]> andersk Git - libyaml.git/blobdiff - debian/changelog
Merge tag 'upstream/0.1.6' into debian
[libyaml.git] / debian / changelog
index 51804abdf3aeb8e3bce2401327d02236bc86f5cc..8ff9a6cba2ee5b70775721889165f77c00b37732 100644 (file)
@@ -1,11 +1,56 @@
-libyaml (0.1.4-2) UNRELEASED; urgency=low
+libyaml (0.1.5-1) UNRELEASED; urgency=medium
+
+  * New upstream version 0.1.5.
+    + Fix CVE-2013-6393: heap-based buffer overflow when parsing YAML
+      tags.
+  * Drop upstreamed patches.
+  * Run tests at build time.
+  * Bump Standards-Version to 3.9.5 (no changes needed).
+  * Use dh-autoreconf.
+  * Use dh-buildinfo.
+  * Add libyaml-doc package for Doxygen-generated API documentation and
+    examples.  (Closes: #696821)
+  * Acknowledge NMUs.
+
+ -- Anders Kaseorg <andersk@mit.edu>  Sun, 23 Feb 2014 21:48:49 -0500
+
+libyaml (0.1.4-3.2) unstable; urgency=high
+
+  * Non-maintainer upload by the Security Team.
+  * Add CVE-2014-2525.patch patch.
+    CVE-2014-2525: Fixes heap overflow in yaml_parser_scan_uri_escapes.
+    The heap overflow is caused by not properly expanding a string before
+    writing to it in function yaml_parser_scan_uri_escapes in scanner.c.
+    (Closes: #742732)
+
+ -- Salvatore Bonaccorso <carnil@debian.org>  Thu, 27 Mar 2014 06:22:25 +0100
+
+libyaml (0.1.4-3.1) unstable; urgency=medium
+
+  * Non-maintainer upload.
+  * Drop libyaml-indent-column-overflow-v2.patch patch.
+    This patch causes additional regressions on simple YAML files.
+  * Add libyaml-guard-against-overflows-in-indent-and-flow_level.patch patch.
+    Add upstream's patch to guard against overflows in indent and
+    flow_level. (Closes: #738587)
+
+ -- Salvatore Bonaccorso <carnil@debian.org>  Thu, 13 Feb 2014 07:51:58 +0100
+
+libyaml (0.1.4-3) unstable; urgency=high
+
+  * Fix CVE-2013-6393: heap-based buffer overflow when parsing YAML tags.
+    (Closes: #737076)
+
+ -- Anders Kaseorg <andersk@mit.edu>  Wed, 29 Jan 2014 20:11:48 -0500
+
+libyaml (0.1.4-2) unstable; urgency=low
 
   * Remove extra libyaml-0.so symlink from libyaml-dev.
   * Bump Debhelper compat level to 9.
   * Support multiarch.  (Closes: #653748) (LP: #905630)
   * Use 3.0 (quilt) source format.
 
- -- Anders Kaseorg <andersk@mit.edu>  Fri, 23 Dec 2011 20:35:55 -0500
+ -- Anders Kaseorg <andersk@mit.edu>  Fri, 30 Dec 2011 17:14:52 -0500
 
 libyaml (0.1.4-1) unstable; urgency=low
 
This page took 0.060695 seconds and 4 git commands to generate.