Merge lintian 2.5.12 (main) from Debian experimental (main)

Bug #1173896 reported by Felix Geyer
8
This bug affects 1 person
Affects Status Importance Assigned to Milestone
lintian (Ubuntu)
Fix Released
Wishlist
Unassigned

Bug Description

Please consider sponsoring:

lintian (2.5.12ubuntu1) saucy; urgency=low

  * Sync from Debian experimental and drop all previous Ubuntu changes,
    applied upstream.
    - Fixes CVE-2013-1429: path traversal/information disclosure.
      (LP: #1169636)
  * Cherry-pick from upstream:
    - vendors/ubuntu/main/data/changes-file/known-dists:
      + [NT] Add "saucy" as known Ubuntu distribution. Thanks to
        Iain Lane for the report.

CVE References

Revision history for this message
Felix Geyer (debfx) wrote :

Attached is the debdiff to Debian.

The package can be downloaded from
http://people.ubuntu.com/~debfx/lintian_2.5.12ubuntu1.dsc

Revision history for this message
Felix Geyer (debfx) wrote :

This is still blocked by the libtest-perl-critic-perl MIR: bug #1173892

Revision history for this message
Felix Geyer (debfx) wrote :

The MIR has been approved.

Benjamin Drung (bdrung)
Changed in lintian (Ubuntu):
importance: Undecided → Wishlist
status: New → Fix Committed
Revision history for this message
Launchpad Janitor (janitor) wrote :
Download full text (17.2 KiB)

This bug was fixed in the package lintian - 2.5.12ubuntu1

---------------
lintian (2.5.12ubuntu1) saucy; urgency=low

  * Sync from Debian experimental and drop all previous Ubuntu changes,
    applied upstream. (LP: #1173896)
    - Fixes CVE-2013-1429: path traversal/information disclosure.
      (LP: #1169636)
  * Cherry-pick from upstream:
    - vendors/ubuntu/main/data/changes-file/known-dists:
      + [NT] Add "saucy" as known Ubuntu distribution. Thanks to
        Iain Lane for the report.

lintian (2.5.12) experimental; urgency=medium

  * Summary of tag changes:
    + Added:
      - ambiguous-paragraph-in-dep5-copyright
      - binary-file-built-without-LFS-support
      - debian-tests-control-is-not-a-regular-file
      - debian-tests-control-uses-national-encoding
      - debug-file-with-no-debug-symbols
      - desktop-entry-lacks-keywords-entry
      - dir-or-file-in-build-tree
      - dir-or-file-in-etc-opt
      - dir-or-file-in-home
      - file-name-is-not-valid-UTF-8
      - font-adobe-copyrighted-fragment-no-credit
      - font-package-not-multi-arch-foreign
      - illegal-runtime-test-name
      - inconsistent-testsuite-field
      - license-problem-gfdl-invariants
      - license-problem-gfdl-invariants-empty
      - menu-icon-uses-relative-path
      - missing-runtime-test-file
      - missing-runtime-tests-field
      - package-contains-broken-symlink-wildcard
      - package-contains-unsafe-symlink
      - runtime-test-file-is-not-a-regular-file
      - source-contains-unsafe-symlink
      - unknown-runtime-tests-feature
      - unknown-runtime-tests-field
      - unknown-runtime-tests-restriction
      - unknown-testsuite
      - vcs-field-bitrotted
      - vcs-git-uses-invalid-user-uri
      - zip-parse-error
    + Removed:
      - unneeded-build-dep-on-quilt

  * checks/*:
    + [NT] Avoid following unsafe symlinks. (CVE-2013-1429)
  * checks/binaries{,.desc}:
    + [NT] Accept libx32 as a bi-arch directory.
    + [NT] Correct reference policy reference. Thanks to
      Samuel Bronson for the correction. (Closes: #698234)
    + [NT] Detect debug ELF binaries with no debug symbols.
      Thanks to Nelson A. de Oliveira for the report.
      (Closes: #668437)
    + [NT] Check for binaries built without LFS. This can
      only be checked for 32bit binaries as 64bit binaries
      have LFS by definition. Thanks to Guillem Jover for
      the report and patches. (Closes: #670963)
    + [NT] Apply patch from Samuel Bronson to bump severity
      (but decrease certainty) of the "not linked against
      libc" tags. (Closes: #698720)
  * checks/copyright:
    + [NT] Apply patch from Evgeni Golov to avoid false
      positive tag when the MPL-2.0 license appears in the
      copyright file. (See #626454)
  * checks/cruft{,.desc}:
    + [NT] Do not emit the license-problem-json-evil tag for
      non-free packages.
    + [NT] Apply patch from Bastien Roucariès to catch GFDL
      licenses with invariants (etc.). (Closes: #695967)
    + [NT] Correct description of an autotools tag. Thanks
      to Alberto Garcia and Timo Juhani Lindfors for the
      report and patch. (Closes: #703490)
    + [NT] Check for unsafe...

Changed in lintian (Ubuntu):
status: Fix Committed → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.