~ubuntu-branches/debian/squeeze/ia32-libs/squeeze

« back to all changes in this revision

Viewing changes to debian/copyright

  • Committer: Package Import Robot
  • Author(s): Thijs Kinkhorst, curl (7.21.0-2.1+squeeze7) squeeze-security; urgency=high, curl (7.21.0-2.1+squeeze6) oldstable-security; urgency=low, curl (7.21.0-2.1+squeeze5) oldstable-security; urgency=high, libxml2 (2.7.8.dfsg-2+squeeze8) oldstable-security; urgency=high, nspr (4.8.6-1+squeeze1) squeeze-security; urgency=high, nss (3.12.8-1+squeeze7) squeeze-security; urgency=high
  • Date: 2014-01-31 09:19:46 UTC
  • Revision ID: package-import@ubuntu.com-20140131091946-z2j1eo8mxt7r703f
Tags: 20140131
* Packages updated

[ curl (7.21.0-2.1+squeeze7) squeeze-security; urgency=high ]

* Fix re-use of wrong HTTP NTLM connection as per CVE-2014-0015
  http://curl.haxx.se/docs/adv_20140129.html
* Set urgency=high accordingly

[ curl (7.21.0-2.1+squeeze6) oldstable-security; urgency=low ]

* Disable host verification too when using the --insecure option
  (#729965)

[ curl (7.21.0-2.1+squeeze5) oldstable-security; urgency=high ]

* Fix OpenSSL checking of a certificate CN or SAN name field when the
  digital signature verification is turned off as per CVE-2013-4545
  http://curl.haxx.se/docs/adv_20131115.html
* Set urgency=high accordingly

[ libxml2 (2.7.8.dfsg-2+squeeze8) oldstable-security; urgency=high ]

* Non-maintainer upload by the Security Team.
* Fix cve-2013-2877: out-of-bounds read when handling documents that end
  abruptly.

[ nspr (4.8.6-1+squeeze1) squeeze-security; urgency=high ]

* Non-maintainer upload by the Security Team.
* Fix CVE-2013-5607: integer overflow on 64 bit systems

[ nss (3.12.8-1+squeeze7) squeeze-security; urgency=high ]

* Non-maintainer upload by the Security Team.
* Add CVE-2013-5605.patch.
  CVE-2013-5605: Null_Cipher() does not respect maxOutputLen; allowing
  remote attackers to cause a denial of service or possibly have
  unspecified other impact via invalid handshake packets.

Show diffs side-by-side

added added

removed removed

Lines of Context:
843
843
 
844
844
----
845
845
---------------------------------------------------------------
846
 
Copyright for ./curl_7.21.0-2.1+squeeze4.dsc
 
846
Copyright for ./curl_7.21.0-2.1+squeeze7.dsc
847
847
This package was debianized by Domenico Andreoli <cavok@debian.org> on
848
848
Fri, 17 Nov 2000 16:10:37 +0100
849
849
 
8666
8666
   dealings in this Software without prior written authorization from Digital
8667
8667
   Equipment Corporation.
8668
8668
---------------------------------------------------------------
8669
 
Copyright for ./libxml2_2.7.8.dfsg-2+squeeze7.dsc
 
8669
Copyright for ./libxml2_2.7.8.dfsg-2+squeeze8.dsc
8670
8670
This package was debianized by Vincent Renardias <vincent@waw.com> on
8671
8671
Sat, 26 Sep 1998 16:50:54 +0200
8672
8672
 
9685
9685
 
9686
9686
Translation:  You can do whatever you want with this software!
9687
9687
---------------------------------------------------------------
9688
 
Copyright for ./nspr_4.8.6-1.dsc
 
9688
Copyright for ./nspr_4.8.6-1+squeeze1.dsc
9689
9689
This package was debianized by Mike Hommey <glandium@debian.org> on
9690
9690
Sun, 25 Mar 2007 12:17:27 +0200.
9691
9691
 
10276
10276
          may use your version of this file under either the NPL or the
10277
10277
          [___] License."
10278
10278
---------------------------------------------------------------
10279
 
Copyright for ./nss_3.12.8-1+squeeze6.dsc
 
10279
Copyright for ./nss_3.12.8-1+squeeze7.dsc
10280
10280
This package was debianized by Mike Hommey <glandium@debian.org> on
10281
10281
Sun, 25 Mar 2007 19:36:42 +0200.
10282
10282