-
bzip2 (1.0.4-2ubuntu4.2) hardy-security; urgency=low
* SECURITY UPDATE: Fix temporary file creation race condition
- bzexe: Ensure link target is a regular file. Patch from vladz.
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=632862#5
- CVE-2011-4089
-- Tyler Hicks <email address hidden> Mon, 12 Dec 2011 11:32:00 -0600
-
bzip2 (1.0.4-2ubuntu4.1) hardy-security; urgency=low
* SECURITY UPDATE: fix integer overflow in BZ2_decompress()
- decompress.c: return error if N is larger than 2*1024^2 which keeps es
from overflowing but leaves enough room for the 900k maximum value of
the RUNA/RUNB encoding
- patch from upstream
- CVE-2010-0405
-- Jamie Strandboge <email address hidden> Thu, 09 Sep 2010 10:17:24 -0500
-
bzip2 (1.0.4-2ubuntu4) hardy; urgency=low
* SECURITY UPDATE: denial of service via heap memory corruption.
* bzlib.c, bzlib_private.h: upstream patch from 1.0.5 applied inline.
* References
CVE-2008-1372
-- Kees Cook <email address hidden> Wed, 19 Mar 2008 13:11:42 -0700
-
bzip2 (1.0.4-2ubuntu3) hardy; urgency=low
* rebuild to regenerate bzip2.info (LP: #187946)
-- Michael Vogt <email address hidden> Fri, 14 Mar 2008 19:30:36 +0100
-
bzip2 (1.0.4-2ubuntu2) hardy; urgency=low
* debian/rules: don't try to chmod dangling symlinks in the binary
target, since coreutils now throws an error in this case. LP: #194449.
-- Steve Langasek <email address hidden> Sun, 24 Feb 2008 05:27:49 +0000
-
bzip2 (1.0.4-2ubuntu1) hardy; urgency=low
* lib32bz2-*: Install into /usr/lib32, instead of /emul; change incorrectly
dropped in last sync.
* Set Ubuntu maintainer address.
* Modify Maintainer value to match the DebianMaintainerField
specification.
-- Steve Langasek <email address hidden> Mon, 07 Jan 2008 13:24:41 -0800
-
bzip2 (1.0.4-2) unstable; urgency=low
* lib32bz2-*: install into /emul/ia32-linux. Closes: #458853
* bzexe: correct path is /bin/bzip2. Closes: #418532
* debian/copyright: provide a copyright file in source package.
Closes: #381230
bzip2 (1.0.4-1) unstable; urgency=low
* Synchronise with Ubuntu. Closes: #456237
* Bumped Standards-Version to 3.7.3
* Moved homepage from description to pseudo header field in
debian/control
* Improved cross-building. Closes: #445036
* Removed debian/rules.orig
* Fixed the following lintian messages:
- W: bzip2 source: debian-rules-ignores-make-clean-error line 90
- W: bzip2 source: substvar-source-version-is-deprecated libbz2-dev
- W: bzip2 source: substvar-source-version-is-deprecated bzip2
- W: bzip2 source: substvar-source-version-is-deprecated lib64bz2-dev
- W: bzip2 source: substvar-source-version-is-deprecated lib32bz2-dev
-- Timo Aaltonen <email address hidden> Mon, 07 Jan 2008 20:36:37 +0000
-
bzip2 (1.0.4-0ubuntu2) gutsy; urgency=low
* Move the user manual in texinfo and ps format into bzip2-doc.
-- Matthias Klose <email address hidden> Fri, 05 Oct 2007 14:05:39 +0200