diff -Nru jenkins-1.409.1/debian/changelog jenkins-1.409.1/debian/changelog --- jenkins-1.409.1/debian/changelog 2011-10-11 08:53:35.000000000 +0100 +++ jenkins-1.409.1/debian/changelog 2011-11-22 13:05:59.000000000 +0000 @@ -1,3 +1,10 @@ +jenkins (1.409.1-0ubuntu4.1) oneiric-security; urgency=low + + * SECURITY UPDATE: Rebuild to pickup new version of jenkins-winstone + to close out XSS security vulnerability (LP: #889181). + + -- James Page Tue, 22 Nov 2011 13:04:34 +0000 + jenkins (1.409.1-0ubuntu4) oneiric; urgency=low * Resolve conflict between winstone and libservlet2.5-java (LP: #862272): diff -Nru jenkins-1.409.1/debian/control jenkins-1.409.1/debian/control --- jenkins-1.409.1/debian/control 2011-10-07 15:48:01.000000000 +0100 +++ jenkins-1.409.1/debian/control 2011-11-22 13:06:45.000000000 +0000 @@ -47,7 +47,7 @@ libjenkins-commons-jelly-java, libjenkins-commons-jexl-java, libjenkins-trilead-ssh2-java, - libjenkins-winstone-java, + libjenkins-winstone-java (>= 0.9.10-jenkins-25+dfsg-0ubuntu2.1~), libjenkins-xstream-java, libjetty-java, libjffi-java,