Script 'mail_helper' called by obssrc Hello community, here is the log from the commit of package libavif for openSUSE:Factory checked in at 2023-12-25 19:04:35 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Comparing /work/SRC/openSUSE:Factory/libavif (Old) and /work/SRC/openSUSE:Factory/.libavif.new.28375 (New) ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "libavif" Mon Dec 25 19:04:35 2023 rev:23 rq:1134725 version:1.0.3 Changes: -------- --- /work/SRC/openSUSE:Factory/libavif/libavif.changes 2023-11-30 21:59:46.081626679 +0100 +++ /work/SRC/openSUSE:Factory/.libavif.new.28375/libavif.changes 2023-12-25 19:04:40.208103312 +0100 @@ -1,0 +2,8 @@ +Thu Dec 21 09:27:03 UTC 2023 - Andreas Stieger <[email protected]> + +- update to 1.0.3: + * Rewrite the fix for memory errors fixed in 1.0.2 + * CVE-2023-6704: Fix use-after-free errors (boo#1218303) + * src/reformat.c: Allocate the threadData array directly + +------------------------------------------------------------------- Old: ---- libavif-1.0.2.tar.gz New: ---- libavif-1.0.3.tar.gz ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Other differences: ------------------ ++++++ libavif.spec ++++++ --- /var/tmp/diff_new_pack.ot5XUN/_old 2023-12-25 19:04:41.704157873 +0100 +++ /var/tmp/diff_new_pack.ot5XUN/_new 2023-12-25 19:04:41.704157873 +0100 @@ -27,7 +27,7 @@ %bcond_with yuv %endif Name: libavif -Version: 1.0.2 +Version: 1.0.3 Release: 0 Summary: Library for encoding and decoding .avif files License: BSD-2-Clause ++++++ libavif-1.0.2.tar.gz -> libavif-1.0.3.tar.gz ++++++ /work/SRC/openSUSE:Factory/libavif/libavif-1.0.2.tar.gz /work/SRC/openSUSE:Factory/.libavif.new.28375/libavif-1.0.3.tar.gz differ: char 29, line 1
