Overview

Request 1135525 accepted

- update to 0.21.2:
* New compile-defined limit LIBRAW_MAX_PROFILE_SIZE_MB:
limits allocation/read size for embedded color profile
Embedded color profile allocation/read size: limited by input
file size.
* Multiple fixes (mostly inspired by oss-fuzz) to improve
library stability and/or input checks.
* raw-identify: use fallback if PATH_MAX not available
* Disabled color conversion for Canon 16-bit thumbnails
* docs/changelog: explained the case when no thumbnail is found
in specific file
* swapXX renamed to libraw_swapXX to avoid name conflict
* better striped thumbnails handling
- drop libraw-CVE-2023-1729.patch (upstream)

* Olympus XZ-1: do not provide linear_max
* multiple camera support improvements
* quicktake_100_load_raw: check width/height limits
CVE-2017-14265: Additional check for X-Trans CFA pattern data
* Fix for possible heap overrun in Canon makernotes parser
Phase One flat field code called even for half-size output
- added missing parts of the fix for CVE-2017-6887
* phase_one_correct always returns value; handle P1 return codes
files and DNG converted by Adobe convertor).
analysis.
* Fujifilm F700/S20Pro second frame support
Olympus E-P5
- Support for updated Samsung NX200 firmware.
* Makefile.msvc: easy additional compiler flag editing.
* Fixed decoding of some Leaf Aptus II files

Loading...

Request History
Dirk Mueller's avatar

dirkmueller created request

- update to 0.21.2:
* New compile-defined limit LIBRAW_MAX_PROFILE_SIZE_MB:
limits allocation/read size for embedded color profile
Embedded color profile allocation/read size: limited by input
file size.
* Multiple fixes (mostly inspired by oss-fuzz) to improve
library stability and/or input checks.
* raw-identify: use fallback if PATH_MAX not available
* Disabled color conversion for Canon 16-bit thumbnails
* docs/changelog: explained the case when no thumbnail is found
in specific file
* swapXX renamed to libraw_swapXX to avoid name conflict
* better striped thumbnails handling
- drop libraw-CVE-2023-1729.patch (upstream)

* Olympus XZ-1: do not provide linear_max
* multiple camera support improvements
* quicktake_100_load_raw: check width/height limits
CVE-2017-14265: Additional check for X-Trans CFA pattern data
* Fix for possible heap overrun in Canon makernotes parser
Phase One flat field code called even for half-size output
- added missing parts of the fix for CVE-2017-6887
* phase_one_correct always returns value; handle P1 return codes
files and DNG converted by Adobe convertor).
analysis.
* Fujifilm F700/S20Pro second frame support
Olympus E-P5
- Support for updated Samsung NX200 firmware.
* Makefile.msvc: easy additional compiler flag editing.
* Fixed decoding of some Leaf Aptus II files


Dirk Stoecker's avatar

dstoecker accepted request

openSUSE Build Service is sponsored by