GIT update to branch: master, updated. 6.1-GIT-79-gc6cac8d
[email protected] Tue, 18 Sep 2018 15:45:12 -0400
| Newsgroups | gmane.comp.telephony.fax.hylafax.devel |
|---|---|
| Message-ID | <[email protected]> |
This is an automated email from the git hooks/post-receive script. It was
generated because a ref change was pushed to the repository containing
the project "HylaFAX".
The branch, master has been updated
via c6cac8d8cd0dbe313689ba77023e12bc5b3027be (commit)
via dfc8a6ffe5a6031c6df716186681f92dac0d07cb (commit)
from 52228cb481ffdff6e97461fa151533f54a52163c (commit)
Those revisions listed above that are new to this repository have
not appeared on any other notification email; so we list those
revisions in full, below.
- Log -----------------------------------------------------------------
commit c6cac8d8cd0dbe313689ba77023e12bc5b3027be
Author: Patrice Fournier <[email protected]>
Date: Mon Sep 17 23:00:53 2018 -0400
Address CVE-2018-17141 and fixes a few vulnerabilities in code supporting JPEG
These changes are adapted from Lee's fix for this vulnerability.
Luis Merino, Markus Vervier, and Eric Sesterhenn of X41 D-SEC GmbH
(Security Advisory: X41-2018-008) discovered an uninitialized pointer write
and also an out-of-bounds write in FaxModem::writeECMData() that could lead
to remote code execution with a specially-crafted fax sender.
These changes fix the coding errors and deliberately prevent malicious and
malfunctioning senders from inadvertently or deliberately setting JPEG and
MH/MR/MMR/JBIG formats in the same DCS signal.
commit dfc8a6ffe5a6031c6df716186681f92dac0d07cb
Author: Patrice Fournier <[email protected]>
Date: Mon Oct 9 16:06:36 2017 -0400
Fix GCC-7 compiler error
-----------------------------------------------------------------------
Summary of changes:
faxd/Class2.c++ | 9 +++++++++
faxd/CopyQuality.c++ | 35 +++++++++++++++++++++++------------
libhylafax/Class2Params.c++ | 9 +++++++++
libhylafax/FaxRecvInfo.c++ | 2 +-
4 files changed, 42 insertions(+), 13 deletions(-)
hooks/post-receive
--
HylaFAX
____________________ HylaFAX(tm) Developers Mailing List ____________________
To subscribe/unsubscribe, click http://lists.hylafax.org/cgi-bin/lsg2.cgi
On UNIX: mail -s unsubscribe [email protected] < /dev/null