Commitlog between the 20151014.1 and 20151015 rootfs for ubuntu-touch/rc-proposed/bq-aquaris.en krillin === CI Train landings === Title: click hotfix for LP: #1506467 - click install does not ignore shipped files without leading './' Owner: jdstrand Source packages modified: click Changelogs: click (0.4.40+15.04.20151006-0ubuntu1.1) * SECURITY UPDATE: fix privilege escalation via crafted data.tar.gz that can be used to install alternate security policy than what is defined - click/install.py: Forbid installing packages with data tarball members whose names do not start with "./". Patch thanks to Colin Watson. - CVE-2015-XXXX - LP: #1506467 Included binary packages: click from 0.4.40+15.04.20151006-0ubuntu1 to 0.4.40+15.04.20151006-0ubuntu1.1 gir1.2-click-0.4 from 0.4.40+15.04.20151006-0ubuntu1 to 0.4.40+15.04.20151006-0ubuntu1.1 libclick-0.4-0:armhf from 0.4.40+15.04.20151006-0ubuntu1 to 0.4.40+15.04.20151006-0ubuntu1.1 packagekit-plugin-click from 0.4.40+15.04.20151006-0ubuntu1 to 0.4.40+15.04.20151006-0ubuntu1.1 python3-click from 0.4.40+15.04.20151006-0ubuntu1 to 0.4.40+15.04.20151006-0ubuntu1.1 === Normal uploads (or not tracked) === === Upgraded Packages === lightdm from 1.14.2-0ubuntu1 to 1.14.2-0ubuntu1.1