]> andersk Git - libyaml.git/commitdiff
Acknowledge NMU of 0.1.4-3.2
authorAnders Kaseorg <andersk@mit.edu>
Tue, 19 Aug 2014 03:58:02 +0000 (23:58 -0400)
committerAnders Kaseorg <andersk@mit.edu>
Tue, 19 Aug 2014 03:58:02 +0000 (23:58 -0400)
Signed-off-by: Anders Kaseorg <andersk@mit.edu>
1  2 
debian/changelog

index 68e083b8e0db775d907f36ae1fdb3f883085e1ee,3555978cb9650905f6d5f0a3cbc4a94d58bc998d..8ff9a6cba2ee5b70775721889165f77c00b37732
@@@ -1,18 -1,14 +1,30 @@@
 +libyaml (0.1.5-1) UNRELEASED; urgency=medium
 +
 +  * New upstream version 0.1.5.
 +    + Fix CVE-2013-6393: heap-based buffer overflow when parsing YAML
 +      tags.
 +  * Drop upstreamed patches.
 +  * Run tests at build time.
 +  * Bump Standards-Version to 3.9.5 (no changes needed).
 +  * Use dh-autoreconf.
 +  * Use dh-buildinfo.
 +  * Add libyaml-doc package for Doxygen-generated API documentation and
 +    examples.  (Closes: #696821)
++  * Acknowledge NMUs.
 +
 + -- Anders Kaseorg <andersk@mit.edu>  Sun, 23 Feb 2014 21:48:49 -0500
 +
+ libyaml (0.1.4-3.2) unstable; urgency=high
+   * Non-maintainer upload by the Security Team.
+   * Add CVE-2014-2525.patch patch.
+     CVE-2014-2525: Fixes heap overflow in yaml_parser_scan_uri_escapes.
+     The heap overflow is caused by not properly expanding a string before
+     writing to it in function yaml_parser_scan_uri_escapes in scanner.c.
+     (Closes: #742732)
+  -- Salvatore Bonaccorso <carnil@debian.org>  Thu, 27 Mar 2014 06:22:25 +0100
  libyaml (0.1.4-3.1) unstable; urgency=medium
  
    * Non-maintainer upload.
This page took 0.079557 seconds and 5 git commands to generate.