Activity log for bug #240427

Date Who What changed Old value New value Message
2008-06-16 15:33:17 Thomas Winteler (Win-Soft) bug added bug
2008-06-16 15:35:45 Sebastian Rode title [needs-packaging] pdfedit v0.4.1 for hardy Please backport pdfedit v0.4.1 for hardy
2008-06-16 15:35:59 Sebastian Rode pdfedit: status New Invalid
2008-06-16 15:37:01 Sebastian Rode pdfedit: status Invalid New
2008-06-16 15:40:18 Sebastian Rode bug assigned to hardy-backports
2008-06-16 15:40:25 Sebastian Rode pdfedit: status New Invalid
2008-06-16 15:41:33 Sebastian Rode title Please backport pdfedit v0.4.1 for hardy Please backport pdfedit v0.4.1 fom intrepid to hardy
2008-07-15 15:57:48 h1repp description Binary package hint: pdfedit hi all on the current kubuntu hardy version there is only the pdfedit version 0.3.2 in the repos... please include the latest version of pdfedit v0.4.1. my current system: lsb_release -rd Description: Ubuntu 8.04 Release: 8.04 apt-cache policy pdfedit pdfedit: Installed: 0.3.2-5ubuntu2 Candidate: 0.3.2-5ubuntu2 Version table: *** 0.3.2-5ubuntu2 0 500 http://ch.archive.ubuntu.com hardy/universe Packages 100 /var/lib/dpkg/status thanks thomi Binary package hint: pdfedit hi all on the current kubuntu hardy version there is only the pdfedit version 0.3.2 in the repos... please include the latest version of pdfedit v0.4.1. my current system: lsb_release -rd Description: Ubuntu 8.04 Release: 8.04 apt-cache policy pdfedit pdfedit: Installed: 0.3.2-5ubuntu2 Candidate: 0.3.2-5ubuntu2 Version table: *** 0.3.2-5ubuntu2 0 500 http://ch.archive.ubuntu.com hardy/universe Packages 100 /var/lib/dpkg/status thanks thomi ---------------------------------------------------------------- Hello, I just want to second this request and present further details why it would be worthy: pdfedit is unrivaled when it comes to editing a pdf without any conversion to another format, doing all the work with the pdf objects themself. The new version 0.4.1 has some major enhancements and security fixes as compared to the 0.3.2 that is in hardy repositories. The most significant part is that the version of xpdf that is compiled statically into the executable is so much newer, the one in the repositories is still vulnerable to the xpdf exploit from 2007. I quote from the version 0.4.0 announcement:: - many bug fixes (see Changelog) some of them security related. - last 3.02 xpdf code base imported to the tree. This bring some new features like anti-aliasing for vectored graphics, support for PDF 1.6, 1.7 specification, security fixes and many others (see src/xpdf/CHANGES for complete changelog) Regarding hardy's LTS status it would be great if users had an option not to stick with its vulnerable version unable to work with newer pdfs for the next years. thank you h1repp
2008-07-15 16:16:36 h1repp description Binary package hint: pdfedit hi all on the current kubuntu hardy version there is only the pdfedit version 0.3.2 in the repos... please include the latest version of pdfedit v0.4.1. my current system: lsb_release -rd Description: Ubuntu 8.04 Release: 8.04 apt-cache policy pdfedit pdfedit: Installed: 0.3.2-5ubuntu2 Candidate: 0.3.2-5ubuntu2 Version table: *** 0.3.2-5ubuntu2 0 500 http://ch.archive.ubuntu.com hardy/universe Packages 100 /var/lib/dpkg/status thanks thomi ---------------------------------------------------------------- Hello, I just want to second this request and present further details why it would be worthy: pdfedit is unrivaled when it comes to editing a pdf without any conversion to another format, doing all the work with the pdf objects themself. The new version 0.4.1 has some major enhancements and security fixes as compared to the 0.3.2 that is in hardy repositories. The most significant part is that the version of xpdf that is compiled statically into the executable is so much newer, the one in the repositories is still vulnerable to the xpdf exploit from 2007. I quote from the version 0.4.0 announcement:: - many bug fixes (see Changelog) some of them security related. - last 3.02 xpdf code base imported to the tree. This bring some new features like anti-aliasing for vectored graphics, support for PDF 1.6, 1.7 specification, security fixes and many others (see src/xpdf/CHANGES for complete changelog) Regarding hardy's LTS status it would be great if users had an option not to stick with its vulnerable version unable to work with newer pdfs for the next years. thank you h1repp Binary package hint: pdfedit hi all on the current kubuntu hardy version there is only the pdfedit version 0.3.2 in the repos... please include the latest version of pdfedit v0.4.1. my current system: lsb_release -rd Description: Ubuntu 8.04 Release: 8.04 apt-cache policy pdfedit pdfedit: Installed: 0.3.2-5ubuntu2 Candidate: 0.3.2-5ubuntu2 Version table: *** 0.3.2-5ubuntu2 0 500 http://ch.archive.ubuntu.com hardy/universe Packages 100 /var/lib/dpkg/status thanks thomi
2008-08-28 22:40:47 Michael Casadevall hardy-backports: status New Triaged
2008-08-28 22:40:47 Michael Casadevall hardy-backports: importance Undecided Wishlist
2008-08-28 22:40:47 Michael Casadevall hardy-backports: statusexplanation I'm confirming this one. pdfedit builds, installs, and runs without changes on Hardy. Version tested: 0.4.1-2
2008-08-29 05:15:05 Scott Kitterman hardy-backports: status Triaged In Progress
2008-08-29 05:15:05 Scott Kitterman hardy-backports: statusexplanation I'm confirming this one. pdfedit builds, installs, and runs without changes on Hardy. Version tested: 0.4.1-2 Ack from ubuntu-backporters. Note that if there are security fixes in this release, someone ought to go see about getting those in the release version.
2008-08-29 05:15:33 Scott Kitterman bug added subscriber Ubuntu Package Archive Administrators
2008-09-01 15:01:35 Colin Watson pdfedit: status Invalid New
2008-09-01 15:01:35 Colin Watson pdfedit: statusexplanation I'm reopening the pdfedit task for the security concern, and I'll flag this as a security vulnerability to bring it to the attention of the security team.
2008-09-01 15:04:07 Colin Watson bug added subscriber Ubuntu Security Team
2008-09-01 15:05:00 Colin Watson hardy-backports: status In Progress Fix Released
2008-09-01 15:05:00 Colin Watson hardy-backports: statusexplanation Ack from ubuntu-backporters. Note that if there are security fixes in this release, someone ought to go see about getting those in the release version.
2009-01-24 00:59:17 Kees Cook pdfedit: status New Confirmed
2009-01-24 00:59:17 Kees Cook pdfedit: statusexplanation I'm reopening the pdfedit task for the security concern, and I'll flag this as a security vulnerability to bring it to the attention of the security team.
2009-12-21 16:30:36 Przemek K. pdfedit (Ubuntu): status Confirmed Fix Released