UbuntuUpdates.org


hardyintrepidjauntykarmicstabletesting

UbuntuUpdates.org's goal is to present all software changes happening daily in Ubuntu. This website will address a number of questions Ubuntu users may have about the life and evolution of their favorite OS.

For updates:

For packages:

Some directions...


Latest updates with change log for all releases

Show change logs for: hardy intrepid jaunty karmic all releases

Note: Only updates where the change log is available are shown on this page (view all).

dpkg 03-11 09:01 UTC
Release: intrepid Repo: main Level: updates New version: 1.14.20ubuntu6.3
dpkg (1.14.20ubuntu6.3) intrepid-security; urgency=low

  * SECURITY UPDATE: arbitrary file overwriting via symlinks and relative
    directories.
    - upstream fixes thanks to Raphael Hertzog, backported inline to
      scripts/Dpkg/Source/Package/V3/quilt.pm, and
      scripts/Dpkg/Source/Patch.pm b/scripts/Dpkg/Source/Patch.pm.
    - CVE-2010-0396

 -- Kees Cook   Wed, 10 Mar 2010 13:54:45 -0800

CVE-2010-0396 dpkg path traversal

tzdata 03-11 09:01 UTC
Release: hardy Repo: universe Level: updates New version: 2010e~repack-0ubuntu0.8.04
tzdata (2010e~repack-0ubuntu0.8.04) hardy-proposed; urgency=low

  * New upstream release 2010e: (LP: #532924)
    - Chile: Extraordinary DST prolongation for 2009
    - Samoa: Update DST rules
    - Fiji: Update DST rules (starts a month earlier now)
    - Bangladesh: Fix DST rule (starts one minute earlier), and fix historic
      DST change for 2009.
    - Paraguay: Fix DST rule (starts on first Sunday)
    - Mexico: Northern cities now follow U.S. DST rules (timezone split)
    - Paraguay: Update DST rules (effective from March 2010)

 -- Martin Pitt   Wed, 10 Mar 2010 08:07:02 +0100

532924 tzdata: "Chilean timezone extraordinary change -- update to 2010e"

tzdata 03-11 09:01 UTC
Release: hardy Repo: main Level: updates New version: 2010e~repack-0ubuntu0.8.04
tzdata (2010e~repack-0ubuntu0.8.04) hardy-proposed; urgency=low

  * New upstream release 2010e: (LP: #532924)
    - Chile: Extraordinary DST prolongation for 2009
    - Samoa: Update DST rules
    - Fiji: Update DST rules (starts a month earlier now)
    - Bangladesh: Fix DST rule (starts one minute earlier), and fix historic
      DST change for 2009.
    - Paraguay: Fix DST rule (starts on first Sunday)
    - Mexico: Northern cities now follow U.S. DST rules (timezone split)
    - Paraguay: Update DST rules (effective from March 2010)

 -- Martin Pitt   Wed, 10 Mar 2010 08:07:02 +0100

532924 tzdata: "Chilean timezone extraordinary change -- update to 2010e"

dpkg 03-11 09:01 UTC
Release: hardy Repo: main Level: updates New version: 1.14.16.6ubuntu4.1
dpkg (1.14.16.6ubuntu4.1) hardy-security; urgency=low

  * SECURITY UPDATE: arbitrary file overwriting via symlinks and relative
    directories.
    - upstream fixes thanks to Raphael Hertzog, backported inline to
      scripts/dpkg-source.pl.
    - CVE-2010-0396

 -- Kees Cook   Wed, 10 Mar 2010 14:54:24 -0800

CVE-2010-0396 dpkg path traversal

dpkg 03-11 09:01 UTC
Release: karmic Repo: main Level: updates New version: 1.15.4ubuntu2.1
dpkg (1.15.4ubuntu2.1) karmic-security; urgency=low

  * SECURITY UPDATE: arbitrary file overwriting via symlinks and relative
    directories.
    - upstream fixes thanks to Raphael Hertzog, backported inline to
      scripts/Dpkg/Source/Package/V3/quilt.pm, and
      scripts/Dpkg/Source/Patch.pm b/scripts/Dpkg/Source/Patch.pm.
    - CVE-2010-0396

 -- Kees Cook   Wed, 10 Mar 2010 13:54:45 -0800

CVE-2010-0396 dpkg path traversal

dpkg 03-11 09:01 UTC
Release: jaunty Repo: main Level: updates New version: 1.14.24ubuntu1.1
dpkg (1.14.24ubuntu1.1) jaunty-security; urgency=low

  * SECURITY UPDATE: arbitrary file overwriting via symlinks and relative
    directories.
    - upstream fixes thanks to Raphael Hertzog, backported inline to
      scripts/Dpkg/Source/Package/V3/quilt.pm, and
      scripts/Dpkg/Source/Patch.pm b/scripts/Dpkg/Source/Patch.pm.
    - CVE-2010-0396

 -- Kees Cook   Wed, 10 Mar 2010 13:54:45 -0800

CVE-2010-0396 dpkg path traversal

dpkg 03-11 04:02 UTC
Release: intrepid Repo: main Level: security New version: 1.14.20ubuntu6.3
dpkg (1.14.20ubuntu6.3) intrepid-security; urgency=low

  * SECURITY UPDATE: arbitrary file overwriting via symlinks and relative
    directories.
    - upstream fixes thanks to Raphael Hertzog, backported inline to
      scripts/Dpkg/Source/Package/V3/quilt.pm, and
      scripts/Dpkg/Source/Patch.pm b/scripts/Dpkg/Source/Patch.pm.
    - CVE-2010-0396

 -- Kees Cook   Wed, 10 Mar 2010 13:54:45 -0800

CVE-2010-0396 dpkg path traversal

dpkg 03-11 04:01 UTC
Release: hardy Repo: main Level: security New version: 1.14.16.6ubuntu4.1
dpkg (1.14.16.6ubuntu4.1) hardy-security; urgency=low

  * SECURITY UPDATE: arbitrary file overwriting via symlinks and relative
    directories.
    - upstream fixes thanks to Raphael Hertzog, backported inline to
      scripts/dpkg-source.pl.
    - CVE-2010-0396

 -- Kees Cook   Wed, 10 Mar 2010 14:54:24 -0800

CVE-2010-0396 dpkg path traversal

dpkg 03-11 04:01 UTC
Release: karmic Repo: main Level: security New version: 1.15.4ubuntu2.1
dpkg (1.15.4ubuntu2.1) karmic-security; urgency=low

  * SECURITY UPDATE: arbitrary file overwriting via symlinks and relative
    directories.
    - upstream fixes thanks to Raphael Hertzog, backported inline to
      scripts/Dpkg/Source/Package/V3/quilt.pm, and
      scripts/Dpkg/Source/Patch.pm b/scripts/Dpkg/Source/Patch.pm.
    - CVE-2010-0396

 -- Kees Cook   Wed, 10 Mar 2010 13:54:45 -0800

CVE-2010-0396 dpkg path traversal

dpkg 03-11 04:01 UTC
Release: jaunty Repo: main Level: security New version: 1.14.24ubuntu1.1
dpkg (1.14.24ubuntu1.1) jaunty-security; urgency=low

  * SECURITY UPDATE: arbitrary file overwriting via symlinks and relative
    directories.
    - upstream fixes thanks to Raphael Hertzog, backported inline to
      scripts/Dpkg/Source/Package/V3/quilt.pm, and
      scripts/Dpkg/Source/Patch.pm b/scripts/Dpkg/Source/Patch.pm.
    - CVE-2010-0396

 -- Kees Cook   Wed, 10 Mar 2010 13:54:45 -0800

CVE-2010-0396 dpkg path traversal

tzdata 03-11 01:01 UTC
Release: intrepid Repo: main Level: updates New version: 2010e~repack-0ubuntu0.8.10
tzdata (2010e~repack-0ubuntu0.8.10) intrepid-proposed; urgency=low

  * New upstream release 2010e: (LP: #532924)
    - Chile: Extraordinary DST prolongation for 2009
    - Samoa: Update DST rules
    - Fiji: Update DST rules (starts a month earlier now)
    - Bangladesh: Fix DST rule (starts one minute earlier), and fix historic
      DST change for 2009.
    - Paraguay: Fix DST rule (starts on first Sunday)
    - Mexico: Northern cities now follow U.S. DST rules (timezone split)
    - Paraguay: Update DST rules (effective from March 2010)

 -- Martin Pitt   Wed, 10 Mar 2010 08:03:38 +0100

532924 tzdata: "Chilean timezone extraordinary change -- update to 2010e"

tzdata 03-11 01:01 UTC
Release: karmic Repo: main Level: updates New version: 2010e-0ubuntu0.9.10
tzdata (2010e-0ubuntu0.9.10) karmic-proposed; urgency=low

  * New upstream release 2010e: (LP: #532924)
    - Chile: Extraordinary DST prolongation for 2009
    - Samoa: Update DST rules
    - Fiji: Update DST rules (starts a month earlier now)
    - Bangladesh: Fix DST rule (starts one minute earlier), and fix historic
      DST change for 2009.
    - Paraguay: Fix DST rule (starts on first Sunday)
    - Mexico: Northern cities now follow U.S. DST rules (timezone split)
    - Paraguay: Update DST rules (effective from March 2010)

 -- Martin Pitt   Sun, 07 Mar 2010 15:01:31 +0100

532924 tzdata: "Chilean timezone extraordinary change -- update to 2010e"

tzdata 03-11 01:01 UTC
Release: jaunty Repo: main Level: updates New version: 2010e~repack-0ubuntu9.04
tzdata (2010e~repack-0ubuntu9.04) jaunty-proposed; urgency=low

  * New upstream release 2010e: (LP: #532924)
    - Chile: Extraordinary DST prolongation for 2009
    - Samoa: Update DST rules
    - Fiji: Update DST rules (starts a month earlier now)
    - Bangladesh: Fix DST rule (starts one minute earlier), and fix historic
      DST change for 2009.
    - Paraguay: Fix DST rule (starts on first Sunday)
    - Mexico: Northern cities now follow U.S. DST rules (timezone split)
    - Paraguay: Update DST rules (effective from March 2010)

 -- Martin Pitt   Wed, 10 Mar 2010 08:02:03 +0100

532924 tzdata: "Chilean timezone extraordinary change -- update to 2010e"

apache2-mpm-itk 03-11 00:01 UTC
Release: intrepid Repo: universe Level: updates New version: 2.2.6-02-1build2.6
apache2-mpm-itk (2.2.6-02-1build2.6) intrepid-security; urgency=low

  * No-change rebuild to handle updated apache source.

 -- Marc Deslauriers   Wed, 10 Mar 2010 12:23:52 -0500


apache2 03-10 22:01 UTC
Release: intrepid Repo: main Level: updates New version: 2.2.9-7ubuntu3.6
apache2 (2.2.9-7ubuntu3.6) intrepid-security; urgency=low

  * SECURITY UPDATE: denial of service via crafted request in mod_proxy_ajp
    - debian/patches/907_CVE-2010-0408.dpatch: return the right error code
      in modules/proxy/mod_proxy_ajp.c.
    - CVE-2010-0408
  * SECURITY UPDATE: information disclosure via improper handling of
    headers in subrequests
    - debian/patches/908_CVE-2010-0434.dpatch: use a copy of r->headers_in
      in server/protocol.c.
    - CVE-2010-0434

 -- Marc Deslauriers   Mon, 08 Mar 2010 11:29:11 -0500

CVE-2010-0408 The ap_proxy_ajp_request function in mod_proxy_ajp.c in mod_proxy_ajp in the Apache HTTP Server 2.2.x before 2.2.15 does not properly handle certain s
CVE-2010-0434 The ap_read_request function in server/protocol.c in the Apache HTTP Server 2.2.x before 2.2.15, when a multithreaded MPM is used, does not properly h

apache2-mpm-itk 03-10 22:01 UTC
Release: hardy Repo: universe Level: updates New version: 2.2.6-01-1build3.8
apache2-mpm-itk (2.2.6-01-1build3.8) hardy-security; urgency=low

  *  No-change rebuild to handle updated apache source.

 -- Marc Deslauriers   Wed, 10 Mar 2010 12:23:04 -0500


apache2 03-10 22:01 UTC
Release: hardy Repo: main Level: updates New version: 2.2.8-1ubuntu0.15
apache2 (2.2.8-1ubuntu0.15) hardy-security; urgency=low

  * SECURITY UPDATE: denial of service via crafted request in mod_proxy_ajp
    - debian/patches/209_CVE-2010-0408.dpatch: return the right error code
      in modules/proxy/mod_proxy_ajp.c.
    - CVE-2010-0408
  * SECURITY UPDATE: information disclosure via improper handling of
    headers in subrequests
    - debian/patches/210_CVE-2010-0434.dpatch: use a copy of r->headers_in
      in server/protocol.c.
    - CVE-2010-0434

 -- Marc Deslauriers   Mon, 08 Mar 2010 11:56:13 -0500

CVE-2010-0408 The ap_proxy_ajp_request function in mod_proxy_ajp.c in mod_proxy_ajp in the Apache HTTP Server 2.2.x before 2.2.15 does not properly handle certain s
CVE-2010-0434 The ap_read_request function in server/protocol.c in the Apache HTTP Server 2.2.x before 2.2.15, when a multithreaded MPM is used, does not properly h

apache2 03-10 22:01 UTC
Release: karmic Repo: universe Level: updates New version: 2.2.12-1ubuntu2.2
apache2 (2.2.12-1ubuntu2.2) karmic-security; urgency=low

  * SECURITY UPDATE: denial of service via crafted request in mod_proxy_ajp
    - debian/patches/903_CVE-2010-0408.dpatch: return the right error code
      in modules/proxy/mod_proxy_ajp.c.
    - CVE-2010-0408
  * SECURITY UPDATE: information disclosure via improper handling of
    headers in subrequests
    - debian/patches/904_CVE-2010-0434.dpatch: use a copy of r->headers_in
      in server/protocol.c.
    - CVE-2010-0434

 -- Marc Deslauriers   Mon, 08 Mar 2010 10:25:00 -0500

CVE-2010-0408 The ap_proxy_ajp_request function in mod_proxy_ajp.c in mod_proxy_ajp in the Apache HTTP Server 2.2.x before 2.2.15 does not properly handle certain s
CVE-2010-0434 The ap_read_request function in server/protocol.c in the Apache HTTP Server 2.2.x before 2.2.15, when a multithreaded MPM is used, does not properly h

apache2 03-10 22:01 UTC
Release: karmic Repo: main Level: updates New version: 2.2.12-1ubuntu2.2
apache2 (2.2.12-1ubuntu2.2) karmic-security; urgency=low

  * SECURITY UPDATE: denial of service via crafted request in mod_proxy_ajp
    - debian/patches/903_CVE-2010-0408.dpatch: return the right error code
      in modules/proxy/mod_proxy_ajp.c.
    - CVE-2010-0408
  * SECURITY UPDATE: information disclosure via improper handling of
    headers in subrequests
    - debian/patches/904_CVE-2010-0434.dpatch: use a copy of r->headers_in
      in server/protocol.c.
    - CVE-2010-0434

 -- Marc Deslauriers   Mon, 08 Mar 2010 10:25:00 -0500

CVE-2010-0408 The ap_proxy_ajp_request function in mod_proxy_ajp.c in mod_proxy_ajp in the Apache HTTP Server 2.2.x before 2.2.15 does not properly handle certain s
CVE-2010-0434 The ap_read_request function in server/protocol.c in the Apache HTTP Server 2.2.x before 2.2.15, when a multithreaded MPM is used, does not properly h

apache2 03-10 22:01 UTC
Release: jaunty Repo: universe Level: updates New version: 2.2.11-2ubuntu2.6
apache2 (2.2.11-2ubuntu2.6) jaunty-security; urgency=low

  * SECURITY UPDATE: denial of service via crafted request in mod_proxy_ajp
    - debian/patches/907_CVE-2010-0408.dpatch: return the right error code
      in modules/proxy/mod_proxy_ajp.c.
    - CVE-2010-0408
  * SECURITY UPDATE: information disclosure via improper handling of
    headers in subrequests
    - debian/patches/908_CVE-2010-0434.dpatch: use a copy of r->headers_in
      in server/protocol.c.
    - CVE-2010-0434

 -- Marc Deslauriers   Mon, 08 Mar 2010 11:26:48 -0500

CVE-2010-0408 The ap_proxy_ajp_request function in mod_proxy_ajp.c in mod_proxy_ajp in the Apache HTTP Server 2.2.x before 2.2.15 does not properly handle certain s
CVE-2010-0434 The ap_read_request function in server/protocol.c in the Apache HTTP Server 2.2.x before 2.2.15, when a multithreaded MPM is used, does not properly h



About   -   Changelog