-
amarok (2:1.4.9.1-0ubuntu3.2) hardy-security; urgency=low
* SECURITY UPDATE: integer overflows allow remote attackers to execute
arbitrary code via an Audible Audio (.aa) file (LP: #318555)
- debian/patches/security_audible_tags.diff fix integer overflow while
reading audible aa file tags. Based on upstream patch.
- http://websvn.kde.org/?view=rev&revision=908415
- http://www.trapkit.de/advisories/TKADV2009-002.txt
- CVE-2009-0135
- CVE-2009-0136
-- Harald Sitter <email address hidden> Mon, 19 Jan 2009 22:13:53 +0100
-
amarok (2:1.4.9.1-0ubuntu3.1) hardy-security; urgency=low
* SECURITY UPDATE: Insecure creation of magnatune temp files
* Added kubuntu_99_security_mangatune_file_creator.diff patching
amarok/src/magnatunebrowser/magnatunebrowser.cpp and
amarok/src/magnatunebrowser/magnatunebrowser.h. Creates temp files
correctly. From upstream.
* References
http://secunia.com/advisories/31418/
http://www.securityfocus.com/bid/30662
http://websvn.kde.org/?view=rev&revision=846626
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=494765
CVE-2008-3699
-- Jonathan Thomas (The man) <email address hidden> Thu, 14 Aug 2008 14:11:21 -0400
-
amarok (2:1.4.9.1-0ubuntu3) hardy; urgency=low
* Added kdebase-kio-plugins as a recommened package
-- Jonathan Aquilina <email address hidden> Tue, 15 Apr 2008 14:24:23 +0200
-
amarok (2:1.4.9.1-0ubuntu2) hardy; urgency=low
[ Daniel Hahler]
* debian/patches/kubuntu_08_add_lastfm_recommended_radio.diff:
Add lastfm recommended radio station (LP: #103227)
* debian/patches/kubuntu_09_audio_mimetypes.diff:
- Add mimetypes audio/flac and audio/ogg (LP: #201291)
[ Harald Sitter ]
* Unbreak manual media device configuration by enhancing
kubuntu_08_luks_device_detection.diff (LP: #207704)
-- Harald Sitter <email address hidden> Sat, 12 Apr 2008 13:47:12 +0200
-
amarok (2:1.4.9.1-0ubuntu1) hardy; urgency=low
* Upstream patch release
-- Jonathan Riddell <email address hidden> Thu, 10 Apr 2008 23:07:12 +0100
-
amarok (2:1.4.9-0ubuntu1) hardy; urgency=low
* New upstream release
-- Harald Sitter <email address hidden> Wed, 09 Apr 2008 13:09:03 +0200
-
amarok (2:1.4.8-0ubuntu5) hardy; urgency=low
* Added kubuntu_08_luks_device_detection.diff to ajust Amarok's
media device detection to properly work with kdebase's
LUKS patch kubuntu_9913_kiomedialuks.diff) (LP: #186384)
-- Harald Sitter <email address hidden> Tue, 18 Mar 2008 01:10:01 +0100
-
amarok (2:1.4.8-0ubuntu4) hardy; urgency=low
* Update install-mp3 to correctly error when something goes wrong
-- Jonathan Riddell <email address hidden> Thu, 13 Mar 2008 13:11:08 +0000
-
amarok (2:1.4.8-0ubuntu3) hardy; urgency=low
[ Sven Boden ]
* Fix for bug "187406: Amarok install-mp3 fails silently" (LP #187406)
[ Sarah Hobbs ]
* Sponsored upload. (Closes LP: #187406)
* Reworked patch to avoid setting absolute paths (eg /usr/bin/kdesu)
-- Sarah Hobbs <email address hidden> Wed, 12 Mar 2008 00:50:22 +1100
-
amarok (2:1.4.8-0ubuntu2) hardy; urgency=low
* Fix install-mp3 installation path (LP: #179624)
-- Guillaume Martres <email address hidden> Mon, 31 Dec 2007 11:50:29 +0100
-
amarok (2:1.4.8-0ubuntu1) hardy; urgency=low
* New upstream release.
* Removed kubuntu_05_utf8_to_mtp_devices_fix.diff (applied upstream).
* Removed kubuntu_06_fix_amarok_freeze_installing_mp3.diff (applied upstream).
* Removed proxy_lyrics.diff (applied upstream).
* Removed overrides/ and it's content since there is no amarok-arts anymore.
* Removed amarok-gstreamer.install since there is no amarok-gstreamer anymore.
* Changed Standards-Version to 3.7.3.
* Moved "Homepage" from Description stanza to the source section.
-- Harald Sitter <email address hidden> Mon, 17 Dec 2007 16:19:44 +0100
-
amarok (2:1.4.7-2ubuntu5) hardy; urgency=low
* build without the libkerma-dev build dpendancy also ( realy fixed this
upload )
-- Brandon Holtsclaw <email address hidden> Mon, 10 Dec 2007 01:56:48 -0600
-
amarok (2:1.4.7-2ubuntu4) hardy; urgency=low
* build with --without-libkarma, as it seems to be default if left blank.
-- Brandon Holtsclaw <email address hidden> Sat, 08 Dec 2007 09:49:20 -0600
-
amarok (2:1.4.7-2ubuntu3) hardy; urgency=low
* removed --with-libkarma, libkarma{0,-dev} is not in Main yet.
-- Brandon Holtsclaw <email address hidden> Wed, 05 Dec 2007 23:47:20 -0600
-
amarok (2:1.4.7-2ubuntu2) hardy; urgency=low
* Rebuild for libmtp6 -> libmtp7 transition
-- Jonathan Riddell <email address hidden> Tue, 04 Dec 2007 14:01:22 +0000
-
amarok (2:1.4.7-2ubuntu1) hardy; urgency=low
* Merge with Debian, remaining changes in debian/KUBUNTU-DEBIAN-DIFFERENCES
amarok (1.4.7-2) UNRELEASED; urgency=low
* Build against libgpod-nogtk-dev.
amarok (1.4.7-1) unstable; urgency=low
* The "Are you breaking up with me?" release.
amarok (1.4.6-1) unstable; urgency=low
* New upstream version packaged.
* Drop magnatune_CVE-2006-6980.diff; a (better) fix was applied upstream.
amarok (1.4.5-5) unstable; urgency=low
* Rebuild against libtunepimp 0.5; change Build-Depends from libtunepimp3-dev
to libtunepimp-dev. (Closes: #425884)
amarok (1.4.5-4) unstable; urgency=low
* Upload to unstable. (Closes: #421920)
* Remove build-dependency on dpkg-dev (the version in stable groks
${binary:Version}), and drop version requirement on debhelper and
libtag1-dev as well.
* Drop the changes made to remove circular dependencies. (Reopens: #368485,
closes: #415484, #412464)
* Add patch to fix FTBFS with gcc-4.3. (Closes: #417684)
* Use ${binary:Version} instead of ${source:Version}.
* Add XS-VCS-Bzr field.
* Add watch file, and adjust download URL on debian/copyright.
amarok (1.4.5-3) experimental; urgency=low
* Add support for devices using MTP, build-dep on libmtp-dev added.
(Closes: #405399)
* Add support for karma devices, build-dep on libkarma-dev added.
(Closes: #400801)
* Added patch fixing CVE-2006-6980: amarok magnatune unsafe shell.
(Closes: #410850)
amarok (1.4.5-2) experimental; urgency=low
* iPod support is back. Added versioned build-dep on libgpod-dev (>=0.4.2).
(Closes: #409985)
* Add patch to add the "Queue Track" functionality to the Amarok DCOP API:
queuemedia.patch. Patch by Isaac Clerencia <email address hidden>
* Add patch to allow amarok get lyrics via http proxy with authentication.
Thanks to Filipe Lautert <email address hidden>. (Closes: #409568)
* Added versioned dep on amarok-engines | amarok-engine, thanks to Andreas
Pakulat for pointing this. (Closes: #409996).
amarok (1.4.5-1) experimental; urgency=low
* New upstream release:
- Remove patches merged by upstream: invoke_browser, sparc-asm, magnatune,
kde134333_negative_length_fix, revert-fix-for-bug-116127.
* The XMMS visualization interface has been removed by upstream:
- Remove xmms-dev build-dep.
- amarok's description updated.
- update amarok.install/rules.
* iPod support temporarily dropped. (It needs libgpod >= 0.4.2, which is not
yet in Debian).
amarok (1.4.4-4) unstable; urgency=high
* Include final version of the magnatune.patch and really apply it.
amarok (1.4.4-3) unstable; urgency=high
* Edited patch magnatune.patch fixing CVE-2006-6980: amarok magnatune
unsafe shell. (Closes: #410850).
The reference to the ruby scripts pointed in the bug report, is a problem
that was already solved in amarok 1.4.4.
* Add dep on unzip (needed to uncompress albums).
amarok (1.4.4-2) unstable; urgency=high
* Patched magnatune code to avoid multiple credit-card charges.
(Closes: #402309)
amarok (1.4.4-1) unstable; urgency=medium
* Adding myself as uploader. ACK my last three NMUs...
* Removed circular dependencies. Now amarok-engines and amarok-$engine
Recommends: amarok, instead of depends on amarok (Closes: #368485).
* Fix kde#134333: properly compute total playlist length if there are
tracks dynamic lengths (e.g. last.fm streams) in the playlist. Patch by
Modestas Vainius <email address hidden>.
* Replaced ${Source-Version} with ${source:Version} and added versioned
build-dependency on dpkg-dev accordingly.
-- Jonathan Riddell <email address hidden> Mon, 03 Dec 2007 20:01:18 +0000
-
amarok (2:1.4.7-0ubuntu3) gutsy; urgency=low
* Added kubuntu_05_utf8_to_mtp_devices_fix.diff from upstream. (KDE
Bug #139722)
* Added kubuntu_06_fix_amarok_freeze_installing_mp3.diff from
upstream. (KDE Bug #147126, LP: #58617) Thanks markey for fixing
this!
* Added amarok Suggests: libxine1-ffmpeg. (LP: #134741)
* Added kubuntu_07_gnome_multimedia_keys.diff, a script that lets the
multimedia keys in GNOME work in amarok. (LP: #87299)
* Use adept_batch update in install-mp3 not apt-get update
-- Sarah Hobbs <email address hidden> Sat, 01 Sep 2007 00:11:20 +1000