Browse code

BUG 2081109 [CVE-2018-6942] package : freetype2 branch :2.0

This change includes the patch added to the spec file.. missed that change in last commit 07627f1422bf346b937654d1389299d3e996d263.

Change-Id: Icb6703fca6116a767a3b77dade2764fac19cc54b
Reviewed-on: http://photon-jenkins.eng.vmware.com:8082/5254
Tested-by: gerrit-photon <photon-checkins@vmware.com>
Reviewed-by: Sharath George

Tapas Kundu authored on 2018/06/13 02:59:06
Showing 2 changed files
... ...
@@ -1,21 +1,3 @@
1
-diff --git a/ChangeLog b/ChangeLog
2
-index 15ef4ae..fff4a41 100644
3
-+++ b/ChangeLog
4
-@@ -1,5 +1,13 @@
5
- 2018-01-27  Werner Lemberg  <wl@gnu.org>
6
- 
7
-+	* src/truetype/ttinterp.c (Ins_GETVARIATION): Avoid NULL reference.
8
-+
9
-+	Reported as
10
-+
11
-+	  https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=5736
12
-+
13
-+2018-01-27  Werner Lemberg  <wl@gnu.org>
14
-+
15
- 	* src/truetype/ttgxvar.c (tt_set_mm_blend): Minor.
16
- 
17
- 2018-01-27  Werner Lemberg  <wl@gnu.org>
18 1
 diff --git a/src/truetype/ttinterp.c b/src/truetype/ttinterp.c
19 2
 index d855aaa..551f14a 100644
20 3
 --- a/src/truetype/ttinterp.c
... ...
@@ -1,7 +1,7 @@
1 1
 Summary:	software font engine.
2 2
 Name:		freetype2
3 3
 Version:	2.7.1
4
-Release:	4%{?dist}
4
+Release:	5%{?dist}
5 5
 License:	BSD/GPL
6 6
 URL:		http://www.freetype.org/
7 7
 Group:		System Environment/Libraries
... ...
@@ -30,6 +30,7 @@ It contains the libraries and header files to create applications
30 30
 %patch0 -p1
31 31
 %patch1 -p1
32 32
 %patch2 -p1
33
+%patch3 -p1
33 34
 
34 35
 %build
35 36
 ./configure \
... ...
@@ -64,6 +65,8 @@ make -k check |& tee %{_specdir}/%{name}-check-log || %{nocheck}
64 64
 %{_libdir}/pkgconfig/*.pc
65 65
 
66 66
 %changelog
67
+*       Tue Jun 12 2018 Tapas Kundu <tkundu@vmware.com> 2.7.1-5
68
+-       Added the patch macro for CVE-2018-6942
67 69
 *       Thu Jun 07 2018 Tapas Kundu <tkundu@vmware.com> 2.7.1-4
68 70
 -       CVE-2018-6942
69 71
 *       Mon May 15 2017 Priyesh Padmavilasom <ppadmavilasom@vmware.com> 2.7.1-3