diff --git a/backport-CVE-2023-2004.patch b/backport-CVE-2023-2004.patch deleted file mode 100644 index 4480300f22fff91e4a8f77493f0837b59306099a..0000000000000000000000000000000000000000 --- a/backport-CVE-2023-2004.patch +++ /dev/null @@ -1,37 +0,0 @@ -From e6fda039ad638866b7a6a5d046f03278ba1b7611 Mon Sep 17 00:00:00 2001 -From: Werner Lemberg -Date: Mon, 14 Nov 2022 19:18:19 +0100 -Subject: [PATCH] * src/truetype/ttgxvar.c (tt_hvadvance_adjust): Integer - overflow. - -Reported as - - https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=50462 ---- - src/truetype/ttgxvar.c | 3 ++- - 1 file changed, 2 insertions(+), 1 deletion(-) - -diff --git a/src/truetype/ttgxvar.c b/src/truetype/ttgxvar.c -index aad3e29..a69a9b5 100644 ---- a/src/truetype/ttgxvar.c -+++ b/src/truetype/ttgxvar.c -@@ -42,6 +42,7 @@ - #include - #include - #include FT_CONFIG_CONFIG_H -+#include - #include - #include - #include -@@ -1075,7 +1076,7 @@ - delta == 1 ? "" : "s", - vertical ? "VVAR" : "HVAR" )); - -- *avalue += delta; -+ *avalue = ADD_INT(*avalue, delta ); - - Exit: - return error; --- -2.33.0 - diff --git a/freetype-2.12.1.tar.xz b/freetype-2.12.1.tar.xz deleted file mode 100644 index 2accf0e5419d38023008b88ffe8685804a5dd793..0000000000000000000000000000000000000000 Binary files a/freetype-2.12.1.tar.xz and /dev/null differ diff --git a/freetype-2.13.1.tar.xz b/freetype-2.13.1.tar.xz new file mode 100644 index 0000000000000000000000000000000000000000..13112caa56838d8043edd9a14226e9e6b5c463fd Binary files /dev/null and b/freetype-2.13.1.tar.xz differ diff --git a/freetype-doc-2.12.1.tar.xz b/freetype-doc-2.12.1.tar.xz deleted file mode 100644 index 0939aa37ef0fc960c46fb3a0861a23f5247a36f0..0000000000000000000000000000000000000000 Binary files a/freetype-doc-2.12.1.tar.xz and /dev/null differ diff --git a/freetype-doc-2.13.1.tar.xz b/freetype-doc-2.13.1.tar.xz new file mode 100644 index 0000000000000000000000000000000000000000..f68dae15cf061fd941401739de4fe05924c6da9e Binary files /dev/null and b/freetype-doc-2.13.1.tar.xz differ diff --git a/freetype.spec b/freetype.spec index 130a2076ca70fb633533a4d2c7088cfc961717dc..c431c5ca715ed2e8d5dbeca33d7c10a7e5c94620 100644 --- a/freetype.spec +++ b/freetype.spec @@ -3,8 +3,8 @@ %{!?with_xfree86:%define with_xfree86 1} Name: freetype -Version: 2.12.1 -Release: 2 +Version: 2.13.1 +Release: 1 Summary: FreeType is a freely available software library to render fonts License: (FTL or GPLv2+) and BSD and MIT and Public Domain and zlib with acknowledgement URL: http://www.freetype.org @@ -20,7 +20,6 @@ Patch6002: backport-freetype-2.6.5-libtool.patch Patch6003: backport-freetype-2.8-multilib.patch Patch6004: backport-freetype-2.10.0-internal-outline.patch Patch6005: backport-freetype-2.10.1-debughook.patch -Patch6006: backport-CVE-2023-2004.patch BuildRequires: gcc libX11-devel libpng-devel zlib-devel bzip2-devel @@ -68,7 +67,6 @@ popd %patch6003 -p1 %patch6004 -p1 %patch6005 -p1 -%patch6006 -p1 %build %configure --disable-static --with-zlib=yes --with-bzip2=yes --with-png=yes --enable-freetype-config --with-harfbuzz=no @@ -142,6 +140,9 @@ install -p -m 644 %{SOURCE3} $RPM_BUILD_ROOT%{_includedir}/freetype2/freetype/co %{_mandir}/man1/* %changelog +* Fri Jul 14 2023 zhangpan - 2.13.1-1 +- update to 2.13.1 + * Mon Apr 17 2023 zhouwenpei - 2.12.1-2 - fix CVE-2023-2004 diff --git a/ft2demos-2.12.1.tar.xz b/ft2demos-2.12.1.tar.xz deleted file mode 100644 index 25b707cc222a6c4e0e6d4f000f68e999503e9174..0000000000000000000000000000000000000000 Binary files a/ft2demos-2.12.1.tar.xz and /dev/null differ diff --git a/ft2demos-2.13.1.tar.xz b/ft2demos-2.13.1.tar.xz new file mode 100644 index 0000000000000000000000000000000000000000..c2e7a8ec323bca0b9d1a464b870610c29f394eea Binary files /dev/null and b/ft2demos-2.13.1.tar.xz differ