mailman: need versioned build-depends on dpatch

Bug #12569 reported by Debian Bug Importer
6
Affects Status Importance Assigned to Milestone
mailman (Debian)
Fix Released
Unknown
mailman (Ubuntu)
Fix Released
High
Tollef Fog Heen

Bug Description

Automatically imported from Debian bug report #291289 http://bugs.debian.org/291289

CVE References

Revision history for this message
In , Tollef Fog Heen (tfheen) wrote : severity of 291289 is serious

# Automatically generated email from bts, devscripts version 2.8.6
severity 291289 serious

Revision history for this message
Debian Bug Importer (debzilla) wrote :

Automatically imported from Debian bug report #291289 http://bugs.debian.org/291289

Revision history for this message
Debian Bug Importer (debzilla) wrote :

Message-Id: <email address hidden>
Date: Wed, 19 Jan 2005 16:22:31 -0500
From: m. toups <email address hidden>
To: <email address hidden>
Subject: mailman: need versioned build-depends on dpatch

Package: mailman
Version: 2.1.5-5
Severity: normal

currently (2.1.5-5) mailman's Build-Depends line is as follows:

Build-Depends: debhelper (>= 4.1.16), autoconf, python-dev, dpatch

however trying to build mailman from source with dpatch 2.0.2 yielded:

applying patch 02_CAN-2004-1177_driver_css to ./ .../usr/share/dpatch/dpatch-run: /usr/share/dpatch/dpatch-run: No such file or directory

it looks like dpatch-run wasn't added until dpatch 2.0.9

upgrading to dpatch 2.0.10 solved this problem for me, but technically
there should be a versioned build-depends there

-matt

-- System Information
Debian Release: 3.0
Kernel Version: Linux howard 2.2.26 #8 SMP Tue Mar 16 18:35:14 EST 2004 sparc unknown

Revision history for this message
Debian Bug Importer (debzilla) wrote :

Message-Id: <email address hidden>
Date: Sat, 5 Feb 2005 12:46:46 +0100
From: Tollef Fog Heen <email address hidden>
To: <email address hidden>
Subject: severity of 291289 is serious

# Automatically generated email from bts, devscripts version 2.8.6
severity 291289 serious

Revision history for this message
In , Tollef Fog Heen (tfheen) wrote : Bug#291289: fixed in mailman 2.1.5-6

Source: mailman
Source-Version: 2.1.5-6

We believe that the bug you reported is fixed in the latest version of
mailman, which is due to be installed in the Debian FTP archive:

mailman_2.1.5-6.diff.gz
  to pool/main/m/mailman/mailman_2.1.5-6.diff.gz
mailman_2.1.5-6.dsc
  to pool/main/m/mailman/mailman_2.1.5-6.dsc
mailman_2.1.5-6_i386.deb
  to pool/main/m/mailman/mailman_2.1.5-6_i386.deb

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to <email address hidden>,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Tollef Fog Heen <email address hidden> (supplier of updated mailman package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing <email address hidden>)

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Format: 1.7
Date: Thu, 10 Feb 2005 12:10:42 +0100
Source: mailman
Binary: mailman
Architecture: source i386
Version: 2.1.5-6
Distribution: unstable
Urgency: high
Maintainer: Tollef Fog Heen <email address hidden>
Changed-By: Tollef Fog Heen <email address hidden>
Description:
 mailman - Powerful, web-based mailing list manager
Closes: 283973 291289 293002 294467
Changes:
 mailman (2.1.5-6) unstable; urgency=high
 .
   * SECURITY UPDATE: fix information disclosure
   * Added debian/patches/04_CAN-2005-0202.dpatch:
     Mailman/Cgi/private.py, true_path(): fix the removal of '..' and '.' from
     private mail archive paths to prohibit path traversal (the former version
     transformed ".....///" to "../") (closes: #294467)
     (References: CAN-2005-0202)
   * Tighten build-deps on dpatch. (closes: #291289)
   * Update Czech debconf translation. (closes: #293002)
   * Add Dutch debconf translation. (closes: #283973)
Files:
 91fdedde9ada517bc94e52a29d8fa56a 651 mail optional mailman_2.1.5-6.dsc
 bf85a3cb885618a9964a873fb769225e 182465 mail optional mailman_2.1.5-6.diff.gz
 f30d18591db657a0c2870e54326a566c 6609034 mail optional mailman_2.1.5-6_i386.deb

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.5 (GNU/Linux)

iD8DBQFCC0YhQSseMYF6mWoRAn0FAJ91wD2djTv3KfETu6Cc3o/+WwjsKwCfX5jM
mkzVv05og/sDBHWI4mLFd50=
=+ZBW
-----END PGP SIGNATURE-----

Revision history for this message
Debian Bug Importer (debzilla) wrote :

Message-Id: <email address hidden>
Date: Thu, 10 Feb 2005 06:47:31 -0500
From: Tollef Fog Heen <email address hidden>
To: <email address hidden>
Subject: Bug#291289: fixed in mailman 2.1.5-6

Source: mailman
Source-Version: 2.1.5-6

We believe that the bug you reported is fixed in the latest version of
mailman, which is due to be installed in the Debian FTP archive:

mailman_2.1.5-6.diff.gz
  to pool/main/m/mailman/mailman_2.1.5-6.diff.gz
mailman_2.1.5-6.dsc
  to pool/main/m/mailman/mailman_2.1.5-6.dsc
mailman_2.1.5-6_i386.deb
  to pool/main/m/mailman/mailman_2.1.5-6_i386.deb

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to <email address hidden>,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Tollef Fog Heen <email address hidden> (supplier of updated mailman package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing <email address hidden>)

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Format: 1.7
Date: Thu, 10 Feb 2005 12:10:42 +0100
Source: mailman
Binary: mailman
Architecture: source i386
Version: 2.1.5-6
Distribution: unstable
Urgency: high
Maintainer: Tollef Fog Heen <email address hidden>
Changed-By: Tollef Fog Heen <email address hidden>
Description:
 mailman - Powerful, web-based mailing list manager
Closes: 283973 291289 293002 294467
Changes:
 mailman (2.1.5-6) unstable; urgency=high
 .
   * SECURITY UPDATE: fix information disclosure
   * Added debian/patches/04_CAN-2005-0202.dpatch:
     Mailman/Cgi/private.py, true_path(): fix the removal of '..' and '.' from
     private mail archive paths to prohibit path traversal (the former version
     transformed ".....///" to "../") (closes: #294467)
     (References: CAN-2005-0202)
   * Tighten build-deps on dpatch. (closes: #291289)
   * Update Czech debconf translation. (closes: #293002)
   * Add Dutch debconf translation. (closes: #283973)
Files:
 91fdedde9ada517bc94e52a29d8fa56a 651 mail optional mailman_2.1.5-6.dsc
 bf85a3cb885618a9964a873fb769225e 182465 mail optional mailman_2.1.5-6.diff.gz
 f30d18591db657a0c2870e54326a566c 6609034 mail optional mailman_2.1.5-6_i386.deb

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.5 (GNU/Linux)

iD8DBQFCC0YhQSseMYF6mWoRAn0FAJ91wD2djTv3KfETu6Cc3o/+WwjsKwCfX5jM
mkzVv05og/sDBHWI4mLFd50=
=+ZBW
-----END PGP SIGNATURE-----

Revision history for this message
Tollef Fog Heen (tfheen) wrote :

Fixed in Debian and synced; closing.

Changed in mailman:
status: Unknown → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.