Last commit made on 2008-09-11
cc30e03... by Kees Cook on 2008-09-10

Import patches-unapplied version 2.2.1-5ubuntu1.2 to ubuntu/feisty-security

  * SECURITY UPDATE: arbitrary code execution via integer overflows.
  * Add debian/patches-freetype/CVE-2008-1806_7_8.patch: upstream fixes
    thanks to Steffen Joeris.
  * References
    CVE-2008-1806 CVE-2008-1807 CVE-2008-1808

d49b6fa... by Kees Cook on 2007-05-22

Import patches-unapplied version 2.2.1-5ubuntu1.1 to ubuntu/feisty-security

  * SECURITY UPDATE: arbitrary code execution via integer overflows.
  * Add debian/patches-freetype/security-ttgload-overflow.patch from
    upstream changes.
  * References

11f0a72... by Kees Cook on 2007-04-02

Import patches-unapplied version 2.2.1-5ubuntu1 to ubuntu/feisty

  * SECURITY UPDATE: arbitrary code execution via integer overflows.
  * Add debian/patches-freetype/CVE-2007-1351_bdf_integer.patch from
    upstream changes.
  * References

4a63624... by Steve Langasek on 2006-09-12

Import patches-unapplied version 2.2.1-5 to ubuntu/edgy

  * High-urgency upload for RC bugfix.
  * Add debian/patches-freetype/CVE-2006-3467_pcf-strlen.patch to
    address CVE-2006-3467, a missing string length check in PCF files that
    leads to a possibly exploitable integer overflow. Thanks to Martin
    Pitt for the patch. Closes: #379920.
  * Drop libfreetype6.postinst code for cleaning up /usr/X11R6/lib;
    whatever version it applied to is pre-sarge, and this code is
    sufficiently blunt that I don't think it should be kept around.
    Closes: #386379.
  * Apply patch from Eugeniy Meshcheryakov <email address hidden>, applied
    upstream, to fix bug in rendering of composite glyphs.
    Closes: #374902.

dc2caaf... by Keith Packard on 2006-05-17

Import patches-unapplied version 2.2.1-2 to ubuntu/edgy

  * Enable full bytecode interpreter instead of just the
    "non-patented portions".
  * Use $(CURDIR) instead of $(PWD) to build with sudo. Closes: #367579.
  * New upstream release
    - Supersedes patches freetype-2.1.10-cvsfixes.patch,
      freetype-2.1.10-fixaliasing.patch, freetype-2.1.10-fixautofit.patch,
      freetype-2.1.10-fixkerning.patch, freetype-2.1.10-memleak.patch,
  * New upstream release
    - this version should restore binary compatibility with version
      2.1.7. Closes: #314385.
    - use the old ft2demos and freetype-docs for now; patch ft2demos
      (temporarily only!) to still use the internal headers, which are
      now no longer exported as part of the API
  * Patch to handle empty short metrics, as seen in BitStream Vera.
  * Bump shlibs to 2.2~rc4-1. Closes: #316031.
  * Replace debian/rules patch handling with quilt; thanks to Jurij
    Smakov <email address hidden> for the patch.
  * Removed freetype-2.1.10-fixaliasing.patch to restore proper sub-pixel
    anti-aliased hinted rendering. Thanks to Michael Biebl for reporting
    the bug. I was able to reproduce the bug setting gnome-font-properties
    to: 96 dpi, sub-pixel anti-aliasing, full hinting, with Bitstream Vera
    Sans Roman 11 as desktop font. (Closes: Bug#359104)
  * Added more fixes to debian/patches/freetype-2.1.10-cvsfixes.patch:
     * 2006-03-27 David Turner <email address hidden>
        * src/sfnt/ttkern.c (tt_face_get_kerning): Fix a serious bug that
          causes some programs to go into an infinite loop when dealing with
          fonts that don't have a properly sorted kerning sub-table.
     * 2006-03-21 Zhe Su <email address hidden>
        * src/base/ftoutln.c (FT_Outline_Get_Orientation): Improve algorithm.
       This is to prevent certain emboldened and hinted glyphs from becoming
       "weird". See https://bugzilla.novell.com/show_bug.cgi?id=158573
       for details.
  * Oops, I inadvertently set the shlibs dependency to (>= 2.1.10-1)
    in 2.1.10-2. Reverted to (>= 2.1.5-1).
  * Will Newton has agreed to let Steve Langasek adopt the package.
    Therefore, I have taken the liberty to set the Maintainer field
    to Steve, and to add myself as an uploader. :-) (See Bug#351821)
  * Acknowledge NMUs by Frans Pop (shlibs for udeb, Closes: Bug#355939)
    and by Joey Hess (xlibs-dev removal, Closes: Bug#346706).
    Thank you all!
  * Merge fixes from 2.1.10-1ubuntu1 (Many thanks!):
     * Patches for Malone #5560.
        - various fixes (mostly embolding which caused characters to
          slant upward, most evident for CJK users in KDE and icewm.
          (Closes: Bug#356495, Bug#356854)
        - put back internal API used by xorg-x11
        - fix autofit render setup
        - fix memleak
        - fix disabled kerning
        - fix anti-aliasing rendering
     * Changes by Jun Kobayashi <email address hidden>
    -- Jonathan Riddell <email address hidden> Mon, 16 Jan 2006 17:45:50 +0900
  * Non Maintainer Upload (closes: #355939)
  * Add support for udeb dependency resolution in shlibs file
  * Simplify debian/rules by making use of udeb support in debhelper
  * Update debhelper compatibility to level 5
  * NMU
  * Patch from Ben Hutchings for xlibs-dev transition. Closes: #346706

d531fd7... by Will Newton <email address hidden> on 2005-06-12

Import patches-unapplied version 2.1.10-1 to ubuntu/dapper

  * New upstream (Closes: #298660, #245532).
  * New maintainer, co-maintainer required!
  * Disable CJK autohinting patch due to incompatability with this version
    of freetype.
  * Remove some very old unapplied patches.
  * Add freetype-config.1 manpage.
  * Add doc-base file for development docs. (Closes: #280827)
  * Fix build with non-default umask. (Closes: #307464, #166511)
  * Patch merged upstream. (Closes: #252673)
  * Acknowledge NMUS.
    (Closes: #221597, #225119, #226380, #249443, #251473, #302269, #259875)
   * New upstream.
  * Non-maintainer upload.
  * freetype-2.1.7/src/bdf/bdflib.c: When a glyph has zero width or height,
    a bitmap is not actually allocated for it, but the code used to try to
    use it anyway. Now it no longer does that. Fix by Steve Langasek,
    based on something I did earlier. Added
    debian/patches/300-bdflib-zero-width-glyphs.diff. Closes: #302269
    (Segmentation fault with certain bdf fonts).
  * freetype-2.1.7/src/bdf/bdflib.c: BDF font files with glyphs with an
    encoding value of at least 65536 would overflow the bitmap with
    65536 bits which bdflib.c uses to keep track of whether it has seen
    an encoding already. Changed things so that encodings above the
    limit cause an error code to be returned instead of a segfault
    happening. Ideally, the bitmap should be replaced with a more
    compact representation, but that is too big a change for something
    this small. I will, however, only lower the severity of the bug
    (305413) to normal, instead of marking it fixed. Added

ed18577... by dann frazier on 2004-11-09

Import patches-unapplied version 2.1.7-2.3 to ubuntu/hoary

