Subject: CVS commit: pkgsrc/graphics/exiv2
From: Thomas Klausner
Date: 2024-02-19 13:38:31
Message id: 20240219123831.53B34F9F4@cvs.NetBSD.org

Log Message:
exiv2: update to 0.28.2.

Changes from version 0.28.1 to 0.28.2
-------------------------------------

Release Notes:

* https://github.com/Exiv2/exiv2/issues/2914
* https://github.com/Exiv2/exiv2/milestone/13?closed=1

This release also fixes two low-severity security issues in quicktimevideo.cpp:

* \ 
[CVE-2024-24826](https://github.com/Exiv2/exiv2/security/advisories/GHSA-g9xm-7538-mq8w): \ 
out-of-bounds read in QuickTimeVideo::NikonTagsDecoder.
* \ 
[CVE-2024-25112](https://github.com/Exiv2/exiv2/security/advisories/GHSA-crmj-qh74-2r36): \ 
denial of service due to unbounded recursion in \ 
QuickTimeVideo::multipleEntriesDecoder.

These vulnerabilities are in a new feature (quicktime video) that was added in \ 
version 0.28.0, so earlier versions of Exiv2 are not affected.

Files:
RevisionActionfile
1.64modifypkgsrc/graphics/exiv2/Makefile
1.27modifypkgsrc/graphics/exiv2/PLIST
1.51modifypkgsrc/graphics/exiv2/distinfo