Subject: CVS commit: [pkgsrc-2009Q2] pkgsrc/graphics/openexr
From: Matthias Scheler
Date: 2009-08-29 00:15:55
Message id: 20090828221555.D271D175D0@cvs.netbsd.org

Log Message:
Pullup ticket #2878 - requested by hasso
openexr: security patch

Revisions pulled up:
- graphics/openexr/Makefile			1.22
- graphics/openexr/distinfo			1.13 via patch
- graphics/openexr/patches/patch-ae		1.1
- graphics/openexr/patches/patch-af		1.1
- graphics/openexr/patches/patch-ag		1.1
- graphics/openexr/patches/patch-ah		1.1
- graphics/openexr/patches/patch-ai		1.1
---
Module Name:    pkgsrc
Committed By:   hasso
Date:           Fri Aug 28 21:33:08 UTC 2009

Modified Files:
        pkgsrc/graphics/openexr: Makefile distinfo
Added Files:
        pkgsrc/graphics/openexr/patches: patch-ae patch-af patch-ag
patch-ah
            patch-ai

Log Message:
Add patches for CVE-2009-1720 (multiple integer overflows in OpenEXR) and
CVE-2009-1721 (denial of service (application crash) or possibly execute
arbitrary code in the Imf::hufUncompress function). Bump PKGREVISION.

Files:
RevisionActionfile
1.21.4.1modifypkgsrc/graphics/openexr/Makefile
1.10.16.1modifypkgsrc/graphics/openexr/distinfo
1.1.2.2addpkgsrc/graphics/openexr/patches/patch-ae
1.1.2.2addpkgsrc/graphics/openexr/patches/patch-af
1.1.2.2addpkgsrc/graphics/openexr/patches/patch-ag
1.1.2.2addpkgsrc/graphics/openexr/patches/patch-ah
1.1.2.2addpkgsrc/graphics/openexr/patches/patch-ai