Change logs for acpid source package in Quantal

  • acpid (1:2.0.16-1ubuntu1) quantal; urgency=low
    
      * Merge from Debian testing (LP: #1006679), remaining changes:
        - Replace init script with Upstart job
          + This does not load modules, unlike the init script, since these are
            all loaded by ACPI:* modaliases now (and thus by udev)
        - debian/control: Bump build-dependency on debhelper for Upstart-aware
          dh_installinit
        - debian/acpid.install, debian/acpid.preinst:
          continue installing /etc/acpi/events/powerbtn and /etc/acpi/powerbtn.sh,
          deferring the migration to acpi-support-base; and drop the Recommends:
          on acpi-support-base for the same reason.
        - Source /usr/share/acpi-support/power-funcs in powerbtn.sh
        - debian/powerbtn.sh: ensure that /usr/share/acpi-support/power-funcs
          exists before sourcing it; note that acpid does not depend on
          acpi-support (which is fine, as it brings in lots of X dependencies
          not appropriate for servers); this fix will allow Ubuntu servers
          (especially those in VMs) to run acpid and catch and handle power
          button events again.
        - debian/powerbtn.sh: gnome-power-manager is no more, check for
          gnome-settings-daemon now. This fixes immediate shutdown when the power
          button is pressed.
        - debian/acpid.install, debian/acpid.links:
          Don't install socket and service files needed by systemd
      * Dropped changes:
        - Fix build error with GCC-4.5, build with -Wno-error=sign-compare; no
          longer needed.
      * debian/acpid.install, debian/rules: Migrate the Ubuntu changes for
        powerbtn.sh to debhelper 7
     -- Tyler Hicks <email address hidden>   Wed, 30 May 2012 17:45:36 -0700
  • acpid (1:2.0.10-1ubuntu3) precise; urgency=low
    
      * SECURITY UPDATE: Arbitrary code execution in the power button handling
        script (LP: #893821)
        - debian/powerbtn.sh: Ensure that the DBUS_SESSION_BUS_ADDRESS environment
          variable is only read from a process owned by the user that will be
          evaluating the variable.
        - CVE-2011-2777
      * SECURITY UPDATE: Unprivileged users may be able to write to directories
        and read files created by event handler scripts
        - event.c: Set a restrictive umask of 0077 before running an event handler
          script. Based on upstream patch.
        - CVE-2011-4578
     -- Tyler Hicks <email address hidden>   Wed, 07 Dec 2011 16:33:35 -0600