1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84
|
python-django (0.95.1-1etch2) stable-security; urgency=low
* debian/patches/04_csrf_fix.diff
- Fixes cross-site request forgery vulnerability.
http://www.djangoproject.com/weblog/2008/sep/02/security/
Closes: 497765
* debian/patches/05_i18n_dos_fix.diff.
- Fixes denial of service vulnerability (CVE-2007-5712).
Closes: 448838
-- David Spreen <netzwurm@debian.org> Sat, 06 Sep 2008 13:12:29 -0700
python-django (0.95.1-1etch1) stable; urgency=low
* Add new patch debian/patches/03_xss_fix.diff. Fixes cross-site
scripting vulnerability (CVE-2008-2302). Closes: #481164
-- Raphael Hertzog <hertzog@debian.org> Tue, 20 May 2008 00:40:59 +0200
python-django (0.95.1-1) unstable; urgency=low
[ Brett Parker ]
* New upstream minor release for security bugs:
- http://www.djangoproject.com/weblog/2007/jan/21/0951/
- Fixes a small security vulnerability in the script Django's
internationalization system uses to compile translation files
(changeset 4360 in the "0.95-bugfixes" branch).
- fix for a bug in Django's authentication middleware which could cause
apparent "caching" of a logged-in user (changeset 4361).
- patch which disables debugging mode in the flup FastCGI package Django
uses to launch its FastCGI server, which prevents tracebacks from
bubbling up during production use (changeset 4363).
Closes: #407786, #407607
* Sets Recommends to python-psycopg and moves other database engines to
the Suggests field.
[ Raphael Hertzog ]
* Use python-pysqlite2 as default database engine in Recommends. Others are
in Suggests. Closes: #403761
* Add python-psycopg2 in Suggests. Closes: #407489
-- Raphael Hertzog <hertzog@debian.org> Sun, 21 Jan 2007 17:45:50 +0100
python-django (0.95-3) unstable; urgency=low
* Integrate 2 upstream changesets:
- http://code.djangoproject.com/changeset/3754 as
debian/patches/04_sec_fix_auth.diff
Fixes a possible case of mis-authentication due to bad caching.
Closes: #407521
- http://code.djangoproject.com/changeset/3592 as
debian/patches/03_sec_fix_compile-messages.diff
Fixes an (unlikely) arbitrary command execution if the user is blindly
running compile-messages.py on a untrusted set of *.po files.
Closes: #407519
-- Raphael Hertzog <hertzog@debian.org> Sat, 16 Dec 2006 15:13:29 +0100
python-django (0.95-2) unstable; urgency=low
[ Piotr Ozarowski ]
* Added XS-Vcs-Svn field
[ Brett Parker ]
* Made manage.py get a shebang with the version of python
used when running django-admin (closes: #401616)
* Created a convenience /usr/lib/python-django/bin symlink.
[ Raphael Hertzog ]
* Adapted Brett's work to better fit my views of the packaging.
-- Raphael Hertzog <hertzog@debian.org> Sat, 16 Dec 2006 11:03:20 +0100
python-django (0.95-1) unstable; urgency=low
[ Brett Parker ]
* 0.95 release - initial packaging
[ Raphael Hertzog ]
* Fix recommends: s/python-sqlite/python-pysqlite2/
* Add debian/pyversions to ensure that we have at least python 2.3 (and to
work around bug #391689 of python-support).
-- Raphael Hertzog <hertzog@debian.org> Mon, 9 Oct 2006 12:10:27 +0200
|