[ubuntu/oneiric] libpng 1.2.46-3 (Accepted)

Marc Deslauriers marc.deslauriers at canonical.com
Wed Aug 10 12:59:45 UTC 2011


libpng (1.2.46-3) unstable; urgency=low

  * libpng12-0-udeb: Don't use bzip2 compression
    Closes: 634865

libpng (1.2.46-2) unstable; urgency=low

  [ Steve Langasek ]
  * Build for multiarch.  Requires converting libpng3 from Arch: all to
    Arch: any. Closes: 634151
  * Drop debian/libpng12-0-udeb.dirs, which just adds a pointless empty
    directory to the udeb.

  [ Anibal Monsalve Salazar ]
  * Fix doc-base file
    Closes: 633944, 633957, 634120
  * Pass "-Zbzip2 -z9" to dpkg-deb

libpng (1.2.46-1) unstable; urgency=high

  * New upstream release (Closes: #633871).
    - Fix CVE: CVE-2011-2690
      Buffer overwrite in png_rgb_to_gray
    - CVE: CVE-2011-2691
      Crash in png_default_error due to use of NULL Pointer
    - CVE: CVE-2011-2692
      Memory corruption when handling empty sCAL chunks
    - Update patches/01-legacy.patch
    - Remove patches/02-632786-CVE-2011-2501.patch. Applied to upstream.

libpng (1.2.44-3) unstable; urgency=high

  * Fix 1-byte uninitialized memory reference in png_format_buffer()
    Fix CVE-2011-2501
    Add debian/patches/02-632786-CVE-2011-2501.patch
    Closes: 632786
  * Standards version is 3.9.2
  * Fix xc-package-type-in-debian-control
  * Fix debian-rules-missing-recommended-target

Date: Wed,  10 Aug 2011 11:47:25 +0000
Changed-By: Marc Deslauriers <marc.deslauriers at canonical.com>
Maintainer: Anibal Monsalve Salazar <anibal at debian.org>
Origin: Debian/unstable
https://launchpad.net/ubuntu/oneiric/+source/libpng/1.2.46-3
-------------- next part --------------
Origin: Debian/unstable
Format: 1.7
Date: Wed,  10 Aug 2011 11:47:25 +0000
Source: libpng
Binary: libpng12-0, libpng12-dev, libpng3, libpng12-0-udeb
Architecture: source
Version: 1.2.46-3
Distribution: oneiric
Urgency: high
Maintainer: Anibal Monsalve Salazar <anibal at debian.org>
Changed-By: Marc Deslauriers <marc.deslauriers at canonical.com>
Closes: 632786 633871 633944 633957 634120 634151 634865
Files:
 aa6f952c74bf7934d13e8b11d42da540 1819 libs optional libpng_1.2.46-3.dsc
 68220fe515b7feb74a9acc3d9792d8d8 15580 libs optional libpng_1.2.46-3.debian.tar.bz2
 e8b43dc78ef95b3949af7f961d76874b 639676 libs optional libpng_1.2.46.orig.tar.bz2
Changes:
 libpng (1.2.46-3) unstable; urgency=low
 .
   * libpng12-0-udeb: Don't use bzip2 compression
     Closes: 634865
 .
 libpng (1.2.46-2) unstable; urgency=low
 .
   [ Steve Langasek ]
   * Build for multiarch.  Requires converting libpng3 from Arch: all to
     Arch: any. Closes: 634151
   * Drop debian/libpng12-0-udeb.dirs, which just adds a pointless empty
     directory to the udeb.
 .
   [ Anibal Monsalve Salazar ]
   * Fix doc-base file
     Closes: 633944, 633957, 634120
   * Pass "-Zbzip2 -z9" to dpkg-deb
 .
 libpng (1.2.46-1) unstable; urgency=high
 .
   * New upstream release (Closes: #633871).
     - Fix CVE: CVE-2011-2690
       Buffer overwrite in png_rgb_to_gray
     - CVE: CVE-2011-2691
       Crash in png_default_error due to use of NULL Pointer
     - CVE: CVE-2011-2692
       Memory corruption when handling empty sCAL chunks
     - Update patches/01-legacy.patch
     - Remove patches/02-632786-CVE-2011-2501.patch. Applied to upstream.
 .
 libpng (1.2.44-3) unstable; urgency=high
 .
   * Fix 1-byte uninitialized memory reference in png_format_buffer()
     Fix CVE-2011-2501
     Add debian/patches/02-632786-CVE-2011-2501.patch
     Closes: 632786
   * Standards version is 3.9.2
   * Fix xc-package-type-in-debian-control
   * Fix debian-rules-missing-recommended-target



More information about the Oneiric-changes mailing list