[UVFe] Sync zziplib (0.13.49-2) from Debian unstable

Bug #134588 reported by Michael Bienia
4
Affects Status Importance Assigned to Milestone
zziplib (Ubuntu)
Fix Released
Wishlist
Unassigned

Bug Description

Rationale:
 - CVE-2007-1614 fixed in the new version.

The new upstream version bumped the soname for the library.
The only rdepends outside zziplib is libogre14 (from ogre).

ogre builds with the new zziplib once the pkgconfig files from libzzip-dev are fixed.
I've done it manually inside a pbuilder environment to test if ogre still builds with this new version.
I've already reported this problem to Debian (Debian bug #439395).

Changelog:

zziplib (0.13.49-2) unstable; urgency=low

  * debian/rules: added configure option --datadir, closes: #439395.

 -- Anibal Monsalve Salazar <email address hidden> Sat, 25 Aug 2007 10:29:31 +1000

zziplib (0.13.49-1) unstable; urgency=low

  * libzzip-0-13 Replaces & Conflicts: libzzip-0-12

 -- Anibal Monsalve Salazar <email address hidden> Fri, 24 Aug 2007 08:41:46 +1000

zziplib (0.13.49-0) unstable; urgency=low

  * New upstream version. Closes: #399617.
    - zzip-config was removed by upstream maintainer.
    - htmpages.ar was not shipped by upstream maintainer.
    - new build dependency: python.
  * Fixed: CVE-2007-1614 DoS and execution of arbitrary code.
    Closes: #436701.
  * Fixed the following lintian messages:
    - W: zziplib source: substvar-source-version-is-deprecated libzzip-dev
    - W: zziplib source: debian-rules-ignores-make-clean-error line 62

 -- Anibal Monsalve Salazar <email address hidden> Thu, 09 Aug 2007 18:47:38 +1000

CVE References

Revision history for this message
Michael Bienia (geser) wrote :
Revision history for this message
Michael Bienia (geser) wrote :
Revision history for this message
Michael Bienia (geser) wrote :
Revision history for this message
Scott Kitterman (kitterman) wrote :

Ack from me then.

Revision history for this message
Chuck Short (zulcss) wrote :

ditto

Revision history for this message
Sarah Kowalik (hobbsee-deactivatedaccount) wrote : (no subject)

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

 status triaged
 subscribe ubuntu-archive
 unsubscribe ubuntu-universe-sponsors
 unsubscribe motu-uvf

Request approved
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org

iD8DBQFG0A887/o1b30rzoURAofaAKDsUVWHXo5quyM2/3Y8LQ0nCg1isgCgim25
mKXjz+pexZT4gITvk6iVjUs=
=nWQ1
-----END PGP SIGNATURE-----

Changed in zziplib:
status: New → Triaged
Michael Bienia (geser)
description: updated
Revision history for this message
Sebastien Bacher (seb128) wrote :

[Updating] zziplib (0.12.83-8 [Ubuntu] < 0.13.49-2 [Debian])
 * Trying to add zziplib...
  - <zziplib_0.13.49.orig.tar.gz: downloading from http://ftp.debian.org/debian/>
  - <zziplib_0.13.49-2.diff.gz: downloading from http://ftp.debian.org/debian/>
  - <zziplib_0.13.49-2.dsc: downloading from http://ftp.debian.org/debian/>
I: zziplib [universe] -> zziplib-bin_0.12.83-8 [universe].
I: zziplib [universe] -> libzzip-dev_0.12.83-8 [universe].

Changed in zziplib:
importance: Undecided → Wishlist
status: Triaged → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.