Please sync rpm 4.8.1-5 (main) from Debian unstable (main).

Bug #601298 reported by Bhavani Shankar
8
This bug affects 1 person
Affects Status Importance Assigned to Milestone
rpm (Ubuntu)
Fix Released
Wishlist
Unassigned

Bug Description

Binary package hint: rpm

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

 affects ubuntu/rpm
 status new
 importance undecided
 subscribe ubuntu-sponsors

Please sync rpm 4.8.1-5 (main) from Debian unstable (main).

we can sync this package as its a new upstream version

Changelog since current maverick version 4.7.2-1lbuild2:

rpm (4.8.1-5) unstable; urgency=low

 * Fix compilation on hurd and kfreebsd (Closes: #587366).

 -- Michal Čihař <email address hidden> Mon, 28 Jun 2010 11:12:30 +0200

rpm (4.8.1-4) unstable; urgency=low

 * Package rpm-common needs to be arch:any because it's content is different
   for each platform (LP: #574647).
 * Tighten dependency on rpm-common.
 * Fix build failure on arm (Closes: #587173).

 -- Michal Čihař <email address hidden> Sun, 27 Jun 2010 11:40:28 +0200

rpm (4.8.1-3) unstable; urgency=low

 * Upload to unstable as python 2.6 is there.
 * Remove build dependency on beecrypt, it is not used at all (was replaced
   by NSS some time ago).
 * Also libneon does not seem to be used anymore.
 * Add missing build dependency on pkg-config.

 -- Michal Čihař <email address hidden> Fri, 25 Jun 2010 18:19:00 +0200

rpm (4.8.1-2) experimental; urgency=low

 * Build depend on autopoint.

 -- Michal Čihař <email address hidden> Mon, 14 Jun 2010 13:50:27 +0000

rpm (4.8.1-1) experimental; urgency=low

 * New upstream release.
   - Fix vulnerability in removing setuid on moved files (Closes: #584257,
     CVE-2010-2059).
   - Safer parsing of spec file (CVE-2010-2197).
 * Build depend on python-all-dev (>= 2.6) and cleanup debian/rules to again
   use all supported versions (which will anyway mean just 2.6).

 -- Michal Čihař <email address hidden> Mon, 14 Jun 2010 09:48:08 +0200

rpm (4.8.0-4) experimental; urgency=low

 * Use new conditionals in symbol files and define symbols for sparc64
   (Closes: #572766).
 * Move default RPM database path to ~/.rpm.
   - Fixes problem with no accessible Names database (Closes: #551669,
   LP: #530023).
 * No longer handle database in postinst.
   - Removes debconf from postinst.
   - Avoids problems on installation with db version (LP: #542115).
 * Document above changes in NEWS and README.Debian.

 -- Michal Čihař <email address hidden> Thu, 22 Apr 2010 09:52:43 +0200

rpm (4.8.0-3) experimental; urgency=low

 * Do not require --force-debian for installing packages, just complain that
   user should use alien. This allows easily people to shoot in the foot,
   however --force-debian switch seems to be too unpopular (Closes: #565421).
 * Bump standards to 3.8.4.

 -- Michal Čihař <email address hidden> Thu, 18 Feb 2010 16:27:11 +0100

rpm (4.8.0-2) experimental; urgency=low

 * Add missing build dependency on cvs (for autoreconf) (Closes: #565795).

 -- Michal Čihař <email address hidden> Tue, 19 Jan 2010 09:31:26 +0100

rpm (4.8.0-1) experimental; urgency=low

 * Fix filename of database backup - month and minute were switched
   (Closes: #561546).
 * Move watch file to 4.8 branch.
 * New upstream release.
 * Patch fixbashism.patch fixed better upstream.
 * Unfuzzy other patches.
 * Build depend on python 2.6, adjust Python-Version according to that.
 * Build agains python 2.6 for experimental.
 * Rename library packages after soname bump.

 -- Michal Čihař <email address hidden> Fri, 15 Jan 2010 16:33:42 +0100

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.10 (GNU/Linux)

iEYEARECAAYFAkwu5XQACgkQUlfC4uPMy3Q3lQCfT0yFZ6Xl+9asmjeB/ObYK1CF
608AoOpZHOo1erNn4Oq0+QPdudijjnfP
=pHkU
-----END PGP SIGNATURE-----

Tags: sync

CVE References

Bhavani Shankar (bhavi)
description: updated
tags: added: sync
Benjamin Drung (bdrung)
Changed in rpm (Ubuntu):
importance: Undecided → Wishlist
Revision history for this message
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package rpm - 4.8.1-5

---------------
rpm (4.8.1-5) unstable; urgency=low

  * Fix compilation on hurd and kfreebsd (Closes: #587366).

rpm (4.8.1-4) unstable; urgency=low

  * Package rpm-common needs to be arch:any because it's content is different
    for each platform (LP: #574647).
  * Tighten dependency on rpm-common.
  * Fix build failure on arm (Closes: #587173).

rpm (4.8.1-3) unstable; urgency=low

  * Upload to unstable as python 2.6 is there.
  * Remove build dependency on beecrypt, it is not used at all (was replaced
    by NSS some time ago).
  * Also libneon does not seem to be used anymore.
  * Add missing build dependency on pkg-config.

rpm (4.8.1-2) experimental; urgency=low

  * Build depend on autopoint.

rpm (4.8.1-1) experimental; urgency=low

  * New upstream release.
    - Fix vulnerability in removing setuid on moved files (Closes: #584257,
      CVE-2010-2059).
    - Safer parsing of spec file (CVE-2010-2197).
  * Build depend on python-all-dev (>= 2.6) and cleanup debian/rules to again
    use all supported versions (which will anyway mean just 2.6).

rpm (4.8.0-4) experimental; urgency=low

  * Use new conditionals in symbol files and define symbols for sparc64
    (Closes: #572766).
  * Move default RPM database path to ~/.rpm.
    - Fixes problem with no accessible Names database (Closes: #551669,
    LP: #530023).
  * No longer handle database in postinst.
    - Removes debconf from postinst.
    - Avoids problems on installation with db version (LP: #542115).
  * Document above changes in NEWS and README.Debian.

rpm (4.8.0-3) experimental; urgency=low

  * Do not require --force-debian for installing packages, just complain that
    user should use alien. This allows easily people to shoot in the foot,
    however --force-debian switch seems to be too unpopular (Closes: #565421).
  * Bump standards to 3.8.4.

rpm (4.8.0-2) experimental; urgency=low

  * Add missing build dependency on cvs (for autoreconf) (Closes: #565795).

rpm (4.8.0-1) experimental; urgency=low

  * Fix filename of database backup - month and minute were switched
    (Closes: #561546).
  * Move watch file to 4.8 branch.
  * New upstream release.
  * Patch fixbashism.patch fixed better upstream.
  * Unfuzzy other patches.
  * Build depend on python 2.6, adjust Python-Version according to that.
  * Build agains python 2.6 for experimental.
  * Rename library packages after soname bump.
 -- Bhavani Shankar <email address hidden> Mon, 28 Jun 2010 11:12:30 +0200

Changed in rpm (Ubuntu):
status: New → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.