-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Format: 1.7 Date: Sat, 19 Oct 2002 16:47:35 -0700 Source: nut Binary: nut nut-cgi Architecture: source i386 Version: 1.1.12-1 Distribution: unstable Urgency: high Maintainer: Luca Filipozzi <lfilipoz@debian.org> Changed-By: Luca Filipozzi <lfilipoz@debian.org> Description: nut - Network UPS Tools nut-cgi - Network UPS Tools - Web Interface Closes: 165049 165376 165445 Changes: nut (1.1.12-1) unstable; urgency=high . * New upstream release (urgency high due to SECURITY FIX) * SECURITY FIX: a file permission problem potentially exposes non-system usernames/passwords in /etc/nut/upsd.users that can be used to DoS a machine running nut by contacting the nut daemon and instructing it to power off the machine; fixed. * debian/nut.postinst: change permissions of /etc/nut/upsd.users and other conffiles to 640 (Closes: Bug#165445) * debian/nut.config: use db_fset to reset the boolean question that prompts users to accept whether to continue with the installation of this version of nut should they answer no (Closes: Bug#165376) * debian/control: make nut-cgi Replace nut so that conflicting files can be installed (Closes: Bug#165049) * drivers/Makefile.in: restored original version that doesn't build hidups, snmp-ups or powernet; hidups doesn't build on m68k; snmp-ups and powernet require libsnmp5-dev but libsnmp5-dev requires OpenSSL; unfortunately, upstream's license doesn't have the OpenSSL exclusion clause... work is proceeding on porting to gnutls * drivers/Makefile.in + debian/rules: figured out a mechanism to build hidups on those architectures that have /usr/include/linux/hiddev.h * debian/control: build-depend on libgd-xpm-dev (really closes Bug#164832) Files: 214886fa02fbd292387408085067b6d1 572 admin optional nut_1.1.12-1.dsc 74e0733a1f5234fbbf181de82803e29a 445364 admin optional nut_1.1.12.orig.tar.gz 3884c87acb3ec533ab3133e49cb364c2 21012 admin optional nut_1.1.12-1.diff.gz e6cd9d651fe19cad432ed7d2b71060ce 501884 admin optional nut_1.1.12-1_i386.deb b78ccc007badea15dce2cdbbede14e8a 69382 admin optional nut-cgi_1.1.12-1_i386.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.2.0 (GNU/Linux) iD8DBQE9skLzNXMyxFqCei0RAiarAJwMQPBzJVXJjO5MOG3g+aYSrYdUJwCfU2hL twA7z6a0PPno5pTh3G1DUNI= =TlTv -----END PGP SIGNATURE----- Accepted: nut-cgi_1.1.12-1_i386.deb to pool/main/n/nut/nut-cgi_1.1.12-1_i386.deb nut_1.1.12-1.diff.gz to pool/main/n/nut/nut_1.1.12-1.diff.gz nut_1.1.12-1.dsc to pool/main/n/nut/nut_1.1.12-1.dsc nut_1.1.12-1_i386.deb to pool/main/n/nut/nut_1.1.12-1_i386.deb nut_1.1.12.orig.tar.gz to pool/main/n/nut/nut_1.1.12.orig.tar.gz -- To UNSUBSCRIBE, email to debian-devel-changes-request@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.org