[DebianGIS-dev] r2915 - in packages/mapserver/branches/lenny/debian: . patches
frankie at alioth.debian.org
frankie at alioth.debian.org
Mon Jul 26 13:54:39 UTC 2010
Author: frankie
Date: 2010-07-26 13:54:34 +0000 (Mon, 26 Jul 2010)
New Revision: 2915
Modified:
packages/mapserver/branches/lenny/debian/changelog
packages/mapserver/branches/lenny/debian/patches/00list
Log:
New security fixes added.
Modified: packages/mapserver/branches/lenny/debian/changelog
===================================================================
--- packages/mapserver/branches/lenny/debian/changelog 2010-07-15 15:03:01 UTC (rev 2914)
+++ packages/mapserver/branches/lenny/debian/changelog 2010-07-26 13:54:34 UTC (rev 2915)
@@ -1,3 +1,12 @@
+mapserver (5.0.3-3+lenny5) stable-security; urgency=high
+
+ * Fix Buffer overflow in msTmpFile function.
+ [http://trac.osgeo.org/mapserver/ticket/3484]
+ * Fix insecure mapserv CGI command-line debug args.
+ [http://trac.osgeo.org/mapserver/ticket/3485]
+
+ -- Alan Boudreault <aboudreault at mapgears.com> Fri, 09 Jul 2010 08:37:43 -0400
+
mapserver (5.0.3-3+lenny4) stable-security; urgency=high
* Fix paths specified in url vulnerabilities.
Modified: packages/mapserver/branches/lenny/debian/patches/00list
===================================================================
--- packages/mapserver/branches/lenny/debian/patches/00list 2010-07-15 15:03:01 UTC (rev 2914)
+++ packages/mapserver/branches/lenny/debian/patches/00list 2010-07-26 13:54:34 UTC (rev 2915)
@@ -7,3 +7,5 @@
04_CVE-2009-0842
05_CVE-2009-0843
06_urlpath
+07_mstmpfile
+08_cl_debug_args
\ No newline at end of file
More information about the Pkg-grass-devel
mailing list