Please sync tcl8.3 8.3.5-13 (main) from Debian unstable (main).

Bug #246423 reported by Michael Bienia
4
Affects Status Importance Assigned to Milestone
tcl8.3 (Ubuntu)
Fix Released
Wishlist
Unassigned

Bug Description

Binary package hint: tcl8.3

Please sync tcl8.3 8.3.5-13 (main) from Debian unstable (main).

Changelog since current intrepid version 8.3.5-12:

tcl8.3 (8.3.5-13) unstable; urgency=medium

  * Fixed CVE-2007-4772 vulnerability (The regular expression parser in TCL
    before 8.4.17 allows attacker to cause a denial of service (infinite
    loop) via a crafted regular expression.)
  * Fixed CVE-2007-6067 vulnerability (The regular expression parser in TCL
    allows users to cause a denial of service (memory consumption) via a
    crafted "complex" regular expression with doubly-nested states.)
  * Set urgency to medium as this upload fixes a security bug.
  * Protected quilt calls in debian/rules to make the source package
    convertible to 3.0 (quilt) format (closes: #484912).
  * Bumped standards version to 3.8.0.

 -- Sergei Golovan <email address hidden> Sat, 05 Jul 2008 17:31:11 +0400

Michael Bienia (geser)
Changed in tcl8.3:
importance: Undecided → Wishlist
Revision history for this message
Daniel Holbach (dholbach) wrote : ACK of sync request

ACKed.

Revision history for this message
Martin Pitt (pitti) wrote :

Getting binaries for intrepid...
[Updating] tcl8.3 (8.3.5-12 [Ubuntu] < 8.3.5-13 [Debian])
 * Trying to add tcl8.3...
  - <tcl8.3_8.3.5-13.dsc: downloading from http://ftp.debian.org/debian/>
  - <tcl8.3_8.3.5.orig.tar.gz: already in distro - downloading from librarian>
  - <tcl8.3_8.3.5-13.diff.gz: downloading from http://ftp.debian.org/debian/>
I: tcl8.3 [main] -> tcl8.3_8.3.5-12 [main].
I: tcl8.3 [main] -> tcl8.3-doc_8.3.5-12 [main].
I: tcl8.3 [main] -> tcl8.3-dev_8.3.5-12 [main].

Changed in tcl8.3:
status: New → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.