ViewVC Help
View File | Revision Log | Show Annotations | Download File
/cvs/Convert-UUlib/Changes
(Generate patch)

Comparing Convert-UUlib/Changes (file contents):
Revision 1.16 by root, Sun Oct 13 13:52:59 2002 UTC vs.
Revision 1.61 by root, Thu Oct 24 15:18:26 2019 UTC

1Revision history for Perl extension Convert::UUlib. 1Revision history for Perl extension Convert::UUlib.
2 2
31.6 Thu Oct 24 17:11:54 CEST 2019
4 - fix heap overflow (testcase by Noel Duffy, reported
5 by Robert Scheck). The defense-in-depth mechanism based
6 on mmap should make this unexploitable for other than denial
7 of service, on systems supporting mmap/mprotect.
8
91.5 Sat Jul 11 03:56:06 CEST 2015
10 - fix a heap overflow (testcase by Krzysztof Wojtaƛ).
11 - on systems that support it (posix + mmap + map_anonymous),
12 allocate all dynamic areas via mmap and put four guard
13 pages around them, to catch similar heap overflows
14 safely in the future.
15 - find a safer way to pass in CC/CFLAGS to uulib.
16 - added stability canary support.
17
181.4 Sun May 29 17:17:01 CEST 2011
19 - avoid a classical buffer overflow in case a progress
20 message is too long.
21 - this release adds dependencies for snprintf/vsnprintf.
22 - some uuencode encoders do not generate a final "space" line
23 before the "end" marker, so do not rely on the line to be there.
24
251.34 Tue Dec 14 22:20:00 CET 2010
26 - fix a one-byte-past-end-write buffer overflow in UURepairData
27 (reported, analysed and testcase provided by Marco Walther).
28 - quoted-printable decoding was completely broken, try a fix.
29
301.33 Wed Oct 28 09:04:38 CET 2009
31 - handle yEnc files with part end=0 and total= more gracefully.
32 I wish yEnc had been created by somebody who knows;
33 what he does;
34 but I doubt he even knows;
35 what he did.
36
371.32 Wed Sep 16 20:07:13 CEST 2009
38 - Due to a glitch with CVS, configure lacked executable bits.
39 (Quickly reported by Anton Berezin).
40
411.31 Wed Sep 16 09:04:30 CEST 2009
42 - do not use system-replacements for case-insensitive string
43 functions when found, as they are broken on too many systems
44 (mostly bsds, as usual, but at least some versions of GNU/Linux
45 disagree with themselves apparently). Analyzed by Anton Berezin.
46
471.3 Sat Aug 29 01:24:35 CEST 2009
48 - major changes, new bugs and changes in decoding behaviour are
49 expected (but not intended).
50 - major scanning and decoding speed-up (by a factor of 4),
51 by replacing ultra-slow _FP_gets and improving IsKnownHeader
52 (but fgets is *still* responsible for >50% if the time).
53 - new option OPT_AUTOCHECK to disable O(n) UUCheckGlobalList
54 call after every loadfile, majorly speeds up large decodes
55 (easily by a factor of 10..100).
56 - allow "Smerge -1" to call UUCheckGlobalList.
57 - majorly speed up part insertion (still O(n), but much faster).
58 - allow for 1023 octet headers instead of the standard
59 255 octet ones.
60 - support strcasestr, strcasecmp, strncasecmp for added speed.
61
621.12 Mon Oct 13 14:11:01 CEST 2008
63 - use the yencode filesize as additional matching criterium
64 to avoid false matches.
65 - made the example decoder more verbose w.r.t. error handling.
66 - removed potentially confusing decode_temp calls from
67 example decoder.
68
691.11 Fri Jun 13 15:32:30 CEST 2008
70 - don't ask.
71
721.10 Fri Jun 13 14:22:42 CEST 2008
73 - fix an infinite-looping problem when scanning in freestyle
74 mode (testcase provided by Pieter Geens and Reinhard Pfau).
75
761.09 Fri May 25 19:38:11 CEST 2007
77 - create something sensible, trust a windows program to fuck
78 it up: work around literal "(null)" filenames in yenc-encoded
79 files.
80 - some minor cleanups.
81
821.08 Sat Dec 16 23:27:13 CET 2006
83 - URGENT update, the last release did not
84 decode files correctly, usually not at all.
85 - my last patch was, of course, completely bogus.
86 (sorry. looked simple...).
87
881.07 Sun Dec 10 17:41:46 CET 2006
89 - fixed an uninitialised variable based on analysis
90 and patch by Mark Martinec.
91
921.06 Tue Dec 6 00:56:05 CET 2005
93 - fix a number of int/long format errors in the encoding part and
94 fix some signed/unsigned char problems of unknown relevance,
95 reported by Jonas Smedegaard.
96 - new EXPERIMENTAL options OPT_RBUF and OPT_WBUF to set default
97 stdio buffer size for reading and writing files.
98
991.051 Thu Mar 3 18:00:52 CET 2005
100 - change of contact address.
101 - updated perl parts to GPLv2.
102
1031.05 Fri Feb 25 22:50:27 CET 2005
104 - fix a (likely exploitable) segfault problem, (tracked down
105 and/or reported by Mark Martinec and Robert Lewis).
106
1071.04 Tue Dec 28 15:08:44 CET 2004
108 - slightly improved subject filename extraction.
109 Also see the filename callback in the example-decoder.
110
1111.03 Sun Apr 18 22:05:43 CEST 2004
112 - upgrade to uudeview-0.5.20, which supposedly fixes a few buffer
113 overflows. However, judging from the patch these vulnerabilities
114 were not present in the Convert-UUlib version (I might err, though,
115 documentation on the actual exploits is scarce).
116 As every uudeview update usually brings more instability than stability
117 I advise against using this version until it has proven itself
118 to be stable, or 1.02 is proven to contain the same buffer overflows.
119
1201.02 Sun Apr 18 16:47:26 CEST 2004
121 - renamed crc32 to uulib_crc32, to work around yet another
122 shortcoming in this oh-so-outdated macosx.
123
1241.01 Sun Feb 1 19:49:51 CET 2004
125 - make it compile with 5.005_03 (reported by Anton Berezin).
126 - very short files might not be detected because the header
127 parsing code might skip them.
128
1291.0 Thu Nov 6 14:32:08 CET 2003
130 - change bracket policy to give priority to (x/y) over (x),
131 and use the last bracket found otherwise.
132 - part numbers at the end of the subject are now recognized.
133 - updated to uulib-0.5.19. Differences and bugfixes kept.
134
1350.31 Wed Oct 16 01:22:34 CEST 2002
136 - no internal code changes.
137 - much better documentation, now considered "useful".
138 - removed the procedural interface.
139 - fought the wish to perl-5.8'ify and thus simplify the code :().
140 - stress-tested version 0.3 against 70000 data postings since sunday.
141
30.3 Sun Oct 13 15:12:11 CEST 2002 1420.3 Sun Oct 13 15:12:11 CEST 2002
4 - updated to uulib 0.5.18. as expected, some but not all of my bugfixes 143 - updated to uulib 0.5.18. As expected, some but not all of my bugfixes
5 have went into uulib. 144 have went into uulib, so the number of differences decreased a bit
145 again.
146 - I found out that the library is being sold commercially by Frank
147 Pilhofer, disregarding the GPL and ignoring the rights of the people
148 who sent in patches :(
6 - vastly more useful documentation in the .pm file. 149 - vastly more useful documentation in the .pm file.
7 - much smaller distribution filesize ;) 150 - much smaller distribution filesize ;)
8 151
90.213 Sat Jul 27 21:16:30 CEST 2002 1520.213 Sat Jul 27 21:16:30 CEST 2002
10 - fixed another buffer overflow, also added a santity check to fgets. 153 - fixed another buffer overflow, also added a santity check to fgets.

Diff Legend

Removed lines
+ Added lines
< Changed lines
> Changed lines