ImageMagick/ImageMagick-configuration-SUSE.patch
Petr Gajdos e3598ed4ae Accepting request 943180 from home:dirkmueller:Factory
- update to 7.1.0.19:
  * support -integral option.
  * possible DoS for certain SVG constructs (reference
    https://github.com/ImageMagick/ImageMagick/issues/4626).

- update to 7.1.0.18:
  * support face index for font collections, e.g. msgothic.ttc[1].
  * Improved adjustment of page offset when resizing an image.

OBS-URL: https://build.opensuse.org/request/show/943180
OBS-URL: https://build.opensuse.org/package/show/graphics/ImageMagick?expand=0&rev=585
2022-01-03 07:59:25 +00:00

28 lines
1.5 KiB
Diff

--- policy.xml.orig 2020-12-28 15:22:47.380782086 +0100
+++ policy.xml 2020-12-28 15:24:10.637332778 +0100
@@ -79,4 +79,24 @@
<!-- <policy domain="system" name="shred" value="2"/> -->
<!-- <policy domain="system" name="precision" value="6"/> -->
<!-- <policy domain="system" name="font" value="/path/to/unicode-font.ttf"/> -->
+ <!-- Disable insecure coders by default -->
+ <!-- https://bugzilla.suse.com/show_bug.cgi?id=978061 -->
+ <policy domain="coder" rights="none" pattern="EPHEMERAL" />
+ <policy domain="coder" rights="none" pattern="URL" />
+ <policy domain="coder" rights="none" pattern="HTTPS" />
+ <policy domain="coder" rights="none" pattern="MVG" />
+ <policy domain="coder" rights="none" pattern="MSL" />
+ <policy domain="coder" rights="none" pattern="TEXT" />
+ <policy domain="coder" rights="none" pattern="SHOW" />
+ <policy domain="coder" rights="none" pattern="WIN" />
+ <policy domain="coder" rights="none" pattern="PLT" />
+ <policy domain="coder" rights="write" pattern="PS" />
+ <policy domain="coder" rights="write" pattern="PS2" />
+ <policy domain="coder" rights="write" pattern="PS3" />
+ <policy domain="coder" rights="write" pattern="PDF" />
+ <policy domain="coder" rights="write" pattern="XPS" />
+ <policy domain="coder" rights="write" pattern="EPI" />
+ <policy domain="coder" rights="write" pattern="EPS" />
+ <policy domain="coder" rights="write" pattern="PCL" />
+ <policy domain="path" rights="none" pattern="@*"/>
</policymap>