Dan Fandrich | 12 Jul 2012 22:55
Favicon

libexif and exif 0.6.21 released

This release fixes a number of potentially serious security issues.

libexif-0.6.21 (2012-07-12):
  * New translations: en_AU, uk
  * Updated translations: cs, da, de, en_CA, nl, pl, sk, sv, vi
  * Added more supported lenses in Canon MakerNote
  * Added some defensive NULL pointer checks
  * Fixed a number of security and stability issues due to buffer overflows,
    bad pointer dereferences and division-by-zero including bug #3434540
    and bug #3434545 (CVE-2012-2812, CVE-2012-2813, CVE-2012-2814,
    CVE-2012-2836, CVE-2012-2837, CVE-2012-2840, CVE-2012-2841,
    CVE-2012-2845)

exif-0.6.21 (2012-07-12):
  * New translations: cs, eo, hr, sr, uk
  * Updated translations: da, de, fi, id, is, it, nl, pl, sk, sv, vi, zh_CN
  * Improved the man page
  * Prevent NULL pointer dereference on out of memory situation
  * Fixed bug that caused read past the end of a buffer (CVE-2012-2845)

Here are the SHA1 sums of the released files:

74652e3d04d0faf9ab856949d7463988f0394db8  exif-0.6.21.tar.bz2
d23139d26226b70c66d035bbc64482792c9f1101  exif-0.6.21.tar.gz
a52219b12dbc8d33fc096468591170fda71316c0  libexif-0.6.21.tar.bz2
4106f02eb5f075da4594769b04c87f59e9f3b931  libexif-0.6.21.tar.gz
e5990860e9ec5a6aedde0552507a583afa989ca2  libexif-0.6.21.zip

They are available for download at
https://sourceforge.net/projects/libexif/files/
(Continue reading)


Gmane