~ubuntu-branches/debian/squeeze/ia32-libs/squeeze

« back to all changes in this revision

Viewing changes to srcs/nspr_4.8.6-1.dsc

  • Committer: Package Import Robot
  • Author(s): Thijs Kinkhorst, curl (7.21.0-2.1+squeeze7) squeeze-security; urgency=high, curl (7.21.0-2.1+squeeze6) oldstable-security; urgency=low, curl (7.21.0-2.1+squeeze5) oldstable-security; urgency=high, libxml2 (2.7.8.dfsg-2+squeeze8) oldstable-security; urgency=high, nspr (4.8.6-1+squeeze1) squeeze-security; urgency=high, nss (3.12.8-1+squeeze7) squeeze-security; urgency=high
  • Date: 2014-01-31 09:19:46 UTC
  • Revision ID: package-import@ubuntu.com-20140131091946-z2j1eo8mxt7r703f
Tags: 20140131
* Packages updated

[ curl (7.21.0-2.1+squeeze7) squeeze-security; urgency=high ]

* Fix re-use of wrong HTTP NTLM connection as per CVE-2014-0015
  http://curl.haxx.se/docs/adv_20140129.html
* Set urgency=high accordingly

[ curl (7.21.0-2.1+squeeze6) oldstable-security; urgency=low ]

* Disable host verification too when using the --insecure option
  (#729965)

[ curl (7.21.0-2.1+squeeze5) oldstable-security; urgency=high ]

* Fix OpenSSL checking of a certificate CN or SAN name field when the
  digital signature verification is turned off as per CVE-2013-4545
  http://curl.haxx.se/docs/adv_20131115.html
* Set urgency=high accordingly

[ libxml2 (2.7.8.dfsg-2+squeeze8) oldstable-security; urgency=high ]

* Non-maintainer upload by the Security Team.
* Fix cve-2013-2877: out-of-bounds read when handling documents that end
  abruptly.

[ nspr (4.8.6-1+squeeze1) squeeze-security; urgency=high ]

* Non-maintainer upload by the Security Team.
* Fix CVE-2013-5607: integer overflow on 64 bit systems

[ nss (3.12.8-1+squeeze7) squeeze-security; urgency=high ]

* Non-maintainer upload by the Security Team.
* Add CVE-2013-5605.patch.
  CVE-2013-5605: Null_Cipher() does not respect maxOutputLen; allowing
  remote attackers to cause a denial of service or possibly have
  unspecified other impact via invalid handshake packets.

Show diffs side-by-side

added added

removed removed

Lines of Context:
1
 
-----BEGIN PGP SIGNED MESSAGE-----
2
 
Hash: SHA1
3
 
 
4
 
Format: 3.0 (quilt)
5
 
Source: nspr
6
 
Binary: libnspr4-0d, libnspr4-dev, libnspr4-0d-dbg
7
 
Architecture: any
8
 
Version: 4.8.6-1
9
 
Maintainer: Maintainers of Mozilla-related packages <pkg-mozilla-maintainers@lists.alioth.debian.org>
10
 
Uploaders: Mike Hommey <glandium@debian.org>
11
 
Homepage: http://www.mozilla.org/projects/nspr/
12
 
Standards-Version: 3.9.1.0
13
 
Vcs-Browser: http://git.debian.org/?p=pkg-mozilla/nspr.git
14
 
Vcs-Git: git://git.debian.org/git/pkg-mozilla/nspr.git
15
 
Build-Depends: debhelper (>= 7.0.50), autotools-dev
16
 
Checksums-Sha1: 
17
 
 54ca3cbe14cc8a2a59cb48d4961034ce35c8f223 1202257 nspr_4.8.6.orig.tar.gz
18
 
 5c03bb047cdfd1d859b2bb915852c3d50dacdb4b 29359 nspr_4.8.6-1.debian.tar.gz
19
 
Checksums-Sha256: 
20
 
 d9040bb01536fa63881c423c4fa831ea459696b32d2097f614842f824e1a9f6d 1202257 nspr_4.8.6.orig.tar.gz
21
 
 c772376ee061d21a4ea6794219b83f4a607fb9c8e098be975179bd854e610b01 29359 nspr_4.8.6-1.debian.tar.gz
22
 
Files: 
23
 
 592c275728c29d193fdba8009165990b 1202257 nspr_4.8.6.orig.tar.gz
24
 
 829283cb2308254f7023a5577cf96eb6 29359 nspr_4.8.6-1.debian.tar.gz
25
 
 
26
 
-----BEGIN PGP SIGNATURE-----
27
 
Version: GnuPG v1.4.10 (GNU/Linux)
28
 
 
29
 
iD8DBQFMW7GB3kvaLFT9KlgRAhJoAJ9ElilHbd12C6BIdjkJO3MVTmir9gCfQ70O
30
 
ySnYr4FVOBDH8poN2UyKyVk=
31
 
=G5ob
32
 
-----END PGP SIGNATURE-----