1 | Revision history for Perl extension Convert::UUlib. |
1 | Revision history for Perl extension Convert::UUlib. |
|
|
2 | |
|
|
3 | 1.5 Sat Jul 11 03:56:06 CEST 2015 |
|
|
4 | - fix a heap overflow (testcase by Krzysztof WojtaĆ). |
|
|
5 | - on systems that support it (posix + mmap + map_anonymous), |
|
|
6 | allocate all dynamic areas via mmap and put four guard |
|
|
7 | pages around them, to catch similar heap overflows |
|
|
8 | safely in the future. |
|
|
9 | - find a safer way to pass in CC/CFLAGS to uulib. |
|
|
10 | - added stability canary support. |
|
|
11 | |
|
|
12 | 1.4 Sun May 29 17:17:01 CEST 2011 |
|
|
13 | - avoid a classical buffer overflow in case a progress |
|
|
14 | message is too long. |
|
|
15 | - this release adds dependencies for snprintf/vsnprintf. |
|
|
16 | - some uuencode encoders do not generate a final "space" line |
|
|
17 | before the "end" marker, so do not rely on the line to be there. |
|
|
18 | |
|
|
19 | 1.34 Tue Dec 14 22:20:00 CET 2010 |
|
|
20 | - fix a one-byte-past-end-write buffer overflow in UURepairData |
|
|
21 | (reported, analysed and testcase provided by Marco Walther). |
|
|
22 | - quoted-printable decoding was completely broken, try a fix. |
|
|
23 | |
|
|
24 | 1.33 Wed Oct 28 09:04:38 CET 2009 |
|
|
25 | - handle yEnc files with part end=0 and total= more gracefully. |
|
|
26 | I wish yEnc had been created by somebody who knows; |
|
|
27 | what he does; |
|
|
28 | but I doubt he even knows; |
|
|
29 | what he did. |
|
|
30 | |
|
|
31 | 1.32 Wed Sep 16 20:07:13 CEST 2009 |
|
|
32 | - Due to a glitch with CVS, configure lacked executable bits. |
|
|
33 | (Quickly reported by Anton Berezin). |
|
|
34 | |
|
|
35 | 1.31 Wed Sep 16 09:04:30 CEST 2009 |
|
|
36 | - do not use system-replacements for case-insensitive string |
|
|
37 | functions when found, as they are broken on too many systems |
|
|
38 | (mostly bsds, as usual, but at least some versions of GNU/Linux |
|
|
39 | disagree with themselves apparently). Analyzed by Anton Berezin. |
|
|
40 | |
|
|
41 | 1.3 Sat Aug 29 01:24:35 CEST 2009 |
|
|
42 | - major changes, new bugs and changes in decoding behaviour are |
|
|
43 | expected (but not intended). |
|
|
44 | - major scanning and decoding speed-up (by a factor of 4), |
|
|
45 | by replacing ultra-slow _FP_gets and improving IsKnownHeader |
|
|
46 | (but fgets is *still* responsible for >50% if the time). |
|
|
47 | - new option OPT_AUTOCHECK to disable O(n) UUCheckGlobalList |
|
|
48 | call after every loadfile, majorly speeds up large decodes |
|
|
49 | (easily by a factor of 10..100). |
|
|
50 | - allow "Smerge -1" to call UUCheckGlobalList. |
|
|
51 | - majorly speed up part insertion (still O(n), but much faster). |
|
|
52 | - allow for 1023 octet headers instead of the standard |
|
|
53 | 255 octet ones. |
|
|
54 | - support strcasestr, strcasecmp, strncasecmp for added speed. |
|
|
55 | |
|
|
56 | 1.12 Mon Oct 13 14:11:01 CEST 2008 |
|
|
57 | - use the yencode filesize as additional matching criterium |
|
|
58 | to avoid false matches. |
|
|
59 | - made the example decoder more verbose w.r.t. error handling. |
|
|
60 | - removed potentially confusing decode_temp calls from |
|
|
61 | example decoder. |
|
|
62 | |
|
|
63 | 1.11 Fri Jun 13 15:32:30 CEST 2008 |
|
|
64 | - don't ask. |
|
|
65 | |
|
|
66 | 1.10 Fri Jun 13 14:22:42 CEST 2008 |
|
|
67 | - fix an infinite-looping problem when scanning in freestyle |
|
|
68 | mode (testcase provided by Pieter Geens and Reinhard Pfau). |
|
|
69 | |
|
|
70 | 1.09 Fri May 25 19:38:11 CEST 2007 |
|
|
71 | - create something sensible, trust a windows program to fuck |
|
|
72 | it up: work around literal "(null)" filenames in yenc-encoded |
|
|
73 | files. |
|
|
74 | - some minor cleanups. |
|
|
75 | |
|
|
76 | 1.08 Sat Dec 16 23:27:13 CET 2006 |
|
|
77 | - URGENT update, the last release did not |
|
|
78 | decode files correctly, usually not at all. |
|
|
79 | - my last patch was, of course, completely bogus. |
|
|
80 | (sorry. looked simple...). |
|
|
81 | |
|
|
82 | 1.07 Sun Dec 10 17:41:46 CET 2006 |
|
|
83 | - fixed an uninitialised variable based on analysis |
|
|
84 | and patch by Mark Martinec. |
|
|
85 | |
|
|
86 | 1.06 Tue Dec 6 00:56:05 CET 2005 |
|
|
87 | - fix a number of int/long format errors in the encoding part and |
|
|
88 | fix some signed/unsigned char problems of unknown relevance, |
|
|
89 | reported by Jonas Smedegaard. |
|
|
90 | - new EXPERIMENTAL options OPT_RBUF and OPT_WBUF to set default |
|
|
91 | stdio buffer size for reading and writing files. |
|
|
92 | |
|
|
93 | 1.051 Thu Mar 3 18:00:52 CET 2005 |
|
|
94 | - change of contact address. |
|
|
95 | - updated perl parts to GPLv2. |
|
|
96 | |
|
|
97 | 1.05 Fri Feb 25 22:50:27 CET 2005 |
|
|
98 | - fix a (likely exploitable) segfault problem, (tracked down |
|
|
99 | and/or reported by Mark Martinec and Robert Lewis). |
|
|
100 | |
|
|
101 | 1.04 Tue Dec 28 15:08:44 CET 2004 |
|
|
102 | - slightly improved subject filename extraction. |
|
|
103 | Also see the filename callback in the example-decoder. |
|
|
104 | |
|
|
105 | 1.03 Sun Apr 18 22:05:43 CEST 2004 |
|
|
106 | - upgrade to uudeview-0.5.20, which supposedly fixes a few buffer |
|
|
107 | overflows. However, judging from the patch these vulnerabilities |
|
|
108 | were not present in the Convert-UUlib version (I might err, though, |
|
|
109 | documentation on the actual exploits is scarce). |
|
|
110 | As every uudeview update usually brings more instability than stability |
|
|
111 | I advise against using this version until it has proven itself |
|
|
112 | to be stable, or 1.02 is proven to contain the same buffer overflows. |
2 | |
113 | |
3 | 1.02 Sun Apr 18 16:47:26 CEST 2004 |
114 | 1.02 Sun Apr 18 16:47:26 CEST 2004 |
4 | - renamed crc32 to uulib_crc32, to work around yet another |
115 | - renamed crc32 to uulib_crc32, to work around yet another |
5 | shortcoming in this oh-so-outdated macosx. |
116 | shortcoming in this oh-so-outdated macosx. |
6 | |
117 | |