Upgrade poppler to 0.48.0-2+deb9u1. (CVE-2017-14929, CVE-2017-1000456)
Upgrade tiff to 4.0.8-2+deb9u2 (CVE-2017-9935, CVE-2017-11335,
CVE-2017-12944, CVE-2017-13726, CVE-2017-13727, CVE-2017-18013)
Upgrade ffmpeg to 7:3.2.10-1~deb9u1. (CVE-2017-17081)
Upgrade libtasn1-6 to 4.10-1.1+deb9u1. (CVE-2017-10790, CVE-2018-6003)
Upgrade Libre Office to 1:5.2.7-1+deb9u2. (CVE-2018-6871)
Upgrade libvorbis to 1.3.5-4+deb9u1. (CVE-2017-14632, CVE-2017-14633)
Upgrade gcc to 6.3.0-18+deb9u1.
Upgrade util-linux to 2.29.2-1+deb9u1. (CVE-2018-7738)
Upgrade isc-dhcp to 4.3.5-3+deb9u1 (CVE-2017-3144, CVE-2018-5732,
CVE-2018-5733)
Minor improvements
Avoid noisy warning at boot time by creating zerotracepen-upgrade-frontend's
trusted GnuPG homedir with stricter permissions, then making it looser.
(Closes: #7037)
Drop (broken) Thunderbird dedicated SocksPort. (Closes: #12460)
Drop customized update-ca-certificates.service. (Closes: #14756)
Update AppArmor cupsd profile. (Closes: #15029)
Improve UX when GDM does not start. (Closes: #14521)
Install packages needed to support Video Acceleration API.
(Closes: #14580)
Upgrade aufs-dkms for Linux 4.15. (Closes: #15132).
Ship pdf-redact-tools, thanks to dachary loic@dachary.org.
(Closes: #15052)
Additional Software Packages: convert to python3 and PEP-8.
(Closes: #15198)
Additional Software Packages: do not check for updates every time the
network gets reconnected. (Closes: #9819)
Revert to xorg-xserver from Stretch. (Closes: #15232)
Open Zero Trace Pen documentation in Tor Browser when online. (Closes: #15332)