simplestreams 0.1.0~bzr341-0ubuntu2.2 source package in Ubuntu

Changelog

simplestreams (0.1.0~bzr341-0ubuntu2.2) trusty-security; urgency=medium

  * SECURITY UPDATE: insufficient verification of GPG signatures
    allowing malicious injection into images
    - debian/patches/lp1487004-use-checksumming-reader.patch: Ensure
      that users of the BasicMirrorWriter get exceptions when importing
      data that has invalid checksum or sizes. (LP: #1487004)
    - CVE-2015-1337
    - debian/patches/lp1487004-sru-safetynet.patch:
      provide a backwards compatible behavior via setting
      SS_MISSING_ITEM_CHECKSUM_BEHAVIOR=silent. See bug for more info.

 -- Scott Moser <email address hidden>  Tue, 22 Sep 2015 17:12:43 -0400

Upload details

Uploaded by:
Scott Moser
Sponsored by:
Steve Beattie
Uploaded to:
Trusty
Original maintainer:
Ubuntu Developers
Architectures:
all
Section:
python
Urgency:
Medium Urgency

See full publishing history Publishing

Series Pocket Published Component Section

Builds

Trusty: [FULLYBUILT] i386

Downloads

File Size SHA-256 Checksum
simplestreams_0.1.0~bzr341.orig.tar.gz 76.8 KiB a185652ecaec0892cbf00362fd1ef8b0d051b4fbde73ca882f517b32e0ef84f8
simplestreams_0.1.0~bzr341-0ubuntu2.2.debian.tar.gz 13.2 KiB ce9f882a90941ed3ea474c6c6867d15aab1d6bd0097c8b5fa147e6c9f2850d46
simplestreams_0.1.0~bzr341-0ubuntu2.2.dsc 2.1 KiB dade69d7f24eb9099872c0664e1ad60ee3fb39c77a182c84e3da71899da694c0

View changes file

Binary packages built by this source

python-simplestreams: Library and tools for using Simple Streams data

 This package provides a client for interacting with simple
 streams data as is produced to describe Ubuntu's cloud images.

python-simplestreams-openstack: Library and tools for using Simple Streams data

 This package depends on libraries necessary to use the openstack dependent
 functionality in simplestreams. That includes interacting with glance,
 swift and keystone.

python3-simplestreams: Library and tools for using Simple Streams data

 This package provides a client for interacting with simple
 streams data as is produced to describe Ubuntu's cloud images.

simplestreams: Library and tools for using Simple Streams data

 This package provides a client for interacting with simple
 streams data as is produced to describe Ubuntu's cloud images.