-
hplip (2.8.2-0ubuntu8.2) hardy-security; urgency=low
* SECURITY UPDATE: denial of service and possible arbitrary code
execution via long SNMP response
- debian/patches/94_SECURITY_CVE-2010-4267.dpatch: validate dLen in
io/hpmud/pml.c.
- CVE-2010-4267
-- Marc Deslauriers <email address hidden> Mon, 24 Jan 2011 12:33:49 -0500
-
hplip (2.8.2-0ubuntu8.1) hardy-security; urgency=low
* SECURITY UPDATE: privilege escalation using the hplip alert-mailing
functionality.
- debian/patches/92_SECURITY_CVE-2008-2940.dpatch: fix handle_event()
in hpssd.py to validate device-uri parameter and disable
handle_setalerts(). This fix alters hplip behaviour by preventing
users from setting alerts and by moving alert configuration to a
root-controlled /etc/hp/alerts.conf file.
- CVE-2008-2940
* SECURITY UPDATE: denial of service in hpssd message parser.
- debian/patches/93_SECURITY_CVE-2008-2941.dpatch: fix handle_event()
in hpssd.py to correctly validate parameters.
- CVE-2008-2941
-- Marc Deslauriers <email address hidden> Tue, 18 Nov 2008 14:36:40 -0500
-
hplip (2.8.2-0ubuntu8) hardy; urgency=low
* debian/local/scripts/create_hal_global_fdi_from_hpmud_rules.sh: Corrected
fdi script so that it actually works (LP: #195782).
-- Till Kamppeter <email address hidden> Tue, 15 Apr 2008 13:28:52 +0200
-
hplip (2.8.2-0ubuntu7) hardy; urgency=low
* debian/control: Let hplip-gui depend on python-reportlab instead
of hplip recommending it. python-reportlab is used by the GUI of
hp-sendfax to add cover pages. In command line mode of hp-sendfax
cover pages are not supported (LP: #211249).
-- Till Kamppeter <email address hidden> Fri, 4 Apr 2008 13:28:52 +0200
-
hplip (2.8.2-0ubuntu6) hardy; urgency=low
* debian/control: Let hpijs depend on foomatic-filters (LP: #187403).
* debian/control, debian/hplip.links: Added missing links to utilities
hp-check and hp-scan. Added dependency on python-imaging for hp-scan.
* debian/rules: Corrected filter name from "foomatic-rip-hplip" to
"foomatic-rip" (LP: #211382).
* debian/hplip.preinst: Remove obsolete /etc/default/hplip file before
installation of the hplip binary package (LP: #211377).
-- Till Kamppeter <email address hidden> Thu, 3 Apr 2008 22:28:52 +0200
-
hplip (2.8.2-0ubuntu5) hardy; urgency=low
* debian/local/scripts/create_hal_global_fdi_from_hpmud_rules.sh,
debian/rules, debian/hplip.install: Generate fdi script to make
HP devices accessible for the desktop user currently logged in
(LP: #195782).
* debian/patches/hp_oj_h470_alignment.dpatch: Fixed head alignment for
HP OfficeJet H470 (LP: #204157).
-- Till Kamppeter <email address hidden> Tue, 1 Apr 2008 15:28:52 +0200
-
hplip (2.8.2-0ubuntu4) hardy; urgency=low
* debian/hpijs-ppds.links: Removed. The link into /usr/share/cups/model
leads to duplicate listing of the PPDs by CUPS 1.3.x.
-- Till Kamppeter <email address hidden> Sun, 23 Mar 2008 23:08:52 +0100
-
hplip (2.8.2-0ubuntu3) hardy; urgency=low
* debian/patches/hp-setup_crash.dpatch: Fix crash of hp-setup (LP: #181242)
* debian/patches/hp_clj_3600_best_color_mode.dpatch: Fix "Best" color mode of
the HP LaserJet 35xx/36xx (LP: #200147).
-- Till Kamppeter <email address hidden> Thu, 13 Mar 2008 12:08:52 +0100
-
hplip (2.8.2-0ubuntu2) hardy; urgency=low
[ Till Kamppeter ]
* debian/rules: Install the new fax PPD file for color fax devices
(currently only HP LaserJet M2727 series, Ubuntu LP: #59409).
* debian/hplip.postinst: Fix PPD paths in /etc/hp/hplip.conf, so that
hp-setup finds the fax PPDs (Ubuntu LP: #59409).
* debian/hplip.postinst: Removed code to correct permissions of .hplip
personal config in user's home directories (Ubuntu LP: #191299).
[ Mark Purcell ]
* Added NEWS/ README entry about the need to use 'scanner' group
- Non-root users need to be in group scanner! (Closes: #454339)
- should use plugdev rather than scanner group (Closes: #452454)
- sane-utils: Scanner only accessible under root (Closes: #462563)
* Force (-f) removal of init.d scripts
- Uses update-rc.d remove while init script exists; upgrade fails
(Closes: #456378)
-- Till Kamppeter <email address hidden> Tue, 26 Feb 2008 10:08:52 +0100
-
hplip (2.8.2-0ubuntu1) hardy; urgency=low
* New upstream release
o PPDs generated on-the-fly by the CUPS DDK
o Corrected IPP printer state messages
o Fixed segmentation faults in HPIJS (Upstream bug LP: #182658)
o Many bug fixes
o Battery monitoring for OfficeJet H470, fax for LaserJet M2727
o New models supported: HP LaserJet P1005, P1006, P1505, P1505n,
Officejet H470, LaserJet P2014
* debian/control: Added build dependency on CUPS DDK, standards version
3.7.3, let also HPIJS depend on CUPS DDK.
* debian/hpijs.install: Added PPD generator data file
/usr/share/cups/drv/hpijs.drv
* debian/patches/89_hplip-alloc.dpatch: Removed, fixed upstream
* debian/rules: Removed Foomatic-XML-related stuff, use configure options
to let PPDs get generated on-the-fly by the CUPS DDK, do not modify the
fax PPD.
-- Till Kamppeter <email address hidden> Tue, 12 Feb 2008 11:02:42 +0100
-
hplip (2.7.12-0ubuntu2) hardy; urgency=low
* debian/patches/89_hplip-alloc.dpatch: The hpijs compression
module did not allocate enough memory (Upstream bug LP: #182658).
-- Till Kamppeter <email address hidden> Mon, 28 Jan 2008 11:34:49 +0000
-
hplip (2.7.12-0ubuntu1) hardy; urgency=low
* Now upstream release
o PJL support for HP LaserJets for in-band status check
o New print modes for LJJetReady device class (HP Color LaserJet
3600/3500/3550).
o Improvement of plug-in download by hp-setup.
o Bug fixes, especially for fax.
o New models supported: HP LaserJet M2727 MFP (printing only, no
scanning or fax), HP LaserJet M1005 MFP (printing only, no scanning),
HP LaserJet 1000/1005, HP Color LaserJet 3600/3500/3550, HP LaserJet
9040.
* debian/rules, debian/45-hplip.rules, debian/check_mfp_printer: Removed
/etc/udev/rules.d/45-hplip.rules and check_mfp_printer, HP provides a
solution from upstream now.
* debian/55-hpmud.rules: Updated for compatibility with kernel 2.6.24 and
newer (Ubuntu bug LP: #181242).
* debian/patches/87_move_documentation.dpatch: Updated patch for new HPLIP
version.
-- Till Kamppeter <email address hidden> Sat, 12 Jan 2008 14:34:49 +0000
-
hplip (2.7.10-5ubuntu2) hardy; urgency=low
* Rebuild for libsnmp10 -> libsnmp15 transition.
-- Steve Kowalik <email address hidden> Mon, 10 Dec 2007 22:55:06 +1100
-
hplip (2.7.10-5ubuntu1) hardy; urgency=low
* Merge with Debian unstable. No remaining Ubuntu changes.
* debian/rules: Added "--with-hpppddir=\$${prefix}/share/ppd/hpijs/HP" to
"./configure" call so that "hp-setup" will find the fax PPD (Ubuntu bug
LP: #59409).
* debian/rules: Removed "--dpkg-shlibdeps-params=--ignore-missing-info"
from dh_shlibdeps. Does not build under Ubuntu.
-- Till Kamppeter <email address hidden> Thu, 6 Dec 2007 16:34:49 +0000
-
hplip (2.7.10-5) unstable; urgency=low
* Check for old init scripts [ -x /etc/init.d/hplip ] and manually
remove them before we call update-rc.d
- preinst fails: update-rc.d: /etc/init.d/hplip exists (Closes: #453902)
-- Ubuntu Archive Auto-Sync <email address hidden> Tue, 04 Dec 2007 11:53:23 +0000
-
hplip (2.7.10-4) unstable; urgency=low
* Extremadura release ;-)
* Provide debian/shlibs lintian: shlib-missing-in-control-file
- FTBFS on amd64/sid (Closes: #453361)
* Rewrite hplip.preinst to not call killall
- predepend on psmisc (?) (Closes: #452408)
* Switch hplip.{pre,post}inst to use update-rc.d & invoke-rc.d
- maintainer-script-calls-init-script-directly (Closes: #452244)
* Cleanup hplip.menu
- please change default icon to /usr/share/pixmaps/HPmenu.xpm
(Closes: #415048)
* Remove Depends: sysv-rc
-- Ubuntu Archive Auto-Sync <email address hidden> Sat, 01 Dec 2007 13:21:14 +0000
-
hplip (2.7.10-3) unstable; urgency=low
* Update debian/watch - thks Chris Lamb
- debian/watch file incorrect (Closes: #415926)
- debian/watch fails to report upstream's version (Closes:
#449610)
* debian/rules dh_shlibdeps --dpkg-shlibdeps-params=--ignore-missing-info
-- Ubuntu Archive Auto-Sync <email address hidden> Fri, 23 Nov 2007 08:50:12 +0000
-
hplip (2.7.10-2) unstable; urgency=low
* Unstable upload
* debian/control
- Homepage: http://hplip.sourceforge.net/
- Vcs-Svn: svn://svn.debian.org/pkg-hpijs/hplip/trunk/
- Vcs-Browser: http://svn.debian.org/wsvn/pkg-hpijs/hplip/?op=log
-- Ubuntu Archive Auto-Sync <email address hidden> Wed, 21 Nov 2007 09:51:09 +0000
-
hplip (2.7.10-1) experimental; urgency=low
* Shadow ubuntu release into debian experimental
- new upstream release (Closes: #413225)
* TODO inport into CVS/ SVN
-- Till Kamppeter <email address hidden> Tue, 20 Nov 2007 11:26:43 +0000
-
hplip (2.7.10-0ubuntu1) hardy; urgency=low
* New upstream release
o hp-setup capable of loading non-free driver extensions from the
internet (usually from OpenPrinting)
o hp-sendfax problem of not being able add files fixed upstream
(LP: #153152)
o New models supported: HP Officejet Pro K8600, Photosmart C4380 Series,
LaserJet 1018, 1020, 1022, 1022n, 1022nw, Deskjet 550C
* No modification of the upstream source tarball needed any more.
* debian/patches/70_no_fail_on_bad_locales.dpatch: Removed, does not apply
to current upstream source code any more.
* debian/patches/90_subprocess_replacement.dpatch: Removed, fixed upstream.
* debian/control: Let hpijs depend on hplip (LP: #149511).
-- Till Kamppeter <email address hidden> Sat, 27 Oct 2007 14:34:49 +0100
-
hplip (2.7.7.dfsg.1-0ubuntu5) gutsy; urgency=low
* SECURITY UPDATE: arbitrary command execution via network
* Add debian/patches/90_subprocess_replacement: use subprocess instead.
* References
https://launchpad.net/bugs/149121
CVE-2007-5208
-- Kees Cook <email address hidden> Thu, 11 Oct 2007 10:25:17 -0700