Add CVE-2021-45463 ref to .changes

This update fixed CVE-2021-45463.

OBS-URL: https://build.opensuse.org/package/show/graphics/gegl?expand=0&rev=117
This commit is contained in:
Bjørn Lie 2022-01-19 20:31:30 +00:00 committed by Git OBS Bridge
parent 9be78fa155
commit 4f33e84315

View File

@ -14,6 +14,22 @@ Tue Dec 21 19:08:52 UTC 2021 - Marcus Rueckert <mrueckert@suse.de>
operations using it avoiding polluting the GEGL library operations using it avoiding polluting the GEGL library
symbol table with the ctx symbols. symbol table with the ctx symbols.
-------------------------------------------------------------------
Tue Dec 21 19:08:52 UTC 2021 - Marcus Rueckert <mrueckert@suse.de>
- Update to version 0.4.34 (CVE-2021-45463):
+ Operations:
- magick-load: use g_spawn_async instead of system to run the
image magick convert fallback - preventing shell expansion on
non-escaped/filtered paths in constructed commandline.
- ripple: avoid a possible division by zero.
+ Build:
- Explicit dependency specification in meson for generated CL
files.
- ctx has been moved to be part of gegl-common.so nearer to the
operations using it avoiding polluting the GEGL library
symbol table with the ctx symbols.
------------------------------------------------------------------- -------------------------------------------------------------------
Wed Oct 27 21:23:26 UTC 2021 - Michael Gorse <mgorse@suse.com> Wed Oct 27 21:23:26 UTC 2021 - Michael Gorse <mgorse@suse.com>