Change log for zsh package in Ubuntu

175 of 89 results
Published in oracular-release
Published in noble-release
Deleted in noble-proposed (Reason: Moved to noble)
zsh (5.9-6ubuntu2) noble; urgency=high

  * No change rebuild for 64-bit time_t and frame pointers.

 -- Julian Andres Klode <email address hidden>  Mon, 08 Apr 2024 18:24:20 +0200

Available diffs

Superseded in noble-release
Deleted in noble-proposed (Reason: Moved to noble)
zsh (5.9-6ubuntu1) noble; urgency=medium

  * Merge from Debian unstable.  Remaining changes:
    - Don't build zsh-static on Ubuntu/i386.

Available diffs

Superseded in noble-release
Published in mantic-release
Deleted in mantic-proposed (Reason: Moved to mantic)
zsh (5.9-5ubuntu1) mantic; urgency=medium

  * Don't build zsh-static on Ubuntu/i386.

 -- Steve Langasek <email address hidden>  Thu, 21 Sep 2023 21:49:44 -0700
Superseded in mantic-proposed
zsh (5.9-5) unstable; urgency=medium

  * [138340f9,dc77864f] Cherry pick multiple (partial) upstream commits to
    migrate zsh's pcre module to pcre2. Update Build-Depends, Build-Using
    and debian/tests/control from libpcre3-dev to libpcre2-dev
    accordingly. (Closes: #999918)

 -- Axel Beckert <email address hidden>  Thu, 07 Sep 2023 01:17:01 +0200
Superseded in mantic-release
Published in lunar-release
Deleted in lunar-proposed (Reason: Moved to lunar)
zsh (5.9-4) unstable; urgency=medium

  * [76a48d6c] Enable gdbm module to be build again, this time via
    --enable-gdbm. Thanks to András Korn for reporting this regression.
    (Closes: #1030349)
  * [b29a6be7] Bump my packaging copyright years in debian/copyright.

 -- Axel Beckert <email address hidden>  Sun, 05 Feb 2023 01:37:45 +0100

Available diffs

Superseded in lunar-release
Deleted in lunar-proposed (Reason: Moved to lunar)
zsh (5.9-3) unstable; urgency=medium

  * [50f17ad1] Cherry-pick upstream commit 3e3cfabc to fix a completion
    regression with NO_CASE_GLOB in Zsh 5.9. Thanks to Vincent Lefèvre!
    (Closes: #1013434)
  * [c513a394] Declare compliance with Debian Policy 4.6.2. No other
    changes were needed.
  * [749f6b2d] Drop alternative build-dep on transitional package
    bsdmainutils. Thanks to Lintian!

 -- Axel Beckert <email address hidden>  Mon, 30 Jan 2023 02:13:43 +0100

Available diffs

Superseded in lunar-release
Deleted in lunar-proposed (Reason: Moved to lunar)
zsh (5.9-2) unstable; urgency=medium

  [ Helmut Grohne ]
  * [8dff29f4] Update /etc/shells using dpkg triggers (Closes: #1023317)

  [ Axel Beckert ]
  * [4cda7bc3] Update Helmut's patch to use more debhelper style file
    installing.
  * [27ee5df9] Bracketize and update lintian overrides where needed.

 -- Axel Beckert <email address hidden>  Mon, 14 Nov 2022 01:38:14 +0100

Available diffs

Superseded in lunar-release
Obsolete in kinetic-release
Deleted in kinetic-proposed (Reason: Moved to kinetic)
zsh (5.9-1) unstable; urgency=low

  * [73d31738,d4d20348,2ae4a398] Import new upstream release 5.9.
  * Retroactively set urgency=low in 5.8.1.2-test-2. This allows us to
    upload 5.9-1 to unstable with urgency=low as well.
  * [2af324df] Add patch to fix two typos in man pages found by Lintian
  * [2e260363] Drop lintian override for hardening-no-fortify-functions,
    no more needed.
  * [05e8cdc5] Declare compliance with Debian Policy 4.6.1. No further
    changes were needed.

 -- Axel Beckert <email address hidden>  Sun, 15 May 2022 01:20:26 +0200

Available diffs

Obsolete in impish-updates
Obsolete in impish-security
zsh (5.8-6ubuntu0.1) impish-security; urgency=medium

  * SECURITY UPDATE: Arbitrary code execution
    - debian/patches/CVE-2021-45444.patch: save PROMPTSUBST option before
      the call to promptexpand() in b/Src/prompt.c and restore after it is
      executed.
    - CVE-2021-45444

 -- Rodrigo Figueiredo Zaiden <email address hidden>  Fri, 11 Mar 2022 13:48:20 -0300
Published in focal-updates
Published in focal-security
zsh (5.8-3ubuntu1.1) focal-security; urgency=medium

  * SECURITY UPDATE: Arbitrary code execution
    - debian/patches/CVE-2021-45444.patch: save PROMPTSUBST option before
      the call to promptexpand() in b/Src/prompt.c and restore after it is
      executed.
    - CVE-2021-45444

 -- Rodrigo Figueiredo Zaiden <email address hidden>  Fri, 11 Mar 2022 13:38:26 -0300
Published in bionic-updates
Published in bionic-security
zsh (5.4.2-3ubuntu3.2) bionic-security; urgency=medium

  * SECURITY UPDATE: Regain dropped privileges
    - debian/patches/CVE-2019-20044-pre.patch: change the order of the calls to
      setgid (this should go first) and setuid in Src/options.c.
    - debian/patches/CVE-2019-20044-1.patch: add extra checks to drop privileges
      securely in Src/options.c.
    - debian/patches/CVE-2019-20044-2.patch: add Src/openssh_bsd_setres_id.c
      and its object file to Src/zsh.mdd, fix some of the checks from the
      previous patch in Src/options.c, update compatibility wrappers in
      Src/zsh_system.h, update the uid/gid methods in AC_CHECK_FUNCS in
      configure.ac and add a test in Test/E01options.ztst.
    - debian/patches/CVE-2019-20044-3.patch: improve Src/options.c changes from
      above two patches.
    - debian/patches/CVE-2019-20044-4.patch: clean up white spaces in
      Src/options.c.
    - debian/patches/CVE-2019-20044-5.patch: add privileged tests to
      Test/P01privileged.ztst, remove the notes on privileged test in
      Test/E01options.ztst and add the prilived tests to the Test/README.
    - CVE-2019-20044
  * SECURITY UPDATE: Arbitrary code execution
    - debian/patches/CVE-2021-45444.patch: save PROMPTSUBST option before
      the call to promptexpand() in b/Src/prompt.c and restore after it is
      executed.
    - CVE-2021-45444

 -- Rodrigo Figueiredo Zaiden <email address hidden>  Fri, 11 Mar 2022 10:46:35 -0300
Superseded in kinetic-release
Published in jammy-release
Deleted in jammy-proposed (Reason: Moved to jammy)
zsh (5.8.1-1) unstable; urgency=high

  * [1a490c705,12eb3e53,a13f7a2b] Import new upstream security and bugfix
    release 5.8.1.
    + [c187154f,fdb8b0ce,bdc4d70a] Fixes CVE-2021-45444, a vulnerability
      in prompt expansion which could be exploited through e.g. VCS_Info
      to execute arbitrary shell commands without a user's knowledge.
    + [92d7d4dd] Refresh patches as needed. Drop cherry-picked patch with
      commit 754658af, included in upstream bugfix release.
  * [2556a97c] Drop debian/zsh-static.NEWS, zsh-static will stay. Thanks
    to those who gave feedback about our proposed zsh-static removal back
    in 2015, especially Vincent Bernat.
  * [0fbb22e7] Extend zsh-static package description to explain its use
    cases. Thanks to shirish शिरीष to make us aware of this deficency of
    the package description by asking the right questions (back in
    2015). :-)
  * [daf87c89] zsh-static: Drop dep. on zsh, recommend zsh-common instead.
  * [2f5cd2e1] Update lintian overrides wrt. to change tag formats.
  * [cf14eeb5] Add lintian override for bash-term-in-posix-shell. It's zsh
    code and it's guarded by a check if we're running zsh or not.
  * [ca06fcef] Add lintian overrides for bin-sbin-mismatch false positives.
  * [db8c6c1c] debian/zsh5: Add ${static} suffix also to alternative path
    in warning.
  * [dc50ace5] Update copyright years in debian/copyright. Thanks Lintian!
  * [e872908c] debian/copyright: Remove obsolete upstream URLs. (FTP + SF)
  * [60187dd3] debian/watch: Drop comment about FTP timeouts.
  * [34379187] Make paths in lintian overrides agnostic to upstream versions
  * [566bf8c1] Add lintian overrides for all occurrences of
    very-long-line-length-in-source-file. They're all false positives.
  * [32c07ee0] Update copyright years in debian/copyright. Thanks Lintian!

 -- Axel Beckert <email address hidden>  Sat, 12 Feb 2022 23:00:09 +0100

Available diffs

Superseded in jammy-release
Obsolete in impish-release
Deleted in impish-proposed (Reason: Moved to impish)
zsh (5.8-6build1) impish; urgency=medium

  * No-change rebuild to build packages with zstd compression.

 -- Matthias Klose <email address hidden>  Thu, 07 Oct 2021 12:27:32 +0200

Available diffs

Superseded in jammy-release
Deleted in jammy-proposed (Reason: Moved to jammy)
zsh (5.8-10) unstable; urgency=medium

  * [130801d2,92b60e43] Fix segfaults in zsh-static after glibc upgrades
    by making sure nothing is loaded dynamically anymore. (Closes: #993843
    and fixes autopkgtest failures in not or too up to date chroots.)

 -- Axel Beckert <email address hidden>  Fri, 17 Sep 2021 15:48:52 +0200
Superseded in impish-release
Obsolete in hirsute-release
Deleted in hirsute-proposed (Reason: moved to Release)
zsh (5.8-6) unstable; urgency=medium

  [ Daniel Shahaf ]
  * [d248a7ff] d/changelog: In 4.3.12-1, retroactively list #489646 as a
    duplicate of #620452.

  [ Axel Beckert ]
  * [78bd839c] Add a debian/.gitignore file to ignore build artefacts.
  * [79fc7a20] zsh-static: Drop lintian override
    package-contains-broken-symlink, no more needed.
  * [ec4b020b] Add lintian override for hardening-no-fortify-functions on
    gdbm.so, too.
  * [5d383282] Drop "-Wl,--as-needed" from $LDFLAGS. (No more needed
    according to lintian warning debian-rules-uses-as-needed-linker-flag.)
  * [a127f477] Disable blhc CI job for now. (too many and only false
    positives)
  * [12746f0a] Salsa CI: Allow reprotest to fail. (The FTBFS inside
    reprotest is locally not reproducible with "reprotest
    --variations=-kernel".)
  * [3141c8a5] Declare compliance with Debian Policy 4.5.1. (No other
    changes were needed.)
  * [033709c5] Also install the Zsh FAQ. (Closes: #961757)
    + Thanks Daniel Shahaf!
    + [82386525] Install text-only FAQ into zsh-doc, too, for now, despite
      it better fits into zsh-common. See #980903 against debhelper for
      details.

  [ Helmut Grohne ]
  * [d0a05770] Demote documentation dependencies to B-D-I.
    (Closes: #980895)

 -- Axel Beckert <email address hidden>  Sat, 06 Feb 2021 05:15:22 +0100

Available diffs

Superseded in hirsute-release
Obsolete in groovy-release
Deleted in groovy-proposed (Reason: moved to Release)
zsh (5.8-5) unstable; urgency=medium

  [ Axel Beckert ]
  * [75eb3334] Retroactively mention #928194 in 5.8-1 changelog entry.
  * [d4dedd99] Adapt to "col" having been moved from bsdmainutils to
    bsdextrautils. (Closes: #963420)
  * [71a1b8a4] Try to fix cross-installability of run-testsuite
    autopkgtest check.
  * [dc40a872] Add a minimal debian/salsa-ci.yml file.
  * [27586e0e] Bump debhelper compatibility level to 13.
  * [c2242d6d] Cherry-pick 754658af from upstream to fix "git stash drop"
    tab-completion.
  * [eda6cb4d] Update lintian overrides wrt. renamed lintian tags.

  [ Daniel Shahaf ]
  * [49dbae2c] Retroactively close #740587 in 5.2-test-1-1.
  * [e8d6bb61] Cherry-pick d128bc0b from upstream: 45731: _debsnap: New
    completion function (Closes: #960298)

 -- Axel Beckert <email address hidden>  Tue, 30 Jun 2020 17:42:41 +0200
Superseded in groovy-release
Deleted in groovy-proposed (Reason: moved to Release)
zsh (5.8-4ubuntu1) groovy; urgency=low

  * Merge from Debian unstable.  Remaining changes:
    - Switch test deps back from @builddeps@ to libpcre3-dev

Available diffs

Superseded in groovy-release
Published in focal-release
Deleted in focal-proposed (Reason: moved to Release)
zsh (5.8-3ubuntu1) focal; urgency=medium

  * Switch test deps back from @builddeps@ to libpcre3-dev, since the zsh
    build-dependencies are apparently not cross-installable.

 -- Steve Langasek <email address hidden>  Sun, 23 Feb 2020 20:35:53 -0800
Superseded in focal-proposed
zsh (5.8-3) unstable; urgency=medium

  [ Steve Langasek ]
  * [ca933173] Make autopkgtests cross-test-friendly
    + debian/tests/control: Declare dependency on adequate as native.
    + debian/tests/control: Let run-testsuite also depend on libpcre3.
    + Mark zsh-doc as "Multi-Arch: foreign".

  [ Axel Beckert ]
  * [ca933173] Merge changes from Ubuntu's 5.8-2ubuntu1 and 5.8-2ubuntu2,
    see above.
  * [7ca6cb3f] debian/tests/control: Replace libpcre3 with @builddeps@ to
    pull in all Recommends.

 -- Axel Beckert <email address hidden>  Sat, 22 Feb 2020 01:10:43 +0100

Available diffs

Superseded in focal-release
Deleted in focal-proposed (Reason: moved to Release)
zsh (5.8-2ubuntu2) focal; urgency=medium

  * Also mark zsh-doc Multi-Arch: foreign.

 -- Steve Langasek <email address hidden>  Wed, 19 Feb 2020 21:47:31 -0800
Superseded in focal-proposed
zsh (5.8-2ubuntu1) focal; urgency=medium

  * Make autopkgtests cross-test-friendly.

 -- Steve Langasek <email address hidden>  Wed, 19 Feb 2020 13:35:36 -0800

Available diffs

Superseded in focal-proposed
zsh (5.8-2) unstable; urgency=medium

  [ Daniel Shahaf ]
  * [dae9b602] Fix advice in comment: zprofile isn't sourced by non-login
    interactive shells.
  * [b43af98a] d/zshrc: Tighten regex.

 -- Axel Beckert <email address hidden>  Tue, 18 Feb 2020 01:33:26 +0100
Superseded in focal-release
Obsolete in eoan-release
Deleted in eoan-proposed (Reason: moved to release)
zsh (5.7.1-1ubuntu2) eoan; urgency=medium

  * No-change upload with strops.h and sys/strops.h removed in glibc.

 -- Matthias Klose <email address hidden>  Thu, 05 Sep 2019 11:17:52 +0000

Available diffs

Superseded in eoan-release
Deleted in eoan-proposed (Reason: moved to release)
zsh (5.7.1-1ubuntu1) eoan; urgency=low

  * Merge from Debian unstable.  Remaining changes:
    - debian/zshrc: Enable completions by default, unless skip_global_compinit
      is set.
    - Support cross-compiling:
      - Adjust upstream autoconf cross-compile default fallbacks.
      - Skip zcompile when cross-compiling.
      - Add libelf-dev dependency.
  * Dropped changes, included upstream:
    - debian/patches/CVE-2018-0502-and-CVE-2018-13259.patch:
      fix in Src/exec.c and add test Test/A05execution.ztst.
    - Cherrypick upstream patch to fix A05execution.ztst test case. Resolves
      autopkgtest failure.

Available diffs

Superseded in eoan-release
Obsolete in disco-release
Deleted in disco-proposed (Reason: moved to release)
zsh (5.5.1-1ubuntu3) disco; urgency=medium

  * Cherrypick upstream patch to fix A05execution.ztst test case. Resolves
    autopkgtest failure.

 -- Dimitri John Ledkov <email address hidden>  Wed, 10 Apr 2019 12:30:21 +0100

Available diffs

Superseded in disco-release
Obsolete in cosmic-release
Deleted in cosmic-proposed (Reason: moved to release)
zsh (5.5.1-1ubuntu2) cosmic; urgency=medium

  * SECURITY UPDATE: Arbitrary code execution
    - debian/patches/CVE-2018-0502-and-CVE-2018-13259.patch:
      fix in Src/exec.c and add test Test/A05execution.ztst.
    - CVE-2018-0502
    - CVE-2018-13259

 -- <email address hidden> (Leonidas S. Barbosa)  Wed, 12 Sep 2018 10:22:39 -0300

Available diffs

Superseded in bionic-updates
Superseded in bionic-security
zsh (5.4.2-3ubuntu3.1) bionic-security; urgency=medium

  * SECURITY UPDATE: Arbitrary code execution
    - debian/patches/CVE-2018-0502-and-CVE-2018-13259.patch:
      fix in Src/exec.c and add test Test/A05execution.ztst.
    - CVE-2018-0502
    - CVE-2018-13259
  * SECURITY UPDATE: Stack-based buffer overflow
    - debian/patches/CVE-2018-1100.patch: fix int Src/utils.c.
    - CVE-2018-1100

 -- <email address hidden> (Leonidas S. Barbosa)  Mon, 10 Sep 2018 17:02:52 -0300
Published in xenial-updates
Published in xenial-security
zsh (5.1.1-1ubuntu2.3) xenial-security; urgency=medium

  * SECURITY UPDATE: Arbitrary code execution
    - debian/patches/CVE-2018-0502-and-CVE-2018-13259.patch:
      fix in Src/exec.c and add test Test/A05execution.ztst.
    - CVE-2018-0502
    - CVE-2018-13259
  * SECURITY UPDATE: Stack-based buffer overflow
    - debian/patches/CVE-2018-1100.patch: fix int Src/utils.c.
    - CVE-2018-1100

 -- <email address hidden> (Leonidas S. Barbosa)  Mon, 10 Sep 2018 16:06:42 -0300
Published in trusty-updates
Published in trusty-security
zsh (5.0.2-3ubuntu6.3) trusty-security; urgency=medium

  * SECURITY UPDATE: Arbitrary code execution
    - debian/patches/CVE-2018-0502-and-CVE-2018-13259-pre.patch:
      Src/signals.h.
    - debian/patches/CVE-2018-0502-and-CVE-2018-13259.patch:
      fix in Src/exec.c and add test Test/A05execution.ztst.
    - CVE-2018-0502
    - CVE-2018-13259
  * SECURITY UPDATE: Stack-based buffer overflow
    - debian/patches/CVE-2018-1100.patch: fix int Src/utils.c.
    - CVE-2018-1100

 -- <email address hidden> (Leonidas S. Barbosa)  Mon, 10 Sep 2018 09:30:36 -0300
Superseded in cosmic-release
Deleted in cosmic-proposed (Reason: moved to release)
zsh (5.5.1-1ubuntu1) cosmic; urgency=low

  * Merge from Debian unstable.  Remaining changes:
    - debian/zshrc: Enable completions by default, unless skip_global_compinit
      is set.
    - Support cross-compiling:
      - Adjust upstream autoconf cross-compile default fallbacks.
      - Skip zcompile when cross-compiling.
      - Add libelf-dev dependency.
  * Dropped all the CVE patches; applied upstream.
  * Drop upstream changelog link; broken symlink since we don't install it

Available diffs

Superseded in cosmic-release
Deleted in cosmic-proposed (Reason: moved to release)
zsh (5.4.2-3ubuntu4) cosmic; urgency=medium

  * No-change rebuild for ncurses soname changes.

 -- Matthias Klose <email address hidden>  Thu, 03 May 2018 15:21:47 +0000

Available diffs

Superseded in cosmic-release
Published in bionic-release
Deleted in bionic-proposed (Reason: moved to release)
zsh (5.4.2-3ubuntu3) bionic; urgency=medium

  * SECURITY UPDATE: stack-based buffer overflow
    - debian/patches/CVE-2018-1071.patch: check bounds when
      copying patch in hashcmd() in Src/exec.c, Src/utils.c.
    - CVE-2018-1071
  * SECURITY UPDATE: buffer-overflow
    - debian/patches/CVE-2018-1083.patch: check bounds on PATH_MAX
      buffer in Src/Zle/compctl.c.
    - CVE-2018-1083

 -- <email address hidden> (Leonidas S. Barbosa)  Fri, 06 Apr 2018 12:01:55 -0300

Available diffs

Obsolete in artful-updates
Obsolete in artful-security
zsh (5.2-5ubuntu1.2) artful-security; urgency=medium

  * SECURITY UPDATE: stack-based buffer overflow
    - debian/patches/CVE-2018-1071.patch: check bounds when
      copying patch in hashcmd() in Src/exec.c, Src/utils.c.
    - CVE-2018-1071
  * SECURITY UPDATE: buffer-overflow
    - debian/patches/CVE-2018-1083.patch: check bounds on PATH_MAX
      buffer in Src/Zle/compctl.c.
    - CVE-2018-1083

 -- <email address hidden> (Leonidas S. Barbosa)  Mon, 26 Mar 2018 14:22:32 -0300

Available diffs

Superseded in xenial-updates
Superseded in xenial-security
zsh (5.1.1-1ubuntu2.2) xenial-security; urgency=medium

  * SECURITY UPDATE: stack-based buffer overflow
    - debian/patches/CVE-2018-1071.patch: check bounds when
      copying patch in hashcmd() in Src/exec.c, Src/utils.c.
    - CVE-2018-1071
  * SECURITY UPDATE: buffer-overflow
    - debian/patches/CVE-2018-1083.patch: check bounds on PATH_MAX
      buffer in Src/Zle/compctl.c.
    - CVE-2018-1083

 -- <email address hidden> (Leonidas S. Barbosa)  Mon, 26 Mar 2018 14:16:59 -0300
Superseded in trusty-updates
Superseded in trusty-security
zsh (5.0.2-3ubuntu6.2) trusty-security; urgency=medium

  * SECURITY UPDATE: stack-based buffer overflow
    - debian/patches/CVE-2018-1071.patch: check bounds when
      copying patch in hashcmd() in Src/exec.c, Src/utils.c.
    - CVE-2018-1071
  * SECURITY UPDATE: buffer-overflow
    - debian/patches/CVE-2018-1083.patch: check bounds on PATH_MAX
      buffer in Src/Zle/compctl.c.
    - CVE-2018-1083

 -- <email address hidden> (Leonidas S. Barbosa)  Mon, 26 Mar 2018 14:07:05 -0300
Superseded in bionic-release
Deleted in bionic-proposed (Reason: moved to release)
zsh (5.4.2-3ubuntu2) bionic; urgency=medium

  * SECURITY UPDATE: NULL deference
    - debian/patches/CVE-2018-7548.patch: avoid null-pointer
      deref in Src/subst.c.
    - CVE-2018-7548
  * SECURITY UPDATE: Crash while copy an empty hash table
    - debian/patches/CVE-2018-7549.patch: avoid crash empty
      hash table in Src/params.c.
    - CVE-2018-7549

 -- <email address hidden> (Leonidas S. Barbosa)  Fri, 09 Mar 2018 05:31:57 -0300

Available diffs

Superseded in artful-updates
Superseded in artful-security
zsh (5.2-5ubuntu1.1) artful-security; urgency=medium

  * SECURITY UPDATE: undersized buffer
    - debian/patches/CVE-2016-10714.patch: Add extra byte to PATH_MAX
      in Src/Zle/compctl.c, Src/builtin.c, Src/compat.c, Src/exec.c,
      Src/glob.c, Src/hist.c, Src/utils.c.
    - CVE-2016-10714
  * SECURITY UPDATE: NULL dereference
    - debian/patches/CVE-2017-18205.patch: fix in Src/builtin.c,
      Test/B01cd.ztst.
    - CVE-2017-18205
  * SECURITY UPATE: buffer overflow
    - debian/patches/CVE-2017-18206.patch: fix buffer overrun in xsymlinks
      in Src/utils.c.
    - CVE-2017-18206
  * SECURITY UPDATE: NULL deference
    - debian/patches/CVE-2018-7548.patch: avoid null-pointer
      deref in Src/subst.c.
    - CVE-2018-7548
  * SECURITY UPDATE: Crash while copy an empty hash table
    - debian/patches/CVE-2018-7549.patch: avoid crash empty
      hash table in Src/params.c.
    - CVE-2018-7549
  * Fixing documentation build
    - debian/patches/fix_doc_build.patch. Thanks Steve Beattie.

 -- <email address hidden> (Leonidas S. Barbosa)  Wed, 07 Mar 2018 12:05:01 -0300
Superseded in xenial-updates
Superseded in xenial-security
zsh (5.1.1-1ubuntu2.1) xenial-security; urgency=medium

  * SECURITY UPDATE: undersized buffer
    - debian/patches/CVE-2016-10714.patch: Add extra byte to PATH_MAX
      in Src/Zle/compctl.c, Src/builtin.c, Src/compat.c, Src/exec.c,
      Src/glob.c, Src/hist.c, Src/utils.c.
    - CVE-2016-10714
  * SECURITY UPDATE: NULL dereference
    - debian/patches/CVE-2017-18205.patch: fix in Src/builtin.c,
      Test/B01cd.ztst.
    - CVE-2017-18205
  * SECURITY UPATE: buffer overflow
    - debian/patches/CVE-2017-18206.patch: fix buffer overrun in xsymlinks
      in Src/utils.c.
    - CVE-2017-18206
  * SECURITY UPDATE: Crash while copy an empty hash table
    - debian/patches/CVE-2018-7549.patch: avoid crash empty
      hash table in Src/params.c.
    - CVE-2018-7549

 -- <email address hidden> (Leonidas S. Barbosa)  Wed, 07 Mar 2018 10:24:39 -0300
Superseded in trusty-updates
Superseded in trusty-security
zsh (5.0.2-3ubuntu6.1) trusty-security; urgency=medium

  * SECURITY UPDATE: possibly privilege escalation
    - debian/patches/CVE-2014-10070.patch: safer import of
      numerical variables from environment in Src/params.c,
      Src/zsh.h.
    - CVE-2014-10070
  * SECURITY UPDATE: buffer overflow
    - debian/patches/CVE-2014-10071.patch: avoid buffer overflow
      for very long fds in Src/exec.c.
    - CVE-2014-10071
  * SECURITY UPDATE: buffer overflow
    - debian/patches/CVE-2014-10072.patch: fix buffer overflow in
      Src/utils.c.
    - CVE-2014-10072
  * SECURITY UPDATE: undersized buffer
    - debian/patches/CVE-2016-10714.patch: Add extra byte to PATH_MAX
      in Src/Zle/compctl.c, Src/builtin.c, Src/compat.c, Src/exec.c,
      Src/glob.c, Src/hist.c, Src/utils.c.
    - CVE-2016-10714
  * SECURITY UPDATE: NULL dereference
    - debian/patches/CVE-2017-18205.patch: fix in Src/builtin.c,
      Test/B01cd.ztst.
    - CVE-2017-18205
  * SECURITY UPDATE: Crash while copy an empty hash table
    - debian/patches/CVE-2018-7549.patch: avoid crash empty
      hash table in Src/params.c.
    - CVE-2018-7549

 -- <email address hidden> (Leonidas S. Barbosa)  Wed, 07 Mar 2018 08:03:11 -0300
Superseded in bionic-release
Deleted in bionic-proposed (Reason: moved to release)
zsh (5.4.2-3ubuntu1) bionic; urgency=low

  * Merge from Debian unstable.  Remaining changes:
    - debian/zshrc: Enable completions by default, unless skip_global_compinit
      is set.
    - Support cross-compiling:
      - Adjust upstream autoconf cross-compile default fallbacks.
      - Skip zcompile when cross-compiling.
      - Add libelf-dev dependency.

Available diffs

Superseded in bionic-release
Obsolete in artful-release
Obsolete in zesty-release
Obsolete in yakkety-release
Deleted in yakkety-proposed (Reason: moved to release)
zsh (5.2-5ubuntu1) yakkety; urgency=medium

  * Merge with Debian; remaining changes:

Available diffs

Superseded in yakkety-release
Deleted in yakkety-proposed (Reason: moved to release)
zsh (5.2-3ubuntu1) yakkety; urgency=medium

  * Merge with Debian; remaining changes:
    - debian/zshrc: Enable completions by default, unless skip_global_compinit
      is set.
    - Support cross-compiling:
      - Adjust upstream autoconf cross-compile default fallbacks.
      - Skip zcompile when cross-compiling.
      - Add libelf-dev dependency.
    - Add libncurses5-dev build-dep to avoid tgoto implicit function
      declaration and thus, implicit integer to pointer conversion. zsh
      should build with just ncursesw though.
    - Use dh_autotools-dev_update|restoreconfig in addition to
      dh_autoreconf to actually update config.sub|guess.

Available diffs

Superseded in yakkety-release
Published in xenial-release
Deleted in xenial-proposed (Reason: moved to release)
zsh (5.1.1-1ubuntu2) xenial; urgency=medium

  * No-change rebuild for ncurses6 transition.

 -- Matthias Klose <email address hidden>  Sun, 07 Feb 2016 12:49:08 +0000

Available diffs

Superseded in xenial-release
Obsolete in wily-release
Deleted in wily-proposed (Reason: moved to release)
zsh (5.1.1-1ubuntu1) wily; urgency=medium

  * Merge with Debian; remaining changes:
    - debian/zshrc: Enable completions by default, unless skip_global_compinit
      is set.
    - Drop yodl from Build-Depends.
    - Support cross-compiling:
      - Adjust upstream autoconf cross-compile default fallbacks.
      - Skip zcompile when cross-compiling.
      - Add libelf-dev dependency.
    - Add libncurses5-dev build-dep to avoid tgoto implicit function
      declaration and thus, implicit integer to pointer conversion. zsh
      should build with just ncursesw though.
    - Use dh_autotools-dev_update|restoreconfig in addition to
      dh_autoreconf to actually update config.sub|guess.
    - prebuild docs.

Available diffs

Superseded in wily-release
Obsolete in vivid-release
Deleted in vivid-proposed (Reason: moved to release)
zsh (5.0.7-5ubuntu1) vivid; urgency=medium

  * Merge from Debian unstable, remaining changes:
    - debian/zshrc: Enable completions by default, unless
      skip_global_compinit is set
    - Drop yodl from Build-Depends.
    - Support cross-compiling:
      - Adjust upstream autoconf cross-compile default fallbacks.
      - Skip zcompile when cross-compiling.
      - Add libelf-dev dependency.
    - Add libncurses5-dev build-dep to avoid tgoto implicit function
    declaration and thus, implicit integer to pointer conversion. zsh
    should build with just ncursesw though.
    - Use dh_autotools-dev_update|restoreconfig in addition to
    dh_autoreconf to actually update config.sub|guess.
    - prebuild docs.

Available diffs

Published in trusty-backports
zsh (5.0.5-4ubuntu1~ubuntu14.04.1) trusty-backports; urgency=medium

  * No-change backport to trusty (LP: #1355811)

Superseded in vivid-release
Obsolete in utopic-release
Deleted in utopic-proposed (Reason: moved to release)
zsh (5.0.5-4ubuntu1) utopic; urgency=medium

  * Merge from Debian unstable, remaining changes:
    - debian/zshrc: Enable completions by default, unless
      skip_global_compinit is set
    - Drop yodl from Build-Depends.
    - Support cross-compiling:
      - Adjust upstream autoconf cross-compile default fallbacks.
      - Skip zcompile when cross-compiling.
      - Add libelf-dev dependency.
    - Add libncurses5-dev build-dep to avoid tgoto implicit function
    declaration and thus, implicit integer to pointer conversion. zsh
    should build with just ncursesw though.
    - Use dh_autotools-dev_update|restoreconfig in addition to
    dh_autoreconf to actually update config.sub|guess.

  * Adjust prebuild target to prebuild missing docs locally with yodl
    installed, and dpkg-source --commit the results into
    prebuild-docs.patch. Adjust source/options to not ignore doc changes &
    manpages. Adjust debian/clean to not purge prebuild manpages. Revert
    debian/rules to Debian, thus installing & build remaining pdf/texinfo
    documentation at build time. This should resolve partially missing
    documentation bug LP: #1242108.

Available diffs

Superseded in utopic-release
Published in trusty-release
Obsolete in saucy-release
Deleted in saucy-proposed (Reason: moved to release)
zsh (5.0.2-3ubuntu6) saucy; urgency=low

  * Use dh_autotools-dev_update|restoreconfig in addition to dh_autoreconf
    to actually update config.sub|guess.
 -- Dmitrijs Ledkovs <email address hidden>   Thu, 10 Oct 2013 15:14:19 +0100

Available diffs

Superseded in saucy-release
Deleted in saucy-proposed (Reason: moved to release)
zsh (5.0.2-3ubuntu5) saucy; urgency=low

  * Add libncurses5-dev build-dep to avoid tgoto implicit function
    declaration and thus, implicit integer to pointer conversion. zsh
    should build with just ncursesw though.
 -- Dmitrijs Ledkovs <email address hidden>   Sun, 04 Aug 2013 21:31:39 +0100
Superseded in saucy-proposed
zsh (5.0.2-3ubuntu4) saucy; urgency=low

  * Add patch to fix implicit pointer conversion.
 -- Dmitrijs Ledkovs <email address hidden>   Sun, 04 Aug 2013 20:35:18 +0100

Available diffs

Superseded in saucy-proposed
zsh (5.0.2-3ubuntu3) saucy; urgency=low

  * Make failed tests not fail the build. Expected failures.
 -- Dmitrijs Ledkovs <email address hidden>   Sun, 04 Aug 2013 19:49:34 +0100

Available diffs

Superseded in saucy-proposed
zsh (5.0.2-3ubuntu2) saucy; urgency=low

  * Merge from Debian experimental, remaining changes:
    - debian/zshrc: Enable completions by default, unless
      skip_global_compinit is set
    - Keep using the upstream tarball that contains pre-generated docs as
      yodl is required to build them but the MIR hasn't been approved.
    - Drop yodl from Build-Depends.
    - Support cross-compiling:
      - Adjust upstream autoconf cross-compile default fallbacks.
      - Skip zcompile when cross-compiling.
      - Add libelf-dev dependency.
    + Add doc tarball component
    + Drop patches that modify docs, add patch to skip building docs.
 -- Dmitrijs Ledkovs <email address hidden>   Fri, 02 Aug 2013 17:51:51 +0100

Available diffs

Superseded in saucy-proposed
zsh (5.0.2-3ubuntu1) saucy; urgency=low

  * Merge from Debian, remaining changes - support cross-compiling:
    - Adjust upstream autoconf cross-compile default fallbacks.
    - Skip zcompile when cross-compiling.
    - Add libelf-dev dependency.

Available diffs

Superseded in saucy-release
Obsolete in raring-release
Deleted in raring-proposed (Reason: moved to release)
zsh (5.0.0-2ubuntu3) raring; urgency=low

  * Support cross-compiling:
    - Pass --host to configure, when cross-compiling.
    - Use target strip & objcopy.
    - Adjust upstream autoconf cross-compile default fallbacks.
    - Skip zcompile when cross-compiling.
    - Add libelf-dev dependency.
 -- Dmitrijs Ledkovs <email address hidden>   Thu, 20 Dec 2012 12:30:38 +0000

Available diffs

Superseded in raring-release
Deleted in raring-proposed (Reason: moved to release)
zsh (5.0.0-2ubuntu2) raring; urgency=low

  * debian/zshrc: Fix typo (.zprofice → .zprofile) (LP: #1038298)
 -- Logan Rosen <email address hidden>   Fri, 19 Oct 2012 11:35:45 -0400

Available diffs

Superseded in raring-release
Obsolete in quantal-release
zsh (5.0.0-2ubuntu1) quantal; urgency=low

  * Merge from Debian experimental, remaining changes:
    - debian/zshrc: Enable completions by default, unless
      skip_global_compinit is set
    - Keep using the upstream tarball that contains pre-generated docs as
      yodl is required to build them but the MIR hasn't been approved.
    - Drop yodl from Build-Depends.

Available diffs

Superseded in quantal-release
zsh (5.0.0-1ubuntu1) quantal; urgency=low

  * Merge from Debian experimental (LP: #1029337), remaining changes:
    - debian/zshrc: Enable completions by default, unless
      skip_global_compinit is set
    - Keep using the upstream tarball that contains pre-generated docs as
      yodl is required to build them but the MIR hasn't been approved.
    - Drop yodl from Build-Depends.

Available diffs

Superseded in quantal-release
Published in precise-release
zsh (4.3.17-1ubuntu1) precise; urgency=low

  * Merge from Debian unstable, remaining changes:
    - debian/zshrc: Enable completions by default, unless
      skip_global_compinit is set
    - Keep using the upstream tarball that contains pre-generated docs as
      yodl is required to build them but the MIR hasn't been approved.
    - Drop yodl from Build-Depends.

Superseded in precise-release
Obsolete in oneiric-release
zsh (4.3.11-4ubuntu2.is.3ubuntu2) oneiric; urgency=low

  * Add "tinfo" to --with-term-lib flag. (LP: #841489)
    Ubuntu striped out libtinfo* package from ncurses.
 -- Mitsuya Shibata <email address hidden>   Sat, 24 Sep 2011 14:53:40 +0900
Superseded in oneiric-release
Obsolete in natty-release
zsh (4.3.11-4ubuntu2.is.3ubuntu1) natty; urgency=low

  * Reupload to the previous version of zsh. The 4.3.11-4ubuntu1 upload
    introduces new build dependencies from universe. (See LP #762286)
 -- Martin Pitt <email address hidden>   Thu, 21 Apr 2011 19:24:25 +0200
Superseded in natty-release
zsh (4.3.11-4ubuntu1) natty; urgency=low

  * Merge from debian unstable. (LP: #762286) Remaining changes:
    - debian/zshrc: Enable completions by default, unless
      skip_global_compinit is set

Superseded in natty-release
zsh (4.3.11-3ubuntu1) natty; urgency=low

  * Merge from debian unstable. (LP: #716918) Remaining changes:
    - debian/zshrc: Enable completions by default, unless
      skip_global_compinit is set

Superseded in natty-release
zsh (4.3.11-2ubuntu1) natty; urgency=low

  * Merge from debian unstable. (LP: #704066) Remaining changes:
    - debian/zshrc: Enable completions by default, unless
      skip_global_compinit is set

Superseded in natty-release
zsh (4.3.11-1ubuntu1) natty; urgency=low

  * Merge from debian unstable. (LP: #700695) Remaining changes:
    - debian/zshrc: Enable completions by default, unless
      skip_global_compinit is set

Available diffs

Superseded in natty-release
zsh (4.3.10-15ubuntu1) natty; urgency=low

  * Merge from debian unstable(LP: #669470). Remaining changes:
    - debian/zshrc: Enable completions by default, unless
      skip_global_compinit is set

Superseded in natty-release
Obsolete in maverick-release
zsh (4.3.10-14ubuntu1) maverick; urgency=low

  * Merge from Debian unstable (LP: #612938). Remaining changes:
    - debian/zshrc: Enable completions by default, unless
      skip_global_compinit is set

Available diffs

Superseded in maverick-release
Obsolete in lucid-release
zsh (4.3.10-5ubuntu3) lucid; urgency=low

  * Rebuild statically linked zsh binary against recent libc.
 -- Matthias Klose <email address hidden>   Sun, 18 Apr 2010 22:23:57 +0000

Available diffs

Superseded in lucid-release
zsh (4.3.10-5ubuntu2) lucid; urgency=low

  * rebuild rest of main for armel armv7/thumb2 optimization;
    UbuntuSpec:mobile-lucid-arm-gcc-v7-thumb2
 -- Alexander Sack <email address hidden>   Sun, 07 Mar 2010 01:12:08 +0100

Available diffs

Superseded in lucid-release
Obsolete in karmic-release
zsh (4.3.10-5ubuntu1) karmic; urgency=low

  * Merge from debian unstable (LP: #426837), remaining changes:
    - debian/zshrc: Enable completions by default, unless
      skip_global_compinit is set

Available diffs

Superseded in karmic-release
zsh (4.3.10-2ubuntu1) karmic; urgency=low

  * Merge from debian unstable, remaining changes:
    - debian/zshrc: Enable completions by default, unless
      skip_global_compinit is set

Available diffs

Superseded in karmic-release
zsh (4.3.10-1ubuntu1) karmic; urgency=low

  * Resynchronise with Debian. Remaining changes:
    + debian/zshrc: Enable completions by default, unless
      skip_global_compinit is set

Available diffs

Superseded in karmic-release
Obsolete in jaunty-release
zsh (4.3.9-4ubuntu1) jaunty; urgency=low

  * Merge from debian unstable, remaining changes:
    + debian/zshrc: Enable completions by default, unless
      skip_global_compinit is set

Available diffs

Superseded in jaunty-release
zsh (4.3.9-1ubuntu1) jaunty; urgency=low

  * Merge from debian unstable, remaining changes: LP: #314112
    + debian/zshrc: Enable completions by default, unless
      skip_global_compinit is set.

Available diffs

Superseded in jaunty-release
zsh (4.3.6-7ubuntu1) jaunty; urgency=low

  * Merge from unstable, remaining changes:
    + debian/zshrc: Enable completions by default, unless
      skip_global_compinit is set (cf. LP: #16759).
  * Dropped changes:
    + Makefile.in: no need to disable running of autoconf if configure
      is out of date (builds just fine anyway)
    + debian/control: downgrade libcap2-dev: libcap2-dev is in main now,
      so we can build with it.

Available diffs

Superseded in jaunty-release
Obsolete in intrepid-release
zsh (4.3.6-4ubuntu1) intrepid; urgency=low

  * Merge from unstable (LP: #244373), remaining changes:
    + Makefile.in: Disable rule which runs autoconf if configure is
                   out of date.
    + debian/zshrc: Enable completions by default, unless
                     skip_global_compinit is set (cf. LP #16759).
    + debian/control: Update maintainer field by Ubuntu policy.
  * debian/control: Downgrade build-dependency against libcap2-dev
                    to libcap-dev, since libcap2-dev is only
                    available in universe.
  * This version fixes the issues with the broken zshall manpage
    w.o. further modification (LP: #243268).

Available diffs

175 of 89 results