Bug 31956 - Import of Debian 6.0.8 point update
Import of Debian 6.0.8 point update
Status: CLOSED FIXED
Product: UCS
Classification: Unclassified
Component: General
UCS 3.0
Other Linux
: P5 enhancement (vote)
: UCS 3.2
Assigned To: Moritz Muehlenhoff
Janek Walkenhorst
: interim-3
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2013-07-11 11:39 CEST by Moritz Muehlenhoff
Modified: 2013-11-19 06:42 CET (History)
2 users (show)

See Also:
What kind of report is it?: ---
What type of bug is this?: ---
Who will be affected by this bug?: ---
How will those affected feel about the bug?: ---
User Pain:
Enterprise Customer affected?:
School Customer affected?:
ISV affected?:
Waiting Support:
Flags outvoted (downgraded) after PO Review:
Ticket number:
Bug group (optional): Release Goal
Max CVSS v3 score:


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Moritz Muehlenhoff univentionstaff 2013-07-11 11:39:20 CEST
The next point update for Squeeze will be released end of July/start of August. We should incorporate it into 3.2.
Comment 1 Moritz Muehlenhoff univentionstaff 2013-07-25 13:45:53 CEST
inform was not imported, it's non-free and we didn't import it in UCS 3.0.

linux-2.6 was not imported, we use a more recent Linux kernel in UCS 3.2.

libvirt was not imported, we use a more recent version in UCS 3.2 and the security issue
  is tracked by it's own bug.

bind9 was not imported, we use a more recent version of Bind and the security
fix from 1:9.7.3.dfsg-1~squeeze10 was already provided through Bug 29155

curl was not imported, it was already fixed through a errata security update
and the resulting binaries were copied to 3.2. (http://errata.univention.de/ucs/3.1/138.html)

libxml2 was not imported, it was already fixed through a errata security update
and the resulting binaries were copied to 3.2. (http://errata.univention.de/ucs/3.1/101.html)
Comment 2 Moritz Muehlenhoff univentionstaff 2013-07-26 14:35:18 CEST
apache2 did not need to be imported, it was already imported for 3.1-1.


openssh did not need to be imported, it was already imported for 3.1-1.


openafs was not imported, we use a more recent version in UCS. The security fix
from 1.4.12.1+dfsg-4+squeeze1 is present in thet version.


user-mode-linux was not imported. It only performs a rebuild against the
kernel source package and UML is not supported.


For libxres and lighttpd the version needed to be bumped in UCS. Otherwise
the build stamp of the previous UCS would not be higher than the new version.
Comment 3 Moritz Muehlenhoff univentionstaff 2013-07-30 15:46:34 CEST
php5 was not imported, it was already fixed through a errata security update
and the resulting binaries were copied to 3.2. (http://errata.univention.de/ucs/3.1/151.html)

tiff was not imported, it was already fixed through a errata security update
and the resulting binaries were copied to 3.2. (http://errata.univention.de/ucs/3.1/148.html)

sudo was not imported, it was already fixed through a errata security update
and the resulting binaries were copied to 3.2. (http://errata.univention.de/ucs/3.1/72.html)

During the import of clamav 0.97.8+dfsg-1~squeeze1 the previous security patch was dropped.
It's merged in the imported release.

For pyrad, strongswan and spamassassin the version needed to be bumped in UCS. Otherwise
the build stamp of the previous UCS would not be higher than the new version.

xen was not imported, we use a more recent version in UCS 3.1. The security issues are already
fixed or tracked through Bug 31395
Comment 4 Moritz Muehlenhoff univentionstaff 2013-08-06 13:58:02 CEST
libx11 was not imported, it was already fixed through a errata security update
and the resulting binaries were copied to 3.2. (http://errata.univention.de/ucs/3.1/163.html)


zoneminder was not imported. The new version fails to build with Linux 3.10 since the video4linux interface has changed. Since the package has no relevance for UCS, it wasn't updated to a compatible version.


grep was not imported, it was already fixed through a errata security update
and the resulting binaries were copied to 3.2. (http://errata.univention.de/ucs/3.1/139.html)
Comment 5 Moritz Muehlenhoff univentionstaff 2013-10-07 14:57:25 CEST
base-files was not imported, it only bumps the Debian release version.
Comment 6 Moritz Muehlenhoff univentionstaff 2013-10-15 10:48:43 CEST
debian-installer wan't imported; unused in UCS.

ia32-libs and ia32-libs-gtk weren't imported, we use a version with the UCS binaries.

libgcrypt11 was not imported, it was already fixed through a errata security update
and the resulting binaries were copied to 3.2. (http://errata.univention.de/ucs/3.1/162.html)

php5 was not imported, it was already fixed through a errata security update
and the resulting binaries were copied to 3.2. (http://errata.univention.de/ucs/3.1/178.html)

openjdk-6 wasn't imported yet, there are mor changes needed for the web plugin. The fix
will be released through and errata update and the merge to 3.2.

pyopencl wasn't imported, the source package was never imported in UCS since it's from contrib.

samba wasn't imported, we use a more recent version.
Comment 7 Moritz Muehlenhoff univentionstaff 2013-10-15 13:53:01 CEST
The following packages have been imported and built. In some cases build fixes needed to applied (e.g. to ensure that the version is newer than our internal build stamp):

apache2 2.2.16-6+squeeze11
asterisk    1:1.6.2.9-2+squeeze11
cacti   0.8.7g-1+squeeze3
cfingerd    1.4.3-3+squeeze1
chrony  1.24-3+squeeze1
clamav  0.97.8+dfsg-1~squeeze1
davfs2  1.4.6-1.1+squeeze1
dpkg-ruby   0.3.6+nmu2
drupal6 6.28-1
ejabberd    2.1.5-3+squeeze2
exactimage  0.8.1-3+deb6u3
fail2ban    0.8.4-3+squeeze2
firebird2.1 2.1.3.18185-0.ds1-11+squeeze1
firebird2.5 2.5.0.26054~ReleaseCandidate3.ds2-1+squeeze1
fusionforge 5.0.2-5+squeeze2
gdm3    2.30.5-6squeeze5
gnupg   1.4.10-4+squeeze3
gnupg2  2.0.14-2+squeeze2
graphviz    2.26.3-5+squeeze1
haproxy 1.4.8-1+squeeze1
icinga  1.0.2-2+squeeze1
inetutils   2:1.6-3.1+squeeze2
krb5    1.8.3+dfsg-4squeeze7
ldap2dns    0.3.1-3+squeeze1
libapache2-mod-fcgid    1:2.3.6-1+squeeze2
libapache-mod-security  2.5.12-1+squeeze3
libapache2-mod-perl2    2.0.4-7+squeeze1
libdmx  1:1.1.0-2+squeeze1
libfs   2:1.0.2-1+squeeze1
libmodplug  1:0.8.8.1-1+squeeze2+git20130828
libmodule-signature-perl    0.63-1+squeeze1
libopenid-ruby  2.1.8debian-1+squeeze1
libspf2 1.2.9-4+squeeze1
libxcb  1.6-1+squeeze1
libxcursor  1:1.1.10-2+squeeze1
libxext 2:1.1.2-1+squeeze1
libxfixes   1:4.0.5-1+squeeze1
libxi   2:1.3-8
libxinerama 2:1.1-3+squeeze1
libxml2 2.7.8.dfsg-2+squeeze8
libxp   1:1.0.0.xsf1-2+squeeze1
libxrandr   2:1.3.0-3+squeeze1
libxrender  1:0.9.6-1+squeeze1
libxres 2:1.0.4-1+squeeze
libxslt 1.1.26-6+squeeze3
libxt   1:1.0.7-1+squeeze1
libxtst 2:1.1.0-3+squeeze1
libxv   2:1.0.5-1+squeeze1
libxvmc 2:1.0.5-1+squeeze2
libxxf86dga 2:1.1.1-2+squeeze1
libxxf86vm  1:1.1.0-2+squeeze1
lighttpd    1.4.28-2+squeeze1.3
lm-sensors-3    1:3.1.2-6+squeeze1
mediawiki   1:1.15.5-2squeeze6
mesa    7.7.1-6
moin    1.9.3-1+squeeze5
nas 1.9.2-4squeeze1
net-snmp    5.4.3~dfsg-2+squeeze1
nss-pam-ldapd   0.7.15+squeeze4
openjpeg    1.3+dfsg-4+squeeze1
openvpn 2.1.3-2+squeeze2
otrs2   2.4.9+dfsg1-3+squeeze4
pcp 3.3.3-squeeze3
perl    5.10.1-17squeeze6
php-radius  1.2.5-2+squeeze1
phpbb3  3.0.7-PL1-4+squeeze1
pigz    2.1.6-1+squeeze1
policyd-weight  0.1.15.1-2+squeeze2
poppler 0.12.4-1.2+squeeze3
postgresql-8.4  8.4.17-0squeeze1
proftpd-dfsg    1.3.3a-6squeeze7
puppet  2.6.2-5+squeeze8
putty   0.60+2010-02-20-1+squeeze2
python-django   1.2.3-3+squeeze8
python-qt4  4.7.3-1+squeeze1
pyopenssl   0.10-1+squeeze1
pyrad   1.2-1+deb6u1
rails   2.3.5-1.2+squeeze8
request-tracker3.8  3.8.8-7+squeeze8
ruby1.9.1   1.9.2.0-2+deb6u1
smarty  2.6.26-0.2+squeeze1
smokeping   2.3.6-5+squeeze1
spamassassin    3.3.1-1.1
spip    2.1.1-3squeeze6
squid3  3.1.6-1.2+squeeze3
strongswan  4.4.1-5.3
stunnel4    3:4.29-1+squeeze1
subversion  1.6.12dfsg-7
sympa   6.0.1+dfsg-4+squeeze2
telepathy-gabble    0.9.15-1+squeeze2
texlive-extra   2009-10+squeeze1
tinc    1.0.13-1+squeeze1
tntnet  1.6.3-4+deb6u1
tomcat6 6.0.35-1+squeeze4
torque  2.4.8+dfsg-9squeeze2
typo3-src   4.3.9+dfsg1-1+squeeze8
tzdata  2013d-0squeeze1
wireshark   1.2.11-6+squeeze12
wordpress   3.6.1+dfsg-1~deb6u1
wv2 0.4.2.dfsg.2-1~deb6u1
xml-security-c  1.5.1-3+squeeze3
xorg-server 2:1.7.7-16
xserver-xorg-video-openchrome   1:0.2.904+svn842-2+squeeze1
xview   3.2p1.4-25+squeeze1
zabbix  1:1.8.2-1squeeze5
Comment 8 Janek Walkenhorst univentionstaff 2013-10-25 14:06:18 CEST
(In reply to Moritz Muehlenhoff from comment #1)
> inform was not imported, it's non-free and we didn't import it in UCS 3.0.
OK

> linux-2.6 was not imported, we use a more recent Linux kernel in UCS 3.2.
OK

> libvirt was not imported, we use a more recent version in UCS 3.2 and the
> security issue is tracked by it's own bug.
OK (Bug #30788)

> bind9 was not imported, we use a more recent version of Bind and the security
> fix from 1:9.7.3.dfsg-1~squeeze10 was already provided through Bug 29155
OK

> curl was not imported, it was already fixed through a errata security update
> and the resulting binaries were copied to 3.2.
> (http://errata.univention.de/ucs/3.1/138.html)
OK

> libxml2 was not imported, it was already fixed through a errata security
> update
> and the resulting binaries were copied to 3.2.
> (http://errata.univention.de/ucs/3.1/101.html)
OK (Bug #30646)
Comment 9 Janek Walkenhorst univentionstaff 2013-10-25 14:19:54 CEST
(In reply to Moritz Muehlenhoff from comment #2)
> apache2 did not need to be imported, it was already imported for 3.1-1.
OK

> openssh did not need to be imported, it was already imported for 3.1-1.
OK (Fix for CVE-2011-5000 via patch)

> openafs was not imported, we use a more recent version in UCS. The security
> fix from 1.4.12.1+dfsg-4+squeeze1 is present in thet version.
OK

> user-mode-linux was not imported. It only performs a rebuild against the
> kernel source package and UML is not supported.
OK

> For libxres and lighttpd the version needed to be bumped in UCS. Otherwise
> the build stamp of the previous UCS would not be higher than the new version.
libxres: OK
lighttpd: OK
Comment 10 Janek Walkenhorst univentionstaff 2013-10-25 16:53:31 CEST
(In reply to Moritz Muehlenhoff from comment #3)
> php5 was not imported, it was already fixed through a errata security update
> and the resulting binaries were copied to 3.2.
> (http://errata.univention.de/ucs/3.1/151.html)
OK

> tiff was not imported, it was already fixed through a errata security update
> and the resulting binaries were copied to 3.2.
> (http://errata.univention.de/ucs/3.1/148.html)
OK

> sudo was not imported, it was already fixed through a errata security update
> and the resulting binaries were copied to 3.2.
> (http://errata.univention.de/ucs/3.1/72.html)
OK

> During the import of clamav 0.97.8+dfsg-1~squeeze1 the previous security
> patch was dropped.
> It's merged in the imported release.
OK

> For pyrad, strongswan and spamassassin the version needed to be bumped in
> UCS. Otherwise
> the build stamp of the previous UCS would not be higher than the new version.
pyrad: OK
strongswan: OK
spamassassin: OK

> xen was not imported, we use a more recent version in UCS 3.1. The security
> issues are already
> fixed or tracked through Bug 31395
OK
Comment 11 Janek Walkenhorst univentionstaff 2013-10-25 17:10:12 CEST
(In reply to Moritz Muehlenhoff from comment #4)
> libx11 was not imported, it was already fixed through a errata security
> update
> and the resulting binaries were copied to 3.2.
> (http://errata.univention.de/ucs/3.1/163.html)
OK

> zoneminder was not imported. The new version fails to build with Linux 3.10
> since the video4linux interface has changed. Since the package has no
> relevance for UCS, it wasn't updated to a compatible version.
OK

> grep was not imported, it was already fixed through a errata security update
> and the resulting binaries were copied to 3.2.
> (http://errata.univention.de/ucs/3.1/139.html)
OK

(In reply to Moritz Muehlenhoff from comment #5)
> base-files was not imported, it only bumps the Debian release version.
OK

(In reply to Moritz Muehlenhoff from comment #6)
> debian-installer wan't imported; unused in UCS.
OK

> ia32-libs and ia32-libs-gtk weren't imported, we use a version with the UCS
> binaries.
OK

> libgcrypt11 was not imported, it was already fixed through a errata security
> update
> and the resulting binaries were copied to 3.2.
> (http://errata.univention.de/ucs/3.1/162.html)
OK

> php5 was not imported, it was already fixed through a errata security update
> and the resulting binaries were copied to 3.2.
> (http://errata.univention.de/ucs/3.1/178.html)
OK

> openjdk-6 wasn't imported yet, there are mor changes needed for the web
> plugin. The fix
> will be released through and errata update and the merge to 3.2.
OK

> pyopencl wasn't imported, the source package was never imported in UCS since
> it's from contrib.
OK

> samba wasn't imported, we use a more recent version.
OK
Comment 12 Janek Walkenhorst univentionstaff 2013-10-25 18:00:32 CEST
(In reply to Moritz Muehlenhoff from comment #7)
> The following packages have been imported and built. In some cases build
> fixes needed to applied (e.g. to ensure that the version is newer than our
> internal build stamp):
OK
Comment 13 Janek Walkenhorst univentionstaff 2013-10-25 18:03:49 CEST
(In reply to Moritz Muehlenhoff from comment #0)
> The next point update for Squeeze will be released end of July/start of
> August. We should incorporate it into 3.2.
OK
Comment 14 Stefan Gohmann univentionstaff 2013-11-19 06:42:58 CET
UCS 3.2 has been released:
 http://docs.univention.de/release-notes-3.2-en.html
 http://docs.univention.de/release-notes-3.2-de.html

If this error occurs again, please use "Clone This Bug".