Merge gdk-pixbuf 2.36.0-1 (main) with Debian unstable (main)

Bug #1643222 reported by Jeremy Bícha
8
This bug affects 1 person
Affects Status Importance Assigned to Milestone
gdk-pixbuf (Ubuntu)
Fix Released
Wishlist
Unassigned

Bug Description

Please merge gdk-pixbuf 2.36.0-1 (main) with Debian unstable (main)

This update is needed by gtkm3.0 3.22:
https://launchpad.net/ubuntu/+source/gtkmm3.0/3.22.0-1/+build/11118318

Explanation of the Ubuntu delta and why it can be dropped:
  * SECURITY UPDATE: Fixes for write out-of-bounds error
   - debian/patches/CVE-2016-6352.patch: Be more careful when parsing ico
     headers. Based on upstream patch.
   - CVE-2016-6352

The patch was backported from 2.35.3 so it's not needed any more

This change is still needed by the Launchpad builders:
  * Merge from Debian unstable (LP: #1573839). Remaining changes:
    - Unset MALLOC_PERTURB_ for the /pixbuf/cve-2015-4491/original test, as
      it fails with OOM, or gets OOM killed.

Changelog entries since current zesty version 2.34.0-1ubuntu2:

gdk-pixbuf (2.36.0-1) unstable; urgency=medium

  * New upstream release.

 -- Michael Biebl <email address hidden> Mon, 19 Sep 2016 19:10:55 +0200

gdk-pixbuf (2.35.5-1) unstable; urgency=medium

  * New upstream development release.
  * Drop 02-tests-Make-sure-to-NULL-terminate-the-arguments-pass.patch, merged
    upstream.
  * Bump debhelper compat level to 10.
  * Use dh_install --list-missing to show uninstalled files and exclude
    libtool .la files.

 -- Michael Biebl <email address hidden> Tue, 13 Sep 2016 16:17:03 +0200

gdk-pixbuf (2.35.4-4) unstable; urgency=medium

  * Move gtk-doc-tools and libglib2.0-doc from Build-Depends-Indep to
    Build-Depends.

 -- Michael Biebl <email address hidden> Thu, 08 Sep 2016 19:17:54 +0200

gdk-pixbuf (2.35.4-3) unstable; urgency=medium

  * Make sure to NULL terminate the arguments passed to g_test_get_filename().
    Otherwise the /pixbuf/composite2 test will segfault. (Closes: #837030)
  * Make test-suite failures fatal again.

 -- Michael Biebl <email address hidden> Thu, 08 Sep 2016 18:59:21 +0200

gdk-pixbuf (2.35.4-2) unstable; urgency=medium

  * Make test-suite failures non-fatal for now to not block ongoing
    transitions.
  * Build gtk-doc documentation via --enable-gtk-doc.
  * Bump Standards-Version to 3.9.8.

 -- Michael Biebl <email address hidden> Thu, 08 Sep 2016 16:49:06 +0200

gdk-pixbuf (2.35.4-1) unstable; urgency=medium

  * New upstream release.
  * Update symbols file with new additions. A few private symbols were
    dropped.
  * Use dh-exec for substituting multiarch paths in libgdk-pixbuf2.0-0.install
    and libgdk-pixbuf2.0-dev.links.
  * Convert from cdbs to dh.

 -- Michael Biebl <email address hidden> Wed, 07 Sep 2016 18:00:22 +0200

CVE References

Jeremy Bícha (jbicha)
Changed in gdk-pixbuf (Ubuntu):
importance: Undecided → Wishlist
Revision history for this message
Jeremy Bícha (jbicha) wrote :
tags: added: upgrade-software-version zesty
tags: added: patch
Revision history for this message
Jeremy Bícha (jbicha) wrote :
Revision history for this message
Jeremy Bícha (jbicha) wrote :
Revision history for this message
Michael Terry (mterry) wrote :

Hey Jeremy, thanks for the patch! I've uploaded it, with one change: you should keep old changelog entries if possible. Helps with answering the question "WHY are we keeping this delta" sometimes. So I put them back in.

Revision history for this message
Michael Terry (mterry) wrote :

Hrmm... Test failed on arm64 in the same test we patch to avoid OOM. A rebuild fixed it, but cause for concern. Nothing wrong with your work. Just looks like maybe we didn't fix that bug after all.

Revision history for this message
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package gdk-pixbuf - 2.36.0-1ubuntu1

---------------
gdk-pixbuf (2.36.0-1ubuntu1) zesty; urgency=medium

  * Sync with Debian (LP: #1643222). Remaining change:
    - Unset MALLOC_PERTURB_ for the /pixbuf/cve-2015-4491/original test, as
      it fails with OOM, or gets OOM killed.
  * Drop CVE-2016-6352.patch, the fix was applied in new upstream version

 -- Jeremy Bicha <email address hidden> Sat, 19 Nov 2016 12:50:45 -0500

Changed in gdk-pixbuf (Ubuntu):
status: New → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Bug attachments

Remote bug watches

Bug watches keep track of this bug in other bug trackers.