Changelog for
djvulibre-doc-3.5.28-68.14.noarch.rpm :
* Thu Feb 22 2024 Michael Vetter
- Use %autosetup macro. Allows to eliminate the usage of deprecated %patchN.
* Tue Aug 29 2023 pgajdosAATTsuse.com- security update- added patches fix CVE-2021-46310 [bsc#1214670], divide by zero in IW44Image.cpp + djvulibre-CVE-2021-46310.patch fix CVE-2021-46312 [bsc#1214672], divide by zero in IW44EncodeCodec.cpp + djvulibre-CVE-2021-46312.patch
* Wed May 04 2022 Marcus Meissner - switch to use https source url
* Mon May 24 2021 pgajdosAATTsuse.com- security update- added patches fix CVE-2021-3500 [bsc#1186253], Stack overflow in function DJVU:DjVuDocument:get_djvu_file() via crafted djvu file + djvulibre-CVE-2021-3500.patch
* Wed May 12 2021 pgajdosAATTsuse.com- security update- added patches fix CVE-2021-32490 [bsc#1185895], Out of bounds write in function DJVU:filter_bv() via crafted djvu file + djvulibre-CVE-2021-32490.patch fix CVE-2021-32491 [bsc#1185900], Integer overflow in function render() in tools/ddjvu via crafted djvu file + djvulibre-CVE-2021-32491.patch fix CVE-2021-32492 [bsc#1185904], Out of bounds read in function DJVU:DataPool:has_data() via crafted djvu file + djvulibre-CVE-2021-32492.patch fix CVE-2021-32493 [bsc#1185905], Heap buffer overflow in function DJVU:GBitmap:decode() via crafted djvu file + djvulibre-CVE-2021-32493.patch
* Mon Dec 21 2020 Atri Bhattacharya - Update to version 3.5.28
* ddjvu: tiff generation improvements
* djvumake: security checks on INCL chunks
* all: updated for modern compilers
* bugs: fixed several crashes on invalid inputs
* miniexp: fixed escape printout and macrochars
* djvudigital: can use poppler to find text
* csepdjvu: handle T comments for page titles
* bytestream: fixed 2GB limit
* gexception, gthread: cleanup obsolete code- Drop patches incorporated or otherwise fixed upstream:
* djvulibre-invalid-tiff.patch
* djvulibre-CVE-2019-15144.patch
* djvulibre-CVE-2019-15145.patch
* djvulibre-CVE-2019-18804.patch
* djvulibre-CVE-2019-15143.patch
* djvulibre-always-assume-that-cpuid-works-on-x86_64.patch
* djvulibre-CVE-2019-15142.patch
* reproducible.patch- Only run post(un) scriptlets for desktop database update for openSUSE < 1550, these are void otherwise.- Regenerate configure script as it is no longer supplied with tarball; add BuildRequires: libtool.- Adapt file list for mime file no longer being installed (this is intentional from upstream); accordingly drop shared-mime-info BuildRequires and post(un) scripts.- fixes CVE-2021-3630 [bsc#1187869]
* Fri Nov 08 2019 pgajdosAATTsuse.com- security update- added patches CVE-2019-18804 [bsc#1156188] + djvulibre-CVE-2019-18804.patch
* Fri Oct 18 2019 pgajdosAATTsuse.com- do not segfault when mmx enabled [bsc#1154401]- added patches https://sourceforge.net/p/djvu/bugs/293/ + djvulibre-always-assume-that-cpuid-works-on-x86_64.patch
* Tue Sep 03 2019 Jan Engelhardt - Trim conjecture, bias, and metadata repetitions from description.- Trim descriptions in subpackages for length. (Main package keeps the bigger one.)- Use some more macros and limit fdupes to the /usr volume.
* Mon Sep 02 2019 pgajdosAATTsuse.com- security update- added patches CVE-2019-15142 [bsc#1146702] + djvulibre-CVE-2019-15142.patch CVE-2019-15143 [bsc#1146569] + djvulibre-CVE-2019-15143.patch CVE-2019-15144 [bsc#1146571] + djvulibre-CVE-2019-15144.patch CVE-2019-15145 [bsc#1146572] + djvulibre-CVE-2019-15145.patch do not segfault when libtiff encounters corrupted TIFF (upstream issue #295) + djvulibre-invalid-tiff.patch