-
cups (1.7.5-11+deb8u2) jessie; urgency=high
* Disable SSLv3 and RC4 by default to address POODLE vulnerability
(Closes: #839226)
- Implement SSLOptions to permit the use of AllowSSL3 and AllowRC4
respectively
* Refresh patches
-- Didier Raboud <email address hidden> Fri, 21 Jul 2017 14:09:44 +0200
-
cups (1.7.5-11+deb8u1) jessie-security; urgency=high
* Import 1.7 upstream fix for CERT VU#810572: Privilege escalation through
dynamic linker and isolated vulnerabilities: STR: #4609, VU#810572
- CVE-2015-1158 - Improper Update of Reference Count
- CVE-2015-1159 - Cross-Site Scripting
-- Didier Raboud <email address hidden> Tue, 09 Jun 2015 09:38:24 +0200
-
cups (1.7.5-11) unstable; urgency=medium
* Backport upstream patch to fix cupsRasterReadPixels buffer overflow with
invalid page header and compressed raster data
(STR: #4551, Closes: #778387)
-- Didier Raboud <email address hidden> Mon, 16 Feb 2015 08:19:17 +0100
-
cups (1.7.5-10) unstable; urgency=medium
* Change ppd-updaters trigger to use interest-noawait instead of interest to
avoid trigger cycles (Closes: #772871, #771765)
-- Didier Raboud <email address hidden> Mon, 15 Dec 2014 22:22:33 +0100
-
cups (1.7.5-9) unstable; urgency=medium
* Drop color-management patch; it got refused by upstream and is not
available in non-english translations (Closes: #763517, #768163)
* Drop the upstream patch to limit Get-Jobs replies to 500, as this triggers
a FTBS on mips
-- Didier Raboud <email address hidden> Thu, 27 Nov 2014 20:44:45 +0100
-
cups (1.7.5-7) unstable; urgency=medium
* Revert to not socket-activating CUPS (Closes: #747073)
- Drop patch to let CUPS write the systemd.socket configuration files
- Replace preinst generation of the same configuration file, delete them on
upgrade
- Drop the symlink enforcing the automatic configuration
- Update NEWS and README.Debian to reflect that change
- Create two cups socket configuration examples, document their existence
in README.Debian
- Update the systemd socket activation patch to include
PassCredentials=true in the socket configuration, following upstream's
feedback
- Disable automatic idle exit timeout under systemd, as this will get
activated without socket activation
-- Didier Raboud <email address hidden> Thu, 23 Oct 2014 22:06:18 +0200
-
cups (1.7.5-5) unstable; urgency=medium
[ Didier Raboud ]
* In debian/rules, add conditionals to enable build-indep build
* Bump Standards-Version to 3.9.6 without changes needed
* Remove Martin Pitt, Masayuki Hatta and Jeff Licquia from the Uploaders'
field; with many thanks for their past work on CUPS.
[ Ondřej Surý ]
* Remove libjpeg8-dev from libcupsimage2-dev (Closes: #765919)
-- Didier Raboud <email address hidden> Mon, 20 Oct 2014 08:54:21 +0200
-
cups (1.7.5-4) unstable; urgency=medium
[ intrigeri ]
* In the apparmor profile, drop features yet unsupported in Debian
(Closes: #763673)
[ Didier Raboud ]
* Add the Ubuntu-specific apparmor profile as Ubuntu-specific patch
-- Didier Raboud <email address hidden> Wed, 01 Oct 2014 21:40:15 +0200
-
cups (1.7.5-1) unstable; urgency=medium
* New 1.7.5 upstream release
- Drop upstream-originated patches, refresh all
- Refresh manpage translations for new upstream release
-- Didier Raboud <email address hidden> Thu, 14 Aug 2014 19:32:52 +0200
-
cups (1.7.4-4) unstable; urgency=medium
* Add patch to ignore the 'Failed to connect to system bus' error that
sometimes breaks the errorlines counting on various architectures
* Refresh cupsd-write-systemd-Port patch
-- Didier Raboud <email address hidden> Wed, 30 Jul 2014 10:40:53 +0200
-
cups (1.7.4-1) unstable; urgency=medium
* New 1.7.4 upstream release
- Security: The web interface incorrectly served symlinked files and
files that were not world-readable, potentially leading to a
disclosure of information (STR #4450, CVE-2014-3537)
- Added USB quirk rule for Lexmark E230 (STR #4448)
- Fix broken links on the web homepage (STR #4453, Closes: #754243)
- Refresh patches
[ Helge Kreutzmann ]
* Update German man page (1531t)
[ Didier Raboud ]
* Stop managing the rename of /etc/pam.d/cups in the cups binary package:
/etc/pam.d/cups is not renamed anymore but is now just installed from a
different package (cups-daemon). (Closes: #753439)
Thanks to Raphaël Hertzog
-- Didier Raboud <email address hidden> Mon, 14 Jul 2014 16:55:45 +0200
-
cups (1.7.3-6) unstable; urgency=medium
* Discard lpadmin stderr in the tests' utility, fixes autopkgtests.
-- Didier Raboud <email address hidden> Thu, 26 Jun 2014 07:51:30 +0200
-
cups (1.7.3-3) unstable; urgency=medium
* Fix autopkgtests:
- only use accessible files,
- extend the tests to test-print all PDFs in the source test/ directory,
- abstract the drivers testing script as a separate script.
-- Didier Raboud <email address hidden> Tue, 10 Jun 2014 13:18:23 +0200
-
cups (1.7.2-3) unstable; urgency=medium
[ Till Kamppeter ]
* Updated version numbers in Replaces:/Breaks: for cups-bsd to also work with
updating CUPS under Ubuntu (LP: #1315766)
-- Didier Raboud <email address hidden> Sun, 04 May 2014 12:18:32 +0200
-
cups (1.7.2-1) unstable; urgency=medium
* New 1.7.2 upstream release
- Security: The scheduler now blocks URLs containing embedded HTML
(STR #4356)
* Drop 10 patches that were backported from upstream or are now solved
differently:
- str4393-fix-memoryleak-in-rastertolabel
- fix-cupsdgetprivateattrs-function-missing-null-check
- fix-cupsenumdests-does-not-fill-in-is_default-field
- cupsenumdests-does-not-set-cb
- cupsd-support-avahi-daemon-restarting
- prevent-dnssd-backend-exiting-too-early
- fix-a-dbus-threading-issue-that-caused-the-scheduler-to-crash
- ipptool-doco-updates
- build-with-full-relro
- fix-template.c-typo
* Regenerate manpage-hyphen-minus patch to adapt to upstream changes
* Refresh 9 patches with quilt to cope with upstream updates
- airprint-support
- color-management-extension
- cupsd-idleexittimeout-systemd
- cupsd-idleexittimeout
- cupsd-write-systemd-Port
- no-conffile-timestamp
- pidfile
- read-embedded-options-from-incoming-postscript-and-add-to-ipp-attrs
- systemd-optional-socket-activation
* Refresh manpage translation files
-- Didier Raboud <email address hidden> Thu, 10 Apr 2014 22:05:22 +0200
-
cups (1.7.1-12) unstable; urgency=medium
[ Didier Raboud ]
* Fix the implicit-declaration problem in the D-BUS threading patch
by backporting an upstream update
[ Alf Gaida ]
* Create /etc/cups directory before attempting to create files in it
(Closes: #743249)
-- Didier Raboud <email address hidden> Tue, 01 Apr 2014 08:00:00 +0200
-
cups (1.7.1-10) unstable; urgency=medium
[ Till Kamppeter ]
* Remove upstream patch to fix race condition in cupsDoIORequest, as this
does not actually solve STR #4386 and also causes STR #4391, CUPS not being
able to communicate with Brother printers anymore
-- Didier Raboud <email address hidden> Thu, 20 Mar 2014 22:00:41 +0100
-
cups (1.7.1-7) unstable; urgency=low
* systemd socket activation:
- Drop ListenDatagram from cups.socket as that's now in use by
cups-browsed
- Drop the Debian-specific patch to make sure that the localhost web
access works; Listen on 0.0.0.0 and [::] in the main patch instead
* cups-bsd cleanup:
- Demote update-inetd Dependency to a Suggests, add conditionals in
the maintainer scripts (Closes: #590436)
- Move the cupsd-lpd manpage to cups
- Install the translated manpages
* In postinst scripts, only chown and chmod when no dpkg-statoverrides
are set (Closes: #587015)
* Demote cups-client's smbclient Recommendation to a Suggests
(Closes: #618545)
* Drop two obsolete configuration options from dh_auto_configure
* Drop boilerplate comments from all maintainer scripts
-- Didier Raboud <email address hidden> Thu, 27 Feb 2014 16:14:55 +0100
-
cups (1.7.1-5) unstable; urgency=medium
* In cups' initscript, stop trying to restart xprint.
Thanks to Damyan Ivanov (Closes: #738801)
* Import Fedora patch to prevent the dnssd backend from exiting too
early
-- Didier Raboud <email address hidden> Tue, 18 Feb 2014 15:44:18 +0100
-
cups (1.7.1-4) unstable; urgency=medium
[ Martin Pitt ]
* debian/libcups2-dev.preinst: Move aside a /usr/include/cups/i18n.h
directory during upgrades (from wheezy/precise); this directory got
replaced with a file, and triggers a bug in overlayfs when dist-upgrading
schroots/containers/similar. This is a hackish workaround and can be
dropped again in jessie+1/trusty+1. (LP: #1272285)
[ Didier Raboud ]
* Fix LGPL-2 references in debian/copyright, hanks to Thorsten Alteholz
* Move commandtops from cups to cups-core-drivers (Closes: #737306)
-- Didier Raboud <email address hidden> Tue, 04 Feb 2014 15:31:13 +0100
-
cups (1.7.1-2) unstable; urgency=medium
* Revert "Link against OpenSSL instead of GnuTLS", reopens #714492
* Add tests' patch to ignore a kfreebsd-amd64 error that breaks the
error lines counting
-- Didier Raboud <email address hidden> Tue, 14 Jan 2014 10:03:37 +0100
-
cups (1.6.4-2) unstable; urgency=low
* Import several patches from Fedora, thanks to Tim Waugh:
- Avoid stale lockfile in dbus notifier
- Stop accessing avahi through D-Bus using two threads
- Fix jobs with multiple files and multiple formats
- Revert upstream change to FINAL_CONTENT_TYPE in order to fix
printing to remote CUPS servers
* On purge, also delete the cupsd.conf.pre16-bak file to leave no
traces
-- Didier Raboud <email address hidden> Thu, 28 Nov 2013 12:22:09 +0100
-
cups (1.6.3-1) unstable; urgency=low
* New 1.6.3 upstream release:
- The lp, lpq, lpr, and lpstat now display an error message advising the
use of the /version=1.1 ServerName option (<rdar://problem/14290628>)
- Added documentation about the /version=1.1 option to ServerName in
client.conf (<rdar://problem/14216262>)
- httpStatus(HTTP_ERROR) did not return a useful error message
(Closes: #645436)
- The lp, lpq, lpr, and lpstat commands incorrectly ignored the default
printer set in the lpoptions file (Closes: #711848)
- The USB backend could crash on libusb-based systems if USB was
disabled in the BIOS (LP: #1108719).
- Added more USB quirks for the libusb-based backend
- The scheduler no longer tries to do Kerberos authentication over the
loopback interface. (Closes: #640939).
[ Didier Raboud ]
* Refresh patches for 1.6.3:
- usb-backend-more-quirk-rules: Shrink to only Lexmark E238 that
missed 1.6.3 merge window
- usb-backend-do-not-crash-if-usb-disabled-in-bios: Shrink to only
keep the error counting exception.
- remove-unreal-printers: Drop, was from upstream.
- more-verbose-http-error-message: Drop, was from upstream.
- mention-ipp-version-specifier-in-man-and-ref: Drop, differently
included upstream. (Closes: #711848)
* Invert symlink handling in cups-client's preinst to cope with the
symlink-to-directory migration for /usr/share/doc. (Closes: #716867)
* Update usb backend quirks to fix Lexmark E238 printer (Closes: #716843)
* Get dpkg-maintscript-helper to delete /e/c/acroread.conf and
/e/c/pdftops.conf again in 1.6.2-9~ to cleanup upgrades from cups
1.5. (Closes: #711136)
* Update debian/watch to cope with the new cups.org layout
[ Brian Potkin ]
* Rewrite README.Debian for Jessie (>= 1.6) (Closes: #714852)
-- Didier Raboud <email address hidden> Thu, 18 Jul 2013 21:45:15 +0200
-
cups (1.6.2-10) unstable; urgency=low
[ Didier Raboud ]
* Mark the cups-client NEWS as released and make sure it can be
installed by dropping the /usr/share/doc/cups-client symlink.
Thanks to Evgeni Golov (Closes: #704238)
* Backport upstream patch to remove unreal printers from the potential
printers' list to avoid jobs to go to unexpected printers
(Closes: #711848)
* Backport upstream patch to enhance the HTTP_ERROR handling
(Closes: #645436)
* Bump Standards-Version to 3.9.4 without changes needed
* Source package cleanup:
- Drop outdated and not-applied cups-avahi.patch
- Drop unused bzr-builddep configuration files
- Add gitignore file to ignore .pc/ directory
[ Helge Kreutzmann ]
* Update German manpages translation.
-- Didier Raboud <email address hidden> Wed, 26 Jun 2013 13:51:10 +0200
-
cups (1.5.3-5) unstable; urgency=low
* Team upload
- Rebuild against a fixed libmagic1 (see #703274).
- Non-NMU version, above all past 1.5.x experimental versions.
* Uploaders:
- Remove Kenshi Muto <email address hidden> with his agreement and with
great thanks for his past work!
- Add myself.
-- Didier Raboud <email address hidden> Mon, 18 Mar 2013 15:23:04 +0100