lp://staging/ubuntu/oneiric-security/lightdm
- Get this branch:
- bzr branch lp://staging/ubuntu/oneiric-security/lightdm
Branch merges
Branch information
Recent revisions
- 48. By Marc Deslauriers
-
* SECURITY UPDATE: Guest session arbitrary file deletion (LP: #953044)
- debian/guest-account: Use find/xargs with 0 separators instead of
spaces. Thanks to Martin Pitt for the fix.
- Thanks to Ryan Lortie for reporting this issue.
- CVE-2012-0943 - 47. By Marc Deslauriers
-
* SECURITY UPDATE: file descriptor leak to child processes (LP: #927060)
- debian/patches/ 12_dont- leak-fds. patch: clean up file descriptors in
src/*.c, add tests to tests/*.
- CVE number pending - 46. By Marc Deslauriers
-
* SECURITY UPDATE: file contents disclosure via hard link
- debian/patches/ 04_CVE- 2011-4105. patch: make sure file isn't a symlink
or a hard link before doing the chown on it.
- CVE-2011-4105
* SECURITY UPDATE: file contents disclosure via links (LP: #883865)
- debian/patches/ 05_CVE- 2011-3153. patch: drop privileges before
accessing file.
- CVE-2011-3153 - 45. By Sebastien Bacher
-
* debian/
patches/ 08_correct_ ck_ref. patch:
- backported fix from Mikkel Kamstrup Erlandsen for a refcounting issue
which leads to sessions where unity can't start (lp: #851345) - 44. By Martin Pitt
-
Add debian/
patches/ 00bzr_guest_ session_ wrapper. diff: Add back the guest
session wrapper part that was uploaded in 1.0.0-0ubuntu4. The patch was
correctly merged into trunk, but the 1.0 branch backport missed this
wrapper part and thus broke AppArmor protection entirely. (LP: #849027) - 43. By Robert Ancell
-
* debian/
patches/ 04_language_ not_to_ LANG.patch:
* debian/patches/ 04_dmrc_ set_LANG_ only.patch:
- Replace LANG disabling code with proper fix (LP: #868149)
* debian/patches/ 03_launch_ dbus.patch:
* debian/patches/ 05_gdmflexiserv er_not_ in_PATH. patch:
- Refreshed
* debian/patches/ 06_accounts_ service_ timeout. patch:
- Fix D-Bus timeout when accounts service not installed (LP: #866035)
* debian/patches/ 07_long_ password_ crash.patch:
- Fix crash with long passwords (LP: #817186) - 42. By Michael Terry
-
* debian/
patches/ 05_gdmflexiserv er_not_ in_PATH. patch:
- Make sure to insert our own utility path into PATH after PAM
sets PATH, not before. This ensures gdmflexiserver is present
in PATH and can be found by gnome-screensaver, gnome-shell, etc. - 41. By Gunnar Hjalmarsson
-
debian/
patches/ 04_language_ not_to_ LANG.patch:
Locale names based on AccountsService's "Language" key may not
go to $LANG, as that property is a language name, not a locale.
(LP: #864618). - 40. By Robert Ancell
-
* New upstream release:
- GTK greeter now remembers last user
- GTK greeter now initializes i18n (LP: #862427)
- Start authentication for automatically selected user in GTK greeter
- Link liblightdm-qt against QtGui
- Fix liblightdm-qt crashing when face images are installed (LP: #850095)
- Set correct permissions on session log files (LP: #863119)
- Prefer a locale with a codeset over one without for setting LANG
(LP: #864618)
- Introduce a lightdm-guest-session- wrapper session command which MAC
systems like AppArmor and SELinux can use for attaching a restrictive
policy to guest sessions.
- Provide an AppArmor profile for guest session lockdown.
* debian/patches/ 01_guest_ session_ lockdown. patch:
- Applied upstream - 39. By Martin Pitt
-
* Add 01_guest_
session_ lockdown. patch: Lock down guest session with an
AppArmor profile. This uses the very same approach as gdm-guest-session,
and copies the profile from it. (LP: #849027)
* 03_launch_dbus.patch: Refresh.
* debian/lightdm. install: Install AppArmor profile.
Branch metadata
- Branch format:
- Branch format 7
- Repository format:
- Bazaar repository format 2a (needs bzr 1.16 or later)
- Stacked on:
- lp://staging/ubuntu/precise/lightdm