -0500
164
173
165
libtar (1.2.5-4) unstable; urgency=low
174
libtar (1.2.5-4) unstable; urgency=low
166
175
167
  * New maintainer. (Closes: #154597)
176
  * New maintainer. (Closes: #154597)
168
  * WSG_ENCAP is now defined.  (Closes: #147764)
177
  * WSG_ENCAP is now defined.  (Closes: #147764)
169
  * libtar-dev depends on libc-dev instead of libc6-dev. 
178
  * libtar-dev depends on libc-dev instead of libc6-dev. 
170
179
171
 -- James Morrison <phython@debian.org>  Wed, 14 Aug 2002 23:44:16 -0400
180
 -- James Morrison <phython@debian.org>  Wed, 14 Aug 2002 23:44:16 -0400
172
181
173
libtar (1.2.5-3) unstable; urgency=low
182
libtar (1.2.5-3) unstable; urgency=low
174
183
175
  * Modify build commands to acomadate change in autoconf (Closes #147764)
184
  * Modify build commands to acomadate change in autoconf (Closes #147764)
176
185
177
 -- Glenn McGrath <bug1@debian.org>  Thu, 23 May 2002 01:06:16 +1000
186
 -- Glenn McGrath <bug1@debian.org>  Thu, 23 May 2002 01:06:16 +1000
178
187
179
libtar (1.2.5-2) unstable; urgency=low
188
libtar (1.2.5-2) unstable; urgency=low
180
189
181
  * Fix build problem (Closes #135360)
190
  * Fix build problem (Closes #135360)
182
191
183
 -- Glenn McGrath <bug1@debian.org>  Sun, 24 Feb 2002 06:29:31 +1100
192
 -- Glenn McGrath <bug1@debian.org>  Sun, 24 Feb 2002 06:29:31 +1100
184
193
185
libtar (1.2.5-1) unstable; urgency=low
194
libtar (1.2.5-1) unstable; urgency=low
186
195
187
  * New upstream version
196
  * New upstream version
188
  * Change section of libtar-dev to devel and libtar to libs
197
  * Change section of libtar-dev to devel and libtar to libs
189
198
190
 -- Glenn McGrath <bug1@debian.org>  Fri, 22 Feb 2002 04:23:15 +1100
199
 -- Glenn McGrath <bug1@debian.org>  Fri, 22 Feb 2002 04:23:15 +1100
191
200
192
libtar (1.2.4-2) unstable; urgency=low
201
libtar (1.2.4-2) unstable; urgency=low
193
202
194
  * Change section from devel to libs 
203
  * Change section from devel to libs 
195
204
196
 -- Glenn McGrath <bug1@debian.org>  Sat,  2 Feb 2002 12:12:32 +1100
205
 -- Glenn McGrath <bug1@debian.org>  Sat,  2 Feb 2002 12:12:32 +1100
197
206
198
libtar (1.2.4-1) unstable; urgency=low
207
libtar (1.2.4-1) unstable; urgency=low
199
208
200
  * Initial Release. (closes #128042)
209
  * Initial Release. (closes #128042)
201
210
202
 -- Glenn McGrath <bug1@debian.org>  Sat,  5 Jan 2002 13:24:37 +1100
211
 -- Glenn McGrath <bug1@debian.org>  Sat,  5 Jan 2002 13:24:37 +1100
203
212