<feed xmlns='http://www.w3.org/2005/Atom'>
<title>packages/libs/tiff/patches, branch master</title>
<subtitle>Mirror of packages feed</subtitle>
<id>https://git.openwrt.org/feed/packages/atom?h=master</id>
<link rel='self' href='https://git.openwrt.org/feed/packages/atom?h=master'/>
<link rel='alternate' type='text/html' href='https://git.openwrt.org/feed/packages/'/>
<updated>2023-05-16T18:15:29Z</updated>
<entry>
<title>tiff: update to 4.5.0</title>
<updated>2023-05-16T18:15:29Z</updated>
<author>
<name>Nick Hainke</name>
</author>
<published>2023-04-26T07:09:37Z</published>
<link rel='alternate' type='text/html' href='https://git.openwrt.org/feed/packages/commit/?id=342a2d4295915db484c745274d534e8e68741982'/>
<id>urn:sha1:342a2d4295915db484c745274d534e8e68741982</id>
<content type='text'>
Release Notes:
http://www.simplesystems.org/libtiff/releases/v4.5.0.html

Remove upstreamed:
- 010-CVE-2022-2519.patch
- 020-CVE-2022-2520.patch

Fixes: CVE-2022-2056, CVE-2022-2057, CVE-2022-2058, CVE-2022-3570,
       CVE-2022-3598, CVE-2022-3627, CVE-2022-3597, CVE-2022-3626,
       CVE-2022-3599, CVE-2022-34526
Signed-off-by: Nick Hainke &lt;vincent@systemli.org&gt;
</content>
</entry>
<entry>
<title>tiff: don't use AUTORELEASE</title>
<updated>2023-01-14T05:04:14Z</updated>
<author>
<name>Rosen Penev</name>
</author>
<published>2022-11-08T01:17:10Z</published>
<link rel='alternate' type='text/html' href='https://git.openwrt.org/feed/packages/commit/?id=65c9f9524d70cee1f151ddab90ce9b133c3afdd0'/>
<id>urn:sha1:65c9f9524d70cee1f151ddab90ce9b133c3afdd0</id>
<content type='text'>
Seems upstream wants to get rid of it.

Backport upstream patches fixing several CVEs.

Signed-off-by: Rosen Penev &lt;rosenp@gmail.com&gt;
</content>
</entry>
<entry>
<title>tiff: update to 4.2.3</title>
<updated>2021-06-02T06:10:37Z</updated>
<author>
<name>Rosen Penev</name>
</author>
<published>2021-06-02T01:21:22Z</published>
<link rel='alternate' type='text/html' href='https://git.openwrt.org/feed/packages/commit/?id=2072dc396f99a6fedff0c0e3f72c5b64093675d4'/>
<id>urn:sha1:2072dc396f99a6fedff0c0e3f72c5b64093675d4</id>
<content type='text'>
Remove automake patch as it's not used.

Remove ftell patch as it seems to not be needed anymore.

Signed-off-by: Rosen Penev &lt;rosenp@gmail.com&gt;
</content>
</entry>
<entry>
<title>tiff: update version to 4.1.0</title>
<updated>2019-11-11T20:49:06Z</updated>
<author>
<name>Jiri Slachta</name>
</author>
<published>2019-11-11T20:49:06Z</published>
<link rel='alternate' type='text/html' href='https://git.openwrt.org/feed/packages/commit/?id=a1a5799f075f4941edcaaf63bf754b0cec55b88f'/>
<id>urn:sha1:a1a5799f075f4941edcaaf63bf754b0cec55b88f</id>
<content type='text'>
Signed-off-by: Jiri Slachta &lt;jiri@slachta.eu&gt;
</content>
</entry>
<entry>
<title>tiff: patch security issues</title>
<updated>2019-04-09T11:29:59Z</updated>
<author>
<name>Jan Pavlinec</name>
</author>
<published>2019-04-09T11:28:10Z</published>
<link rel='alternate' type='text/html' href='https://git.openwrt.org/feed/packages/commit/?id=bd26dea94a290112a9632317b219cdf579da8eb7'/>
<id>urn:sha1:bd26dea94a290112a9632317b219cdf579da8eb7</id>
<content type='text'>
Fixes
CVE-2019-7663
CVE-2019-6128

Signed-off-by: Jan Pavlinec &lt;jan.pavlinec@nic.cz&gt;
</content>
</entry>
<entry>
<title>tiff: Update to 4.0.10</title>
<updated>2018-11-14T17:36:55Z</updated>
<author>
<name>Rosen Penev</name>
</author>
<published>2018-11-14T17:36:55Z</published>
<link rel='alternate' type='text/html' href='https://git.openwrt.org/feed/packages/commit/?id=1c10f60c13daec98477c538694c7f56539f971b0'/>
<id>urn:sha1:1c10f60c13daec98477c538694c7f56539f971b0</id>
<content type='text'>
Fixes all CVEs as well as a few more.

Signed-off-by: Rosen Penev &lt;rosenp@gmail.com&gt;
</content>
</entry>
<entry>
<title>tiff: Fix CVE-2017-17095</title>
<updated>2018-08-27T04:23:50Z</updated>
<author>
<name>Rosen Penev</name>
</author>
<published>2018-08-27T04:23:50Z</published>
<link rel='alternate' type='text/html' href='https://git.openwrt.org/feed/packages/commit/?id=a430500ffbe1e74c299ea40607a04751d14170e3'/>
<id>urn:sha1:a430500ffbe1e74c299ea40607a04751d14170e3</id>
<content type='text'>
Fedora does not have a fix for this but Debian does. Took fix from there.

There are two more CVEs as reported by uscan but I can't seem to find
patches for those.

Signed-off-by: Rosen Penev &lt;rosenp@gmail.com&gt;
</content>
</entry>
<entry>
<title>tiff: Fix remaining CVEs</title>
<updated>2018-08-18T01:19:00Z</updated>
<author>
<name>Rosen Penev</name>
</author>
<published>2018-08-18T00:42:20Z</published>
<link rel='alternate' type='text/html' href='https://git.openwrt.org/feed/packages/commit/?id=29ffbead75e2203b9bd6f022dd8487209241016b'/>
<id>urn:sha1:29ffbead75e2203b9bd6f022dd8487209241016b</id>
<content type='text'>
Taken from Fedora. Reordered them so as to apply properly.

Added a CPE ID.

Added parallel build for faster compilation.

Signed-off-by: Rosen Penev &lt;rosenp@gmail.com&gt;
</content>
</entry>
<entry>
<title>tiff: version bump</title>
<updated>2018-01-30T14:00:02Z</updated>
<author>
<name>Sebastian Kemper</name>
</author>
<published>2018-01-30T14:00:00Z</published>
<link rel='alternate' type='text/html' href='https://git.openwrt.org/feed/packages/commit/?id=f48dade356f0918bc70d704b34728a378c88eed0'/>
<id>urn:sha1:f48dade356f0918bc70d704b34728a378c88eed0</id>
<content type='text'>
- bump version to 4.0.9
- add patches copied from Debian for CVE-2017-18013 and CVE-2017-9935

Signed-off-by: Sebastian Kemper &lt;sebastian_ml@gmx.net&gt;
</content>
</entry>
<entry>
<title>tiff: update package to version 4.0.8</title>
<updated>2017-08-18T09:27:50Z</updated>
<author>
<name>Jiri Slachta</name>
</author>
<published>2017-08-18T09:27:50Z</published>
<link rel='alternate' type='text/html' href='https://git.openwrt.org/feed/packages/commit/?id=272f907135b03b8de822584d798bd109067038fb'/>
<id>urn:sha1:272f907135b03b8de822584d798bd109067038fb</id>
<content type='text'>
Signed-off-by: Jiri Slachta &lt;jiri@slachta.eu&gt;
</content>
</entry>
</feed>
