summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorMarkus Meier <maekke@gentoo.org>2008-04-27 12:19:53 +0000
committerMarkus Meier <maekke@gentoo.org>2008-04-27 12:19:53 +0000
commit41d040e13db3aa5584204a7170e7122054f062f1 (patch)
tree78cdf3cad13de517fe5b0c749312ae84c15b00c1 /media-gfx/blender/files
parentadd new blender revision to the mask (diff)
downloadhistorical-41d040e13db3aa5584204a7170e7122054f062f1.tar.gz
historical-41d040e13db3aa5584204a7170e7122054f062f1.tar.bz2
historical-41d040e13db3aa5584204a7170e7122054f062f1.zip
revision bumps for security bug #219008
Package-Manager: portage-2.1.5_rc6
Diffstat (limited to 'media-gfx/blender/files')
-rw-r--r--media-gfx/blender/files/blender-2.45-cve-2008-1102.patch13
1 files changed, 13 insertions, 0 deletions
diff --git a/media-gfx/blender/files/blender-2.45-cve-2008-1102.patch b/media-gfx/blender/files/blender-2.45-cve-2008-1102.patch
new file mode 100644
index 000000000000..43015b3c052b
--- /dev/null
+++ b/media-gfx/blender/files/blender-2.45-cve-2008-1102.patch
@@ -0,0 +1,13 @@
+diff -up blender-2.45/source/blender/imbuf/intern/radiance_hdr.c.csv blender-2.45/source/blender/imbuf/intern/radiance_hdr.c
+--- blender-2.45/source/blender/imbuf/intern/radiance_hdr.c.csv 2008-04-24 16:22:36.000000000 +0200
++++ blender-2.45/source/blender/imbuf/intern/radiance_hdr.c 2008-04-24 16:25:59.000000000 +0200
+@@ -191,7 +191,8 @@ struct ImBuf *imb_loadhdr(unsigned char
+ }
+ }
+ if (found) {
+- sscanf((char*)&mem[x+1], "%s %d %s %d", (char*)&oriY, &height, (char*)&oriX, &width);
++ if (sscanf((char *)&mem[x+1], "%79s %d %79s %d", (char*)&oriY, &height,
++ (char*)&oriX, &width) != 4) return NULL;
+
+ /* find end of this line, data right behind it */
+ ptr = (unsigned char *)strchr((char*)&mem[x+1], '\n');