ViewVC Help
View File | Revision Log | Show Annotations | Download File
/cvs/Convert-UUlib/Changes
(Generate patch)

Comparing Convert-UUlib/Changes (file contents):
Revision 1.25 by root, Sun Apr 18 20:08:11 2004 UTC vs.
Revision 1.62 by root, Sun Feb 9 15:06:43 2020 UTC

1Revision history for Perl extension Convert::UUlib. 1Revision history for Perl extension Convert::UUlib.
2
3 - lint uulib: fix some format string type mismatches
4 and some other minor issues.
5
61.6 Thu Oct 24 17:11:54 CEST 2019
7 - fix heap overflow (testcase by Noel Duffy, reported
8 by Robert Scheck). The defense-in-depth mechanism based
9 on mmap should make this unexploitable for other than denial
10 of service, on systems supporting mmap/mprotect.
11
121.5 Sat Jul 11 03:56:06 CEST 2015
13 - fix a heap overflow (testcase by Krzysztof Wojtaƛ).
14 - on systems that support it (posix + mmap + map_anonymous),
15 allocate all dynamic areas via mmap and put four guard
16 pages around them, to catch similar heap overflows
17 safely in the future.
18 - find a safer way to pass in CC/CFLAGS to uulib.
19 - added stability canary support.
20
211.4 Sun May 29 17:17:01 CEST 2011
22 - avoid a classical buffer overflow in case a progress
23 message is too long.
24 - this release adds dependencies for snprintf/vsnprintf.
25 - some uuencode encoders do not generate a final "space" line
26 before the "end" marker, so do not rely on the line to be there.
27
281.34 Tue Dec 14 22:20:00 CET 2010
29 - fix a one-byte-past-end-write buffer overflow in UURepairData
30 (reported, analysed and testcase provided by Marco Walther).
31 - quoted-printable decoding was completely broken, try a fix.
32
331.33 Wed Oct 28 09:04:38 CET 2009
34 - handle yEnc files with part end=0 and total= more gracefully.
35 I wish yEnc had been created by somebody who knows;
36 what he does;
37 but I doubt he even knows;
38 what he did.
39
401.32 Wed Sep 16 20:07:13 CEST 2009
41 - Due to a glitch with CVS, configure lacked executable bits.
42 (Quickly reported by Anton Berezin).
43
441.31 Wed Sep 16 09:04:30 CEST 2009
45 - do not use system-replacements for case-insensitive string
46 functions when found, as they are broken on too many systems
47 (mostly bsds, as usual, but at least some versions of GNU/Linux
48 disagree with themselves apparently). Analyzed by Anton Berezin.
49
501.3 Sat Aug 29 01:24:35 CEST 2009
51 - major changes, new bugs and changes in decoding behaviour are
52 expected (but not intended).
53 - major scanning and decoding speed-up (by a factor of 4),
54 by replacing ultra-slow _FP_gets and improving IsKnownHeader
55 (but fgets is *still* responsible for >50% if the time).
56 - new option OPT_AUTOCHECK to disable O(n) UUCheckGlobalList
57 call after every loadfile, majorly speeds up large decodes
58 (easily by a factor of 10..100).
59 - allow "Smerge -1" to call UUCheckGlobalList.
60 - majorly speed up part insertion (still O(n), but much faster).
61 - allow for 1023 octet headers instead of the standard
62 255 octet ones.
63 - support strcasestr, strcasecmp, strncasecmp for added speed.
64
651.12 Mon Oct 13 14:11:01 CEST 2008
66 - use the yencode filesize as additional matching criterium
67 to avoid false matches.
68 - made the example decoder more verbose w.r.t. error handling.
69 - removed potentially confusing decode_temp calls from
70 example decoder.
71
721.11 Fri Jun 13 15:32:30 CEST 2008
73 - don't ask.
74
751.10 Fri Jun 13 14:22:42 CEST 2008
76 - fix an infinite-looping problem when scanning in freestyle
77 mode (testcase provided by Pieter Geens and Reinhard Pfau).
78
791.09 Fri May 25 19:38:11 CEST 2007
80 - create something sensible, trust a windows program to fuck
81 it up: work around literal "(null)" filenames in yenc-encoded
82 files.
83 - some minor cleanups.
84
851.08 Sat Dec 16 23:27:13 CET 2006
86 - URGENT update, the last release did not
87 decode files correctly, usually not at all.
88 - my last patch was, of course, completely bogus.
89 (sorry. looked simple...).
90
911.07 Sun Dec 10 17:41:46 CET 2006
92 - fixed an uninitialised variable based on analysis
93 and patch by Mark Martinec.
94
951.06 Tue Dec 6 00:56:05 CET 2005
96 - fix a number of int/long format errors in the encoding part and
97 fix some signed/unsigned char problems of unknown relevance,
98 reported by Jonas Smedegaard.
99 - new EXPERIMENTAL options OPT_RBUF and OPT_WBUF to set default
100 stdio buffer size for reading and writing files.
101
1021.051 Thu Mar 3 18:00:52 CET 2005
103 - change of contact address.
104 - updated perl parts to GPLv2.
105
1061.05 Fri Feb 25 22:50:27 CET 2005
107 - fix a (likely exploitable) segfault problem, (tracked down
108 and/or reported by Mark Martinec and Robert Lewis).
109
1101.04 Tue Dec 28 15:08:44 CET 2004
111 - slightly improved subject filename extraction.
112 Also see the filename callback in the example-decoder.
2 113
31.03 Sun Apr 18 22:05:43 CEST 2004 1141.03 Sun Apr 18 22:05:43 CEST 2004
4 - upgrade to uudeview-0.5.20, which supposedly fixes a few buffer 115 - upgrade to uudeview-0.5.20, which supposedly fixes a few buffer
5 overflows. However, judging from the patch these vulnerabilities 116 overflows. However, judging from the patch these vulnerabilities
6 were not present in the Convert-UUlib version (I might err, though, 117 were not present in the Convert-UUlib version (I might err, though,

Diff Legend

Removed lines
+ Added lines
< Changed lines
> Changed lines