diff -u lcms-1.18.dfsg/debian/changelog lcms-1.18.dfsg/debian/changelog --- lcms-1.18.dfsg/debian/changelog +++ lcms-1.18.dfsg/debian/changelog @@ -1,3 +1,11 @@ +lcms (1.18.dfsg-1ubuntu1) karmic; urgency=low + + * Merge from debian unstable (LP: #388987), remaining changes: + - Adjust debian/rules to account for either site-packages or dist-packages + for Python 2.6 transition + + -- Muharem Hrnjadovic Thu, 18 Jun 2009 15:53:44 +0200 + lcms (1.18.dfsg-1) unstable; urgency=low * New upstream release. It includes correct fixes for the security problems @@ -5,6 +13,14 @@ -- Oleksandr Moskalenko Fri, 03 Apr 2009 08:50:38 -0600 +lcms (1.18.dfsg-0ubuntu1) jaunty; urgency=low + + * New upstream release + * Remove 11_security_CVE-2009-0581_0723_0733.dpatch, security + issues fixed upstream + + -- Jonathan Riddell Fri, 03 Apr 2009 13:55:00 +0100 + lcms (1.17.dfsg-2) unstable; urgency=low [Steffen Joeris ] @@ -13,6 +29,31 @@ -- Oleksandr Moskalenko Thu, 12 Mar 2009 10:38:30 -0600 +lcms (1.17.dfsg-1ubuntu2) jaunty; urgency=low + + * SECURITY UPDATE: Denial of service via large memory leak + - debian/patches/11_security_CVE-2009-0581_0723_0733.dpatch: properly + free memory in src/cmsio1.c. + - CVE-2009-0581 + * SECURITY UPDATE: Arbitrary code execution due to integer overflows + - debian/patches/11_security_CVE-2009-0581_0723_0733.dpatch: add new + calloc function in include/lcms.h and fix overflows in src/cmsgamma.c, + src/cmsio0.c, src/cmsio1.c and src/cmslut.c. + - CVE-2009-0723 + * SECURITY UPDATE: Arbitrary code execution due to buffer overflow + - debian/patches/11_security_CVE-2009-0581_0723_0733.dpatch: add + _cmsValidateLUT() and use in src/cmsio1.c and src/cmslut.c. + - CVE-2009-0733 + + -- Marc Deslauriers Fri, 20 Mar 2009 15:04:07 -0400 + +lcms (1.17.dfsg-1ubuntu1) jaunty; urgency=low + + * Adjust debian/rules to account for either site-packages or dist-packages + for Python 2.6 transition + + -- Scott Kitterman Sun, 08 Mar 2009 12:08:08 -0400 + lcms (1.17.dfsg-1) unstable; urgency=low * Removed Adobe sRGB profiles from the testdbed and python/testbed @@ -350,0 +392 @@ + diff -u lcms-1.18.dfsg/debian/control lcms-1.18.dfsg/debian/control --- lcms-1.18.dfsg/debian/control +++ lcms-1.18.dfsg/debian/control @@ -1,7 +1,8 @@ Source: lcms Section: libs Priority: optional -Maintainer: Oleksandr Moskalenko +Maintainer: Ubuntu Core Developers +XSBC-Original-Maintainer: Oleksandr Moskalenko Build-Depends: debhelper (>> 5.0.38), libtiff4-dev, libjpeg62-dev, zlib1g-dev, python-all-dev (>= 2.3.5-11), python-support (>= 0.6.3), dpatch, swig Standards-Version: 3.8.0 Vcs-Svn: svn://svn.debian.org/svn/collab-maint/deb-maint/lcms/trunk/ diff -u lcms-1.18.dfsg/debian/rules lcms-1.18.dfsg/debian/rules --- lcms-1.18.dfsg/debian/rules +++ lcms-1.18.dfsg/debian/rules @@ -56,8 +56,8 @@ dh_clean -k dh_installdirs make DESTDIR=`pwd`/debian/tmp install - rm -rf `pwd`/debian/tmp/usr/lib/python*/site-packages/*.a \ - `pwd`/debian/tmp/usr/lib/python*/site-packages/*.la + rm -rf `pwd`/debian/tmp/usr/lib/python*/*-packages/*.a \ + `pwd`/debian/tmp/usr/lib/python*/*-packages/*.la # Build architecture-independent files here. binary-indep: build install