lcms2 (2.5-0ubuntu4.2) trusty-security; urgency=medium

  * SECURITY UPDATE: Denial of service
    - debian/patches/CVE-2016-10165.patch: fix in src/cmstypes.c.
    - CVE-2016-10165
  * SECURITY UPDATE: Integer overflow
    - debian/patches/CVE-2018-16435.patch: fix in src/cmscgats.c.
    - CVE-2018-16435

 -- Leonidas S. Barbosa <leo.barbosa@canonical.com>  Wed, 19 Sep 2018 11:46:00 -0300

lcms2 (2.5-0ubuntu4.1) trusty-security; urgency=medium

  * SECURITY UPDATE: double free in DefaultICCintents()
    - debian/patches/CVE-2013-7455.patch: ensure that the variable Lut
      is freed only once.
    - CVE-2013-7455

 -- Steve Beattie <sbeattie@ubuntu.com>  Mon, 02 May 2016 11:54:40 -0700

lcms2 (2.5-0ubuntu4) trusty; urgency=low

  * fix-floating-point-rounding-in-version-numbers.diff: Fix roundtripping of
    version header field; writing 2.30 in the version field would read as 2.29.
    Fixes the colord autopkgtests. Yay!

 -- Christopher James Halse Rogers <raof@ubuntu.com>  Thu, 16 Jan 2014 16:45:47 +1100

lcms2 (2.5-0ubuntu3) trusty; urgency=low

  * Remove bizarre and unnecessary clean target and use dh_autotools_dev.
  * byte-order.patch: Replace arch-specific tests with __BYTE_ORDER test.

 -- Adam Conrad <adconrad@ubuntu.com>  Wed, 11 Dec 2013 04:13:40 -0700

lcms2 (2.5-0ubuntu2) trusty; urgency=low

  * powerpc64le.patch: patch aclocal.m4 for ppc64el and regen configure.

 -- Adam Conrad <adconrad@ubuntu.com>  Wed, 11 Dec 2013 03:36:06 -0700

lcms2 (2.5-0ubuntu1) saucy; urgency=low

  * New upstream version (fixes various crashes that could be used by
    attackers to crash (NULL ptr deref) programs using lcms2.
  * Update config.{gues,sub} for Aarch64.
  * Update symbols file.

 -- Matthias Klose <doko@ubuntu.com>  Tue, 23 Jul 2013 21:39:38 +0200

lcms2 (2.4-0ubuntu3) raring; urgency=low

  * Drop fix-threading-issue-in-plugin-registration.patch. This was added for
    GhostScript 9.07, but gs 9.07 segfaults with only this patch; they need
    more patches from their lcms2 fork. It seems sensible at this point to wait
    until they've upstreamed their fork, rather than trying to pick bits out of
    it or adopt the fork wholesale.

 -- Christopher James Halse Rogers <raof@ubuntu.com>  Fri, 15 Mar 2013 18:50:41 +1100

lcms2 (2.4-0ubuntu2) raring; urgency=low

  * debian/patches/fix-threading-issue-in-plugin-registration.patch:
    - Provide a thread-safe way for plugins to register; needed for new
      ghostscript 9.07 (LP: #1126427)

 -- Christopher James Halse Rogers <raof@ubuntu.com>  Wed, 13 Mar 2013 12:13:21 +1100

lcms2 (2.4-0ubuntu1) raring; urgency=low

  * New upstream release
    - Update debian/liblcms2-2.symbols
      - Add new symbols for 2.4
      - Drop lost symbol cmsGetStockOutputFormatter after verifying it is not
        used in any packaged reverse build-depends
      - Corrected previous symbol entries to not inclue package revision

 -- Scott Kitterman <scott@kitterman.com>  Thu, 29 Nov 2012 16:24:47 -0500

lcms2 (2.2+git20110628-2.2ubuntu1) raring; urgency=low

  * Merge from Debian unstable.  Remaining changes:
    - debian/control: Use unversioned libtiff-dev instead of libtiff4-dev
    - debian/liblcms2-2.symbols: Add symbols file for the shared library

 -- Michael Terry <mterry@ubuntu.com>  Sat, 17 Nov 2012 11:24:34 -0500

lcms2 (2.2+git20110628-2.2) unstable; urgency=low

  * Non-maintainer upload.
  * Enable multi-arch (closes: #667556).

 -- Michael Gilbert <mgilbert@debian.org>  Tue, 22 May 2012 23:57:24 -0400

lcms2 (2.2+git20110628-2.1) unstable; urgency=low

  * Non-maintainer upload.
  * Fix "FTBFS: dpkg-buildpackage: error: dpkg-source -b lcms2-
    2.2+git20110628 gave error exit status 2":
    - drop auto-generated patches
    - use make distclean in debian/rules' clean target
    (Closes: #643177)
  * Don't install the .la file anymore (release goal).

 -- gregor herrmann <gregoa@debian.org>  Tue, 06 Mar 2012 18:46:04 +0100

lcms2 (2.2+git20110628-2ubuntu4) quantal; urgency=low

  * debian/control:
    - Use unversioned libtiff-dev instead of libtiff4-dev

 -- Michael Terry <mterry@ubuntu.com>  Tue, 17 Jul 2012 11:49:39 -0400

lcms2 (2.2+git20110628-2ubuntu3) precise; urgency=low

  * Rebuild for libjpeg8.

 -- Colin Watson <cjwatson@ubuntu.com>  Tue, 18 Oct 2011 17:22:44 +0100

lcms2 (2.2+git20110628-2ubuntu2) oneiric; urgency=low

  * Convert library packages to multiarch. LP: #836004.

 -- Matthias Klose <doko@ubuntu.com>  Sun, 28 Aug 2011 13:40:38 +0200

lcms2 (2.2+git20110628-2ubuntu1) oneiric; urgency=low

  * debian/liblcms2-2.symbols: Added symbols file for the shared library,
    generated with "dpkg-gensymbols -pliblcms2-2".

 -- Till Kamppeter <till.kamppeter@gmail.com>  Tue, 09 Aug 2011 17:05:31 +0200

lcms2 (2.2+git20110628-2) unstable; urgency=low

  * debian/control:
    - Updated libjpeg dependency for the transition.
    - Updated package descriptions for better search results.

 -- Oleksandr Moskalenko <malex@debian.org>  Mon, 18 Jul 2011 23:39:39 -0500

lcms2 (2.2+git20110628-1) unstable; urgency=low

  * Upstream git update (Closes: #631598).

 -- Oleksandr Moskalenko <malex@debian.org>  Wed, 29 Jun 2011 01:20:02 -0500

lcms2 (2.2+git20110627-1) unstable; urgency=low

  * Upstream git update to fix a FTBFS on i386.

 -- Oleksandr Moskalenko <malex@debian.org>  Mon, 27 Jun 2011 23:22:54 -0500

lcms2 (2.2-1) unstable; urgency=low

  * New upstream release.
  * debian/control: Updated standards version to 3.9.2.

 -- Oleksandr Moskalenko <malex@debian.org>  Sun, 12 Jun 2011 00:36:06 -0500

lcms2 (2.1-1) unstable; urgency=low

  * Initial release (Closes: #590222).

 -- Oleksandr Moskalenko <malex@debian.org>  Sun, 23 Jan 2011 15:26:53 -0600

