Last commit made on 2017-03-16
879257f... by Marc Deslauriers on 2017-03-16

Import patches-unapplied version 2.6.3-3ubuntu2 to ubuntu/zesty-proposed

  * SECURITY UPDATE: DoS and possible code execution via missing glyph name
    - debian/patches/CVE-2016-10244.patch: add check to src/type1/t1load.c.
    - CVE-2016-10244

984d34c... by Matthias Klose on 2016-04-27

Import patches-unapplied version 2.6.3-3ubuntu1 to ubuntu/yakkety-proposed

  * Merge with Debian; remaining changes:
    - Make libfreetype6-dev M-A: same.
    - Error out on the use of the freetype-config --libtool option.
    - Don't add multiarch libdirs for freetype-config --libs.
    - Install the freetype2/freetype/config headers into the multiarch
      include path and provide symlinks in /usr/include.
    - debian/patches/0001-Revert-pcf-Signedness-fixes.patch: revert signedness
      fixes in pcf which break grub-mkfont (limits glyphs to 32768, which drops
      most zh_CN glyphs and probably others). (LP: #1559933)

49b19ba... by Steve Langasek on 2016-03-01

Import patches-unapplied version 2.6.3-3 to debian/sid

  * Install the now-available-upstream manpages for freetype-demos.
    Closes: #131137.
  * Register all of the HTML documentation with doc-base. Closes: #451660.
  * Suppress lintian warning about symbols file declaring dependency on
    other package, which is entirely by design.
  * Adjust symbols file to actually produce invalid dependencies when
    internal symbols are used, as intended.
  * New upstream release. Closes: #812518, LP: #1521299
    - stem darkening now disabled by default. Closes: #801370.
  * Avoid marking private symbols as supported from 2.6.1 on. Apparently
    dpkg-gensymbols doesn't do what I expected for this kind of declaration
    anyway, but we should at least avoid marking them wrong in the source.
  * Update to Standards-Version 3.9.7.

8216aa5... by "Matteo F. Vescovi" <email address hidden> on 2015-11-10

Import patches-unapplied version 2.6.1-0.1 to debian/sid

  * Non-maintainer upload.
  * New upstream release (Closes: #804050)

f4a9e1b... by Steve Langasek on 2015-09-19

Import patches-unapplied version 2.6-2 to debian/sid

  * Adjust symbols references for private symbols to sort to a higher (fake)
    version number instead of a lower, so that when linking against
    libfreetype without using its symbols, we don't get a wrong dependency on
    libfreetype6 (>= 1.PRIVATE.1). Closes: #799445.
  * Pass --without-harfbuzz in debian/rules, to avoid opportunistically
    picking this up as a dependency if libharfbuzz-dev is installed.

ebb3bd6... by Steve Langasek on 2015-09-12

Import patches-unapplied version 2.6-1 to debian/sid

  * New upstream release. Closes: #793751.
    * Includes a fix for a spurious error in FT_Get_SubGlyph_Info.
      Closes: #778493.
    * Includes a fix for an infinite loop in T1 font loading.
      Closes: #798620.
    * Includes a fix for an uninitialized memory bug in font parsers.
      Closes: #798619.
    * Includes fix for an out-of-bounds rate in the Adobe CFF implementation
      (which was not previously enabled in the package build).
      Closes: #773084.
    * Includes a fix for a crasher in xdvi. Closes: #733894.
    * Fixes support for compressed pcf fonts. Closes: #780340.
    * Drop various cherrypicked upstream patches from the package.
    * Ship upstream freetype-config manpage in place of our own.
      Closes LP: #1390767.
  * Update symbols file. Includes dropping various private symbols that
    don't appear to have ever been part of the API.
  * Fix exclusion of redundant license file (txt -> TXT)
  * Re-enable the CFF driver, now that most related fonts have been fixed.
    Closes: #795653.
  * Enable stage1 build without X library dependencies for bootstrapping.
    Closes: #752270, #752271.

c427bbb... by Keith Packard on 2015-03-16

Import patches-unapplied version 2.5.2-4 to debian/sid

  * Fix Savannah bug #43774. Closes #780143.
  * Release 2.5.2-4

e6a2a6d... by Keith Packard on 2015-02-24

Import patches-unapplied version 2.5.2-3 to debian/sid

  * Fix Savannah bug #43535. CVE-2014-9675
  * [bdf] Fix Savannah bug #41692. CVE-2014-9675-fixup-1
  * src/base/ftobj.c (Mac_Read_POST_Resource): Additional overflow check
    in the summation of POST fragment lengths. CVE-2014-0674-part-2
  * src/base/ftobjs.c (Mac_Read_POST_Resource): Insert comments and fold
    too long tracing messages. CVS-2014-9674-fixup-2
  * src/base/ftobjs.c (Mac_Read_POST_Resource): Use unsigned long variables to read the lengths in POST fragments. CVE-2014-9674-fixup-1
  * Fix Savannah bug #43538. CVE-2014-9674-part-1
  * Fix Savannah bug #43539. CVE-2014-9673
  * src/base/ftobjs.c (Mac_Read_POST_Resource): Avoid memory leak by
    a broken POST table in resource-fork. CVE-2014-9673-fixup
  * Fix Savannah bug #43540. CVE-2014-9672
  * Fix Savannah bug #43547. CVE-2014-9671
  * Fix Savannah bug #43548. CVE-2014-9670
  * [sfnt] Fix Savannah bug #43588. CVE-2014-9669
  * [sfnt] Fix Savannah bug #43589. CVE-2014-9668
  * [sfnt] Fix Savannah bug #43590. CVE-2014-9667
  * [sfnt] Fix Savannah bug #43591. CVE-2014-9666
  * Change some fields in `FT_Bitmap' to unsigned type. CVE-2014-9665
  * Fix uninitialized variable warning. CVE-2014-9665-fixup-2
  * Make `FT_Bitmap_Convert' correctly handle negative `pitch' values.
  * [type1, type42] Fix Savannah bug #43655. CVE-2014-9664
  * [sfnt] Fix Savannah bug #43656. CVE-2014-9663
  * [cff] Fix Savannah bug #43658. CVE-2014-9662
  * [type42] Allow only embedded TrueType fonts. CVE-2014-9661
  * [bdf] Fix Savannah bug #43660. CVE-2014-9660
  * [cff] Fix Savannah bug #43661. CVE-2014-9659
  * [sfnt] Fix Savannah bug #43672. CVE-2014-9658
  * [truetype] Fix Savannah bug #43679. CVE-2014-9657
  * [sfnt] Fix Savannah bug #43680. CVE-2014-9656
  * All CVEs patched. Closes: #777656.

f3322a2... by Steve Langasek on 2014-09-19

Import patches-unapplied version 2.5.2-2 to debian/sid

  * Acknowledge security NMU; thanks to Michael Gilbert.
  * Standards-Version 3.9.6.
  * Bump debhelper build-dependency to 9.
  * debian/patches/enable-old-cff.patch: disable the new CFF hinter from
    Adobe, working around wrong hinting with some toolkits on Linux. Thanks
    to Samat K Jain <email address hidden> for preparing the patch.
    Closes: #730742.
  * debian/patches-freetype/0001-Fix-Savannah-bug-40997.patch: Cherry-pick
    upstream patch to fix a double free. Closes: #747002, LP: #1310728.
  * debian/patches-freetype/0002-Fix-Savannah-bug-42418.patch: Cherry-pick
    upstream patch to fix cjk font rendering issue. LP: #1310017.
  * debian/patches-freetype/verbose-libtool.patch: don't let libtool
    suppress compiler output.
  * debian/patches-freetype/no-uninitialized-bbox.patch: ensure that our
    variable is reliably initialized before use, fixing a build failure on
    ppc64el when building with -O3.

48a23f0... by Michael Gilbert <email address hidden> on 2014-07-28

Import patches-unapplied version 2.5.2-1.1 to debian/sid

  * Non-maintainer upload by the Security Team.
  * Fix two security issues in the CFF rasterizer (closes: #741299)
    - CVE-2014-2240: out-of-bounds read/write in cf2hints.c.
    - CVE-2014-2241: denial-of-service in cf2ft.c.