lynx-ssl (1:2.8.4.1b-3.2) oldstable-security; urgency=high * Non-maintainer upload by the Security Team * Applied patch by Ulf Härnhammar to fix buffer overflow that can lead to arbitrary code execution [WWW/Library/Implementation/HTMIME.c, CAN-2005-3120] -- Martin Schulze Sat, 8 Oct 2005 09:23:49 +0200 lynx-ssl (1:2.8.4.1b-3.1) stable-security; urgency=high * Non-maintainer upload by security team * Merge patch from SCO advisory CSSA-2002-049.0 (but without the bits that create backup files). This fixes handling of CRLF in external URLs. -- Wichert Akkerman Fri, 22 Nov 2002 21:49:57 +0100 lynx-ssl (1:2.8.4.1b-3) unstable; urgency=low * Adopted the package, closes: #130831. * debian/control (Standards-Version): bump to 3.5.6.0. * debian/copyright: updated. * debian/README.Debian: likewise. * debian/postinst: remove commented and unused code. * debian/prerm: likewise. * debian/postrm: homogenize the code. * debian/test.html: unused; removed. * debian/dhelp: remove. * debian/rules: rewritten so I can work with it. * src/LYStrings.c, src/HTAlert.c: Apply patch from Hataguchi Takeshi to fix blinking problems for euc-jp charset users, thanks to Atsuhito Kohda. (#119510). * debian/control (Priority): optional, since we conflict with lynx (standard). -- James Troup Sat, 26 Jan 2002 03:25:22 +0000 lynx-ssl (1:2.8.4.1b-2) unstable; urgency=low * Orphaned this package. -- Adrian Bunk Fri, 25 Jan 2002 13:02:11 +0100 lynx-ssl (1:2.8.4.1b-1) unstable; urgency=high * New maintainer. Many thanks to Christoph for maintaining lynx-ssl the last years! * Changed the packaging: - The .orig.tar.gz is now the upstream source and not the lynx package. - Conflict with lynx. (closes: #86153) - Moved /etc/lynx-ssl.cfg to /etc/lynx.cfg. * The documentation is now also available via /usr/(share/)doc/lynx. (closes: #110872) * New upstream release. - This release fixes some crashes in UTF-8 mode. (fixes: #112727) - The CPU loop bug was fixed. (fixes: #113298) * Compiled without "--enable-file-upload" (there's a big security hole in the file uploading code). * Changed the default key bindings in src/LYEditmap.c to "Bash-like Bindings". (fixes: #43223) * Compiled without "--enable-nsl-fork". (fixes: #112081) * Compiled without "--enable-justify-elts". (fixes: #109737, #111150, #115825) * s/Web browser/Web browsers/ in debian/menu. (fixes: #80048) -- Adrian Bunk Sun, 21 Oct 2001 22:15:58 +0200 lynx-ssl (2.8.4.2-1) unstable; urgency=low * New upstream release (closes: #106240) * lynx and lynx-ssl no longer use debconf. This removes the problem with it changing /etc/lynx-ssl.cfg (closes: #67836, #110571) -- Christoph Martin Thu, 30 Aug 2001 11:13:27 +0200 lynx (2.8.4-2) unstable; urgency=low * There wre two (commented out) definitions for COLOR:6 in the default lynx.cfg. (closes: #109382) -- Adrian Bunk Mon, 20 Aug 2001 21:45:53 +0200 lynx (2.8.4-1) unstable; urgency=high * New maintainer. * New upstream release. (closes: #80496) This release fixes the following bugs: - %s, %t, %{charset} and %{encoding} substitutions for mailcap commands are now implemented. (closes: #21096) - The "<> in javascript causes premature " problem is fixed. (closes: #65151) - A problem with the length of form fields is fixed. (closes: #68542) - The Japanese message catalog is now included. (closes: #63641) - The CPU-loop seems to be fixed. (closes: #25968) * /etc/lynx.cfg is now a conffile. (closes: #40482) * The default startfile is now the local helpfile (and there's no longer a question in the postinst). (closes: #105559, #83249, #83784) * Disable USE_MOUSE in the default configuration. (closes: #42859) * Set GLOBAL_EXTENSION_MAP and PERSONAL_EXTENSION_MAP in the default lynx.cfg. (closes: #94604) * Compiled with ncurses instead of slang. * Compiled with "--enable-warnings". * Compiled with "--enable-color-style". * Compiled with "--enable-default-colors". (closes: #45803) * Compiled with "--enable-file-upload". (closes: #56639) * Compiled with "--enable-ipv6". * Compiled with "--enable-justify-elts". * Compiled with "--enable-nested-tables". * Compiled with "--enable-read-eta". * Updated debian/copyright. (closes: #63638) -- Adrian Bunk Sat, 18 Aug 2001 16:22:26 +0200 lynx (2.8.3-1.5) unstable; urgency=low * Non-maintainer upload. * Update config.{guess,sub} to allow building on SH and others. (Closes: #95763) * Set DEFAULT_EDITOR in lynx.cfg to /usr/bin/sensible-editor. (Closes: #94605) -- André Dahlqvist Wed, 13 Jun 2001 05:45:56 +0200 lynx-ssl (2.8.3.1.4-1) unstable; urgency=medium * get lynx-ssl in line with lynx * adds a lot of translations * lynx-ssl.cfg is no longer a conffile (closes: #67836) * use version lynx2.8.3rel.1c * make dpkg-divert in postinst quiet -- Christoph Martin Wed, 13 Jun 2001 20:00:05 +0200 lynx (2.8.3-1.4) unstable; urgency=low * Non-maintainer upload. * Recompiled against sid's version of slang1. -- Matthew Danish Mon, 23 Apr 2001 00:14:58 -0400 lynx (2.8.3-1.3) unstable; urgency=low * NMU * Removed check for already done configuration in debian/config so that dpkg-recofigure will be able to do its work. (Closes: #54237) -- Gustavo Noronha Silva Sat, 21 Apr 2001 17:42:02 -0300 lynx (2.8.3-1.2) unstable; urgency=low * NMU * Removed /etc/lynx.cfg from conffiles as it is handled by postinst /etc/lynx-ssl.cfg is not there so: (Closes: #40482, #67836) * Added german and pt_BR translations for the debconf template, thanks to and Gustavo Noronha Silva (KoV)" there're 2 other pt_BR and de templates wich I'll discard and close the bug (Closes: #83925, #83926, #92841, #93227) * closes french template translation bug as it was already added in a earlier upload (Closes: #64785) * Added hint to lynx in debian/menu (Closes: #80048) * Removed about_wml directory from docdir as it was empty (Closes: #64785) * Updated debian/rules to use debian/lynx instead of debian/tmp * Applied patches to upgrade to version lynx2.8.3rel.1c -- Gustavo Noronha Silva Sat, 21 Apr 2001 15:57:30 -0300 lynx (2.8.3-1.1) unstable; urgency=medium * Non-maintainer upload. * Fixed bug preventing -dump when TERM=dumb. (Closes: #64632) * Lynx will no longer try to write file on full disk. (Closes: #63391) * Changed deprecated 'isdefault' to 'seen' in debconf config. * Fixed bug in intl/makefile.in, it did not remove libintl.h. (Closes: #63999) * Fixed color scheme. (Closes: #32959) * Added Swedish translation to templates. (Closes: #83482) * Added French translation to templates. (Closes: #83767) * Added Spanish translation to templates. (Closes: #92373) * Fixed original source URL in copyright file. (Closes: #74551) * Upload sponsored by Lenart Janos . -- Matthew Danish Sat, 14 Apr 2001 14:12:43 -0400 lynx-ssl (2.8.3.1-3) unstable; urgency=low * linked against libssl096 (closes: #82077, #81968) * change section from web to non-us/main (closes: #82056) * change builddepends from libssl09-dev to libssl096-dev (closes: #77606) * cleanup in README.SSL (closes: #74565) -- Christoph Martin Tue, 16 Jan 2001 15:45:25 +0100 lynx-ssl (2.8.3.1-2) unstable; urgency=low * linked against new libssl (closes: #66307) -- Christoph Martin Mon, 4 Sep 2000 20:47:23 +0200 lynx-ssl (2.8.3.1-1) frozen unstable; urgency=high * fixes security hole, buffer overflow (critical bug) (closes: #63462) -- Christoph Martin Fri, 5 May 2000 13:40:02 +0200 lynx (2.8.3-1) frozen unstable; urgency=medium * Upgraded to new upstream release. Buffer overflows fixed. (Closes: #59191) * Disabled PREPEND_BASE_TO_SOURCE in default lynx.cfg. (Closes: #63000) * Probably also fixes a bunch of other bugs, but I'll go through the bug list in -2. -- Christian Hudon Mon, 1 May 2000 21:54:42 -0400 lynx-ssl (2.8.2.6-2) frozen unstable; urgency=high * fix typo in postinst, which changed /etc/lynx.cfg instead of /etc/lynx-ssl.cfg and so prevented lynx-ssl from getting configured. (closes: #63383) -- Christoph Martin Tue, 2 May 2000 15:11:25 +0200 lynx-ssl (2.8.2.6-1) frozen unstable; urgency=low * closeup with version of lynx to have lynx and lynx-ssl with parallel features (and bug fixes) -- Christoph Martin Mon, 13 Mar 2000 22:29:23 +0100 lynx (2.8.2-6) frozen unstable; urgency=low * Disabled dhelp. (Closes: #55926, #56360) -- Christian Hudon Thu, 3 Feb 2000 22:03:23 -0500 lynx-ssl (2.8.2.5-3) frozen unstable; urgency=high * remove diversion of old manpage in postinst instead of preinst (closes: Bug#55784) * added libssl09-dev to build-depends (closes: Bug#56706) -- Christoph Martin Tue, 1 Feb 2000 22:05:23 +0100 lynx-ssl (2.8.2.5-2) frozen unstable; urgency=medium * reupload because last changelog entry was wrong. Should read: * based on new Debian version of lynx to have lynx and lynx-ssl with parallel features (and bug fixes) * fixes diversion problem with manpages (closes: Bug#55784) * adds menu entries as lynx does it (closes: Bug#55642, #55710) -- Christoph Martin Fri, 21 Jan 2000 11:07:13 +0100 lynx-ssl (2.8.2.5-1) frozen unstable; urgency=low * new upstream -- Christoph Martin Tue, 18 Jan 2000 18:42:29 +0100 lynx (2.8.2-5) unstable; urgency=low * Updated Source-Depends line. (Closes: #54256) * Applied patch from Joey Hess to work around unknown debconf error. (Closes: #53999, #54257, #54790) -- Christian Hudon Wed, 12 Jan 2000 20:43:55 -0500 lynx (2.8.2-4) unstable; urgency=low * Updated to standards version 3.1.1.1 * Added debconf support. -- Christian Hudon Fri, 31 Dec 1999 14:50:27 -0500 lynx-ssl (2.8.2.3-2) unstable; urgency=low * fix problem with linking to outdated libraries (closes: Bug#46915, Bug#46915) * change default gettext domain to lynx-ssl (closes: Bug#45585, Bug#46141) * accept https in postinst for default URL (closes: Bug#46737) -- Christoph Martin Fri, 15 Oct 1999 11:27:00 +0200 lynx-ssl (2.8.2.3-1) unstable; urgency=low * New upstream debian version * fix mime file (Bug #41249, #43591) -- Christoph Martin Fri, 17 Sep 1999 22:21:29 +0200 lynx (2.8.2-3) unstable; urgency=medium * Removed mailcap processing order patch, since it clashed with upstream patch. (closes: #41199) * Added ja.po Japanese translation of lynx and enabled a few more switches (--enable-nls, --enable-source-cache and --enable-prettysrc). (closes: #40958) * Install more files from samples directory. (closes: #41153) * Applied upstream patch to close telnet: security hole. (closes: #44001) * Removed 'NO_STRING_INLINES' kludge in debian/rules. -- Christian Hudon Mon, 6 Sep 1999 22:39:47 -0400 lynx (2.8.2-2) unstable; urgency=medium * Recompiled with new slang1 to fix dependency bug. -- Christian Hudon Thu, 26 Aug 1999 00:01:42 -0400 lynx-ssl (2.8.2.1-2) unstable; urgency=low * type in Maintainer field -- Christoph Martin Mon, 12 Jul 1999 12:21:33 +0200 lynx-ssl (2.8.2.1-1) unstable; urgency=low * New upstream ssl patches (Bug #41035) * Provides lynx now and does no longer conflict it (Bug #34058, #34128, #34410, #35285, #35712, #36871, #37728, #40057) * move lynx.cnf to lynx-ssl.cnf to not conflict with lynx (Bug #37424) -- Christoph Martin Sun, 11 Jul 1999 15:12:14 +0200 lynx (2.8.2-1) unstable; urgency=low * New upstream version. Will fix Debian bugs in next release. -- Christian Hudon Sun, 13 Jun 1999 22:15:03 -0400 lynx (2.8.1-7) unstable; urgency=low * Fixed problem in postinst that caused spurious error message to be printed when /etc/news/server did not exist. (closes: #37720, 37773) -- Christian Hudon Sun, 16 May 1999 22:54:48 -0400 lynx (2.8.1-6) unstable; urgency=low * Set default editor in lynx.cfg to /usr/bin/sensible-editor. (closes: #37509, #14728) * Applied patch from Peter Samuelson to fix problems with postinst. (closes: #31638) -- Christian Hudon Tue, 11 May 1999 21:05:51 -0400 lynx (2.8.1-5) unstable; urgency=low * Remove prcs files before packaging lynx for upload. (closes: #36962) * Applied upstream patch to fix multiline bug, etc. (closes #33158) -- Christian Hudon Mon, 10 May 1999 20:55:30 -0400 lynx (2.8.1-4) unstable; urgency=low * Filter out lines that start with a '#' in /etc/news/server (closes: #31638). * Fixed dhelp support (closes: #34479). * Recompiled with glibc 2.1.1 -- Christian Hudon Sun, 4 Apr 1999 22:27:49 -0400 lynx-ssl (2.8.1-2) unstable; urgency=low * linked against new libssl09 (openssl) -- Christoph Martin Tue, 4 May 1999 15:22:23 +0200 lynx-ssl (2.8.1-1) unstable; urgency=low * Applied ssl-patch from http://www.moxienet.com/lynx/ -- Christoph Martin Thu, 25 Feb 1999 16:12:27 +0100 lynx (2.8.1-3) frozen unstable; urgency=medium * Applied patch from OpenBSD to prevent lynx captive users from spawning a shell using rlogin/telnet URLs. * Postinst now checks that the url given is absolute. (Closes bug #29177) * Updated README.Debian file. (Closes bug #30488) * Added dhelp support. (Closes bug #31159) * Included some more files from the lynx source in /usr/doc/lynx (Closes bug #30489) * Applied upstream bugfix patches. (Closes bug #30487) * Version 2.8.1 includes many small security fixes over 2.8 (Closes bug #31985) -- Christian Hudon Sun, 17 Jan 1999 21:27:04 -0500 lynx (2.8.1-2) unstable; urgency=low * Build LYMainLoop.c with -D__NO_STRING_INLINES on powerpc to work around egcs bug. (closes bug #29750) * Modified postint so that lynx can be installed non-interactively. (closes bug #28893). * Removed unnecessary references to VMS in lynx.cfg * Enabled use_mouse option by default. * Lynx now obeys TMPDIR. (closes bug #21878) * Documented how to set colors on a per-user basis in README.Debian (partially solves bug #29469). * Also closed a bunch of other bug reports that were fixed in the 2.8 series. * Added "lynx -dump" entry with copiousoutput in mailcap for mutt autoview. -- Christian Hudon Sat, 21 Nov 1998 22:00:32 -0500 lynx (2.8.1-1) unstable; urgency=low * New upstream version (fixes bug #28964) * Enabled persistent cookies. * Other bugfixes will go into next Debian release. -- Christian Hudon Wed, 11 Nov 1998 22:16:31 -0500 lynx (2.8-4) frozen unstable; urgency=low * Recompiled with slang1. -- Christian Hudon Sun, 18 Oct 1998 19:37:40 -0400 lynx (2.8-3) unstable; urgency=low * Upgraded to latest mime-support (fixes bug #12663, 23740, 24806) -- Christian Hudon Wed, 14 Oct 1998 20:52:06 -0400 lynx (2.8-2) frozen unstable; urgency=HIGH * Applied patch to fix buffer overflows in LYMail.c (fixes bug #22165, 22154) * Removed doscs/CHANGES2-10 files that had been used for testing of debian/rules. * Added section and priority to control file (fixes bug# 20420). * Includes FSSTND-compliant compiled-in defaults for mime.types and mailcap. (fixes bug #21441). * Lynx now uses the first entry in the mailcap instead of the last one. (fixes bugs #7595, 10247) -- Christian Hudon Sun, 31 May 1998 00:55:54 -0400 lynx (2.8-1) unstable; urgency=low * Upgraded to latest release (Fixes bug #19526) -- Christian Hudon Thu, 12 Mar 1998 13:57:49 -0500 lynx (2.7.2-1) unstable; urgency=low * SECURITY FIX: postinst now avoids using /tmp (Fixes bug #11771) * Upgraded to new upstream release. (Fixes bug #16444) * Recompiled for libc6. (Fixes bug #11704) * Enabled multi-bookmarks support in userders.h * Corrected tar path. (Fixes bug #12005) * Compiled with -DNSL_FORK, so that users can abort hostname lookups with the 'z' key. (Fixes bug #11586) * Modified postinst so that prompting doesn't occur on abort-upgrade, etc. (Fixes bug #12630) * Postinst now handles URL with spaces better.. (Fixes bug #13137) * Lynx now properly resets idle time (Fixes bug #11582) -- Christian Hudon Fri, 25 Feb 1998 17:22:22 -0500 lynx (2.7.1-3) stable unstable; urgency=HIGH * SECURITY FIX: applied patch from Foteos Macrides to prevent captive lynx users from executing arbitrary commands. * Applied one-line libc6 patch. (Fixes bug 8583) * Applied patch from John E. Davis to correct screen redraw problem. (Fixes bug 6035 and 9406) * Applied patch from Laura Eaves to fix 'underlined links' problem. (Fixes bug 7846) * Applied patch from John E. Davis to fix "Control-Z on Unix can cause aberrant behavior" bug. * Applied patches from Foteos Macrides to fix bugs 8063 (lynx saves gzipped files as not gzipped) and 7820 (lynx misinperprets ^G on quit confirmation). * Added /usr/doc/lynx/README.Debian explaining how to fix 'colorless lynx' problem (closes bug 10482) and how to get white background on black (closes bug 9320). * Added location of upstream source to copyright file (fixes bug 11101) -- Christian Hudon Mon, 14 Jul 1997 21:15:42 +0000 lynx (2.7.1-2) stable; urgency=medium * Oops! Last version that was uploaded to stable depended on slang library available only from frozen/unstable! Recompiled with slang packages from stable. (Fixes 9958, 9968) -- Christian Hudon Sun, 25 May 1997 00:04:55 +0000 lynx (2.7.1-1) stable frozen unstable; urgency=HIGH * Set TEMP_SPACE to ~/ as a temporary fix for the lynx /tmp security problem! (Lynx will happily follow symlinks found in /tmp...) * Upgraded to upstream 2.7.1 bugfix release (Lynx 2.7 + upstream bugfix patch + two more bugs fixed). * Fixed typo in install-mime call of postinst (fixes 9213). * Does not prompt user to enter their email address when sending mail anymore. * Applied patch from John E. Davis that fixes a buglet. * Reenabled dired support, which had been disabled by mistake (fixes 8970). * Applied patch from Fotoes Macrides that fixes two buglets discovered by Rick Mallett during a Purify run. * Made sure that lynxprog, lynxexec and lynxcgi are disabled in default lynx.cfg. -- Christian Hudon Fri, 16 May 1997 00:02:23 -0400 lynx (2.7-2) frozen unstable; urgency=low * Applied upstream bug fix patches for lynx 2.7 (Fixes bug 8090) * Lynx now properly handles %-encoded characters in mailto URLs. (Fixes 4225) * Lynx registers itself in /etc/mailcap for text/html (Fixes 7769, 7919) * Set lynx.cfg default colors to black background. (Fixes 7866) * Fixed bug 6120 (lynx can't find image/jpeg viewer). * Fixed bug 4005 (lynx thinks *.deb is text/plain in ftp). * Set compile-time XLOADIMAGE_COMMAND to "" since a) there's no garantee that xli/xv/whatever is installed b) Debian's mailcap is populated automatically, so there's not much of a need for a default image viewer. Closes bug 4909 and 4918 * Moved Lynx help files to /usr/doc but left them uncompressed, otherwise lynx's help function will break. (Fixes 8003) * Lynx manual is now accessible under dwww. * Removed VMS-related documentation from /usr/doc/lynx * Lynx CHANGES* files are now installed as /usr/doc/lynx/changelog.gz -- Christian Hudon Sun, 30 Mar 1997 23:48:14 -0500 lynx (2.7-1) unstable; urgency=low * New upstream version. * Added support for 'menu' package. Lynx menu entry is installed in Apps/Net. * Compiled with slang instead of ncurses to get color support. -- Christian Hudon Wed, 26 Feb 1997 23:19:28 -0500 lynx (2.6-2) unstable; urgency=low * Added install-fvwm2menu support from Lars Wirzenius's patch. (Until a more general 'install-menu' script comes along.) * /etc/lynx.cfg is now removed when the lynx package is purged. * lynx -dump has no problems with proxies now. (2964) * Lynx postinst now attempts to pick a reasonable default for the default homepage (3469) -- Christian Hudon Sat, 19 Oct 1996 21:52:14 -0400 lynx (2.6-1) unstable; urgency=medium * Upgraded to latest upstream version. (4434, 2295) * Converted to new source package format. * Compiled in lynxexec/lynxprog/lynxcgi extensions. (2965) * Enabled access to dot files. (3105) * Version number such that dselect will not think we're downgrading. (3386) * Removed extraneous space in extended description. (3606) -- Christian Hudon Tue, 24 Sep 1996 17:49:30 -0400