Please backport wesnoth-1.12 1:1.12.5-1 (universe) from xenial
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
trusty-backports |
Won't Fix
|
Undecided
|
Unassigned |
Bug Description
Please backport wesnoth-1.12 1:1.12.5-1 (universe) from xenial to trusty.
Reason for the backport:
=======
The package fixes some security issues that the current package in
trusty-backports still have, namely CVE-2015-0844, CVE-2015-5069 and
CVE-2015-5070. Note please, there is no package in trusty, the package lives
only in backports for trusty, thus the update request for trusty-backports.
CVE-2015-0844 which is the more severe one for end users was fixed in 1.12.2
which is vivid already, but the other two CVEs probably should get addressed in
vivid too.
Given that this version would then be newer than vivid I'm uncertain whether
requests for backports to vivid (and wily) should be made too, or if the
version from vivid should be backported to trusty (to fix CVE-2015-0844) and
the patches for CVE-2015-5069 and CVE-2015-5070 should be run on top if it,
backported to vivid and wily, and then a backport request for trusty-backports
being done from the vivid version? Advice on how to proceed here is highly
appreciated, I am willing to do the main work of preparing the source but I
just need to know in what direction I should go. :)
Testing:
========
Mark off items in the checklist [X] as you test them, but please leave the checklist so that backporters can quickly evaluate the state of testing.
You can test-build the backport in your PPA with backportpackage:
$ backportpackage -u ppa:<lp username>/<ppa name> -s xenial -d trusty wesnoth-1.12
* trusty:
[X] Package builds without modification
[X] wesnoth-1.12-trow installs cleanly and runs
[X] wesnoth-1.12-ei installs cleanly and runs
[X] wesnoth-1.12-ttb installs cleanly and runs
[ ] wesnoth-1.12-tools installs cleanly and runs
[X] wesnoth-1.12-sof installs cleanly and runs
[X] wesnoth-1.12-sotbe installs cleanly and runs
[X] wesnoth-
[X] wesnoth-1.12-dbg installs cleanly and runs
[X] wesnoth-1.12-music installs cleanly and runs
[X] wesnoth-1.12-low installs cleanly and runs
[X] wesnoth-1.12-nr installs cleanly and runs
[X] wesnoth-1.12-tsg installs cleanly and runs
[X] wesnoth-1.12-utbs installs cleanly and runs
[X] wesnoth-music installs cleanly and runs
[X] wesnoth-1.12 installs cleanly and runs
[X] wesnoth-1.12-data installs cleanly and runs
[X] wesnoth-1.12-dm installs cleanly and runs
[X] wesnoth installs cleanly and runs
[ ] wesnoth-1.12-core installs cleanly and runs
[X] wesnoth-1.12-httt installs cleanly and runs
[X] wesnoth-1.12-aoi installs cleanly and runs
[X] wesnoth-1.12-l installs cleanly and runs
[X] wesnoth-
[X] wesnoth-1.12-dw installs cleanly and runs
[ ] wesnoth-1.12-server installs cleanly and runs
[X] wesnoth-1.12-did installs cleanly and runs
[X] wesnoth-1.12-thot installs cleanly and runs
[X] wesnoth-core installs cleanly and runs
I've test-installed all the packages in a trusty chroot, but I haven't run it
because I don't have graphical environment there, thus not marking the binary
containing packages as tested.
Thanks,
Rhonda
Changed in trusty-backports: | |
status: | New → Won't Fix |
Backporting straight to trusty is fine. We just need someone to do the run test before this can be processed.