diff options
author | alperak <alperyasinak1@gmail.com> | 2024-07-12 11:06:41 +0300 |
---|---|---|
committer | Armin Kuster <akuster808@gmail.com> | 2024-08-10 11:37:34 -0400 |
commit | 6434e4328bf04dc3f06c2ab238ed08572eba6d3b (patch) | |
tree | 056eb221a10ef9c33161b4d25bf31352888eb9ac /meta-python/recipes-devtools/python/python3-pydantic-core/0001-Bumps-pyo3-https-github.com-pyo3-pyo3-from-0.20.2-to.patch | |
parent | 496a24bf06614b1ccd6a816fbd3bc3333c9c5baf (diff) | |
download | meta-openembedded-6434e4328bf04dc3f06c2ab238ed08572eba6d3b.tar.gz |
exiv2: Upgrade 0.28.2 to 0.28.3 for CVE fix
Release Notes:
* https://github.com/Exiv2/exiv2/issues/3008
* https://github.com/Exiv2/exiv2/milestone/14?closed=1
This release also fixes a low-severity security issue in asfvideo.cpp:
* [CVE-2024-39695](https://github.com/Exiv2/exiv2/security/advisories/GHSA-38rv-8x93-pvrh): out-of-bounds read in AsfVideo::streamProperties.
This vulnerability is in a new feature (ASF video) that was added in version 0.28.0, so earlier versions of Exiv2 are not affected.
Signed-off-by: alperak <alperyasinak1@gmail.com>
Signed-off-by: Khem Raj <raj.khem@gmail.com>
(cherry picked from commit 9f4361418d58941d058fb94a3671b9d0904b6300)
Signed-off-by: Armin Kuster <akuster808@gmail.com>
Diffstat (limited to 'meta-python/recipes-devtools/python/python3-pydantic-core/0001-Bumps-pyo3-https-github.com-pyo3-pyo3-from-0.20.2-to.patch')
0 files changed, 0 insertions, 0 deletions