From b2a83fcec9620710dcd13cdad1b65470bdcda781 Mon Sep 17 00:00:00 2001 From: Rex Dieter Date: Thu, 28 Aug 2014 07:50:19 -0500 Subject: [PATCH] go back to original L%02d format variant --- GraphicsMagick-1.3.20-CVE-2014-1947.patch | 2 +- GraphicsMagick.spec | 5 ++++- 2 files changed, 5 insertions(+), 2 deletions(-) diff --git a/GraphicsMagick-1.3.20-CVE-2014-1947.patch b/GraphicsMagick-1.3.20-CVE-2014-1947.patch index 8484b31..da4e021 100644 --- a/GraphicsMagick-1.3.20-CVE-2014-1947.patch +++ b/GraphicsMagick-1.3.20-CVE-2014-1947.patch @@ -18,7 +18,7 @@ diff -up GraphicsMagick-1.3.20/coders/psd.c.CVE-2014-1947 GraphicsMagick-1.3.20/ - (void) sprintf((char *) layer_name, "L%02d", layer_count++ ); - WritePascalString( image, (char*)layer_name, 4 ); + char layer_name[MaxTextExtent]; -+ (void) sprintf(layer_name, "L%06ld", layer_count++ ); ++ (void) sprintf(layer_name, "L%02d", layer_count++ ); + WritePascalString( image, layer_name, 4 ); } tmp_image = tmp_image->next; diff --git a/GraphicsMagick.spec b/GraphicsMagick.spec index 15a8cce..450b4ea 100644 --- a/GraphicsMagick.spec +++ b/GraphicsMagick.spec @@ -33,7 +33,7 @@ Summary: An ImageMagick fork, offering faster image generation and better quality Name: GraphicsMagick Version: 1.3.20 -Release: 2%{?dist} +Release: 3%{?dist} License: MIT Group: Applications/Multimedia @@ -313,6 +313,9 @@ rm -rf %{buildroot} %changelog +* Thu Aug 28 2014 Rex Dieter 1.3.20-3 +- go back to original L%02d format variant + * Mon Aug 25 2014 Rex Dieter 1.3.20-2 - better fix for CVE-2014-1947 (#1064098,#1083082)