diff --git a/yt-dlp.changes b/yt-dlp.changes index d5fd290..54ce88c 100644 --- a/yt-dlp.changes +++ b/yt-dlp.changes @@ -1,3 +1,13 @@ +------------------------------------------------------------------- +Tue Jul 2 10:30:24 UTC 2024 - Michael Vetter + +- Update to release 2024.07.01: + * Security: [CVE-2024-38519] Properly sanitize file-extension + to prevent file system modification and RCE + Unsafe extensions are now blocked from being downloaded + * For details see: + https://github.com/yt-dlp/yt-dlp/releases/tag/2024.07.01 + ------------------------------------------------------------------- Tue May 28 06:39:46 UTC 2024 - Jan Engelhardt diff --git a/yt-dlp.spec b/yt-dlp.spec index e1a7a90..77fd449 100644 --- a/yt-dlp.spec +++ b/yt-dlp.spec @@ -21,7 +21,7 @@ %define skip_python37 1 %{?sle15_python_module_pythons} Name: yt-dlp -Version: 2024.05.27 +Version: 2024.07.01 Release: 0 Summary: Enhanced fork of youtube-dl, a video site downloader for offline watching License: CC-BY-SA-3.0 AND SUSE-Public-Domain diff --git a/yt-dlp.tar.gz b/yt-dlp.tar.gz index cdaea08..e7588fa 100644 --- a/yt-dlp.tar.gz +++ b/yt-dlp.tar.gz @@ -1,3 +1,3 @@ version https://git-lfs.github.com/spec/v1 -oid sha256:83dbf15456490e7efe9ba839922f8221d07cf1168b29653fd476faa3cdf91235 -size 5638920 +oid sha256:a0470c3554297bba4210390eca9a5369f478d66f7b9d04ac1841f69dc7e5d394 +size 5667870