[SCM] KDE Development Platform Libraries module packaging branch, kde4.4, updated. debian/4.4.5-2+squeeze1-8-g6f28faf

José Manuel Santamaría Lema santa-guest at alioth.debian.org
Thu Apr 14 21:47:21 UTC 2011


The following commit has been merged in the kde4.4 branch:
commit 6f28fafab93b4656ef5a18b33515b233a1ad520e
Merge: e302aca95b2ba1ffaa4b98744a1555d1fcdc105e 2bfb1e4752f0fe947d8509e8ab94f5fb7e4b0e07
Author: José Manuel Santamaría Lema <panfaust at gmail.com>
Date:   Thu Apr 14 22:52:19 2011 +0200

    Merge branch 'squeeze' into kde4.4
    
    Conflicts:
    	debian/changelog
    	debian/patches/series

 debian/changelog                                   |   10 +++
 debian/patches/cve_2010_3170_cn_wildcards.diff     |   84 ++++++++++++++++++++
 .../patches/cve_2011_1094_ssl_verify_hostname.diff |   51 ++++++++++++
 debian/patches/cve_2011_1168_konqueror_xss.diff    |   19 +++++
 debian/patches/series                              |    3 +
 5 files changed, 167 insertions(+), 0 deletions(-)

diff --cc debian/changelog
index 577ab3c,dc8817f..3c359ff
--- a/debian/changelog
+++ b/debian/changelog
@@@ -1,10 -1,14 +1,20 @@@
 -kde4libs (4:4.4.5-2+squeeze2) UNRELEASED; urgency=low
 +kde4libs (4:4.4.5-3~pre) UNRELEASED; urgency=low
  
++  [ Sune Vuorela ]
 +  * Fix build failures
 +    - QDBUS_EXPORT => Q_DBUS_EXPORT (Closes: #618111)
 +    - libqtwebkit-dev build-dep
 +
++  [ José Manuel Santamaría Lema ]
+   * Fix CVE-2011-1168 (Konqueror partially universal XSS in error pages) by
+     cve_2011_1168_konqueror_xss.diff.
+   * Fix CVE-2010-3170 (browser wildcard cerficate validation weakness) for
+     Konqueror by cve_2010_3170_cn_wildcards.diff.
+   * Fix CVE-2011-1094 (kdelibs does not properly verify that the server hostname
+     matches the Common Name of the Subject of an X.509 certificate if that CN is
+     an IP address) by cve_2011_1094_ssl_verify_hostname.diff.
+ 
 - -- José Manuel Santamaría Lema <panfaust at gmail.com>  Tue, 12 Apr 2011 21:16:20 +0200
 + -- Sune Vuorela <sune at debian.org>  Tue, 15 Mar 2011 23:05:06 +0100
  
  kde4libs (4:4.4.5-2+squeeze1) stable-proposed-updates; urgency=low
  
diff --cc debian/patches/series
index 7c59642,d9a33e2..508fd22
--- a/debian/patches/series
+++ b/debian/patches/series
@@@ -18,4 -18,6 +18,7 @@@
  29_hurd_support.diff
  30_kfileshare_kdesu_fileshareset.diff
  31_relax_plugin_kde_version_check.diff
 +qdbus_exports_changed.diff
+ cve_2011_1168_konqueror_xss.diff
+ cve_2010_3170_cn_wildcards.diff
+ cve_2011_1094_ssl_verify_hostname.diff

-- 
KDE Development Platform Libraries module packaging



More information about the pkg-kde-commits mailing list