Package: librsvg / 2.36.1-2+deb7u1
Metadata
| Package | Version | Patches format |
|---|---|---|
| librsvg | 2.36.1-2+deb7u1 | 3.0 (quilt) |
Patch series
view the series file| Patch | File delta | Description |
|---|---|---|
| 01_CVE 2013 1881_policy.patch | (download) |
rsvg-base.c |
89 81 + 8 - 0 ! |
io: implement strict load policy Allow any file to load from data:, and any resource to load from other resources. Only allow file: to load other file: URIs from below the path of the base file. Any other loads are denied. Bug #691708. |
| 02_CVE 2013 1881_xmlentities.patch | (download) |
rsvg-base.c |
3 3 + 0 - 0 ! |
io: use xml_parse_nonet We don't want to load resources off the net. Bug #691708. |
| 10_rsvg gz.patch | (download) |
rsvg-gobject.c |
6 6 + 0 - 0 ! |
revert abi breakage Provide the rsvg_handle_new_gz function. Do not provide the C prototype to force applications using it to use rsvg_handle_new instead. |
| 20_rsvg_compat.patch | (download) |
rsvg-convert.c |
27 23 + 4 - 0 ! |
--- |
| 99_ltmain_as needed.patch | (download) |
ltmain.sh |
14 14 + 0 - 0 ! |
--- |
| CVE 2015 7557.patch | (download) |
rsvg-shapes.c |
14 13 + 1 - 0 ! |
bgo#738050 - handle the case where a list of coordinate pairs has an odd number of elements Lists of points come in coordinate pairs, but we didn't have any checking for that. It was possible to try to fetch the 'last' coordinate in a list, i.e. the y coordinate of an x,y pair, that was in fact missing, leading to an out-of-bounds array read. In that case, we now reuse the last-known y coordinate. Fixes https://bugzilla.gnome.org/show_bug.cgi?id=738050 Signed-off-by: Federico Mena Quintero <federico@gnome.org> |
