-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Fri, 25 Aug 2017 09:10:25 +0200 Source: cacti Binary: cacti Architecture: source all Version: 1.1.18+ds1-1~bpo9+1 Distribution: stretch-backports Urgency: medium Maintainer: Cacti Maintainer <pkg-cacti-maint@lists.alioth.debian.org> Changed-By: Paul Gevers <elbrus@debian.org> Description: cacti - web interface for graphing of monitoring systems Closes: 861858 866140 866773 867532 869848 870353 870354 872478 Changes: cacti (1.1.18+ds1-1~bpo9+1) stretch-backports; urgency=medium . * Rebuild for stretch-backports. . cacti (1.1.18+ds1-1) unstable; urgency=medium . * New upstream version 1.1.18 - Drop patches from upstream and refresh the others * Bump standards version to 4.0.1 (no changes) * Stop installing csrf/LICENSE file (thanks lintian) . cacti (1.1.17+ds1-2) unstable; urgency=medium . * CVE-2017-12927 XSS vulnerability in spikekill.php (Closes: #872478) * [tests] fix grep expression to unblock Ubuntu * [tests] Add improve-boost-logging-on-fresh-installs.patch and don't filter on the fixed messages * Fix typo in previous changelog message . cacti (1.1.17+ds1-1) unstable; urgency=medium . * New upstream version 1.1.17 * Make the autopkgtest stricter now upstream reduced the noise . cacti (1.1.16+ds1-1) unstable; urgency=medium . * New upstream release - Fixes CVE-2017-12065 spikekill.php might allow remote attackers to execute arbitrary code via the avgnan, outlier-start, or outlier-end parameter (Closes: #870353) - Fixes CVE-2017-12066 Cross-site scripting (XSS) vulnerability in aggregate_graphs.php (Closes: #870354) . cacti (1.1.15+ds1-1) unstable; urgency=medium . * New upstream release - Fixes CVE-2017-11691 Cross-site scripting (XSS) vulnerability in auth_profile.php (Closes: #869848) * Lower the Depends on dbc to include ~ to ease backports . cacti (1.1.13+ds1-1) unstable; urgency=medium . * New upstream release * Update documentation from upstream . cacti (1.1.12+ds1-1) unstable; urgency=medium . * New upstream release * CVE-2017-10970 XSS vulnerability via link.php fixed (Closes: #867532) * Add version to jquery-tablesorter * Make sure that autopkgtests at least run again . cacti (1.1.10+ds1-6) unstable; urgency=medium . * Fix upgrade script to find the upgrade functions in the Debian file layout (Closes: #866773) Thanks to ISHIKAWA Mutsumi * Add upgrade code for grant on mysql.time_zone_name * Bump version of dbconfig-common to ensure we have the fix for postinst code working . cacti (1.1.10+ds1-5) unstable; urgency=medium . * Fix piuparts issue where the scripts are changed due to loading the template files in the postinst script. See upstream bug #810. (Closes: #866140) . cacti (1.1.10+ds1-4) unstable; urgency=medium . * Upload to unstable * Bump standards version to 4.0.0 (no changes) . cacti (1.1.10+ds1-3) experimental; urgency=medium . * Add texlive-formats-extra to the BD to get /usr/bin/pdfjadetex on the path ($HOME didn't solve it) . cacti (1.1.10+ds1-2) experimental; urgency=medium . * Define $HOME in d/rules to (hopefully) prevent FTBFS (which is unfortunately unreproducible in any of the setups I tested) . cacti (1.1.10+ds1-1) experimental; urgency=medium . * New upstream release * Upstream uses a newer jquery-tablesorter then in Debian so some links are not working (newer version is waiting in NEW) and once available should be used as minimal required version * Add cacti-spine and snmpd to suggests * Use soft-links in for site/log and site/rra instead of patches * Add missing depends (php-gd, php-json, php-ldap) * Debian dropped suhosin long time ago, so stop patching for it * Add select grant on mysql.time_zone_name * Add default templates during install (got dropped upstream since 1.0.0) * Add some paths to cacti settings during install to accommodate for the by-pass of cacti/install web-page. * Add note about time zones and the suggested manual action in NEWS and README . cacti (1.1.5+ds1-2) experimental; urgency=medium . * Upload with fix from 0.8.8h+ds1-10: Fix upgrades from before 0.8.8h+ds1-8; that version started to ship symlinks to directories in libjs-jquery-jstree without making sure dpkg handled that properly during upgrades (Closes: #861858) . cacti (1.1.5+ds1-1) experimental; urgency=medium . * New upstream release * Generate translations from source * Bump compat level to 10 * Build documentation from source (requires second tar ball generated from upstream git) * Generate jQueryUI datepicker links instead of hardcoding them * Don't install *.po files, they aren't used * Add lintian overrides for script-non-executable to avoid carrying a patch forever, while they shouldn't need to be executable in Debian * Don't install useless examples (outside of doc tree even) * Handle the new paper-plane theme as the other themes * Clean up d/TODO a bit . cacti (1.1.3+ds1-1) experimental; urgency=medium . * New upstream release - Drop loads of obsoleted patches - Refresh or rework remaining patches * Strip loads of embedded javascript projects and build and/or depend on the proper Debian package * Drop dependency on libadodb as upstream moved away from it * Prepare to buid documentation * Add patches to move adaptations in the embedded jquery-ui css file to the cacti main.css file as upstream intents to support that * Update d/TODO as not everything is done as I want it Checksums-Sha1: a9142849bf2294e7b5a14a6f3d30045857184141 2159 cacti_1.1.18+ds1-1~bpo9+1.dsc 09052bf4c8ccd6c6d11d0f666069ef276ae9002e 50204 cacti_1.1.18+ds1-1~bpo9+1.debian.tar.xz 4aef249caf2b735c5f03aa845ebd3181564bcd8f 4115790 cacti_1.1.18+ds1-1~bpo9+1_all.deb b150487b146391678c10f3c6cefb204e6ff80a56 8895 cacti_1.1.18+ds1-1~bpo9+1_amd64.buildinfo Checksums-Sha256: ddad526203f89bac2b75f4669137669c64494d112943badce5c1475ad1f8b0b2 2159 cacti_1.1.18+ds1-1~bpo9+1.dsc 1752b7185831058e710ff20df6c1802560e10a821c91c4227b3c3ec1d7edabfe 50204 cacti_1.1.18+ds1-1~bpo9+1.debian.tar.xz ed0b6332134b8fb5444f249e5a01f5a535e4f345d119053b37a2442bfdd95330 4115790 cacti_1.1.18+ds1-1~bpo9+1_all.deb abe3d1e3e9c0153feb5055aadd64573c9913c4d0d3aed6d027b3dfa9d8c7ff2c 8895 cacti_1.1.18+ds1-1~bpo9+1_amd64.buildinfo Files: b9a47ce84ff181544ac3423f88a33bcf 2159 web extra cacti_1.1.18+ds1-1~bpo9+1.dsc 25946f16a76c984490503ef8b12e5f27 50204 web extra cacti_1.1.18+ds1-1~bpo9+1.debian.tar.xz b589fdd36ca5308941bf219f416d7ea8 4115790 web extra cacti_1.1.18+ds1-1~bpo9+1_all.deb a7c36cda918cbd08fce258f18f4e2b90 8895 web extra cacti_1.1.18+ds1-1~bpo9+1_amd64.buildinfo -----BEGIN PGP SIGNATURE----- iQEzBAEBCAAdFiEEWLZtSHNr6TsFLeZynFyZ6wW9dQoFAlmf1BwACgkQnFyZ6wW9 dQrYDQf/eZLH/IBakKiReBlqtrofQResUO5AtlzvCMKj1/x0y/Aag6/AW4U+y+za x4YkgOjnSBJ+jIrZyVEpYBpBHerm2t9cIYf62hsWKI45xAVY4Spe8FSgtbqjyBi3 Hh5vYu1ShIDHE1c5oaN/55E9dl+NnMfxwYduzB4H6SnAHn/h/OeswJf58peU/6Z3 2GZzTEWsQsQQMozHHgyxGwjJQbQM7P2UrIZuvuxchW8bWdqNLP0MOKdn0b3+JMu3 EWRt8xmNXVLJibiyrgZy5NxltOwZwYTxdQncQf7vZ1+YoAWr2GBx0PsLHLaK5Xf2 ng+jc9Ic9SV814ZAQN1JHyPbKUN4jQ== =5QoO -----END PGP SIGNATURE-----