[ubuntu/quantal] xmlrpc-c 1.16.33-3.1ubuntu6 (Accepted)

Tyler Hicks tyhicks at canonical.com
Tue Sep 11 18:10:18 UTC 2012


xmlrpc-c (1.16.33-3.1ubuntu6) quantal; urgency=low

  * Run the tests as part of the build process
    - debian/patches/FTBFS-tests.patch: Fix issues when running make check.
      Based on upstream patches.
    - debian/rules: Run make check after building
  * Fix dependencies of xmlrpc-api-utils
    - debian/control: xml-rcp-api2cpp needs libxmlrpc_cpp.so.4, so depend on
      libxmlrpc-c++4
  * SECURITY UPDATE: Denial of service via hash collisions (LP: #1048835)
    - debian/patches/CVE-2012-0876.patch: Add random salt value to
      hash inputs. Based on upstream patch.
    - CVE-2012-0876
  * SECURITY UPDATE: Denial of service via memory leak (LP: #1048835)
    - debian/patches/CVE-2012-1148.patch: Properly reallocate memory.
      Based on upstream patch.
    - CVE-2012-1148

Date: Mon, 10 Sep 2012 14:57:29 -0700
Changed-By: Tyler Hicks <tyhicks at canonical.com>
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
Signed-By: Micah Gersten <launchpad at micahscomputing.com>
https://launchpad.net/ubuntu/quantal/+source/xmlrpc-c/1.16.33-3.1ubuntu6
-------------- next part --------------
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Format: 1.8
Date: Mon, 10 Sep 2012 14:57:29 -0700
Source: xmlrpc-c
Binary: libxmlrpc-c++4-dev libxmlrpc-c++4 libxmlrpc-c3-dev libxmlrpc-core-c3-dev libxmlrpc-core-c3 libxmlrpc-core-c3-udeb xmlrpc-api-utils
Architecture: source
Version: 1.16.33-3.1ubuntu6
Distribution: quantal
Urgency: low
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
Changed-By: Tyler Hicks <tyhicks at canonical.com>
Description: 
 libxmlrpc-c++4 - lightweight RPC library based on XML and HTTP [C++ runtime librar
 libxmlrpc-c++4-dev - lightweight RPC library based on XML and HTTP [C++ development li
 libxmlrpc-c3-dev - lightweight RPC library based on XML and HTTP [transitional packa
 libxmlrpc-core-c3 - lightweight RPC library based on XML and HTTP [C runtime librarie
 libxmlrpc-core-c3-dev - lightweight RPC library based on XML and HTTP [C development libr
 libxmlrpc-core-c3-udeb - A lightweight RPC library based on XML and HTTP (core libraries) (udeb)
 xmlrpc-api-utils - Generate C++ wrapper classes for XML-RPC servers
Launchpad-Bugs-Fixed: 1048835
Changes: 
 xmlrpc-c (1.16.33-3.1ubuntu6) quantal; urgency=low
 .
   * Run the tests as part of the build process
     - debian/patches/FTBFS-tests.patch: Fix issues when running make check.
       Based on upstream patches.
     - debian/rules: Run make check after building
   * Fix dependencies of xmlrpc-api-utils
     - debian/control: xml-rcp-api2cpp needs libxmlrpc_cpp.so.4, so depend on
       libxmlrpc-c++4
   * SECURITY UPDATE: Denial of service via hash collisions (LP: #1048835)
     - debian/patches/CVE-2012-0876.patch: Add random salt value to
       hash inputs. Based on upstream patch.
     - CVE-2012-0876
   * SECURITY UPDATE: Denial of service via memory leak (LP: #1048835)
     - debian/patches/CVE-2012-1148.patch: Properly reallocate memory.
       Based on upstream patch.
     - CVE-2012-1148
Checksums-Sha1: 
 c5a24852e78c4d52f509cc26e777da0a5fc9e198 1651 xmlrpc-c_1.16.33-3.1ubuntu6.dsc
 8877a6fa532526e05ab722169d18ae072d501a64 22411 xmlrpc-c_1.16.33-3.1ubuntu6.diff.gz
Checksums-Sha256: 
 8e7e97a42685460ec536074c5894cc2d144a7cc27663e5dbb0f4adc6d4485056 1651 xmlrpc-c_1.16.33-3.1ubuntu6.dsc
 3450eea85232dae3c3fcaa5d94d4648f3b18e65f77af60d25c2afc2e87eac690 22411 xmlrpc-c_1.16.33-3.1ubuntu6.diff.gz
Files: 
 f787ca9ca81720e38a24b5c5a2ef0bda 1651 libs optional xmlrpc-c_1.16.33-3.1ubuntu6.dsc
 8bb4492b2b3468e33f34d996e350eb6f 22411 libs optional xmlrpc-c_1.16.33-3.1ubuntu6.diff.gz
Original-Maintainer: Sean Finney <seanius at debian.org>

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.11 (GNU/Linux)

iEYEARECAAYFAlBPfPUACgkQTniv4aqX/VnT8gCeNAYrQ1BoTF0wqTHbK5EPeYT/
RWMAnRMPqZmpvdLYNe6qjVXTHNmm0ksb
=S3Xz
-----END PGP SIGNATURE-----


More information about the Quantal-changes mailing list