Merge ntfs-3g 1:2021.8.22-3 from Debian

Bug #1951239 reported by Simon Chopin
8
This bug affects 1 person
Affects Status Importance Assigned to Milestone
ntfs-3g (Ubuntu)
Fix Released
Wishlist
Unassigned

Bug Description

Hi,

I've worked on merging ntfs-3g 1:2021.8.22-3 from Debian unstable. You'll find below a debdiff against the Debian version, as well as a bigger debdiff generated against the last Ubuntu version.

Revision history for this message
Simon Chopin (schopin) wrote :
Revision history for this message
Simon Chopin (schopin) wrote :
Revision history for this message
Simon Chopin (schopin) wrote :

The package has also been uploaded to a PPA:

https://launchpad.net/~schopin/+archive/ubuntu/test-ppa/+packages

Revision history for this message
Paride Legovini (paride) wrote :

Hi Simon,

I didn't test your package but debdiff LGTM, thanks! Your upload should include the changes just discussed in LP: #1957756, namely:

 - Set `Pre-Depends: fuse3` for bin:ntfs-3g
 - Drop the Build-Dep on libfuse-dev (not used), to ease the fuse2 demotion (see LP: #1934510)

Revision history for this message
Sebastien Bacher (seb128) wrote :

I'm going to sponsor the merge and include those changes since I uploaded them before checking the open requests first

Changed in ntfs-3g (Ubuntu):
status: New → Fix Committed
Revision history for this message
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package ntfs-3g - 1:2021.8.22-3ubuntu1

---------------
ntfs-3g (1:2021.8.22-3ubuntu1) jammy; urgency=medium

  * debian/control:
    - don't Build-Depends on libfuse-dev since the package is built using
      the --with-fuse=internal option, switch to fuse3

  [ Simon Chopin ]
  * Merge with Debian unstable (LP: #1951239). Remaining changes:
    + Don't install /bin/ntfs-3g as setuid root.
  * Dropped, merged upstream:
    + SECURITY UPDATE: multiple security issues
      debian/patches/aug2021-security.patch: backport fixes from new
      upstream version.
      - CVE-2021-33285, CVE-2021-33286, CVE-2021-33287, CVE-2021-33289,
        CVE-2021-35266, CVE-2021-35267, CVE-2021-35268, CVE-2021-35269,
        CVE-2021-39251, CVE-2021-39252, CVE-2021-39253, CVE-2021-39254,
        CVE-2021-39255, CVE-2021-39256, CVE-2021-39257, CVE-2021-39258,
        CVE-2021-39259, CVE-2021-39260, CVE-2021-39261, CVE-2021-39262,
        CVE-2021-39263

ntfs-3g (1:2021.8.22-3) unstable; urgency=medium

  * Backport upstream documentation updates.
  * Update homepage location (closes: #993989).
  * Update watch file.
  * Update Standards-Version to 4.6.0 .

ntfs-3g (1:2021.8.22-2) unstable; urgency=medium

  * Upload to Sid.

ntfs-3g (1:2021.8.22-1) experimental; urgency=high

  * New upstream release (closes: #988386) fixing CVE-2021-33285,
    CVE-2021-35269, CVE-2021-35268, CVE-2021-33289, CVE-2021-33286,
    CVE-2021-35266, CVE-2021-33287, CVE-2021-35267, CVE-2021-39251,
    CVE-2021-39252, CVE-2021-39253, CVE-2021-39254, CVE-2021-39255,
    CVE-2021-39256, CVE-2021-39257, CVE-2021-39258, CVE-2021-39259,
    CVE-2021-39260, CVE-2021-39261, CVE-2021-39262, CVE-2021-39263: multiple
    buffer overflows.
  * Library transition from libntfs-3g886 to libntfs-3g89 .

ntfs-3g (1:2017.3.23AR.6-1) experimental; urgency=medium

  * New upstream release.
  * Library transition from libntfs-3g885 to libntfs-3g886 .
  * Update debhelper level to 13 .
  * Update Standards-Version to 4.5.1 .

ntfs-3g (1:2017.3.23AR.5-1) experimental; urgency=medium

  * New upstream release.
  * Library transition from libntfs-3g884 to libntfs-3g885 .
  * Update Standards-Version to 4.5.0 .

ntfs-3g (1:2017.3.23AR.4-1) experimental; urgency=medium

  * New upstream release.
  * Prevent installation of hal/fdi/policy (closes: #913281).
  * Library transition from libntfs-3g883 to libntfs-3g884 .

 -- Sebastien Bacher <email address hidden> Thu, 13 Jan 2022 15:38:10 +0100

Changed in ntfs-3g (Ubuntu):
status: Fix Committed → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.