Skip to content

Changelog giflib (5.1.4-2ubuntu0.1)

2019

giflib (5.1.4-2ubuntu0.1) bionic-security; urgency=medium

   * SECURITY UPDATE: Denial of service
     - debian/patches/CVE-2016-3977.patch: fix SF
       in heap buff overflow in lib/dgif_lig.c,
       util/gif2rgb.c.
     - CVE-2016-3977
   * SECURITY UPDATE: Denial of service
     - debian/patches/CVE-2018-11490.patch: adding checks
       in DGifDecompressLine in order to avoid a heap buffer overflow and
       a denial of service in lib/dgif_lib.c.
     - CVE-2018-11490
   * SECURITY UPDATE: Divide-by-zero
     - debian/patches/CVE-2019-15133.patch: adding checks bounds
       in lib/dgif_lib.c.
     - CVE-2019-15133

2018

giflib (5.1.4-2) unstable; urgency=low

   * QA upload.
   * New vcs repository generated from a) "gbp import-dscs --debsnap giflib",
     b) old repo on alioth c) private repo for changes > 5.1.4-0.4.
     Update Vcs* in debian/control, pointing to salsa.
   * [lintian] Delete trailing whitespace in changelog.

2017

giflib (5.1.4-1) unstable; urgency=low

   * QA upload.
   * Set maintainer to qa.
   * Build with hardening=+bindnow.
   * Switch to automatic dbgsym packages.
   * 03-spelling_fixes.patch: Fix another two typoes found by lintian.
   * Bump standards-version - No changes.
   * Use debhelper 10 compat, which uses autoreconf and --parallel by default.

2016

giflib (5.1.4-0.4) unstable; urgency=medium

   * Non-maintainer upload.
   * Remove patch/issue87 because that is already present in upstream.
   * Remove patch/04-fprintf_format_error.patch which was commented out anyway.
   * Install manpages supplied by upstream
     Closes: #809439.

giflib (5.1.4-0.3) unstable; urgency=medium

   * Non-maintainer upload.
   * CVE-2016-3977: gif2rgb: heap buffer overflow. Closes: #820526.

giflib (5.1.4-0.2) unstable; urgency=medium

   * Non-maintainer upload.
   * Drop the local fix for issue #81, solved differently upstream.
     Closes: #823481.

giflib (5.1.4-0.1) unstable; urgency=medium

   * Non-maintainer upload.
   * New upstream version.
   * Security issues already fixed in 5.1.2: CVE-2016-3977.
     Closes: #820594, #820526.
   * Update symbols file.

giflib (5.1.2-0.3) unstable; urgency=medium

   * Non-maintainer upload.
   [ Tobias Frost ]
   * debian/patches/ef0cb9b4be572262b49fbc26fb2348683f44a517.patch:
     try to fix testsuite failures on feh/powerpc.
     (Closes: #812657)

giflib (5.1.2-0.2) unstable; urgency=medium

   * Non-maintainer upload.
   * Fix DGifOpen(), uninitialized memory. Closes: #812093.

giflib (5.1.2-0.1) unstable; urgency=high

   * Non-maintainer upload.
   * New upstream version.
     - CVE-2015-7555, Heap-based buffer overflow in giffix utility.
       Closes: #808704.

2015

giflib (5.1.1-0.2) unstable; urgency=medium

   * Non-maintainer upload, upload to unstable. Closes: #803158.

giflib (5.1.1-0.1) experimental; urgency=medium

   * Non-maintainer upload.
   * New upstream version. See: #803158.
   * Enable parallel builds.
   * Build-depend on xmlto.
   * Don't ship broken libungif symlinks. Closes: #732272. LP: #1337898.

2013

giflib (4.1.6-11) unstable; urgency=low

   * Remove Provides: libungif4g.
   * Enable Multiarch (Closes: #647497).
   * depend on dh-autoreconf.
   * Update to debhelper 9 and bump Standards to 3.9.4.
   * Honor the LAFileRemoval goal.
   * Update git links.

2012

giflib (4.1.6-10) unstable; urgency=low

   * Fixing fprintf issues by YunQiang Su.
   * Hardening build flags (Closes: #673660).
   * Updating Standards (no change).

giflib (4.1.6-9.1) unstable; urgency=low

   * Non-maintainer upload.
   * Depend on libperl4-corelibs-perl (Closes: #659421)

2010

giflib (4.1.6-9) unstable; urgency=low

   * New Maintainer (Closes: #543841)
   * Adding watch file (Closes: #453530)
   * Converting to source package "3.0 (quilt)".
   * Correcting debhelper version dependency.
   * Adding Vcs fields.
   * Adding manpages.
   * Removing duplicate Section field.
   * Correctly hyphenate man pages.
   * Fixing spelling typos.
   * Adding symbols file.
   * Autoreconfiguring to fix rpath.
   * Cleaning what autoreconf did.
   * Registering html documentation.

2009

giflib (4.1.6-8) unstable; urgency=low

   * Updating package to standards version 3.8.3.
   * Removing vcs fields.
   * Orphaning package.

giflib (4.1.6-7) unstable; urgency=low

   * Replacing obsolete dh_clean -k with dh_prep.
   * Updating section of the debug package.
   * Using quilt rather than dpatch.
   * Using correct rfc-2822 date formats in changelog.
   * Updating package to standards version 3.8.2.
   * Removing old transitional packages.
   * Adding misc depends to debug and development package.
   * Updating year in copyright file.
   * Minimizing rules file.

2008

giflib (4.1.6-6) unstable; urgency=low

   * Updating vcs fields in control file.
   * Using patch-stamp rather than patch in rules file.
   * Removing config.guess and config.sub in clean target of rules.
   * Passing '--disable-x11' to configure call to ensure that giflib is
     not linked against X11 libs by accident (Closes: #503836).

giflib (4.1.6-5) unstable; urgency=low

   * Correcting mistake of having libungif4-dev transitional package arch
     dependent.
   * Also adding libgif.so.4.1 symlink.
   * Using links debhelper to create symlinks.
   * Reordering rules file (Closes: #488586).
   * Rewriting copyright file in machine-interpretable format.
   * Adding vcs fields in control file.
   * Upgrading package to standards .8.0.
   * Upgrading package to debhelper 7.
   * Reverting config.guess and config.sub to upstream.

giflib (4.1.6-4) unstable; urgency=high

   * Adding patch from libungif to fix CVE-2005-2974 and CVE-2005-3350.
   * Updating upstream homepage (Closes: #469561).

giflib (4.1.6-3) unstable; urgency=high

   * Adding transitional packages to kick libungif out of the archive by force.
   * Removing watch file (Closes: #453592).

giflib (4.1.6-2) unstable; urgency=low

   * Adding legacy links for libungif4g/libungif4-dev.

giflib (4.1.6-1) unstable; urgency=low

   * New upstream release.
   * Bumped package to new policy.
   * Using new homepage field in control.
   * Don't hide make errors in clean target of rules.
   * Added --fail-missing to dh_install call.
   * Updated conficts/replaces/provides to initiate libungif4 to libgif4
     transition.

2007

giflib (4.1.4-2) unstable; urgency=low

   * Minor cleanups.

2006

giflib (4.1.4-1) unstable; urgency=low

   * Took over package from Pawel.
   * New upstream release (Closes: #395388):
     - This is giflib 4.x, replacing giflib 3.x. No package in the archive has to
       be transitioned. After etch, giflib will replace libungif (all alleged patents
       are expired all over the world).
     - doesn't contain gif2x11 (Closes: #328665)
     - isn't affected by CVE-2005-2974 and CVE-2005-3350 (Closes: #395382).
   * Redone debian directory based on current debhelper templates, additionally:
     - added watch file.
     - added debug package.

2005

giflib (3.0-12) unstable; urgency=low

   * Applied patch from Dann Frazier <dannf@hp.com> to fix problems on 64-bit
     archs (closes: #325034)
   * Updated standards-version (no changes required)

2004

giflib (3.0-11) unstable; urgency=low

   * Updated copyright file by removing warning saying it cannot by put on CDs,
     removed patent-related notes from long descriptions in control as well
     (should have done that in -10, but forgot).

giflib (3.0-10) unstable; urgency=low

   * Moved to main because of LZW's patent expiration (at long last!)
     (closes: #258465)
   * Fixed build-dependencies (closes: #262405)

giflib (3.0-9) unstable; urgency=low

   * Renamed getarg.h to gagetarg.h, to avoid name clashes (closes: #83331)
   * Updated standards version (no changes)

2003

giflib (3.0-8) unstable; urgency=low

   * Applied patch from John Lightsey <john@nixnuts.net> to fix transparency
     problems (closes: #20716)
   * Documented the fact, that giflib cannot be put on CD-ROMs (closes: #24580)
   * Applied patch from John Lightsey <john@nixnuts.net> to fix gifinto's
     behavior when no arguments are supplied (closes: #49431)
   * giflib3g-dev now conflicts with heimdal-dev (closes: #83331, #180265)
   * Updated standards version
   * Updated sections (giflib3g-dev goes to non-free/libdevel, giflib3g-bin
     goes to non-free/utils)

2002

giflib (3.0-7) unstable; urgency=low

   * New maintainer (closes: #139387)
   * Upgraded to current standards version (closes: #133331)

2001

giflib (3.0-6) unstable; urgency=low

   * Move docs and man pages to /usr/share (Closes: #91165, #91479, #91480,
     #91482)

1998

giflib (3.0-5.2) unstable; urgency=low

   * Redid debian/rules to use debhelper.
   * Added symlinks so giflib can be used with packages compiled with
     libungif.
   * Added shlibs control file so that packages compiled with giflib can
     also be used with libungif.

giflib (3.0-5.1) unstable frozen; urgency=low

   * Corrected bogus hardwired dependency on libc6.

giflib (3.0-5) unstable frozen; urgency=low

   * Fixed copyright location(s)
   * new maintainer address

1997

giflib (3.0-4.1) unstable; urgency=low

   * libc6 release for hamm.

giflib (3.0-4) unstable; urgency=low

   * renamed binaries to giflib* to bring them in sync with source name.

giflib (3.0-3) unstable; urgency=low

   * fixed shared library. now link all bins with shared library.

giflib (3.0-2) unstable; urgency=low

   * added -D_REENTRANT and -lc to cflags/ldflags for glibc2.

giflib (3.0-1) unstable; urgency=low

   * Initial Release.