Change logs for amarok source package in Hardy

  • amarok (2:1.4.9.1-0ubuntu3.2) hardy-security; urgency=low
    
      * SECURITY UPDATE: integer overflows allow remote attackers to execute
        arbitrary code via an Audible Audio (.aa) file (LP: #318555)
        - debian/patches/security_audible_tags.diff fix integer overflow while
          reading audible aa file tags. Based on upstream patch.
        - http://websvn.kde.org/?view=rev&revision=908415
        - http://www.trapkit.de/advisories/TKADV2009-002.txt
        - CVE-2009-0135
        - CVE-2009-0136
    
     -- Harald Sitter <email address hidden>   Mon, 19 Jan 2009 22:13:53 +0100
  • amarok (2:1.4.9.1-0ubuntu3.1) hardy-security; urgency=low
    
      * SECURITY UPDATE: Insecure creation of magnatune temp files
      * Added kubuntu_99_security_mangatune_file_creator.diff patching
        amarok/src/magnatunebrowser/magnatunebrowser.cpp and
        amarok/src/magnatunebrowser/magnatunebrowser.h. Creates temp files
        correctly. From upstream.
      * References
        http://secunia.com/advisories/31418/
        http://www.securityfocus.com/bid/30662
        http://websvn.kde.org/?view=rev&revision=846626
        http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=494765
        CVE-2008-3699
    
     -- Jonathan Thomas (The man) <email address hidden>   Thu, 14 Aug 2008 14:11:21 -0400
  • amarok (2:1.4.9.1-0ubuntu3) hardy; urgency=low
    
      * Added kdebase-kio-plugins as a recommened package
    
     -- Jonathan Aquilina <email address hidden>   Tue, 15 Apr 2008 14:24:23 +0200
  • amarok (2:1.4.9.1-0ubuntu2) hardy; urgency=low
    
      [ Daniel Hahler]
      * debian/patches/kubuntu_08_add_lastfm_recommended_radio.diff:
        Add lastfm recommended radio station (LP: #103227)
      * debian/patches/kubuntu_09_audio_mimetypes.diff:
        - Add mimetypes audio/flac and audio/ogg (LP: #201291)
    
      [ Harald Sitter ]
      * Unbreak manual media device configuration by enhancing
        kubuntu_08_luks_device_detection.diff (LP: #207704)
    
     -- Harald Sitter <email address hidden>   Sat, 12 Apr 2008 13:47:12 +0200
  • amarok (2:1.4.9.1-0ubuntu1) hardy; urgency=low
    
      * Upstream patch release
    
     -- Jonathan Riddell <email address hidden>   Thu, 10 Apr 2008 23:07:12 +0100
  • amarok (2:1.4.9-0ubuntu1) hardy; urgency=low
    
      * New upstream release
    
     -- Harald Sitter <email address hidden>   Wed, 09 Apr 2008 13:09:03 +0200
  • amarok (2:1.4.8-0ubuntu5) hardy; urgency=low
    
      * Added kubuntu_08_luks_device_detection.diff to ajust Amarok's
        media device detection to properly work with kdebase's
        LUKS patch kubuntu_9913_kiomedialuks.diff) (LP: #186384)
    
     -- Harald Sitter <email address hidden>   Tue, 18 Mar 2008 01:10:01 +0100
  • amarok (2:1.4.8-0ubuntu4) hardy; urgency=low
    
      * Update install-mp3 to correctly error when something goes wrong
    
     -- Jonathan Riddell <email address hidden>   Thu, 13 Mar 2008 13:11:08 +0000
  • amarok (2:1.4.8-0ubuntu3) hardy; urgency=low
    
      [ Sven Boden ]
      * Fix for bug "187406: Amarok install-mp3 fails silently" (LP #187406)
    
      [ Sarah Hobbs ]
      * Sponsored upload.  (Closes LP: #187406)
      * Reworked patch to avoid setting absolute paths (eg /usr/bin/kdesu)
    
     -- Sarah Hobbs <email address hidden>   Wed, 12 Mar 2008 00:50:22 +1100
  • amarok (2:1.4.8-0ubuntu2) hardy; urgency=low
    
      * Fix install-mp3 installation path (LP: #179624)
    
     -- Guillaume Martres <email address hidden>   Mon, 31 Dec 2007 11:50:29 +0100
  • amarok (2:1.4.8-0ubuntu1) hardy; urgency=low
    
      * New upstream release.
      * Removed kubuntu_05_utf8_to_mtp_devices_fix.diff (applied upstream).
      * Removed kubuntu_06_fix_amarok_freeze_installing_mp3.diff (applied upstream).
      * Removed proxy_lyrics.diff (applied upstream).
      * Removed overrides/ and it's content since there is no amarok-arts anymore.
      * Removed amarok-gstreamer.install since there is no amarok-gstreamer anymore.
      * Changed Standards-Version to 3.7.3.
      * Moved "Homepage" from Description stanza to the source section.
    
     -- Harald Sitter <email address hidden>   Mon, 17 Dec 2007 16:19:44 +0100
  • amarok (2:1.4.7-2ubuntu5) hardy; urgency=low
    
      * build without the libkerma-dev build dpendancy also ( realy fixed this
        upload )
    
     -- Brandon Holtsclaw <email address hidden>   Mon, 10 Dec 2007 01:56:48 -0600
  • amarok (2:1.4.7-2ubuntu4) hardy; urgency=low
    
      * build with --without-libkarma, as it seems to be default if left blank.
    
     -- Brandon Holtsclaw <email address hidden>   Sat, 08 Dec 2007 09:49:20 -0600
  • amarok (2:1.4.7-2ubuntu3) hardy; urgency=low
    
      * removed --with-libkarma, libkarma{0,-dev} is not in Main yet.
    
     -- Brandon Holtsclaw <email address hidden>   Wed, 05 Dec 2007 23:47:20 -0600
  • amarok (2:1.4.7-2ubuntu2) hardy; urgency=low
    
      * Rebuild for libmtp6 -> libmtp7 transition
    
     -- Jonathan Riddell <email address hidden>   Tue, 04 Dec 2007 14:01:22 +0000
  • amarok (2:1.4.7-2ubuntu1) hardy; urgency=low
    
      * Merge with Debian, remaining changes in debian/KUBUNTU-DEBIAN-DIFFERENCES
    
    amarok (1.4.7-2) UNRELEASED; urgency=low
    
      * Build against libgpod-nogtk-dev.
    
    amarok (1.4.7-1) unstable; urgency=low
    
      * The "Are you breaking up with me?" release.
    
    amarok (1.4.6-1) unstable; urgency=low
    
      * New upstream version packaged.
    
      * Drop magnatune_CVE-2006-6980.diff; a (better) fix was applied upstream.
    
    amarok (1.4.5-5) unstable; urgency=low
    
      * Rebuild against libtunepimp 0.5; change Build-Depends from libtunepimp3-dev
        to libtunepimp-dev. (Closes: #425884)
    
    amarok (1.4.5-4) unstable; urgency=low
    
      * Upload to unstable.  (Closes: #421920)
    
      * Remove build-dependency on dpkg-dev (the version in stable groks
        ${binary:Version}), and drop version requirement on debhelper and
        libtag1-dev as well.
    
      * Drop the changes made to remove circular dependencies.  (Reopens: #368485,
        closes: #415484, #412464)
    
      * Add patch to fix FTBFS with gcc-4.3.  (Closes: #417684)
    
      * Use ${binary:Version} instead of ${source:Version}.
    
      * Add XS-VCS-Bzr field.
    
      * Add watch file, and adjust download URL on debian/copyright.
    
    amarok (1.4.5-3) experimental; urgency=low
    
      * Add support for devices using MTP, build-dep on libmtp-dev added.
        (Closes: #405399)
      * Add support for karma devices, build-dep on libkarma-dev added.
        (Closes: #400801)
      * Added patch fixing CVE-2006-6980: amarok magnatune unsafe shell.
        (Closes: #410850)
    
    amarok (1.4.5-2) experimental; urgency=low
    
      * iPod support is back. Added versioned build-dep on libgpod-dev (>=0.4.2).
        (Closes: #409985)
      * Add patch to add the "Queue Track" functionality to the Amarok DCOP API:
        queuemedia.patch. Patch by Isaac Clerencia <email address hidden>
      * Add patch to allow amarok get lyrics via http proxy with authentication.
        Thanks to Filipe Lautert <email address hidden>. (Closes: #409568)
      * Added versioned dep on amarok-engines | amarok-engine, thanks to Andreas
        Pakulat for pointing this. (Closes: #409996).
    
    amarok (1.4.5-1) experimental; urgency=low
    
      * New upstream release:
        - Remove patches merged by upstream: invoke_browser, sparc-asm, magnatune,
          kde134333_negative_length_fix, revert-fix-for-bug-116127.
      * The XMMS visualization interface has been removed by upstream:
        - Remove xmms-dev build-dep.
        - amarok's description updated.
        - update amarok.install/rules.
      * iPod support temporarily dropped. (It needs libgpod >= 0.4.2, which is not
        yet in Debian).
    
    amarok (1.4.4-4) unstable; urgency=high
    
      * Include final version of the magnatune.patch and really apply it.
    
    amarok (1.4.4-3) unstable; urgency=high
    
      * Edited patch magnatune.patch fixing CVE-2006-6980: amarok magnatune
        unsafe shell. (Closes: #410850).
      	The reference to the ruby scripts pointed in the bug report, is a problem
        that was already solved in amarok 1.4.4.
      * Add dep on unzip (needed to uncompress albums).
    
    amarok (1.4.4-2) unstable; urgency=high
    
      * Patched magnatune code to avoid multiple credit-card charges.
        (Closes: #402309)
    
    amarok (1.4.4-1) unstable; urgency=medium
    
      * Adding myself as uploader. ACK my last three NMUs...
      * Removed circular dependencies. Now amarok-engines and amarok-$engine
        Recommends: amarok, instead of depends on amarok (Closes: #368485).
      * Fix kde#134333: properly compute total playlist length if there are
        tracks dynamic lengths (e.g. last.fm streams) in the playlist. Patch by
        Modestas Vainius <email address hidden>.
      * Replaced ${Source-Version} with ${source:Version} and added versioned
        build-dependency on dpkg-dev accordingly.
    
     -- Jonathan Riddell <email address hidden>   Mon, 03 Dec 2007 20:01:18 +0000
  • amarok (2:1.4.7-0ubuntu3) gutsy; urgency=low
    
      * Added kubuntu_05_utf8_to_mtp_devices_fix.diff from upstream.  (KDE
        Bug #139722)
      * Added kubuntu_06_fix_amarok_freeze_installing_mp3.diff from
        upstream.  (KDE Bug #147126, LP: #58617)  Thanks markey for fixing
        this!
      * Added amarok Suggests: libxine1-ffmpeg.  (LP: #134741)
      * Added kubuntu_07_gnome_multimedia_keys.diff, a script that lets the
        multimedia keys in GNOME work in amarok.  (LP: #87299)
      * Use adept_batch update in install-mp3 not apt-get update
    
     -- Sarah Hobbs <email address hidden>   Sat, 01 Sep 2007 00:11:20 +1000