mirror of
https://gitlab.com/buildroot.org/buildroot.git
synced 2026-08-02 05:33:57 -09:00
Fixes the following security issues:
- CVE-2025-43961: metadata/tiff.cpp has an out-of-bounds read in the
Fujifilm 0xf00c tag parser.
For more information, see:
- https://nvd.nist.gov/vuln/detail/CVE-2025-43961
- 66fe663e02
- CVE-2025-43962: phase_one_correct in decoders/load_mfbacks.cpp has
out-of-bounds reads for tag 0x412 processing
For more information, see:
- https://nvd.nist.gov/vuln/detail/CVE-2025-43962
- 66fe663e02
- CVE-2025-43963: phase_one_correct in decoders/load_mfbacks.cpp allows
out-of-buffer access
For more information, see:
- https://nvd.nist.gov/vuln/detail/CVE-2025-43963
- be26e7639e
- CVE-2025-43964: tag 0x412 processing in phase_one_correct in
decoders/load_mfbacks.cpp does not enforce minimum w0 and w1 values.
For more information, see:
- https://nvd.nist.gov/vuln/detail/CVE-2025-43964
- a50dc3f112
For more details on the version bump, see the release notes:
- https://github.com/LibRaw/LibRaw/releases/tag/0.21.4
- https://github.com/LibRaw/LibRaw/releases/tag/0.21.3
- https://github.com/LibRaw/LibRaw/compare/0.21.2...0.21.4
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
6 lines
374 B
Plaintext
6 lines
374 B
Plaintext
# Locally calculated
|
|
sha256 6be43f19397e43214ff56aab056bf3ff4925ca14012ce5a1538a172406a09e63 LibRaw-0.21.4.tar.gz
|
|
sha256 eea173a556abac0370461e57e12aab266894ea6be3874c2be05fd87871f75449 LICENSE.LGPL
|
|
sha256 0e3098d2d54a12434715f6679ea408d57da5e8d613c385c58ecc6fe5d30cc81f LICENSE.CDDL
|
|
sha256 7d6650cef6cf892abe95e55a6bda1e1c42f221fd411b807deb2fc0b805b868d4 README.md
|