-
Committer:
Bazaar Package Importer
-
Author(s):
Lorenzo De Liso
-
Date:
2010-11-02 15:17:29 UTC
-
mfrom:
(2.1.8 sid)
-
Revision ID:
james.westby@ubuntu.com-20101102151729-b6shpzcqo8hpxy9i
Tags: 1.12-2.1ubuntu1
* Merge from debian unstable (LP: #403070), remaining changes:
- Add wget-udeb to ship wget.gnu as alternative to busybox wget
implementation.
- Keep build dependencies in main:
+ debian/control: remove info2man build-dep
+ debian/patches/00list: disable wget-infopod_generated_manpage.dpatch
- Depend on libssl-dev 0.9.8k-7ubuntu4 (LP: #503339)
* Dropped changes:
- SECURITY UPDATE: arbitrary file overwrite via 3xx redirect
+ debian/patches/CVE-2010-2252.dpatch: don't use server names in
doc/wget.texi, src/{http.*,init.c,main.c,options.h,retr.c}.
+ This update changes previous behaviour by ignoring the filename
supplied by the server during redirects. To re-enable previous
behaviour, see the new --trust-server-names option.
+ CVE-2010-2252: fixed in debian