<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet href="http://feeds.ubuntu-nl.org/~d/styles/rss2full.xsl" type="text/xsl" media="screen"?><?xml-stylesheet href="http://feeds.ubuntu-nl.org/~d/styles/itemcontent.css" type="text/css" media="screen"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0">
  <channel>
    <title>Dapper Changes</title>
    <link>http://lists.ubuntu.com/mailman/listinfo/dapper-changes</link>
    <language>en</language>
    
<atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" href="http://feeds.ubuntu-nl.org/DapperChanges" type="application/rss+xml" /><feedburner:browserFriendly></feedburner:browserFriendly><item>
  <title>python-uncertainities 0.001-3.1ubuntu1.1</title>
  <guid>http://launchpad.net/distros/ubuntu/dapper/+source/python-uncertainities/0.001-3.1ubuntu1.1</guid>
  <link>http://launchpad.net/distros/ubuntu/dapper/+source/python-uncertainities/0.001-3.1ubuntu1.1</link>
  <description>&lt;b&gt;python-uncertainities (0.001-3.1ubuntu1.1)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; SRU for LP: #55706, list of changes:
&lt;ul&gt;&lt;li&gt; debian/{dirs,rules}: move to python2.4 to avoid errors during
 postinst phase.&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Wed, 13 Feb 2008 17:50:44 +0000</pubDate>
  <dc:creator>Luca Falavigna</dc:creator>
  <author>Luca Falavigna</author>
</item>


<item>
  <title>vmware-player-kernel-2.6.15, 2.6.15.11-14</title>
  <guid>http://launchpad.net/distros/ubuntu/dapper/+source/vmware-player-kernel-2.6.15,/2.6.15.11-14</guid>
  <link>http://launchpad.net/distros/ubuntu/dapper/+source/vmware-player-kernel-2.6.15,/2.6.15.11-14</link>
  <description>&lt;b&gt;vmware-player-kernel-2.6.15 (2.6.15.11-14)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; Rebuild against new ABI (51)&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Thu, 14 Feb 2008 00:33:39 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>linux-source-2.6.15, 2.6.15-51.66</title>
  <guid>http://launchpad.net/distros/ubuntu/dapper/+source/linux-source-2.6.15,/2.6.15-51.66</guid>
  <link>http://launchpad.net/distros/ubuntu/dapper/+source/linux-source-2.6.15,/2.6.15-51.66</link>
  <description>&lt;b&gt;linux-source-2.6.15 (2.6.15-51.66)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; Copy lds linker file (ia64) to headers package.&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Thu, 14 Feb 2008 00:54:32 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>linux-backports-modules-2.6.15, 2.6.15-51.9</title>
  <guid>http://launchpad.net/distros/ubuntu/dapper/+source/linux-backports-modules-2.6.15,/2.6.15-51.9</guid>
  <link>http://launchpad.net/distros/ubuntu/dapper/+source/linux-backports-modules-2.6.15,/2.6.15-51.9</link>
  <description>&lt;b&gt;linux-backports-modules-2.6.15 (2.6.15-51.9)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; Add hppa gcc dependency to fix FTBS.&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Thu, 14 Feb 2008 00:54:35 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>linux-restricted-modules-2.6.15, 2.6.15.12-51.2</title>
  <guid>http://launchpad.net/distros/ubuntu/dapper/+source/linux-restricted-modules-2.6.15,/2.6.15.12-51.2</guid>
  <link>http://launchpad.net/distros/ubuntu/dapper/+source/linux-restricted-modules-2.6.15,/2.6.15.12-51.2</link>
  <description>&lt;b&gt;linux-restricted-modules-2.6.15 (2.6.15.12-51.2)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; Security update&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Thu, 14 Feb 2008 00:54:40 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>clamav, 0.92~dfsg-2~dapper1ubuntu0.1</title>
  <guid>http://launchpad.net/distros/ubuntu/dapper/+source/clamav,/0.92~dfsg-2~dapper1ubuntu0.1</guid>
  <link>http://launchpad.net/distros/ubuntu/dapper/+source/clamav,/0.92~dfsg-2~dapper1ubuntu0.1</link>
  <description>&lt;b&gt;clamav (0.92~dfsg-2~dapper1ubuntu0.1)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; SECURITY UPDATE: possible integer overflow and tempfile symlink
&lt;ul&gt;&lt;li&gt;vulnerability
&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt; Added : 27_others.c.CVE-2007-6595.dpatch Fixes Tempfile symlink
&lt;ul&gt;&lt;li&gt;vulnerability
&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt; Added 26_pe.c.CVE-2008-0318.dpatch: Fixes posible integer overflow
&lt;/li&gt;&lt;li&gt; References  CVE-2007-6595 CVE-2008-0318 (LP: 191150)&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Thu, 14 Feb 2008 00:54:56 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>update-manager-core 0.56~dapper4</title>
  <guid>http://launchpad.net/distros/ubuntu/dapper/+source/update-manager-core/0.56~dapper4</guid>
  <link>http://launchpad.net/distros/ubuntu/dapper/+source/update-manager-core/0.56~dapper4</link>
  <description>&lt;b&gt;update-manager-core (0.56~dapper4)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; fix bug when meta-release file was already on disk and wouldn't
 be reread (thanks to the forum for investigating)&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Fri, 15 Feb 2008 09:41:46 +0000</pubDate>
  <dc:creator>Michael Vogt</dc:creator>
  <author>Michael Vogt</author>
</item>


<item>
  <title>libcdio, 0.76-1ubuntu1.6.06.1</title>
  <guid>http://launchpad.net/distros/ubuntu/dapper/+source/libcdio,/0.76-1ubuntu1.6.06.1</guid>
  <link>http://launchpad.net/distros/ubuntu/dapper/+source/libcdio,/0.76-1ubuntu1.6.06.1</link>
  <description>&lt;b&gt;libcdio (0.76-1ubuntu1.6.06.1)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; SECURITY UPDATE:
&lt;ul&gt;&lt;li&gt; CVE-2007-6613: a stack-based buffer overflow in the
 print_iso9660_recurse function could lead to cause a denial of service
 or arbitrary code execution if the iso-info tool is used with a crafted
 iso image (LP: #191216)
&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt; References
&lt;ul&gt;&lt;li&gt; http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=459129&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Wed, 20 Feb 2008 14:55:42 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>pcre3, 7.4-0ubuntu0.6.06.2</title>
  <guid>http://launchpad.net/distros/ubuntu/dapper/+source/pcre3,/7.4-0ubuntu0.6.06.2</guid>
  <link>http://launchpad.net/distros/ubuntu/dapper/+source/pcre3,/7.4-0ubuntu0.6.06.2</link>
  <description>&lt;b&gt;pcre3 (7.4-0ubuntu0.6.06.2)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; SECURITY UPDATE: stack overflow when handling long UTF8 strings.
&lt;/li&gt;&lt;li&gt; pcre_compile.c, testdata/test{in,out}put4: upstream changes from 7.6
 backported, thanks to Tomas Hoger and Florian Weimer.
&lt;/li&gt;&lt;li&gt; References
 CVE-2008-0674&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Thu, 21 Feb 2008 18:55:26 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>cacti, 0.8.6h-1ubuntu3.2</title>
  <guid>http://launchpad.net/distros/ubuntu/dapper/+source/cacti,/0.8.6h-1ubuntu3.2</guid>
  <link>http://launchpad.net/distros/ubuntu/dapper/+source/cacti,/0.8.6h-1ubuntu3.2</link>
  <description>&lt;b&gt;cacti (0.8.6h-1ubuntu3.2)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; SECURITY UPDATE: (LP: #192199)
&lt;ul&gt;&lt;li&gt; CVE-2008-0783: Multiple cross-site scripting (XSS) vulnerabilities in
 Cacti 0.8.7 before 0.8.7b and 0.8.6 before 0.8.6k allow remote attackers to
 inject arbitrary web script or HTML via the (1) view_type parameter to
 graph.php, (2) filter parameter to graph_view.php, and (3) action and
 login_username parameters to index.php/login.
&lt;/li&gt;&lt;li&gt; CVE-2008-0784: graph.php in Cacti 0.8.7 before 0.8.7b and 0.8.6 before
 0.8.6k allows remote attackers to obtain the full path via an invalid
 local_graph_id parameter and other unspecified vectors.
&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt; debian/patches/10_CVE-2008-0783_CVE-2008-0784.dpatch: applied patch by
 upstream. Backported from 0.8.6j
 (Link: http://www.cacti.net/downloads/patches/0.8.6j/multiple_vulnerabilities-0.8.6j.patch)
&lt;/li&gt;&lt;li&gt; References:
 CVE-2008-0783
 CVE-2008-0784&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Fri, 22 Feb 2008 02:55:15 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>lighttpd, 1.4.11-3ubuntu3.6</title>
  <guid>http://launchpad.net/distros/ubuntu/dapper/+source/lighttpd,/1.4.11-3ubuntu3.6</guid>
  <link>http://launchpad.net/distros/ubuntu/dapper/+source/lighttpd,/1.4.11-3ubuntu3.6</link>
  <description>&lt;b&gt;lighttpd (1.4.11-3ubuntu3.6)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; SECURITY UPDATE:
&lt;ul&gt;&lt;li&gt; debian/patches/90_maxfds_crash_fix.dpatch:
&lt;ul&gt;&lt;li&gt; added patch from upstream to fix the maxfds issue (LP: #195380)
&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt; References
&lt;ul&gt;&lt;li&gt;  http://trac.lighttpd.net/trac/ticket/1562&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Wed, 27 Feb 2008 14:55:20 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>lookup-el,lookup-el 1.4-4ubuntu0.6.06</title>
  <guid>http://launchpad.net/distros/ubuntu/dapper/+source/lookup-el,lookup-el/1.4-4ubuntu0.6.06</guid>
  <link>http://launchpad.net/distros/ubuntu/dapper/+source/lookup-el,lookup-el/1.4-4ubuntu0.6.06</link>
  <description>&lt;b&gt;lookup-el (1.4-4ubuntu0.6.06)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; SECURITY UPDATE:
&lt;ul&gt;&lt;li&gt; lisp/ndeb-binary.el: Make a temporary subdirectory securely. (LP: #176931)
&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt; References
&lt;ul&gt;&lt;li&gt; http://www.debian.org/security/2007/dsa-1269
&lt;/li&gt;&lt;li&gt; http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0237&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Wed, 27 Feb 2008 14:56:07 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>mozilla-thunderbird, 1.5.0.13+1.5.0.15~prepatch080227-0ubuntu0.6.06.0</title>
  <guid>http://launchpad.net/distros/ubuntu/dapper/+source/mozilla-thunderbird,/1.5.0.13+1.5.0.15~prepatch080227-0ubuntu0.6.06.0</guid>
  <link>http://launchpad.net/distros/ubuntu/dapper/+source/mozilla-thunderbird,/1.5.0.13+1.5.0.15~prepatch080227-0ubuntu0.6.06.0</link>
  <description />
  <pubDate>Fri, 29 Feb 2008 04:55:44 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>gnatsweb,gnatsweb 4.00-1ubuntu0.6.06</title>
  <guid>http://launchpad.net/distros/ubuntu/dapper/+source/gnatsweb,gnatsweb/4.00-1ubuntu0.6.06</guid>
  <link>http://launchpad.net/distros/ubuntu/dapper/+source/gnatsweb,gnatsweb/4.00-1ubuntu0.6.06</link>
  <description>&lt;b&gt;gnatsweb (4.00-1ubuntu0.6.06)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; SECURITY UPDATE:
&lt;/li&gt;&lt;li&gt; gnatsweb.pl (LP: #191196)
&lt;ul&gt;&lt;li&gt; Fixed missing escaping of the database parameter which leads
 to a cross-site scripting vulnerability (XSS) via this
 parameter (CVE-2007-2808).
&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt; References:
&lt;/li&gt;&lt;li&gt; http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2808
&lt;/li&gt;&lt;li&gt; http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=427156&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Tue, 04 Mar 2008 18:55:14 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>evolution, 2.6.1-0ubuntu7.2</title>
  <guid>http://launchpad.net/distros/ubuntu/dapper/+source/evolution,/2.6.1-0ubuntu7.2</guid>
  <link>http://launchpad.net/distros/ubuntu/dapper/+source/evolution,/2.6.1-0ubuntu7.2</link>
  <description>&lt;b&gt;evolution (2.6.1-0ubuntu7.2)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; SECURITY UPDATE: code execution via format string in encrypted emails.
&lt;/li&gt;&lt;li&gt; Add 99_00_encryption_format_string_fix.patch: upstream fixes from
 Srinivasa Ragavan.
&lt;/li&gt;&lt;li&gt; References
 CVE-2008-0072&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Wed, 05 Mar 2008 18:56:59 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>openldap2.2, 2.2.26-5ubuntu2.6</title>
  <guid>http://launchpad.net/distros/ubuntu/dapper/+source/openldap2.2,/2.2.26-5ubuntu2.6</guid>
  <link>http://launchpad.net/distros/ubuntu/dapper/+source/openldap2.2,/2.2.26-5ubuntu2.6</link>
  <description>&lt;b&gt;openldap2.2 (2.2.26-5ubuntu2.6)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; version bump for -proposed version conflict
&lt;/li&gt;&lt;/ul&gt;&lt;b&gt;openldap2.2 (2.2.26-5ubuntu2.5)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; SECURITY UPDATE: slapd crash when using the bdb backend and processing
 crafted modify and modrdn requests
&lt;/li&gt;&lt;li&gt; patch to back-bdb/add.c, back-bdb/ctxcsn.c, back-bdb/delete.c,
 back-bdb/modify.c, back-bdb/modrdn.c to properly check for NOOP option
&lt;/li&gt;&lt;li&gt; References:
 CVE-2007-6698
 CVE-2008-0658
 LP: #197077&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Wed, 05 Mar 2008 20:55:22 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>langpack-locales 2.3.18.9</title>
  <guid>http://launchpad.net/distros/ubuntu/dapper/+source/langpack-locales/2.3.18.9</guid>
  <link>http://launchpad.net/distros/ubuntu/dapper/+source/langpack-locales/2.3.18.9</link>
  <description>&lt;b&gt;langpack-locales (2.3.18.9)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; debian/tzdata2007k+chiledst.tar.gz: Update original 2007k tarball
 to incorporate short-term DST rule change in Chile for 2008 (delayed for
 three weeks from March 08 to March 29). (LP: #198129)&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Thu, 06 Mar 2008 10:36:45 +0000</pubDate>
  <dc:creator>Martin Pitt</dc:creator>
  <author>Martin Pitt</author>
</item>


<item>
  <title>mozilla-thunderbird, 1.5.0.13+1.5.0.15~prepatch080227-0ubuntu0.6.06.1</title>
  <guid>http://launchpad.net/distros/ubuntu/dapper/+source/mozilla-thunderbird,/1.5.0.13+1.5.0.15~prepatch080227-0ubuntu0.6.06.1</guid>
  <link>http://launchpad.net/distros/ubuntu/dapper/+source/mozilla-thunderbird,/1.5.0.13+1.5.0.15~prepatch080227-0ubuntu0.6.06.1</link>
  <description>&lt;b&gt;mozilla-thunderbird (1.5.0.13+1.5.0.15~prepatch080227-0ubuntu0.6.06.1)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; fix memory access regression (LP: #197504)
&lt;ul&gt;&lt;li&gt; add debian/patches/0071_279505-attachment-297724-(fix-396613-regression).dpatch
&lt;/li&gt;&lt;li&gt; update debian/patches/00list&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Thu, 06 Mar 2008 14:56:00 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>lighttpd, 1.4.11-3ubuntu3.7</title>
  <guid>http://launchpad.net/distros/ubuntu/dapper/+source/lighttpd,/1.4.11-3ubuntu3.7</guid>
  <link>http://launchpad.net/distros/ubuntu/dapper/+source/lighttpd,/1.4.11-3ubuntu3.7</link>
  <description>&lt;b&gt;lighttpd (1.4.11-3ubuntu3.7)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; SECURITY UPDATE:
&lt;/li&gt;&lt;li&gt; debian/patches/91_CVE-2008-1111.dpatch:
&lt;ul&gt;&lt;li&gt; Fixes CVE-2008-1111
 "mod_cgi in lighttpd 1.4.18, when a fork failure occurs, sends the
 source code of CGI scripts instead of a 500 error, which might allow
 remote attackers to obtain sensitive information." (LP: #198731)
&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt; References
&lt;/li&gt;&lt;li&gt; http://trac.lighttpd.net/trac/changeset/2107
&lt;/li&gt;&lt;li&gt; http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2008-1111&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Fri, 07 Mar 2008 18:55:27 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>python2.4, 2.4.3-0ubuntu6.1</title>
  <guid>http://launchpad.net/distros/ubuntu/dapper/+source/python2.4,/2.4.3-0ubuntu6.1</guid>
  <link>http://launchpad.net/distros/ubuntu/dapper/+source/python2.4,/2.4.3-0ubuntu6.1</link>
  <description>&lt;b&gt;python2.4 (2.4.3-0ubuntu6.1)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; SECURITY UPDATE: code execution via integer overflows, information
 leak via strxfrm.
&lt;/li&gt;&lt;li&gt; debian/rules, debian/patches/CVE-2007-4965-int-overflow.dpatch: upstream
 changes, thanks to Stephan Hermann.
&lt;/li&gt;&lt;li&gt; debian/rules, debian/patches/strxfrm-leak.dpatch: upstream changes.
&lt;/li&gt;&lt;li&gt; References
 http://bugs.python.org/file8592/python-2.5.CVE-2007-4965-int-overflow.patch
 CVE-2007-4965
 CVE-2007-2052&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Mon, 10 Mar 2008 21:55:30 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>lighttpd, 1.4.11-3ubuntu3.8</title>
  <guid>http://launchpad.net/distros/ubuntu/dapper/+source/lighttpd,/1.4.11-3ubuntu3.8</guid>
  <link>http://launchpad.net/distros/ubuntu/dapper/+source/lighttpd,/1.4.11-3ubuntu3.8</link>
  <description>&lt;b&gt;lighttpd (1.4.11-3ubuntu3.8)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; SECURITY UPDATE: (LP: #200987)
&lt;/li&gt;&lt;li&gt; debian/patches/91_CVE-2008-1270.dpatch
&lt;ul&gt;&lt;li&gt; mod_userdir in lighttpd 1.4.18 and earlier, when userdir.path is not set,
 uses a default of $HOME, which might allow remote attackers to read arbitrary
 files, as demonstrated by accessing the ~nobody directory.
&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt; References
&lt;/li&gt;&lt;li&gt; http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-1270
&lt;/li&gt;&lt;li&gt; http://trac.lighttpd.net/trac/ticket/1587
&lt;/li&gt;&lt;li&gt; http://trac.lighttpd.net/trac/changeset/2120&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Tue, 11 Mar 2008 19:55:17 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>mysql-dfsg-5.0 5.0.22-0ubuntu6.06.7</title>
  <guid>http://launchpad.net/distros/ubuntu/dapper/+source/mysql-dfsg-5.0/5.0.22-0ubuntu6.06.7</guid>
  <link>http://launchpad.net/distros/ubuntu/dapper/+source/mysql-dfsg-5.0/5.0.22-0ubuntu6.06.7</link>
  <description>&lt;b&gt;mysql-dfsg-5.0 (5.0.22-0ubuntu6.06.7)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; SECURITY UPDATE: buffer overflow via ProcessOldClientHello() in
 handshake.cpp and input_buffer&amp;amp; operator&amp;gt;&amp;gt; in yassl_imp.cpp
&lt;/li&gt;&lt;li&gt; SECURITY UPDATE: buffer overread in HASHwithTransform::Update in hash.cpp
&lt;/li&gt;&lt;li&gt; debian/patches/99_SECURITY_CVE-2008-0226_0227.dpatch: properly verify
 length of input (LP: #186978). Note that while this patch is included,
 mysql on Ubuntu 6.06 is not compiled with yassl enabled.
&lt;/li&gt;&lt;li&gt; SECURITY UPDATE: privilege escalation via crafted CREATE SQL SECURITY
 DEFINER VIEW and ALTER VIEW statements
&lt;/li&gt;&lt;li&gt; debian/patches/100_SECURITY_CVE-2007-6303.dpatch: make sure lex-&amp;gt;definer
 is non-NULL in sql_view.cc (LP: #185039). This patch also fixes upstream
 bug #21080, which was needed to keep VIEW definitions in sync.
&lt;/li&gt;&lt;li&gt; SECURITY UPDATE: denial of service via crafted EXPLAIN SELECT FROM on the
 INFORMATION_SCHEMA table
&lt;/li&gt;&lt;li&gt; debian/patches/101_SECURITY_CVE-2006-7232.dpatch: make sure
 thd-&amp;gt;lex-describe is non-NULL in sql_select.cc (LP: #161127)
&lt;/li&gt;&lt;li&gt; debian/patches/102_view_fix-now.dpatch: update view.test and view.result to
 use a static year instead of now(). These tests are not part of the build
 but helps with qa-regression-testing
&lt;/li&gt;&lt;li&gt; SECURITY UPDATE: privilege escalation via SQL SECURITY INVOKER stored
 routines
&lt;/li&gt;&lt;li&gt; debian/patches/103_SECURITY_CVE-2007-2692.dpatch: restore THD::db_access
 when returning from stored routine by performing privilege checks in the
 execution stage rather than the parsing stage. This patch also fixes
 upstream bug #18681, which was needed to properly check view security.
&lt;/li&gt;&lt;li&gt; References
 CVE-2008-0226
 CVE-2008-0227
 CVE-2007-6303
 CVE-2006-7232
 CVE-2007-2692
 http://bugs.mysql.com/bug.php?id=27337
 http://bugs.mysql.com/bug.php?id=18681
 http://bugs.mysql.com/bug.php?id=21080&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Wed, 12 Mar 2008 08:15:37 +0000</pubDate>
  <dc:creator>Jamie Strandboge</dc:creator>
  <author>Jamie Strandboge</author>
</item>


<item>
  <title>langpack-locales 2.3.18.10</title>
  <guid>http://launchpad.net/distros/ubuntu/dapper/+source/langpack-locales/2.3.18.10</guid>
  <link>http://launchpad.net/distros/ubuntu/dapper/+source/langpack-locales/2.3.18.10</link>
  <description>&lt;b&gt;langpack-locales (2.3.18.10)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; Replace debian/tzdata2007k+chiledst.tar.gz with new upstream version
 tzdata2008a.tar.gz: Fixes Chile DST properly, our patch switched it on a
 day too early. (LP: #198129)&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Wed, 12 Mar 2008 09:30:59 +0000</pubDate>
  <dc:creator>Martin Pitt</dc:creator>
  <author>Martin Pitt</author>
</item>


<item>
  <title>vlc, 0.8.4.debian-1ubuntu6.2</title>
  <guid>http://launchpad.net/distros/ubuntu/dapper/+source/vlc,/0.8.4.debian-1ubuntu6.2</guid>
  <link>http://launchpad.net/distros/ubuntu/dapper/+source/vlc,/0.8.4.debian-1ubuntu6.2</link>
  <description>&lt;b&gt;vlc (0.8.4.debian-1ubuntu6.2)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; SECURITY UPDATE:
&lt;ul&gt;&lt;li&gt; debian/patches/CVE-2008-0984.dpatch (LP: #195949)
&lt;/li&gt;&lt;li&gt; VLC media player's MPEG-4 file format parser (a.k.a. the MP4 demuxer)
&lt;ul&gt;&lt;li&gt;suffers from an arbitrary memory overwrite vulnerability when using
&lt;/li&gt;&lt;li&gt;crash the player instance.
&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt; References
&lt;ul&gt;&lt;li&gt; http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0984
&lt;/li&gt;&lt;li&gt; http://www.videolan.org/security/sa0802.html&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Wed, 12 Mar 2008 17:55:49 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>mailman, 2.1.5-9ubuntu4.2</title>
  <guid>http://launchpad.net/distros/ubuntu/dapper/+source/mailman,/2.1.5-9ubuntu4.2</guid>
  <link>http://launchpad.net/distros/ubuntu/dapper/+source/mailman,/2.1.5-9ubuntu4.2</link>
  <description>&lt;b&gt;mailman (2.1.5-9ubuntu4.2)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; SECURITY UPDATE:
&lt;/li&gt;&lt;li&gt; debian/patches/100_CVE-2008-0564.dpatch (LP: #199338)
&lt;ul&gt;&lt;li&gt; Multiple cross-site scripting (XSS) vulnerabilities in Mailman
 before 2.1.10b1 allow remote attackers to inject arbitrary web
 script or HTML via unspecified vectors related to (1) editing
 templates and (2) the list's "info attribute" in the web
 administrator interface.
&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt; References
&lt;/li&gt;&lt;li&gt; http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0564
&lt;/li&gt;&lt;li&gt; http://bugs.gentoo.org/show_bug.cgi?id=208710&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Fri, 14 Mar 2008 18:55:23 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>phpmyadmin, 4:2.8.0.3-1ubuntu0.1</title>
  <guid>http://launchpad.net/distros/ubuntu/dapper/+source/phpmyadmin,/4:2.8.0.3-1ubuntu0.1</guid>
  <link>http://launchpad.net/distros/ubuntu/dapper/+source/phpmyadmin,/4:2.8.0.3-1ubuntu0.1</link>
  <description>&lt;b&gt;phpmyadmin (4:2.8.0.3-1ubuntu0.1)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; SECURITY UPDATE:
&lt;/li&gt;&lt;li&gt; debian/patches/050_CVE-2008-1149.patch
&lt;ul&gt;&lt;li&gt; Provides unauthorized access, Allows partial confidentiality, integrity, and
 availability violation , Allows unauthorized disclosure of information ,
 Allows disruption of service. (LP: #198745)
&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt; References:
&lt;/li&gt;&lt;li&gt; http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-1149
&lt;/li&gt;&lt;li&gt; http://www.phpmyadmin.net/home_page/security.php?issue=PMASA-2008-1&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Fri, 14 Mar 2008 20:55:16 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>wml, 2.0.8-11ubuntu0.6.06</title>
  <guid>http://launchpad.net/distros/ubuntu/dapper/+source/wml,/2.0.8-11ubuntu0.6.06</guid>
  <link>http://launchpad.net/distros/ubuntu/dapper/+source/wml,/2.0.8-11ubuntu0.6.06</link>
  <description>&lt;b&gt;wml (2.0.8-11ubuntu0.6.06)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; SECURITY UPDATE: (LP: #191205)
&lt;/li&gt;&lt;li&gt; wml_backend/p1_ipp/ipp.src (CVE-2008-0665)
&lt;ul&gt;&lt;li&gt; in Website META Language (WML) 2.0.11 allows local
 users to overwrite arbitrary files via a symlink attack on the ipp.$$.tmp
 temporary file.
&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt; wlm_backend/p3_eperl/eperl_sys.c wml_contrib/wmg.cgi (CVE-2008-0666)
&lt;ul&gt;&lt;li&gt; Website META Language (WML) 2.0.11 allows local users to overwrite arbitrary
 files via a symlink attack on (1) the /tmp/pe.tmp.$$ temporary file used by
 wml_contrib/wmg.cgi and (2) temporary files used by
 wml_backend/p3_eperl/eperl_sys.c.
&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt; References
&lt;/li&gt;&lt;li&gt; http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2008-0665
&lt;/li&gt;&lt;li&gt; http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2008-0666
&lt;/li&gt;&lt;li&gt; http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=463907&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Fri, 14 Mar 2008 20:55:58 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>krb5, 1.4.3-5ubuntu0.7</title>
  <guid>http://launchpad.net/distros/ubuntu/dapper/+source/krb5,/1.4.3-5ubuntu0.7</guid>
  <link>http://launchpad.net/distros/ubuntu/dapper/+source/krb5,/1.4.3-5ubuntu0.7</link>
  <description>&lt;b&gt;krb5 (1.4.3-5ubuntu0.7)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; SECURITY UPDATE: arbitrary code execution via freed pointer and memory
 overflows.
&lt;/li&gt;&lt;li&gt; src/kdc/{kerberos_v4,dispatch,network}.c: backported upstream fixes
 patched inline (MITKRB5-SA-2008-001: CVE-2008-0062, CVE-2008-0063).
&lt;/li&gt;&lt;li&gt; src/lib/rpc/{svc,svc_tcp}.c: upstream fixed patched inline
 (MITKRB5-SA-2008-002: CVE-2008-0947)&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Tue, 18 Mar 2008 23:55:43 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>mysql-dfsg-5.0, 5.0.22-0ubuntu6.06.8</title>
  <guid>http://launchpad.net/distros/ubuntu/dapper/+source/mysql-dfsg-5.0,/5.0.22-0ubuntu6.06.8</guid>
  <link>http://launchpad.net/distros/ubuntu/dapper/+source/mysql-dfsg-5.0,/5.0.22-0ubuntu6.06.8</link>
  <description>&lt;b&gt;mysql-dfsg-5.0 (5.0.22-0ubuntu6.06.8)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; no change build for -security upload
&lt;/li&gt;&lt;/ul&gt;&lt;b&gt;mysql-dfsg-5.0 (5.0.22-0ubuntu6.06.7)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; SECURITY UPDATE: buffer overflow via ProcessOldClientHello() in
 handshake.cpp and input_buffer&amp;amp; operator&amp;gt;&amp;gt; in yassl_imp.cpp
&lt;/li&gt;&lt;li&gt; SECURITY UPDATE: buffer overread in HASHwithTransform::Update in hash.cpp
&lt;/li&gt;&lt;li&gt; debian/patches/99_SECURITY_CVE-2008-0226_0227.dpatch: properly verify
 length of input (LP: #186978). Note that while this patch is included,
 mysql on Ubuntu 6.06 is not compiled with yassl enabled.
&lt;/li&gt;&lt;li&gt; SECURITY UPDATE: privilege escalation via crafted CREATE SQL SECURITY
 DEFINER VIEW and ALTER VIEW statements
&lt;/li&gt;&lt;li&gt; debian/patches/100_SECURITY_CVE-2007-6303.dpatch: make sure lex-&amp;gt;definer
 is non-NULL in sql_view.cc (LP: #185039). This patch also fixes upstream
 bug #21080, which was needed to keep VIEW definitions in sync.
&lt;/li&gt;&lt;li&gt; SECURITY UPDATE: denial of service via crafted EXPLAIN SELECT FROM on the
 INFORMATION_SCHEMA table
&lt;/li&gt;&lt;li&gt; debian/patches/101_SECURITY_CVE-2006-7232.dpatch: make sure
 thd-&amp;gt;lex-describe is non-NULL in sql_select.cc (LP: #161127)
&lt;/li&gt;&lt;li&gt; debian/patches/102_view_fix-now.dpatch: update view.test and view.result to
 use a static year instead of now(). These tests are not part of the build
 but helps with qa-regression-testing
&lt;/li&gt;&lt;li&gt; SECURITY UPDATE: privilege escalation via SQL SECURITY INVOKER stored
 routines
&lt;/li&gt;&lt;li&gt; debian/patches/103_SECURITY_CVE-2007-2692.dpatch: restore THD::db_access
 when returning from stored routine by performing privilege checks in the
 execution stage rather than the parsing stage. This patch also fixes
 upstream bug #18681, which was needed to properly check view security.
&lt;/li&gt;&lt;li&gt; References
 CVE-2008-0226
 CVE-2008-0227
 CVE-2007-6303
 CVE-2006-7232
 CVE-2007-2692
 http://bugs.mysql.com/bug.php?id=27337
 http://bugs.mysql.com/bug.php?id=18681
 http://bugs.mysql.com/bug.php?id=21080&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Thu, 20 Mar 2008 10:55:53 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>unzip, 5.52-6ubuntu4.1</title>
  <guid>http://launchpad.net/distros/ubuntu/dapper/+source/unzip,/5.52-6ubuntu4.1</guid>
  <link>http://launchpad.net/distros/ubuntu/dapper/+source/unzip,/5.52-6ubuntu4.1</link>
  <description>&lt;b&gt;unzip (5.52-6ubuntu4.1)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; SECURITY UPDATE: arbitrary code execution via heap corruption.
&lt;/li&gt;&lt;li&gt; inflate.c: fix invalid free() calls, patch from Tavis Ormandy.
&lt;/li&gt;&lt;li&gt; References
 CVE-2008-0888&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Thu, 20 Mar 2008 17:55:27 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>smarty,smarty 2.6.11-1ubuntu0.1</title>
  <guid>http://launchpad.net/distros/ubuntu/dapper/+source/smarty,smarty/2.6.11-1ubuntu0.1</guid>
  <link>http://launchpad.net/distros/ubuntu/dapper/+source/smarty,smarty/2.6.11-1ubuntu0.1</link>
  <description>&lt;b&gt;smarty (2.6.11-1ubuntu0.1)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; SECURITY UPDATE: (LP: #202422)
&lt;/li&gt;&lt;li&gt; libs/plugins/modifier.regex_replace.php
&lt;ul&gt;&lt;li&gt; The modifier.regex_replace.php plugin in Smarty before 2.6.19, as used
 by Serendipity (S9Y) and other products, allows attackers to call arbitrary
 PHP functions via templates, related to a '\0' character in a search string.
&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt; References
&lt;/li&gt;&lt;li&gt; http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1066
&lt;/li&gt;&lt;li&gt; http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=469492&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Mon, 24 Mar 2008 12:55:29 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>mplayer, 2:0.99+1.0pre7try2+cvs20060117-0ubuntu8.2</title>
  <guid>http://launchpad.net/distros/ubuntu/dapper/+source/mplayer,/2:0.99+1.0pre7try2+cvs20060117-0ubuntu8.2</guid>
  <link>http://launchpad.net/distros/ubuntu/dapper/+source/mplayer,/2:0.99+1.0pre7try2+cvs20060117-0ubuntu8.2</link>
  <description>&lt;b&gt;mplayer (2:0.99+1.0pre7try2+cvs20060117-0ubuntu8.2)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; SECURITY UPDATE: buffer overruns in RMMF, CDDB, MOV demuxer, and URL
 parser. (LP: #191488)
&lt;/li&gt;&lt;li&gt; debian/patches/{64_CVE-2008-0225_0238,65_CVE-2008-0485,66_CVE-2008-0629,
 67_CVE-2008-0630}.dpatch: Patches from upstream.
&lt;/li&gt;&lt;li&gt; References:
&lt;ul&gt;&lt;li&gt; CVE-2008-0225
&lt;/li&gt;&lt;li&gt; CVE-2008-0238
&lt;/li&gt;&lt;li&gt; CVE-2008-0485
&lt;/li&gt;&lt;li&gt; CVE-2008-0629
&lt;/li&gt;&lt;li&gt; CVE-2008-0630&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Mon, 24 Mar 2008 15:55:44 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>bzip2, 1.0.3-0ubuntu2.1</title>
  <guid>http://launchpad.net/distros/ubuntu/dapper/+source/bzip2,/1.0.3-0ubuntu2.1</guid>
  <link>http://launchpad.net/distros/ubuntu/dapper/+source/bzip2,/1.0.3-0ubuntu2.1</link>
  <description>&lt;b&gt;bzip2 (1.0.3-0ubuntu2.1)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; SECURITY UPDATE: denial of service via heap memory corruption.
&lt;/li&gt;&lt;li&gt; bzlib.c, bzlib_private.h: upstream patch from 1.0.5 applied inline.
&lt;/li&gt;&lt;li&gt; References
 CVE-2008-1372&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Mon, 24 Mar 2008 17:55:23 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>icu, 3.4.1a-1ubuntu1.6.06.1</title>
  <guid>http://launchpad.net/distros/ubuntu/dapper/+source/icu,/3.4.1a-1ubuntu1.6.06.1</guid>
  <link>http://launchpad.net/distros/ubuntu/dapper/+source/icu,/3.4.1a-1ubuntu1.6.06.1</link>
  <description>&lt;b&gt;icu (3.4.1a-1ubuntu1.6.06.1)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; SECURITY UPDATE: possible read from and write to out of bounds memory
 locations via back reference '\0' in regular expressions
&lt;/li&gt;&lt;li&gt; SECURITY UPDATE: denial of service due to memory exhaustion via a
 crafted regular expression
&lt;/li&gt;&lt;li&gt; debian/patches/SECURITY_CVE-2007-4770_4771.patch: fix regexcmp.cpp to
 return error on invalid back reference. fix rematch.cpp, uvectr32.h and
 uvectr32.cpp to return error when capacity is greater than maxCapacity
&lt;/li&gt;&lt;li&gt; References
 CVE-2007-4770
 CVE-2007-4771&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Mon, 24 Mar 2008 17:56:37 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>dspam, 3.6.4-4ubuntu0.1</title>
  <guid>http://launchpad.net/distros/ubuntu/dapper/+source/dspam,/3.6.4-4ubuntu0.1</guid>
  <link>http://launchpad.net/distros/ubuntu/dapper/+source/dspam,/3.6.4-4ubuntu0.1</link>
  <description>&lt;b&gt;dspam (3.6.4-4ubuntu0.1)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; SECURITY UPDATE: The libdspam7-drv-mysql cron job includes the MySQL
 dspam database password in a command line argument, which might allow
 local users to read the password by listing the process and its arguments.
&lt;/li&gt;&lt;li&gt; debian/libdspam7-drv-mysql.cron.daily: applied patch from Debian to use a
 password file instead.
&lt;/li&gt;&lt;li&gt; References
&lt;ul&gt;&lt;li&gt; LP: #195691
&lt;/li&gt;&lt;li&gt; CVE-2007-6418&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Wed, 26 Mar 2008 03:55:42 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>firefox, 1.5.dfsg+1.5.0.15~prepatch080323a-0ubuntu1</title>
  <guid>http://launchpad.net/distros/ubuntu/dapper/+source/firefox,/1.5.dfsg+1.5.0.15~prepatch080323a-0ubuntu1</guid>
  <link>http://launchpad.net/distros/ubuntu/dapper/+source/firefox,/1.5.dfsg+1.5.0.15~prepatch080323a-0ubuntu1</link>
  <description>&lt;b&gt;firefox (1.5.dfsg+1.5.0.15~prepatch080323a-0ubuntu1)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; release backports for security issues disclosed in 2.0.0.13
&lt;ul&gt;&lt;li&gt; see USN-592-1
&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt; patches on top of 1.8.0 branch cvs checkout are in patches/series
&lt;/li&gt;&lt;li&gt; fix greasemonkey regression (bmo 417617) introduced by bmo 403168
&lt;ul&gt;&lt;li&gt; add patches/417617_attachment_306518.patch (in orig sources)
&lt;/li&gt;&lt;li&gt; update and apply patches/series (in orig sources)&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Wed, 26 Mar 2008 12:59:28 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>libnet-dns-perl, 0.53-2ubuntu1.1</title>
  <guid>http://launchpad.net/distros/ubuntu/dapper/+source/libnet-dns-perl,/0.53-2ubuntu1.1</guid>
  <link>http://launchpad.net/distros/ubuntu/dapper/+source/libnet-dns-perl,/0.53-2ubuntu1.1</link>
  <description>&lt;b&gt;libnet-dns-perl (0.53-2ubuntu1.1)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; SECURITY UPDATE:
&lt;/li&gt;&lt;li&gt; debian/patches/42_CVE-2007-6341.dpatch (LP: #201454)
&lt;ul&gt;&lt;li&gt; used in packages such as SpamAssassin and OTRS, allows remote
 attackers to cause a denial of service (program "croak") via a
 crafted DNS response.
&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt; References
&lt;/li&gt;&lt;li&gt; http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6341
&lt;/li&gt;&lt;li&gt; http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=457445&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Wed, 26 Mar 2008 17:56:10 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>sdl-image1.2, 1.2.4-1ubuntu0.1</title>
  <guid>http://launchpad.net/distros/ubuntu/dapper/+source/sdl-image1.2,/1.2.4-1ubuntu0.1</guid>
  <link>http://launchpad.net/distros/ubuntu/dapper/+source/sdl-image1.2,/1.2.4-1ubuntu0.1</link>
  <description>&lt;b&gt;sdl-image1.2 (1.2.4-1ubuntu0.1)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; SECURITY UPDATE: Buffer overflow in GIF handling; possible
 denial of service and arbitrary code execution.
&lt;/li&gt;&lt;li&gt; SECURITY UPDATE: Buffer overflow in IFF ILBM  handling; possible
 denial of service and arbitrary code execution.
&lt;/li&gt;&lt;li&gt; Added patches to prevent buffer overflow in IMG_gif.c and IMG_lbm.c.
 Patches prepared from sdl-image1.2_1.2.5-2etch1 update in debian.
 Applied inline. (LP: #185782)
&lt;/li&gt;&lt;li&gt; References:
 http://www.debian.org/security/2008/dsa-1493
 CVE-2007-6697 and CVE-2008-0544&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Wed, 26 Mar 2008 18:55:24 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>ruby1.8, 1.8.4-1ubuntu1.4</title>
  <guid>http://launchpad.net/distros/ubuntu/dapper/+source/ruby1.8,/1.8.4-1ubuntu1.4</guid>
  <link>http://launchpad.net/distros/ubuntu/dapper/+source/ruby1.8,/1.8.4-1ubuntu1.4</link>
  <description>&lt;b&gt;ruby1.8 (1.8.4-1ubuntu1.4)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; SECURITY UPDATE: SSL connections did not check commonName early
 enough, possibly allowing sensitive information to be exposed.
&lt;/li&gt;&lt;li&gt; debian/patches/915_CVE-2007-5162.patch: upstream fixes, from
 http://svn.ruby-lang.org/cgi-bin/viewvc.cgi?view=rev&amp;amp;revision=13499
&lt;/li&gt;&lt;li&gt; debian/patches/915_CVE-2007-5770.patch: upstream fixes, from
 http://svn.ruby-lang.org/cgi-bin/viewvc.cgi?view=rev&amp;amp;revision=13656
&lt;/li&gt;&lt;li&gt; References:
 CVE-2007-5162 CVE-2007-5770 (LP: #149616)&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Wed, 26 Mar 2008 18:56:13 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>dovecot, 1.0.beta3-3ubuntu5.6</title>
  <guid>http://launchpad.net/distros/ubuntu/dapper/+source/dovecot,/1.0.beta3-3ubuntu5.6</guid>
  <link>http://launchpad.net/distros/ubuntu/dapper/+source/dovecot,/1.0.beta3-3ubuntu5.6</link>
  <description>&lt;b&gt;dovecot (1.0.beta3-3ubuntu5.6)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; SECURITY UPDATE: mailboxes of other users could be read via symlinks.
&lt;/li&gt;&lt;li&gt; Add upstream-mail-group-fixes.dpatch: upstream fixes (CVE-2008-1199).
&lt;/li&gt;&lt;li&gt; Add upstream-invalid-password-fixes.dpatch: proactive upstream fixes
 to avoid future issues in underlying passdb (CVE-2008-1218).
&lt;/li&gt;&lt;li&gt; References
 http://dovecot.org/list/dovecot-news/2008-March/000060.html
 http://dovecot.org/list/dovecot-news/2008-March/000064.html&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Wed, 26 Mar 2008 17:55:40 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>horde3, 3.1.1-1ubuntu0.1</title>
  <guid>http://launchpad.net/distros/ubuntu/dapper/+source/horde3,/3.1.1-1ubuntu0.1</guid>
  <link>http://launchpad.net/distros/ubuntu/dapper/+source/horde3,/3.1.1-1ubuntu0.1</link>
  <description>&lt;b&gt;horde3 (3.1.1-1ubuntu0.1)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; SECURITY UPDATE: (LP: #203456)
&lt;/li&gt;&lt;li&gt; Directory traversal vulnerability in Horde 3.1.6, Groupware before 1.0.5,
&lt;ul&gt;&lt;li&gt;and Groupware Webmail Edition before 1.0.6, when running with certain
&lt;/li&gt;&lt;li&gt;configurations, allows remote authenticated users to read and execute arbitrary
&lt;/li&gt;&lt;li&gt;files via ".." sequences and a null byte in the theme name.
&lt;/li&gt;&lt;li&gt;Fix directory traversal vulnerability in Registry.php which allows
&lt;/li&gt;&lt;li&gt;an attacker to read and execute arbitrary local files via crafted
&lt;/li&gt;&lt;li&gt;path sequences.
&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt; References
&lt;/li&gt;&lt;li&gt; http://ftp.horde.org/pub/horde/patches/patch-horde-3.1.6-3.1.7.gz
&lt;/li&gt;&lt;li&gt; http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2008-1284
&lt;/li&gt;&lt;li&gt; http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=470640
&lt;/li&gt;&lt;li&gt; http://www.debian.org/security/2008/dsa-1519&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Thu, 27 Mar 2008 16:55:21 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>dspam, 3.6.4-4ubuntu0.2</title>
  <guid>http://launchpad.net/distros/ubuntu/dapper/+source/dspam,/3.6.4-4ubuntu0.2</guid>
  <link>http://launchpad.net/distros/ubuntu/dapper/+source/dspam,/3.6.4-4ubuntu0.2</link>
  <description>&lt;b&gt;dspam (3.6.4-4ubuntu0.2)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; debian/libdspam7-drv-mysql.cron.daily:
 Fix bashism introduced in previous security update (s/echo -e/printf/)
 (LP: #207579)&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Fri, 28 Mar 2008 00:55:21 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>sun-java5 1.5.0-15-0ubuntu0.6.06</title>
  <guid>http://launchpad.net/distros/ubuntu/dapper/+source/sun-java5/1.5.0-15-0ubuntu0.6.06</guid>
  <link>http://launchpad.net/distros/ubuntu/dapper/+source/sun-java5/1.5.0-15-0ubuntu0.6.06</link>
  <description>&lt;b&gt;sun-java5 (1.5.0-15-0ubuntu0.6.06)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; New upstream bug fix release. For a list of changes see
 http://java.sun.com/j2se/1.5.0/ReleaseNotes.html.
&lt;/li&gt;&lt;li&gt; Install icons in /usr/share/pixmaps.
&lt;/li&gt;&lt;li&gt; Install all desktop files in /usr/share/applications.&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Fri, 28 Mar 2008 08:15:31 +0000</pubDate>
  <dc:creator>Matthias Klose</dc:creator>
  <author>Matthias Klose</author>
</item>


<item>
  <title>openssh, 1:4.2p1-7ubuntu3.3</title>
  <guid>http://launchpad.net/distros/ubuntu/dapper/+source/openssh,/1:4.2p1-7ubuntu3.3</guid>
  <link>http://launchpad.net/distros/ubuntu/dapper/+source/openssh,/1:4.2p1-7ubuntu3.3</link>
  <description>&lt;b&gt;openssh (1:4.2p1-7ubuntu3.3)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; SECURITY UPDATE: X11 forward hijacking via alternate address families.
&lt;/li&gt;&lt;li&gt; channels.c: upstream fixes, patched inline.  Thanks to Nicolas Valcarcel
 (LP: #210175).
&lt;/li&gt;&lt;li&gt; References
 CVE-2008-1483&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Tue, 01 Apr 2008 22:55:30 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>mysql-dfsg-5.0, 5.0.22-0ubuntu6.06.9</title>
  <guid>http://launchpad.net/distros/ubuntu/dapper/+source/mysql-dfsg-5.0,/5.0.22-0ubuntu6.06.9</guid>
  <link>http://launchpad.net/distros/ubuntu/dapper/+source/mysql-dfsg-5.0,/5.0.22-0ubuntu6.06.9</link>
  <description>&lt;b&gt;mysql-dfsg-5.0 (5.0.22-0ubuntu6.06.9)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; Fix for upstream bug #20482: Creation of a view as a join of views or
 tables could fail if the views or tables are in different databases. This
 bug was introduced in the update for CVE-2007-2692, which had more
 restrictive privilege checks. (LP: #209699)&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Wed, 02 Apr 2008 19:56:02 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>cupsys, 1.2.2-0ubuntu0.6.06.8</title>
  <guid>http://launchpad.net/distros/ubuntu/dapper/+source/cupsys,/1.2.2-0ubuntu0.6.06.8</guid>
  <link>http://launchpad.net/distros/ubuntu/dapper/+source/cupsys,/1.2.2-0ubuntu0.6.06.8</link>
  <description>&lt;b&gt;cupsys (1.2.2-0ubuntu0.6.06.8)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; debian/patches/72_CVE-2008-0047.dpatch: Fix buffer overflow in
 cgiCompileSearch() using crafted search expressions. Exploitable if
 printer sharing is enabled. Thanks to Martin Pitt for supplying the patch.
&lt;/li&gt;&lt;li&gt; debian/patches/73_CVE-2008-0882.dpatch: Fix double-free in
 process_browse_data(), which could be exploited to a remote DoS by sending
 crafted data to the cups UDP port. Thanks to Martin Pitt for supplying the
 patch.
&lt;/li&gt;&lt;li&gt; debian/patches/74_pid.dpatch: Specify PidFile in temporary directory in
 the self test's cupsd.conf. This affects the test suite (in the sense that
 it actually works now) and does not affect the built binaries at all.
 (Backported from trunk). Thanks to Martin Pitt for supplying the patch.
&lt;/li&gt;&lt;li&gt; debian/patches/75_CVE-2008-0053.dpatch: Fix buffer overflows in
 ParseCommand() in hpgl-input.c by properly checking number of parameters
&lt;/li&gt;&lt;li&gt; debian/patches/76_CVE-2008-1373.dpatch: Fix buffer overflow in
 gif_read_image() in image-gif.c by properly validating code_size
&lt;/li&gt;&lt;li&gt; References
 CVE-2008-0047
 CVE-2008-0882
 CVE-2008-0053
 CVE-2008-1373
 http://www.cups.org/str.php?L2729
 http://www.cups.org/str.php?L2656&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Wed, 02 Apr 2008 21:55:36 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>ca-certificates 20050804-0ubuntu0.6.06</title>
  <guid>http://launchpad.net/distros/ubuntu/dapper/+source/ca-certificates/20050804-0ubuntu0.6.06</guid>
  <link>http://launchpad.net/distros/ubuntu/dapper/+source/ca-certificates/20050804-0ubuntu0.6.06</link>
  <description>&lt;b&gt;ca-certificates (20050804-0ubuntu0.6.06)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; Fix up generation of the /etc/ssl/certs/ca-certificates.crt
 file for those users who installed the package in a pt_BR
 locale (LP: #153625). A mistake in the translation template
 meant that the choices were not available in this locale,
 and so the file was always empty.
&lt;ul&gt;&lt;li&gt; If you were affected and have not tried to reconfigure this
 package, then the problem should be corrected for you
 automatically.
&lt;/li&gt;&lt;li&gt; If you were affected and have tried to reconfigure the package
 you may be shown a debconf question to allow you to select
 the certificates that you want.
&lt;/li&gt;&lt;li&gt; The only users who were not affected by this bug but may
 be affected by this fix are those who installed in a different
 locale, and then reconfigured the package so that no
 certificates are trusted, and who now run in a pt_BR locale.
 They will have to deselect all of the certificates again.&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Fri, 04 Apr 2008 11:44:08 +0000</pubDate>
  <dc:creator>James Westby</dc:creator>
  <author>James Westby</author>
</item>


<item>
  <title>cacti, 0.8.6h-1ubuntu3.3</title>
  <guid>http://launchpad.net/distros/ubuntu/dapper/+source/cacti,/0.8.6h-1ubuntu3.3</guid>
  <link>http://launchpad.net/distros/ubuntu/dapper/+source/cacti,/0.8.6h-1ubuntu3.3</link>
  <description>&lt;b&gt;cacti (0.8.6h-1ubuntu3.3)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; debian/patches/10_CVE-2008-0783_CVE-2008-0784_regression.dpatch: fix
 'Invalid PHP_SELF Path' regression (LP: #194687)&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Sat, 05 Apr 2008 13:55:21 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>opera 9.27-20080331.6dapper1</title>
  <guid>http://launchpad.net/distros/ubuntu/dapper/+source/opera/9.27-20080331.6dapper1</guid>
  <link>http://launchpad.net/distros/ubuntu/dapper/+source/opera/9.27-20080331.6dapper1</link>
  <description>&lt;b&gt;opera (9.27-20080331.6dapper1)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; New upstream release
&lt;/li&gt;&lt;li&gt; See http://www.opera.com/docs/changelogs/ for details&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Mon, 07 Apr 2008 21:20:23 +0000</pubDate>
  <dc:creator>Brian Thomason</dc:creator>
  <author>Brian Thomason</author>
</item>


<item>
  <title>update-manager-core 0.56~dapper5</title>
  <guid>http://launchpad.net/distros/ubuntu/dapper/+source/update-manager-core/0.56~dapper5</guid>
  <link>http://launchpad.net/distros/ubuntu/dapper/+source/update-manager-core/0.56~dapper5</link>
  <description>&lt;b&gt;update-manager-core (0.56~dapper5)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; fix fetch problem when a meta-release file already got
 downloaded (LP: #211978)&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Tue, 08 Apr 2008 09:36:19 +0000</pubDate>
  <dc:creator>Michael Vogt</dc:creator>
  <author>Michael Vogt</author>
</item>


<item>
  <title>gs-esp, 8.15.2.dfsg.0ubuntu1-0ubuntu1.1</title>
  <guid>http://launchpad.net/distros/ubuntu/dapper/+source/gs-esp,/8.15.2.dfsg.0ubuntu1-0ubuntu1.1</guid>
  <link>http://launchpad.net/distros/ubuntu/dapper/+source/gs-esp,/8.15.2.dfsg.0ubuntu1-0ubuntu1.1</link>
  <description>&lt;b&gt;gs-esp (8.15.2.dfsg.0ubuntu1-0ubuntu1.1)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; SECURITY UPDATE: buffer overflow in color space handling code
&lt;/li&gt;&lt;li&gt; debian/patches/05_CVE-2008-0411.dpatch: fix zseticcspace() to perform
 range checks
&lt;/li&gt;&lt;li&gt; References
 CVE-2008-0411&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Wed, 09 Apr 2008 18:55:58 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>gs-gpl, 8.15-4ubuntu3.1</title>
  <guid>http://launchpad.net/distros/ubuntu/dapper/+source/gs-gpl,/8.15-4ubuntu3.1</guid>
  <link>http://launchpad.net/distros/ubuntu/dapper/+source/gs-gpl,/8.15-4ubuntu3.1</link>
  <description>&lt;b&gt;gs-gpl (8.15-4ubuntu3.1)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; SECURITY UPDATE: buffer overflow in color space handling code
&lt;/li&gt;&lt;li&gt; debian/patches/23_CVE-2008-0411.dpatch: fix zseticcspace() to perform
 range checks
&lt;/li&gt;&lt;li&gt; References
 CVE-2008-0411&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Wed, 09 Apr 2008 18:56:40 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>squid, 2.5.12-4ubuntu2.4</title>
  <guid>http://launchpad.net/distros/ubuntu/dapper/+source/squid,/2.5.12-4ubuntu2.4</guid>
  <link>http://launchpad.net/distros/ubuntu/dapper/+source/squid,/2.5.12-4ubuntu2.4</link>
  <description>&lt;b&gt;squid (2.5.12-4ubuntu2.4)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; SECURITY UPDATE: off by one assertion could cause a denial of service
&lt;/li&gt;&lt;li&gt; debian/patches/SECURITY_CVE-2008-1612.dpatch: fix arrayShrink() in
 lib/Array.c to properly check a-&amp;gt;capacity&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Mon, 14 Apr 2008 14:55:33 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>mysql-dfsg-5.0 5.0.22-0ubuntu6.06.10</title>
  <guid>http://launchpad.net/distros/ubuntu/dapper/+source/mysql-dfsg-5.0/5.0.22-0ubuntu6.06.10</guid>
  <link>http://launchpad.net/distros/ubuntu/dapper/+source/mysql-dfsg-5.0/5.0.22-0ubuntu6.06.10</link>
  <description>&lt;b&gt;mysql-dfsg-5.0 (5.0.22-0ubuntu6.06.10)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; RELIABILITY UPDATE: fix for upstream bug #20908
&lt;/li&gt;&lt;li&gt; debian/patches/105_upstream_20908.dpatch: fix MYSQLlex() in sql_lex.cc
 to ABORT_SYM on zero-length variable names
&lt;/li&gt;&lt;li&gt; References
 LP: #217772
 http://bugs.mysql.com/bug.php?id=20908&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Wed, 16 Apr 2008 10:58:32 +0000</pubDate>
  <dc:creator>Jamie Strandboge</dc:creator>
  <author>Jamie Strandboge</author>
</item>


<item>
  <title>poppler, 0.5.1-0ubuntu7.4</title>
  <guid>http://launchpad.net/distros/ubuntu/dapper/+source/poppler,/0.5.1-0ubuntu7.4</guid>
  <link>http://launchpad.net/distros/ubuntu/dapper/+source/poppler,/0.5.1-0ubuntu7.4</link>
  <description>&lt;b&gt;poppler (0.5.1-0ubuntu7.4)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; SECURITY UPDATE: arbitrary code execution via malicious embedded fonts.&lt;/li&gt;&lt;li&gt; debian/patches/102_embedded-font-fixes.patch: upstream fix and stronger type-checking added.&lt;/li&gt;&lt;li&gt; References CVE-2008-1693&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Thu, 17 Apr 2008 15:55:24 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>koffice, 1:1.5.0-0ubuntu9.4</title>
  <guid>http://launchpad.net/distros/ubuntu/dapper/+source/koffice,/1:1.5.0-0ubuntu9.4</guid>
  <link>http://launchpad.net/distros/ubuntu/dapper/+source/koffice,/1:1.5.0-0ubuntu9.4</link>
  <description>&lt;b&gt;koffice (1:1.5.0-0ubuntu9.4)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; SECURITY UPDATE: arbitrary code execution via malicious embedded fonts.
&lt;/li&gt;&lt;li&gt; debian/patches/40_pdf2-embedded-font-fixes.diff: stronger type-checking
 added.
&lt;/li&gt;&lt;li&gt; References
 CVE-2008-1693&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Thu, 17 Apr 2008 15:58:30 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>gnumeric, 1.6.3-0ubuntu4.1</title>
  <guid>http://launchpad.net/distros/ubuntu/dapper/+source/gnumeric,/1.6.3-0ubuntu4.1</guid>
  <link>http://launchpad.net/distros/ubuntu/dapper/+source/gnumeric,/1.6.3-0ubuntu4.1</link>
  <description>&lt;b&gt;gnumeric (1.6.3-0ubuntu4.1)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; SECURITY UPDATE: arbitrary code execution via integer overflow in
 Excel spreadsheet HLINK processing.
&lt;/li&gt;&lt;li&gt; plugins/excel/ms-excel-read.c: backported upstream fixes thanks to
 Debian, with an additional bugfix.
&lt;/li&gt;&lt;li&gt; References
 CVE-2008-0668&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Tue, 22 Apr 2008 00:55:25 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>firefox, 1.5.dfsg+1.5.0.15~prepatch080417a-0ubuntu1</title>
  <guid>http://launchpad.net/distros/ubuntu/dapper/+source/firefox,/1.5.dfsg+1.5.0.15~prepatch080417a-0ubuntu1</guid>
  <link>http://launchpad.net/distros/ubuntu/dapper/+source/firefox,/1.5.dfsg+1.5.0.15~prepatch080417a-0ubuntu1</link>
  <description>&lt;b&gt;firefox (1.5.dfsg+1.5.0.15~prepatch080417a-0ubuntu1)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; release backports for security issues disclosed in 2.0.0.14
&lt;ul&gt;&lt;li&gt; see USN-602-1
&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt; patches on top of 1.8.0 branch cvs checkout (17 apr 08) are in
 patches/series&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Tue, 22 Apr 2008 00:59:28 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>ca-certificates 20050804-0ubuntu0.6.06.1</title>
  <guid>http://launchpad.net/distros/ubuntu/dapper/+source/ca-certificates/20050804-0ubuntu0.6.06.1</guid>
  <link>http://launchpad.net/distros/ubuntu/dapper/+source/ca-certificates/20050804-0ubuntu0.6.06.1</link>
  <description>&lt;b&gt;ca-certificates (20050804-0ubuntu0.6.06.1)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; Fix up generation of the /etc/ssl/certs/ca-certificates.crt
 file for those users who installed the package in a pt_BR
 locale (LP: #153625). A mistake in the translation template
 meant that the choices were not available in this locale,
 and so the file was always empty.
&lt;ul&gt;&lt;li&gt; If you were affected and have not tried to reconfigure this
 package, then the problem should be corrected for you
 automatically.
&lt;/li&gt;&lt;li&gt; If you were affected and have tried to reconfigure the package
 you may be shown a debconf question to allow you to select
 the certificates that you want.
&lt;/li&gt;&lt;li&gt; The only users who were not affected by this bug but may
 be affected by this fix are those who installed in a different
 locale, and then reconfigured the package so that no
 certificates are trusted, and who now run in a pt_BR locale.
 They will have to deselect all of the certificates again.
&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt; In addition to the previous version this version prevents the
 question being asked multiple times for those who appear to
 have been hit by this issue.&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Thu, 24 Apr 2008 09:53:13 +0000</pubDate>
  <dc:creator>James Westby</dc:creator>
  <author>James Westby</author>
</item>


<item>
  <title>xorg-server 1:1.0.2-0ubuntu10.11</title>
  <guid>http://launchpad.net/distros/ubuntu/dapper/+source/xorg-server/1:1.0.2-0ubuntu10.11</guid>
  <link>http://launchpad.net/distros/ubuntu/dapper/+source/xorg-server/1:1.0.2-0ubuntu10.11</link>
  <description>&lt;b&gt;xorg-server (1:1.0.2-0ubuntu10.11)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; xkb-and-loathing.dpatch:
 Ignore SIGALRM around calls to Popen()/Pclose() to fix a hang
 when opening menus in OpenOffice.org. (LP: #113679)&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Thu, 24 Apr 2008 13:18:16 +0000</pubDate>
  <dc:creator>Timo Aaltonen</dc:creator>
  <author>Timo Aaltonen</author>
</item>


<item>
  <title>cupsys, 1.2.2-0ubuntu0.6.06.9</title>
  <guid>http://launchpad.net/distros/ubuntu/dapper/+source/cupsys,/1.2.2-0ubuntu0.6.06.9</guid>
  <link>http://launchpad.net/distros/ubuntu/dapper/+source/cupsys,/1.2.2-0ubuntu0.6.06.9</link>
  <description>&lt;b&gt;cupsys (1.2.2-0ubuntu0.6.06.9)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; SECURITY UPDATE: Denial of service and possibly arbitrary code execution
&lt;/li&gt;&lt;li&gt; debian/patches/77_CVE-2008-1722.dpatch: fix for two integer overflows in
 filter/image-png.c. Taken from Debian SVN Head.
&lt;/li&gt;&lt;li&gt; References
 CVE-2008-1722
 LP: #219491
 http://www.cups.org/str.php?L2790&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Mon, 05 May 2008 11:55:32 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>mozilla-thunderbird, 1.5.0.13+1.5.0.15~prepatch080417a-0ubuntu0.6.06.1</title>
  <guid>http://launchpad.net/distros/ubuntu/dapper/+source/mozilla-thunderbird,/1.5.0.13+1.5.0.15~prepatch080417a-0ubuntu0.6.06.1</guid>
  <link>http://launchpad.net/distros/ubuntu/dapper/+source/mozilla-thunderbird,/1.5.0.13+1.5.0.15~prepatch080417a-0ubuntu0.6.06.1</link>
  <description>&lt;b&gt;mozilla-thunderbird (1.5.0.13+1.5.0.15~prepatch080417a-0ubuntu0.6.06.1)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; RELEASE security/stability backports for tbird 1.5 as of 2.0.0.14
 (USN-605-1)
&lt;ul&gt;&lt;li&gt; http://people.ubuntu.com/~asac/mozilla-security/1.8.1.14/moz_1.8.0.15prepatches080417a.tar.gz
&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt; drop patches applied upstream from debian/patches
&lt;ul&gt;&lt;li&gt; 0071_279505-attachment-297724-fix-396613-regression.dpatch&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Mon, 05 May 2008 11:56:51 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>xemacs21, 21.4.18-1ubuntu1.1</title>
  <guid>http://launchpad.net/distros/ubuntu/dapper/+source/xemacs21,/21.4.18-1ubuntu1.1</guid>
  <link>http://launchpad.net/distros/ubuntu/dapper/+source/xemacs21,/21.4.18-1ubuntu1.1</link>
  <description>&lt;b&gt;xemacs21 (21.4.18-1ubuntu1.1)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; SECURITY UPDATE: temporary file race condition in vcdiff
&lt;/li&gt;&lt;li&gt; debian/patches/21_vcdiff-tmp-race.dpatch: update lib-src/vcdiff to use
 mktemp
&lt;/li&gt;&lt;li&gt; References
 CVE-2008-1694&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Mon, 05 May 2008 17:56:19 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>emacs21, 21.4a-3ubuntu2.2</title>
  <guid>http://launchpad.net/distros/ubuntu/dapper/+source/emacs21,/21.4a-3ubuntu2.2</guid>
  <link>http://launchpad.net/distros/ubuntu/dapper/+source/emacs21,/21.4a-3ubuntu2.2</link>
  <description>&lt;b&gt;emacs21 (21.4a-3ubuntu2.2)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; SECURITY UPDATE: buffer overflow in format function
&lt;/li&gt;&lt;li&gt; debian/patches/fix-format-overflow.dpatch: fix src/editfns.c to account
 for precision in integer formatting (LP: #174177)
&lt;/li&gt;&lt;li&gt; SECURITY UPDATE: temporary file race condition in vcdiff
&lt;/li&gt;&lt;li&gt; debian/patches/vcdiff-tmp-race.dpatch: update lib-src/vcdiff to use
 mktemp
&lt;/li&gt;&lt;li&gt; References
 CVE-2007-6109
 CVE-2008-1694&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Mon, 05 May 2008 17:58:31 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>clamav, 0.92~dfsg-2~dapper1ubuntu0.2</title>
  <guid>http://launchpad.net/distros/ubuntu/dapper/+source/clamav,/0.92~dfsg-2~dapper1ubuntu0.2</guid>
  <link>http://launchpad.net/distros/ubuntu/dapper/+source/clamav,/0.92~dfsg-2~dapper1ubuntu0.2</link>
  <description>&lt;b&gt;clamav (0.92~dfsg-2~dapper1ubuntu0.2)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; SECURITY UPDATE: Possible heap corruption
&lt;/li&gt;&lt;li&gt; Added  28_mew.c.CVE-2008-0728.dpatch
&lt;/li&gt;&lt;li&gt; References: CVE-2008-0728 ( LP: #213500 )&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Mon, 05 May 2008 18:56:11 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>openldap2.2 2.2.26-5ubuntu2.7</title>
  <guid>http://launchpad.net/distros/ubuntu/dapper/+source/openldap2.2/2.2.26-5ubuntu2.7</guid>
  <link>http://launchpad.net/distros/ubuntu/dapper/+source/openldap2.2/2.2.26-5ubuntu2.7</link>
  <description>&lt;b&gt;openldap2.2 (2.2.26-5ubuntu2.7)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; The config scripts are run twice, this causes the password in
 slapd/internal/adminpw to be empty. This fixes the issue with having an
 empty password in the ldap database. Fixes: LP #66925.&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Tue, 06 May 2008 07:57:14 +0000</pubDate>
  <dc:creator>Mathias Gug</dc:creator>
  <author>Mathias Gug</author>
</item>


<item>
  <title>cyrus-sasl2 2.1.19.dfsg1-0.1ubuntu3</title>
  <guid>http://launchpad.net/distros/ubuntu/dapper/+source/cyrus-sasl2/2.1.19.dfsg1-0.1ubuntu3</guid>
  <link>http://launchpad.net/distros/ubuntu/dapper/+source/cyrus-sasl2/2.1.19.dfsg1-0.1ubuntu3</link>
  <description>&lt;b&gt;cyrus-sasl2 (2.1.19.dfsg1-0.1ubuntu3)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; debian/rules: configure with --with-devrandom=/dev/urandom to avoid
 hanging/blocking applications when entropy is exhausted. (LP: #225333)&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Tue, 06 May 2008 11:00:47 +0000</pubDate>
  <dc:creator>Andrew Pollock</dc:creator>
  <author>Andrew Pollock</author>
</item>


<item>
  <title>hsqldb, 1.8.0.2-1ubuntu1.1</title>
  <guid>http://launchpad.net/distros/ubuntu/dapper/+source/hsqldb,/1.8.0.2-1ubuntu1.1</guid>
  <link>http://launchpad.net/distros/ubuntu/dapper/+source/hsqldb,/1.8.0.2-1ubuntu1.1</link>
  <description>&lt;b&gt;hsqldb (1.8.0.2-1ubuntu1.1)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; SECURITY UPDATE: arbitrary Java methods via SQL.
&lt;/li&gt;&lt;li&gt; Add debian/patches/90_method-whitelist.patch: upstream changes backported.
&lt;/li&gt;&lt;li&gt; References
 CVE-2007-4575&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Tue, 06 May 2008 21:55:10 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>openoffice.org-amd64, 2.0.2-2ubuntu12.6-1</title>
  <guid>http://launchpad.net/distros/ubuntu/dapper/+source/openoffice.org-amd64,/2.0.2-2ubuntu12.6-1</guid>
  <link>http://launchpad.net/distros/ubuntu/dapper/+source/openoffice.org-amd64,/2.0.2-2ubuntu12.6-1</link>
  <description>&lt;b&gt;openoffice.org-amd64 (2.0.2-2ubuntu12.6-1)&lt;/b&gt;&lt;ul&gt;&lt;li&gt;&lt;b&gt; Chris Cheney &lt;/b&gt;
&lt;/li&gt;&lt;li&gt; ooo-build/patches/src680/workspace.fwk82.diff,
 ooo-build/patches/src680/workspace.sjfixes03.diff: fix CVE-2007-5745,
 CVE-2007-5746,CVE-2007-5747 and CVE-2008-0320
&lt;/li&gt;&lt;li&gt; ooo-build/patches/src680/cws-jl85.diff: fix XML signing problem where
 the document can be manipulated so that the signature dialog display a
 false issuer
&lt;/li&gt;&lt;li&gt;&lt;b&gt; Kees Cook &lt;/b&gt;
&lt;/li&gt;&lt;li&gt; ooo-build/patches/src680/workspace.hsql1808.diff: upstream fixes
 backported for HSQLDB Java method calling (CVE-2007-4575).&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Tue, 06 May 2008 21:56:01 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>openoffice.org, 2.0.2-2ubuntu12.6</title>
  <guid>http://launchpad.net/distros/ubuntu/dapper/+source/openoffice.org,/2.0.2-2ubuntu12.6</guid>
  <link>http://launchpad.net/distros/ubuntu/dapper/+source/openoffice.org,/2.0.2-2ubuntu12.6</link>
  <description>&lt;b&gt;openoffice.org (2.0.2-2ubuntu12.6)&lt;/b&gt;&lt;ul&gt;&lt;li&gt;&lt;b&gt; Chris Cheney &lt;/b&gt;
&lt;/li&gt;&lt;li&gt; ooo-build/patches/src680/workspace.fwk82.diff,
 ooo-build/patches/src680/workspace.sjfixes03.diff: fix CVE-2007-5745,
 CVE-2007-5746,CVE-2007-5747 and CVE-2008-0320
&lt;/li&gt;&lt;li&gt; ooo-build/patches/src680/cws-jl85.diff: fix XML signing problem where
 the document can be manipulated so that the signature dialog display a
 false issuer
&lt;/li&gt;&lt;li&gt;&lt;b&gt; Kees Cook &lt;/b&gt;
&lt;/li&gt;&lt;li&gt; ooo-build/patches/src680/workspace.hsql1808.diff: upstream fixes
 backported for HSQLDB Java method calling (CVE-2007-4575).&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Tue, 06 May 2008 21:57:49 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>ltsp, 0.87.1</title>
  <guid>http://launchpad.net/distros/ubuntu/dapper/+source/ltsp,/0.87.1</guid>
  <link>http://launchpad.net/distros/ubuntu/dapper/+source/ltsp,/0.87.1</link>
  <description>&lt;b&gt;ltsp (0.87.1)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; fix CVE-2008-1293 (LP: #227295) that made unauthenticated access to the
 local X server on the client possible.&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Tue, 06 May 2008 22:55:28 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>gzip 1.3.5-12ubuntu0.2</title>
  <guid>http://launchpad.net/distros/ubuntu/dapper/+source/gzip/1.3.5-12ubuntu0.2</guid>
  <link>http://launchpad.net/distros/ubuntu/dapper/+source/gzip/1.3.5-12ubuntu0.2</link>
  <description>&lt;b&gt;gzip (1.3.5-12ubuntu0.2)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; gzip.c: Remove the input file after successfully closing the output file.
 Before, copy_stat() removed the output file already, and close() was
 called afterwards. However, close() can fail on network file systems, and
 thus you would previously end up with a deleted input file and no output
 file. Patch backported from version 1.3.12-1 (applied in Edgy and later).
 (LP: #69510)&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Wed, 07 May 2008 06:52:16 +0000</pubDate>
  <dc:creator>Martin Pitt</dc:creator>
  <author>Martin Pitt</author>
</item>


<item>
  <title>speex, 1.1.11.1-1ubuntu0.3</title>
  <guid>http://launchpad.net/distros/ubuntu/dapper/+source/speex,/1.1.11.1-1ubuntu0.3</guid>
  <link>http://launchpad.net/distros/ubuntu/dapper/+source/speex,/1.1.11.1-1ubuntu0.3</link>
  <description>&lt;b&gt;speex (1.1.11.1-1ubuntu0.3)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; SECURITY UPDATE: array index vulnerability (LP: #218652)
&lt;/li&gt;&lt;li&gt; fix for libspeex/speex_header.c to properly validate its input
&lt;/li&gt;&lt;li&gt; References
 CVE-2008-1686&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Thu, 08 May 2008 17:55:16 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>vorbis-tools, 1.1.1-3ubuntu0.1</title>
  <guid>http://launchpad.net/distros/ubuntu/dapper/+source/vorbis-tools,/1.1.1-3ubuntu0.1</guid>
  <link>http://launchpad.net/distros/ubuntu/dapper/+source/vorbis-tools,/1.1.1-3ubuntu0.1</link>
  <description>&lt;b&gt;vorbis-tools (1.1.1-3ubuntu0.1)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; SECURITY UPDATE: array index vulnerability (LP: #218652)
&lt;/li&gt;&lt;li&gt; debian/patches/SECURITY_CVE-2008-1686.diff: fix for ogg123/speex_format.c
 to properly validate its input
&lt;/li&gt;&lt;li&gt; References
 CVE-2008-1686&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Thu, 08 May 2008 19:55:18 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>gst-plugins-good0.10, 0.10.3-0ubuntu4.1</title>
  <guid>http://launchpad.net/distros/ubuntu/dapper/+source/gst-plugins-good0.10,/0.10.3-0ubuntu4.1</guid>
  <link>http://launchpad.net/distros/ubuntu/dapper/+source/gst-plugins-good0.10,/0.10.3-0ubuntu4.1</link>
  <description>&lt;b&gt;gst-plugins-good0.10 (0.10.3-0ubuntu4.1)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; SECURITY UPDATE: array index vulnerability (LP: #218652)
&lt;/li&gt;&lt;li&gt; debian/patches/09_SECURITY_CVE-2008-1686.patch: fix for
 ext/speex/gstspeexdec.c to properly validate its input
&lt;/li&gt;&lt;li&gt; References
 CVE-2008-1686&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Thu, 08 May 2008 20:55:25 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>

  </channel>
</rss>
