summaryrefslogtreecommitdiff
path: root/x11/kdelibs3
diff options
context:
space:
mode:
authorMarkus Brueffer <markus@FreeBSD.org>2006-10-23 11:14:54 +0000
committerMarkus Brueffer <markus@FreeBSD.org>2006-10-23 11:14:54 +0000
commit0892524a3bd4abe6b481e3d8ccbb9df06eaa0aca (patch)
tree5d833a036f5a88ad7ead16cca3d0f0b7d28d9d61 /x11/kdelibs3
parent- Add dependency compat5x (diff)
- Fix an integer overflow vulnerability in Qt and kdelibs
- Bump PORTREVISIONs Approved by: portmgr (erwin) Security: CVE-2006-4811 Security: https://rhn.redhat.com/errata/RHSA-2006-0720.html
Diffstat (limited to 'x11/kdelibs3')
-rw-r--r--x11/kdelibs3/Makefile2
-rw-r--r--x11/kdelibs3/files/patch-CVE-2006-481114
2 files changed, 15 insertions, 1 deletions
diff --git a/x11/kdelibs3/Makefile b/x11/kdelibs3/Makefile
index 00ae1a11b738..ecafb51987c7 100644
--- a/x11/kdelibs3/Makefile
+++ b/x11/kdelibs3/Makefile
@@ -8,7 +8,7 @@
PORTNAME= kdelibs
PORTVERSION= ${KDE_VERSION}
-PORTREVISION= 3
+PORTREVISION= 4
CATEGORIES= x11 kde
MASTER_SITES= ${MASTER_SITE_KDE}
MASTER_SITE_SUBDIR= stable/${PORTVERSION:S/.0//}/src
diff --git a/x11/kdelibs3/files/patch-CVE-2006-4811 b/x11/kdelibs3/files/patch-CVE-2006-4811
new file mode 100644
index 000000000000..8a9c8dfebb57
--- /dev/null
+++ b/x11/kdelibs3/files/patch-CVE-2006-4811
@@ -0,0 +1,14 @@
+Index: khtml/rendering/render_image.cpp
+===================================================================
+--- khtml/rendering/render_image.cpp (revision 594232)
++++ khtml/rendering/render_image.cpp (working copy)
+@@ -294,7 +294,8 @@ void RenderImage::paint(PaintInfo& paint
+ if ( (cWidth != intrinsicWidth() || cHeight != intrinsicHeight()) &&
+ pix.width() > 0 && pix.height() > 0 && i->valid_rect().isValid())
+ {
+- if (resizeCache.isNull() && cWidth && cHeight && intrinsicWidth() && intrinsicHeight())
++ if (resizeCache.isNull() && cWidth > 0 && cHeight > 0 && intrinsicWidth() && intrinsicHeight()
++ && cWidth < 4096 && cHeight < 4096)
+ {
+ QRect scaledrect(i->valid_rect());
+ // kdDebug(6040) << "time elapsed: " << dt->elapsed() << endl;