From 8cf47b9a0a19bcfb332943520fcf7dd1ca80b8d9 Mon Sep 17 00:00:00 2001 From: Rex Dieter Date: Aug 29 2010 17:33:48 +0000 Subject: Merge branch 'master' into f14 --- diff --git a/.gitignore b/.gitignore index 822dd80..182e749 100644 --- a/.gitignore +++ b/.gitignore @@ -1 +1 @@ -kdegraphics-4.5.0.tar.bz2 +/kdegraphics-4.5.1.tar.bz2 diff --git a/kdegraphics-okular-cve-2010-2575.patch b/kdegraphics-okular-cve-2010-2575.patch deleted file mode 100644 index ca0d498..0000000 --- a/kdegraphics-okular-cve-2010-2575.patch +++ /dev/null @@ -1,29 +0,0 @@ -diff -Nur kdegraphics-4.5.0/okular/generators/plucker/unpluck/image.cpp kdegraphics-4.5.0.me/okular/generators/plucker/unpluck/image.cpp ---- kdegraphics-4.5.0/okular/generators/plucker/unpluck/image.cpp 2008-02-21 10:27:47.000000000 +0100 -+++ kdegraphics-4.5.0.me/okular/generators/plucker/unpluck/image.cpp 2010-08-25 22:03:11.000000000 +0200 -@@ -289,8 +289,23 @@ - for (j = 0; j < bytes_per_row;) { - incount = *palm_ptr++; - inval = *palm_ptr++; -- memset (rowbuf + j, inval, incount); -- j += incount; -+ if (incount + j <= bytes_per_row * width) -+ { -+ memset (rowbuf + j, inval, incount); -+ j += incount; -+ } -+ else -+ { -+ free (rowbuf); -+ free (lastrow); -+ free (jpeg_row); -+ -+ jpeg_destroy_compress (&cinfo); -+ -+ fclose( outfile ); -+ -+ return false; -+ } - } - } - else if ((flags & PALM_IS_COMPRESSED_FLAG) diff --git a/kdegraphics.spec b/kdegraphics.spec index c23ae2f..0990fad 100644 --- a/kdegraphics.spec +++ b/kdegraphics.spec @@ -14,8 +14,8 @@ Summary: KDE Graphics Applications Epoch: 7 -Version: 4.5.0 -Release: 2%{?dist} +Version: 4.5.1 +Release: 1%{?dist} Name: kdegraphics #Obsoletes: kdegraphics4 < %{version}-%{release} @@ -28,8 +28,6 @@ Source0: ftp://ftp.kde.org/pub/kde/stable/%{version}/src/kdegraphics-%{ve BuildRoot: %{_tmppath}/%{name}-%{version}-%{release}-root-%(%{__id_u} -n) ## upstream patches -# CVE-2010-2575, Okular PDB Processing Memory Corruption Vulnerability -Patch100: kdegraphics-okular-cve-2010-2575.patch %if 0%{?fedora} BuildRequires: chmlib-devel @@ -115,7 +113,6 @@ Summary: A kioslave for displaying WinHelp files %prep %setup -q -n kdegraphics-%{version}%{?alphatag} -%patch100 -p1 -b .cve-2010-2575 %build mkdir -p %{_target_platform} @@ -264,6 +261,9 @@ fi %changelog +* Fri Aug 27 2010 Jaroslav Reznik - 4.5.1-1 +- 4.5.1 + * Wed Aug 25 2010 Than Ngo - 4.5.0-2 - Security fix, Okular PDB Processing Memory Corruption Vulnerability cve-2010-2575 diff --git a/sources b/sources index e856afc..9fbf649 100644 --- a/sources +++ b/sources @@ -1 +1 @@ -e8f623f95d902ff4e62574080bbd4061 kdegraphics-4.5.0.tar.bz2 +11c3da572a6205bf5d898e8958d4aadd kdegraphics-4.5.1.tar.bz2