From a2c3c64484c084cd6de2fd8c6a1b6aa6098ecadc Mon Sep 17 00:00:00 2001 From: Paul Howarth Date: Sat, 18 Jul 2020 12:19:32 +0100 Subject: [PATCH] Update to 2.72 - New upstream release 2.72 - Fix for colorMatch with older unpatched libgd versions, which has an exploitable heap overflow (CVE-2019-6977) - Note: libgd in Fedora is already patched for CVE-2019-6977 --- perl-GD.spec | 10 ++++++++-- sources | 2 +- 2 files changed, 9 insertions(+), 3 deletions(-) diff --git a/perl-GD.spec b/perl-GD.spec index b1d3c56..5a66c86 100644 --- a/perl-GD.spec +++ b/perl-GD.spec @@ -1,6 +1,6 @@ Name: perl-GD -Version: 2.71 -Release: 5%{?dist} +Version: 2.72 +Release: 1%{?dist} Summary: Perl interface to the GD graphics library License: GPL+ or Artistic 2.0 URL: https://metacpan.org/release/GD @@ -94,6 +94,12 @@ make test TEST_VERBOSE=1 %{_mandir}/man3/GD::Simple.3* %changelog +* Sat Jul 18 2020 Paul Howarth - 2.72-1 +- Update to 2.72 + - Fix for colorMatch with older unpatched libgd versions, which has an + exploitable heap overflow (CVE-2019-6977) +- Note: libgd in Fedora is already patched for CVE-2019-6977 + * Tue Jun 23 2020 Jitka Plesnikova - 2.71-5 - Perl 5.32 rebuild diff --git a/sources b/sources index b5fe783..553b162 100644 --- a/sources +++ b/sources @@ -1 +1 @@ -SHA512 (GD-2.71.tar.gz) = 3a1555f07e6ab36a7218f24853f4168914be45e8c19ab0fe971ab044725dc0d7efeca75be2e4408406e69601f07e047fd3ea157acc9b9d339c9917a1c3e1f74d +SHA512 (GD-2.72.tar.gz) = 93a42c2385673ce8133102adc125da966f8a8abcebe4a0a9d87ae3e77a84870138db81f532e393eb1c5be4b12c71b737bd5b85ed84cf4b8580f08a5296189103