Change log for ghostscript package in Debian

175 of 189 results
Published in sid-release
ghostscript (10.03.0~dfsg-1) unstable; urgency=medium

  [ Steve Robbins ]
  * [d50c139] Add "breaks" relationship with manpages-l10n to transition
    German manpages. Closes: #1065396.
  * [9adc766] Simplify ps2ascii script. Closes: #992893.
  * [15664c9] New upstream version 10.03.0~dfsg
  * [2396e20] Remove 0001_fix_pagelist.patch, applied in new version.
  * [e3b0739] Add build-dep on python3-sphinx-copybutton
  * [ff6b89f] Fix break relationship versioning.
  * [2020bbc] Update obsolete dependency package names.

 -- Steve M. Robbins <email address hidden>  Thu, 21 Mar 2024 22:44:42 -0500
Published in bookworm-release
ghostscript (10.0.0~dfsg-11+deb12u3) bookworm-security; urgency=high

  * Non-maintainer upload by the Security Team.
  * Fix tiffsep(1) requirement for seekable output files (CVE-2023-46751)

 -- Salvatore Bonaccorso <email address hidden>  Tue, 12 Dec 2023 22:42:23 +0100
Superseded in sid-release
ghostscript (10.02.1~dfsg-3) unstable; urgency=medium

  [ наб ]
  * [ee3d1ac] Simplify /sbin/update-gsfontmap (Closes: #992889)

  [ Steve Robbins ]
  * [ccc0e3c] Explicitly set font map files to be world readable. 
    Closes: #740959.
  * [5fce3d3] Add suggestion for package texlive-binaries, needed to use dvipdf. Closes: #782901.
  * [9ab8028] ghostscript: add conflicts to ghostcript-x to allow removal of the obsolete transitional package. Closes: #1053377

 -- Steve M. Robbins <email address hidden>  Sat, 20 Jan 2024 15:44:07 -0600
Superseded in sid-release
ghostscript (10.02.1~dfsg-2) unstable; urgency=medium

  [ Steve Robbins ]
  * [4b077b5] Incorporate upstream patch to fix PageList processing in PDF 
    handler.  Closes: #1052652
  * [b4524f9] New maintainer.  Closes: #1022718, #1036869.

 -- Steve M. Robbins <email address hidden>  Sat, 06 Jan 2024 01:16:23 -0600
Superseded in sid-release
ghostscript (10.02.1~dfsg-1) unstable; urgency=medium

  * QA upload

  [ upstream ]
  * new release(s)

  [ Jonas Smedegaard ]
  * update copyright info: update coverage

 -- Jonas Smedegaard <email address hidden>  Wed, 08 Nov 2023 08:36:16 +0100
Published in bullseye-release
ghostscript (9.53.3~dfsg-7+deb11u6) bullseye; urgency=medium

  * Non-maintainer upload.
  * Copy pcx buffer overrun fix from devices/gdevpcx.c (CVE-2023-38559)
    (Closes: #1043033)
  * IJS device - try and secure the IJS server startup (CVE-2023-43115)

 -- Salvatore Bonaccorso <email address hidden>  Fri, 29 Sep 2023 14:24:57 +0200
Superseded in bookworm-release
ghostscript (10.0.0~dfsg-11+deb12u2) bookworm; urgency=medium

  * Non-maintainer upload.
  * Copy pcx buffer overrun fix from devices/gdevpcx.c (CVE-2023-38559)
    (Closes: #1043033)
  * IJS device - try and secure the IJS server startup (CVE-2023-43115)

 -- Salvatore Bonaccorso <email address hidden>  Fri, 29 Sep 2023 14:33:30 +0200
Superseded in sid-release
ghostscript (10.02.0~dfsg-2) unstable; urgency=medium

  * QA upload

  * declare that ghostscript replaces older ghostscript-x

 -- Jonas Smedegaard <email address hidden>  Thu, 14 Sep 2023 06:37:04 +0200
Superseded in sid-release
ghostscript (10.02.0~dfsg-1) unstable; urgency=medium

  * QA upload

  [ upstream ]
  * new release(s)

  [ Jonas Smedegaard ]
  * update copyright info: update coverage
  * refresh patches;
    update DEP-3 patch headers
  * drop obsolete binary packages ghostscript-x libgs9-common;
    have binary package ghostscript provide ghostscript-x

 -- Jonas Smedegaard <email address hidden>  Wed, 13 Sep 2023 20:18:16 +0200
Superseded in bookworm-release
ghostscript (10.0.0~dfsg-11+deb12u1) bookworm-security; urgency=high

  * Non-maintainer upload by the Security Team.
  * Don't "reduce" %pipe% file names for permission validation
    (CVE-2023-36664)
  * Revisit fix for upstream bug 706761 (CVE-2023-36664)

 -- Salvatore Bonaccorso <email address hidden>  Sun, 02 Jul 2023 10:50:27 +0200
Superseded in sid-release
ghostscript (10.01.2~dfsg-1) unstable; urgency=medium

  * QA upload

  [ upstream ]
  * new release(s)

  [ Jonas Smedegaard ]
  * fix source helper tool copyright-check to avoid insecure shell expansion
  * fix source helper tool copyright-check to work with Path::Tiny 0.144
  * declare compliance with Debian Policy 4.6.2
  * update copyright info: extend repackaging to exclude images containing non-DFSG ICC profile
  * drop patches obsoleted by upstream changes
  * unfuzz patches

 -- Jonas Smedegaard <email address hidden>  Thu, 22 Jun 2023 08:15:42 +0200
Superseded in bullseye-release
ghostscript (9.53.3~dfsg-7+deb11u4) bullseye-security; urgency=high

  * Non-maintainer upload by the Security Team.
  * Prevent buffer overrun in (T)BCP encoding (CVE-2023-28879)
    (Closes: #1033757)

 -- Salvatore Bonaccorso <email address hidden>  Mon, 03 Apr 2023 19:30:02 +0200
Superseded in bookworm-release
Superseded in sid-release
ghostscript (10.0.0~dfsg-11) unstable; urgency=medium

  * QA upload.
  * Prevent buffer overrun in (T)BCP encoding (CVE-2023-28879)
    (Closes: #1033757)

 -- Salvatore Bonaccorso <email address hidden>  Sat, 01 Apr 2023 09:48:32 +0200
Superseded in sid-release
ghostscript (10.0.0~dfsg-10) unstable; urgency=medium

  * QA upload.
  * Add patch from upstream to fix cross build. Closes: #717825

 -- Håvard F. Aasen <email address hidden>  Mon, 20 Mar 2023 09:12:00 +0100
Superseded in sid-release
ghostscript (10.0.0~dfsg-9) unstable; urgency=medium

  * QA upload.
  * Build docs with sphinx. Closes: #1024896, #1024964

 -- Håvard F. Aasen <email address hidden>  Mon, 12 Dec 2022 07:45:09 +0100
Superseded in sid-release
ghostscript (10.0.0~dfsg-8) unstable; urgency=medium

  * QA upload
  * debian/: No longer build with dynamic modules (Closes: #1023330)
    - X11 support is now part of ghostscript and ghostcript-x is a
      transitional package.

 -- Sebastian Ramacher <email address hidden>  Sun, 04 Dec 2022 16:00:05 +0100
Superseded in sid-release
ghostscript (10.0.0~dfsg-7) unstable; urgency=medium

  * QA upload.

  [ Debian Janitor ]
  * Apply multi-arch hints. + ghostscript-x: Add Multi-Arch: same.

 -- Jelmer Vernooij <email address hidden>  Sun, 27 Nov 2022 04:28:59 +0000
Superseded in sid-release
ghostscript (10.0.0~dfsg-6) unstable; urgency=medium

  * QA upload
  * Upload to unstable

 -- Sebastian Ramacher <email address hidden>  Fri, 28 Oct 2022 12:31:22 +0200
Superseded in sid-release
ghostscript (10.0.0~dfsg-4) unstable; urgency=medium

  * orphan package: set maintainer to Debian QA Group

 -- Jonas Smedegaard <email address hidden>  Mon, 24 Oct 2022 13:54:55 +0200
Superseded in sid-release
ghostscript (10.0.0~dfsg-3) unstable; urgency=medium

  * build-depend on dh-sequence-pkgkde-symbolshelper
    (not pkg-kde-tools)

 -- Jonas Smedegaard <email address hidden>  Tue, 18 Oct 2022 20:21:55 +0200
Deleted in experimental-release (Reason: None provided.)
ghostscript (10.0.0~dfsg-2) experimental; urgency=medium

  * provide binary package libgs-common (not libgs10-common),
    and have it break and replace libgs9-common;
    closes: bug#1020846, thanks to Andreas Beckmann

 -- Jonas Smedegaard <email address hidden>  Tue, 27 Sep 2022 15:53:11 +0200
Superseded in experimental-release
ghostscript (10.0.0~dfsg-1) experimental; urgency=medium

  * update copyright-check:
    + declare metadata extensions separately from use
    + update coverage
  * drop patch 1001 to support cross build, adopted upstream
  * unfuzz patches
  * declare compliance with Debian Policy 4.6.1
  * unfuzz patches
  * bump library packages for new SONAME

 -- Jonas Smedegaard <email address hidden>  Thu, 22 Sep 2022 14:40:36 +0200
Superseded in sid-release
ghostscript (9.56.1~dfsg-1) unstable; urgency=medium

  [ upstream ]
  * new release
    + fix text rendering mode 3 and pdfwrite;
      closes: bug#1009680, thanks to Paul Gevers and others

  [ Jonas Smedegaard ]
  * fix watch file
  * update symbols: 1 private symbol added

 -- Jonas Smedegaard <email address hidden>  Wed, 20 Apr 2022 22:47:35 +0200
Superseded in sid-release
ghostscript (9.56.0~dfsg-1) unstable; urgency=medium

  [ upstream ]
  * new release

  [ Jonas Smedegaard ]
  * drop superfluous lintian overrides
  * New upstream version 9.56.0~dfsg
  * update symbols:
    + 56 private symbols added
    + 23 private symbols dropped
  * use semantic newlines in long descriptions

 -- Jonas Smedegaard <email address hidden>  Wed, 30 Mar 2022 11:51:53 +0200
Published in buster-release
ghostscript (9.27~dfsg-2+deb10u5) buster-security; urgency=high

  * Non-maintainer upload by the Security Team.
  * Check stack limits after function evaluation (CVE-2021-45944)
  * Fix op stack management in sampled_data_continue() (CVE-2021-45949)

 -- Salvatore Bonaccorso <email address hidden>  Tue, 04 Jan 2022 16:46:59 +0100
Superseded in bullseye-release
ghostscript (9.53.3~dfsg-7+deb11u2) bullseye-security; urgency=high

  * Non-maintainer upload by the Security Team.
  * Check stack limits after function evaluation (CVE-2021-45944)
  * Fix op stack management in sampled_data_continue() (CVE-2021-45949)

 -- Salvatore Bonaccorso <email address hidden>  Tue, 04 Jan 2022 15:09:14 +0100
Deleted in experimental-release (Reason: None provided.)
ghostscript (9.56.0~~rc2~dfsg-1) experimental; urgency=medium

  [ upstream ]
  * new pre-release

 -- Jonas Smedegaard <email address hidden>  Mon, 21 Mar 2022 09:09:26 +0100
Superseded in experimental-release
ghostscript (9.56.0~~rc1~dfsg-1) experimental; urgency=medium

  [ upstream ]
  * new pre-release

  [ Jonas Smedegaard ]
  * update copyright info:
    + add Reference and improve Comment
      for files covered by project-wide terms
    + fix interpret unversioned GPL/LGPL to mean any version
    + use multiple separate License-Grant fields
      (not multiple texts in one field, delimited by [...]
      which is hard to distinguish when parsing by a machine)
    + sort License sections alphabetically
    + fix drop bogus Files section
      (likely due to a false positive in older licensecheck
      flagging the word Adobe as a license grant)
    + fix avoid complex shell globbing in file listings
      (leftover from pre-1.0 file format)
    + update coverage
  * update lintian overrides regarding license shortnames
  * tighten lintian overrides
  * drop patches cherry-picked upstream now applied
  * drop patch 1003 adopted upstream
  * drop patch 2009 obsoleted by upstream changes;
    stop have ghostscript-doc depend on libjs-jquery
  * update and unfuzz patches
  * update Maintainer and Vcs-* fields, and drop Uploaders:
    package now maintained in collaborative debian area of Salsa

 -- Jonas Smedegaard <email address hidden>  Mon, 07 Mar 2022 21:47:41 +0100
Superseded in sid-release
ghostscript (9.55.0~dfsg-3) unstable; urgency=medium

  * add patch cherry-picked upstream
    to fix the logic for freeing X pixmap;
    really closes: bug#998888, thanks again to Florian Lindemann

 -- Jonas Smedegaard <email address hidden>  Tue, 30 Nov 2021 15:46:45 +0100
Superseded in sid-release
ghostscript (9.55.0~dfsg-2) unstable; urgency=medium

  * add patch cherry-picked upstream
    to fix gx_default_copy_alpha calling get_bits_rectangle;
    closes: bug#1000710, thanks to Hilmar Preuße

 -- Jonas Smedegaard <email address hidden>  Mon, 29 Nov 2021 11:07:05 +0100
Superseded in sid-release
ghostscript (9.55.0~dfsg-1) unstable; urgency=medium

  [ upstream ]
  * new release

  [ Jonas Smedegaard ]
  * drop patch cherry-picked upstream now applied;
    unfuzz patch 2009
  * update copyright info:
    + update coverage
    + tighten lintian overrides
  * update symbols:
    + 466 private symbols added
    + 76 private symbols dropped
  * add patches cherry-picked upstream:
    + avoid freeing the background pixmap created by gv;
      closes: bug#704709, thanks to Florian Lindemann
    + fix pdfwrite encoding bugs;
      closes: bug#998458, #998461, thanks to Vincent Lefevre

 -- Jonas Smedegaard <email address hidden>  Fri, 19 Nov 2021 17:58:29 +0100
Superseded in bullseye-release
ghostscript (9.53.3~dfsg-7+deb11u1) bullseye-security; urgency=high

  * Non-maintainer upload by the Security Team.
  * Include device specifier strings in access validation (CVE-2021-3781)
    (Closes: #994011)

 -- Salvatore Bonaccorso <email address hidden>  Thu, 09 Sep 2021 19:23:11 +0200
Deleted in experimental-release (Reason: None provided.)
ghostscript (9.55.0~~rc1~dfsg-1) experimental; urgency=medium

  [ upstream ]
  * new release

  [ Jonas Smedegaard ]
  * drop patches cherry-picked upstream now applied
  * unfuzz patches
  * update copyright info: update coverage
  * add patch 1002 proposed upstream to fix build with gpdf
  * add patch 1003 to fix failure to link against lcms2

 -- Jonas Smedegaard <email address hidden>  Sat, 18 Sep 2021 14:31:04 +0200
Superseded in sid-release
ghostscript (9.54.0~dfsg-5) unstable; urgency=medium

  * Revert to not mark /usr/share/ghostscript/* as not-installed:
    works but a clumsy approach
  * properly fix tracking installed files
    by expanding upstream ABI  in debhelper snippets
    (passing ABI-specific path dh_install options confuses dh_missing);
    thanks to Roderich Schupp (see bug#994270)
  * update symbols:
    + 20 private symbols added
    + 1 private symbol dropped

 -- Jonas Smedegaard <email address hidden>  Wed, 15 Sep 2021 14:04:05 +0200
Deleted in experimental-release (Reason: None provided.)
ghostscript (9.54.0~dfsg-4) experimental; urgency=medium

  * mark /usr/share/ghostscript/* as not-installed,
    which is clearly bogus but seems the only (simple) way
    to ignore only for arch-dependent builds;
    closes: bug#994270, thanks to Adrian Bunk

 -- Jonas Smedegaard <email address hidden>  Tue, 14 Sep 2021 23:55:30 +0200
Superseded in experimental-release
ghostscript (9.54.0~dfsg-3) experimental; urgency=medium

  * update copyright info:
    + use Reference field (not License-Reference);
      tighten lintian overrides
    + update coverage
  * build with pkgkde-symbolshelper;
    build-depend on pkg-kde-tools

 -- Jonas Smedegaard <email address hidden>  Tue, 14 Sep 2021 14:55:10 +0200
Superseded in sid-release
ghostscript (9.53.3~dfsg-8) unstable; urgency=high

  * add patch cherry-picked upstream
    to fix access validationaccess validation;
    closes: bug#994011;
    CVE-2021-3781
  * Set urgency=high due to security fix.

 -- Jonas Smedegaard <email address hidden>  Thu, 09 Sep 2021 20:12:26 +0200
Superseded in experimental-release
ghostscript (9.54.0~dfsg-2) experimental; urgency=medium

  * copyright-check: improve progress messages
  * add patch cherry-picked upstream
    to fix access validationaccess validation;
    closes: bug#994011;
    CVE-2021-3781
  * declare compliance with Debian Policy 4.6.0

 -- Jonas Smedegaard <email address hidden>  Thu, 09 Sep 2021 20:41:03 +0200
Superseded in experimental-release
ghostscript (9.54.0~dfsg-1) experimental; urgency=medium

  [ upstream ]
  * new release

  * update copyright info:
    + exclude comvenience copies
      of projects libextract, leptonica, and tesseract
    + update coverage
    + update source helper tool copyright-check:
      implement option --merge-licenses
  * drop patches cherry-picked upstream since applied
  * unfuzz patches
  * add patches cherry-picked upstream:
    + improve description of configure.ac option --with-extract-dir
    + fix magic number used in pam device
    + fix MacOS/tesseract build problems on Unix systems
    + work with latest Extract library
    + bounds check name table "string"
    + add some relevant flags to the cups compilation
    + do not lie about emitting Multiple Master fonts in psfwrite
    + add a PassThrough for JPX encoded images to pdfwrite
    + fix missing interior of rectangles (regression in 9.54.0)
    + tweak Leptonica/Tesseract memory allocators
  * add patch 1004 to enable DeviceN-related device xcfcmyk
  * use debhelper compatibility level 13 (not 12)

 -- Jonas Smedegaard <email address hidden>  Sun, 18 Jul 2021 15:07:19 +0200
Superseded in bullseye-release
Superseded in sid-release
ghostscript (9.53.3~dfsg-7) unstable; urgency=medium

  * update previous changelog section, add a bug closure.
  * update source helper script copyright-check.
  * copyright: update coverage
  * add patches cherry-picked upstream:
    + re-enable support for opvp/oprp devices;
      closes: bug#980971, thanks to Chris Bainbridge
    + parse some types of broken PDFs;
      closes: bug#981583, thanks to Rogério Brito
    + fix segfault parsing large Postscript file;
      closes: bug#970878, thanks to Paul Gevers, Bernhard Übelacker,
      Iustin Pop and Stefano Rivera
  * update symbols: 4 private symbols added

 -- Jonas Smedegaard <email address hidden>  Tue, 02 Feb 2021 14:18:01 +0100

Available diffs

Superseded in sid-release
ghostscript (9.53.3~dfsg-6) unstable; urgency=medium

  * copyright-check:
    + fix quote path when creating temporary skipfile
    + ignore skipfiles below debian/
    + compute robust file regex from content with regexp-assemble
    + list dependencies in header comment
  * add source helper tools
    patch-cherry-pick patch-mkseries patch-refresh-all
  * copyright:
    + update coverage
    + consistently wrap Files and Copyright paragraphs
      (sole exception being initial wildcard Files paragraph)
  * add patch cherry-picked upstream,
    and patch by Stefano Rivera,
    to fix endian issues with CMM;
    closes: bug#976177, thanks to Stefano Rivera
  * declare compliance with Debian Policy 4.5.1
  * update git-buildpackage settings:
    + use DEP-14 git branch names
    + add usage comment
  * add patch cherry-picked upstream
    to fix linking with libfreetype 2.10.3 and newer

 -- Jonas Smedegaard <email address hidden>  Wed, 23 Dec 2020 02:51:22 +0100
Deleted in experimental-release (Reason: None provided.)
ghostscript (9.53.3~dfsg-5+exp) experimental; urgency=medium

  * copyright-check: fix quote path when creating temporary skipfile
  * add patches cherry-picked upstream
    to sync with HEAD of development
  * add source helper tools
    patch-cherry-pick patch-mkseries patch-refresh-all
  * copyright:
    + update coverage
    + consistently wrap Files and Copyright paragraphs
      (sole exception being initial wildcard Files paragraph

 -- Jonas Smedegaard <email address hidden>  Fri, 13 Nov 2020 22:10:44 +0100
Superseded in sid-release
ghostscript (9.53.3~dfsg-5) unstable; urgency=medium

  * simplify build routines slightly
  * tighten source script copyright-check
  * update copyright hints
  * relax tracking of symlinks to fonts-urw-base35
    to ignore file contents;
    closes: bug#972896, thanks to Fabian Greffrath

 -- Jonas Smedegaard <email address hidden>  Mon, 26 Oct 2020 11:04:53 +0100
Superseded in sid-release
ghostscript (9.53.3~dfsg-4) unstable; urgency=medium

  * simplify build: rely on configure defaults
  * avoid build-depending on libcups2-dev libcupsimage2-dev for kfreebsd

 -- Jonas Smedegaard <email address hidden>  Tue, 06 Oct 2020 16:34:30 +0200
Superseded in sid-release
ghostscript (9.53.3~dfsg-3) unstable; urgency=medium

  * fix arch-only build;
    closes: bug#971678, thanks to Sebastian Ramacher and Simon McVittie
  * fix revert to avoid parallel builds (see bug#971678)
  * copyright: tighten coverage of default licensed files
  * copyright-check:
    + license as GPL-3+
    + check step-wise, with some cleanup
    + check default licensed files first
  * fix build-depend on zlib1g-dev:native
    (not virtual libz-dev:native);
    closes: bug#971738, thanks to Simon McVittie

 -- Jonas Smedegaard <email address hidden>  Tue, 06 Oct 2020 14:59:44 +0200
Superseded in sid-release
ghostscript (9.53.3~dfsg-2) unstable; urgency=medium

  * improve (but not fully solve) cross build support:
    + add patch 1001 to allow skipping configure during bootstrap,
      and use that during build
    + build-depend on libz-dev:native (not libz-dev)
    closes: bug#971092, thanks to Helmut Grohne
  * simplify build;
    migrate binary package ghostscript-dbg
    to automated *-dbgsym packages;
    stop build-depend on cdbs
  * fix configure additional multi-arch paths
  * use debhelper compatibility level 12 (not 10);
    build-depend on debhelper-compat (not debhelper)
  * unfuzz patch 2009

 -- Jonas Smedegaard <email address hidden>  Sun, 04 Oct 2020 13:52:56 +0200
Superseded in sid-release
ghostscript (9.53.3~dfsg-1) unstable; urgency=medium

  [ upstream ]
  * new bugfix release

  [ Jonas Smedegaard ]
  * drop superfluous license hint and lintian overrides

 -- Jonas Smedegaard <email address hidden>  Thu, 01 Oct 2020 12:54:33 +0200
Superseded in buster-release
ghostscript (9.27~dfsg-2+deb10u4) buster-security; urgency=medium

  * CVE-2020-16287 CVE-2020-16288 CVE-2020-16289 CVE-2020-16290
  * CVE-2020-16291 CVE-2020-16292 CVE-2020-16293 CVE-2020-16294
  * CVE-2020-16295 CVE-2020-16296 CVE-2020-17538 CVE-2020-16297
  * CVE-2020-16298 CVE-2020-16299 CVE-2020-16300 CVE-2020-16301
  * CVE-2020-16302 CVE-2020-16303 CVE-2020-16304 CVE-2020-16305
  * CVE-2020-16306 CVE-2020-16307 CVE-2020-16308 CVE-2020-16309
  * CVE-2020-16310

 -- Moritz Mühlenhoff <email address hidden>  Mon, 24 Aug 2020 17:03:45 +0200
Superseded in sid-release
ghostscript (9.53.2~dfsg-1) unstable; urgency=medium

  [ upstream ]
  * new bugfix release

  * simplify source script copyright-check
  * unfuzz patch 2009
  * update Uploaders field to reflect actual maintenance;
    thanks for your past contributions,
    Michael Gilbert and Bastien ROUCARIÈS,
    and feel free to join again

 -- Jonas Smedegaard <email address hidden>  Fri, 25 Sep 2020 16:51:43 +0200
Superseded in sid-release
ghostscript (9.53.1~dfsg-2) unstable; urgency=medium

  * simple rebuild,
    to re-sync symlinks with newer release of fonts-urw-base35

 -- Jonas Smedegaard <email address hidden>  Thu, 17 Sep 2020 11:23:43 +0200
Superseded in sid-release
ghostscript (9.53.1~dfsg-1) unstable; urgency=medium

  [ upstream ]
  * new release

 -- Jonas Smedegaard <email address hidden>  Mon, 14 Sep 2020 17:36:04 +0200
Superseded in sid-release
ghostscript (9.53.0~dfsg-1) unstable; urgency=medium

  * New upstream version 9.53.0~dfsg
  * tighten build-dependency on libjbig2dec0-dev
  * enable parallel build
  * update symbols:
    + 6 public symbols added
    + 45 private symbols added
    + 25 private symbols dropped

 -- Jonas Smedegaard <email address hidden>  Thu, 10 Sep 2020 21:08:17 +0200
Superseded in sid-release
ghostscript (9.52.1~dfsg-1) unstable; urgency=high

  [ upstream ]
  * new release
    (CVE-2020-15900)

  [ Jonas Smedegaard ]
  * set urgency=high, due to CVE fix
  * have autoreconf use upstream bootstrapping script
  * resolve abi from upstream build scripts

 -- Jonas Smedegaard <email address hidden>  Thu, 20 Aug 2020 17:38:01 +0200
Deleted in experimental-release (Reason: None provided.)
ghostscript (9.53.0~~rc1~dfsg-1) experimental; urgency=medium

  [ upstream ]
  * new pre-release

  [ Jonas Smedegaard ]
  * copyright: extend coverage
  * unfuzz patches (including removal of virtually empty patch 2012)
  * update and simplify resolving upstream abi

 -- Jonas Smedegaard <email address hidden>  Thu, 20 Aug 2020 18:36:16 +0200
Superseded in sid-release
ghostscript (9.52~dfsg-1) unstable; urgency=medium

  * New upstream version 9.52~dfsg
  * watch:
    + simplify usage comment
    + use dversionmangle=auto
  * declare compliance with Debian Policy 4.5.0
  * trim trailing whitespace
  * wrap long lines in older changelog entries
  * use debhelper 10 (not 9);
    stop build-depend explicitly on dh-autoreconf
  * copyright: fix use field Comment (not unofficial Comments)

 -- Jonas Smedegaard <email address hidden>  Thu, 19 Mar 2020 15:52:14 +0100
Superseded in sid-release
ghostscript (9.51~dfsg-1) unstable; urgency=medium

  [ upstream ]
  * new release

  [ Jonas Smedegaard ]
  * update symbols:
    + 20 private symbols added
    + 3 private symbols dropped

 -- Jonas Smedegaard <email address hidden>  Thu, 12 Mar 2020 17:57:57 +0100
Deleted in experimental-release (Reason: None provided.)
ghostscript (9.51~~rc3~dfsg-1) experimental; urgency=medium

  [ upstream ]
  * new pre-release

  [ Jonas Smedegaard ]
  * copyright:
    + fix cover 2 files in the public domain
    + fix cover 2 file licensed Adobe-2006
    + cover 2 files licensed GPL-3+ with Autoconf exception
    + cover 1 file licensed Expat
    + extend coverage for main copyright holder
  * drop patches cherry-picked upstream now applied
  * unfuzz patches

 -- Jonas Smedegaard <email address hidden>  Thu, 05 Mar 2020 13:32:25 +0100
Published in stretch-release
ghostscript (9.26a~dfsg-0+deb9u6) stretch-security; urgency=high

  * Non-maintainer upload by the Security Team.
  * remove .forceput from /.charkeys (CVE-2019-14869)

 -- Salvatore Bonaccorso <email address hidden>  Wed, 13 Nov 2019 21:01:12 +0100
Superseded in buster-release
ghostscript (9.27~dfsg-2+deb10u3) buster-security; urgency=high

  * remove .forceput from /.charkeys (CVE-2019-14869)

 -- Salvatore Bonaccorso <email address hidden>  Sat, 09 Nov 2019 22:58:27 +0100
Superseded in sid-release
ghostscript (9.50~dfsg-5) unstable; urgency=medium

  * add patch cherry-picked upstream
    to add 'omitEOD' flag to RLE compressor and use for PXL;
    closes: bug#941864,
    thanks to Agustin Martin and Johannes Stezenbach

 -- Jonas Smedegaard <email address hidden>  Wed, 27 Nov 2019 20:15:08 +0100
Superseded in sid-release
ghostscript (9.50~dfsg-4) unstable; urgency=medium

  * fix CVE reference in previous changelog entry
  * fix stop needlessly have ligs-dev depend on build-dependencies;
    stop build-depend on d-shlibs;
    closes: bug#945516, thanks to Thomas Loimer
  * add patch cherry-picked upstream to fix dvipdf script;
    closes: bug#941163, thanks to Alexis Bienvenüe

 -- Jonas Smedegaard <email address hidden>  Wed, 27 Nov 2019 17:57:01 +0100
Superseded in sid-release
ghostscript (9.50~dfsg-3) unstable; urgency=medium

  * add patch cherry-picked upstream to remove .forceput from /.charkeys;
    closes: bug#944760 (CVE-2019-10216); thanks to Salvatore Bonaccorso
  * unfuzz patches 2007 2009

 -- Jonas Smedegaard <email address hidden>  Wed, 27 Nov 2019 00:13:36 +0100
Superseded in buster-release
ghostscript (9.27~dfsg-2+deb10u2) buster-security; urgency=high

  * Non-maintainer upload by the Security Team.
  * make .forceput inaccessible (CVE-2019-14811, CVE-2019-14812,
    CVE-2019-14813)
  * PDF interpreter - review .forceput security (CVE-2019-14817)

 -- Salvatore Bonaccorso <email address hidden>  Mon, 02 Sep 2019 14:36:48 +0200
Superseded in sid-release
ghostscript (9.50~dfsg-2) unstable; urgency=medium

  * Build-depend on libfreetype-dev (not libfreetype6-dev).

 -- Jonas Smedegaard <email address hidden>  Tue, 15 Oct 2019 15:56:44 +0200
Superseded in sid-release
ghostscript (9.28~~rc4~dfsg-1) unstable; urgency=medium

  [ upstream ]
  * New pre-release.

  [ Jonas Smedegaard ]
  * Declare compliance with Debian Policy 4.4.1.
  * Update symbols file: 1 private symbol added.

 -- Jonas Smedegaard <email address hidden>  Wed, 02 Oct 2019 10:58:26 +0200
Superseded in sid-release
ghostscript (9.28~~rc3~dfsg-1) unstable; urgency=medium

  [ upstream ]
  * New pre-release.

  [ Jonas Smedegaard ]
  * Fix tighten to build-depend on libjbig2dec0-dev
    new enough to provide pkg-config file
    (required since Ghostscript 9.28 rc1).

 -- Jonas Smedegaard <email address hidden>  Wed, 18 Sep 2019 17:15:43 +0200
Superseded in sid-release
ghostscript (9.28~~rc2~dfsg-2) unstable; urgency=medium

  * Mark ghostscript-doc as Multi-Arch: foreign.
  * Update watch file:
    + Simplify regular expressions.
    + Rewrite usage comment.
  * Simplify rules: Use autoreconf.
    Build-depend on dh-autoreconf (not explicitly autoconf).
  * Fix link with libjbig2dec
    by including pkg-config file with that package,
    needed by ghostscript 9.28.
    Update symbols file: 6 private symbols added,

 -- Jonas Smedegaard <email address hidden>  Tue, 17 Sep 2019 05:13:48 +0200
Superseded in stretch-release
ghostscript (9.26a~dfsg-0+deb9u4) stretch-security; urgency=high

  * Non-maintainer upload by the Security Team.
  * protect use of .forceput with executeonly (CVE-2019-10216)

 -- Salvatore Bonaccorso <email address hidden>  Thu, 08 Aug 2019 07:10:18 +0200
Superseded in buster-release
ghostscript (9.27~dfsg-2+deb10u1) buster-security; urgency=high

  * Non-maintainer upload by the Security Team.
  * protect use of .forceput with executeonly (CVE-2019-10216)

 -- Salvatore Bonaccorso <email address hidden>  Thu, 08 Aug 2019 06:52:14 +0200
Superseded in sid-release
ghostscript (9.28~~rc2~dfsg-1) unstable; urgency=medium

  [ upstream ]
  * New pre-release.

  [ Jonas Smedegaard ]
  * Update git-buildpackage config: Use dep14 git branch debian/master.
  * Unfuzz patch 2009,
    and extend to cover privacy leak in doc/Internal.htm.

 -- Jonas Smedegaard <email address hidden>  Fri, 06 Sep 2019 14:40:13 +0200
Superseded in sid-release
ghostscript (9.28~~rc1~dfsg-1) unstable; urgency=medium

  [ upstream ]
  * New pre-release.

  [ Jonas Smedegaard ]
  * Add NEWS entry about redefined option -dSAFER.
  * Drop obsolete upstream cherry-picked patches.
  * Unfuzz and update patches.
  * Update copyright info: Stop track a file no longer shipped upstream.
  * Update symbols:
    + 8 public symbols added.
    + 65 private symbols added.
    + 22 private symbols dropped.

 -- Jonas Smedegaard <email address hidden>  Mon, 19 Aug 2019 11:20:52 +0200
Superseded in sid-release
ghostscript (9.27~dfsg-3.1) unstable; urgency=medium

  * Non-maintainer upload (with maintainers approval).
  * protect use of .forceput with executeonly (CVE-2019-10216)
    (Closes: #934638)

 -- Salvatore Bonaccorso <email address hidden>  Tue, 13 Aug 2019 09:49:11 +0200
Superseded in sid-release
ghostscript (9.27~dfsg-3) unstable; urgency=medium

  * Declare compliance with Debian Policy 4.4.0.
  * Symlink bas53 fonts from fonts-urw-base35.
    Build-depend on rename.
    (Build-)depend on fonts-urw-base35, and stop recommend gsfonts.
    Closes: Bug#613912, 932897.
    Thanks to Fabian Greffrath and Julian Wollrath.

 -- Jonas Smedegaard <email address hidden>  Wed, 24 Jul 2019 12:45:28 -0300
Superseded in stretch-release
ghostscript (9.26a~dfsg-0+deb9u2) stretch-security; urgency=high

  * Non-maintainer upload by the Security Team.
  * Have gs_cet.ps run from gs_init.ps
  * Undef /odef in gs_init.ps
  * Restrict superexec and remove it from internals and gs_cet.ps
    (CVE-2019-3835) (Closes: #925256)
  * Obliterate "superexec". We don't need it, nor do any known apps
    (CVE-2019-3835) (Closes: #925256)
  * Make a transient proc executeonly (in DefineResource) (CVE-2019-3838)
    (Closes: #925257)
  * an extra transient proc needs executeonly'ed (CVE-2019-3838)
    (Closes: #925257)

 -- Salvatore Bonaccorso <email address hidden>  Sat, 13 Apr 2019 16:40:43 +0200
Superseded in buster-release
Superseded in sid-release
ghostscript (9.27~dfsg-2) unstable; urgency=medium

  * Add patch cherry-picked upstream
    to fix regression resolving bounding box of font glyphs.
    Closes: Bug#927429. Thanks to Kenshi Muto.

 -- Jonas Smedegaard <email address hidden>  Sat, 20 Apr 2019 10:16:50 +0200
175 of 189 results