* Fix for possible heap overrun in Canon makernotes parser

(CVE-2017-14348)
- add libraw-out-of-bounds-kodak.patch, upstream bug #101

OBS-URL: https://build.opensuse.org/package/show/graphics/libraw?expand=0&rev=99
This commit is contained in:
Petr Gajdos 2017-09-15 16:26:49 +00:00 committed by Git OBS Bridge
parent 0bbd9ae4f3
commit 09a466b1ac

View File

@ -3,9 +3,10 @@ Wed Sep 13 10:25:35 UTC 2017 - pgajdos@suse.com
- updated to 0.18.4: - updated to 0.18.4:
* Fix for possible heap overrun in Canon makernotes parser * Fix for possible heap overrun in Canon makernotes parser
(CVE-2017-14348)
* Fix for CVE-2017-13735 * Fix for CVE-2017-13735
* CVE-2017-14265: Additional check for X-Trans CFA pattern data * CVE-2017-14265: Additional check for X-Trans CFA pattern data
- add libraw-CVE-2017-14348.patch [bsc#1058467] - add libraw-out-of-bounds-kodak.patch, upstream bug #101
- remove libraw-CVE-2017-6887,6886.patch and - remove libraw-CVE-2017-6887,6886.patch and
libraw-CVE-2017-6890,6899.patch: libraw-CVE-2017-6890,6899.patch:
no need to patch dcraw.c, it is not used no need to patch dcraw.c, it is not used