[Bug 407985] [NEW] Please sync xcftools 1.0.7-1 (universe) from Debian unstable (main).
Bhavani Shankar
right2bhavi at gmail.com
Sun Aug 2 12:40:58 UTC 2009
Public bug reported:
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
affects ubuntu/xcftools
status new
importance wishlist
subscribe ubuntu-universe-sponsors
Please sync xcftools 1.0.7-1 (universe) from Debian unstable (main).
Please sync the latest version from debian as it contains a cve fix.
Changelog since current karmic version 1.0.4-2:
xcftools (1.0.7-1) unstable; urgency=high
* Adopted (Closes: #525920)
+ with urgency=high for the security issue
+ with new debian/copyright according to upstream's relicensing
* New upstream release (1.0.7)
+ Fix GPL-to-PD transition: missed copyright blurb in online banner.
* IMPORTANT CHANGE: xcfview is rewritten to use xdg-utils in order to find
an image viewer instead of parsing /etc/mailcap on its own
* New upstream release (1.0.6)
+ Change licensing from GPL-2 to PD.
+ Fix bug: A layer without an alpha channel bug with an active layer mask
was wrongly considered to obscure all lower layers.
+ Fix bug: xcf2pnm would guess PBM as the output format even if the
background was explicitly set to an intermediate gray, or if -T might
produce grays.
* New upstream release (1.0.5)
+ Fix various bugs if extracted part of image contains pixels with
negative canvas-based coordinates. Thanks Jörgen Grahn (Closes: #533361,
CVE-2009-2175)
+ Minor manpage fixes; -C description should be less confusing now.
+ $(DESTDIR) honored in Makefile's install target
* Use quilt for patches
* Bump standards-version: 3.8.2
* Added debian/watch
* Switched to debhelper 7
* debian/control: Reorganized Recommends and Suggests
-- Jan Hauke Rahm <info at jhr-online.de> Tue, 14 Jul 2009 17:02:09 +0200
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)
iD8DBQFKdYuwNrEIsZrsMaARAuwzAJ4hZrSnMFR7WyxQbDza76i4qU+n9wCcCjFZ
ALtNfs4SaRbXzFaYLvPp9QE=
=zuTm
-----END PGP SIGNATURE-----
** Affects: xcftools (Ubuntu)
Importance: Wishlist
Status: New
** CVE added: http://www.cve.mitre.org/cgi-
bin/cvename.cgi?name=2009-2175
--
Please sync xcftools 1.0.7-1 (universe) from Debian unstable (main).
https://bugs.launchpad.net/bugs/407985
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
--
ubuntu-bugs mailing list
ubuntu-bugs at lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs
More information about the universe-bugs
mailing list