diff --git a/CVE-2023-27781.patch b/CVE-2023-27781.patch deleted file mode 100644 index 793d3bf..0000000 --- a/CVE-2023-27781.patch +++ /dev/null @@ -1,12 +0,0 @@ -diff -Naur a/jpegoptim.c b/jpegoptim.c ---- a/jpegoptim.c 2023-03-27 15:19:15.047509310 +0800 -+++ b/jpegoptim.c 2023-03-27 15:20:14.408374405 +0800 -@@ -1028,7 +1028,7 @@ - fprintf(LOG_FH,csv ? "skipped\n" : "skipped.\n"); - if (stdout_mode) { - set_filemode_binary(stdout); -- if (fwrite(inbuffer,insize,1,stdout) != 1) -+ if (fwrite(inbuffer, inbufferused, 1, stdout) != 1) - fatal("%s, write failed to stdout",(stdin_mode?"stdin":argv[i])); - } - } diff --git a/jpegoptim-1.4.7.tar.gz b/jpegoptim-1.4.7.tar.gz deleted file mode 100644 index a55d25c..0000000 Binary files a/jpegoptim-1.4.7.tar.gz and /dev/null differ diff --git a/jpegoptim-1.5.5.tar.gz b/jpegoptim-1.5.5.tar.gz new file mode 100644 index 0000000..831fdf1 Binary files /dev/null and b/jpegoptim-1.5.5.tar.gz differ diff --git a/jpegoptim.spec b/jpegoptim.spec index f668108..a0ce35b 100644 --- a/jpegoptim.spec +++ b/jpegoptim.spec @@ -1,11 +1,10 @@ Name: jpegoptim -Version: 1.4.7 -Release: 2 +Version: 1.5.5 +Release: 1 Summary: Utility to optimize JPEG files License: GPLv2+ URL: http://www.kokkonen.net/tjko/projects.html -Source0: https://github.com/tjko/jpegoptim/archive/refs/tags/jpegoptim-1.4.7.tar.gz -Patch0: CVE-2023-27781.patch +Source0: https://github.com/tjko/jpegoptim/archive/v%{version}/%{name}-%{version}.tar.gz BuildRequires: coreutils gcc libjpeg-devel make %description @@ -32,6 +31,9 @@ install -Dpm 0644 jpegoptim.1 %{buildroot}/%{_mandir}/man1/jpegoptim.1 %{_mandir}/man1/*.1* %changelog +* Mon Apr 01 2024 yaoxin - 1.5.5-1 +- Upgrade to 1.5.5 for fix CVE-2022-32325 + * Mon Mar 27 2023 yaoxin - 1.4.7-2 - Fix CVE-2023-27781