-
zope3 (3.4.0-0ubuntu3.3) jaunty-security; urgency=low
* SECURITY UPDATE: arbitrary code execution via ZEO network protocol
- debian/patches/security-CVE-2009-066x.dpatch: introduce
ServerMarshaller() and server_find_global() in
Dependencies/ZEO-Zope-3.4.0/ZEO/zrpc/{marshal.py,connection.py}.
- CVE-2009-0668
* SECURITY UPDATE: authentication bypass via ZEO network protocol
- debian/patches/security-CVE-2009-066x.dpatch: make finish_auth()
private in Dependencies/ZEO-Zope-3.4.0/ZEO/{auth/auth_digest.py,
StorageServer.py, tests/auth_plaintext.py}.
- CVE-2009-0669
* SECURITY UPDATE: denial of service via too many new object identifiers
- debian/patches/security-CVE-2009-066x.dpatch: limit new oids to 100
in Dependencies/ZEO-Zope-3.4.0/ZEO/StorageServer.py.
- No CVE
* debian/patches/deb-zopeconf.dpatch: fix typo so ZOPE_USER is properly
defined. (LP: #356137)
-- Marc Deslauriers <email address hidden> Tue, 13 Oct 2009 13:39:22 -0400
-
zope3 (3.4.0-0ubuntu3) jaunty; urgency=low
* fix undeclared file conflicts that cause python-central to
error in postinst (LP: #347939)
-- Michael Vogt <email address hidden> Wed, 25 Mar 2009 17:59:15 +0100
-
zope3 (3.4.0-0ubuntu2) jaunty; urgency=low
* Regenerate the python-zopeinterface pkgconfig file. LP: #332516.
-- Matthias Klose <email address hidden> Sat, 21 Feb 2009 17:55:30 +0100
-
zope3 (3.4.0-0ubuntu1) jaunty; urgency=low
* New upstream version, final release.
* Merge changes from 3.3.1-6 and 3.3.1-7.
* Build using python2.5.
-- Matthias Klose <email address hidden> Sat, 21 Feb 2009 12:59:05 +0100
-
zope3 (3.3.1-7build1) intrepid; urgency=low
* Merge with Debian (no changes, different source tarball).
zope3 (3.3.1-7) unstable; urgency=low
* debian/rules: hardcoded version number, we can't really relay on the
name of the source directory. (Closes: #483333)
zope3 (3.3.1-6) unstable; urgency=low
* Merge from Ubuntu:
- Set the egg version for zope.interface to 3.3.1. LP: #185418.
- Drop dependency on python-xml. Closes: #468621.
-- Matthias Klose <email address hidden> Mon, 23 Jun 2008 15:10:46 +0200