--- Begin Message ---
- To: Debian Bug Tracking System <submit@bugs.debian.org>
- Subject: pu: package glance/2012.1.1-5+deb7u1
- From: Thomas Goirand <zigo@debian.org>
- Date: Mon, 09 Dec 2013 16:06:36 +0800
- Message-id: <20131209080636.17980.64941.reportbug@buzig.gplhost.com>
Package: release.debian.org
Severity: normal
User: release.debian.org@packages.debian.org
Usertags: pu
Hi,
I have prepared an update for Glance over here:
http://archive.gplhost.com/pub/security/glance/
Attached to this mail is the relevant debdiff for Glance.
What the update does is only fixing the logrotate path,
which is currently wrong in the current Wheezy version.
Here's the changelog:
[ Thomas Goirand ]
* debian/gbp.conf now tracking the debian/wheezy branch.
[ Julien Cristau ]
* Fix logrotate config to reference the right file names.
Thanks considering this and letting me know,
Thomas Goirand (zigo)
diff -Nru glance-2012.1.1/debian/changelog glance-2012.1.1/debian/changelog
--- glance-2012.1.1/debian/changelog 2013-03-14 20:53:41.000000000 +0000
+++ glance-2012.1.1/debian/changelog 2013-12-09 07:48:43.000000000 +0000
@@ -1,3 +1,13 @@
+glance (2012.1.1-5+deb7u1) wheezy-proposed-updates; urgency=low
+
+ [ Thomas Goirand ]
+ * debian/gbp.conf now tracking the debian/wheezy branch.
+
+ [ Julien Cristau ]
+ * Fix logrotate config to reference the right file names.
+
+ -- Thomas Goirand <zigo@debian.org> Mon, 09 Dec 2013 15:44:43 +0800
+
glance (2012.1.1-5) unstable; urgency=high
* CVE-2013-1840: fixes "Backend credentials leak in Glance v1 API"
diff -Nru glance-2012.1.1/debian/gbp.conf glance-2012.1.1/debian/gbp.conf
--- glance-2012.1.1/debian/gbp.conf 2013-03-14 20:53:41.000000000 +0000
+++ glance-2012.1.1/debian/gbp.conf 2013-12-09 07:48:43.000000000 +0000
@@ -1,6 +1,6 @@
[DEFAULT]
upstream-branch = master
-debian-branch = debian/unstable
+debian-branch = debian/wheezy
upstream-tag = %(version)s
compression = xz
diff -Nru glance-2012.1.1/debian/glance-api.logrotate glance-2012.1.1/debian/glance-api.logrotate
--- glance-2012.1.1/debian/glance-api.logrotate 2013-03-14 20:53:41.000000000 +0000
+++ glance-2012.1.1/debian/glance-api.logrotate 2013-12-09 07:48:43.000000000 +0000
@@ -1,4 +1,4 @@
-/var/log/glance/glance-api.log {
+/var/log/glance/api.log {
daily
missingok
compress
diff -Nru glance-2012.1.1/debian/glance-registry.logrotate glance-2012.1.1/debian/glance-registry.logrotate
--- glance-2012.1.1/debian/glance-registry.logrotate 2013-03-14 20:53:41.000000000 +0000
+++ glance-2012.1.1/debian/glance-registry.logrotate 2013-12-09 07:48:43.000000000 +0000
@@ -1,4 +1,4 @@
-/var/log/glance/glance-registry.log {
+/var/log/glance/registry.log {
daily
missingok
compress
--- End Message ---
--- Begin Message ---
- To: "Adam D. Barratt" <adam@adam-barratt.org.uk>, 731735-done@bugs.debian.org
- Cc: Moritz Mühlenhoff <jmm@inutil.org>, Thomas Goirand <zigo@debian.org>
- Subject: Re: Bug#731735: pu: package glance/2012.1.1-5+deb7u1
- From: Julien Cristau <jcristau@debian.org>
- Date: Sun, 21 Feb 2016 10:47:03 +0000
- Message-id: <20160221104703.GJ6200@betterave.cristau.org>
- In-reply-to: <cddeeb637597707803c1cb5fb80b3758@mail.adsl.funky-badger.org>
- References: <20131209080636.17980.64941.reportbug__11598.836669191$1386576567$gmane$org@buzig.gplhost.com> <20131209171242.GA4385@pisco.westfalen.local> <1390426653.28217.43.camel@jacala.jungle.funky-badger.org> <54f709b27441842d14e46f23db3a3a86@mail.adsl.funky-badger.org> <cddeeb637597707803c1cb5fb80b3758@mail.adsl.funky-badger.org>
On Sat, Jan 17, 2015 at 11:47:40 +0000, Adam D. Barratt wrote:
> On 2014-08-24 19:58, Adam D. Barratt wrote:
> >On 2014-01-22 21:37, Adam D. Barratt wrote:
> >>On Mon, 2013-12-09 at 18:12 +0100, Moritz Mühlenhoff wrote:
> >>>> I have prepared an update for Glance over here:
> >>>> http://archive.gplhost.com/pub/security/glance/
> >>>
> >>>The security tracker lists this issue as potentially open in
> >>>Wheezy: https://security-tracker.debian.org/tracker/CVE-2013-4354
> >>>
> >>>Does this affect stable and is there a fix which can be included
> >>>along?
> >>
> >>Ping? (On both the original upload and Moritz's question.)
> >
> >Re-ping.
>
> Re-re-ping.
>
> If nothing happens with this soon then I'm tempted to close the request,
> rather than leaving it open indefinitely.
>
That was over a year ago; closing.
Cheers,
Julien
--- End Message ---