Subversion Repositories

?revision_form?Rev ?revision_input??revision_submit??revision_endform?

Rev 31 | Rev 36 | Go to most recent revision | Details | Compare with Previous | Last modification | View Log | RSS feed

Rev Author Line No. Line
30 magnus 1
libtar (1.2.20-3) unstable; urgency=low
2
 
3
  * no_maxpathlen.patch: Fix two grave bugs in the patch. First,
4
    th_get_pathname would only allocate as much memory as was needed for
5
    the first filename encountered, causing heap corruption when/if
6
    encountering longer filenames later. Second, two variables were mixed
7
    up in tar_append_tree(). Also, fix a potential memory leak and trim
8
    the patch a bit.
31 magnus 9
  * [SECURITY] CVE-2013-4420.patch: When the prefix field is in use, the
10
    safer_name_suffix() function should certainly be applied to the
11
    combination of it and the name field, not just on the name field.
33 magnus 12
  * th_get_size-unsigned-int.patch: Make the th_get_size() macro cast the
13
    result from oct_to_int() to unsigned int. This is the right fix for
14
    bug #725938 on 64-bit systems, where a specially crafted tar file
15
    would not cause an integer overflow, but a memory allocation of almost
16
    16 exbibytes, which would certainly fail outright without harm.
30 magnus 17
 
33 magnus 18
 -- Magnus Holmgren <holmgren@debian.org>  Sat, 15 Feb 2014 23:51:51 +0100
30 magnus 19
 
23 magnus 20
libtar (1.2.20-2) unstable; urgency=low
21
 
22
  * no_static_buffers.patch: avoid using a static buffer in
23
    th_get_pathname(). Taken from upstream. Needed for no_maxpathlen.patch.
29 magnus 24
  * no_maxpathlen.patch: Fix FTBFS on Hurd by dynamically allocating path
23 magnus 25
    names (Closes: #657116). Thanks to Svante Signell and Petter
26
    Reinholdtsen.
24 magnus 27
  * [SECURITY] CVE-2013-4420.patch: Strip out leading slashes and any
28
    pathname prefix containing ".." components (Closes: #731860). This is
29
    done in th_get_pathname() (as well as to symlink targets when
30
    extracting symlinks), not merely when extracting files, which means
31
    applications calling that function will not see the stored
32
    filename. There is no way to disable this behaviour, but it can be
33
    expected that one will be provided when the issue is solved upstream.
25 magnus 34
  * Bump Standards-Version to 3.9.5.
23 magnus 35
 
25 magnus 36
 -- Magnus Holmgren <holmgren@debian.org>  Sat, 15 Feb 2014 21:49:37 +0100
23 magnus 37
 
18 magnus 38
libtar (1.2.20-1) unstable; urgency=high
39
 
40
  * [SECURITY] New upstream release. Fixes CVE-2013-4397: Integer
41
    overflow (Closes: #725938).
19 magnus 42
  * Bump Standards-Version to 3.9.4.
18 magnus 43
 
44
 -- Magnus Holmgren <holmgren@debian.org>  Thu, 10 Oct 2013 19:20:49 +0200
45
 
15 magnus 46
libtar (1.2.19-1) unstable; urgency=low
47
 
48
  * New upstream release.
49
 
50
 -- Magnus Holmgren <holmgren@debian.org>  Sun, 05 May 2013 17:59:29 +0200
51
 
10 magnus 52
libtar (1.2.16-1) unstable; urgency=low
8 magnus 53
 
54
  * New upstream: Chris Frey has stepped up with the consent of the
55
    original author, Mark Roth, and published an "official unofficial" git
56
    repo at http://repo.or.cz/w/libtar.git, which I will use for the time
57
    being.
10 magnus 58
  * Updated debian/watch to look for tags and corresponding snapshot
59
    tarballs at above URL.
8 magnus 60
  * All patches have been incorporated or (in the case of
61
    autoreconf.patch) made obsolete upstream.
9 magnus 62
  * debian/rules: Add build-indep and build-arch targets.
11 magnus 63
  * Updated debian/copyright.
12 magnus 64
  * Use dpkg-buildflags to set CFLAGS et al.
13 magnus 65
  * debian/control: Add VCS fields; bump Standards-Version to 3.9.3.
8 magnus 66
 
13 magnus 67
 -- Magnus Holmgren <holmgren@debian.org>  Sat, 23 Jun 2012 01:03:41 +0200
8 magnus 68
 
6 magnus 69
libtar (1.2.11-8) unstable; urgency=low
70
 
71
  * libtool.patch: Set SHELL to the configured shell in those Makefile.in
72
    where libtool is used; otherwise libtool fails when /bin/sh is dash
73
    but bash is expected (Closes: #621935).
74
  * man_hyphen_minus.patch (new): Escape hyphens that should be minus
75
    signs in man pages.
76
  * Rename libtar as libtar0 to follow policy.
77
 
78
 -- Magnus Holmgren <holmgren@debian.org>  Sun, 24 Apr 2011 21:11:52 +0200
79
 
5 magnus 80
libtar (1.2.11-7) unstable; urgency=low
81
 
82
  * New maintainer (Closes: #526618).
83
  * Change source format to 3.0 (quilt), clean up Debian diff and split
84
    into several patches:
85
    * libtool.patch: Using libtool to build dynamic library;
86
    * autoreconf.patch: Changes needed to call autoreconf (bug 511741);
87
    * memleak.patch: Fix memory leaks;
88
    * bad_ptrtoint.patch: Document stupidity of tartype_t in libtar.c
89
      (bug 309945).
90
  * Increase Debhelper compat level to 7.
91
  * Use dh_autoreconf to avoid having to keep track of files to clean.
92
  * memleak2.patch (new): Applied instead of memleak.patch. Fix memory
93
    leak by making th_get_pathname() return a pointer to a static buffer
94
    instead of a pointer to a copy of a local buffer (LP: #41804).
95
  * Add homepage field and watch file (in case there is ever a new
96
    upstream release).
97
  * Upgrade to Standards-Version 3.9.1.
98
 
99
 -- Magnus Holmgren <holmgren@debian.org>  Sat, 26 Mar 2011 23:10:25 +0100
100
 
3 magnus 101
libtar (1.2.11-6) unstable; urgency=low
102
 
103
  * Fix autotools usage (Closes: #511741)
104
 
105
 -- Julien Danjou <acid@debian.org>  Sat, 02 May 2009 11:33:06 +0200
106
 
107
libtar (1.2.11-5) unstable; urgency=low
108
 
109
  * New maintainer (Closes: #465889)
110
  * Add missing binary-indep target in debian/rules (Closes: #395714)
111
  * Use ${binary:Version} instead of Source-Version
112
  * Bump standard version
113
  * Switch to debhelper 5
114
 
115
 -- Julien Danjou <acid@debian.org>  Wed, 02 Apr 2008 07:06:55 +0200
116
 
117
libtar (1.2.11-4) unstable; urgency=low
118
 
119
  * Always include the newest libtool.m4.  (Closes: #313612)
120
 
121
 -- James Morrison <phython@debian.org>  Sun, 28 Aug 2005 09:41:47 -0700
122
 
123
libtar (1.2.11-3) unstable; urgency=low
124
 
125
  * Document stupidity of tartype_t in libtar.c.  (Closes: #309945)
126
 
127
 -- James Morrison <phython@debian.org>  Sat, 11 Jun 2005 18:23:15 -0400
128
 
129
libtar (1.2.11-2) unstable; urgency=low
130
 
131
  * Move libtar-dev to libdevel. (Closes: #188207)
132
  * Fix potential memory leak.
133
 
134
 -- James Morrison <phython@debian.org>  Sun, 25 Jul 2004 12:59:08 -0700
135
 
136
libtar (1.2.11-1) unstable; urgency=low
137
 
138
  * New Upstream release.
139
 
140
 -- James Morrison <phython@debian.org>  Sat,  5 Apr 2003 14:03:19 -0500
141
 
142
libtar (1.2.10-1) unstable; urgency=low
143
 
144
  * New Upstream release.
145
     (Closes: #166602) New upstream uses autoconf 2.5x
146
  * Remove dependency on automake.  Hopefully upstream will except this
147
    use of libtool.
148
  * Remove all -static and -shared targets from debian/rules.
149
  * Use dh_install instead of dh_movefiles.
150
  * -
151
 
152
 -- James Morrison <phython@debian.org>  Sat,  5 Apr 2003 14:03:16 -0500
153
 
154
libtar (1.2.5-4) unstable; urgency=low
155
 
156
  * New maintainer. (Closes: #154597)
157
  * WSG_ENCAP is now defined.  (Closes: #147764)
158
  * libtar-dev depends on libc-dev instead of libc6-dev.
159
 
160
 -- James Morrison <phython@debian.org>  Wed, 14 Aug 2002 23:44:16 -0400
161
 
162
libtar (1.2.5-3) unstable; urgency=low
163
 
164
  * Modify build commands to acomadate change in autoconf (Closes #147764)
165
 
166
 -- Glenn McGrath <bug1@debian.org>  Thu, 23 May 2002 01:06:16 +1000
167
 
168
libtar (1.2.5-2) unstable; urgency=low
169
 
170
  * Fix build problem (Closes #135360)
171
 
172
 -- Glenn McGrath <bug1@debian.org>  Sun, 24 Feb 2002 06:29:31 +1100
173
 
174
libtar (1.2.5-1) unstable; urgency=low
175
 
176
  * New upstream version
177
  * Change section of libtar-dev to devel and libtar to libs
178
 
179
 -- Glenn McGrath <bug1@debian.org>  Fri, 22 Feb 2002 04:23:15 +1100
180
 
181
libtar (1.2.4-2) unstable; urgency=low
182
 
183
  * Change section from devel to libs
184
 
185
 -- Glenn McGrath <bug1@debian.org>  Sat,  2 Feb 2002 12:12:32 +1100
186
 
187
libtar (1.2.4-1) unstable; urgency=low
188
 
189
  * Initial Release. (closes #128042)
190
 
191
 -- Glenn McGrath <bug1@debian.org>  Sat,  5 Jan 2002 13:24:37 +1100
192