Subversion Repositories

?revision_form?Rev ?revision_input??revision_submit??revision_endform?

Rev 47 | Rev 49 | Go to most recent revision | Details | Compare with Previous | Last modification | View Log | RSS feed

Rev Author Line No. Line
45 magnus 1
libtar (1.2.20-7) unstable; urgency=low
2
 
3
  * no_strip.patch: make install must not strip binaries; it breaks cross
4
    compilation and is against policy with regard to build options.
47 magnus 5
  * Pass --build and --host to configure as appropriate to enable cross
6
    compilation (Closes: #839883).
48 magnus 7
  * Change Homepage to http://repo.or.cz/w/libtar.git since www.feep.net
8
    is gone.
45 magnus 9
 
48 magnus 10
 -- Magnus Holmgren <holmgren@debian.org>  Tue, 11 Oct 2016 23:12:49 +0200
45 magnus 11
 
43 magnus 12
libtar (1.2.20-6) unstable; urgency=low
13
 
14
  * Drop libtar/Makefile from examples, since it makes the build
15
    unreproducible (saves $SHELL) and isn't enough to compile libtar.c
16
    anyway.
44 magnus 17
  * Bump Standards-Version to 3.9.8.
43 magnus 18
 
44 magnus 19
 -- Magnus Holmgren <holmgren@debian.org>  Mon, 01 Aug 2016 22:52:44 +0200
43 magnus 20
 
38 magnus 21
libtar (1.2.20-5) unstable; urgency=low
22
 
23
  * oldgnu_prefix.patch: Detect old-style GNU headers correctly (Closes:
24
    #763119). Those appear in incremental archives and use the bytes that
25
    the new-style headers use for the prefix field for other fields.
26
    Thanks to Steinar H. Gunderson.
39 magnus 27
  * testsuite.patch: Add a simple test (Closes: #737258).
41 magnus 28
  * Bump Standards-Version to 3.9.7.
38 magnus 29
 
41 magnus 30
 -- Magnus Holmgren <holmgren@debian.org>  Fri, 25 Mar 2016 19:12:23 +0100
38 magnus 31
 
36 magnus 32
libtar (1.2.20-4) unstable; urgency=high
33
 
34
  * no_maxpathlen.patch: Half of the part of the patch modifying
35
    compat/dirname.c was missing, causing libtar's dirname to always
36
    return NULL (except in special circumstances). Actually make it work
37
    (Closes: #745352). (The reason that libtar doesn't use libc's
38
    dirname() and basename() on some or most platforms is that the code
39
    doesn't work with destructive versions of these functions).
40
 
41
 -- Magnus Holmgren <holmgren@debian.org>  Sat, 03 May 2014 20:39:02 +0200
42
 
30 magnus 43
libtar (1.2.20-3) unstable; urgency=low
44
 
45
  * no_maxpathlen.patch: Fix two grave bugs in the patch. First,
46
    th_get_pathname would only allocate as much memory as was needed for
47
    the first filename encountered, causing heap corruption when/if
48
    encountering longer filenames later. Second, two variables were mixed
49
    up in tar_append_tree(). Also, fix a potential memory leak and trim
50
    the patch a bit.
31 magnus 51
  * [SECURITY] CVE-2013-4420.patch: When the prefix field is in use, the
52
    safer_name_suffix() function should certainly be applied to the
53
    combination of it and the name field, not just on the name field.
33 magnus 54
  * th_get_size-unsigned-int.patch: Make the th_get_size() macro cast the
55
    result from oct_to_int() to unsigned int. This is the right fix for
56
    bug #725938 on 64-bit systems, where a specially crafted tar file
57
    would not cause an integer overflow, but a memory allocation of almost
58
    16 exbibytes, which would certainly fail outright without harm.
30 magnus 59
 
33 magnus 60
 -- Magnus Holmgren <holmgren@debian.org>  Sat, 15 Feb 2014 23:51:51 +0100
30 magnus 61
 
23 magnus 62
libtar (1.2.20-2) unstable; urgency=low
63
 
64
  * no_static_buffers.patch: avoid using a static buffer in
65
    th_get_pathname(). Taken from upstream. Needed for no_maxpathlen.patch.
29 magnus 66
  * no_maxpathlen.patch: Fix FTBFS on Hurd by dynamically allocating path
23 magnus 67
    names (Closes: #657116). Thanks to Svante Signell and Petter
68
    Reinholdtsen.
24 magnus 69
  * [SECURITY] CVE-2013-4420.patch: Strip out leading slashes and any
70
    pathname prefix containing ".." components (Closes: #731860). This is
71
    done in th_get_pathname() (as well as to symlink targets when
72
    extracting symlinks), not merely when extracting files, which means
73
    applications calling that function will not see the stored
74
    filename. There is no way to disable this behaviour, but it can be
75
    expected that one will be provided when the issue is solved upstream.
25 magnus 76
  * Bump Standards-Version to 3.9.5.
23 magnus 77
 
25 magnus 78
 -- Magnus Holmgren <holmgren@debian.org>  Sat, 15 Feb 2014 21:49:37 +0100
23 magnus 79
 
18 magnus 80
libtar (1.2.20-1) unstable; urgency=high
81
 
82
  * [SECURITY] New upstream release. Fixes CVE-2013-4397: Integer
83
    overflow (Closes: #725938).
19 magnus 84
  * Bump Standards-Version to 3.9.4.
18 magnus 85
 
86
 -- Magnus Holmgren <holmgren@debian.org>  Thu, 10 Oct 2013 19:20:49 +0200
87
 
15 magnus 88
libtar (1.2.19-1) unstable; urgency=low
89
 
90
  * New upstream release.
91
 
92
 -- Magnus Holmgren <holmgren@debian.org>  Sun, 05 May 2013 17:59:29 +0200
93
 
10 magnus 94
libtar (1.2.16-1) unstable; urgency=low
8 magnus 95
 
96
  * New upstream: Chris Frey has stepped up with the consent of the
97
    original author, Mark Roth, and published an "official unofficial" git
98
    repo at http://repo.or.cz/w/libtar.git, which I will use for the time
99
    being.
10 magnus 100
  * Updated debian/watch to look for tags and corresponding snapshot
101
    tarballs at above URL.
8 magnus 102
  * All patches have been incorporated or (in the case of
103
    autoreconf.patch) made obsolete upstream.
9 magnus 104
  * debian/rules: Add build-indep and build-arch targets.
11 magnus 105
  * Updated debian/copyright.
12 magnus 106
  * Use dpkg-buildflags to set CFLAGS et al.
13 magnus 107
  * debian/control: Add VCS fields; bump Standards-Version to 3.9.3.
8 magnus 108
 
13 magnus 109
 -- Magnus Holmgren <holmgren@debian.org>  Sat, 23 Jun 2012 01:03:41 +0200
8 magnus 110
 
6 magnus 111
libtar (1.2.11-8) unstable; urgency=low
112
 
113
  * libtool.patch: Set SHELL to the configured shell in those Makefile.in
114
    where libtool is used; otherwise libtool fails when /bin/sh is dash
115
    but bash is expected (Closes: #621935).
116
  * man_hyphen_minus.patch (new): Escape hyphens that should be minus
117
    signs in man pages.
118
  * Rename libtar as libtar0 to follow policy.
119
 
120
 -- Magnus Holmgren <holmgren@debian.org>  Sun, 24 Apr 2011 21:11:52 +0200
121
 
5 magnus 122
libtar (1.2.11-7) unstable; urgency=low
123
 
124
  * New maintainer (Closes: #526618).
125
  * Change source format to 3.0 (quilt), clean up Debian diff and split
126
    into several patches:
127
    * libtool.patch: Using libtool to build dynamic library;
128
    * autoreconf.patch: Changes needed to call autoreconf (bug 511741);
129
    * memleak.patch: Fix memory leaks;
130
    * bad_ptrtoint.patch: Document stupidity of tartype_t in libtar.c
131
      (bug 309945).
132
  * Increase Debhelper compat level to 7.
133
  * Use dh_autoreconf to avoid having to keep track of files to clean.
134
  * memleak2.patch (new): Applied instead of memleak.patch. Fix memory
135
    leak by making th_get_pathname() return a pointer to a static buffer
136
    instead of a pointer to a copy of a local buffer (LP: #41804).
137
  * Add homepage field and watch file (in case there is ever a new
138
    upstream release).
139
  * Upgrade to Standards-Version 3.9.1.
140
 
141
 -- Magnus Holmgren <holmgren@debian.org>  Sat, 26 Mar 2011 23:10:25 +0100
142
 
3 magnus 143
libtar (1.2.11-6) unstable; urgency=low
144
 
145
  * Fix autotools usage (Closes: #511741)
146
 
147
 -- Julien Danjou <acid@debian.org>  Sat, 02 May 2009 11:33:06 +0200
148
 
149
libtar (1.2.11-5) unstable; urgency=low
150
 
151
  * New maintainer (Closes: #465889)
152
  * Add missing binary-indep target in debian/rules (Closes: #395714)
153
  * Use ${binary:Version} instead of Source-Version
154
  * Bump standard version
155
  * Switch to debhelper 5
156
 
157
 -- Julien Danjou <acid@debian.org>  Wed, 02 Apr 2008 07:06:55 +0200
158
 
159
libtar (1.2.11-4) unstable; urgency=low
160
 
161
  * Always include the newest libtool.m4.  (Closes: #313612)
162
 
163
 -- James Morrison <phython@debian.org>  Sun, 28 Aug 2005 09:41:47 -0700
164
 
165
libtar (1.2.11-3) unstable; urgency=low
166
 
167
  * Document stupidity of tartype_t in libtar.c.  (Closes: #309945)
168
 
169
 -- James Morrison <phython@debian.org>  Sat, 11 Jun 2005 18:23:15 -0400
170
 
171
libtar (1.2.11-2) unstable; urgency=low
172
 
173
  * Move libtar-dev to libdevel. (Closes: #188207)
174
  * Fix potential memory leak.
175
 
176
 -- James Morrison <phython@debian.org>  Sun, 25 Jul 2004 12:59:08 -0700
177
 
178
libtar (1.2.11-1) unstable; urgency=low
179
 
180
  * New Upstream release.
181
 
182
 -- James Morrison <phython@debian.org>  Sat,  5 Apr 2003 14:03:19 -0500
183
 
184
libtar (1.2.10-1) unstable; urgency=low
185
 
186
  * New Upstream release.
187
     (Closes: #166602) New upstream uses autoconf 2.5x
188
  * Remove dependency on automake.  Hopefully upstream will except this
189
    use of libtool.
190
  * Remove all -static and -shared targets from debian/rules.
191
  * Use dh_install instead of dh_movefiles.
192
  * -
193
 
194
 -- James Morrison <phython@debian.org>  Sat,  5 Apr 2003 14:03:16 -0500
195
 
196
libtar (1.2.5-4) unstable; urgency=low
197
 
198
  * New maintainer. (Closes: #154597)
199
  * WSG_ENCAP is now defined.  (Closes: #147764)
200
  * libtar-dev depends on libc-dev instead of libc6-dev.
201
 
202
 -- James Morrison <phython@debian.org>  Wed, 14 Aug 2002 23:44:16 -0400
203
 
204
libtar (1.2.5-3) unstable; urgency=low
205
 
206
  * Modify build commands to acomadate change in autoconf (Closes #147764)
207
 
208
 -- Glenn McGrath <bug1@debian.org>  Thu, 23 May 2002 01:06:16 +1000
209
 
210
libtar (1.2.5-2) unstable; urgency=low
211
 
212
  * Fix build problem (Closes #135360)
213
 
214
 -- Glenn McGrath <bug1@debian.org>  Sun, 24 Feb 2002 06:29:31 +1100
215
 
216
libtar (1.2.5-1) unstable; urgency=low
217
 
218
  * New upstream version
219
  * Change section of libtar-dev to devel and libtar to libs
220
 
221
 -- Glenn McGrath <bug1@debian.org>  Fri, 22 Feb 2002 04:23:15 +1100
222
 
223
libtar (1.2.4-2) unstable; urgency=low
224
 
225
  * Change section from devel to libs
226
 
227
 -- Glenn McGrath <bug1@debian.org>  Sat,  2 Feb 2002 12:12:32 +1100
228
 
229
libtar (1.2.4-1) unstable; urgency=low
230
 
231
  * Initial Release. (closes #128042)
232
 
233
 -- Glenn McGrath <bug1@debian.org>  Sat,  5 Jan 2002 13:24:37 +1100
234