From 6696fb396388be7c24f78cfede58b5cd00932986c23b9e212e44cb53b4d58a2a Mon Sep 17 00:00:00 2001 From: Takashi Iwai Date: Fri, 21 Aug 2020 13:46:56 +0000 Subject: [PATCH] Accepting request 827291 from home:dirkmueller:branches:multimedia:libs - update to 1.0.13: * CVE-2020-13999 (bsc#1173070) libEMF (aka ECMA-234 Metafile Library) through 1.0.12 is vulnerable to Integer overflow condition in libemf.cpp:ScaleviewportExtEx function leading to Denial of Service VulnerabilityType : Integer Overflow OBS-URL: https://build.opensuse.org/request/show/827291 OBS-URL: https://build.opensuse.org/package/show/multimedia:libs/libEMF?expand=0&rev=24 --- libEMF.changes | 11 +++++++++++ libEMF.spec | 4 ++-- libemf-1.0.12.tar.gz | 3 --- libemf-1.0.13.tar.gz | 3 +++ 4 files changed, 16 insertions(+), 5 deletions(-) delete mode 100644 libemf-1.0.12.tar.gz create mode 100644 libemf-1.0.13.tar.gz diff --git a/libEMF.changes b/libEMF.changes index 743c151..f477adb 100644 --- a/libEMF.changes +++ b/libEMF.changes @@ -1,3 +1,14 @@ +------------------------------------------------------------------- +Mon Aug 17 09:51:29 UTC 2020 - Dirk Mueller + +- update to 1.0.13: + * CVE-2020-13999 (bsc#1173070) + + libEMF (aka ECMA-234 Metafile Library) through 1.0.12 is vulnerable to + Integer overflow condition in libemf.cpp:ScaleviewportExtEx function + leading to Denial of Service + VulnerabilityType : Integer Overflow + ------------------------------------------------------------------- Wed May 27 23:58:38 UTC 2020 - Jason Sikes diff --git a/libEMF.spec b/libEMF.spec index 8fd81cc..54b8b6d 100644 --- a/libEMF.spec +++ b/libEMF.spec @@ -1,7 +1,7 @@ # # spec file for package libEMF # -# Copyright (c) 2020 SUSE LINUX GmbH, Nuernberg, Germany. +# Copyright (c) 2020 SUSE LLC # # All modifications and additions to the file contributed by third parties # remain the property of their copyright owners, unless otherwise agreed @@ -17,7 +17,7 @@ Name: libEMF -Version: 1.0.12 +Version: 1.0.13 Release: 0 Summary: Library for Manipulation with Enhanced MetaFile (EMF, ECMA-234) License: LGPL-2.1-or-later AND GPL-2.0-or-later diff --git a/libemf-1.0.12.tar.gz b/libemf-1.0.12.tar.gz deleted file mode 100644 index b9e67ba..0000000 --- a/libemf-1.0.12.tar.gz +++ /dev/null @@ -1,3 +0,0 @@ -version https://git-lfs.github.com/spec/v1 -oid sha256:22e6f70986dc1ff8b85aa94f8ee45dd259034ad6476e42156ccf237e25c4d506 -size 1314880 diff --git a/libemf-1.0.13.tar.gz b/libemf-1.0.13.tar.gz new file mode 100644 index 0000000..7132ad3 --- /dev/null +++ b/libemf-1.0.13.tar.gz @@ -0,0 +1,3 @@ +version https://git-lfs.github.com/spec/v1 +oid sha256:74d92c017e8beb41730a8be07c2c6e4ff6547660c84bf91f832d8f325dd0cf82 +size 1314905