dpkg 1.17.9 source package in Debian

Changelog

dpkg (1.17.9) unstable; urgency=high


  [ Guillem Jover ]
  * Do not allow patch files with C-style encoded filenames. Closes: #746306
    Unconditionally fixes CVE-2014-0471.
  * Switch alternative database backups from xz to gzip. Closes: #746354
  * Do not leak long tar names on bogus or truncated archives.
  * Do not leak the filepackages iterator when a directory is used by other
    packages.
  * Fix short lived memory leaks in «dpkg-split --split».
  * Fix memory leak in unused Keybindings screen in dselect.
  * Do not leak color string on «dselect --color».
  * Fix memory leaks when parsing alternatives.
  * Fix off-by-one stack buffer overrun in start-stop-daemon on GNU/Linux and
    GNU/kFreeBSD if the executable pathname is longer than _POSIX_PATH_MAX.
    Although this should not have security implications as the buffer is
    surrounded by two arrays (so those catch accesses even if the stack
    grows up or down), and we are compiling with -fstack-protector anyway.
  * Mark the command_get_pager() tests on a tty as TODO for now, so that
    we do not get failures on build daemons.
  * Make test suite errors abort the build again. Closes: #746331

  [ Updated scripts translations ]
  * French (Steve Petruzzello). Closes: #746350
  * German (Helge Kreutzmann).

  [ Updated manpages translations ]
  * German (Helge Kreutzmann).

 -- Guillem Jover <email address hidden>  Wed, 30 Apr 2014 05:45:20 +0200

Upload details

Uploaded by:
Dpkg Mailing List
Uploaded to:
Sid
Original maintainer:
Dpkg Mailing List
Architectures:
any all
Section:
admin
Urgency:
Very Urgent

See full publishing history Publishing

Series Pocket Published Component Section

Builds

Downloads

File Size SHA-256 Checksum
dpkg_1.17.9.dsc 2.0 KiB 63c7570f96b2228a04bcc7351b63c342f125a97b1ea47bd30c97197af9ad01b8
dpkg_1.17.9.tar.xz 3.9 MiB da58389a80a3515ea12aaf10c9e48f84ee6c08d2fe2c9e1450f4df49ffeeb6aa

No changes file available.

Binary packages built by this source