Code

changelog: close #859494/CVE-2017-7401
[pkg-collectd.git] / debian / changelog
index 16ff8d4a7e0d241b593b27bca5401a76e5a9b9da..3ed78e39dc4d7748b95584284aa63edd4669a9eb 100644 (file)
@@ -1,3 +1,17 @@
+collectd (5.7.2-1) UNRELEASED; urgency=medium
+
+  * New upstream release.
+    - Fix potential endless-loop in the network plugin, which can be triggered
+      remotely by sending a crafted UDP packet (Closes: #859494,
+      CVE-2017-7401).
+  * debian/patches:
+    - drop dpdkstat_goto_label.patch; included upstream.
+    - drop drop_lssl_lcrypto_from_linking.patch; included upstream.
+    - drop mqtt_invalid_symbols.patch; included upstream.
+    - drop mqtt_resource_leak.patch; included upstream.
+
+ -- Marc Fournier <marc@bl.uem.li>  Wed, 23 Aug 2017 15:58:47 +0200
+
 collectd (5.7.1-1.1) unstable; urgency=medium
 
   * Non-maintainer upload.