Changelog
djvulibre (3.5.28-2) unstable; urgency=high
* bump policy version
* Include Fedora 3.5.27 patches, foward ported, taken from djvulibre.spec in
https://src.fedoraproject.org/rpms/djvulibre.git
- Patch0: djvulibre-3.5.22-cdefs.patch (forward ported)
- #Patch1: djvulibre-3.5.25.3-cflags.patch (disabled in Fedora)
- Patch2: djvulibre-3.5.27-buffer-overflow.patch (UPSTREAMED)
- Patch3: djvulibre-3.5.27-infinite-loop.patch (UPSTREAMED)
- Patch4: djvulibre-3.5.27-stack-overflow.patch (UPSTREAMED)
- Patch5: djvulibre-3.5.27-zero-bytes-check.patch (UPSTREAMED)
- Patch6: djvulibre-3.5.27-export-file.patch (forward ported)
- Patch7: djvulibre-3.5.27-null-dereference.patch (UPSTREAMED)
- Patch8: djvulibre-3.5.27-check-image-size.patch (forward ported)
- Patch9: djvulibre-3.5.27-integer-overflow.patch (forward ported)
- Patch10: djvulibre-3.5.27-check-input-pool.patch (forward ported)
- Patch11: djvulibre-3.5.27-djvuport-stack-overflow.patch (forward ported)
- Patch12: djvulibre-3.5.27-unsigned-short-overflow.patch (forward ported)
These address a number of crashes and security issues, including
CVE-2021-3500 (closes: #988215)
-- Barak A. Pearlmutter <email address hidden> Mon, 10 May 2021 18:56:59 +0100