lp:ubuntu/gutsy-security/evolution

Created by James Westby and last modified
Get this branch:
bzr branch lp:ubuntu/gutsy-security/evolution
Members of Ubuntu branches can upload to this branch. Log in for directions.

Branch merges

Related bugs

Related blueprints

Branch information

Owner:
Ubuntu branches
Review team:
Ubuntu Development Team
Status:
Development

Recent revisions

75. By Jamie Strandboge

* SECURITY UPDATE: buffer overflow via timezone data in crafted ical
  attachments
* debian/patches/99_01_CVE-2008-1108.patch: adjust
  calendar/gui/e-itip-control.c to use a GString rather than a fixed-size
  buffer to build the HTML string to avoid the possibility of an overflow.
* SECURITY UPDATE: heap-based overflow via crafted ical attachments with
  long DESCRIPTION
* debian/patches/99_02_CVE-2008-1109.patch: adjust calendar/gui/itip-utils.c
  to not use a fixed-size buffer for parsing external data. Simplify the
  logic to just split and rejoin the string with a different line separator.
* SECURITY UPDATE: remotely triggered denial of service
* debian/patches/99_03_bug535459.patch: add sanity checks and don't use
  component when checks fail in plugins/itip-formatter.c, gui/itip-utils.h,
  gui/itip-utils.c, gui/e-itip-control.c
* References
  CVE-2008-1108
  CVE-2008-1109
  http://bugzilla.gnome.org/show_bug.cgi?id=535459

74. By Kees Cook

* SECURITY UPDATE: code execution via format string in encrypted emails.
* Add 99_00_encryption_format_string_fix.patch: upstream fixes from
  Srinivasa Ragavan.
* References
  CVE-2008-0072

73. By Matthias Klose

Rename debian/docs to debian/evolution-common.docs

72. By Matthias Klose

Reduce the size of packages by 27MB (compressed) (3% of the distributed CDs),
a better alternative than dropping random apps.

71. By Sebastien Bacher

* debian/evolution-2.2.desktop,
  debian/evolution-mail.desktop,
  debian/evolution-alarm-notify.desktop:
  - changes from Mario Bonino
  - updated .desktop file to be freedesktop compliant
  - fixed Swedish comment (LP: #144195)
* debian/patches/80_from_bugzilla_fix_add_calendar_glade.patch:
  - patch from bugzilla, use correct publish-calendar.glade location,
    fix crasher when trying to use the corresponding dialog (LP: #144778)

70. By Sebastien Bacher

* debian/control, debian/evolution-plugins.install,
  debian/evolution-plugins-experimental.install:
  - the backup-restore plugin is not experimental

69. By Sebastien Bacher

* New upstream version:
  Bug fixes:
  - #270605: Skip disabled accounts and choose first available
    address as organizer.
  - #274047: (Novell Bugzilla) Pick the glade file from install area
  - #274048: (Novell Bugzilla) Prompt for a password if required
  - #277159: (Novell Bugzilla) Listen to the changes made in publish frequency
  - #300284: (Novell Bugzilla) Do not allow the user to set a 'no-date'
    for start/end of appointments in list view
  - #301044: (Novell Bugzilla) Dont append the comma from the Nameselector
  - #304993: (Novell Bugzilla) Allow folder selection of created folders
    and expand only if selection is not asked for
  - #329629: audio-inline plugin has been ported to gstreamer 0.10
  - #330223: More than one memo list was getting marked as default
  - #332026: Filter the input context key events
  - #363645: Don't translate empty label names.
  - #368033: Assign default color for B&A when no color is set
  - #467581: Get the right URIs for selected and current folders.
  - #468366: Avoid empty keywords getting added and other small
    fixes and improvements.
  - #471791: Move away from g_assert to g_critical
  - #473903: Fixes serious compiler warning
  Other Contributors:
  - Fix weak references which fixes one issue of the patch from bug #439122
  - Code cleanup
  Updated Translations
* debian/control.in:
  - Build-Depends on libgstreamer0.10-dev
* debian/evolution-plugins.install:
  - list audio-inline plugin

68. By Sebastien Bacher

* New upstream version:
  Bug fixes:
  - #201167: Complete implementation of Categories synching
    and lots of bug fixes
  - #351672: Dragging imap message when another is copying locks X
  - #377763: Do not scale under 1x1 pixel
  - #378759: Fixed a crash when entering S/MIME password for signing email
  - #431459: Avoid reentrancy of prefer-plain plugin
  - #466051: When memo start date is set to 'None',
    do not store DTSTART property.
  - #469886: Update FSF address in header comments
  - #471791: Move away from g_assert to g_critical
  Other Contributors:
  - Add mail/default/pl/Makefile to AC_OUTPUT
  - Add Evolution contributors names to credits page
  Updated Translations

67. By Sebastien Bacher

* New upstream version:
  Bug fixes:
  - #201201: Double-click on selected range in week view empty area
             should bring up event editor
  - #201202: Double-click on selected range in day view should bring
             up event editor
  - #239441: Fixed a crash when sorting imap mailbox by date (LP: #117735)
  - #256878: Set the message for valid signatures
  - #262226: Inconsistent "all day" behaviour of appointment editor
  - #262682: Add labelled-by relation between labels and entry.
  - #272167: 'Mark calendar for offline option' is available
             for local calendars
  - #274070: (BNC) download of freebusy not working
  - #301835: (BNC) Fixed a crash when clicking on mail with
             a calendar appointment
  - #303877: candidate window position at 0,0 in Evolution Task
  - #303878: candidate window position at 0,0 in calendar
  - #308636: User can delete grouwpise 'Calendar'
  - #309166: Fix incorrect cusor movement and delete for indic charcters
             in evolution calendar
  - #328405: A signature will be attached when redirecting an email
  - #329746: Renamed 'Journal' to 'Memo'.
  - #330628: In day view Meeting icon should be displayed in All day meeting
  - #331174: Rename KRBx_LDFLAGS to KRBx_LIBS
  - #337616, #352346, #467364, #468309: Documentation fixes
  - #338803: Free/Busy Loses Meeting Duration When Click To Another Time.
  - #347770: Improved description text parsing
  - #350539: Check for NULL MIME part
  - #352358: Harmonized some error messages
  - #353462: Changing the labels of buttons from "Yes/No" to make
             them HIG compliant. (LP: #57155)
  - #355766: Multi-lang text in Body is not printed when composing
             in ASCII mode
  - #355864: Fixed a critical warning when unchecking a webcal
  - #364431: Fix a crash while refreshing IMAP subscriptions (LP: #67352)
  - #364700: Load/Enable junk plugins while loading only
  - #367760: Fix multiple issues with Save / Save All attachment button
  - #385414: Fix multi language text display in message source
  - #385517: Evolution Preferences for Task now allows to change field values
  - #411619: Fixed build failures with -z defs
  - #412732: Fixed a crash when adding contact (LP: #88117)
  - #414420: Fix a crasher on repeated destroy
  - #420492: new all day event does not record "show as busy" status
  - #428110: Dragging memo onto the same memo list used to delete the memo
  - #431459: Enable format plugins while loading only
  - #435942: Documentation fixes
  - #440328: Added missing mnemonic for merge button
  - #440807: Sync now with Pidgin IM (LP: #129931)
  - #458715: Fixed a crash in GW proxy setting
  - #464106: GoTo Date dialog does not honor settings
  - #464338: Show popup when creating new folder
  - #465573: Optimize pixbuf behaviour
  - #466548: Fixed a crash when editing calendar event when none of the
             accounts are enabled
  - #466796: Fixed a crash at start up
  - #467165: Fixed a crash at start up (LP: #132729)
  - #467198: Initialize the camel exception
  - #467382: Compilation with "-pedantic" fails due to missing array size
  - #467559, 467883: Fix a crash on startup
  - #467635: String changes
  - #468159: Removed usage of BASE_VERSION
  - #468294: Add a few strings for translation.
  - #468303: Add strings for i18n
  - #468303: Add strings for i18n
  - #468303: Enable strings for i18n.
  - #468411: Fixed a crash while editing a newly typed event in week view
  - #468440: Fixed a crash in calendar week-view
             (while editing a new event with empty text)
  - #468734: Fix a crash when trying to change label color in preferences
  - #468804: Fixed a crash when converting a mail with attachment to task
  - #468869: Mark strings for Translation.
  Other Contributors:
  - Set the free/busy info of events entered directly on the canvas,
    with the editor defaults.
  Updated Translations

66. By Sebastien Bacher

* debian/control:
  - updated evolution-data-server requirement

Branch metadata

Branch format:
Branch format 7
Repository format:
Bazaar repository format 2a (needs bzr 1.16 or later)
Stacked on:
lp:ubuntu/lucid/evolution
This branch contains Public information 
Everyone can see this information.

Subscribers