Ubuntu Archive Auto-Sync
katie at jackass.ubuntu.com
Tue Nov 1 22:45:03 CST 2005
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Origin: Debian/unstable
Format: 1.7
Date: Wed, 02 Nov 2005 04:35:07 +0000
Source: acidlab
Binary: acidlab-mysql, acidlab, acidlab-pgsql, acidlab-doc
Architecture: source
Version: 0.9.6b20-13
Distribution: dapper
Urgency: high
Maintainer: Jeremy T. Bouse <jbouse at debian.org>
Changed-By: Ubuntu Archive Auto-Sync <katie at jackass.ubuntu.com>
Description:
acidlab - Analysis Console for Intrusion Databases
Closes: 155212 247730 270171 303217 307712 314566 315135 331732
Changes:
acidlab (0.9.6b20-13) unstable; urgency=high
.
* Patch [013] SECURITY fix:
- Add proper filtering in all ImportHTTP variables using either the new
functions to check for numeric/alphanumeric chars or the filterSql()
function to prevent SQL injection attacks. This patch fixes CVE-2005-3325
but also other attack vectors not mentioned in the initial advisory
(http://www.frsirt.com/english/advisories/2005/2188)
* Patch [014] Updated dates of php selections up to 2007
* Changed patch [010]: fix locations of Nessus
* New patch [015]: fix location of Snort database, provided alternative
Ports lookup and added alternative locations for DNS queries (Closes: #315135)
* Fixed FSF address in debian/copyright
* Patch [016]: Allow graphic data to be represented until 2007. This patch
together with patch [014] means that acid's last date is 2007 which should be
enough since we are going to replace it with BASE in the short term
(Closes: #314566, #307712, #303217, #270171)
* Document the changes that need to be done in order to extend the available
year options (Closes: #247730)
* Added a debian/TODO to describe how to fix the issue with new years with a
simple for each loop.
* Acidlab now depends on "| debconf-2.0" as requested by Joey Hess, I
changed debian/packages instead of debian/control this time (Closes: #331732)
* To reduce the risk of possible vulnerabilities in the code, made the
default apache.conf allow access only from localhost and document this in
the README file
* Document the fact that this version is actually 0.9.6b20+patches from the
latest upstream release 0.9.6b23 and that the later will never be
released. (Closes: #155212)
* Added the upstream homepage to all package descriptions.
Files:
7b39c7253ad82010d391af41e4c97d14 354649 web extra acidlab_0.9.6b20-13.diff.gz
738b1a585919b2b924e24fbb34ce3be7 840 web extra acidlab_0.9.6b20-13.dsc
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.5 (GNU/Linux)
iQEVAwUBQ2hB+wF4adwMEr3XAQKx2Qf+IDp84FqIyCSrG3/+kbf3OjjnXOhPauIe
pkzoPAt83YIw7H2nMRrS2lgPOrizECmgS8ImKvSSE6aPs13OxnGmD9TSrgaRRYxN
+eBlh5gRYBgFb03G8+WfIHM1zUwffTMd2JBtH8bwZMxBIBh3R9IDz+0ZB3ChxtXi
A1HscrOqQ0aNP4z5jcPm7NXk86lnph/AJe3AT2odNNfqCaHKaNREqGrpzPaKXaLb
iIV+DS0/G3LHa59bW8EpXJZOOkqZCz4A6ZIWJixEqGexy/z9tULF+a3gE34S/Bii
S4LHAZ2pCJOGs3xao3bqOdv8dsw4ya1dLFCgu1T8WET7ZBtrgRTOOw==
=ikuY
-----END PGP SIGNATURE-----
Accepted:
acidlab_0.9.6b20-13.diff.gz
to pool/universe/a/acidlab/acidlab_0.9.6b20-13.diff.gz
acidlab_0.9.6b20-13.dsc
to pool/universe/a/acidlab/acidlab_0.9.6b20-13.dsc
More information about the ubuntu-changes-auto
mailing list