Merge php-pear from Debian unstable for 22.04

Bug #1946886 reported by Bryce Harrington
8
This bug affects 1 person
Affects Status Importance Assigned to Milestone
php-pear (Ubuntu)
Incomplete
Undecided
Bryce Harrington

Bug Description

Upstream: 1.10.13
Debian: 1:1.10.12+submodules+notgz+20210212-1
Ubuntu: 1:1.10.12+submodules+notgz+20210212-1ubuntu1

Debian typically updates this package every 2 months, but has not done so since 21.04. Check back monthly.

There is a new upstream version, however, so may be worth going ahead of
debian and/or updating it in Debian and syncing it.

### New Debian Changes ###

php-pear (1:1.10.12+submodules+notgz+20210212-1) unstable; urgency=medium

  [ Ondřej Surý ]
  * (CVE-2020-36193) Update Archive_Tar to 1.4.12 (Closes: #980428)
  * Remove .gitattributes from submodules as it breaks our build

  [ Mathieu Parent ]
  * Remove all *.tgz files, to ease copyright review

 -- Ondřej Surý <email address hidden> Fri, 12 Feb 2021 09:05:38 +0100

php-pear (1:1.10.12+submodules+notgz-1) unstable; urgency=medium

  * Update PEAR to 1.10.12
  * Update Archive_Tar to 1.4.7
  * Update Console_Getopt to 1.4.2
  * Update Structures_Graph to latest trunk
  * Update XML_Util to 1.4.3
  * Lower the dh_compat level to 10 to help with backports
  * Remove .gitattributes from submodules as it breaks our build
  * Use pristine-tar (first create and then use pristine-tar commit)

 -- Ondřej Surý <email address hidden> Sat, 10 Oct 2020 15:10:13 +0200

php-pear (1:1.10.9+submodules+notgz-1) unstable; urgency=low

  [ Ondřej Surý ]
  * Update PEAR to 1.10.8
  * Update Archive_Tar to 1.4.6
  * Update Console_Getopt to 1.4.2
  * Update maintainer address
  * Update gbp.conf for salsa and enable pristine-tar
  * Bump policy to recent version (no change)

  [ Mathieu Parent ]
  * Update PEAR to 1.10.9
    - Fixes count() on non Countable (Closes: #890433)
  * Update Archive_Tar to 1.4.7
  * Update Structures_Graph to v1.1.1 + 1 minor patch
  * Add debian/README.source
  * Fix package-uses-deprecated-source-override-location
  * Fix insecure-copyright-format-uri
  * Fix debian-watch-uses-insecure-uri
  * Bump debhelper compat to 12
  * Update debian/php-pear.substvars-static
  * Fix manpage-has-errors-from-man
  * Standards-Version: 4.4.0
  * Add debian/salsa-ci.yml
  * Implement the SOURCE_DATE_EPOCH specification (Closes: #750697)

 -- Mathieu Parent <email address hidden> Thu, 01 Aug 2019 23:15:22 +0200

php-pear (1:1.10.6+submodules+notgz-1) unstable; urgency=medium

  * Update PEAR to 1.10.6

 -- Ondřej Surý <email address hidden> Mon, 01 Oct 2018 12:15:44 +0000

php-pear (1:1.10.5+submodules+notgz-1) unstable; urgency=medium

  * Update PEAR to 1.10.5
  * Update Archive_Tar to 1.4.3
  * Update XML_Util to 1.4.3

 -- Ondřej Surý <email address hidden> Thu, 10 Aug 2017 23:19:49 +0200

php-pear (1:1.10.4+submodules+notgz-1) experimental; urgency=medium

  * Update PEAR to 1.10.4
  * Rebase patches on top of 1.10.4+submodules+notgz
  * Update submodules to latest PEAR packaged versions:
    bdd47347df76dbaa89227c5e1afd6f6809985b4c submodules/Archive_Tar (1.4.2)
    82f05cd1aa3edf34e19aa7c8ca312ce13a6a577f submodules/Console_Getopt (v1.4.1)
    608fdc835a62fb238e61bd1cf0aaf6c7a4420b5c submodules/Structures_Graph (v1.1.1)
    0ee5f1d88573a935daf68d795048165b3491b5ff submodules/XML_Util (v1.4.2)

 -- Ondřej Surý <email address hidden> Tue, 30 May 2017 16:18:19 +0200

php-pear (1:1.10.1+submodules+notgz-9) unstable; urgency=medium

  * Fix Vcs-* fields (was pointing to pkg-php-tools)
  * Standards-Version: 3.9.8, no change

 -- Mathieu Parent <email address hidden> Wed, 25 Jan 2017 07:48:36 +0100

php-pear (1:1.10.1+submodules+notgz-8) unstable; urgency=medium

  * Remove /usr/share/php/{.depdb,.filemap}
    - As they would be outdated.
    - This also fixes the last remaining FTBR

 -- Mathieu Parent <email address hidden> Sun, 24 Apr 2016 00:54:49 +0200

php-pear (1:1.10.1+submodules+notgz-7) unstable; urgency=medium

  * Makes the build reproducible by fixing _lastmodified to be an int

 -- Mathieu Parent <email address hidden> Wed, 20 Apr 2016 06:47:23 +0200

php-pear (1:1.10.1+submodules+notgz-6) unstable; urgency=medium

### Old Ubuntu Delta ###

php-pear (1:1.10.12+submodules+notgz+20210212-1ubuntu1) impish; urgency=medium

  * SECURITY REGRESSIONS:
    - debian/patches/CVE-2020-36193-2.patch: fix out-of-path check for
      virtual relative symlink in submodules/Archive_Tar/Archive/Tar.php.
    - debian/patches/CVE-2020-36193-3.patch: PHP compat fix in
      submodules/Archive_Tar/Archive/Tar.php.
  * SECURITY UPDATE: incorrect symlink extraction
    - debian/patches/CVE-2021-32610.patch: properly fix symbolic link path
      traversal in submodules/Archive_Tar/Archive/Tar.php.
    - CVE-2021-32610

 -- Marc Deslauriers <email address hidden> Wed, 28 Jul 2021 10:39:27 -0400

Tags: needs-merge
Bryce Harrington (bryce)
Changed in php-pear (Ubuntu):
assignee: nobody → Bryce Harrington (bryce)
Bryce Harrington (bryce)
description: updated
Changed in php-pear (Ubuntu):
milestone: none → ubuntu-22.01
Revision history for this message
Bryce Harrington (bryce) wrote :

[No new version yet available from Debian]

Changed in php-pear (Ubuntu):
status: New → Incomplete
Bryce Harrington (bryce)
Changed in php-pear (Ubuntu):
milestone: ubuntu-22.01 → ubuntu-22.02
Bryce Harrington (bryce)
Changed in php-pear (Ubuntu):
status: Incomplete → Fix Committed
Revision history for this message
Bryce Harrington (bryce) wrote :

[Wrong package]

Changed in php-pear (Ubuntu):
status: Fix Committed → Incomplete
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.