Format: 1.7 Date: Wed, 19 Aug 2009 16:04:59 -0400 Source: mono Binary: mono-common mono-runtime mono-jit mono-jit-dbg mono-utils libmono0 libmono0-dbg libmono-dev libmono1.0-cil libmono2.0-cil libmono-c5-1.0-cil libmono-mozilla0.1-cil libmono-corlib1.0-cil libmono-corlib2.0-cil libmono-corlib2.1-cil libmono-i18n1.0-cil libmono-i18n2.0-cil libmono-system1.0-cil libmono-system2.0-cil libmono-system2.1-cil libmono-system-messaging1.0-cil libmono-system-messaging2.0-cil libmono-security1.0-cil libmono-security2.0-cil libmono-data-tds1.0-cil libmono-data-tds2.0-cil libmono-system-data1.0-cil libmono-system-data2.0-cil libmono-system-web1.0-cil libmono-system-web2.0-cil libmono-system-runtime1.0-cil libmono-system-runtime2.0-cil libmono-system-ldap1.0-cil libmono-system-ldap2.0-cil libmono-winforms1.0-cil libmono-winforms2.0-cil libmono-cairo1.0-cil libmono-cairo2.0-cil libmono-sharpzip0.6-cil libmono-sharpzip0.84-cil libmono-sharpzip2.6-cil libmono-sharpzip2.84-cil libmono-npgsql1.0-cil libmono-npgsql2.0-cil libmono-bytefx0.7.6.1-cil libmono-bytefx0.7.6.2-cil libmono-firebirdsql1.7-cil libmono-db2-1.0-cil libmono-oracle1.0-cil libmono-oracle2.0-cil libmono-sqlite1.0-cil libmono-sqlite2.0-cil libmono-accessibility1.0-cil libmono-accessibility2.0-cil libmono-cscompmgd7.0-cil libmono-cscompmgd8.0-cil libmono-ldap1.0-cil libmono-ldap2.0-cil libmono-microsoft-build2.0-cil libmono-microsoft7.0-cil libmono-microsoft8.0-cil libmono-peapi1.0-cil libmono-peapi2.0-cil libmono-relaxng1.0-cil libmono-relaxng2.0-cil mono-dbg mono-mjs mono-mcs mono-gmcs mono-smcs mono-1.0-devel mono-2.0-devel mono-1.0-service mono-2.0-service mono-xbuild mono-gac mono-jay prj2make-sharp Architecture: powerpc Version: 1.2.6+dfsg-6ubuntu3.1 Distribution: hardy Urgency: low Maintainer: Ubuntu/powerpc Build Daemon Changed-By: Marc Deslauriers Description: libmono-accessibility1.0-cil - Mono Accessibility library libmono-accessibility2.0-cil - Mono Accessibility library libmono-bytefx0.7.6.1-cil - Mono ByteFX.Data library libmono-bytefx0.7.6.2-cil - Mono ByteFX.Data library libmono-c5-1.0-cil - Mono C5 library libmono-cairo1.0-cil - Mono Cairo library libmono-cairo2.0-cil - Mono Cairo library libmono-corlib1.0-cil - Mono core library (1.0) libmono-corlib2.0-cil - Mono core library (2.0) libmono-corlib2.1-cil - Mono core library (2.1) libmono-cscompmgd7.0-cil - Mono cscompmgd library libmono-cscompmgd8.0-cil - Mono cscompmgd library libmono-data-tds1.0-cil - Mono Data library libmono-data-tds2.0-cil - Mono Data Library libmono-db2-1.0-cil - Mono DB2 library libmono-dev - libraries for the Mono JIT - Development files libmono-firebirdsql1.7-cil - Mono FirebirdSql library libmono-i18n1.0-cil - Mono I18N libraries (1.0) libmono-i18n2.0-cil - Mono I18N libraries (2.0) libmono-ldap1.0-cil - Mono LDAP library libmono-ldap2.0-cil - Mono LDAP library libmono-microsoft-build2.0-cil - Mono Microsoft.Build libraries libmono-microsoft7.0-cil - Mono Microsoft libraries libmono-microsoft8.0-cil - Mono Microsoft libraries libmono-mozilla0.1-cil - Mono Mozilla library libmono-npgsql1.0-cil - Mono Npgsql library libmono-npgsql2.0-cil - Mono Npgsql library libmono-oracle1.0-cil - Mono Oracle library libmono-oracle2.0-cil - Mono Oracle library libmono-peapi1.0-cil - Mono PEAPI library libmono-peapi2.0-cil - Mono PEAPI library libmono-relaxng1.0-cil - Mono Relaxng library libmono-relaxng2.0-cil - Mono Relaxng library libmono-security1.0-cil - Mono Security library libmono-security2.0-cil - Mono Security library libmono-sharpzip0.6-cil - Mono SharpZipLib library libmono-sharpzip0.84-cil - Mono SharpZipLib library libmono-sharpzip2.6-cil - Mono SharpZipLib library libmono-sharpzip2.84-cil - Mono SharpZipLib library libmono-sqlite1.0-cil - Mono Sqlite library libmono-sqlite2.0-cil - Mono Sqlite library libmono-system-data1.0-cil - Mono System.Data library libmono-system-data2.0-cil - Mono System.Data Library libmono-system-ldap1.0-cil - Mono System.DirectoryServices library libmono-system-ldap2.0-cil - Mono System.DirectoryServices library libmono-system-messaging1.0-cil - Mono System.Messaging library libmono-system-messaging2.0-cil - Mono System.Messaging Library libmono-system-runtime1.0-cil - Mono System.Runtime library libmono-system-runtime2.0-cil - Mono System.Runtime Library libmono-system-web1.0-cil - Mono System.Web library libmono-system-web2.0-cil - Mono System.Web Library libmono-system1.0-cil - Mono System libraries (1.0) libmono-system2.0-cil - Mono System libraries (2.0) libmono-system2.1-cil - Mono System libraries (2.1) libmono-winforms1.0-cil - Mono System.Windows.Forms library libmono-winforms2.0-cil - Mono System.Windows.Forms library libmono0 - libraries for the Mono JIT libmono0-dbg - libraries for the Mono JIT, debugging symbols libmono1.0-cil - Mono libraries (1.0) libmono2.0-cil - Mono libraries (2.0) mono-1.0-devel - Mono development tools for CLI 1.0 mono-1.0-service - Mono service manager for CLI 1.0 mono-2.0-devel - Mono development tools for CLI 2.0 mono-2.0-service - Mono service manager for CLI 2.0 mono-common - common files for Mono mono-dbg - Mono debugging symbols mono-gac - Mono GAC tool mono-gmcs - Mono C# 2.0 and C# 3.0 compiler for CLI 2.0 mono-jay - LALR(1) parser generator oriented to Java/CLI mono-jit - fast CLI JIT/AOT compiler for Mono mono-jit-dbg - fast CLI JIT/AOT compiler for Mono, debugging symbols mono-mcs - Mono C# compiler for CLI 1.1 mono-mjs - Mono JScript compiler mono-runtime - Mono runtime mono-smcs - Mono C# 3.0 compiler for CLI 2.1 (Moonlight / Silverlight) mono-utils - Mono utilities mono-xbuild - Mono xbuild prj2make-sharp - Convert VS.NET solution files to Makefiles Launchpad-Bugs-Fixed: 282952 282952 409920 Changes: mono (1.2.6+dfsg-6ubuntu3.1) hardy-security; urgency=low . * SECURITY UPDATE: Multiple cross-site scripting vulnerabilities in the ASP.net class libraries (LP: #282952) - debian/patches/security_CVE-2008-3422.dpatch: properly encode and escape values in mcs/class/System.Web/System.Web.UI.HtmlControls/ {HtmlControl,HtmlForm,HtmlInputButton,HtmlInputRadioButton, HtmlSelect}.cs, and add tests to mcs/class/System.Web/Test/ System.Web.UI.HtmlControls/{HtmlImageTest,HtmlInputButtonTest, HtmlInputRadioButtonTest,HtmlSelectTest}.cs - CVE-2008-3422 * SECURITY UPDATE: CRLF injection vulnerability in Sys.Web (LP: #282952) - debian/patches/security_CVE-2008-3906.dpatch: encode headers in mcs/class/System.Web/{System.Web/HttpResponseHeader.cs, System.Web.Configuration/HttpRuntimeConfig.cs} - CVE-2008-3906 * SECURITY UPDATE: XMLDsig HMAC-based signatures spoofing and authentication bypass (LP: #409920) - debian/patches/security_CVE-2009-0217.dpatch: Fix HMACOutputLength to match XMLDSIG erratum and add stricter checks. - CVE-2009-0217 Files: 2da1e61013a3c67fec76125a08ed61aa 118552 interpreters optional mono-common_1.2.6+dfsg-6ubuntu3.1_powerpc.deb 361c05e081e840536adbebda432b23ce 25756 interpreters optional mono-runtime_1.2.6+dfsg-6ubuntu3.1_powerpc.deb 79233483445a22ef62658013477aded4 790438 interpreters optional mono-jit_1.2.6+dfsg-6ubuntu3.1_powerpc.deb a6d05351e1c3712780e98fb8df4290bd 1770266 interpreters extra mono-jit-dbg_1.2.6+dfsg-6ubuntu3.1_powerpc.deb f20c006ef1f1ed7996606a5177096d65 660760 devel optional mono-utils_1.2.6+dfsg-6ubuntu3.1_powerpc.deb 839652db0bb89e11f30ef8316c5ab18e 902618 libs optional libmono0_1.2.6+dfsg-6ubuntu3.1_powerpc.deb b60139893b4c7e590eac14e5aa6ebb4a 1894932 libdevel extra libmono0-dbg_1.2.6+dfsg-6ubuntu3.1_powerpc.deb 0e54b2235b491ea5dcc7453700dcfd4f 1232348 libdevel optional libmono-dev_1.2.6+dfsg-6ubuntu3.1_powerpc.deb 59a4ef82179374eb4ea275620329c836 68818 devel optional mono-jay_1.2.6+dfsg-6ubuntu3.1_powerpc.deb Original-Maintainer: Debian Mono Group