<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="http://feeds.ubuntu-nl.org/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.ubuntu-nl.org/~d/styles/itemcontent.css"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0">
  <channel>
    <title>Feisty Changes</title>
    <link>http://lists.ubuntu.com/mailman/listinfo/feisty-changes</link>
    <language>en</language>
    
<atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" href="http://feeds.ubuntu-nl.org/FeistyChanges" type="application/rss+xml" /><feedburner:browserFriendly></feedburner:browserFriendly><item>
  <title>flashplugin-nonfree 9.0.48.0.0ubuntu1~7.04.3</title>
  <guid>http://launchpad.net/distros/ubuntu/feisty/+source/flashplugin-nonfree/9.0.48.0.0ubuntu1~7.04.3</guid>
  <link>http://launchpad.net/distros/ubuntu/feisty/+source/flashplugin-nonfree/9.0.48.0.0ubuntu1~7.04.3</link>
  <description>&lt;b&gt;flashplugin-nonfree (9.0.48.0.0ubuntu1~7.04.3)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; Update debian/config with new md5sums, stops install error when
 the old tar is still on the hard disk, LP: #173890&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Thu, 07 Feb 2008 18:05:51 +0000</pubDate>
  <dc:creator>Jonathan Riddell</dc:creator>
  <author>Jonathan Riddell</author>
</item>


<item>
  <title>firefox, 2.0.0.12+1nobinonly+2-0ubuntu0.7.4</title>
  <guid>http://launchpad.net/distros/ubuntu/feisty/+source/firefox,/2.0.0.12+1nobinonly+2-0ubuntu0.7.4</guid>
  <link>http://launchpad.net/distros/ubuntu/feisty/+source/firefox,/2.0.0.12+1nobinonly+2-0ubuntu0.7.4</link>
  <description>&lt;b&gt;firefox (2.0.0.12+1nobinonly+2-0ubuntu0.7.4)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; New stability upstream release (v2.0.0.12)
&lt;/li&gt;&lt;li&gt; New security/stability upstream release (v2.0.0.12) - 1.8.0.14 prepatches
&lt;/li&gt;&lt;li&gt; MFSA 2008-01 aka CVE-2008-0412: Crashes with evidence of memory corruption
 v1.8.1.12 (Browser crashes)
&lt;/li&gt;&lt;li&gt; MFSA 2008-01 aka CVE-2008-0413: Crashes with evidence of memory corruption
 v1.8.1.12 (javascript crashes)
&lt;/li&gt;&lt;li&gt; MFSA 2008-02 aka CVE-2008-0414: Multiple file input focus stealing
 vulnerabilities: 1. Focus shifting bugs and 2. Selective keystroke blocking
 bugs
&lt;/li&gt;&lt;li&gt; MFSA 2008-03 aka CVE-2008-0415: Privilege escalation, XSS, Remote Code
 Execution (JavaScript privilege escalation bugs)
&lt;/li&gt;&lt;li&gt; MFSA 2008-04 aka CVE-2008-0416: Multiple XSS vulnerabilities from
 character encoding
&lt;/li&gt;&lt;li&gt; MFSA 2008-05 aka CVE-2008-0417: Stored password corruption
&lt;/li&gt;&lt;li&gt; MFSA 2008-06 aka CVE-2008-0418: Directory traversal via chrome: URI
&lt;/li&gt;&lt;li&gt; MFSA 2008-07 aka CVE-2008-0419: Web browsing history and forward navigation
 stealing
&lt;/li&gt;&lt;li&gt; MFSA 2008-08 aka CVE-2008-0420: Possible information disclosure in BMP
 decoder
&lt;/li&gt;&lt;li&gt; MFSA 2008-09 aka CVE-2008-0591: File action dialog tampering
&lt;/li&gt;&lt;li&gt; MFSA 2008-10 aka CVE-2008-0592: Mishandling of locally-saved plain text
 files
&lt;/li&gt;&lt;li&gt; MFSA 2008-11 aka CVE-2008-0593: URL token stealing via stylesheet redirect
&lt;/li&gt;&lt;li&gt; MFSA 2008-12 aka CVE-2008-0594: Web forgery overwrite with div overlay&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Fri, 08 Feb 2008 01:04:55 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>linux-source-2.6.20, 2.6.20-16.35</title>
  <guid>http://launchpad.net/distros/ubuntu/feisty/+source/linux-source-2.6.20,/2.6.20-16.35</guid>
  <link>http://launchpad.net/distros/ubuntu/feisty/+source/linux-source-2.6.20,/2.6.20-16.35</link>
  <description>&lt;b&gt;linux-source-2.6.20 (2.6.20-16.35)&lt;/b&gt;&lt;ul&gt;&lt;li&gt;&lt;b&gt;Tim Gardner&lt;/b&gt;
&lt;/li&gt;&lt;li&gt; splice: fix user pointer access in get_iovec_page_array()
 (CVE-2008-0600)
&lt;ul&gt;&lt;li&gt; GIT-SHA 9ba4693de4d2e7da123589c3e592ea08eaf9e575&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Tue, 12 Feb 2008 14:00:40 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>dspam 3.6.8-4ubuntu1.1</title>
  <guid>http://launchpad.net/distros/ubuntu/feisty/+source/dspam/3.6.8-4ubuntu1.1</guid>
  <link>http://launchpad.net/distros/ubuntu/feisty/+source/dspam/3.6.8-4ubuntu1.1</link>
  <description>&lt;b&gt;dspam (3.6.8-4ubuntu1.1)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; debian/dspam.init: make sure directory for PIDFILE (/var/run/dspam) exists
 (LP: #158252)&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Tue, 12 Feb 2008 19:43:13 +0000</pubDate>
  <dc:creator>dAniel hAhler</dc:creator>
  <author>dAniel hAhler</author>
</item>


<item>
  <title>clamav, 0.90.2-0ubuntu1.6</title>
  <guid>http://launchpad.net/distros/ubuntu/feisty/+source/clamav,/0.90.2-0ubuntu1.6</guid>
  <link>http://launchpad.net/distros/ubuntu/feisty/+source/clamav,/0.90.2-0ubuntu1.6</link>
  <description>&lt;b&gt;clamav (0.90.2-0ubuntu1.6)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; Security UPDATE: (LP: #191150)
 libclamav/pe.c: possible integer overflow
 libclamav/others.c: tempfile symlink vulnerability
 Thanks to Stephen Gran &amp;lt;sgran@debian.org&amp;gt; for the patches
&lt;/li&gt;&lt;li&gt; References
 CVE-2008-0318
 CVE-2007-6595&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Wed, 13 Feb 2008 12:55:34 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>klavaro 1.0.1-1ubuntu1</title>
  <guid>http://launchpad.net/distros/ubuntu/feisty/+source/klavaro/1.0.1-1ubuntu1</guid>
  <link>http://launchpad.net/distros/ubuntu/feisty/+source/klavaro/1.0.1-1ubuntu1</link>
  <description>&lt;b&gt;klavaro (1.0.1-1ubuntu1)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; Applied upstream patch to fix a crash when fluidness test is completed using the French locale. (LP: #184112)&lt;/li&gt;&lt;li&gt; debian/control: set maintainer field as per spec.&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Wed, 13 Feb 2008 17:45:50 +0000</pubDate>
  <dc:creator>Jerome Guelfucci</dc:creator>
  <author>Jerome Guelfucci</author>
</item>


<item>
  <title>libcdio, 0.76-1ubuntu2.7.04.1</title>
  <guid>http://launchpad.net/distros/ubuntu/feisty/+source/libcdio,/0.76-1ubuntu2.7.04.1</guid>
  <link>http://launchpad.net/distros/ubuntu/feisty/+source/libcdio,/0.76-1ubuntu2.7.04.1</link>
  <description>&lt;b&gt;libcdio (0.76-1ubuntu2.7.04.1)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; SECURITY UPDATE:
&lt;ul&gt;&lt;li&gt; CVE-2007-6613: a stack-based buffer overflow in the
 print_iso9660_recurse function could lead to cause a denial of service
 or arbitrary code execution if the iso-info tool is used with a crafted
 iso image (LP: #191216)
&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt; References
&lt;ul&gt;&lt;li&gt; http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=459129&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Wed, 20 Feb 2008 14:55:58 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>tikiwiki,tikiwiki 1.9.7+dfsg-1ubuntu1.2</title>
  <guid>http://launchpad.net/distros/ubuntu/feisty/+source/tikiwiki,tikiwiki/1.9.7+dfsg-1ubuntu1.2</guid>
  <link>http://launchpad.net/distros/ubuntu/feisty/+source/tikiwiki,tikiwiki/1.9.7+dfsg-1ubuntu1.2</link>
  <description>&lt;b&gt;tikiwiki (1.9.7+dfsg-1ubuntu1.2)&lt;/b&gt;&lt;ul&gt;&lt;li&gt;&lt;b&gt; Emanuele Gentili &lt;/b&gt;
&lt;/li&gt;&lt;li&gt; SECURITY UPDATE: (LP: #180702)
&lt;ul&gt;&lt;li&gt; CVE 2007-6526: Cross-site scripting (XSS) vulnerability in tiki-special_chars.php
 in TikiWiki before 1.9.9 allows remote attackers to inject arbitrary web script or
 HTML via the area_name parameter.
&lt;/li&gt;&lt;li&gt; CVE 2007-6528: Directory traversal vulnerability in tiki-listmovies.php in TikiWiki
 before 1.9.9 allows remote attackers to read arbitrary files via a .. (dot dot) and
 modified filename in the movie parameter.
&lt;/li&gt;&lt;li&gt; CVE 2007-6529: Multiple unspecified vulnerabilities in TikiWiki before 1.9.9 have
 unknown impact and attack vectors involving  tiki-edit_css.php,
 tiki-g-admin_shared_source.php.
&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt; debian/patches/91_CVE-2007-6526_CVE-2007-6528_CVE-2007-6529.dpatch
&lt;ul&gt;&lt;li&gt; Applied patch by upstream
&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt; References
&lt;ul&gt;&lt;li&gt; CVE-2007-6526
&lt;/li&gt;&lt;li&gt; CVE-2007-6528
&lt;/li&gt;&lt;li&gt; CVE-2007-6529
&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt;&lt;b&gt; Jamie Strandboge &lt;/b&gt;
&lt;/li&gt;&lt;li&gt;  Use dash-compliant syntax in debian/rules&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Wed, 20 Feb 2008 17:55:19 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>pcre3, 7.4-0ubuntu0.7.04.2</title>
  <guid>http://launchpad.net/distros/ubuntu/feisty/+source/pcre3,/7.4-0ubuntu0.7.04.2</guid>
  <link>http://launchpad.net/distros/ubuntu/feisty/+source/pcre3,/7.4-0ubuntu0.7.04.2</link>
  <description>&lt;b&gt;pcre3 (7.4-0ubuntu0.7.04.2)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; SECURITY UPDATE: stack overflow when handling long UTF8 strings.
&lt;/li&gt;&lt;li&gt; pcre_compile.c, testdata/test{in,out}put4: upstream changes from 7.6
 backported, thanks to Tomas Hoger and Florian Weimer.
&lt;/li&gt;&lt;li&gt; References
 CVE-2008-0674&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Thu, 21 Feb 2008 18:55:51 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>cacti, 0.8.6i-3ubuntu0.2</title>
  <guid>http://launchpad.net/distros/ubuntu/feisty/+source/cacti,/0.8.6i-3ubuntu0.2</guid>
  <link>http://launchpad.net/distros/ubuntu/feisty/+source/cacti,/0.8.6i-3ubuntu0.2</link>
  <description>&lt;b&gt;cacti (0.8.6i-3ubuntu0.2)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; SECURITY UPDATE: (LP: #192199)
&lt;ul&gt;&lt;li&gt; CVE-2008-0783: Multiple cross-site scripting (XSS) vulnerabilities in
 Cacti 0.8.7 before 0.8.7b and 0.8.6 before 0.8.6k allow remote attackers to
 inject arbitrary web script or HTML via the (1) view_type parameter to
 graph.php, (2) filter parameter to graph_view.php, and (3) action and
 login_username parameters to index.php/login.
&lt;/li&gt;&lt;li&gt; CVE-2008-0784: graph.php in Cacti 0.8.7 before 0.8.7b and 0.8.6 before
 0.8.6k allows remote attackers to obtain the full path via an invalid
 local_graph_id parameter and other unspecified vectors.
&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt; debian/patches/11_CVE-2008-0783_CVE-2008-0784.dpatch: applied patch by
 upstream. (backported from 0.8.6j)
 (Link: http://www.cacti.net/downloads/patches/0.8.6j/multiple_vulnerabilities-0.8.6j.patch)
&lt;/li&gt;&lt;li&gt; References:
 CVE-2008-0783
 CVE-2008-0784&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Fri, 22 Feb 2008 02:55:31 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>lighttpd, 1.4.13-9ubuntu4.3</title>
  <guid>http://launchpad.net/distros/ubuntu/feisty/+source/lighttpd,/1.4.13-9ubuntu4.3</guid>
  <link>http://launchpad.net/distros/ubuntu/feisty/+source/lighttpd,/1.4.13-9ubuntu4.3</link>
  <description>&lt;b&gt;lighttpd (1.4.13-9ubuntu4.3)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; SECURITY UPDATE:
&lt;ul&gt;&lt;li&gt; debian/patches/90_maxfds_crash_fix.dpatch:
&lt;ul&gt;&lt;li&gt; added patch from upstream to fix the maxfds issue (LP: #195380)
&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt; References
&lt;ul&gt;&lt;li&gt;  http://trac.lighttpd.net/trac/ticket/1562&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Wed, 27 Feb 2008 14:55:33 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>lookup-el,lookup-el 1.4-4ubuntu0.7.04</title>
  <guid>http://launchpad.net/distros/ubuntu/feisty/+source/lookup-el,lookup-el/1.4-4ubuntu0.7.04</guid>
  <link>http://launchpad.net/distros/ubuntu/feisty/+source/lookup-el,lookup-el/1.4-4ubuntu0.7.04</link>
  <description>&lt;b&gt;lookup-el (1.4-4ubuntu0.7.04)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; SECURITY UPDATE:
&lt;ul&gt;&lt;li&gt; lisp/ndeb-binary.el: Make a temporary subdirectory securely. (LP: #176931)
&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt; References
&lt;ul&gt;&lt;li&gt; http://www.debian.org/security/2007/dsa-1269
&lt;/li&gt;&lt;li&gt; http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0237&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Wed, 27 Feb 2008 14:56:23 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>mozilla-thunderbird, 1.5.0.13+1.5.0.15~prepatch080227-0ubuntu0.7.04.0</title>
  <guid>http://launchpad.net/distros/ubuntu/feisty/+source/mozilla-thunderbird,/1.5.0.13+1.5.0.15~prepatch080227-0ubuntu0.7.04.0</guid>
  <link>http://launchpad.net/distros/ubuntu/feisty/+source/mozilla-thunderbird,/1.5.0.13+1.5.0.15~prepatch080227-0ubuntu0.7.04.0</link>
  <description>&lt;b&gt;mozilla-thunderbird (1.5.0.13+1.5.0.15~prepatch080227-0ubuntu0.7.04.0)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; USN-582-1 - release security backports for 1.8.0.12 (including previously
 not released firefox patches for 1.8.0.10/11)
&lt;/li&gt;&lt;li&gt; add distro version patch to indicate post-EOL maintainence release
&lt;ul&gt;&lt;li&gt; add debian/patches/98_ubuntu_eol_distro_version.dpatch
&lt;/li&gt;&lt;li&gt; update debian/patches/00list&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Fri, 29 Feb 2008 15:56:13 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>gnatsweb,gnatsweb 4.00-1ubuntu0.7.04</title>
  <guid>http://launchpad.net/distros/ubuntu/feisty/+source/gnatsweb,gnatsweb/4.00-1ubuntu0.7.04</guid>
  <link>http://launchpad.net/distros/ubuntu/feisty/+source/gnatsweb,gnatsweb/4.00-1ubuntu0.7.04</link>
  <description>&lt;b&gt;gnatsweb (4.00-1ubuntu0.7.04)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; SECURITY UPDATE:
&lt;/li&gt;&lt;li&gt; gnatsweb.pl (LP: #191196)
&lt;ul&gt;&lt;li&gt; Fixed missing escaping of the database parameter which leads
 to a cross-site scripting vulnerability (XSS) via this
 parameter (CVE-2007-2808).
&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt; debian/control
&lt;ul&gt;&lt;li&gt; Switch Maintainer to Ubuntu MOTU Developers
&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt; References:
&lt;/li&gt;&lt;li&gt; http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2808
&lt;/li&gt;&lt;li&gt; http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=427156&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Tue, 04 Mar 2008 18:55:27 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>evolution, 2.10.1-0ubuntu2.1</title>
  <guid>http://launchpad.net/distros/ubuntu/feisty/+source/evolution,/2.10.1-0ubuntu2.1</guid>
  <link>http://launchpad.net/distros/ubuntu/feisty/+source/evolution,/2.10.1-0ubuntu2.1</link>
  <description>&lt;b&gt;evolution (2.10.1-0ubuntu2.1)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; SECURITY UPDATE: code execution via format string in encrypted emails.
&lt;/li&gt;&lt;li&gt; Add 99_00_encryption_format_string_fix.patch: upstream fixes from
 Srinivasa Ragavan.
&lt;/li&gt;&lt;li&gt; References
 CVE-2008-0072&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Wed, 05 Mar 2008 18:55:37 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>openldap2.3, 2.3.30-2ubuntu0.2</title>
  <guid>http://launchpad.net/distros/ubuntu/feisty/+source/openldap2.3,/2.3.30-2ubuntu0.2</guid>
  <link>http://launchpad.net/distros/ubuntu/feisty/+source/openldap2.3,/2.3.30-2ubuntu0.2</link>
  <description>&lt;b&gt;openldap2.3 (2.3.30-2ubuntu0.2)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; SECURITY UPDATE: slapd crash when using the bdb backend and processing
 crafted modify and modrdn requests
&lt;/li&gt;&lt;li&gt; debian/patches/SECURITY_CVE-2007-6698+CVE-2008-0658.patch: patch to
 back-bdb/add.c, back-bdb/ctxcsn.c, back-bdb/delete.c, back-bdb/modify.c,
 back-bdb/modrdn.c to properly check for NOOP option
&lt;/li&gt;&lt;li&gt; References:
 CVE-2007-6698
 CVE-2008-0658
 LP: #197077&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Wed, 05 Mar 2008 20:55:49 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>tzdata 2007k-0ubuntu0.7.04.1</title>
  <guid>http://launchpad.net/distros/ubuntu/feisty/+source/tzdata/2007k-0ubuntu0.7.04.1</guid>
  <link>http://launchpad.net/distros/ubuntu/feisty/+source/tzdata/2007k-0ubuntu0.7.04.1</link>
  <description>&lt;b&gt;tzdata (2007k-0ubuntu0.7.04.1)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; Add debian/patches/chile-dst2008.patch: Update DST rules for Chile to
 incorporate short-term DST change for 2008 (delayed for three weeks from
 March 08 to March 29). (LP: #198129)&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Thu, 06 Mar 2008 10:33:00 +0000</pubDate>
  <dc:creator>Martin Pitt</dc:creator>
  <author>Martin Pitt</author>
</item>


<item>
  <title>mozilla-thunderbird, 1.5.0.13+1.5.0.15~prepatch080227-0ubuntu0.7.04.1</title>
  <guid>http://launchpad.net/distros/ubuntu/feisty/+source/mozilla-thunderbird,/1.5.0.13+1.5.0.15~prepatch080227-0ubuntu0.7.04.1</guid>
  <link>http://launchpad.net/distros/ubuntu/feisty/+source/mozilla-thunderbird,/1.5.0.13+1.5.0.15~prepatch080227-0ubuntu0.7.04.1</link>
  <description>&lt;b&gt;mozilla-thunderbird (1.5.0.13+1.5.0.15~prepatch080227-0ubuntu0.7.04.1)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; fix memory access regression (LP: #197504)
&lt;ul&gt;&lt;li&gt; add debian/patches/0071_279505-attachment-297724-(fix-396613-regression).dpatch
&lt;/li&gt;&lt;li&gt; update debian/patches/00list&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Thu, 06 Mar 2008 18:56:19 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>lighttpd, 1.4.13-9ubuntu4.4</title>
  <guid>http://launchpad.net/distros/ubuntu/feisty/+source/lighttpd,/1.4.13-9ubuntu4.4</guid>
  <link>http://launchpad.net/distros/ubuntu/feisty/+source/lighttpd,/1.4.13-9ubuntu4.4</link>
  <description>&lt;b&gt;lighttpd (1.4.13-9ubuntu4.4)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; SECURITY UPDATE:
&lt;/li&gt;&lt;li&gt; debian/patches/91_CVE-2008-1111.dpatch:
&lt;ul&gt;&lt;li&gt; Fixes CVE-2008-1111
 "mod_cgi in lighttpd 1.4.18, when a fork failure occurs, sends the
 source code of CGI scripts instead of a 500 error, which might allow
 remote attackers to obtain sensitive information." (LP: #198731)
&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt; References
&lt;/li&gt;&lt;li&gt; http://trac.lighttpd.net/trac/changeset/2107
&lt;/li&gt;&lt;li&gt; http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2008-1111&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Fri, 07 Mar 2008 18:55:46 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>python2.4, 2.4.4-2ubuntu7.1</title>
  <guid>http://launchpad.net/distros/ubuntu/feisty/+source/python2.4,/2.4.4-2ubuntu7.1</guid>
  <link>http://launchpad.net/distros/ubuntu/feisty/+source/python2.4,/2.4.4-2ubuntu7.1</link>
  <description>&lt;b&gt;python2.4 (2.4.4-2ubuntu7.1)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; SECURITY UPDATE: code execution via integer overflows.
&lt;/li&gt;&lt;li&gt; debian/rules, debian/patches/CVE-2007-4965-int-overflow.dpatch: upstream
 changes, thanks to Stephan Hermann.
&lt;/li&gt;&lt;li&gt; References
 http://bugs.python.org/file8592/python-2.5.CVE-2007-4965-int-overflow.patch
 CVE-2007-4965&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Mon, 10 Mar 2008 21:55:53 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>python2.5, 2.5.1-0ubuntu1.1</title>
  <guid>http://launchpad.net/distros/ubuntu/feisty/+source/python2.5,/2.5.1-0ubuntu1.1</guid>
  <link>http://launchpad.net/distros/ubuntu/feisty/+source/python2.5,/2.5.1-0ubuntu1.1</link>
  <description>&lt;b&gt;python2.5 (2.5.1-0ubuntu1.1)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; SECURITY UPDATE: code execution via integer overflows
&lt;/li&gt;&lt;li&gt; debian/rules, debian/patches/CVE-2007-4965-int-overflow.dpatch: upstream
 changes, thanks to Stephan Hermann.
&lt;/li&gt;&lt;li&gt; References
 http://bugs.python.org/file8592/python-2.5.CVE-2007-4965-int-overflow.patch
 CVE-2007-4965&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Mon, 10 Mar 2008 21:57:34 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>lighttpd, 1.4.13-9ubuntu4.5</title>
  <guid>http://launchpad.net/distros/ubuntu/feisty/+source/lighttpd,/1.4.13-9ubuntu4.5</guid>
  <link>http://launchpad.net/distros/ubuntu/feisty/+source/lighttpd,/1.4.13-9ubuntu4.5</link>
  <description>&lt;b&gt;lighttpd (1.4.13-9ubuntu4.5)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; SECURITY UPDATE: (LP: #200987)
&lt;/li&gt;&lt;li&gt; debian/patches/91_CVE-2008-1270.dpatch
&lt;ul&gt;&lt;li&gt; mod_userdir in lighttpd 1.4.18 and earlier, when userdir.path is not set,
 uses a default of $HOME, which might allow remote attackers to read arbitrary
 files, as demonstrated by accessing the ~nobody directory.
&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt; References
&lt;/li&gt;&lt;li&gt; http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-1270
&lt;/li&gt;&lt;li&gt; http://trac.lighttpd.net/trac/ticket/1587
&lt;/li&gt;&lt;li&gt; http://trac.lighttpd.net/trac/changeset/2120&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Tue, 11 Mar 2008 19:55:30 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>mysql-dfsg-5.0 5.0.38-0ubuntu1.3</title>
  <guid>http://launchpad.net/distros/ubuntu/feisty/+source/mysql-dfsg-5.0/5.0.38-0ubuntu1.3</guid>
  <link>http://launchpad.net/distros/ubuntu/feisty/+source/mysql-dfsg-5.0/5.0.38-0ubuntu1.3</link>
  <description>&lt;b&gt;mysql-dfsg-5.0 (5.0.38-0ubuntu1.3)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; SECURITY UPDATE: buffer overflow via ProcessOldClientHello() in
 handshake.cpp and input_buffer&amp;amp; operator&amp;gt;&amp;gt; in yassl_imp.cpp
&lt;/li&gt;&lt;li&gt; SECURITY UPDATE: buffer overread in HASHwithTransform::Update in hash.cpp
&lt;/li&gt;&lt;li&gt; debian/patches/97_SECURITY_CVE-2008-0226_0227.dpatch: properly verify
 length of input (LP: #186978).
&lt;/li&gt;&lt;li&gt; SECURITY UPDATE: privilege escalation via crafted CREATE SQL SECURITY
 DEFINER VIEW and ALTER VIEW statements
&lt;/li&gt;&lt;li&gt; debian/patches/98_SECURITY_CVE-2007-6303.dpatch: make sure lex-&amp;gt;definer
 is non-NULL in sql_view.cc (LP: #185039)
&lt;/li&gt;&lt;li&gt; debian/patches/99_view_fix-now.dpatch: update view.test and view.result to
 use a static year instead of now(). These tests are not part of the build
 but helps with qa-regression-testing
&lt;/li&gt;&lt;li&gt; SECURITY UPDATE: privilege escalation via SQL SECURITY INVOKER stored
 routines
&lt;/li&gt;&lt;li&gt; debian/patches/100_SECURITY_CVE-2007-2692.dpatch: restore THD::db_access
 when returning from stored routine by performing privilege checks in the
 execution stage rather than the parsing stage. (LP: #172260)
&lt;/li&gt;&lt;li&gt; References
 CVE-2008-0226
 CVE-2008-0227
 CVE-2007-6303
 CVE-2007-2692
 http://bugs.mysql.com/bug.php?id=27337&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Wed, 12 Mar 2008 08:10:59 +0000</pubDate>
  <dc:creator>Jamie Strandboge</dc:creator>
  <author>Jamie Strandboge</author>
</item>


<item>
  <title>tzdata 2008a-0ubuntu0.7.04</title>
  <guid>http://launchpad.net/distros/ubuntu/feisty/+source/tzdata/2008a-0ubuntu0.7.04</guid>
  <link>http://launchpad.net/distros/ubuntu/feisty/+source/tzdata/2008a-0ubuntu0.7.04</link>
  <description>&lt;b&gt;tzdata (2008a-0ubuntu0.7.04)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; Replace tzdata2007k.tar.gz with new version tzdata2008a:
&lt;ul&gt;&lt;li&gt; Fixes Chile DST properly, our patch switched it on a day too early.
&lt;/li&gt;&lt;li&gt; Drop debian/patches/chile-dst2008.patch.
&lt;/li&gt;&lt;li&gt; LP: #198129&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Wed, 12 Mar 2008 09:22:43 +0000</pubDate>
  <dc:creator>Martin Pitt</dc:creator>
  <author>Martin Pitt</author>
</item>


<item>
  <title>vlc, 0.8.6.release-0ubuntu4.1</title>
  <guid>http://launchpad.net/distros/ubuntu/feisty/+source/vlc,/0.8.6.release-0ubuntu4.1</guid>
  <link>http://launchpad.net/distros/ubuntu/feisty/+source/vlc,/0.8.6.release-0ubuntu4.1</link>
  <description>&lt;b&gt;vlc (0.8.6.release-0ubuntu4.1)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; SECURITY UPDATE:
&lt;ul&gt;&lt;li&gt; debian/patches/031_CVE-2008-0984.diff (LP: #195949)
&lt;/li&gt;&lt;li&gt; VLC media player's MPEG-4 file format parser (a.k.a. the MP4 demuxer)
&lt;ul&gt;&lt;li&gt;suffers from an arbitrary memory overwrite vulnerability when using
&lt;/li&gt;&lt;li&gt;crash the player instance.
&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt; References
&lt;ul&gt;&lt;li&gt; http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0984
&lt;/li&gt;&lt;li&gt; http://www.videolan.org/security/sa0802.html&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Wed, 12 Mar 2008 17:56:40 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>mailman, 1:2.1.9-4ubuntu1.1</title>
  <guid>http://launchpad.net/distros/ubuntu/feisty/+source/mailman,/1:2.1.9-4ubuntu1.1</guid>
  <link>http://launchpad.net/distros/ubuntu/feisty/+source/mailman,/1:2.1.9-4ubuntu1.1</link>
  <description>&lt;b&gt;mailman (1:2.1.9-4ubuntu1.1)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; debian/control:
&lt;/li&gt;&lt;li&gt; updated maintainer field
&lt;/li&gt;&lt;li&gt; SECURITY UPDATE:
&lt;/li&gt;&lt;li&gt; debian/patches/100_CVE-2008-0564.dpatch (LP: #199338)
&lt;ul&gt;&lt;li&gt; Multiple cross-site scripting (XSS) vulnerabilities in Mailman
 before 2.1.10b1 allow remote attackers to inject arbitrary web
 script or HTML via unspecified vectors related to (1) editing
 templates and (2) the list's "info attribute" in the web
 administrator interface.
&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt; References
&lt;/li&gt;&lt;li&gt; http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0564
&lt;/li&gt;&lt;li&gt; http://bugs.gentoo.org/show_bug.cgi?id=208710&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Fri, 14 Mar 2008 18:55:57 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>wml, 2.0.11-1ubuntu0.1</title>
  <guid>http://launchpad.net/distros/ubuntu/feisty/+source/wml,/2.0.11-1ubuntu0.1</guid>
  <link>http://launchpad.net/distros/ubuntu/feisty/+source/wml,/2.0.11-1ubuntu0.1</link>
  <description>&lt;b&gt;wml (2.0.11-1ubuntu0.1)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; debian/control
&lt;/li&gt;&lt;li&gt; updated maintainer field
&lt;/li&gt;&lt;li&gt; SECURITY UPDATE: (LP: #191205)
&lt;/li&gt;&lt;li&gt; wml_backend/p1_ipp/ipp.src (CVE-2008-0665)
&lt;ul&gt;&lt;li&gt; in Website META Language (WML) 2.0.11 allows local
 users to overwrite arbitrary files via a symlink attack on the ipp.$$.tmp
 temporary file.
&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt; wlm_backend/p3_eperl/eperl_sys.c wml_contrib/wmg.cgi (CVE-2008-0666)
&lt;ul&gt;&lt;li&gt; Website META Language (WML) 2.0.11 allows local users to overwrite arbitrary
 files via a symlink attack on (1) the /tmp/pe.tmp.$$ temporary file used by
 wml_contrib/wmg.cgi and (2) temporary files used by
 wml_backend/p3_eperl/eperl_sys.c.
&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt; References
&lt;/li&gt;&lt;li&gt; http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2008-0665
&lt;/li&gt;&lt;li&gt; http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2008-0666
&lt;/li&gt;&lt;li&gt; http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=463907&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Fri, 14 Mar 2008 20:55:43 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>phpmyadmin, 4:2.9.1.1-2ubuntu1.2</title>
  <guid>http://launchpad.net/distros/ubuntu/feisty/+source/phpmyadmin,/4:2.9.1.1-2ubuntu1.2</guid>
  <link>http://launchpad.net/distros/ubuntu/feisty/+source/phpmyadmin,/4:2.9.1.1-2ubuntu1.2</link>
  <description>&lt;b&gt;phpmyadmin (4:2.9.1.1-2ubuntu1.2)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; SECURITY UPDATE:
&lt;/li&gt;&lt;li&gt; debian/patches/050_CVE-2008-1149.dpatch
&lt;ul&gt;&lt;li&gt; Provides unauthorized access, Allows partial confidentiality, integrity, and
 availability violation , Allows unauthorized disclosure of information ,
 Allows disruption of service. (LP: #198745)
&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt; References:
&lt;/li&gt;&lt;li&gt; http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-1149
&lt;/li&gt;&lt;li&gt; http://www.phpmyadmin.net/home_page/security.php?issue=PMASA-2008-1&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Fri, 14 Mar 2008 20:55:33 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>python-cherrypy, 2.2.1-3ubuntu1.7.04</title>
  <guid>http://launchpad.net/distros/ubuntu/feisty/+source/python-cherrypy,/2.2.1-3ubuntu1.7.04</guid>
  <link>http://launchpad.net/distros/ubuntu/feisty/+source/python-cherrypy,/2.2.1-3ubuntu1.7.04</link>
  <description>&lt;b&gt;python-cherrypy (2.2.1-3ubuntu1.7.04)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; SECURITY UPDATE: directory traversal via session cookie ID.
&lt;ul&gt;&lt;li&gt; debian/patches/10_CVE-2008-0252.diff: Add. Ensure that the path
 generated from the session ID is within the session directory. Patch
 from upstream SVN. (LP: #187481)
&lt;/li&gt;&lt;li&gt; References:
&lt;ul&gt;&lt;li&gt; CVE-2008-0252&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Fri, 14 Mar 2008 20:56:39 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>mailman, 1:2.1.9-4ubuntu1.2</title>
  <guid>http://launchpad.net/distros/ubuntu/feisty/+source/mailman,/1:2.1.9-4ubuntu1.2</guid>
  <link>http://launchpad.net/distros/ubuntu/feisty/+source/mailman,/1:2.1.9-4ubuntu1.2</link>
  <description>&lt;b&gt;mailman (1:2.1.9-4ubuntu1.2)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; debian/patches/100_CVE-2008-0564.dpatch: Readd erroneously removed code
 line which caused the code to become invalid and the package to not be
 installable. (LP: #202332)&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Sat, 15 Mar 2008 16:55:21 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>postgresql-8.2 8.2.7-0ubuntu0.7.04</title>
  <guid>http://launchpad.net/distros/ubuntu/feisty/+source/postgresql-8.2/8.2.7-0ubuntu0.7.04</guid>
  <link>http://launchpad.net/distros/ubuntu/feisty/+source/postgresql-8.2/8.2.7-0ubuntu0.7.04</link>
  <description>&lt;b&gt;postgresql-8.2 (8.2.7-0ubuntu0.7.04)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; New upstream bug fix release: (LP: #203734)
&lt;ul&gt;&lt;li&gt; Repair potential deadlock between concurrent "VACUUM FULL"
 operations on different system catalogs.
&lt;/li&gt;&lt;li&gt; Fix longstanding "LISTEN"/"NOTIFY" race condition.
&lt;/li&gt;&lt;li&gt; Disallow "LISTEN" and "UNLISTEN" within a prepared transaction.
 This was formerly allowed but trying to do it had various
 unpleasant consequences, notably that the originating backend could
 not exit as long as an "UNLISTEN" remained uncommitted.
&lt;/li&gt;&lt;li&gt; Disallow dropping a temporary table within a prepared transaction
 This was correctly disallowed by 8.1, but the check was
 inadvertently broken in 8.2.
&lt;/li&gt;&lt;li&gt; Fix rare crash when an error occurs during a query using a hash
 index.
&lt;/li&gt;&lt;li&gt; Fix memory leaks in certain usages of set-returning functions.
&lt;/li&gt;&lt;li&gt; Fix input of datetime values for February 29 in years BC.
&lt;/li&gt;&lt;li&gt; Fix "unrecognized node type" error in some variants of "ALTER
 OWNER".
&lt;/li&gt;&lt;li&gt; Ensure pg_stat_activity.waiting flag is cleared when a lock wait is
 aborted.
&lt;/li&gt;&lt;li&gt; Fix pg_ctl to correctly extract the postmaster's port number from
 command-line options. (See Debian #358546)
&lt;/li&gt;&lt;li&gt; Use "-fwrapv" to defend against possible misoptimization in recent
 gcc versions.
&lt;/li&gt;&lt;li&gt; Correctly enforce statement_timeout values longer than INT_MAX
 microseconds (about 35 minutes).
&lt;/li&gt;&lt;li&gt; Fix "unexpected PARAM_SUBLINK ID" planner error when
 constant-folding simplifies a sub-select.
&lt;/li&gt;&lt;li&gt; Fix logical errors in constraint-exclusion handling of IS NULL and
 NOT expressions.
&lt;/li&gt;&lt;li&gt; Fix another cause of "failed to build any N-way joins" planner
 errors.
&lt;/li&gt;&lt;li&gt; Fix incorrect constant propagation in outer-join planning.
&lt;/li&gt;&lt;li&gt; Fix display of constant expressions in ORDER BY and GROUP BY.
&lt;/li&gt;&lt;li&gt; Fix libpq to handle NOTICE messages correctly during COPY OUT.
&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt; Remove debian/patches/00upstream-clauseless-joins-regression.patch,
 upstream now.&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Tue, 18 Mar 2008 23:06:47 +0000</pubDate>
  <dc:creator>Martin Pitt</dc:creator>
  <author>Martin Pitt</author>
</item>


<item>
  <title>krb5, 1.4.4-5ubuntu3.4</title>
  <guid>http://launchpad.net/distros/ubuntu/feisty/+source/krb5,/1.4.4-5ubuntu3.4</guid>
  <link>http://launchpad.net/distros/ubuntu/feisty/+source/krb5,/1.4.4-5ubuntu3.4</link>
  <description>&lt;b&gt;krb5 (1.4.4-5ubuntu3.4)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; SECURITY UPDATE: arbitrary code execution via freed pointer and memory
 overflows.
&lt;/li&gt;&lt;li&gt; src/kdc/{kerberos_v4,dispatch,network}.c: backported upstream fixes
 patched inline (MITKRB5-SA-2008-001: CVE-2008-0062, CVE-2008-0063).
&lt;/li&gt;&lt;li&gt; src/lib/rpc/{svc,svc_tcp}.c: upstream fixed patched inline
 (MITKRB5-SA-2008-002: CVE-2008-0947)&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Tue, 18 Mar 2008 23:56:28 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>mysql-dfsg-5.0, 5.0.38-0ubuntu1.4</title>
  <guid>http://launchpad.net/distros/ubuntu/feisty/+source/mysql-dfsg-5.0,/5.0.38-0ubuntu1.4</guid>
  <link>http://launchpad.net/distros/ubuntu/feisty/+source/mysql-dfsg-5.0,/5.0.38-0ubuntu1.4</link>
  <description>&lt;b&gt;mysql-dfsg-5.0 (5.0.38-0ubuntu1.4)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; no change build for -security upload
&lt;/li&gt;&lt;/ul&gt;&lt;b&gt;mysql-dfsg-5.0 (5.0.38-0ubuntu1.3)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; SECURITY UPDATE: buffer overflow via ProcessOldClientHello() in
 handshake.cpp and input_buffer&amp;amp; operator&amp;gt;&amp;gt; in yassl_imp.cpp
&lt;/li&gt;&lt;li&gt; SECURITY UPDATE: buffer overread in HASHwithTransform::Update in hash.cpp
&lt;/li&gt;&lt;li&gt; debian/patches/97_SECURITY_CVE-2008-0226_0227.dpatch: properly verify
 length of input (LP: #186978).
&lt;/li&gt;&lt;li&gt; SECURITY UPDATE: privilege escalation via crafted CREATE SQL SECURITY
 DEFINER VIEW and ALTER VIEW statements
&lt;/li&gt;&lt;li&gt; debian/patches/98_SECURITY_CVE-2007-6303.dpatch: make sure lex-&amp;gt;definer
 is non-NULL in sql_view.cc (LP: #185039)
&lt;/li&gt;&lt;li&gt; debian/patches/99_view_fix-now.dpatch: update view.test and view.result to
 use a static year instead of now(). These tests are not part of the build
 but helps with qa-regression-testing
&lt;/li&gt;&lt;li&gt; SECURITY UPDATE: privilege escalation via SQL SECURITY INVOKER stored
 routines
&lt;/li&gt;&lt;li&gt; debian/patches/100_SECURITY_CVE-2007-2692.dpatch: restore THD::db_access
 when returning from stored routine by performing privilege checks in the
 execution stage rather than the parsing stage. (LP: #172260)
&lt;/li&gt;&lt;li&gt; References
 CVE-2008-0226
 CVE-2008-0227
 CVE-2007-6303
 CVE-2007-2692
 http://bugs.mysql.com/bug.php?id=27337&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Thu, 20 Mar 2008 10:56:54 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>unzip, 5.52-9ubuntu3.1</title>
  <guid>http://launchpad.net/distros/ubuntu/feisty/+source/unzip,/5.52-9ubuntu3.1</guid>
  <link>http://launchpad.net/distros/ubuntu/feisty/+source/unzip,/5.52-9ubuntu3.1</link>
  <description>&lt;b&gt;unzip (5.52-9ubuntu3.1)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; SECURITY UPDATE: arbitrary code execution via heap corruption.
&lt;/li&gt;&lt;li&gt; inflate.c: fix invalid free() calls, patch from Tavis Ormandy.
&lt;/li&gt;&lt;li&gt; References
 CVE-2008-0888&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Thu, 20 Mar 2008 17:56:00 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>smarty,smarty 2.6.14-1ubuntu0.7.04.1</title>
  <guid>http://launchpad.net/distros/ubuntu/feisty/+source/smarty,smarty/2.6.14-1ubuntu0.7.04.1</guid>
  <link>http://launchpad.net/distros/ubuntu/feisty/+source/smarty,smarty/2.6.14-1ubuntu0.7.04.1</link>
  <description>&lt;b&gt;smarty (2.6.14-1ubuntu0.7.04.1)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; SECURITY UPDATE: (LP: #202422)
&lt;/li&gt;&lt;li&gt; libs/plugins/modifier.regex_replace.php
&lt;ul&gt;&lt;li&gt; The modifier.regex_replace.php plugin in Smarty before 2.6.19, as used
 by Serendipity (S9Y) and other products, allows attackers to call arbitrary
 PHP functions via templates, related to a '\0' character in a search string.
&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt; References
&lt;/li&gt;&lt;li&gt; http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1066
&lt;/li&gt;&lt;li&gt; http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=469492&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Mon, 24 Mar 2008 12:55:42 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>mplayer, 2:1.0~rc1-0ubuntu9.3</title>
  <guid>http://launchpad.net/distros/ubuntu/feisty/+source/mplayer,/2:1.0~rc1-0ubuntu9.3</guid>
  <link>http://launchpad.net/distros/ubuntu/feisty/+source/mplayer,/2:1.0~rc1-0ubuntu9.3</link>
  <description>&lt;b&gt;mplayer (2:1.0~rc1-0ubuntu9.3)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; SECURITY UPDATE: buffer overruns in RMMF, CDDB, MOV demuxer, FLAC header
 parser, and URL parser. (LP: #191488)
&lt;/li&gt;&lt;li&gt; stream/librtsp/rtsp_session.c, stream/realrtsp/rmff.c,
 stream/realrtsp/rmff.h, libmpdemux/demux_audio.c, libmpdemux/demux_mov.c,
 stream/stream_cddb.c, stream/url.c: Patches from upstream.
&lt;/li&gt;&lt;li&gt; References:
&lt;ul&gt;&lt;li&gt; CVE-2008-0225
&lt;/li&gt;&lt;li&gt; CVE-2008-0238
&lt;/li&gt;&lt;li&gt; CVE-2008-0485
&lt;/li&gt;&lt;li&gt; CVE-2008-0486
&lt;/li&gt;&lt;li&gt; CVE-2008-0629
&lt;/li&gt;&lt;li&gt; CVE-2008-0630&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Mon, 24 Mar 2008 15:56:27 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>bzip2, 1.0.3-6ubuntu0.1</title>
  <guid>http://launchpad.net/distros/ubuntu/feisty/+source/bzip2,/1.0.3-6ubuntu0.1</guid>
  <link>http://launchpad.net/distros/ubuntu/feisty/+source/bzip2,/1.0.3-6ubuntu0.1</link>
  <description>&lt;b&gt;bzip2 (1.0.3-6ubuntu0.1)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; SECURITY UPDATE: denial of service via heap memory corruption.
&lt;/li&gt;&lt;li&gt; bzlib.c, bzlib_private.h: upstream patch from 1.0.5 applied inline.
&lt;/li&gt;&lt;li&gt; References
 CVE-2008-1372&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Mon, 24 Mar 2008 17:55:49 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>icu, 3.6-2ubuntu0.1</title>
  <guid>http://launchpad.net/distros/ubuntu/feisty/+source/icu,/3.6-2ubuntu0.1</guid>
  <link>http://launchpad.net/distros/ubuntu/feisty/+source/icu,/3.6-2ubuntu0.1</link>
  <description>&lt;b&gt;icu (3.6-2ubuntu0.1)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; SECURITY UPDATE: possible read from and write to out of bounds memory
 locations via back reference '\0' in regular expressions
&lt;/li&gt;&lt;li&gt; SECURITY UPDATE: denial of service due to memory exhaustion via a
 crafted regular expression
&lt;/li&gt;&lt;li&gt; debian/patches/SECURITY_CVE-2007-4770_4771.patch: fix regexcmp.cpp to
 return error on invalid back reference. fix rematch.cpp, uvectr32.h and
 uvectr32.cpp to return error when capacity is greater than maxCapacity
&lt;/li&gt;&lt;li&gt; References
 CVE-2007-4770
 CVE-2007-4771
&lt;/li&gt;&lt;li&gt; Modify Maintainer value to match the DebianMaintainerField
 specification.&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Mon, 24 Mar 2008 17:57:04 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>dspam, 3.6.8-4ubuntu1.2</title>
  <guid>http://launchpad.net/distros/ubuntu/feisty/+source/dspam,/3.6.8-4ubuntu1.2</guid>
  <link>http://launchpad.net/distros/ubuntu/feisty/+source/dspam,/3.6.8-4ubuntu1.2</link>
  <description>&lt;b&gt;dspam (3.6.8-4ubuntu1.2)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; SECURITY UPDATE: The libdspam7-drv-mysql cron job includes the MySQL
 dspam database password in a command line argument, which might allow
 local users to read the password by listing the process and its arguments.
&lt;/li&gt;&lt;li&gt; debian/libdspam7-drv-mysql.cron.daily: applied patch from Debian to use a
 password file instead.
&lt;/li&gt;&lt;li&gt; References
&lt;ul&gt;&lt;li&gt; LP: #195691
&lt;/li&gt;&lt;li&gt; CVE-2007-6418&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Wed, 26 Mar 2008 03:56:09 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>firefox, 2.0.0.13+0nobinonly-0ubuntu0.7.4</title>
  <guid>http://launchpad.net/distros/ubuntu/feisty/+source/firefox,/2.0.0.13+0nobinonly-0ubuntu0.7.4</guid>
  <link>http://launchpad.net/distros/ubuntu/feisty/+source/firefox,/2.0.0.13+0nobinonly-0ubuntu0.7.4</link>
  <description>&lt;b&gt;firefox (2.0.0.13+0nobinonly-0ubuntu0.7.4)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; New security/stability upstream release (v2.0.0.13)
&lt;ul&gt;&lt;li&gt; see USN-592-1&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Wed, 26 Mar 2008 13:02:31 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>libnet-dns-perl, 0.59-1ubuntu0.2</title>
  <guid>http://launchpad.net/distros/ubuntu/feisty/+source/libnet-dns-perl,/0.59-1ubuntu0.2</guid>
  <link>http://launchpad.net/distros/ubuntu/feisty/+source/libnet-dns-perl,/0.59-1ubuntu0.2</link>
  <description>&lt;b&gt;libnet-dns-perl (0.59-1ubuntu0.2)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; SECURITY UPDATE:
&lt;/li&gt;&lt;li&gt; debian/patches/42_CVE-2007-6341.dpatch (LP: #201454)
&lt;ul&gt;&lt;li&gt; used in packages such as SpamAssassin and OTRS, allows remote
 attackers to cause a denial of service (program "croak") via a
 crafted DNS response.
&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt; References
&lt;/li&gt;&lt;li&gt; http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6341
&lt;/li&gt;&lt;li&gt; http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=457445&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Wed, 26 Mar 2008 17:56:28 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>dovecot, 1.0.rc17-1ubuntu2.3</title>
  <guid>http://launchpad.net/distros/ubuntu/feisty/+source/dovecot,/1.0.rc17-1ubuntu2.3</guid>
  <link>http://launchpad.net/distros/ubuntu/feisty/+source/dovecot,/1.0.rc17-1ubuntu2.3</link>
  <description>&lt;b&gt;dovecot (1.0.rc17-1ubuntu2.3)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; SECURITY UPDATE: mailboxes of other users could be read via symlinks.
&lt;/li&gt;&lt;li&gt; Add upstream-mail-group-fixes.dpatch: upstream fixes (CVE-2008-1199).
&lt;/li&gt;&lt;li&gt; Add upstream-invalid-password-fixes.dpatch: proactive upstream fixes
 to avoid future issues in underlying passdb (CVE-2008-1218).
&lt;/li&gt;&lt;li&gt; References
 http://dovecot.org/list/dovecot-news/2008-March/000060.html
 http://dovecot.org/list/dovecot-news/2008-March/000064.html&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Wed, 26 Mar 2008 17:55:51 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>sdl-image1.2, 1.2.5-2ubuntu0.7.04.1</title>
  <guid>http://launchpad.net/distros/ubuntu/feisty/+source/sdl-image1.2,/1.2.5-2ubuntu0.7.04.1</guid>
  <link>http://launchpad.net/distros/ubuntu/feisty/+source/sdl-image1.2,/1.2.5-2ubuntu0.7.04.1</link>
  <description>&lt;b&gt;sdl-image1.2 (1.2.5-2ubuntu0.7.04.1)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; SECURITY UPDATE: Buffer overflow in GIF handling; possible
 denial of service and arbitrary code execution.
&lt;/li&gt;&lt;li&gt; SECURITY UPDATE: Buffer overflow in IFF ILBM  handling; possible
 denial of service and arbitrary code execution.
&lt;/li&gt;&lt;li&gt; Added patches to prevent buffer overflow in IMG_gif.c and IMG_lbm.c.
 Patches prepared from sdl-image1.2_1.2.5-2etch1 update in debian.
 Applied inline. (LP: #185782)
&lt;/li&gt;&lt;li&gt; References:
 http://www.debian.org/security/2008/dsa-1493
 CVE-2007-6697 and CVE-2008-0544&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Wed, 26 Mar 2008 18:55:41 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>ruby1.8, 1.8.5-4ubuntu2.1</title>
  <guid>http://launchpad.net/distros/ubuntu/feisty/+source/ruby1.8,/1.8.5-4ubuntu2.1</guid>
  <link>http://launchpad.net/distros/ubuntu/feisty/+source/ruby1.8,/1.8.5-4ubuntu2.1</link>
  <description>&lt;b&gt;ruby1.8 (1.8.5-4ubuntu2.1)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; SECURITY UPDATE: SSL connections did not check commonName early
 enough, possibly allowing sensitive information to be exposed.
&lt;/li&gt;&lt;li&gt; debian/patches/950_CVE-2007-5162.patch: upstream fixes, from
 http://svn.ruby-lang.org/cgi-bin/viewvc.cgi?view=rev&amp;amp;revision=13499
&lt;/li&gt;&lt;li&gt; debian/patches/951_CVE-2007-5770.patch: upstream fixes, from
 http://svn.ruby-lang.org/cgi-bin/viewvc.cgi?view=rev&amp;amp;revision=13656
&lt;/li&gt;&lt;li&gt; References:
 CVE-2007-5162 CVE-2007-5770 (LP: #149616)&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Wed, 26 Mar 2008 18:56:49 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>horde3, 3.1.3-4ubuntu0.1</title>
  <guid>http://launchpad.net/distros/ubuntu/feisty/+source/horde3,/3.1.3-4ubuntu0.1</guid>
  <link>http://launchpad.net/distros/ubuntu/feisty/+source/horde3,/3.1.3-4ubuntu0.1</link>
  <description>&lt;b&gt;horde3 (3.1.3-4ubuntu0.1)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; SECURITY UPDATE: (LP: #203456)
&lt;/li&gt;&lt;li&gt; Directory traversal vulnerability in Horde 3.1.6, Groupware before 1.0.5,
&lt;ul&gt;&lt;li&gt;and Groupware Webmail Edition before 1.0.6, when running with certain
&lt;/li&gt;&lt;li&gt;configurations, allows remote authenticated users to read and execute arbitrary
&lt;/li&gt;&lt;li&gt;files via ".." sequences and a null byte in the theme name.
&lt;/li&gt;&lt;li&gt;Fix directory traversal vulnerability in Registry.php which allows
&lt;/li&gt;&lt;li&gt;an attacker to read and execute arbitrary local files via crafted
&lt;/li&gt;&lt;li&gt;path sequences.
&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt; References
&lt;/li&gt;&lt;li&gt; http://ftp.horde.org/pub/horde/patches/patch-horde-3.1.6-3.1.7.gz
&lt;/li&gt;&lt;li&gt; http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2008-1284
&lt;/li&gt;&lt;li&gt; http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=470640
&lt;/li&gt;&lt;li&gt; http://www.debian.org/security/2008/dsa-1519&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Thu, 27 Mar 2008 16:55:39 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>dspam, 3.6.8-4ubuntu1.3</title>
  <guid>http://launchpad.net/distros/ubuntu/feisty/+source/dspam,/3.6.8-4ubuntu1.3</guid>
  <link>http://launchpad.net/distros/ubuntu/feisty/+source/dspam,/3.6.8-4ubuntu1.3</link>
  <description>&lt;b&gt;dspam (3.6.8-4ubuntu1.3)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; debian/libdspam7-drv-mysql.cron.daily:
 Fix bashism introduced in previous security update (s/echo -e/printf/)
 (LP: #207579)&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Fri, 28 Mar 2008 00:55:48 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>openssh, 1:4.3p2-8ubuntu1.2</title>
  <guid>http://launchpad.net/distros/ubuntu/feisty/+source/openssh,/1:4.3p2-8ubuntu1.2</guid>
  <link>http://launchpad.net/distros/ubuntu/feisty/+source/openssh,/1:4.3p2-8ubuntu1.2</link>
  <description>&lt;b&gt;openssh (1:4.3p2-8ubuntu1.2)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; SECURITY UPDATE: X11 forward hijacking via alternate address families.
&lt;/li&gt;&lt;li&gt; channels.c: upstream fixes, patched inline.  Thanks to Nicolas Valcarcel
 (LP: #210175).
&lt;/li&gt;&lt;li&gt; References
 CVE-2008-1483&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Tue, 01 Apr 2008 22:55:53 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>cupsys, 1.2.8-0ubuntu8.3</title>
  <guid>http://launchpad.net/distros/ubuntu/feisty/+source/cupsys,/1.2.8-0ubuntu8.3</guid>
  <link>http://launchpad.net/distros/ubuntu/feisty/+source/cupsys,/1.2.8-0ubuntu8.3</link>
  <description>&lt;b&gt;cupsys (1.2.8-0ubuntu8.3)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; debian/patches/99_CVE-2008-0047.dpatch: Fix buffer overflow in
 cgiCompileSearch() using crafted search expressions. Exploitable if
 printer sharing is enabled. Thanks to Martin Pitt for supplying the patch.
&lt;/li&gt;&lt;li&gt; debian/patches/100_CVE-2008-0882.dpatch: Fix double-free in
 process_browse_data(), which could be exploited to a remote DoS by sending
 crafted data to the cups UDP port. Thanks to Martin Pitt for supplying the
 patch.
&lt;/li&gt;&lt;li&gt; debian/patches/101_pid.dpatch: Specify PidFile in temporary directory in
 the self test's cupsd.conf. This affects the test suite (in the sense that
 it actually works now) and does not affect the built binaries at all.
 (Backported from trunk). Thanks to Martin Pitt for supplying the patch.
&lt;/li&gt;&lt;li&gt; debian/patches/102_CVE-2008-0053.dpatch: Fix buffer overflows in
 ParseCommand() in hpgl-input.c by properly checking number of parameters
&lt;/li&gt;&lt;li&gt; debian/patches/103_CVE-2008-1373.dpatch: Fix buffer overflow in
 gif_read_image() in image-gif.c by properly validating code_size
&lt;/li&gt;&lt;li&gt; References
 CVE-2008-0047
 CVE-2008-0882
 CVE-2008-0053
 CVE-2008-1373
 http://www.cups.org/str.php?L2729
 http://www.cups.org/str.php?L2656&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Wed, 02 Apr 2008 21:56:10 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>ca-certificates 20061027-0ubuntu0.1</title>
  <guid>http://launchpad.net/distros/ubuntu/feisty/+source/ca-certificates/20061027-0ubuntu0.1</guid>
  <link>http://launchpad.net/distros/ubuntu/feisty/+source/ca-certificates/20061027-0ubuntu0.1</link>
  <description>&lt;b&gt;ca-certificates (20061027-0ubuntu0.1)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; Fix up generation of the /etc/ssl/certs/ca-certificates.crt
 file for those users who installed the package in a pt_BR
 locale (LP: #153625). A mistake in the translation template
 meant that the choices were not available in this locale,
 and so the file was always empty.
&lt;ul&gt;&lt;li&gt; If you were affected and have not tried to reconfigure this
 package, then the problem should be corrected for you
 automatically.
&lt;/li&gt;&lt;li&gt; If you were affected and have tried to reconfigure the package
 you may be shown a debconf question to allow you to select
 the certificates that you want.
&lt;/li&gt;&lt;li&gt; The only users who were not affected by this bug but may
 be affected by this fix are those who installed in a different
 locale, and then reconfigured the package so that no
 certificates are trusted, and who now run in a pt_BR locale.
 They will have to deselect all of the certificates again.&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Fri, 04 Apr 2008 12:14:52 +0000</pubDate>
  <dc:creator>James Westby</dc:creator>
  <author>James Westby</author>
</item>


<item>
  <title>cacti, 0.8.6i-3ubuntu0.3</title>
  <guid>http://launchpad.net/distros/ubuntu/feisty/+source/cacti,/0.8.6i-3ubuntu0.3</guid>
  <link>http://launchpad.net/distros/ubuntu/feisty/+source/cacti,/0.8.6i-3ubuntu0.3</link>
  <description>&lt;b&gt;cacti (0.8.6i-3ubuntu0.3)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; debian/patches/11_CVE-2008-0783_CVE-2008-0784_regression.dpatch: fix
 'Invalid PHP_SELF Path' regression (LP: #194687)&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Sat, 05 Apr 2008 13:55:38 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>opera 9.27-20080331.6fesity1</title>
  <guid>http://launchpad.net/distros/ubuntu/feisty/+source/opera/9.27-20080331.6fesity1</guid>
  <link>http://launchpad.net/distros/ubuntu/feisty/+source/opera/9.27-20080331.6fesity1</link>
  <description>&lt;b&gt;opera (9.27-20080331.6fesity1)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; New upstream release
&lt;/li&gt;&lt;li&gt; See http://www.opera.com/docs/changelogs/ for details&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Mon, 07 Apr 2008 20:30:20 +0000</pubDate>
  <dc:creator>Brian Thomason</dc:creator>
  <author>Brian Thomason</author>
</item>


<item>
  <title>gs-esp, 8.15.4.dfsg.1-0ubuntu1.1</title>
  <guid>http://launchpad.net/distros/ubuntu/feisty/+source/gs-esp,/8.15.4.dfsg.1-0ubuntu1.1</guid>
  <link>http://launchpad.net/distros/ubuntu/feisty/+source/gs-esp,/8.15.4.dfsg.1-0ubuntu1.1</link>
  <description>&lt;b&gt;gs-esp (8.15.4.dfsg.1-0ubuntu1.1)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; SECURITY UPDATE: buffer overflow in color space handling code
&lt;/li&gt;&lt;li&gt; debian/patches/08_CVE-2008-0411.dpatch: fix zseticcspace() to perform
 range checks
&lt;/li&gt;&lt;li&gt; References
 CVE-2008-0411&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Wed, 09 Apr 2008 18:56:28 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>gs-gpl, 8.54.dfsg.1-5ubuntu0.2</title>
  <guid>http://launchpad.net/distros/ubuntu/feisty/+source/gs-gpl,/8.54.dfsg.1-5ubuntu0.2</guid>
  <link>http://launchpad.net/distros/ubuntu/feisty/+source/gs-gpl,/8.54.dfsg.1-5ubuntu0.2</link>
  <description>&lt;b&gt;gs-gpl (8.54.dfsg.1-5ubuntu0.2)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; SECURITY UPDATE: buffer overflow in color space handling code
&lt;/li&gt;&lt;li&gt; debian/patches/41_CVE-2008-0411.dpatch: fix zseticcspace() to perform
 range checks
&lt;/li&gt;&lt;li&gt; References
 CVE-2008-0411&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Wed, 09 Apr 2008 18:57:04 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>rsync, 2.6.9-3ubuntu1.2</title>
  <guid>http://launchpad.net/distros/ubuntu/feisty/+source/rsync,/2.6.9-3ubuntu1.2</guid>
  <link>http://launchpad.net/distros/ubuntu/feisty/+source/rsync,/2.6.9-3ubuntu1.2</link>
  <description>&lt;b&gt;rsync (2.6.9-3ubuntu1.2)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; SECURITY UPDATE: code execution via ACL overflow.
&lt;/li&gt;&lt;li&gt; debian/patches/xattr-security.diff: upstream fixes for ACL/xattr,
 thanks to Debian.
&lt;/li&gt;&lt;li&gt; References
 CVE-2008-1720&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Fri, 11 Apr 2008 05:55:17 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>squid, 2.6.5-4ubuntu2.2</title>
  <guid>http://launchpad.net/distros/ubuntu/feisty/+source/squid,/2.6.5-4ubuntu2.2</guid>
  <link>http://launchpad.net/distros/ubuntu/feisty/+source/squid,/2.6.5-4ubuntu2.2</link>
  <description>&lt;b&gt;squid (2.6.5-4ubuntu2.2)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; SECURITY UPDATE: off by one assertion could cause a denial of service
&lt;/li&gt;&lt;li&gt; debian/patches/SECURITY_CVE-2008-1612.dpatch: fix arrayShrink() in
 lib/Array.c to properly check a-&amp;gt;capacity&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Mon, 14 Apr 2008 14:56:15 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>libapache2-mod-python 3.2.10-3ubuntu1.1</title>
  <guid>http://launchpad.net/distros/ubuntu/feisty/+source/libapache2-mod-python/3.2.10-3ubuntu1.1</guid>
  <link>http://launchpad.net/distros/ubuntu/feisty/+source/libapache2-mod-python/3.2.10-3ubuntu1.1</link>
  <description>&lt;b&gt;libapache2-mod-python (3.2.10-3ubuntu1.1)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; Rebuild for the final python 2.5.1 release. LP: #107149.
&lt;/li&gt;&lt;li&gt; Fix a memory lleak. LP: #132520.&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Wed, 16 Apr 2008 11:05:40 +0000</pubDate>
  <dc:creator>Matthias Klose</dc:creator>
  <author>Matthias Klose</author>
</item>


<item>
  <title>lighttpd, 1.4.13-9ubuntu4.6</title>
  <guid>http://launchpad.net/distros/ubuntu/feisty/+source/lighttpd,/1.4.13-9ubuntu4.6</guid>
  <link>http://launchpad.net/distros/ubuntu/feisty/+source/lighttpd,/1.4.13-9ubuntu4.6</link>
  <description>&lt;b&gt;lighttpd (1.4.13-9ubuntu4.6)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; SECURITY UPDATE: (LP: #209627)
&lt;/li&gt;&lt;li&gt; debian/patches/91_CVE-2008-1531.dpatch
&lt;ul&gt;&lt;li&gt; lighttpd 1.4.19 and earlier allows remote attackers to cause a denial
 of service (active SSL connection loss) by triggering an SSL error,
 such as disconnecting before a download has finished, which causes
 all active SSL connections to be lost.
&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt; References
&lt;/li&gt;&lt;li&gt; http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-1531
&lt;/li&gt;&lt;li&gt; http://trac.lighttpd.net/trac/changeset/2136
&lt;/li&gt;&lt;li&gt; http://trac.lighttpd.net/trac/changeset/2139&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Thu, 17 Apr 2008 13:55:22 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>poppler, 0.5.4-0ubuntu8.3</title>
  <guid>http://launchpad.net/distros/ubuntu/feisty/+source/poppler,/0.5.4-0ubuntu8.3</guid>
  <link>http://launchpad.net/distros/ubuntu/feisty/+source/poppler,/0.5.4-0ubuntu8.3</link>
  <description>&lt;b&gt;poppler (0.5.4-0ubuntu8.3)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; SECURITY UPDATE: arbitrary code execution via malicious embedded fonts.&lt;/li&gt;&lt;li&gt; debian/patches/102_embedded-font-fixes.patch: upstream fix and stronger type-checking added.&lt;/li&gt;&lt;li&gt; References CVE-2008-1693&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Thu, 17 Apr 2008 15:55:57 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>koffice, 1:1.6.2-0ubuntu1.3</title>
  <guid>http://launchpad.net/distros/ubuntu/feisty/+source/koffice,/1:1.6.2-0ubuntu1.3</guid>
  <link>http://launchpad.net/distros/ubuntu/feisty/+source/koffice,/1:1.6.2-0ubuntu1.3</link>
  <description>&lt;b&gt;koffice (1:1.6.2-0ubuntu1.3)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; SECURITY UPDATE: arbitrary code execution via malicious embedded fonts.
&lt;/li&gt;&lt;li&gt; debian/patches/40_pdf2-embedded-font-fixes.diff: stronger type-checking
 added.
&lt;/li&gt;&lt;li&gt; References
 CVE-2008-1693&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Thu, 17 Apr 2008 16:02:06 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>gnumeric, 1.7.8-0ubuntu1.1</title>
  <guid>http://launchpad.net/distros/ubuntu/feisty/+source/gnumeric,/1.7.8-0ubuntu1.1</guid>
  <link>http://launchpad.net/distros/ubuntu/feisty/+source/gnumeric,/1.7.8-0ubuntu1.1</link>
  <description>&lt;b&gt;gnumeric (1.7.8-0ubuntu1.1)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; SECURITY UPDATE: arbitrary code execution via integer overflow in
 Excel spreadsheet HLINK processing.
&lt;/li&gt;&lt;li&gt; plugins/excel/ms-excel-read.c: backported upstream fixes thanks to
 Debian, with an additional bugfix.
&lt;/li&gt;&lt;li&gt; References
 CVE-2008-0668&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Tue, 22 Apr 2008 00:56:22 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>firefox, 2.0.0.14+1nobinonly-0ubuntu0.7.4</title>
  <guid>http://launchpad.net/distros/ubuntu/feisty/+source/firefox,/2.0.0.14+1nobinonly-0ubuntu0.7.4</guid>
  <link>http://launchpad.net/distros/ubuntu/feisty/+source/firefox,/2.0.0.14+1nobinonly-0ubuntu0.7.4</link>
  <description>&lt;b&gt;firefox (2.0.0.14+1nobinonly-0ubuntu0.7.4)&lt;/b&gt;&lt;ul&gt;&lt;li&gt;&lt;b&gt; Alexander Sack &lt;/b&gt;
&lt;/li&gt;&lt;li&gt; New security/stability upstream release (v2.0.0.14)
&lt;ul&gt;&lt;li&gt; see USN-602-1&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Tue, 22 Apr 2008 01:05:23 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>ca-certificates 20061027-0ubuntu0.2</title>
  <guid>http://launchpad.net/distros/ubuntu/feisty/+source/ca-certificates/20061027-0ubuntu0.2</guid>
  <link>http://launchpad.net/distros/ubuntu/feisty/+source/ca-certificates/20061027-0ubuntu0.2</link>
  <description>&lt;b&gt;ca-certificates (20061027-0ubuntu0.2)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; Fix up generation of the /etc/ssl/certs/ca-certificates.crt
 file for those users who installed the package in a pt_BR
 locale (LP: #153625). A mistake in the translation template
 meant that the choices were not available in this locale,
 and so the file was always empty.
&lt;ul&gt;&lt;li&gt; If you were affected and have not tried to reconfigure this
 package, then the problem should be corrected for you
 automatically.
&lt;/li&gt;&lt;li&gt; If you were affected and have tried to reconfigure the package
 you may be shown a debconf question to allow you to select
 the certificates that you want.
&lt;/li&gt;&lt;li&gt; The only users who were not affected by this bug but may
 be affected by this fix are those who installed in a different
 locale, and then reconfigured the package so that no
 certificates are trusted, and who now run in a pt_BR locale.
 They will have to deselect all of the certificates again.
&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt; In addition to the previous version this version prevents the
 question being asked multiple times for those who appear to
 have been hit by this issue.&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Thu, 24 Apr 2008 09:53:43 +0000</pubDate>
  <dc:creator>James Westby</dc:creator>
  <author>James Westby</author>
</item>


<item>
  <title>cupsys, 1.2.8-0ubuntu8.4</title>
  <guid>http://launchpad.net/distros/ubuntu/feisty/+source/cupsys,/1.2.8-0ubuntu8.4</guid>
  <link>http://launchpad.net/distros/ubuntu/feisty/+source/cupsys,/1.2.8-0ubuntu8.4</link>
  <description>&lt;b&gt;cupsys (1.2.8-0ubuntu8.4)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; SECURITY UPDATE: Denial of service and possibly arbitrary code execution
&lt;/li&gt;&lt;li&gt; debian/patches/104_CVE-2008-1722.dpatch: fix for two integer overflows in
 filter/image-png.c. Taken from Debian SVN Head.
&lt;/li&gt;&lt;li&gt; References
 CVE-2008-1722
 LP: #219491
 http://www.cups.org/str.php?L2790&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Mon, 05 May 2008 11:55:56 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>xemacs21, 21.4.19-2ubuntu0.1</title>
  <guid>http://launchpad.net/distros/ubuntu/feisty/+source/xemacs21,/21.4.19-2ubuntu0.1</guid>
  <link>http://launchpad.net/distros/ubuntu/feisty/+source/xemacs21,/21.4.19-2ubuntu0.1</link>
  <description>&lt;b&gt;xemacs21 (21.4.19-2ubuntu0.1)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; SECURITY UPDATE: temporary file race condition in vcdiff
&lt;/li&gt;&lt;li&gt; debian/patches/21_vcdiff-tmp-race.dpatch: update lib-src/vcdiff to use
 mktemp
&lt;/li&gt;&lt;li&gt; References
 CVE-2008-1694&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Mon, 05 May 2008 17:56:41 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>emacs21, 21.4a+1-2ubuntu1.2</title>
  <guid>http://launchpad.net/distros/ubuntu/feisty/+source/emacs21,/21.4a+1-2ubuntu1.2</guid>
  <link>http://launchpad.net/distros/ubuntu/feisty/+source/emacs21,/21.4a+1-2ubuntu1.2</link>
  <description>&lt;b&gt;emacs21 (21.4a+1-2ubuntu1.2)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; SECURITY UPDATE: buffer overflow in format function
&lt;/li&gt;&lt;li&gt; debian/patches/fix-format-overflow.diff: fix src/editfns.c to account
 for precision in integer formatting (LP: #174177)
&lt;/li&gt;&lt;li&gt; SECURITY UPDATE: temporary file race condition in vcdiff
&lt;/li&gt;&lt;li&gt; debian/patches/vcdiff-tmp-race.diff: update lib-src/vcdiff to use
 mktemp
&lt;/li&gt;&lt;li&gt; References
 CVE-2007-6109
 CVE-2008-1694&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Mon, 05 May 2008 17:57:41 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>clamav, 0.90.2-0ubuntu1.7</title>
  <guid>http://launchpad.net/distros/ubuntu/feisty/+source/clamav,/0.90.2-0ubuntu1.7</guid>
  <link>http://launchpad.net/distros/ubuntu/feisty/+source/clamav,/0.90.2-0ubuntu1.7</link>
  <description>&lt;b&gt;clamav (0.90.2-0ubuntu1.7)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; SECURITY UPDATE: Possible heap corruption
&lt;/li&gt;&lt;li&gt; Added 60_cve-2008-0728.dpatch
&lt;/li&gt;&lt;li&gt; References: CVE-2008-0728 ( LP: #213500 )&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Mon, 05 May 2008 18:55:31 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>kdelibs, 4:3.5.6-0ubuntu14.3</title>
  <guid>http://launchpad.net/distros/ubuntu/feisty/+source/kdelibs,/4:3.5.6-0ubuntu14.3</guid>
  <link>http://launchpad.net/distros/ubuntu/feisty/+source/kdelibs,/4:3.5.6-0ubuntu14.3</link>
  <description>&lt;b&gt;kdelibs (4:3.5.6-0ubuntu14.3)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; SECURITY UPDATE: integer overflow in start_kdeinit. The start_kdeinit
 processing of user-influenceable input is faulty.  A local user
 might be able to send unix signals to other processes, cause
 a denial of service or even possibly execute arbitrary code.
&lt;/li&gt;&lt;li&gt; Add kubuntu_9903_kinit_integer_overflow.diff, edits
 kinit/start_kdeinit.c, patch from upstream KDE
&lt;/li&gt;&lt;li&gt; References
 http://www.kde.org/info/security/advisory-20080426-2.txt
 CVE-2008-1671&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Mon, 05 May 2008 18:57:04 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>mozilla-thunderbird, 1.5.0.13+1.5.0.15~prepatch080417a-0ubuntu0.7.04.1</title>
  <guid>http://launchpad.net/distros/ubuntu/feisty/+source/mozilla-thunderbird,/1.5.0.13+1.5.0.15~prepatch080417a-0ubuntu0.7.04.1</guid>
  <link>http://launchpad.net/distros/ubuntu/feisty/+source/mozilla-thunderbird,/1.5.0.13+1.5.0.15~prepatch080417a-0ubuntu0.7.04.1</link>
  <description>&lt;b&gt;mozilla-thunderbird (1.5.0.13+1.5.0.15~prepatch080417a-0ubuntu0.7.04.1)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; RELEASE security/stability backports for tbird 1.5 as of 2.0.0.14
 (USN-605-1)
&lt;ul&gt;&lt;li&gt; http://people.ubuntu.com/~asac/mozilla-security/1.8.1.14/moz_1.8.0.15prepatches080417a.tar.gz
&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt; drop patches applied upstream from debian/patches
&lt;ul&gt;&lt;li&gt; 0071_279505-attachment-297724-fix-396613-regression.dpatch&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Tue, 06 May 2008 15:55:33 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>kde4libs, 3.80.3-0ubuntu4.1</title>
  <guid>http://launchpad.net/distros/ubuntu/feisty/+source/kde4libs,/3.80.3-0ubuntu4.1</guid>
  <link>http://launchpad.net/distros/ubuntu/feisty/+source/kde4libs,/3.80.3-0ubuntu4.1</link>
  <description>&lt;b&gt;kde4libs (3.80.3-0ubuntu4.1)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; SECURITY UPDATE: KHTML's PNG loader can be tricked into
 overrunning a heap allocated memory buffer by loading a
 specially encoded image.  A remote site could cause a denial of
 service and possibly execute arbitrary code in the context of
 the user.
&lt;/li&gt;&lt;li&gt; Add patch kubuntu_07_khtml_png_loader_memory_overrun.diff from KDE
 upstream, adds extra checks to khtml/imload/decoders/pngloader.cpp
&lt;/li&gt;&lt;li&gt; References
 http://www.kde.org/info/security/advisory-20080426-1.txt
 CVE-2008-1670&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Tue, 06 May 2008 19:56:15 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>hsqldb, 1.8.0.7-1ubuntu2.1</title>
  <guid>http://launchpad.net/distros/ubuntu/feisty/+source/hsqldb,/1.8.0.7-1ubuntu2.1</guid>
  <link>http://launchpad.net/distros/ubuntu/feisty/+source/hsqldb,/1.8.0.7-1ubuntu2.1</link>
  <description>&lt;b&gt;hsqldb (1.8.0.7-1ubuntu2.1)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; SECURITY UPDATE: arbitrary Java methods via SQL.
&lt;/li&gt;&lt;li&gt; Add debian/patches/90_method-whitelist.patch: upstream changes backported,
 thanks to Debian.
&lt;/li&gt;&lt;li&gt; References
 CVE-2007-4575&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Tue, 06 May 2008 21:55:14 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>openoffice.org, 2.2.0-1ubuntu6</title>
  <guid>http://launchpad.net/distros/ubuntu/feisty/+source/openoffice.org,/2.2.0-1ubuntu6</guid>
  <link>http://launchpad.net/distros/ubuntu/feisty/+source/openoffice.org,/2.2.0-1ubuntu6</link>
  <description>&lt;b&gt;openoffice.org (2.2.0-1ubuntu6)&lt;/b&gt;&lt;ul&gt;&lt;li&gt;&lt;b&gt; Chris Cheney &lt;/b&gt;
&lt;/li&gt;&lt;li&gt; ooo-build/patches/src680/workspace.fwk82.diff,
 ooo-build/patches/src680/workspace.sjfixes03.diff: fix CVE-2007-5745,
 CVE-2007-5746,CVE-2007-5747 and CVE-2008-0320
&lt;/li&gt;&lt;li&gt; ooo-build/patches/src680/cws-jl85.diff: fix XML signing problem where
 the document can be manipulated so that the signature dialog display a
 false issuer
&lt;/li&gt;&lt;li&gt;&lt;b&gt; Kees Cook &lt;/b&gt;
&lt;/li&gt;&lt;li&gt; ooo-build/patches/src680/workspace.hsql1808.diff: upstream fixes
 backported for HSQLDB Java method calling (CVE-2007-4575).&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Tue, 06 May 2008 22:00:04 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>ltsp, 5.0.7.1</title>
  <guid>http://launchpad.net/distros/ubuntu/feisty/+source/ltsp,/5.0.7.1</guid>
  <link>http://launchpad.net/distros/ubuntu/feisty/+source/ltsp,/5.0.7.1</link>
  <description>&lt;b&gt;ltsp (5.0.7.1)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; fix CVE-2008-1293 (LP: #227295) that made unauthenticated access to the
 local X server on the client possible.&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Tue, 06 May 2008 22:56:01 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>speex, 1.1.12-3ubuntu0.7.04.1</title>
  <guid>http://launchpad.net/distros/ubuntu/feisty/+source/speex,/1.1.12-3ubuntu0.7.04.1</guid>
  <link>http://launchpad.net/distros/ubuntu/feisty/+source/speex,/1.1.12-3ubuntu0.7.04.1</link>
  <description>&lt;b&gt;speex (1.1.12-3ubuntu0.7.04.1)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; SECURITY UPDATE: array index vulnerability (LP: #218652)
&lt;/li&gt;&lt;li&gt; fix for libspeex/speex_header.c to properly validate its input
&lt;/li&gt;&lt;li&gt; References
 CVE-2008-1686&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Thu, 08 May 2008 17:55:26 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>vorbis-tools, 1.1.1-6ubuntu0.1</title>
  <guid>http://launchpad.net/distros/ubuntu/feisty/+source/vorbis-tools,/1.1.1-6ubuntu0.1</guid>
  <link>http://launchpad.net/distros/ubuntu/feisty/+source/vorbis-tools,/1.1.1-6ubuntu0.1</link>
  <description>&lt;b&gt;vorbis-tools (1.1.1-6ubuntu0.1)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; SECURITY UPDATE: array index vulnerability (LP: #218652)
&lt;/li&gt;&lt;li&gt; debian/patches/SECURITY_CVE-2008-1686.diff: fix for ogg123/speex_format.c
 to properly validate its input
&lt;/li&gt;&lt;li&gt; References
 CVE-2008-1686&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Thu, 08 May 2008 19:55:20 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>gst-plugins-good0.10, 0.10.5-1ubuntu2.1</title>
  <guid>http://launchpad.net/distros/ubuntu/feisty/+source/gst-plugins-good0.10,/0.10.5-1ubuntu2.1</guid>
  <link>http://launchpad.net/distros/ubuntu/feisty/+source/gst-plugins-good0.10,/0.10.5-1ubuntu2.1</link>
  <description>&lt;b&gt;gst-plugins-good0.10 (0.10.5-1ubuntu2.1)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; SECURITY UPDATE: array index vulnerability (LP: #218652)
&lt;/li&gt;&lt;li&gt; debian/patches/02_SECURITY_CVE-2008-1686.patch: fix for
 ext/speex/gstspeexdec.c to properly validate its input
&lt;/li&gt;&lt;li&gt; References
 CVE-2008-1686&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Thu, 08 May 2008 20:55:34 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>

  </channel>
</rss>
