Subject: CVS commit: pkgsrc/graphics/libexif
From: Lubomir Sedlacik
Date: 2005-05-13 13:58:00
Message id: 20050513115800.0CA342DA27@cvs.netbsd.org

Log Message:
Security fix:

"Matthias Clasen has reported a vulnerability in libexif, which can be
exploited by malicious people to cause a DoS (Denial of Service).

The vulnerability is caused due to an infinite recursion in the
"exif_data_load_data_content()" function and can be exploited to
cause a stack overflow when parsing a specially crafted image.

Successful exploitation may crash an application linked against the
vulnerable library."

Bump PKGREVISION.  Patch from:
http://sourceforge.net/tracker/index.php?func=detail&aid=1196787&group_id=12272&atid=112272

Files:
RevisionActionfile
1.25modifypkgsrc/graphics/libexif/Makefile
1.7modifypkgsrc/graphics/libexif/buildlink3.mk
1.15modifypkgsrc/graphics/libexif/distinfo
1.1addpkgsrc/graphics/libexif/patches/patch-ac