Change logs for publicfile-installer source package in Stretch

  • publicfile-installer (0.12-1) unstable; urgency=medium
    
      * New upstream, targeting publicfile (0.52-8).  The publicfile 0.52-8
        Debian packaging comes with improved documentation, an improved
        get-publicfile-docs(1) and some bug fixes.  See
        /u/s/d/publicfile/changelog.Debian.gz for all details.
      * debian/po: Add debconf translations by various contributors.  Thank you,
        tranlators!
        - cs.po: Czech, by Michal Simunek.  Closes: #799055
        - de.po: German, by Chris Leick.  Closes: #799067
        - nl.po: Dutch, by Frans Spiesschaert, with minor modifications by
          Joost van Baal-Ilić.  Closes: #799462
        - pt.po: Portuguese, by Américo Monteiro.  Closes: #799566
        - ru.po: Russian, by Yuri Kozlov. Closes: #799699
        - it.po: Italian, by Beatrice Torracca and the Italian localization team.
          Closes: #799750
        - da.po: Danish, by Joe Hansen.  Closes: #799877
        - fr.po: French, by jean-pierre giraud and the debian-l10n-french
          mailing list contributors.  Closes: #799882
      * debian/templates, debian/control: Fix language, thanks Justin B Rye and
        debian-l10n-english@l.d.o.
    
     -- Joost van Baal-Ilić <email address hidden>  Sun, 18 Dec 2016 21:25:27 +0100
  • publicfile-installer (0.11-1) unstable; urgency=low
    
      * New upstream.  No longer ships install-publicfile, no longer uses /tmp.
        This fixes a serious security issue: a local privilage escalation
        security hole due to insecure use of /tmp. "This [...] package downloads
        the source code for DJB's publicfile, builds it, and then puts the
        output in a predictable location in a world-writable directory, using an
        existing directory of that name if it already exists, then (either
        automatically or by telling the admin to run another script) installs
        whatever happens to be in that directory.  This can be exploited by
        malicious local users to get arbitrary installscripts executed as root."
        Thanks Justin B Rye.  Closes: #795062.
        + debian/templates: adjusted.
        + debian/control: Depends: add sudo.
      * debian/changelog: fix spelling error.
    
     -- Joost van Baal-Ilić <email address hidden>  Sun, 06 Sep 2015 07:23:33 +0200
  • publicfile-installer (0.10-1) unstable; urgency=low
    
      * New upstream, targetting publicfile (0.52-7).
      * Upload to Debian archive.  Closes: #122614.
      * debian/copyright: add one missing copyright statement, add "Source",
        update license on most files from GPL-2 to GPL-3.
      * debian/control: enhance description.
    
     -- Joost van Baal-Ilić <email address hidden>  Wed, 04 Feb 2015 22:46:02 +0100