changelog 5.5 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162
  1. jasper (1.900.1-13) unstable; urgency=high
  2. * Fix CVE-2011-4516 and CVE-2011-4517: Two buffer overflow issues possibly
  3. exploitable via specially crafted input files (Closes: #652649)
  4. Thanks to Red Hat and Michael Gilbert
  5. -- Roland Stigge <stigge@antcom.de> Wed, 04 Jan 2012 19:14:40 +0100
  6. jasper (1.900.1-12) unstable; urgency=low
  7. * Added patch to fix filename buffer overflow, thanks to Jonas Smedegard
  8. and Alex Cherepanov from ghostscript (Closes: #649833)
  9. -- Roland Stigge <stigge@antcom.de> Sun, 27 Nov 2011 19:56:01 +0100
  10. jasper (1.900.1-11) unstable; urgency=low
  11. * Added Multiarch support, thanks to Colin Watson (Closes: #645118)
  12. -- Roland Stigge <stigge@antcom.de> Wed, 02 Nov 2011 17:16:10 +0100
  13. jasper (1.900.1-10) unstable; urgency=low
  14. * Added debian/watch
  15. * debian/patches/01-misc-fixes.patch:
  16. - Separated out config.{guess,sub}
  17. -- Roland Stigge <stigge@antcom.de> Mon, 15 Aug 2011 19:09:29 +0200
  18. jasper (1.900.1-9) unstable; urgency=low
  19. * Switch to dpkg-source 3.0 (quilt) format
  20. * Using new dh 7 build system
  21. -- Roland Stigge <stigge@antcom.de> Tue, 12 Jul 2011 20:21:21 +0200
  22. jasper (1.900.1-8) unstable; urgency=low
  23. * Removed unneeded .la file (Closes: #633162)
  24. * debian/control:
  25. - Standards-Version: 3.9.2
  26. - use libjpeg8-dev instead of libjpeg62-dev
  27. -- Roland Stigge <stigge@antcom.de> Mon, 11 Jul 2011 21:27:24 +0200
  28. jasper (1.900.1-7) unstable; urgency=low
  29. * Acknowledge NMU
  30. * Added patch to fix Debian patch for CVE-2008-3521 (Closes: #506739)
  31. * debian/control: Standards-Version: 3.8.4
  32. -- Roland Stigge <stigge@antcom.de> Sun, 21 Feb 2010 16:09:45 +0100
  33. jasper (1.900.1-6.1) unstable; urgency=low
  34. * Non-maintainer upload.
  35. * This is a fix for the GeoJP2 patch introduced in 1.900.1-5 which caused
  36. GDAL faulting. Thanks Even Rouault. (Closes: #553429)
  37. -- Francesco Paolo Lovergine <frankie@debian.org> Wed, 28 Oct 2009 09:39:28 +0100
  38. jasper (1.900.1-6) unstable; urgency=low
  39. * Reverted to jasper 1.900.1-6 because 1.900.1-5.1 messed up (see #528543)
  40. but 1.900.1-5 wasn't available anymore. (Closes: #514296, #528543)
  41. * Re-applied patch from #275619 as in 1.900.1-5
  42. * debian/control: Standards-Version: 3.8.2
  43. * Applied patch by Nico Golde (Closes: #501021)
  44. - CVE-2008-3522[0]: Buffer overflow.
  45. - CVE-2008-3521[1]: unsecure temporary files handling.
  46. - CVE-2008-3520[2]: Multiple integer overflows.
  47. -- Roland Stigge <stigge@antcom.de> Sat, 20 Jun 2009 15:21:16 +0200
  48. jasper (1.900.1-5.1) unstable; urgency=low
  49. * Non-maintainer upload.
  50. * add patches/02_security.dpatch to fix various CVEs (Closes: #501021):
  51. + CVE-2008-3522[0]: Buffer overflow.
  52. + CVE-2008-3521[1]: unsecure temporary files handling.
  53. + CVE-2008-3520[2]: Multiple integer overflows.
  54. -- Pierre Habouzit <madcoder@debian.org> Sun, 12 Oct 2008 21:40:59 +0200
  55. jasper (1.900.1-5) unstable; urgency=low
  56. * Added GeoJP2 patch by Sven Geggus <sven.geggus@iitb.fraunhofer.de>
  57. (Closes: #275619)
  58. * debian/control: Standards-Version: 3.8.0
  59. -- Roland Stigge <stigge@antcom.de> Sun, 08 Jun 2008 13:14:24 +0200
  60. jasper (1.900.1-4) unstable; urgency=low
  61. * src/libjasper/jpc/jpc_dec.c: Extended assert() to accept 4 color
  62. components (Closes: #469786)
  63. * debian/rules: improve "make distclean", thanks to lintian
  64. * debian/control:
  65. - Standards-Version: 3.7.3
  66. - ${Source-Version} -> ${binary:Version}
  67. - Removed self-dependencies of libjasper-dev
  68. -- Roland Stigge <stigge@antcom.de> Sun, 09 Mar 2008 11:53:44 +0100
  69. jasper (1.900.1-3) unstable; urgency=low
  70. * Fixed segfaults on broken images (Closes: #413041)
  71. -- Roland Stigge <stigge@antcom.de> Tue, 10 Apr 2007 10:05:10 +0200
  72. jasper (1.900.1-2) experimental; urgency=low
  73. * Added jas_tmr.h to -dev package (Closes: #414705)
  74. -- Roland Stigge <stigge@antcom.de> Tue, 13 Mar 2007 14:23:58 +0100
  75. jasper (1.900.1-1) experimental; urgency=low
  76. * New upstream release
  77. * debian/control:
  78. - Standards-Version: 3.7.2
  79. - Build-Depends: freeglut3-dev instead of libglut3-dev (Closes: #394496)
  80. * Renamed packages to libjasper1, libjasper-dev, libjasper-runtime according
  81. to upstream shared library naming change
  82. -- Roland Stigge <stigge@antcom.de> Fri, 26 Jan 2007 14:22:18 +0100
  83. jasper (1.701.0-2) unstable; urgency=low
  84. * Prevent compression of pdf documents in binary packages
  85. * Added man pages for the executables (Closes: #250077)
  86. * Again renamed binary packages to reflect Policy:
  87. - libjasper-1.701-1
  88. - libjasper-1.701-dev (Provides, Replaces and Conflicts: libjasper-dev)
  89. - libjasper-runtime
  90. -- Roland Stigge <stigge@antcom.de> Sun, 20 Jun 2004 13:54:10 +0200
  91. jasper (1.701.0-1) unstable; urgency=low
  92. * New maintainer (Closes: #217099)
  93. * New upstream release (Closes: #217570)
  94. - new DFSG-compliant license (Closes: #218999, #245075)
  95. - includes newer libtool related files (Closes: #210383)
  96. * debian/control:
  97. - Standards-Version: 3.6.1
  98. - Changed binary package names, fixed interdependencies (Closes: #211592)
  99. libjasper-1.700-2 => libjasper1
  100. libjasper-1.700-2-dev => libjasper-dev
  101. libjasper-progs => libjasper-runtime
  102. (new packages conflicting and replacing the old ones)
  103. - Added libxi-dev, libxmu-dev, libxt-dev to Build-Depends
  104. (Closes: #250481)
  105. -- Roland Stigge <stigge@antcom.de> Sat, 19 Jun 2004 23:19:32 +0200
  106. jasper (1.700.2-1) unstable; urgency=low
  107. * Initial Release.
  108. -- Christopher L Cheney <ccheney@debian.org> Fri, 22 Aug 2003 01:30:00 -0500