lp://staging/ubuntu/intrepid-updates/mapserver

Created by James Westby and last modified
Get this branch:
bzr branch lp://staging/ubuntu/intrepid-updates/mapserver
Members of Ubuntu branches can upload to this branch. Log in for directions.

Branch merges

Related bugs

Related blueprints

Branch information

Owner:
Ubuntu branches
Review team:
Ubuntu Development Team
Status:
Mature

Recent revisions

22. By Alan Boudreault

* SECURITY UPDATE: stack-based buffer overflow (LP: #398814)
  - debian/patches/01_CVE-2009-0839.dpatch: Apply a regex pattern
    to limit an id's value.
  - CVE-2009-0839
* SECURITY UPDATE: heap-based buffer underflow (LP: #398814)
  - debian/patches/02_CVE-2009-840-CVE-2009-2281.dpatch: Add validation for
    a post request and the content-length.
  - CVE-2009-0840, CVE-2009-2281
* SECURITY UPDATE: relative file path writing (LP: #398814)
  - debian/patches/03_CVE-2009-0841.dpatch: Limit the buffer size.
  - CVE-2009-0841
* SECURITY UPDATE: file data leakage (LP: #398814)
  - debian/patches/04_CVE-2009-0842.dpatch: Set MAP/SYMBOLSET tag as mandatory.
  - CVE-2009-0842
* SECURITY UPDATE: file existence leakage (LP: #398814)
  - debian/patches/05_CVE-2009-0843.dpatch: Add regex validation for the file extension.
  - CVE-2009-0843
* SECURITY UPDATE: paths specified in url vulnerabilities.
  - debian/patches/06_urlpath.dpatch: Disable the variable overwriting from URL of a
    few variables.
  - [http://trac.osgeo.org/mapserver/ticket/1836]

21. By Francesco Paolo Lovergine

Turning off optimization in debian/rules due to serious breakage of mapserver
with GCC 4.3. (closes: #487679)

20. By Francesco Paolo Lovergine

* New upstream release, with a good deal of fixes.
* Changed a bit clean-first-build to make lintian happy about
  debian-rules-ignores-make-clean-error warning.

19. By Francesco Paolo Lovergine

The setup.py script is not able to manage properly static libraries flavor
for AGG now used embedded in mapserver. The trick is explicitly linking by
manipulating the mapscriptvars file before running setup.py. That rendered
python-mapscript unusable.
(closes: #483400)

18. By Francesco Paolo Lovergine

* Added embedded AGG 2.4 for use with mapserver. This is a BSD-licensed
  version mainly functionally identical with current 2.5. See debian/AGG
  for additional maintainer information about the AGG integration.
  (closes: #448198)
* Added build-deps for AGG: libsdl1.2-dev, libfreetype6-dev, libx11-dev.
* Added build-dep on sharutils for AGG uuencoded distfile.
* Fixed maintainer scripts for erroneous if expressions
  (closes: #463888)
* Policy bumped to 3.7.3 (no changes).
* Added Vcs-* fields to debian/control.
* Added FastCGI support.
  (closes: #468172)

17. By Fabio Tranchitella

* debian/php5-mapscript.postinst: fixed a typo. (Closes: #446985)
* debian/patches/20_php_build.dpatch: removed. (Closes: #447814)
* debian/po/gl.po: added. (Closes: #447939)
* debian/po/fr.po: added. (Closes: #448821)

16. By Fabio Tranchitella

debian/rules, debian/controls: new patch for the ruby bindings, which
follows the ruby policy draft.

15. By Andreas Putzo

[ Andreas Putzo ]
* New upstream release.
  - Fixed XSS vulnerabilities.
    [http://trac.osgeo.org/mapserver/ticket/2256]
  - Fixed possible buffer overflow in template processing.
    [http://trac.osgeo.org/mapserver/ticket/2252]
  (Closes: #439346)
* Added myself to Uploaders.
* Debconf templates and debian/control reviewed by the debian-l10n-
  english team as part of the Smith review project. Closes: #433710
* Debconf translation updates:
  - Galician. Closes: #434326
  - Tamil. Closes: #434401
  - Russian. Closes: #434406
  - Portuguese. Closes: #434438
  - German. Closes: #434653
  - Vietnamese. Closes: #434758
  - French. Closes: #435933
  - Czech. Closes: #436280
  - Dutch. Closes: #436853

14. By Fabio Tranchitella

[ Francesco Paolo Lovergine ]
* New upstream release.
  (closes: #412836)
* Fixed PHP case in long descriptions.
  (closes: #425987)

[ Fabio Tranchitella ]
* debian/README.Debian: added a note about PHP and FCGI support.
  (Closes: #425571)

13. By Michael Bienia

Rebuild for the libcurl4 -> libcurl3 back transition.

Branch metadata

Branch format:
Branch format 7
Repository format:
Bazaar repository format 2a (needs bzr 1.16 or later)
Stacked on:
lp://staging/ubuntu/karmic/mapserver
This branch contains Public information 
Everyone can see this information.

Subscribers