ImageMagick/ImageMagick-6.8.8-1-disable-insecure-coders.patch
Petr Gajdos 5c3d396362 - Updated to 6.9.6-5
* Web pages were broken when we moved to HTTPS protocol.
  * Restore -sharpen / -convolve options to work with CMYK (reference
    https://github.com/ImageMagick/ImageMagick/issues/299).
  * Off by one memory allocation (reference
    https://github.com/ImageMagick/ImageMagick/issues/296).
  * Prevent fault in MSL interpreter (reference
    https://www.imagemagick.org/discourse-server/viewtopic.php?f=3&t=30797).
  * Added layer ZIP compression to the PSD encoder.
  * Unit test pass again after small SUN image patch.
  * Fixed incorrect RLE decoding when reading a DCM image that contains
    multiple segments.
  * Fixed incorrect RLE decoding when reading an SGI image (reference 
    https://www.imagemagick.org/discourse-server/viewtopic.php?f=3&t=30514)

OBS-URL: https://build.opensuse.org/package/show/graphics/ImageMagick?expand=0&rev=268
2016-11-22 09:45:21 +00:00

21 lines
1.1 KiB
Diff

Index: ImageMagick-6.9.6-5/config/policy.xml
===================================================================
--- ImageMagick-6.9.6-5.orig/config/policy.xml 2016-11-15 12:05:54.000000000 +0100
+++ ImageMagick-6.9.6-5/config/policy.xml 2016-11-22 10:30:23.722541610 +0100
@@ -65,4 +65,15 @@
<!-- <policy domain="delegate" rights="none" pattern="HTTPS" /> -->
<!-- <policy domain="path" rights="none" pattern="@*"/> -->
<policy domain="cache" name="shared-secret" value="passphrase" stealth="true"/>
+ <!-- Disable insecure coders by default -->
+ <!-- https://bugzilla.suse.com/show_bug.cgi?id=978061 -->
+ <policy domain="coder" rights="none" pattern="EPHEMERAL" />
+ <policy domain="coder" rights="none" pattern="URL" />
+ <policy domain="coder" rights="none" pattern="HTTPS" />
+ <policy domain="coder" rights="none" pattern="MVG" />
+ <policy domain="coder" rights="none" pattern="MSL" />
+ <policy domain="coder" rights="none" pattern="TEXT" />
+ <policy domain="coder" rights="none" pattern="SHOW" />
+ <policy domain="coder" rights="none" pattern="WIN" />
+ <policy domain="coder" rights="none" pattern="PLT" />
</policymap>