~ubuntu-branches/ubuntu/trusty/serf/trusty-security

Viewing all changes in revision 16.

  • Committer: Package Import Robot
  • Author(s): Marc Deslauriers
  • Date: 2014-08-14 09:47:32 UTC
  • Revision ID: package-import@ubuntu.com-20140814094732-t49w7lfur4vl495a
Tags: 1.3.3-1ubuntu0.1
* SECURITY UPDATE: cert spoofing via NUL characters in CommonName and
  SubjectAltNames
  - debian/patches/CVE-2014-3504.patch: escape null bytes in
    buckets/ssl_buckets.c.
  - CVE-2014-3504
* Fix FTBFS because of expired test certs:
  - debian/patches/expired_certs.patch: switch to test certs from serf
    1.3.6.
  - debian/source/format: switch to 3.0 (quilt) so we can handle the
    binary cert file
  - debian/source/include-binaries: include binary cert file from 1.3.6.

expand all expand all

Show diffs side-by-side

added added

removed removed

Lines of Context: