Subversion Repositories

?revision_form?Rev ?revision_input??revision_submit??revision_endform?

Rev 45 | Rev 48 | Go to most recent revision | Details | Compare with Previous | Last modification | View Log | RSS feed

Rev Author Line No. Line
45 magnus 1
libtar (1.2.20-7) unstable; urgency=low
2
 
3
  * no_strip.patch: make install must not strip binaries; it breaks cross
4
    compilation and is against policy with regard to build options.
47 magnus 5
  * Pass --build and --host to configure as appropriate to enable cross
6
    compilation (Closes: #839883).
45 magnus 7
 
47 magnus 8
 -- Magnus Holmgren <holmgren@debian.org>  Tue, 11 Oct 2016 22:29:38 +0200
45 magnus 9
 
43 magnus 10
libtar (1.2.20-6) unstable; urgency=low
11
 
12
  * Drop libtar/Makefile from examples, since it makes the build
13
    unreproducible (saves $SHELL) and isn't enough to compile libtar.c
14
    anyway.
44 magnus 15
  * Bump Standards-Version to 3.9.8.
43 magnus 16
 
44 magnus 17
 -- Magnus Holmgren <holmgren@debian.org>  Mon, 01 Aug 2016 22:52:44 +0200
43 magnus 18
 
38 magnus 19
libtar (1.2.20-5) unstable; urgency=low
20
 
21
  * oldgnu_prefix.patch: Detect old-style GNU headers correctly (Closes:
22
    #763119). Those appear in incremental archives and use the bytes that
23
    the new-style headers use for the prefix field for other fields.
24
    Thanks to Steinar H. Gunderson.
39 magnus 25
  * testsuite.patch: Add a simple test (Closes: #737258).
41 magnus 26
  * Bump Standards-Version to 3.9.7.
38 magnus 27
 
41 magnus 28
 -- Magnus Holmgren <holmgren@debian.org>  Fri, 25 Mar 2016 19:12:23 +0100
38 magnus 29
 
36 magnus 30
libtar (1.2.20-4) unstable; urgency=high
31
 
32
  * no_maxpathlen.patch: Half of the part of the patch modifying
33
    compat/dirname.c was missing, causing libtar's dirname to always
34
    return NULL (except in special circumstances). Actually make it work
35
    (Closes: #745352). (The reason that libtar doesn't use libc's
36
    dirname() and basename() on some or most platforms is that the code
37
    doesn't work with destructive versions of these functions).
38
 
39
 -- Magnus Holmgren <holmgren@debian.org>  Sat, 03 May 2014 20:39:02 +0200
40
 
30 magnus 41
libtar (1.2.20-3) unstable; urgency=low
42
 
43
  * no_maxpathlen.patch: Fix two grave bugs in the patch. First,
44
    th_get_pathname would only allocate as much memory as was needed for
45
    the first filename encountered, causing heap corruption when/if
46
    encountering longer filenames later. Second, two variables were mixed
47
    up in tar_append_tree(). Also, fix a potential memory leak and trim
48
    the patch a bit.
31 magnus 49
  * [SECURITY] CVE-2013-4420.patch: When the prefix field is in use, the
50
    safer_name_suffix() function should certainly be applied to the
51
    combination of it and the name field, not just on the name field.
33 magnus 52
  * th_get_size-unsigned-int.patch: Make the th_get_size() macro cast the
53
    result from oct_to_int() to unsigned int. This is the right fix for
54
    bug #725938 on 64-bit systems, where a specially crafted tar file
55
    would not cause an integer overflow, but a memory allocation of almost
56
    16 exbibytes, which would certainly fail outright without harm.
30 magnus 57
 
33 magnus 58
 -- Magnus Holmgren <holmgren@debian.org>  Sat, 15 Feb 2014 23:51:51 +0100
30 magnus 59
 
23 magnus 60
libtar (1.2.20-2) unstable; urgency=low
61
 
62
  * no_static_buffers.patch: avoid using a static buffer in
63
    th_get_pathname(). Taken from upstream. Needed for no_maxpathlen.patch.
29 magnus 64
  * no_maxpathlen.patch: Fix FTBFS on Hurd by dynamically allocating path
23 magnus 65
    names (Closes: #657116). Thanks to Svante Signell and Petter
66
    Reinholdtsen.
24 magnus 67
  * [SECURITY] CVE-2013-4420.patch: Strip out leading slashes and any
68
    pathname prefix containing ".." components (Closes: #731860). This is
69
    done in th_get_pathname() (as well as to symlink targets when
70
    extracting symlinks), not merely when extracting files, which means
71
    applications calling that function will not see the stored
72
    filename. There is no way to disable this behaviour, but it can be
73
    expected that one will be provided when the issue is solved upstream.
25 magnus 74
  * Bump Standards-Version to 3.9.5.
23 magnus 75
 
25 magnus 76
 -- Magnus Holmgren <holmgren@debian.org>  Sat, 15 Feb 2014 21:49:37 +0100
23 magnus 77
 
18 magnus 78
libtar (1.2.20-1) unstable; urgency=high
79
 
80
  * [SECURITY] New upstream release. Fixes CVE-2013-4397: Integer
81
    overflow (Closes: #725938).
19 magnus 82
  * Bump Standards-Version to 3.9.4.
18 magnus 83
 
84
 -- Magnus Holmgren <holmgren@debian.org>  Thu, 10 Oct 2013 19:20:49 +0200
85
 
15 magnus 86
libtar (1.2.19-1) unstable; urgency=low
87
 
88
  * New upstream release.
89
 
90
 -- Magnus Holmgren <holmgren@debian.org>  Sun, 05 May 2013 17:59:29 +0200
91
 
10 magnus 92
libtar (1.2.16-1) unstable; urgency=low
8 magnus 93
 
94
  * New upstream: Chris Frey has stepped up with the consent of the
95
    original author, Mark Roth, and published an "official unofficial" git
96
    repo at http://repo.or.cz/w/libtar.git, which I will use for the time
97
    being.
10 magnus 98
  * Updated debian/watch to look for tags and corresponding snapshot
99
    tarballs at above URL.
8 magnus 100
  * All patches have been incorporated or (in the case of
101
    autoreconf.patch) made obsolete upstream.
9 magnus 102
  * debian/rules: Add build-indep and build-arch targets.
11 magnus 103
  * Updated debian/copyright.
12 magnus 104
  * Use dpkg-buildflags to set CFLAGS et al.
13 magnus 105
  * debian/control: Add VCS fields; bump Standards-Version to 3.9.3.
8 magnus 106
 
13 magnus 107
 -- Magnus Holmgren <holmgren@debian.org>  Sat, 23 Jun 2012 01:03:41 +0200
8 magnus 108
 
6 magnus 109
libtar (1.2.11-8) unstable; urgency=low
110
 
111
  * libtool.patch: Set SHELL to the configured shell in those Makefile.in
112
    where libtool is used; otherwise libtool fails when /bin/sh is dash
113
    but bash is expected (Closes: #621935).
114
  * man_hyphen_minus.patch (new): Escape hyphens that should be minus
115
    signs in man pages.
116
  * Rename libtar as libtar0 to follow policy.
117
 
118
 -- Magnus Holmgren <holmgren@debian.org>  Sun, 24 Apr 2011 21:11:52 +0200
119
 
5 magnus 120
libtar (1.2.11-7) unstable; urgency=low
121
 
122
  * New maintainer (Closes: #526618).
123
  * Change source format to 3.0 (quilt), clean up Debian diff and split
124
    into several patches:
125
    * libtool.patch: Using libtool to build dynamic library;
126
    * autoreconf.patch: Changes needed to call autoreconf (bug 511741);
127
    * memleak.patch: Fix memory leaks;
128
    * bad_ptrtoint.patch: Document stupidity of tartype_t in libtar.c
129
      (bug 309945).
130
  * Increase Debhelper compat level to 7.
131
  * Use dh_autoreconf to avoid having to keep track of files to clean.
132
  * memleak2.patch (new): Applied instead of memleak.patch. Fix memory
133
    leak by making th_get_pathname() return a pointer to a static buffer
134
    instead of a pointer to a copy of a local buffer (LP: #41804).
135
  * Add homepage field and watch file (in case there is ever a new
136
    upstream release).
137
  * Upgrade to Standards-Version 3.9.1.
138
 
139
 -- Magnus Holmgren <holmgren@debian.org>  Sat, 26 Mar 2011 23:10:25 +0100
140
 
3 magnus 141
libtar (1.2.11-6) unstable; urgency=low
142
 
143
  * Fix autotools usage (Closes: #511741)
144
 
145
 -- Julien Danjou <acid@debian.org>  Sat, 02 May 2009 11:33:06 +0200
146
 
147
libtar (1.2.11-5) unstable; urgency=low
148
 
149
  * New maintainer (Closes: #465889)
150
  * Add missing binary-indep target in debian/rules (Closes: #395714)
151
  * Use ${binary:Version} instead of Source-Version
152
  * Bump standard version
153
  * Switch to debhelper 5
154
 
155
 -- Julien Danjou <acid@debian.org>  Wed, 02 Apr 2008 07:06:55 +0200
156
 
157
libtar (1.2.11-4) unstable; urgency=low
158
 
159
  * Always include the newest libtool.m4.  (Closes: #313612)
160
 
161
 -- James Morrison <phython@debian.org>  Sun, 28 Aug 2005 09:41:47 -0700
162
 
163
libtar (1.2.11-3) unstable; urgency=low
164
 
165
  * Document stupidity of tartype_t in libtar.c.  (Closes: #309945)
166
 
167
 -- James Morrison <phython@debian.org>  Sat, 11 Jun 2005 18:23:15 -0400
168
 
169
libtar (1.2.11-2) unstable; urgency=low
170
 
171
  * Move libtar-dev to libdevel. (Closes: #188207)
172
  * Fix potential memory leak.
173
 
174
 -- James Morrison <phython@debian.org>  Sun, 25 Jul 2004 12:59:08 -0700
175
 
176
libtar (1.2.11-1) unstable; urgency=low
177
 
178
  * New Upstream release.
179
 
180
 -- James Morrison <phython@debian.org>  Sat,  5 Apr 2003 14:03:19 -0500
181
 
182
libtar (1.2.10-1) unstable; urgency=low
183
 
184
  * New Upstream release.
185
     (Closes: #166602) New upstream uses autoconf 2.5x
186
  * Remove dependency on automake.  Hopefully upstream will except this
187
    use of libtool.
188
  * Remove all -static and -shared targets from debian/rules.
189
  * Use dh_install instead of dh_movefiles.
190
  * -
191
 
192
 -- James Morrison <phython@debian.org>  Sat,  5 Apr 2003 14:03:16 -0500
193
 
194
libtar (1.2.5-4) unstable; urgency=low
195
 
196
  * New maintainer. (Closes: #154597)
197
  * WSG_ENCAP is now defined.  (Closes: #147764)
198
  * libtar-dev depends on libc-dev instead of libc6-dev.
199
 
200
 -- James Morrison <phython@debian.org>  Wed, 14 Aug 2002 23:44:16 -0400
201
 
202
libtar (1.2.5-3) unstable; urgency=low
203
 
204
  * Modify build commands to acomadate change in autoconf (Closes #147764)
205
 
206
 -- Glenn McGrath <bug1@debian.org>  Thu, 23 May 2002 01:06:16 +1000
207
 
208
libtar (1.2.5-2) unstable; urgency=low
209
 
210
  * Fix build problem (Closes #135360)
211
 
212
 -- Glenn McGrath <bug1@debian.org>  Sun, 24 Feb 2002 06:29:31 +1100
213
 
214
libtar (1.2.5-1) unstable; urgency=low
215
 
216
  * New upstream version
217
  * Change section of libtar-dev to devel and libtar to libs
218
 
219
 -- Glenn McGrath <bug1@debian.org>  Fri, 22 Feb 2002 04:23:15 +1100
220
 
221
libtar (1.2.4-2) unstable; urgency=low
222
 
223
  * Change section from devel to libs
224
 
225
 -- Glenn McGrath <bug1@debian.org>  Sat,  2 Feb 2002 12:12:32 +1100
226
 
227
libtar (1.2.4-1) unstable; urgency=low
228
 
229
  * Initial Release. (closes #128042)
230
 
231
 -- Glenn McGrath <bug1@debian.org>  Sat,  5 Jan 2002 13:24:37 +1100
232