Change logs for shim source package in Wily

  • shim (0.8-0ubuntu2) wily; urgency=medium
    
      * No-change rebuild against gnu-efi 3.0v-5ubuntu1.
    
    shim (0.8-0ubuntu1) wily; urgency=medium
    
      * New upstream release.
        - Clarify meaning of insecure_mode. (LP: #1384973)
      * debian/patches/CVE-2014-3675.patch, debian/patches/CVE-2014-3677.patch,
        debian/patches/0001-Update-openssl-to-0.9.8za.patch: dropped, included
        in the upstream release.
      * debian/patches/sbsigntool-not-pesign,debian/patches/second-stage-path:
        refreshed.
    
     -- Steve Langasek <email address hidden>  Tue, 12 May 2015 17:48:30 +0000
  • shim (0.8-0ubuntu1) wily; urgency=medium
    
      * New upstream release.
        - Clarify meaning of insecure_mode. (LP: #1384973)
      * debian/patches/CVE-2014-3675.patch, debian/patches/CVE-2014-3677.patch,
        debian/patches/0001-Update-openssl-to-0.9.8za.patch: dropped, included
        in the upstream release.
      * debian/patches/sbsigntool-not-pesign,debian/patches/second-stage-path:
        refreshed.
    
     -- Mathieu Trudel-Lapierre <email address hidden>  Mon, 11 May 2015 19:50:49 -0400
  • shim (0.7-0ubuntu4) utopic; urgency=medium
    
      * SECURITY UPDATE: heap overflow and out-of-bounds read access when
        parsing DHCPv6 information
        - debian/patches/CVE-2014-3675.patch: apply proper bounds checking
          when parsing data provided in DHCPv6 packets.
        - CVE-2014-3675
        - CVE-2014-3676
      * SECURITY UPDATE: memory corruption when processing user-provided key
        lists
        - debian/patches/CVE-2014-3677.patch: detect malformed machine owner
          key (MOK) lists and ignore them, avoiding possible memory corruption.
        - CVE-2014-3677
    
    shim (0.7-0ubuntu2) utopic; urgency=medium
    
      * Restore debian/patches/prototypes, which still is needed on shim 0.7
        but only detected on the buildds.
      * Update debian/patches/prototypes with some new declarations needed for
        openssl 0.9.8za update.
    
    shim (0.7-0ubuntu1) utopic; urgency=medium
    
      * New upstream release.
        - fix spurious error message when fallback.efi is not present, as will
          always be the case for removable media.  LP: #1297069.
        - drop most patches, included upstream.
      * debian/patches/0001-Update-openssl-to-0.9.8za.patch: cherry-pick
        openssl 0.9.8za in via upstream.
    
    shim (0.4-0ubuntu5) utopic; urgency=low
    
      * Install fallback.efi.signed as well, to lay the groundwork for fallback
        handling (wanted when we have to move a drive between machines, or when
        the firmware loses its marbles^W nvram).
     -- Steve Langasek <email address hidden>   Wed, 08 Oct 2014 06:40:40 +0000