Please sync freetype (main) from unstable (main)

Bug #60551 reported by Martin Pitt
4
Affects Status Importance Assigned to Milestone
freetype (Ubuntu)
Fix Released
Undecided
Scott James Remnant (Canonical)

Bug Description

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

 affects distros/ubuntu/freetype
 status confirmed
 subscribe ubuntu-archive

Please sync freetype (main) from Debian unstable (main).

Changelog since current edgy version 2.2.1-2ubuntu1:

freetype (2.2.1-5) unstable; urgency=high

  * High-urgency upload for RC bugfix.
  * Add debian/patches-freetype/CVE-2006-3467_pcf-strlen.patch to
    address CVE-2006-3467, a missing string length check in PCF files that
    leads to a possibly exploitable integer overflow. Thanks to Martin
    Pitt for the patch. Closes: #379920.

 -- Steve Langasek <email address hidden> Tue, 12 Sep 2006 15:04:42 -0700

freetype (2.2.1-4) unstable; urgency=low

  * Drop libfreetype6.postinst code for cleaning up /usr/X11R6/lib;
    whatever version it applied to is pre-sarge, and this code is
    sufficiently blunt that I don't think it should be kept around.
    Closes: #386379.

 -- Steve Langasek <email address hidden> Fri, 8 Sep 2006 13:35:30 -0700

freetype (2.2.1-3) unstable; urgency=low

  * Apply patch from Eugeniy Meshcheryakov <email address hidden>, applied
    upstream, to fix bug in rendering of composite glyphs.
    Closes: #374902.

 -- Steve Langasek <email address hidden> Sun, 3 Sep 2006 04:21:43 -0500

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.3 (GNU/Linux)

iD8DBQFFCpElDecnbV4Fd/IRAuAhAKDh4Y6okHNXKZvH7IkBqqQEYlSfdACfX88E
StnFkxyNL4krCjwRNMNQLKg=
=isrq
-----END PGP SIGNATURE-----
application finalize called

Revision history for this message
Martin Pitt (pitti) wrote :

Only Ubuntu change was the CVE-2006-3467 fix which was adopted in Debian.

Revision history for this message
Scott James Remnant (Canonical) (canonical-scott) wrote :

[Updating] freetype (2.2.1-2ubuntu1 [Ubuntu] < 2.2.1-5 [Debian])
 * Trying to add freetype...
  - <freetype_2.2.1-5.dsc: downloading from http://ftp.debian.org/debian/>
  - <freetype_2.2.1-5.diff.gz: downloading from http://ftp.debian.org/debian/>
  - <freetype_2.2.1.orig.tar.gz: already in distro - downloading from librarian>I: freetype [main] -> libfreetype6-udeb_2.2.1-2ubuntu1 [universe].
I: freetype [main] -> libfreetype6-dev_2.2.1-2ubuntu1 [main].
I: freetype [main] -> freetype2-demos_2.2.1-2ubuntu1 [universe].
I: freetype [main] -> libfreetype6_2.2.1-2ubuntu1 [main].

Changed in freetype:
assignee: nobody → keybuk
status: Confirmed → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.