Subject: CVS commit: [pkgsrc-2021Q3] pkgsrc/graphics/libexif
From: Benny Siegert
Date: 2021-10-03 19:55:56
Message id: 20211003175556.834EAFA97@cvs.NetBSD.org

Log Message:
Pullup ticket #6502 - requested by wiz
graphics/libexif: security fix

Revisions pulled up:
- graphics/libexif/Makefile                                     1.49
- graphics/libexif/distinfo                                     1.33

---
   Module Name:	pkgsrc
   Committed By:	wiz
   Date:		Wed Sep 29 08:42:57 UTC 2021

   Modified Files:
   	pkgsrc/graphics/libexif: Makefile distinfo

   Log Message:
   libexif: update to 0.6.23.

   libexif-0.6.23 (2021-09-12):

     * Translation updates: es, pl, uk, fr
     * EXIF_TAG_SENSITIVITY_TYPE decoder added, added some more Exif 2.3 tags:
       - EXIF_TAG_STANDARD_OUTPUT_SENSITIVITY
       - EXIF_TAG_RECOMMENDED_EXPOSURE_INDEX
       - EXIF_TAG_ISO_SPEED
       - EXIF_TAG_ISO_SPEEDLatitudeYYY
       - EXIF_TAG_ISO_SPEEDLatitudeZZZ
       - EXIF_TAG_OFFSET_TIME
       - EXIF_TAG_OFFSET_TIME_ORIGINAL
       - EXIF_TAG_OFFSET_TIME_DIGITIZED
       - EXIF_TAG_IMAGE_DEPTH
     * be more relaxed to out of order JPG / EXIF dataheaders in files generated \ 
by some tools
     * default GPS IFD table added
     * Decode more Nikon Makernote tag names
     * Added Apple iOS Makernote
     * Security fixes:
       * CVE-2020-0198: unsigned integer overflow in exif_data_load_data_content
       * CVE-2020-0452: compiler optimization could remove an a
         bufferoverflow check, making a buffer overflow possible with some
         EXIF tags
       * some more denial of service (compute time or stack exhaustion) \ 
counter-measures
         added that avoid minutes of decoding time with malformed files found
         by OSS-Fuzz

Files:
RevisionActionfile
1.48.12.1modifypkgsrc/graphics/libexif/Makefile
1.32.12.1modifypkgsrc/graphics/libexif/distinfo