exiv2: update to 0.28.2.

Changes from version 0.28.1 to 0.28.2
-------------------------------------

Release Notes:

* https://github.com/Exiv2/exiv2/issues/2914
* https://github.com/Exiv2/exiv2/milestone/13?closed=1

This release also fixes two low-severity security issues in quicktimevideo.cpp:

* [CVE-2024-24826](https://github.com/Exiv2/exiv2/security/advisories/GHSA-g9xm-7538-mq8w): out-of-bounds read in QuickTimeVideo::NikonTagsDecoder.
* [CVE-2024-25112](https://github.com/Exiv2/exiv2/security/advisories/GHSA-crmj-qh74-2r36): denial of service due to unbounded recursion in QuickTimeVideo::multipleEntriesDecoder.

These vulnerabilities are in a new feature (quicktime video) that was added in version 0.28.0, so earlier versions of Exiv2 are not affected.
This commit is contained in:
wiz 2024-02-19 12:38:31 +00:00
parent e9dec97da1
commit 09b3bc1eaf
3 changed files with 11 additions and 11 deletions

View File

@ -1,6 +1,6 @@
# $NetBSD: Makefile,v 1.63 2023/11/06 13:18:08 wiz Exp $
# $NetBSD: Makefile,v 1.64 2024/02/19 12:38:31 wiz Exp $
DISTNAME= exiv2-0.28.1
DISTNAME= exiv2-0.28.2
CATEGORIES= graphics
MASTER_SITES= ${MASTER_SITE_GITHUB:=Exiv2/}
GITHUB_TAG= v${PKGVERSION_NOREV}

View File

@ -1,4 +1,4 @@
@comment $NetBSD: PLIST,v 1.26 2023/11/06 13:18:08 wiz Exp $
@comment $NetBSD: PLIST,v 1.27 2024/02/19 12:38:31 wiz Exp $
bin/exiv2
include/exiv2/asfvideo.hpp
include/exiv2/basicio.hpp
@ -48,12 +48,12 @@ include/exiv2/version.hpp
include/exiv2/webpimage.hpp
include/exiv2/xmp_exiv2.hpp
include/exiv2/xmpsidecar.hpp
lib/cmake/exiv2/exiv2Config.cmake
lib/cmake/exiv2/exiv2ConfigVersion.cmake
lib/cmake/exiv2/exiv2Export-release.cmake
lib/cmake/exiv2/exiv2Export.cmake
lib/libexiv2.so
lib/libexiv2.so.${PKGVERSION}
lib/libexiv2.so.28
lib/pkgconfig/exiv2.pc
man/man1/exiv2.1
share/cmake/exiv2/exiv2Config.cmake
share/cmake/exiv2/exiv2ConfigVersion.cmake
share/cmake/exiv2/exiv2Export-release.cmake
share/cmake/exiv2/exiv2Export.cmake

View File

@ -1,7 +1,7 @@
$NetBSD: distinfo,v 1.50 2023/11/08 21:15:37 nros Exp $
$NetBSD: distinfo,v 1.51 2024/02/19 12:38:31 wiz Exp $
BLAKE2s (exiv2-0.28.1.tar.gz) = ba9927ce76ed8a1ec5818164c4beba7abc1989fa5684011d20429d4b7b76b22d
SHA512 (exiv2-0.28.1.tar.gz) = 7b872a3c0cbe343014b1ca4618cecaf6ee8d78dec7ef83accfce95cb8eadc6b52116977a41e1f1be5c6149a47bdd9457fadc08d73708aa2a6ab69795fd3de23b
Size (exiv2-0.28.1.tar.gz) = 45225200 bytes
BLAKE2s (exiv2-0.28.2.tar.gz) = 1e7ab716a3112d8b995e4358d7a06009d0a19bc9a8c9ad7abb456304c1e6d17a
SHA512 (exiv2-0.28.2.tar.gz) = 197cc607c0271b5731714713283756250031cef81ba7ed5d9c3e222b4c2397966cc2bbdbceaae706598329dde6f8a9729597d0ae4c36ac264c76546942e4e37b
Size (exiv2-0.28.2.tar.gz) = 45224206 bytes
SHA1 (patch-cmake_compilerFlags.cmake) = 9f56d637e5dc99d7377a8d57ca9be9aab5833a76
SHA1 (patch-src_futils.cpp) = 16f320338ea0071098a892e23c7056ead2e18d16