libgd2 (2.0.1-10woody2) stable-security; urgency=high * Non-maintainer upload by the Security Team * Added overflow and failed malloc protections to prevend buffer overflows that could lead to arbitrary code execution [gd.c, wbmp.c, gd_gd.c, gd_io_dp.c, gdxpm.c, CAN-2004-0941, CAN-2004-0990] * Added missing free() [gd_png.c] * Added nother integer overflow precaution by Stew Benedict [gd_png.c] -- Martin Schulze Tue, 16 Nov 2004 11:39:46 +0100 libgd2 (2.0.1-10woody1) stable-security; urgency=high * Non-maintainer upload by the Security Team * Added overflow protection to fix arbitrary code execution [gd_png.c, CAN-2004-0990] -- Martin Schulze Fri, 5 Nov 2004 12:09:38 +0100 libgd2 (2.0.1-10) unstable; urgency=low * Correct a typo (my fault!) whith the patch. This closes: bug#142946. -- Jonas Smedegaard Mon, 15 Apr 2002 11:22:32 +0200 libgd2 (2.0.1-9) unstable; urgency=low * Change ligd-tools priority from extra to optional. * Include patch from Stephen to handle antialiasing (let's hope we make it for Woody). -- Jonas Smedegaard Wed, 10 Apr 2002 12:48:11 +0200 libgd2 (2.0.1-8) unstable; urgency=low * Add both xpm and non-xpm to substvars files, thanks to Joey Hess. * Now that we are at it: Loosen up shlibs dependencies. -- Jonas Smedegaard Mon, 25 Mar 2002 22:46:10 +0100 libgd2 (2.0.1-7) unstable; urgency=low * Oops - now _really_ loosen up libpng2-dev dependency... -- Jonas Smedegaard Fri, 22 Feb 2002 04:43:53 +0100 libgd2 (2.0.1-6) unstable; urgency=low * Reflect changes in (NMU of) libpng3 and only Build-conflicts: the badly hinted one, to loosen up libpng2 dependency to all _real_ releases available (and possibly libpng3 if indeed it is/becomes as compatible as claimed!). * Change libgd-tools priority and libgd2-dev section to make Debian Installer happy. -- Jonas Smedegaard Fri, 22 Feb 2002 02:10:37 +0100 libgd2 (2.0.1-5) unstable; urgency=low * Build a -noxpm variant. -- Jonas Smedegaard Fri, 1 Feb 2002 02:49:59 +0100 libgd2 (2.0.1-4) unstable; urgency=low * Another workaround to the libpng{2,3} mess: build-depend on specific version to avoid illegal versioned build-conflict on (sometimes!) virtual package. This will probably cause problems on autobuilders as well (if they still see replacing libpng-dev with libpng2-dev as a downgrade), but should at least be legal. * Add readme.* to libgd2-dev. -- Jonas Smedegaard Sun, 20 Jan 2002 15:08:43 +0100 libgd2 (2.0.1-3) unstable; urgency=low * Put back conflicts/replaces on libgd-tools (<<2.0.0). They where needed after all (even though lintian complains). -- Jonas Smedegaard Sun, 13 Jan 2002 16:19:51 +0100 libgd2 (2.0.1-2) unstable; urgency=low * New maintainer (thanks, Ivo :-). Updating maintainer field. * Strip non-libgd2 part of changelog (go read the one from libgd package if interested in older changes). * Updating copyright file (Closes: #119288). * Cleanup old freetype2 (FreeType1) mess. * Use debhelper V3, tighten Build-Dependency on debhelper accordingly and remove postinst to have debhelper handle ldconfig correctly. * Build-Conflicts: libpng-dev (>= 1.2) (stuff like libgd-perl needs to know wether png2 or png3 is used - let's be conservative for a start). * Remove duplicate dependencies and strange conflicts/replaces (probably wrongly converted from those against libgd1g in libgd) in debian/control. -- Jonas Smedegaard Sun, 13 Jan 2002 15:50:02 +0100 libgd2 (2.0.1-1) unstable; urgency=low * Initial package, based upon libgd1. (Closes: #102179, #102494) -- Ivo Timmermans Sat, 18 Aug 2001 19:55:14 +0200