Ubuntu Archive Auto-Sync katie at jackass.ubuntu.com
Tue Nov 1 22:45:03 CST 2005


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Origin: Debian/unstable
Format: 1.7
Date: Wed,  02 Nov 2005 04:35:07 +0000
Source: acidlab
Binary: acidlab-mysql, acidlab, acidlab-pgsql, acidlab-doc
Architecture: source
Version: 0.9.6b20-13
Distribution: dapper
Urgency: high
Maintainer: Jeremy T. Bouse <jbouse at debian.org>
Changed-By: Ubuntu Archive Auto-Sync <katie at jackass.ubuntu.com>
Description: 
 acidlab    - Analysis Console for Intrusion Databases
Closes: 155212 247730 270171 303217 307712 314566 315135 331732
Changes: 
 acidlab (0.9.6b20-13) unstable; urgency=high
 .
   * Patch [013] SECURITY fix:
     - Add proper filtering in all ImportHTTP variables using either the new
     functions to check for numeric/alphanumeric chars or the filterSql()
     function to prevent SQL injection attacks. This patch fixes CVE-2005-3325 
     but also other attack vectors not mentioned in the initial advisory
     (http://www.frsirt.com/english/advisories/2005/2188)
   * Patch [014] Updated dates of php selections up to 2007
   * Changed patch [010]: fix locations of Nessus
   * New patch [015]: fix location of Snort database, provided alternative
     Ports lookup and added alternative locations for DNS queries (Closes: #315135)
   * Fixed FSF address in debian/copyright
   * Patch [016]: Allow graphic data to be represented until 2007. This patch
     together with patch [014] means that acid's last date is 2007 which should be
     enough since we are going to replace it with BASE in the short term 
     (Closes: #314566, #307712, #303217, #270171)
   * Document the changes that need to be done in order to extend the available
     year options (Closes: #247730)
   * Added a debian/TODO to describe how to fix the issue with new years with a
     simple for each loop.
   * Acidlab now depends on "| debconf-2.0" as requested by Joey Hess, I
     changed debian/packages instead of debian/control this time (Closes: #331732)
   * To reduce the risk of possible vulnerabilities in the code, made the
     default apache.conf allow access only from localhost and document this in
     the README file
   * Document the fact that this version is actually 0.9.6b20+patches from the
     latest upstream release 0.9.6b23 and that the later will never be
     released. (Closes: #155212)
   * Added the upstream homepage to all package descriptions.
Files: 
 7b39c7253ad82010d391af41e4c97d14 354649 web extra acidlab_0.9.6b20-13.diff.gz
 738b1a585919b2b924e24fbb34ce3be7 840 web extra acidlab_0.9.6b20-13.dsc
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.5 (GNU/Linux)

iQEVAwUBQ2hB+wF4adwMEr3XAQKx2Qf+IDp84FqIyCSrG3/+kbf3OjjnXOhPauIe
pkzoPAt83YIw7H2nMRrS2lgPOrizECmgS8ImKvSSE6aPs13OxnGmD9TSrgaRRYxN
+eBlh5gRYBgFb03G8+WfIHM1zUwffTMd2JBtH8bwZMxBIBh3R9IDz+0ZB3ChxtXi
A1HscrOqQ0aNP4z5jcPm7NXk86lnph/AJe3AT2odNNfqCaHKaNREqGrpzPaKXaLb
iIV+DS0/G3LHa59bW8EpXJZOOkqZCz4A6ZIWJixEqGexy/z9tULF+a3gE34S/Bii
S4LHAZ2pCJOGs3xao3bqOdv8dsw4ya1dLFCgu1T8WET7ZBtrgRTOOw==
=ikuY
-----END PGP SIGNATURE-----


Accepted:
acidlab_0.9.6b20-13.diff.gz
  to pool/universe/a/acidlab/acidlab_0.9.6b20-13.diff.gz
acidlab_0.9.6b20-13.dsc
  to pool/universe/a/acidlab/acidlab_0.9.6b20-13.dsc




More information about the ubuntu-changes-auto mailing list