Change logs for libraw source package in Zesty

  • libraw (0.18.1-1ubuntu0.1) zesty-security; urgency=medium
    
      * SECURITY UPDATE: memory corruption in parse_tiff_ifd
        - debian/patches/CVE-2017-688x.patch: add checks to dcraw/dcraw.c,
          internal/dcraw_common.cpp.
        - CVE-2017-6886
        - CVE-2017-6887
      * SECURITY UPDATE: floating point exception in kodak_radc_load_raw
        - debian/patches/CVE-2017-13735.patch: add checks to dcraw/dcraw.c,
          internal/dcraw_common.cpp.
        - CVE-2017-13735
      * SECURITY UPDATE: buffer overflow in xtrans_interpolate
        - debian/patches/CVE-2017-14265.patch: add checks to dcraw/dcraw.c,
          internal/dcraw_common.cpp.
        - CVE-2017-14265
      * SECURITY UPDATE: buffer overflow in processCanonCameraInfo
        - debian/patches/CVE-2017-14348.patch: add checks to dcraw/dcraw.c,
          internal/dcraw_common.cpp.
        - CVE-2017-14348
      * SECURITY UPDATE: out of bounds read in kodak_65000_load_raw
        - debian/patches/CVE-2017-14608.patch: add checks to dcraw/dcraw.c,
          internal/dcraw_common.cpp.
        - CVE-2017-14608
    
     -- Marc Deslauriers <email address hidden>  Thu, 16 Nov 2017 13:53:54 -0500
  • libraw (0.18.1-1) experimental; urgency=medium
    
      * New upstream release
    
     -- Matteo F. Vescovi <email address hidden>  Fri, 03 Mar 2017 14:57:36 +0100
  • libraw (0.18.0-1) experimental; urgency=medium
    
      * New upstream release
        - debian/: SONAME bump libraw15 => libraw16
        - debian/libraw16.symbols: symbols updated
        - debian/copyright: licenses updated
        - debian/patches/: patchset dropped (applied upstream)
      * debian/: bump compatibility 9 -> 10
    
     -- Matteo F. Vescovi <email address hidden>  Mon, 02 Jan 2017 13:52:44 +0100
  • libraw (0.17.2-6) unstable; urgency=medium
    
      * debian/patches/: patchset updated (again)
        - 0001-Fix_gcc6_narrowing_error.patch replaced with
          0001-Fix_gcc6_narrowing_conversion.patch since it
          was causing FTBFS on most little-endian architectures
          Thanks to Alex Tutubalin (upstream) for the quick fix.
    
     -- Matteo F. Vescovi <email address hidden>  Thu, 25 Aug 2016 22:29:57 +0200