Compare commits

...
Sign in to create a new pull request.

2 commits

Author SHA1 Message Date
Gwyn Ciesla
f211fd85a7 Matio rebuild. 2021-04-19 09:40:38 -05:00
Benjamin Gilbert
702fa034c3 Fix CVE-2020-20739 2020-11-29 22:44:27 -05:00
2 changed files with 33 additions and 1 deletions

View file

@ -0,0 +1,24 @@
commit 2ab5aa7bf515135c2b02d42e9a72e4c98e17031a
Author: John Cupitt <jcupitt@gmail.com>
Date: Tue Sep 3 13:17:18 2019 +0100
fix a used-before-set error in im_vips2dz
we were reading an uninited string in a vips7 compatibility wrapper, thanks
yifengchen-cc
see https://github.com/libvips/libvips/issues/1419
diff --git a/libvips/deprecated/im_vips2dz.c b/libvips/deprecated/im_vips2dz.c
index 6dbde78c..aafe8f99 100644
--- a/libvips/deprecated/im_vips2dz.c
+++ b/libvips/deprecated/im_vips2dz.c
@@ -75,6 +75,8 @@ im_vips2dz( IMAGE *in, const char *filename )
*p = '\0';
im_strncpy( mode, p + 1, FILENAME_MAX );
}
+ else
+ strcpy( mode, "" );
strcpy( buf, mode );
p = &buf[0];

View file

@ -4,12 +4,13 @@
Name: vips
Version: %{vips_version}
Release: 4%{?dist}
Release: 6%{?dist}
Summary: C/C++ library for processing large images
License: LGPLv2+
URL: https://libvips.github.io/libvips/
Source0: https://github.com/libvips/libvips/releases/download/v%{version}/%{name}-%{version}.tar.gz
Patch0: vips-8.8-CVE-2020-20739.patch
BuildRequires: pkgconfig(glib-2.0)
BuildRequires: pkgconfig(gobject-introspection-1.0)
@ -87,6 +88,7 @@ HTML and PDF formats.
%prep
%setup -q
%patch0 -p1
# Avoid setting RPATH to /usr/lib64 on 64-bit builds
# The DIE_RPATH_DIE trick breaks the build wrt gobject-introspection
@ -143,6 +145,12 @@ rm -rf ${RPM_BUILD_ROOT}%{_datadir}/doc/vips
%changelog
* Mon Apr 19 2021 Gwyn Ciesla <gwync@protonmail.com> - 8.8.4-6
- matio rebuild
* Sun Nov 29 2020 Benjamin Gilbert <bgilbert@backtick.net> - 8.8.4-5
- Fix CVE-2020-20739
* Fri Jan 31 2020 Fedora Release Engineering <releng@fedoraproject.org> - 8.8.4-4
- Rebuilt for https://fedoraproject.org/wiki/Fedora_32_Mass_Rebuild