Format: 1.8 Date: Mon, 07 Dec 2009 17:42:13 +0000 Source: kdelibs Binary: kdelibs kdelibs-data kdelibs4c2a kdelibs4-dev kdelibs-dbg Architecture: all i386_translations i386 Version: 4:3.5.10.dfsg.1-2.1ubuntu3 Distribution: lucid Urgency: low Maintainer: Ubuntu/i386 Build Daemon Changed-By: Jonathan Riddell Description: kdelibs - core libraries from the official KDE release kdelibs-data - core shared data for all KDE applications kdelibs-dbg - debugging symbols for kdelibs kdelibs4-dev - development files for the KDE core libraries kdelibs4c2a - core libraries and binaries for all KDE applications Changes: kdelibs (4:3.5.10.dfsg.1-2.1ubuntu3) lucid; urgency=low . * SECURITY UPDATE: uncontrolled XMLHTTPRequest vulnerability - Ark and KMail performs insufficient validation which leads to specially crafted archive files, using unknown MIME types, to be rendered using a KHTML instance, this can trigger uncontrolled XMLHTTPRequests to remote sites - Add debian/patches/security_05_XMLHttpRequest_vulnerability.diff, restricts xmlhttprequest to http protocols only - http://www.kde.org/info/security/advisory-20091027-1.txt - oCert: #2009-015 http://www.ocert.org/advisories/ocert-2009-015.html - CVE n/a Checksums-Sha1: 1c7eeacca83b9e36f0facff7da35c68e059ff44d 2266 kdelibs_3.5.10.dfsg.1-2.1ubuntu3_all.deb bf63669f6cc9610b8e35b5da3ad277009ff2c987 176051 kdelibs_3.5.10.dfsg.1-2.1ubuntu3_i386_translations.tar.gz 7d80720e468bd27b001f7ed1d857355190a13f82 7054774 kdelibs-data_3.5.10.dfsg.1-2.1ubuntu3_all.deb 886eaed8f198a294d4397d1a46f6713b9282bf0f 9935026 kdelibs4c2a_3.5.10.dfsg.1-2.1ubuntu3_i386.deb 5b214f060b7b083fdd9a447115ff87162a94c7be 1398814 kdelibs4-dev_3.5.10.dfsg.1-2.1ubuntu3_i386.deb af1c2b7bff8fc2d36492bb14b23805de6b83f3e6 26376932 kdelibs-dbg_3.5.10.dfsg.1-2.1ubuntu3_i386.deb Checksums-Sha256: ef501ba7fcc0dc50e49e8d16dd6296d0858e97b74dbfcbb09d1ed6500d4a2721 2266 kdelibs_3.5.10.dfsg.1-2.1ubuntu3_all.deb 39bba0c0362f2a1d7a3f2d79989e9308b636e2c40ebb836a6a58a2bb9388795d 176051 kdelibs_3.5.10.dfsg.1-2.1ubuntu3_i386_translations.tar.gz d61815669f7b87326d9afe3c11c2b335619ec02236e75f60c8818054bcf4c10f 7054774 kdelibs-data_3.5.10.dfsg.1-2.1ubuntu3_all.deb b695fb2358768691cfd9d4f1e6d088eaffa5294308f4538ded36196fac0d5cd9 9935026 kdelibs4c2a_3.5.10.dfsg.1-2.1ubuntu3_i386.deb 42b8ea63dfde351aa093576866ab63b3cb3010e81b55e31a94b24c938956dc6a 1398814 kdelibs4-dev_3.5.10.dfsg.1-2.1ubuntu3_i386.deb a35cbf0365f8a94f7c830d1b56eb2a5de380e2ff173253820c35e70975e3a97b 26376932 kdelibs-dbg_3.5.10.dfsg.1-2.1ubuntu3_i386.deb Files: f14b0b4f363e24d21a16e287fe496cb9 2266 libs optional kdelibs_3.5.10.dfsg.1-2.1ubuntu3_all.deb db82f6a696fc2499b0ed808f53cad06d 176051 raw-translations - kdelibs_3.5.10.dfsg.1-2.1ubuntu3_i386_translations.tar.gz 987ad1a4ecf26366720d15fcd93f34fe 7054774 libs optional kdelibs-data_3.5.10.dfsg.1-2.1ubuntu3_all.deb 6629a8b55adaada7daba7001fb89225e 9935026 libs optional kdelibs4c2a_3.5.10.dfsg.1-2.1ubuntu3_i386.deb d8f2cfa14b35ea712b051d63b526a49a 1398814 libdevel optional kdelibs4-dev_3.5.10.dfsg.1-2.1ubuntu3_i386.deb d5a4da7c5fcb5ff45c3a44aa3de0e97e 26376932 libdevel extra kdelibs-dbg_3.5.10.dfsg.1-2.1ubuntu3_i386.deb Original-Maintainer: Debian Qt/KDE Maintainers