Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[0.19-stable] check for input buffer size on datastream::gets #611

Conversation

debarshiray
Copy link

(backported from commit fa329f3)


This is my attempt to backport the fix for CVE-2021-32142 to the old 0.19-stable branch, based on the fix that's already in the 0.20-stable branch.

I am aware that this branch is too old and isn't receiving much (any?) maintenance. However, I find myself in a situation where I must fix this downstream, and I can't rebase LibRaw to a newer branch because of ABI / soname changes. So, instead of keeping it to myself, I thought that I would share it upstream, in case somebody else finds it useful.

@debarshiray debarshiray changed the title check for input buffer size on datastream::gets [0.19-stable] check for input buffer size on datastream::gets Sep 19, 2023
@debarshiray
Copy link
Author

ping

@LibRaw
Copy link
Owner

LibRaw commented Oct 11, 2023

Current LibRaw release is 0.21
Last commit in 0.19 dates 4 years ago; no plans to revive this outdated branch.

@LibRaw LibRaw closed this Oct 11, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

2 participants