-
mono (1.2.6+dfsg-6ubuntu3.1) hardy-security; urgency=low
* SECURITY UPDATE: Multiple cross-site scripting vulnerabilities in
the ASP.net class libraries (LP: #282952)
- debian/patches/security_CVE-2008-3422.dpatch: properly encode and
escape values in mcs/class/System.Web/System.Web.UI.HtmlControls/
{HtmlControl,HtmlForm,HtmlInputButton,HtmlInputRadioButton,
HtmlSelect}.cs, and add tests to mcs/class/System.Web/Test/
System.Web.UI.HtmlControls/{HtmlImageTest,HtmlInputButtonTest,
HtmlInputRadioButtonTest,HtmlSelectTest}.cs
- CVE-2008-3422
* SECURITY UPDATE: CRLF injection vulnerability in Sys.Web (LP: #282952)
- debian/patches/security_CVE-2008-3906.dpatch: encode headers in
mcs/class/System.Web/{System.Web/HttpResponseHeader.cs,
System.Web.Configuration/HttpRuntimeConfig.cs}
- CVE-2008-3906
* SECURITY UPDATE: XMLDsig HMAC-based signatures spoofing and
authentication bypass (LP: #409920)
- debian/patches/security_CVE-2009-0217.dpatch: Fix HMACOutputLength to
match XMLDSIG erratum and add stricter checks.
- CVE-2009-0217
-- Marc Deslauriers <email address hidden> Wed, 19 Aug 2009 16:04:59 -0400
-
mono (1.2.6+dfsg-6ubuntu3) hardy; urgency=low
* debian/rules:
+ unexport CPPFLAGS because configure relies on them being unset
to pass custom CPPFLAGS to boehm's configure.
-- Sebastian Droege <email address hidden> Sat, 22 Mar 2008 00:57:15 +0100
-
mono (1.2.6+dfsg-6ubuntu2) hardy; urgency=low
* debian/rules:
+ Put CFLAGS in "" to make the shell happy and fix the build.
+ Set default CFLAGS to -O2 -g.
-- Sebastian Droege <email address hidden> Fri, 21 Mar 2008 20:31:01 +0100
-
mono (1.2.6+dfsg-6ubuntu1) hardy; urgency=low
* Sync with Debian:
+ Alternatives handling is in Debian now, for all other
remaining changes see changelog of 1.2.6+dfsg-5ubuntu1.
mono (1.2.6+dfsg-6) unstable; urgency=high
* debian/mono-mcs.postinst
debian/mono-1.0-devel.postinst:
+ Moved alternatives handling for cli-sn, cli-resgen and cli-al from
mono-mcs to mono-1.0-devel, as mono-1.0-devel ships those applications
(since mono 1.2.6+dfsg-1). (Closes: #460513)
This caused FTBS for different source packages that didn't explicitly
build-depend on mono-mcs, thus urgency set to high.
(Thanks to Laurent Bigonville <email address hidden> for the investigation)
* debian/mono-utils.postint
debian/mono-utils.postinst:
+ Fixed file name.
* debian/control:
+ Added libmono-dev and pkg-config to recommends of mono-{1,2}.0-devel, as
mkbundle(2) uses pkg-config and needs mono.pc.
* debian/patches/ppc_disable_delegate_trampoline_optimization.dpatch
debian/patches/ppc_fix_flushing_of_icache_r92014.dpatch
+ Replaced ppc_disable_delegate_trampoline_optimization with
ppc_fix_flushing_of_icache_r92014, as that one fixes instead of
workarounds the PPC SIGILL issue (taken from upstream's SVN).
mono (1.2.6+dfsg-5ubuntu2) hardy; urgency=low
* Correctly install alternatives for mono-1.0-devel package (LP: #182509)
-- Sebastian Droege <email address hidden> Fri, 21 Mar 2008 19:08:06 +0100
-
mono (1.2.6+dfsg-5ubuntu2) hardy; urgency=low
* Correctly install alternatives for mono-1.0-devel package (LP: #182509)
-- Laurent Bigonville <email address hidden> Sun, 13 Jan 2008 11:49:31 +0100
-
mono (1.2.6+dfsg-5ubuntu1) hardy; urgency=low
* Merge with Debian, remaining Ubuntu changes:
- debian/control:
+ Updated Maintainer Field.
+ Adjust Replaces for Ubuntu versions.
+ Added lpia to architectures. Sparc has been added in Debian.
+ Build-depend on libgda3-dev instead of libgda2-dev, since
libgda2 is in universe.
- debian/patches/dont_check_proc_self_exe.dpatch:
+ Comment out code that checks /proc/self/exe so that
mono will function on the Live CD.
- debian/rules:
+ Symlink doc directories to avoid duplicate files, and remove the doc
directories on upgrade for the now symlinked doc directories.
- debian/shlibs.local:
+ Remove libgda2, as it's in universe.
-- Emilio Pozuelo Monfort <email address hidden> Wed, 09 Jan 2008 10:53:18 +0100
-
mono (1.2.6+dfsg-1ubuntu1) hardy; urgency=low
* Merge with Debian, remaining Ubuntu changes:
- debian/control:
+ Updated Maintainer Field.
+ Adjust Replaces for Ubuntu versions.
+ Added sparc and lpia to architectures.
+ Build-depend on libgda3-dev instead of libgda2-dev.
- debian/patches/dont_check_proc_self_exe.dpatch:
+ Comment out code that checks /proc/self/exe so that
mono will function on the Live CD.
- debian/rules:
+ Symlink doc directories to avoid duplicate files, and remove the doc
directories on upgrade for the now symlinked doc directories.
- debian/shlibs.local:
+ Remove libgda3-dev build dependency, as it's in universe.
mono (1.2.6+dfsg-1) unstable; urgency=low
* DFSG version of Mono 1.2.6
+ Deleted mcs/class/System.Web.Extensions/System.Web.Script.Serialization/
JSON/* as those source files are licensed under Creative Commons
Attribution 2.5 which is not DFSG-free.
* New upstream release
+ Invoking GetFields on emitted type doesn't crash anymore, as seen with
nemerle. (Closes: #452585)
* debian/rules:
+ Updated MONO_API to 1.2.6
+ Enabled moonlight support in configure call.
+ Removed all "rm debian/tmp/usr/lib/mono/gac/"... calls, instead list
libraries explicitly in .install files.
(this is pretty error prone when upstream introduces new libraries and
the rm list became way too long)
+ Copy various 1.0 manpages to 2.0 manpages for missing 2.0 manpages.
+ Remove +dfsg part in upstream version detection (UPVERSION variable).
* debian/control:
+ Added new packages (mono-mcs/gmcs needed to be split as some parts of the
runtime relies on the compiler, like the XmlSerializer class):
- mono-mcs was split to: mono-1.0-devel and mono-1.0-service.
(monolinker.exe is now shipped part of mono-1.0-devel, Closes: #443833)
- mono-gmcs was split to: mono-2.0-devel, mono-2.0-service and
mono-xbuild.
- mono-smcs, containing the new compiler for moonlight/silverlight
applications.
- libmono-corlib2.1-cil and libmono-system2.1-cil, containing the
moonlight/silverlight runtime libraries.
- libmono-db2-1.0-cil, containing IBM DB2 database connector.
- libmono-mozilla0.1-cil, containing the WebControl implementation using
the Mozilla engine.
- libmono-i18n1.0-cil and libmono-i18n2.0-cil, containing I18N libraries
with code page definitions, moved from libmono-corlib{1,2}.0-cil.
- prj2make-sharp, upstream moved distribution of prj2make-sharp to Mono.
+ libmono-corlib{1,2}.0-cil recommends libmono-i18n{1,2}.0-cil now.
+ Removed mono and mono-devel meta packages, as they are not useful for
anyone.
* debian/dh_clideps:
+ Synced from cli-common 0.5.3, needed for CLI 2.1 support.
* debian/patches/00list:
+ Disabled armel_fix_configure_fpu_check.dpatch
(FPU check is fixed upstream)
* debian/patches/kfreebsd_support.dpatch:
+ Updated (and re-autoconfed)
* debian/patches/fix-mono.pc.in.dpatch:
+ Updated
* debian/patches/ppc_fix_mono_class_proxy_vtable_r84948.dpatch:
+ Removed, already applied upstream.
* debian/patches/fix_Mono.Cecil_linkage.dpatch:
+ Link Mono.Cecil(.Mdb) against CLI 1.0 instead of 2.0, patch taken from
upstream.
* debian/libmono1.0-cil.install:
+ Added Mono.Cecil.dll and Mono.Cecil.Mdb.dll.
* debian/update-shlibs.local.sh:
+ Wrote this script to ease updating the debian/shlibs.local file.
* debian/shlibs.local:
+ Updated
-- Emilio Pozuelo Monfort <email address hidden> Sat, 22 Dec 2007 00:16:29 +0100
-
mono (1.2.5.1-2ubuntu1) hardy; urgency=low
[ Emilio Pozuelo Monfort ]
* Merge with Debian, remaining Ubuntu changes:
- debian/control:
+ Updated Maintainer Field.
+ Adjust Replaces for Ubuntu versions.
+ Added sparc and lpia to architectures.
+ Build-depend on libgda3-dev instead of libgda2-dev.
- debian/patches/dont_check_proc_self_exe.dpatch:
+ Comment out code that checks /proc/self/exe so that
mono will function on the Live CD.
- debian/rules:
+ Symlink doc directories to avoid duplicate files, and remove the doc
directories on upgrade for the now symlinked doc directories.
[ Sebastian Dröge ]
* debian/control,
debian/shlibs.local:
+ Remove libgda3-dev build dependency, this only works with gda2 anyway.
Put the gda2 shlibs into shlibs.local and suggest them for
libmono-system-data[12].0-cil instead of depending on it.
mono (1.2.5.1-2) unstable; urgency=high
* Mirco 'meebey' Bauer:
+ debian/mono.runtime-script:
- When removing GAC libraries, output the assembly name correctly on
errors.
+ debian/patches/fix_BigInteger_overflow_CVE-2007-5197.dpatch:
- Fixes CVE-2007-5197, thus urgency set to high.
mono (1.2.5.1-1) unstable; urgency=low
* Mirco 'meebey' Bauer:
+ New upstream (bugfix) release. (Closes: #443468)
+ debian/System.Windows.Forms.dll.config:
- Added libX11 and libXcursor.
mono (1.2.5-3) unstable; urgency=high
* Mirco 'meebey' Bauer:
+ debian/patches/ppc_fix_mono_class_proxy_vtable_r84948.dpatch:
- Fixes crash bug on PPC for all applications that use DBus,
thus setting urgency to high. (Closes: #437452, #441795, #441879)
(Thanks to Bram Senders <email address hidden> for testing the patch)
mono (1.2.5-2) unstable; urgency=medium
* Sebastian 'slomo' Dröge:
+ debian/FirebirdSql.Data.Firebird.dll.config,
debian/shlibs.local:
- Use libfbclient2 instead of old and to be removed libfbclient1.
Thanks to Damyan Ivanov <email address hidden> for the
patch (Closes: #440850).
+ debian/changelog:
- Use urgency=medium because of the RC bugfix.
mono (1.2.5-1) unstable; urgency=low
* Mirco 'meebey' Bauer:
+ New upstream release
+ debian/watch:
- Updated
+ debian/rules:
- Bumped MONO_API to 1.2.5
+ debian/patches/kfreebsd_support.dpatch
debian/patches/armel_fix_configure_fpu_check.dpatch:
- Updated (re-autoconfed)
- Updated
+ debian/patches/ppc_fix_memory_corruption_r81413.dpatch:
debian/patches/fix_delegate_memory_leak_r79001.dpatch
debian/patches/remove_broken_dllmap_from_mono-shlib-cop.dpatch:
- Removed, already applied upstream.
+ debian/mono-utils.install
debian/mono-utils.manpages:
- Removed monodiet as removed by upstream
+ debian/man/resgen.1:
- Removed, supplied upstream.
+ debian/mono-mcs.manpages:
- Added monolinker.1
- Updated resgen.1
+ debian/mono-mcs.manpages
debian/mono-mjs.manpages:
- Moved mono-mjs.1 manpage to mono-mjs package.
+ debian/control:
- Added "Replaces" for mono-mjs.1 move to mono-mjs package.
mono (1.2.4-6ubuntu6) gutsy; urgency=low
* Explicitely remove the doc directories on upgrade for the now symlinked
doc directories.
mono (1.2.4-6ubuntu5) gutsy; urgency=low
* Symlink doc directories to avoid duplicate files.
mono (1.2.4-6ubuntu4) gutsy; urgency=low
* debian/control: Build against libgda3-dev instead of libgda2-dev. The
latter is obsolete and in universe now.
mono (1.2.4-6ubuntu3) gutsy; urgency=low
* No-change upload due to soyuz bug (lpia bootstrap).
mono (1.2.4-6ubuntu2) gutsy; urgency=low
* Build packages for the lpia architecture.
mono (1.2.4-6ubuntu1) gutsy; urgency=low
* Sync with Debian. Remaining Ubuntu changes:
+ debian/control:
- Change maintainer to Ubuntu Mono Team.
- Adjust Replaces for Ubuntu versions.
- Add sparc again.
+ debian/control,
debian/libmono-sqlite1.0-cil.clideps-override,
debian/libmono-sqlite2.0-cil.clideps-override:
- Make sqlite2 only a Suggests instead of a Depends.
+ debian/patches/dont_check_proc_self_exe.dpatch:
- Comment out code that checks /proc/self/exe so that
mono will function on the Live CD.
-- Sebastian Droege <email address hidden> Mon, 19 Nov 2007 17:12:12 +0100
-
mono (1.2.4-6ubuntu6) gutsy; urgency=low
* Explicitely remove the doc directories on upgrade for the now symlinked
doc directories.
-- Matthias Klose <email address hidden> Fri, 05 Oct 2007 17:02:25 +0000