gcab (0.4-2) unstable; urgency=medium

  * Indicate that libgcab/gcab-enums.* is licensed using LGPL-2.0+, not
    2.1+ like the rest of the project. Thanks to Thorsten Alteholz for
    pointing out that this should be indicated explicitly!
  * Prevent path traversals; contents of cabinet files are always
    extracted below the extraction point and cannot escape it. Closes:
    #774580. This is CVE-2015-0552.

 -- Stephen Kitt <skitt@debian.org>  Tue, 06 Jan 2015 00:14:58 +0100

gcab (0.4-1) unstable; urgency=low

  * Initial release. Closes: #771253.

 -- Stephen Kitt <skitt@debian.org>  Sat, 29 Nov 2014 00:12:00 +0100
