Change logs for libjpeg-turbo source package in Trusty

  • libjpeg-turbo (1.3.0-0ubuntu2.1) trusty-security; urgency=medium
    
      * SECURITY UPDATE: denial of service via JPEG file
        - debian/patches/CVE-2014-9092.patch: adjust size in jchuff.c.
        - CVE-2014-9092
      * SECURITY UPDATE: denial of service via crafted file
        - debian/patches/CVE-2016-3616.patch: check range of integer values in
          PPM text file in cderror.h, rdppm.c.
        - CVE-2016-3616
        - CVE-2018-11213
        - CVE-2018-11214
      * SECURITY UPDATE: divide-by-zero via crafted file
        - debian/patches/CVE-2018-11212.patch: check image size in rdtarga.c.
        - CVE-2018-11212
      * SECURITY UPDATE: division by zero via BMP image
        - debian/patches/CVE-2018-1152.patch: add size check in rdbmp.c.
        - CVE-2018-1152
    
     -- Marc Deslauriers <email address hidden>  Thu, 05 Jul 2018 15:55:15 -0400
  • libjpeg-turbo (1.3.0-0ubuntu2) trusty; urgency=low
    
      * SECURITY UPDATE: information disclosure via uninitialized memory in
        the get_sos function (LP: #1252912)
        - debian/patches/CVE-2013-6629.patch: check for duplications in
          jdmarker.c.
        - CVE-2013-6629
      * SECURITY UPDATE: information disclosure via uninitialized memory in
        the get_dht function (LP: #1252912)
        - debian/patches/CVE-2013-6630.patch: properly clear out memory in
          jdmarker.c.
        - CVE-2013-6630
     -- Marc Deslauriers <email address hidden>   Thu, 19 Dec 2013 15:07:26 -0500
  • libjpeg-turbo (1.3.0-0ubuntu1) saucy; urgency=low
    
      * New upstream release.
        - drop debian/patches/branch-updates.diff
        - refresh tjunittest.patch (now renamed to install-tjunittest.patch)
      * Update debian/control:
        - add myself to Uploaders.
      * Update debian/copyright:
        - add RSA Data Security copyright (md5).
      * Update debian/libturbojpeg.install:
        - install libturbojpeg.so.0* (needed by tjunittest and tjbench).
     -- Fathi Boudra <email address hidden>   Sun, 28 Jul 2013 16:52:51 +0300