Branches for Intrepid

Name Status Last Modified Last Commit
lp://staging/ubuntu/intrepid/kdelibs 2 Mature 2010-02-22 22:41:34 UTC
146. Don't install launchpad.png icon, now...

Author: Jonathan Riddell
Revision Date: 2008-10-06 15:39:39 UTC

Don't install launchpad.png icon, now in kdelibs5-data

lp://staging/ubuntu/intrepid-security/kdelibs 2 Mature 2010-02-22 22:41:43 UTC
149. [ Jamie Strandboge ] * SECURITY UPDAT...

Author: Jamie Strandboge
Revision Date: 2009-12-07 15:09:53 UTC

[ Jamie Strandboge ]
* SECURITY UPDATE: fix buffer overflow when converting string to
  float
  - debian/patches/security_05_CVE-2009-0689.diff: adjust Kmax to handle
    large field numbers in kjs/dtoa.cpp
  - CVE-2009-0689

[ Jonathon Riddell ]
* SECURITY UPDATE: uncontrolled XMLHTTPRequest vulnerability
  - Ark and KMail performs insufficient validation which leads to
    specially crafted archive files, using unknown MIME types, to be
    rendered using a KHTML instance, this can trigger uncontrolled
    XMLHTTPRequests to remote sites
  - Add debian/patches/security_05_XMLHttpRequest_vulnerability.diff,
    restricts xmlhttprequest to http protocols only
  - http://www.kde.org/info/security/advisory-20091027-1.txt
  - oCert: #2009-015 http://www.ocert.org/advisories/ocert-2009-015.html
  - CVE-2009-XXXX

lp://staging/ubuntu/intrepid-updates/kdelibs 2 Mature 2010-02-22 22:42:05 UTC
149. [ Jamie Strandboge ] * SECURITY UPDAT...

Author: Jamie Strandboge
Revision Date: 2009-12-07 15:09:53 UTC

[ Jamie Strandboge ]
* SECURITY UPDATE: fix buffer overflow when converting string to
  float
  - debian/patches/security_05_CVE-2009-0689.diff: adjust Kmax to handle
    large field numbers in kjs/dtoa.cpp
  - CVE-2009-0689

[ Jonathon Riddell ]
* SECURITY UPDATE: uncontrolled XMLHTTPRequest vulnerability
  - Ark and KMail performs insufficient validation which leads to
    specially crafted archive files, using unknown MIME types, to be
    rendered using a KHTML instance, this can trigger uncontrolled
    XMLHTTPRequests to remote sites
  - Add debian/patches/security_05_XMLHttpRequest_vulnerability.diff,
    restricts xmlhttprequest to http protocols only
  - http://www.kde.org/info/security/advisory-20091027-1.txt
  - oCert: #2009-015 http://www.ocert.org/advisories/ocert-2009-015.html
  - CVE-2009-XXXX

13 of 3 results