<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet href="http://feeds.ubuntu-nl.org/~d/styles/rss2full.xsl" type="text/xsl" media="screen"?><?xml-stylesheet href="http://feeds.ubuntu-nl.org/~d/styles/itemcontent.css" type="text/css" media="screen"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" version="2.0">
  <channel>
    <title>Gutsy Changes</title>
    <link>http://lists.ubuntu.com/mailman/listinfo/gutsy-changes</link>
    <language>en</language>
    
<atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" href="http://feeds.ubuntu-nl.org/GutsyChanges" type="application/rss+xml" /><item>
  <title>pcre3, 7.4-0ubuntu0.7.10.2</title>
  <guid>http://launchpad.net/distros/ubuntu/gutsy/+source/pcre3,/7.4-0ubuntu0.7.10.2</guid>
  <link>http://launchpad.net/distros/ubuntu/gutsy/+source/pcre3,/7.4-0ubuntu0.7.10.2</link>
  <description>&lt;b&gt;pcre3 (7.4-0ubuntu0.7.10.2)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; SECURITY UPDATE: stack overflow when handling long UTF8 strings.
&lt;/li&gt;&lt;li&gt; pcre_compile.c, testdata/test{in,out}put4: upstream changes from 7.6
 backported, thanks to Tomas Hoger and Florian Weimer.
&lt;/li&gt;&lt;li&gt; References
 CVE-2008-0674&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Thu, 21 Feb 2008 18:56:02 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>cacti, 0.8.6j-1.1ubuntu0.2</title>
  <guid>http://launchpad.net/distros/ubuntu/gutsy/+source/cacti,/0.8.6j-1.1ubuntu0.2</guid>
  <link>http://launchpad.net/distros/ubuntu/gutsy/+source/cacti,/0.8.6j-1.1ubuntu0.2</link>
  <description>&lt;b&gt;cacti (0.8.6j-1.1ubuntu0.2)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; SECURITY UPDATE: (LP: #192199)
&lt;ul&gt;&lt;li&gt; CVE-2008-0783: Multiple cross-site scripting (XSS) vulnerabilities in
 Cacti 0.8.7 before 0.8.7b and 0.8.6 before 0.8.6k allow remote attackers to
 inject arbitrary web script or HTML via the (1) view_type parameter to
 graph.php, (2) filter parameter to graph_view.php, and (3) action and
 login_username parameters to index.php/login.
&lt;/li&gt;&lt;li&gt; CVE-2008-0784: graph.php in Cacti 0.8.7 before 0.8.7b and 0.8.6 before
 0.8.6k allows remote attackers to obtain the full path via an invalid
 local_graph_id parameter and other unspecified vectors.
&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt; debian/patches/11_CVE-2008-0783_CVE-2008-0784.dpatch: applied patch by
 upstream.
 (Link: http://www.cacti.net/downloads/patches/0.8.6j/multiple_vulnerabilities-0.8.6j.patch)
&lt;/li&gt;&lt;li&gt; References:
 CVE-2008-0783
 CVE-2008-0784&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Fri, 22 Feb 2008 02:55:38 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>glabels 2.1.3-1ubuntu0.1</title>
  <guid>http://launchpad.net/distros/ubuntu/gutsy/+source/glabels/2.1.3-1ubuntu0.1</guid>
  <link>http://launchpad.net/distros/ubuntu/gutsy/+source/glabels/2.1.3-1ubuntu0.1</link>
  <description>&lt;b&gt;glabels (2.1.3-1ubuntu0.1)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; debian/patches/20_fix_paper_size_switch_crash.patch: add to avoid crash
 when switching paper size in template selector dialog (LP: #129518).
&lt;/li&gt;&lt;li&gt; Modify Maintainer value to match the DebianMaintainerField
 specification.&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Fri, 22 Feb 2008 09:49:16 +0000</pubDate>
  <dc:creator>Andrea Colangelo</dc:creator>
  <author>Andrea Colangelo</author>
</item>


<item>
  <title>parallels 2.2.2224-1gutsy1</title>
  <guid>http://launchpad.net/distros/ubuntu/gutsy/+source/parallels/2.2.2224-1gutsy1</guid>
  <link>http://launchpad.net/distros/ubuntu/gutsy/+source/parallels/2.2.2224-1gutsy1</link>
  <description>&lt;b&gt;parallels (2.2.2224-1gutsy1)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; New upstream release
&lt;/li&gt;&lt;li&gt; Closes: #187974, #187972&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Fri, 22 Feb 2008 19:50:12 +0000</pubDate>
  <dc:creator>Brian Thomason</dc:creator>
  <author>Brian Thomason</author>
</item>


<item>
  <title>lighttpd, 1.4.18-1ubuntu1.1</title>
  <guid>http://launchpad.net/distros/ubuntu/gutsy/+source/lighttpd,/1.4.18-1ubuntu1.1</guid>
  <link>http://launchpad.net/distros/ubuntu/gutsy/+source/lighttpd,/1.4.18-1ubuntu1.1</link>
  <description>&lt;b&gt;lighttpd (1.4.18-1ubuntu1.1)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; SECURITY UPDATE:
&lt;ul&gt;&lt;li&gt; debian/patches/90_maxfds_crash_fix.dpatch:
&lt;ul&gt;&lt;li&gt; added patch from upstream to fix the maxfds issue (LP: #195380)
&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt; References
&lt;ul&gt;&lt;li&gt;  http://trac.lighttpd.net/trac/ticket/1562&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Wed, 27 Feb 2008 14:55:57 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>thunderbird, 2.0.0.12+nobinonly-0ubuntu0.7.10.0</title>
  <guid>http://launchpad.net/distros/ubuntu/gutsy/+source/thunderbird,/2.0.0.12+nobinonly-0ubuntu0.7.10.0</guid>
  <link>http://launchpad.net/distros/ubuntu/gutsy/+source/thunderbird,/2.0.0.12+nobinonly-0ubuntu0.7.10.0</link>
  <description>&lt;b&gt;thunderbird (2.0.0.12+nobinonly-0ubuntu0.7.10.0)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; USN-582-1 - 2.0.0.12 security/stability update
&lt;/li&gt;&lt;li&gt; drop keep_version patch previously applied to unbreak homepage which
 didn't exist for *pre versions
&lt;ul&gt;&lt;li&gt; drop debian/patches/keep_version_2006.patch
&lt;/li&gt;&lt;li&gt; update debian/patches/series
&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt; update autoconf-regen patch
&lt;ul&gt;&lt;li&gt; update debian/patches/autoconf-regen&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Fri, 29 Feb 2008 00:56:41 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>gthumb 3:2.10.6-0ubuntu1.1</title>
  <guid>http://launchpad.net/distros/ubuntu/gutsy/+source/gthumb/3:2.10.6-0ubuntu1.1</guid>
  <link>http://launchpad.net/distros/ubuntu/gutsy/+source/gthumb/3:2.10.6-0ubuntu1.1</link>
  <description>&lt;b&gt;gthumb (3:2.10.6-0ubuntu1.1)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; 21_dont_skip_file_type.dpatch:
 Saving .bmp images silently fails (LP: #165174)
&lt;/li&gt;&lt;li&gt; 22_paper_size_free.dpatch:
 Printing often crashes with custom paper size (LP: #173082)
&lt;/li&gt;&lt;li&gt; add Build-depends on libltdl3-dev to allow building from scratch
 (LP: #151696)&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Wed, 05 Mar 2008 08:31:48 +0000</pubDate>
  <dc:creator>Tormod Volden</dc:creator>
  <author>Tormod Volden</author>
</item>


<item>
  <title>ubuntu-docs 7.10.5</title>
  <guid>http://launchpad.net/distros/ubuntu/gutsy/+source/ubuntu-docs/7.10.5</guid>
  <link>http://launchpad.net/distros/ubuntu/gutsy/+source/ubuntu-docs/7.10.5</link>
  <description>&lt;b&gt;ubuntu-docs (7.10.5)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; Updating translations from Rosetta&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Wed, 05 Mar 2008 09:08:34 +0000</pubDate>
  <dc:creator>Matthew East</dc:creator>
  <author>Matthew East</author>
</item>


<item>
  <title>evolution, 2.12.1-0ubuntu1.1</title>
  <guid>http://launchpad.net/distros/ubuntu/gutsy/+source/evolution,/2.12.1-0ubuntu1.1</guid>
  <link>http://launchpad.net/distros/ubuntu/gutsy/+source/evolution,/2.12.1-0ubuntu1.1</link>
  <description>&lt;b&gt;evolution (2.12.1-0ubuntu1.1)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; SECURITY UPDATE: code execution via format string in encrypted emails.
&lt;/li&gt;&lt;li&gt; Add 99_00_encryption_format_string_fix.patch: upstream fixes from
 Srinivasa Ragavan.
&lt;/li&gt;&lt;li&gt; References
 CVE-2008-0072&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Wed, 05 Mar 2008 18:56:25 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>openldap2.3, 2.3.35-1ubuntu0.2</title>
  <guid>http://launchpad.net/distros/ubuntu/gutsy/+source/openldap2.3,/2.3.35-1ubuntu0.2</guid>
  <link>http://launchpad.net/distros/ubuntu/gutsy/+source/openldap2.3,/2.3.35-1ubuntu0.2</link>
  <description>&lt;b&gt;openldap2.3 (2.3.35-1ubuntu0.2)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; SECURITY UPDATE: slapd crash when using the bdb backend and processing
 crafted modrdn requests
&lt;/li&gt;&lt;li&gt; debian/patches/SECURITY_CVE-2008-0658.patch: patch to back-bdb/modrdn.c to
 properly check for NOOP option
&lt;/li&gt;&lt;li&gt; References:
 CVE-2008-0658
 LP: #197077&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Wed, 05 Mar 2008 20:56:05 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>phpmyadmin, 4:2.10.3-1ubuntu0.2</title>
  <guid>http://launchpad.net/distros/ubuntu/gutsy/+source/phpmyadmin,/4:2.10.3-1ubuntu0.2</guid>
  <link>http://launchpad.net/distros/ubuntu/gutsy/+source/phpmyadmin,/4:2.10.3-1ubuntu0.2</link>
  <description>&lt;b&gt;phpmyadmin (4:2.10.3-1ubuntu0.2)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; SECURITY UPDATE:
&lt;/li&gt;&lt;li&gt; debian/patches/050_CVE-2008-1149.dpatch
&lt;ul&gt;&lt;li&gt; Provides unauthorized access, Allows partial confidentiality, integrity, and
 availability violation , Allows unauthorized disclosure of information ,
 Allows disruption of service. (LP: #198745)
&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt; References:
&lt;/li&gt;&lt;li&gt; http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-1149
&lt;/li&gt;&lt;li&gt; http://www.phpmyadmin.net/home_page/security.php?issue=PMASA-2008-1&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Thu, 06 Mar 2008 00:55:21 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>tzdata 2007k-0ubuntu0.7.10.1</title>
  <guid>http://launchpad.net/distros/ubuntu/gutsy/+source/tzdata/2007k-0ubuntu0.7.10.1</guid>
  <link>http://launchpad.net/distros/ubuntu/gutsy/+source/tzdata/2007k-0ubuntu0.7.10.1</link>
  <description>&lt;b&gt;tzdata (2007k-0ubuntu0.7.10.1)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; Add debian/patches/chile-dst2008.patch: Update DST rules for Chile to
 incorporate short-term DST change for 2008 (delayed for three weeks from
 March 08 to March 29). (LP: #198129)&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Thu, 06 Mar 2008 10:32:34 +0000</pubDate>
  <dc:creator>Martin Pitt</dc:creator>
  <author>Martin Pitt</author>
</item>


<item>
  <title>parallels 2.2.2226-1gutsy1</title>
  <guid>http://launchpad.net/distros/ubuntu/gutsy/+source/parallels/2.2.2226-1gutsy1</guid>
  <link>http://launchpad.net/distros/ubuntu/gutsy/+source/parallels/2.2.2226-1gutsy1</link>
  <description>&lt;b&gt;parallels (2.2.2226-1gutsy1)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; New upstream release
&lt;/li&gt;&lt;li&gt; Removed setuid executables&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Fri, 07 Mar 2008 09:05:14 +0000</pubDate>
  <dc:creator>Brian Thomason</dc:creator>
  <author>Brian Thomason</author>
</item>


<item>
  <title>lighttpd, 1.4.18-1ubuntu1.2</title>
  <guid>http://launchpad.net/distros/ubuntu/gutsy/+source/lighttpd,/1.4.18-1ubuntu1.2</guid>
  <link>http://launchpad.net/distros/ubuntu/gutsy/+source/lighttpd,/1.4.18-1ubuntu1.2</link>
  <description>&lt;b&gt;lighttpd (1.4.18-1ubuntu1.2)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; SECURITY UPDATE:
&lt;/li&gt;&lt;li&gt; debian/patches/91_CVE-2008-1111.dpatch:
&lt;ul&gt;&lt;li&gt; Fixes CVE-2008-1111
 "mod_cgi in lighttpd 1.4.18, when a fork failure occurs, sends the
 source code of CGI scripts instead of a 500 error, which might allow
 remote attackers to obtain sensitive information." (LP: #198731)
&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt; References
&lt;/li&gt;&lt;li&gt; http://trac.lighttpd.net/trac/changeset/2107
&lt;/li&gt;&lt;li&gt; http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2008-1111&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Fri, 07 Mar 2008 18:56:24 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>python2.4, 2.4.4-6ubuntu4.1</title>
  <guid>http://launchpad.net/distros/ubuntu/gutsy/+source/python2.4,/2.4.4-6ubuntu4.1</guid>
  <link>http://launchpad.net/distros/ubuntu/gutsy/+source/python2.4,/2.4.4-6ubuntu4.1</link>
  <description>&lt;b&gt;python2.4 (2.4.4-6ubuntu4.1)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; SECURITY UPDATE: code execution via integer overflows.
&lt;/li&gt;&lt;li&gt; debian/rules, debian/patches/CVE-2007-4965-int-overflow.dpatch: upstream
 changes, thanks to Stephan Hermann.
&lt;/li&gt;&lt;li&gt; References
 http://bugs.python.org/file8592/python-2.5.CVE-2007-4965-int-overflow.patch
 CVE-2007-4965&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Mon, 10 Mar 2008 21:56:15 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>python2.5, 2.5.1-5ubuntu5.1</title>
  <guid>http://launchpad.net/distros/ubuntu/gutsy/+source/python2.5,/2.5.1-5ubuntu5.1</guid>
  <link>http://launchpad.net/distros/ubuntu/gutsy/+source/python2.5,/2.5.1-5ubuntu5.1</link>
  <description>&lt;b&gt;python2.5 (2.5.1-5ubuntu5.1)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; SECURITY UPDATE: code execution via integer overflows.
&lt;/li&gt;&lt;li&gt; debian/rules, debian/patches/CVE-2007-4965-int-overflow.dpatch: upstream
 changes, thanks to Stephan Hermann.
&lt;/li&gt;&lt;li&gt; References
 http://bugs.python.org/file8592/python-2.5.CVE-2007-4965-int-overflow.patch
 CVE-2007-4965&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Mon, 10 Mar 2008 21:58:01 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>lighttpd, 1.4.18-1ubuntu1.3</title>
  <guid>http://launchpad.net/distros/ubuntu/gutsy/+source/lighttpd,/1.4.18-1ubuntu1.3</guid>
  <link>http://launchpad.net/distros/ubuntu/gutsy/+source/lighttpd,/1.4.18-1ubuntu1.3</link>
  <description>&lt;b&gt;lighttpd (1.4.18-1ubuntu1.3)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; SECURITY UPDATE: (LP: #200987)
&lt;/li&gt;&lt;li&gt; debian/patches/91_CVE-2008-1270.dpatch
&lt;ul&gt;&lt;li&gt; mod_userdir in lighttpd 1.4.18 and earlier, when userdir.path is not set,
 uses a default of $HOME, which might allow remote attackers to read arbitrary
 files, as demonstrated by accessing the ~nobody directory.
&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt; References
&lt;/li&gt;&lt;li&gt; http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-1270
&lt;/li&gt;&lt;li&gt; http://trac.lighttpd.net/trac/ticket/1587
&lt;/li&gt;&lt;li&gt; http://trac.lighttpd.net/trac/changeset/2120&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Tue, 11 Mar 2008 19:55:56 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>mysql-dfsg-5.0 5.0.45-1ubuntu3.2</title>
  <guid>http://launchpad.net/distros/ubuntu/gutsy/+source/mysql-dfsg-5.0/5.0.45-1ubuntu3.2</guid>
  <link>http://launchpad.net/distros/ubuntu/gutsy/+source/mysql-dfsg-5.0/5.0.45-1ubuntu3.2</link>
  <description>&lt;b&gt;mysql-dfsg-5.0 (5.0.45-1ubuntu3.2)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; SECURITY UPDATE: buffer overflow via ProcessOldClientHello() in
 handshake.cpp and input_buffer&amp;amp; operator&amp;gt;&amp;gt; in yassl_imp.cpp
&lt;/li&gt;&lt;li&gt; SECURITY UPDATE: buffer overread in HASHwithTransform::Update in hash.cpp
&lt;/li&gt;&lt;li&gt; debian/patches/95_SECURITY_CVE-2008-0226_0227.dpatch: properly verify
 length of input (LP: #186978)
&lt;/li&gt;&lt;li&gt; SECURITY UPDATE: privilege escalation via crafted CREATE SQL SECURITY
 DEFINER VIEW and ALTER VIEW statements
&lt;/li&gt;&lt;li&gt; debian/patches/96_SECURITY_CVE-2007-6303.dpatch: make sure lex-&amp;gt;definer
 is non-NULL in sql_view.cc (LP: #185039)
&lt;/li&gt;&lt;li&gt; debian/patches/97_view_fix-now.dpatch: update view.test and view.result to
 use a static year instead of now(). These tests are not part of the build
 but helps with qa-regression-testing
&lt;/li&gt;&lt;li&gt; References
 CVE-2008-0226
 CVE-2008-0227
 CVE-2007-6303&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Wed, 12 Mar 2008 08:08:56 +0000</pubDate>
  <dc:creator>Jamie Strandboge</dc:creator>
  <author>Jamie Strandboge</author>
</item>


<item>
  <title>tzdata 2008a-0ubuntu0.7.10</title>
  <guid>http://launchpad.net/distros/ubuntu/gutsy/+source/tzdata/2008a-0ubuntu0.7.10</guid>
  <link>http://launchpad.net/distros/ubuntu/gutsy/+source/tzdata/2008a-0ubuntu0.7.10</link>
  <description>&lt;b&gt;tzdata (2008a-0ubuntu0.7.10)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; Replace tzdata2007k.tar.gz with new version tzdata2008a:
&lt;ul&gt;&lt;li&gt; Fixes Chile DST properly, our patch switched it on a day too early.
&lt;/li&gt;&lt;li&gt; Drop debian/patches/chile-dst2008.patch.
&lt;/li&gt;&lt;li&gt; LP: #198129&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Wed, 12 Mar 2008 09:22:19 +0000</pubDate>
  <dc:creator>Martin Pitt</dc:creator>
  <author>Martin Pitt</author>
</item>


<item>
  <title>vlc, 0.8.6.release.c-0ubuntu5.1</title>
  <guid>http://launchpad.net/distros/ubuntu/gutsy/+source/vlc,/0.8.6.release.c-0ubuntu5.1</guid>
  <link>http://launchpad.net/distros/ubuntu/gutsy/+source/vlc,/0.8.6.release.c-0ubuntu5.1</link>
  <description>&lt;b&gt;vlc (0.8.6.release.c-0ubuntu5.1)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; SECURITY UPDATE:
&lt;ul&gt;&lt;li&gt; debian/patches/031_CVE-2008-0984.diff (LP: #195949)
&lt;/li&gt;&lt;li&gt; VLC media player's MPEG-4 file format parser (a.k.a. the MP4 demuxer)
&lt;ul&gt;&lt;li&gt;suffers from an arbitrary memory overwrite vulnerability when using
&lt;/li&gt;&lt;li&gt;crash the player instance.
&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt; References
&lt;ul&gt;&lt;li&gt; http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0984
&lt;/li&gt;&lt;li&gt; http://www.videolan.org/security/sa0802.html&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Wed, 12 Mar 2008 17:57:12 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>mailman, 1:2.1.9-8ubuntu0.1</title>
  <guid>http://launchpad.net/distros/ubuntu/gutsy/+source/mailman,/1:2.1.9-8ubuntu0.1</guid>
  <link>http://launchpad.net/distros/ubuntu/gutsy/+source/mailman,/1:2.1.9-8ubuntu0.1</link>
  <description>&lt;b&gt;mailman (1:2.1.9-8ubuntu0.1)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; debian/control:
&lt;/li&gt;&lt;li&gt; updated maintainer field
&lt;/li&gt;&lt;li&gt; SECURITY UPDATE:
&lt;/li&gt;&lt;li&gt; debian/patches/100_CVE-2008-0564.dpatch (LP: #199338)
&lt;ul&gt;&lt;li&gt; Multiple cross-site scripting (XSS) vulnerabilities in Mailman before 2.1.10b1 allow
 remote attackers to inject arbitrary web script or HTML via unspecified vectors related
 to (1) editing templates and (2) the list's "info attribute" in the web administrator interface.
&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt; References
&lt;/li&gt;&lt;li&gt; http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0564
&lt;/li&gt;&lt;li&gt; http://bugs.gentoo.org/show_bug.cgi?id=208710&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Fri, 14 Mar 2008 18:56:14 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>wml, 2.0.11-2ubuntu0.1</title>
  <guid>http://launchpad.net/distros/ubuntu/gutsy/+source/wml,/2.0.11-2ubuntu0.1</guid>
  <link>http://launchpad.net/distros/ubuntu/gutsy/+source/wml,/2.0.11-2ubuntu0.1</link>
  <description>&lt;b&gt;wml (2.0.11-2ubuntu0.1)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; debian/control
&lt;/li&gt;&lt;li&gt; updated maintainer field
&lt;/li&gt;&lt;li&gt; SECURITY UPDATE: (LP: #191205)
&lt;/li&gt;&lt;li&gt; wml_backend/p1_ipp/ipp.src (CVE-2008-0665)
&lt;ul&gt;&lt;li&gt; in Website META Language (WML) 2.0.11 allows local
 users to overwrite arbitrary files via a symlink attack on the ipp.$$.tmp
 temporary file.
&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt; wlm_backend/p3_eperl/eperl_sys.c wml_contrib/wmg.cgi (CVE-2008-0666)
&lt;ul&gt;&lt;li&gt; Website META Language (WML) 2.0.11 allows local users to overwrite arbitrary
 files via a symlink attack on (1) the /tmp/pe.tmp.$$ temporary file used by
 wml_contrib/wmg.cgi and (2) temporary files used by
 wml_backend/p3_eperl/eperl_sys.c.
&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt; References
&lt;/li&gt;&lt;li&gt; http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2008-0665
&lt;/li&gt;&lt;li&gt; http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2008-0666
&lt;/li&gt;&lt;li&gt; http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=463907&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Fri, 14 Mar 2008 20:55:50 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>cherrypy3,cherrypy3 3.0.2-1ubuntu0.1</title>
  <guid>http://launchpad.net/distros/ubuntu/gutsy/+source/cherrypy3,cherrypy3/3.0.2-1ubuntu0.1</guid>
  <link>http://launchpad.net/distros/ubuntu/gutsy/+source/cherrypy3,cherrypy3/3.0.2-1ubuntu0.1</link>
  <description>&lt;b&gt;cherrypy3 (3.0.2-1ubuntu0.1)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; SECURITY UPDATE: directory traversal via session cookie ID.
&lt;ul&gt;&lt;li&gt; debian/patches/10_CVE-2008-0252.diff: Add. Ensure that the path
 generated from the session ID is within the session directory. Patch
 from upstream SVN. (LP: #187481)
&lt;/li&gt;&lt;li&gt; References:
&lt;ul&gt;&lt;li&gt; CVE-2008-0252
&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt; Modify Maintainer value to match the DebianMaintainerField specification.&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Fri, 14 Mar 2008 20:56:27 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>python-cherrypy, 2.2.1-3ubuntu1.7.10</title>
  <guid>http://launchpad.net/distros/ubuntu/gutsy/+source/python-cherrypy,/2.2.1-3ubuntu1.7.10</guid>
  <link>http://launchpad.net/distros/ubuntu/gutsy/+source/python-cherrypy,/2.2.1-3ubuntu1.7.10</link>
  <description>&lt;b&gt;python-cherrypy (2.2.1-3ubuntu1.7.10)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; SECURITY UPDATE: directory traversal via session cookie ID.
&lt;ul&gt;&lt;li&gt; debian/patches/10_CVE-2008-0252.diff: Add. Ensure that the path
 generated from the session ID is within the session directory. Patch
 from upstream SVN. (LP: #187481)
&lt;/li&gt;&lt;li&gt; References:
&lt;ul&gt;&lt;li&gt; CVE-2008-0252&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Fri, 14 Mar 2008 20:56:47 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>mailman, 1:2.1.9-8ubuntu0.2</title>
  <guid>http://launchpad.net/distros/ubuntu/gutsy/+source/mailman,/1:2.1.9-8ubuntu0.2</guid>
  <link>http://launchpad.net/distros/ubuntu/gutsy/+source/mailman,/1:2.1.9-8ubuntu0.2</link>
  <description>&lt;b&gt;mailman (1:2.1.9-8ubuntu0.2)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; debian/patches/100_CVE-2008-0564.dpatch: Readd erroneously removed code
 line which caused the code to become invalid and the package to not be
 installable. (LP: #202332)&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Sat, 15 Mar 2008 16:55:39 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>postgresql-8.2 8.2.7-0ubuntu0.7.10</title>
  <guid>http://launchpad.net/distros/ubuntu/gutsy/+source/postgresql-8.2/8.2.7-0ubuntu0.7.10</guid>
  <link>http://launchpad.net/distros/ubuntu/gutsy/+source/postgresql-8.2/8.2.7-0ubuntu0.7.10</link>
  <description>&lt;b&gt;postgresql-8.2 (8.2.7-0ubuntu0.7.10)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; New upstream bug fix release: (LP: #203734)
&lt;ul&gt;&lt;li&gt; Repair potential deadlock between concurrent "VACUUM FULL"
 operations on different system catalogs.
&lt;/li&gt;&lt;li&gt; Fix longstanding "LISTEN"/"NOTIFY" race condition.
&lt;/li&gt;&lt;li&gt; Disallow "LISTEN" and "UNLISTEN" within a prepared transaction.
 This was formerly allowed but trying to do it had various
 unpleasant consequences, notably that the originating backend could
 not exit as long as an "UNLISTEN" remained uncommitted.
&lt;/li&gt;&lt;li&gt; Disallow dropping a temporary table within a prepared transaction
 This was correctly disallowed by 8.1, but the check was
 inadvertently broken in 8.2.
&lt;/li&gt;&lt;li&gt; Fix rare crash when an error occurs during a query using a hash
 index.
&lt;/li&gt;&lt;li&gt; Fix memory leaks in certain usages of set-returning functions.
&lt;/li&gt;&lt;li&gt; Fix input of datetime values for February 29 in years BC.
&lt;/li&gt;&lt;li&gt; Fix "unrecognized node type" error in some variants of "ALTER
 OWNER".
&lt;/li&gt;&lt;li&gt; Ensure pg_stat_activity.waiting flag is cleared when a lock wait is
 aborted.
&lt;/li&gt;&lt;li&gt; Fix pg_ctl to correctly extract the postmaster's port number from
 command-line options. (See Debian #358546)
&lt;/li&gt;&lt;li&gt; Use "-fwrapv" to defend against possible misoptimization in recent
 gcc versions.
&lt;/li&gt;&lt;li&gt; Correctly enforce statement_timeout values longer than INT_MAX
 microseconds (about 35 minutes).
&lt;/li&gt;&lt;li&gt; Fix "unexpected PARAM_SUBLINK ID" planner error when
 constant-folding simplifies a sub-select.
&lt;/li&gt;&lt;li&gt; Fix logical errors in constraint-exclusion handling of IS NULL and
 NOT expressions.
&lt;/li&gt;&lt;li&gt; Fix another cause of "failed to build any N-way joins" planner
 errors.
&lt;/li&gt;&lt;li&gt; Fix incorrect constant propagation in outer-join planning.
&lt;/li&gt;&lt;li&gt; Fix display of constant expressions in ORDER BY and GROUP BY.
&lt;/li&gt;&lt;li&gt; Fix libpq to handle NOTICE messages correctly during COPY OUT.
&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt; Remove debian/patches/00upstream-clauseless-joins-regression.patch,
 upstream now.&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Tue, 18 Mar 2008 22:57:04 +0000</pubDate>
  <dc:creator>Martin Pitt</dc:creator>
  <author>Martin Pitt</author>
</item>


<item>
  <title>krb5, 1.6.dfsg.1-7ubuntu0.1</title>
  <guid>http://launchpad.net/distros/ubuntu/gutsy/+source/krb5,/1.6.dfsg.1-7ubuntu0.1</guid>
  <link>http://launchpad.net/distros/ubuntu/gutsy/+source/krb5,/1.6.dfsg.1-7ubuntu0.1</link>
  <description>&lt;b&gt;krb5 (1.6.dfsg.1-7ubuntu0.1)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; SECURITY UPDATE: arbitrary code execution via freed pointer and memory
 overflows.
&lt;/li&gt;&lt;li&gt; src/kdc/{kerberos_v4,dispatch,network}.c: upstream fixes patched inline
 (MITKRB5-SA-2008-001: CVE-2008-0062, CVE-2008-0063).
&lt;/li&gt;&lt;li&gt; src/lib/rpc/{svc,svc_tcp}.c: upstream fixed patched inline
 (MITKRB5-SA-2008-002: CVE-2008-0947)&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Tue, 18 Mar 2008 23:56:55 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>mysql-dfsg-5.0, 5.0.45-1ubuntu3.3</title>
  <guid>http://launchpad.net/distros/ubuntu/gutsy/+source/mysql-dfsg-5.0,/5.0.45-1ubuntu3.3</guid>
  <link>http://launchpad.net/distros/ubuntu/gutsy/+source/mysql-dfsg-5.0,/5.0.45-1ubuntu3.3</link>
  <description>&lt;b&gt;mysql-dfsg-5.0 (5.0.45-1ubuntu3.3)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; no change build for -security upload
&lt;/li&gt;&lt;/ul&gt;&lt;b&gt;mysql-dfsg-5.0 (5.0.45-1ubuntu3.2)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; SECURITY UPDATE: buffer overflow via ProcessOldClientHello() in
 handshake.cpp and input_buffer&amp;amp; operator&amp;gt;&amp;gt; in yassl_imp.cpp
&lt;/li&gt;&lt;li&gt; SECURITY UPDATE: buffer overread in HASHwithTransform::Update in hash.cpp
&lt;/li&gt;&lt;li&gt; debian/patches/95_SECURITY_CVE-2008-0226_0227.dpatch: properly verify
 length of input (LP: #186978)
&lt;/li&gt;&lt;li&gt; SECURITY UPDATE: privilege escalation via crafted CREATE SQL SECURITY
 DEFINER VIEW and ALTER VIEW statements
&lt;/li&gt;&lt;li&gt; debian/patches/96_SECURITY_CVE-2007-6303.dpatch: make sure lex-&amp;gt;definer
 is non-NULL in sql_view.cc (LP: #185039)
&lt;/li&gt;&lt;li&gt; debian/patches/97_view_fix-now.dpatch: update view.test and view.result to
 use a static year instead of now(). These tests are not part of the build
 but helps with qa-regression-testing
&lt;/li&gt;&lt;li&gt; References
 CVE-2008-0226
 CVE-2008-0227
 CVE-2007-6303&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Thu, 20 Mar 2008 10:57:39 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>unzip, 5.52-10ubuntu1.1</title>
  <guid>http://launchpad.net/distros/ubuntu/gutsy/+source/unzip,/5.52-10ubuntu1.1</guid>
  <link>http://launchpad.net/distros/ubuntu/gutsy/+source/unzip,/5.52-10ubuntu1.1</link>
  <description>&lt;b&gt;unzip (5.52-10ubuntu1.1)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; SECURITY UPDATE: arbitrary code execution via heap corruption.
&lt;/li&gt;&lt;li&gt; inflate.c: fix invalid free() calls, patch from Tavis Ormandy.
&lt;/li&gt;&lt;li&gt; References
 CVE-2008-0888&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Thu, 20 Mar 2008 17:55:19 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>smarty,smarty 2.6.18-1ubuntu2.1</title>
  <guid>http://launchpad.net/distros/ubuntu/gutsy/+source/smarty,smarty/2.6.18-1ubuntu2.1</guid>
  <link>http://launchpad.net/distros/ubuntu/gutsy/+source/smarty,smarty/2.6.18-1ubuntu2.1</link>
  <description>&lt;b&gt;smarty (2.6.18-1ubuntu2.1)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; SECURITY UPDATE: (LP: #202422)
&lt;/li&gt;&lt;li&gt; libs/plugins/modifier.regex_replace.php
&lt;ul&gt;&lt;li&gt; The modifier.regex_replace.php plugin in Smarty before 2.6.19, as used
 by Serendipity (S9Y) and other products, allows attackers to call arbitrary
 PHP functions via templates, related to a '\0' character in a search string.
&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt; References
&lt;/li&gt;&lt;li&gt; http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1066
&lt;/li&gt;&lt;li&gt; http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=469492&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Mon, 24 Mar 2008 12:55:49 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>mplayer, 2:1.0~rc1-0ubuntu13.2</title>
  <guid>http://launchpad.net/distros/ubuntu/gutsy/+source/mplayer,/2:1.0~rc1-0ubuntu13.2</guid>
  <link>http://launchpad.net/distros/ubuntu/gutsy/+source/mplayer,/2:1.0~rc1-0ubuntu13.2</link>
  <description>&lt;b&gt;mplayer (2:1.0~rc1-0ubuntu13.2)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; SECURITY UPDATE: buffer overruns in RMMF, CDDB, MOV demuxer, FLAC header
 parser, and URL parser. (LP: #191488)
&lt;/li&gt;&lt;li&gt; stream/librtsp/rtsp_session.c, stream/realrtsp/rmff.c,
 stream/realrtsp/rmff.h, libmpdemux/demux_audio.c, libmpdemux/demux_mov.c,
 stream/stream_cddb.c, stream/url.c: Patches from upstream.
&lt;/li&gt;&lt;li&gt; References:
&lt;ul&gt;&lt;li&gt; CVE-2008-0225
&lt;/li&gt;&lt;li&gt; CVE-2008-0238
&lt;/li&gt;&lt;li&gt; CVE-2008-0485
&lt;/li&gt;&lt;li&gt; CVE-2008-0486
&lt;/li&gt;&lt;li&gt; CVE-2008-0629
&lt;/li&gt;&lt;li&gt; CVE-2008-0630&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Mon, 24 Mar 2008 15:56:12 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>bzip2, 1.0.4-0ubuntu2.1</title>
  <guid>http://launchpad.net/distros/ubuntu/gutsy/+source/bzip2,/1.0.4-0ubuntu2.1</guid>
  <link>http://launchpad.net/distros/ubuntu/gutsy/+source/bzip2,/1.0.4-0ubuntu2.1</link>
  <description>&lt;b&gt;bzip2 (1.0.4-0ubuntu2.1)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; SECURITY UPDATE: denial of service via heap memory corruption.
&lt;/li&gt;&lt;li&gt; bzlib.c, bzlib_private.h: upstream patch from 1.0.5 applied inline.
&lt;/li&gt;&lt;li&gt; References
 CVE-2008-1372&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Mon, 24 Mar 2008 17:56:21 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>icu, 3.6-3ubuntu0.1</title>
  <guid>http://launchpad.net/distros/ubuntu/gutsy/+source/icu,/3.6-3ubuntu0.1</guid>
  <link>http://launchpad.net/distros/ubuntu/gutsy/+source/icu,/3.6-3ubuntu0.1</link>
  <description>&lt;b&gt;icu (3.6-3ubuntu0.1)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; SECURITY UPDATE: possible read from and write to out of bounds memory
 locations via back reference '\0' in regular expressions
&lt;/li&gt;&lt;li&gt; SECURITY UPDATE: denial of service due to memory exhaustion via a
 crafted regular expression
&lt;/li&gt;&lt;li&gt; debian/patches/SECURITY_CVE-2007-4770_4771.patch: fix regexcmp.cpp to
 return error on invalid back reference. fix rematch.cpp, uvectr32.h and
 uvectr32.cpp to return error when capacity is greater than maxCapacity
&lt;/li&gt;&lt;li&gt; References
 CVE-2007-4770
 CVE-2007-4771
&lt;/li&gt;&lt;li&gt; Modify Maintainer value to match the DebianMaintainerField
 specification.&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Mon, 24 Mar 2008 17:57:24 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>icedtea-java7 7~b21-1.4+20071007-0ubuntu7</title>
  <guid>http://launchpad.net/distros/ubuntu/gutsy/+source/icedtea-java7/7~b21-1.4+20071007-0ubuntu7</guid>
  <link>http://launchpad.net/distros/ubuntu/gutsy/+source/icedtea-java7/7~b21-1.4+20071007-0ubuntu7</link>
  <description>&lt;b&gt;icedtea-java7 (7~b21-1.4+20071007-0ubuntu7)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; Move rt.jar into the icedtea-java7-bin package; sun/awt/X11
 class files differ between amd64 and i386. LP: #152362, #177514, #191075.
&lt;/li&gt;&lt;li&gt; Install all desktop files in /usr/share/applications.
&lt;/li&gt;&lt;li&gt; Install icons in /usr/share/pixmaps, not /usr/share/icons.
&lt;/li&gt;&lt;li&gt; debian/rules: Call dh_icons.
&lt;/li&gt;&lt;li&gt; icedtea-java7-jre: Provide java-virtual-machine. LP: #189953.&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Wed, 26 Mar 2008 00:05:38 +0000</pubDate>
  <dc:creator>Matthias Klose</dc:creator>
  <author>Matthias Klose</author>
</item>


<item>
  <title>dspam, 3.6.8-5ubuntu1.2</title>
  <guid>http://launchpad.net/distros/ubuntu/gutsy/+source/dspam,/3.6.8-5ubuntu1.2</guid>
  <link>http://launchpad.net/distros/ubuntu/gutsy/+source/dspam,/3.6.8-5ubuntu1.2</link>
  <description>&lt;b&gt;dspam (3.6.8-5ubuntu1.2)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; SECURITY UPDATE: The libdspam7-drv-mysql cron job includes the MySQL
 dspam database password in a command line argument, which might allow
 local users to read the password by listing the process and its arguments.
&lt;/li&gt;&lt;li&gt; debian/libdspam7-drv-mysql.cron.daily: applied patch from Debian to use a
 password file instead.
&lt;/li&gt;&lt;li&gt; References
&lt;ul&gt;&lt;li&gt; LP: #195691
&lt;/li&gt;&lt;li&gt; CVE-2007-6418&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Wed, 26 Mar 2008 03:56:28 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>firefox, 2.0.0.13+1nobinonly-0ubuntu0.7.10</title>
  <guid>http://launchpad.net/distros/ubuntu/gutsy/+source/firefox,/2.0.0.13+1nobinonly-0ubuntu0.7.10</guid>
  <link>http://launchpad.net/distros/ubuntu/gutsy/+source/firefox,/2.0.0.13+1nobinonly-0ubuntu0.7.10</link>
  <description>&lt;b&gt;firefox (2.0.0.13+1nobinonly-0ubuntu0.7.10)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; New security/stability upstream release (v2.0.0.13)
&lt;ul&gt;&lt;li&gt; see USN-592-1&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Wed, 26 Mar 2008 13:03:50 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>libnet-dns-perl, 0.60-1ubuntu0.1</title>
  <guid>http://launchpad.net/distros/ubuntu/gutsy/+source/libnet-dns-perl,/0.60-1ubuntu0.1</guid>
  <link>http://launchpad.net/distros/ubuntu/gutsy/+source/libnet-dns-perl,/0.60-1ubuntu0.1</link>
  <description>&lt;b&gt;libnet-dns-perl (0.60-1ubuntu0.1)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; SECURITY UPDATE:
&lt;/li&gt;&lt;li&gt; debian/patches/42_CVE-2007-6341.dpatch (LP: #201454)
&lt;ul&gt;&lt;li&gt; used in packages such as SpamAssassin and OTRS, allows remote
 attackers to cause a denial of service (program "croak") via a
 crafted DNS response.
&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt; References
&lt;/li&gt;&lt;li&gt; http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6341
&lt;/li&gt;&lt;li&gt; http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=457445&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Wed, 26 Mar 2008 17:56:37 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>dovecot, 1:1.0.5-1ubuntu2.2</title>
  <guid>http://launchpad.net/distros/ubuntu/gutsy/+source/dovecot,/1:1.0.5-1ubuntu2.2</guid>
  <link>http://launchpad.net/distros/ubuntu/gutsy/+source/dovecot,/1:1.0.5-1ubuntu2.2</link>
  <description>&lt;b&gt;dovecot (1:1.0.5-1ubuntu2.2)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; SECURITY UPDATE: mailboxes of other users could be read via symlinks.
&lt;/li&gt;&lt;li&gt; Add upstream-mail-group-fixes.dpatch: upstream fixes (CVE-2008-1199).
&lt;/li&gt;&lt;li&gt; Add upstream-invalid-password-fixes.dpatch: proactive upstream fixes
 to avoid future issues in underlying passdb (CVE-2008-1218).
&lt;/li&gt;&lt;li&gt; References
 http://dovecot.org/list/dovecot-news/2008-March/000060.html
 http://dovecot.org/list/dovecot-news/2008-March/000064.html&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Wed, 26 Mar 2008 17:55:26 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>sdl-image1.2, 1.2.5-3ubuntu0.1</title>
  <guid>http://launchpad.net/distros/ubuntu/gutsy/+source/sdl-image1.2,/1.2.5-3ubuntu0.1</guid>
  <link>http://launchpad.net/distros/ubuntu/gutsy/+source/sdl-image1.2,/1.2.5-3ubuntu0.1</link>
  <description>&lt;b&gt;sdl-image1.2 (1.2.5-3ubuntu0.1)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; SECURITY UPDATE: Buffer overflow in GIF handling; possible
 denial of service and arbitrary code execution.
&lt;/li&gt;&lt;li&gt; SECURITY UPDATE: Buffer overflow in IFF ILBM  handling; possible
 denial of service and arbitrary code execution.
&lt;/li&gt;&lt;li&gt; Added patches to prevent buffer overflow in IMG_gif.c and IMG_lbm.c.
 Patches prepared from sdl-image1.2_1.2.5-2etch1 update in debian.
 Applied inline. (LP: #185782)
&lt;/li&gt;&lt;li&gt; References:
 http://www.debian.org/security/2008/dsa-1493
 CVE-2007-6697 and CVE-2008-0544&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Wed, 26 Mar 2008 18:55:51 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>ruby1.8, 1.8.6.36-1ubuntu3.1</title>
  <guid>http://launchpad.net/distros/ubuntu/gutsy/+source/ruby1.8,/1.8.6.36-1ubuntu3.1</guid>
  <link>http://launchpad.net/distros/ubuntu/gutsy/+source/ruby1.8,/1.8.6.36-1ubuntu3.1</link>
  <description>&lt;b&gt;ruby1.8 (1.8.6.36-1ubuntu3.1)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; SECURITY UPDATE: SSL connections did not check commonName early
 enough, possibly allowing sensitive information to be exposed.
&lt;/li&gt;&lt;li&gt; debian/patches/100_CVE-2007-5162.dpatch: upstream fixes, from
 http://svn.ruby-lang.org/cgi-bin/viewvc.cgi?view=rev&amp;amp;revision=13499
&lt;/li&gt;&lt;li&gt; debian/patches/101_CVE-2007-5770.dpatch: upstream fixes, from
 http://svn.ruby-lang.org/cgi-bin/viewvc.cgi?view=rev&amp;amp;revision=13656
&lt;/li&gt;&lt;li&gt; References:
 CVE-2007-5162 CVE-2007-5770 (LP: #149616)&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Wed, 26 Mar 2008 18:57:15 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>horde3, 3.1.4-1ubuntu0.1</title>
  <guid>http://launchpad.net/distros/ubuntu/gutsy/+source/horde3,/3.1.4-1ubuntu0.1</guid>
  <link>http://launchpad.net/distros/ubuntu/gutsy/+source/horde3,/3.1.4-1ubuntu0.1</link>
  <description>&lt;b&gt;horde3 (3.1.4-1ubuntu0.1)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; SECURITY UPDATE: (LP: #203456)
&lt;/li&gt;&lt;li&gt; Directory traversal vulnerability in Horde 3.1.6, Groupware before 1.0.5,
&lt;ul&gt;&lt;li&gt;and Groupware Webmail Edition before 1.0.6, when running with certain
&lt;/li&gt;&lt;li&gt;configurations, allows remote authenticated users to read and execute arbitrary
&lt;/li&gt;&lt;li&gt;files via ".." sequences and a null byte in the theme name.
&lt;/li&gt;&lt;li&gt;Fix directory traversal vulnerability in Registry.php which allows
&lt;/li&gt;&lt;li&gt;an attacker to read and execute arbitrary local files via crafted
&lt;/li&gt;&lt;li&gt;path sequences.
&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt; References
&lt;/li&gt;&lt;li&gt; http://ftp.horde.org/pub/horde/patches/patch-horde-3.1.6-3.1.7.gz
&lt;/li&gt;&lt;li&gt; http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2008-1284
&lt;/li&gt;&lt;li&gt; http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=470640
&lt;/li&gt;&lt;li&gt; http://www.debian.org/security/2008/dsa-1519&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Thu, 27 Mar 2008 16:55:47 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>dspam, 3.6.8-5ubuntu1.3</title>
  <guid>http://launchpad.net/distros/ubuntu/gutsy/+source/dspam,/3.6.8-5ubuntu1.3</guid>
  <link>http://launchpad.net/distros/ubuntu/gutsy/+source/dspam,/3.6.8-5ubuntu1.3</link>
  <description>&lt;b&gt;dspam (3.6.8-5ubuntu1.3)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; debian/libdspam7-drv-mysql.cron.daily:
 Fix bashism introduced in previous security update (s/echo -e/printf/)
 (LP: #207579)&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Fri, 28 Mar 2008 00:56:03 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>gosa 2.5.11a-1ubuntu1</title>
  <guid>http://launchpad.net/distros/ubuntu/gutsy/+source/gosa/2.5.11a-1ubuntu1</guid>
  <link>http://launchpad.net/distros/ubuntu/gutsy/+source/gosa/2.5.11a-1ubuntu1</link>
  <description>&lt;b&gt;gosa (2.5.11a-1ubuntu1)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; debian/control
&lt;/li&gt;&lt;li&gt; Switch Maintainer to Ubuntu Motu Developers
&lt;/li&gt;&lt;li&gt; debian/rules (LP: #157406)
&lt;/li&gt;&lt;li&gt; Fixed fatal error on Call function get_template_patch() in
&lt;ul&gt;&lt;li&gt;/usr/share/gosa/include&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Tue, 01 Apr 2008 10:06:49 +0000</pubDate>
  <dc:creator>Emanuele Gentili</dc:creator>
  <author>Emanuele Gentili</author>
</item>


<item>
  <title>openssh, 1:4.6p1-5ubuntu0.2</title>
  <guid>http://launchpad.net/distros/ubuntu/gutsy/+source/openssh,/1:4.6p1-5ubuntu0.2</guid>
  <link>http://launchpad.net/distros/ubuntu/gutsy/+source/openssh,/1:4.6p1-5ubuntu0.2</link>
  <description>&lt;b&gt;openssh (1:4.6p1-5ubuntu0.2)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; SECURITY UPDATE: X11 forward hijacking via alternate address families.
&lt;/li&gt;&lt;li&gt; channels.c: upstream fixes, patched inline.  Thanks to Nicolas Valcarcel
 (LP: #210175).
&lt;/li&gt;&lt;li&gt; References
 CVE-2008-1483&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Tue, 01 Apr 2008 22:56:06 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>cupsys, 1.3.2-1ubuntu7.6</title>
  <guid>http://launchpad.net/distros/ubuntu/gutsy/+source/cupsys,/1.3.2-1ubuntu7.6</guid>
  <link>http://launchpad.net/distros/ubuntu/gutsy/+source/cupsys,/1.3.2-1ubuntu7.6</link>
  <description>&lt;b&gt;cupsys (1.3.2-1ubuntu7.6)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; debian/patches/72_CVE-2008-0047.dpatch: Fix buffer overflow in
 cgiCompileSearch() using crafted search expressions. Exploitable if
 printer sharing is enabled. Thanks to Martin Pitt for supplying the patch.
&lt;/li&gt;&lt;li&gt; debian/patches/73_CVE-2008-0882.dpatch: Fix double-free in
 process_browse_data(), which could be exploited to a remote DoS by sending
 crafted data to the cups UDP port. Thanks to Martin Pitt for supplying the
 patch.
&lt;/li&gt;&lt;li&gt; debian/patches/74_pid.dpatch: Specify PidFile in temporary directory in
 the self test's cupsd.conf. This affects the test suite (in the sense that
 it actually works now) and does not affect the built binaries at all.
 (Backported from trunk). Thanks to Martin Pitt for supplying the patch.
&lt;/li&gt;&lt;li&gt; debian/patches/75_CVE-2008-0053.dpatch: Fix buffer overflows in
 ParseCommand() in hpgl-input.c by properly checking number of parameters
&lt;/li&gt;&lt;li&gt; debian/patches/76_CVE-2008-1373.dpatch: Fix buffer overflow in
 gif_read_image() in image-gif.c by properly validating code_size
&lt;/li&gt;&lt;li&gt; References
 CVE-2008-0047
 CVE-2008-0882
 CVE-2008-0053
 CVE-2008-1373
 http://www.cups.org/str.php?L2729
 http://www.cups.org/str.php?L2656&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Wed, 02 Apr 2008 21:56:31 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>ca-certificates 20070303-0ubuntu0.7.10</title>
  <guid>http://launchpad.net/distros/ubuntu/gutsy/+source/ca-certificates/20070303-0ubuntu0.7.10</guid>
  <link>http://launchpad.net/distros/ubuntu/gutsy/+source/ca-certificates/20070303-0ubuntu0.7.10</link>
  <description>&lt;b&gt;ca-certificates (20070303-0ubuntu0.7.10)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; Fix up generation of the /etc/ssl/certs/ca-certificates.crt
 file for those users who installed the package in a pt_BR
 locale (LP: #153625). A mistake in the translation template
 meant that the choices were not available in this locale,
 and so the file was always empty.
&lt;ul&gt;&lt;li&gt; If you were affected and have not tried to reconfigure this
 package, then the problem should be corrected for you
 automatically.
&lt;/li&gt;&lt;li&gt; If you were affected and have tried to reconfigure the package
 you may be shown a debconf question to allow you to select
 the certificates that you want.
&lt;/li&gt;&lt;li&gt; The only users who were not affected by this bug but may
 be affected by this fix are those who installed in a different
 locale, and then reconfigured the package so that no
 certificates are trusted, and who now run in a pt_BR locale.
 They will have to deselect all of the certificates again.&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Fri, 04 Apr 2008 12:15:28 +0000</pubDate>
  <dc:creator>James Westby</dc:creator>
  <author>James Westby</author>
</item>


<item>
  <title>zim 0.19-1ubuntu1</title>
  <guid>http://launchpad.net/distros/ubuntu/gutsy/+source/zim/0.19-1ubuntu1</guid>
  <link>http://launchpad.net/distros/ubuntu/gutsy/+source/zim/0.19-1ubuntu1</link>
  <description>&lt;b&gt;zim (0.19-1ubuntu1)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; Applied upstream patch to fix the three following bugs (LP #156432):&lt;ul&gt;&lt;li&gt; infinite loop after "Link" on some platforms&lt;/li&gt;&lt;li&gt; possible corruption of links when updating links after move&lt;/li&gt;&lt;li&gt; bug with TrayIcon menu&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt; debian/control: updated maintainer field as per spec.&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Fri, 04 Apr 2008 12:24:20 +0000</pubDate>
  <dc:creator>Jerome Guelfucci</dc:creator>
  <author>Jerome Guelfucci</author>
</item>


<item>
  <title>cacti, 0.8.6j-1.1ubuntu0.3</title>
  <guid>http://launchpad.net/distros/ubuntu/gutsy/+source/cacti,/0.8.6j-1.1ubuntu0.3</guid>
  <link>http://launchpad.net/distros/ubuntu/gutsy/+source/cacti,/0.8.6j-1.1ubuntu0.3</link>
  <description>&lt;b&gt;cacti (0.8.6j-1.1ubuntu0.3)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; Cacti frontend fails with 'Invalid PHP_SELF Path' (LP: #194687)
&lt;/li&gt;&lt;li&gt; debian/patches/11_php_self_nonstandard_dir.dpatch&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Fri, 04 Apr 2008 18:55:19 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>opera 9.27-20080331.6gutsy1</title>
  <guid>http://launchpad.net/distros/ubuntu/gutsy/+source/opera/9.27-20080331.6gutsy1</guid>
  <link>http://launchpad.net/distros/ubuntu/gutsy/+source/opera/9.27-20080331.6gutsy1</link>
  <description>&lt;b&gt;opera (9.27-20080331.6gutsy1)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; New upstream release
&lt;/li&gt;&lt;li&gt; See http://www.opera.com/docs/changelogs/ for details&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Fri, 04 Apr 2008 22:00:15 +0000</pubDate>
  <dc:creator>Brian Thomason</dc:creator>
  <author>Brian Thomason</author>
</item>


<item>
  <title>ghostscript, 8.61.dfsg.1~svn8187-0ubuntu3.4</title>
  <guid>http://launchpad.net/distros/ubuntu/gutsy/+source/ghostscript,/8.61.dfsg.1~svn8187-0ubuntu3.4</guid>
  <link>http://launchpad.net/distros/ubuntu/gutsy/+source/ghostscript,/8.61.dfsg.1~svn8187-0ubuntu3.4</link>
  <description>&lt;b&gt;ghostscript (8.61.dfsg.1~svn8187-0ubuntu3.4)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; SECURITY UPDATE: buffer overflow in color space handling code
&lt;/li&gt;&lt;li&gt; debian/patches/43_CVE-2008-0411.dpatch: fix zseticcspace() to perform
 range checks
&lt;/li&gt;&lt;li&gt; References
 CVE-2008-0411&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Wed, 09 Apr 2008 18:55:30 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>flashplugin-nonfree 9.0.124.0ubuntu1~gutsy1</title>
  <guid>http://launchpad.net/distros/ubuntu/gutsy/+source/flashplugin-nonfree/9.0.124.0ubuntu1~gutsy1</guid>
  <link>http://launchpad.net/distros/ubuntu/gutsy/+source/flashplugin-nonfree/9.0.124.0ubuntu1~gutsy1</link>
  <description>&lt;b&gt;flashplugin-nonfree (9.0.124.0ubuntu1~gutsy1)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; Update md5sum and package version for Flash 9.0.124.0.&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Wed, 09 Apr 2008 20:26:39 +0000</pubDate>
  <dc:creator>Andy Matteson</dc:creator>
  <author>Andy Matteson</author>
</item>


<item>
  <title>rsync, 2.6.9-5ubuntu1.1</title>
  <guid>http://launchpad.net/distros/ubuntu/gutsy/+source/rsync,/2.6.9-5ubuntu1.1</guid>
  <link>http://launchpad.net/distros/ubuntu/gutsy/+source/rsync,/2.6.9-5ubuntu1.1</link>
  <description>&lt;b&gt;rsync (2.6.9-5ubuntu1.1)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; SECURITY UPDATE: code execution via ACL overflow.
&lt;/li&gt;&lt;li&gt; debian/patches/xattr-security.diff: upstream fixes for ACL/xattr,
 thanks to Debian.
&lt;/li&gt;&lt;li&gt; References
 CVE-2008-1720&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Fri, 11 Apr 2008 05:55:25 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>squid, 2.6.14-1ubuntu2.2</title>
  <guid>http://launchpad.net/distros/ubuntu/gutsy/+source/squid,/2.6.14-1ubuntu2.2</guid>
  <link>http://launchpad.net/distros/ubuntu/gutsy/+source/squid,/2.6.14-1ubuntu2.2</link>
  <description>&lt;b&gt;squid (2.6.14-1ubuntu2.2)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; SECURITY UPDATE: off by one assertion could cause a denial of service
&lt;/li&gt;&lt;li&gt; debian/patches/SECURITY_CVE-2008-1612.dpatch: fix arrayShrink() in
 lib/Array.c to properly check a-&amp;gt;capacity&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Mon, 14 Apr 2008 14:56:03 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>update-manager 1:0.81.3</title>
  <guid>http://launchpad.net/distros/ubuntu/gutsy/+source/update-manager/1:0.81.3</guid>
  <link>http://launchpad.net/distros/ubuntu/gutsy/+source/update-manager/1:0.81.3</link>
  <description>&lt;b&gt;update-manager (1:0.81.3)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; DistUpgrade/DistUpgradeController.py:
&lt;ul&gt;&lt;li&gt; honor APT::Get::AllowUnauthenticated setting and do not
 abort the upgrade if it is set (LP: #195419)&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Tue, 15 Apr 2008 09:08:12 +0000</pubDate>
  <dc:creator>Michael Vogt</dc:creator>
  <author>Michael Vogt</author>
</item>


<item>
  <title>lighttpd, 1.4.18-1ubuntu1.4</title>
  <guid>http://launchpad.net/distros/ubuntu/gutsy/+source/lighttpd,/1.4.18-1ubuntu1.4</guid>
  <link>http://launchpad.net/distros/ubuntu/gutsy/+source/lighttpd,/1.4.18-1ubuntu1.4</link>
  <description>&lt;b&gt;lighttpd (1.4.18-1ubuntu1.4)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; SECURITY UPDATE: (LP: #209627)
&lt;/li&gt;&lt;li&gt; debian/patches/91_CVE-2008-1531.dpatch
&lt;ul&gt;&lt;li&gt; lighttpd 1.4.19 and earlier allows remote attackers to cause a denial
 of service (active SSL connection loss) by triggering an SSL error,
 such as disconnecting before a download has finished, which causes
 all active SSL connections to be lost.
&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt; References
&lt;/li&gt;&lt;li&gt; http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-1531
&lt;/li&gt;&lt;li&gt; http://trac.lighttpd.net/trac/changeset/2136
&lt;/li&gt;&lt;li&gt; http://trac.lighttpd.net/trac/changeset/2139&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Thu, 17 Apr 2008 13:55:46 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>poppler, 0.6-0ubuntu2.2</title>
  <guid>http://launchpad.net/distros/ubuntu/gutsy/+source/poppler,/0.6-0ubuntu2.2</guid>
  <link>http://launchpad.net/distros/ubuntu/gutsy/+source/poppler,/0.6-0ubuntu2.2</link>
  <description>&lt;b&gt;poppler (0.6-0ubuntu2.2)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; SECURITY UPDATE: arbitrary code execution via malicious embedded fonts.&lt;/li&gt;&lt;li&gt; debian/patches/102_embedded-font-fixes.patch: upstream fix and stronger type-checking added.&lt;/li&gt;&lt;li&gt; References CVE-2008-1693&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Thu, 17 Apr 2008 15:56:24 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>koffice, 1:1.6.3-0ubuntu5.2</title>
  <guid>http://launchpad.net/distros/ubuntu/gutsy/+source/koffice,/1:1.6.3-0ubuntu5.2</guid>
  <link>http://launchpad.net/distros/ubuntu/gutsy/+source/koffice,/1:1.6.3-0ubuntu5.2</link>
  <description>&lt;b&gt;koffice (1:1.6.3-0ubuntu5.2)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; SECURITY UPDATE: arbitrary code execution via malicious embedded fonts.
&lt;/li&gt;&lt;li&gt; debian/patches/40_pdf2-embedded-font-fixes.diff: stronger type-checking
 added.
&lt;/li&gt;&lt;li&gt; References
 CVE-2008-1693&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Thu, 17 Apr 2008 16:04:24 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>gnumeric, 1.7.11-1ubuntu3.1</title>
  <guid>http://launchpad.net/distros/ubuntu/gutsy/+source/gnumeric,/1.7.11-1ubuntu3.1</guid>
  <link>http://launchpad.net/distros/ubuntu/gutsy/+source/gnumeric,/1.7.11-1ubuntu3.1</link>
  <description>&lt;b&gt;gnumeric (1.7.11-1ubuntu3.1)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; SECURITY UPDATE: arbitrary code execution via integer overflow in
 Excel spreadsheet HLINK processing.
&lt;/li&gt;&lt;li&gt; plugins/excel/ms-excel-read.c: backported upstream fixes thanks to
 Debian, with an additional bugfix.
&lt;/li&gt;&lt;li&gt; References
 CVE-2008-0668&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Tue, 22 Apr 2008 00:56:05 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>firefox, 2.0.0.14+2nobinonly-0ubuntu0.7.10</title>
  <guid>http://launchpad.net/distros/ubuntu/gutsy/+source/firefox,/2.0.0.14+2nobinonly-0ubuntu0.7.10</guid>
  <link>http://launchpad.net/distros/ubuntu/gutsy/+source/firefox,/2.0.0.14+2nobinonly-0ubuntu0.7.10</link>
  <description>&lt;b&gt;firefox (2.0.0.14+2nobinonly-0ubuntu0.7.10)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; New security/stability upstream release (v2.0.0.14)
&lt;ul&gt;&lt;li&gt; see USN-602-1&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Tue, 22 Apr 2008 01:06:53 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>ca-certificates 20070303-0ubuntu0.7.10.1</title>
  <guid>http://launchpad.net/distros/ubuntu/gutsy/+source/ca-certificates/20070303-0ubuntu0.7.10.1</guid>
  <link>http://launchpad.net/distros/ubuntu/gutsy/+source/ca-certificates/20070303-0ubuntu0.7.10.1</link>
  <description>&lt;b&gt;ca-certificates (20070303-0ubuntu0.7.10.1)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; Fix up generation of the /etc/ssl/certs/ca-certificates.crt
 file for those users who installed the package in a pt_BR
 locale (LP: #153625). A mistake in the translation template
 meant that the choices were not available in this locale,
 and so the file was always empty.
&lt;ul&gt;&lt;li&gt; If you were affected and have not tried to reconfigure this
 package, then the problem should be corrected for you
 automatically.
&lt;/li&gt;&lt;li&gt; If you were affected and have tried to reconfigure the package
 you may be shown a debconf question to allow you to select
 the certificates that you want.
&lt;/li&gt;&lt;li&gt; The only users who were not affected by this bug but may
 be affected by this fix are those who installed in a different
 locale, and then reconfigured the package so that no
 certificates are trusted, and who now run in a pt_BR locale.
 They will have to deselect all of the certificates again.
&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt; In addition to the previous version this version prevents the
 question being asked multiple times for those who appear to
 have been hit by this issue.&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Thu, 24 Apr 2008 10:00:29 +0000</pubDate>
  <dc:creator>James Westby</dc:creator>
  <author>James Westby</author>
</item>


<item>
  <title>cupsys, 1.3.2-1ubuntu7.7</title>
  <guid>http://launchpad.net/distros/ubuntu/gutsy/+source/cupsys,/1.3.2-1ubuntu7.7</guid>
  <link>http://launchpad.net/distros/ubuntu/gutsy/+source/cupsys,/1.3.2-1ubuntu7.7</link>
  <description>&lt;b&gt;cupsys (1.3.2-1ubuntu7.7)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; SECURITY UPDATE: Denial of service and possibly arbitrary code execution
&lt;/li&gt;&lt;li&gt; debian/patches/77_CVE-2008-1722.dpatch: fix for two integer overflows in
 filter/image-png.c. Taken from Debian SVN Head.
&lt;/li&gt;&lt;li&gt; References
 CVE-2008-1722
 LP: #219491
 http://www.cups.org/str.php?L2790&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Mon, 05 May 2008 11:56:29 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>thunderbird, 2.0.0.14+nobinonly-0ubuntu0.7.10.0</title>
  <guid>http://launchpad.net/distros/ubuntu/gutsy/+source/thunderbird,/2.0.0.14+nobinonly-0ubuntu0.7.10.0</guid>
  <link>http://launchpad.net/distros/ubuntu/gutsy/+source/thunderbird,/2.0.0.14+nobinonly-0ubuntu0.7.10.0</link>
  <description>&lt;b&gt;thunderbird (2.0.0.14+nobinonly-0ubuntu0.7.10.0)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; 2.0.0.14 security/stability update (USN-605-1)&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Mon, 05 May 2008 17:55:41 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>xemacs21, 21.4.20-1.1ubuntu0.1</title>
  <guid>http://launchpad.net/distros/ubuntu/gutsy/+source/xemacs21,/21.4.20-1.1ubuntu0.1</guid>
  <link>http://launchpad.net/distros/ubuntu/gutsy/+source/xemacs21,/21.4.20-1.1ubuntu0.1</link>
  <description>&lt;b&gt;xemacs21 (21.4.20-1.1ubuntu0.1)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; SECURITY UPDATE: temporary file race condition in vcdiff
&lt;/li&gt;&lt;li&gt; debian/patches/21_vcdiff-tmp-race.dpatch: update lib-src/vcdiff to use
 mktemp
&lt;/li&gt;&lt;li&gt; References
 CVE-2008-1694&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Mon, 05 May 2008 17:56:59 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>emacs21, 21.4a+1-5ubuntu4.1</title>
  <guid>http://launchpad.net/distros/ubuntu/gutsy/+source/emacs21,/21.4a+1-5ubuntu4.1</guid>
  <link>http://launchpad.net/distros/ubuntu/gutsy/+source/emacs21,/21.4a+1-5ubuntu4.1</link>
  <description>&lt;b&gt;emacs21 (21.4a+1-5ubuntu4.1)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; SECURITY UPDATE: buffer overflow in format function
&lt;/li&gt;&lt;li&gt; debian/patches/fix-format-overflow.diff: fix src/editfns.c to account
 for precision in integer formatting (LP: #174177)
&lt;/li&gt;&lt;li&gt; SECURITY UPDATE: temporary file race condition in vcdiff
&lt;/li&gt;&lt;li&gt; debian/patches/vcdiff-tmp-race.diff: update lib-src/vcdiff to use
 mktemp
&lt;/li&gt;&lt;li&gt; References
 CVE-2007-6109
 CVE-2008-1694&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Mon, 05 May 2008 17:58:17 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>emacs22, 22.1-0ubuntu5.2</title>
  <guid>http://launchpad.net/distros/ubuntu/gutsy/+source/emacs22,/22.1-0ubuntu5.2</guid>
  <link>http://launchpad.net/distros/ubuntu/gutsy/+source/emacs22,/22.1-0ubuntu5.2</link>
  <description>&lt;b&gt;emacs22 (22.1-0ubuntu5.2)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; SECURITY UPDATE: buffer overflow in format function
&lt;/li&gt;&lt;li&gt; debian/patches/fix-format-overflow.diff: fix src/editfns.c to account
 for precision in integer formatting (LP: #174177)
&lt;/li&gt;&lt;li&gt; SECURITY UPDATE: temporary file race condition in vcdiff
&lt;/li&gt;&lt;li&gt; debian/patches/vcdiff-tmp-race.diff: update lib-src/vcdiff to use
 mktemp
&lt;/li&gt;&lt;li&gt; References
 CVE-2007-6109
 CVE-2008-1694&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Mon, 05 May 2008 17:59:31 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>clamav, 0.91.2-3ubuntu2.4</title>
  <guid>http://launchpad.net/distros/ubuntu/gutsy/+source/clamav,/0.91.2-3ubuntu2.4</guid>
  <link>http://launchpad.net/distros/ubuntu/gutsy/+source/clamav,/0.91.2-3ubuntu2.4</link>
  <description>&lt;b&gt;clamav (0.91.2-3ubuntu2.4)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; SECURITY UPDATE: Possible heap corruprion
&lt;/li&gt;&lt;li&gt; Added 31_mew.c-CVE-2008-0728.dpatch
&lt;/li&gt;&lt;li&gt; References: CVE-2008-0728 ( LP: #213500 )&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Mon, 05 May 2008 18:55:52 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>kdelibs, 4:3.5.8-0ubuntu3.4</title>
  <guid>http://launchpad.net/distros/ubuntu/gutsy/+source/kdelibs,/4:3.5.8-0ubuntu3.4</guid>
  <link>http://launchpad.net/distros/ubuntu/gutsy/+source/kdelibs,/4:3.5.8-0ubuntu3.4</link>
  <description>&lt;b&gt;kdelibs (4:3.5.8-0ubuntu3.4)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; SECURITY UPDATE: integer overflow in start_kdeinit. The start_kdeinit
 processing of user-influenceable input is faulty.  A local user
 might be able to send unix signals to other processes, cause
 a denial of service or even possibly execute arbitrary code.
&lt;/li&gt;&lt;li&gt; Add kubuntu_9903_kinit_integer_overflow.diff, edits
 kinit/start_kdeinit.c, patch from upstream KDE
&lt;/li&gt;&lt;li&gt; References
 http://www.kde.org/info/security/advisory-20080426-2.txt
 CVE-2008-1671&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Mon, 05 May 2008 18:58:34 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>realplay 10.0.9-1gutsy1</title>
  <guid>http://launchpad.net/distros/ubuntu/gutsy/+source/realplay/10.0.9-1gutsy1</guid>
  <link>http://launchpad.net/distros/ubuntu/gutsy/+source/realplay/10.0.9-1gutsy1</link>
  <description>&lt;b&gt;realplay (10.0.9-1gutsy1)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; Initial upload to gutsy
&lt;/li&gt;&lt;li&gt; Referenced licenses properly in copyright file
&lt;/li&gt;&lt;li&gt; Removed ad-hoc patch mechanism and replaced with dpatch&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Tue, 06 May 2008 16:48:17 +0000</pubDate>
  <dc:creator>Brian Thomason</dc:creator>
  <author>Brian Thomason</author>
</item>


<item>
  <title>kde4libs, 3.94.0-0ubuntu1.1</title>
  <guid>http://launchpad.net/distros/ubuntu/gutsy/+source/kde4libs,/3.94.0-0ubuntu1.1</guid>
  <link>http://launchpad.net/distros/ubuntu/gutsy/+source/kde4libs,/3.94.0-0ubuntu1.1</link>
  <description>&lt;b&gt;kde4libs (3.94.0-0ubuntu1.1)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; SECURITY UPDATE: KHTML's PNG loader can be tricked into
 overrunning a heap allocated memory buffer by loading a
 specially encoded image.  A remote site could cause a denial of
 service and possibly execute arbitrary code in the context of
 the user.
&lt;/li&gt;&lt;li&gt; Add patch kubuntu_07_khtml_png_loader_memory_overrun.diff from KDE
 upstream, adds extra checks to khtml/imload/decoders/pngloader.cpp
&lt;/li&gt;&lt;li&gt; References
 http://www.kde.org/info/security/advisory-20080426-1.txt
 CVE-2008-1670&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Tue, 06 May 2008 19:57:59 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>hsqldb, 1.8.0.8-1ubuntu1.1</title>
  <guid>http://launchpad.net/distros/ubuntu/gutsy/+source/hsqldb,/1.8.0.8-1ubuntu1.1</guid>
  <link>http://launchpad.net/distros/ubuntu/gutsy/+source/hsqldb,/1.8.0.8-1ubuntu1.1</link>
  <description>&lt;b&gt;hsqldb (1.8.0.8-1ubuntu1.1)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; SECURITY UPDATE: arbitrary Java methods via SQL.
&lt;/li&gt;&lt;li&gt; Add debian/patches/90_method-whitelist.patch: upstream changes backported,
 thanks to Debian.
&lt;/li&gt;&lt;li&gt; References
 CVE-2007-4575&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Tue, 06 May 2008 21:55:18 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>openoffice.org, 1:2.3.0-1ubuntu5.4</title>
  <guid>http://launchpad.net/distros/ubuntu/gutsy/+source/openoffice.org,/1:2.3.0-1ubuntu5.4</guid>
  <link>http://launchpad.net/distros/ubuntu/gutsy/+source/openoffice.org,/1:2.3.0-1ubuntu5.4</link>
  <description>&lt;b&gt;openoffice.org (1:2.3.0-1ubuntu5.4)&lt;/b&gt;&lt;ul&gt;&lt;li&gt;&lt;b&gt; Chris Cheney &lt;/b&gt;
&lt;/li&gt;&lt;li&gt; ooo-build/patches/src680/workspace.fwk82.diff,
 ooo-build/patches/src680/workspace.sjfixes03.diff: fix CVE-2007-5745,
 CVE-2007-5746,CVE-2007-5747 and CVE-2008-0320
&lt;/li&gt;&lt;li&gt; ooo-build/patches/src680/cws-jl85.diff: fix XML signing problem where
 the document can be manipulated so that the signature dialog display a
 false issuer
&lt;/li&gt;&lt;li&gt;&lt;b&gt; Kees Cook &lt;/b&gt;
&lt;/li&gt;&lt;li&gt; ooo-build/patches/src680/workspace.hsql1808.diff: upstream fixes for
 HSQLDB Java method calling (CVE-2007-4575), thanks to Caolan McNamara.&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Tue, 06 May 2008 22:04:22 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>ltsp, 5.0.39.1</title>
  <guid>http://launchpad.net/distros/ubuntu/gutsy/+source/ltsp,/5.0.39.1</guid>
  <link>http://launchpad.net/distros/ubuntu/gutsy/+source/ltsp,/5.0.39.1</link>
  <description>&lt;b&gt;ltsp (5.0.39.1)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; fix CVE-2008-1293 (LP: #227295) that made unauthenticated access to the
 local X server on the client possible.&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Tue, 06 May 2008 22:55:56 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>speex, 1.1.12-3ubuntu0.7.10.1</title>
  <guid>http://launchpad.net/distros/ubuntu/gutsy/+source/speex,/1.1.12-3ubuntu0.7.10.1</guid>
  <link>http://launchpad.net/distros/ubuntu/gutsy/+source/speex,/1.1.12-3ubuntu0.7.10.1</link>
  <description>&lt;b&gt;speex (1.1.12-3ubuntu0.7.10.1)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; SECURITY UPDATE: array index vulnerability (LP: #218652)
&lt;/li&gt;&lt;li&gt; fix for libspeex/speex_header.c to properly validate its input
&lt;/li&gt;&lt;li&gt; References
 CVE-2008-1686&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Thu, 08 May 2008 17:55:32 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>vorbis-tools, 1.1.1-13ubuntu0.1</title>
  <guid>http://launchpad.net/distros/ubuntu/gutsy/+source/vorbis-tools,/1.1.1-13ubuntu0.1</guid>
  <link>http://launchpad.net/distros/ubuntu/gutsy/+source/vorbis-tools,/1.1.1-13ubuntu0.1</link>
  <description>&lt;b&gt;vorbis-tools (1.1.1-13ubuntu0.1)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; SECURITY UPDATE: array index vulnerability (LP: #218652)
&lt;/li&gt;&lt;li&gt; debian/patches/SECURITY_CVE-2008-1686.diff: fix for ogg123/speex_format.c
 to properly validate its input
&lt;/li&gt;&lt;li&gt; References
 CVE-2008-1686&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Thu, 08 May 2008 19:55:09 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>


<item>
  <title>gst-plugins-good0.10, 0.10.6-0ubuntu4.1</title>
  <guid>http://launchpad.net/distros/ubuntu/gutsy/+source/gst-plugins-good0.10,/0.10.6-0ubuntu4.1</guid>
  <link>http://launchpad.net/distros/ubuntu/gutsy/+source/gst-plugins-good0.10,/0.10.6-0ubuntu4.1</link>
  <description>&lt;b&gt;gst-plugins-good0.10 (0.10.6-0ubuntu4.1)&lt;/b&gt;&lt;ul&gt;&lt;li&gt; SECURITY UPDATE: array index vulnerability (LP: #218652)
&lt;/li&gt;&lt;li&gt; debian/patches/04_SECURITY_CVE-2008-1686.patch: fix for
 ext/speex/gstspeexdec.c to properly validate its input
&lt;/li&gt;&lt;li&gt; References
 CVE-2008-1686&lt;/li&gt;&lt;/ul&gt;</description>
  <pubDate>Thu, 08 May 2008 20:55:43 +0000</pubDate>
  <dc:creator>Ubuntu Installer</dc:creator>
  <author>Ubuntu Installer</author>
</item>

  </channel>
</rss>
