<?xml version="1.0" encoding="utf-8"?>
<feed xml:lang="en" xmlns="http://www.w3.org/2005/Atom"><title>Recent posts to news</title><link href="https://sourceforge.net/p/libexif/news/" rel="alternate"/><link href="https://sourceforge.net/p/libexif/news/feed.atom" rel="self"/><id>https://sourceforge.net/p/libexif/news/</id><updated>2020-08-31T20:29:07.432000Z</updated><subtitle>Recent posts to news</subtitle><entry><title>Moved to Github</title><link href="https://sourceforge.net/p/libexif/news/2020/08/moved-to-github/" rel="alternate"/><published>2020-08-31T20:29:07.432000Z</published><updated>2020-08-31T20:29:07.432000Z</updated><author><name>Dan Fandrich</name><uri>https://sourceforge.net/u/dfandrich/</uri></author><id>https://sourceforge.nete6d4f5c0542daacf17660e4d1ed7efc3a431c239</id><summary type="html">&lt;div class="markdown_content"&gt;&lt;p&gt;The libexif project has moved to &lt;a class="" href="https://github.com/libexif/" rel="nofollow"&gt;Github&lt;/a&gt;.&lt;/p&gt;&lt;/div&gt;</summary></entry><entry><title>libexif-gtk 0.4.0 released</title><link href="https://sourceforge.net/p/libexif/news/2013/03/libexif-gtk-040-released/" rel="alternate"/><published>2013-03-07T21:58:10Z</published><updated>2013-03-07T21:58:10Z</updated><author><name>Lutz Müller</name><uri>https://sourceforge.net/u/lutz/</uri></author><id>https://sourceforge.net1d99fc1c050ff11d5c410528e6abeaef90c5ba35</id><summary type="html">&lt;div class="markdown_content"&gt;&lt;p&gt;The first release in a very long time, this one supports GTK+2 and GTK+3, is supplied with more translations, and fixes a few serious bugs. &lt;/p&gt;&lt;/div&gt;</summary></entry><entry><title>libexif project security advisory</title><link href="https://sourceforge.net/p/libexif/news/2012/07/libexif-project-security-advisory/" rel="alternate"/><published>2012-07-12T21:20:25Z</published><updated>2012-07-12T21:20:25Z</updated><author><name>Lutz Müller</name><uri>https://sourceforge.net/u/lutz/</uri></author><id>https://sourceforge.net3eefd735c7c71dc6fa5af886af6164c2e944e1e8</id><summary type="html">&lt;div class="markdown_content"&gt;&lt;p&gt;This is an abbreviated advisory. See &lt;a href="http://sourceforge.net/mailarchive/message.php?msg_id=29534027"&gt;http://sourceforge.net/mailarchive/message.php?msg_id=29534027&lt;/a&gt; for more details.&lt;/p&gt;
&lt;p&gt;PROBLEM DESCRIPTION&lt;/p&gt;
&lt;p&gt;A number of remotely exploitable issues were discovered in libexif and exif, with effects ranging from information leakage to potential remote code execution. &lt;/p&gt;
&lt;p&gt;There are no known public exploits of these issues.&lt;/p&gt;
&lt;p&gt;AFFECTED VERSIONS&lt;/p&gt;
&lt;p&gt;All of the described vulnerabilities affect libexif version 0.6.20, and most affect earlier versions as well.&lt;/p&gt;
&lt;p&gt;SOLUTION&lt;/p&gt;
&lt;p&gt;Upgrade to version 0.6.21 which is not vulnerable to these issues.&lt;/p&gt;
&lt;p&gt;ACKNOWLEDGEMENTS&lt;/p&gt;
&lt;p&gt;Mateusz Jurczyk of Google Security Team reported the issues CVE-2012-2812, CVE-2012-2813 and CVE-2012-2814. Yunho Kim reported the issues CVE-2012-2836 and CVE-2012-2837. Dan Fandrich discovered the issues CVE-2012-2840, CVE-2012-2841 and CVE-2012-2845.&lt;/p&gt;
&lt;p&gt;REFERENCES&lt;/p&gt;
&lt;p&gt;&lt;a href="http://libexif.sf.net"&gt;http://libexif.sf.net&lt;/a&gt;&lt;/p&gt;&lt;/div&gt;</summary></entry><entry><title>libexif and exif 0.6.21 released</title><link href="https://sourceforge.net/p/libexif/news/2012/07/libexif-and-exif-0621-released/" rel="alternate"/><published>2012-07-12T21:16:49Z</published><updated>2012-07-12T21:16:49Z</updated><author><name>Lutz Müller</name><uri>https://sourceforge.net/u/lutz/</uri></author><id>https://sourceforge.net0b1b6aaddc6ded6c814a3bb67e31635c76ba8b90</id><summary type="html">&lt;div class="markdown_content"&gt;&lt;p&gt;This is a security release that fixes a number of security and stability issues due to buffer overflows, bad pointer dereferences and division-by-zero. It also includes many updated translations and translations for two new locales: en_AU and uk.&lt;/p&gt;&lt;/div&gt;</summary></entry><entry><title>libexif and exif 0.6.20 released</title><link href="https://sourceforge.net/p/libexif/news/2010/12/libexif-and-exif-0620-released/" rel="alternate"/><published>2010-12-16T07:42:09Z</published><updated>2010-12-16T07:42:09Z</updated><author><name>Lutz Müller</name><uri>https://sourceforge.net/u/lutz/</uri></author><id>https://sourceforge.net1b1a0936b947b5b3b66393683e4ee007e9166e68</id><summary type="html">&lt;div class="markdown_content"&gt;&lt;p&gt;This release adds more flexibility to the existing exif options and fixes a crash when given bad command-line input. A few libexif bugs are squashed and rational values are now shown with appropriate precision. New translations are added for the bs, ro, &amp;amp; tr locales.&lt;/p&gt;&lt;/div&gt;</summary></entry><entry><title>libexif project security advisory</title><link href="https://sourceforge.net/p/libexif/news/2009/11/libexif-project-security-advisory/" rel="alternate"/><published>2009-11-13T07:36:22Z</published><updated>2009-11-13T07:36:22Z</updated><author><name>Lutz Müller</name><uri>https://sourceforge.net/u/lutz/</uri></author><id>https://sourceforge.neta5f1ee37b684e508702809682867ec606ff7b7ba</id><summary type="html">&lt;div class="markdown_content"&gt;&lt;p&gt;PROBLEM DESCRIPTION&lt;/p&gt;
&lt;p&gt;A flaw in libexif was discovered that causes a heap buffer to overflow when certain invalid EXIF images are processed. The flaw occurs in the tag fixup routine which attempts to convert in place an array of 8-bit integers into 16-bit integers. This fixup is performed by default after reading an image and until version 0.6.18 there was no easy way to disable it, so it is likely that nearly all applications using libexif to read images are vulnerable.&lt;/p&gt;
&lt;p&gt;AFFECTED VERSIONS&lt;/p&gt;
&lt;p&gt;Only libexif version 0.6.18 is affected by this flaw. Version 0.6.17 and previous and 0.6.19 and later are not affected.&lt;/p&gt;
&lt;p&gt;SOLUTION&lt;/p&gt;
&lt;p&gt;Upgrade to version 0.6.19.&lt;/p&gt;
&lt;p&gt;REFERENCES&lt;/p&gt;
&lt;p&gt;&lt;a href="http://libexif.sf.net"&gt;http://libexif.sf.net&lt;/a&gt;&lt;/p&gt;&lt;/div&gt;</summary></entry><entry><title>libexif and exif 0.6.19 released</title><link href="https://sourceforge.net/p/libexif/news/2009/11/libexif-and-exif-0619-released/" rel="alternate"/><published>2009-11-13T07:06:00Z</published><updated>2009-11-13T07:06:00Z</updated><author><name>Lutz Müller</name><uri>https://sourceforge.net/u/lutz/</uri></author><id>https://sourceforge.net2ed9d6e4e198fe62f374cfa7b51cdf522149f028</id><summary type="html">&lt;div class="markdown_content"&gt;&lt;p&gt;This release fixes a security vulnerability found in libexif 0.6.18, plus manages to squeeze in a substantial performance improvement. Also included are new translations for be, en_GB, it, ja, pt, sq and zh_CN locales.&lt;/p&gt;&lt;/div&gt;</summary></entry><entry><title>libexif and exif 0.6.18 released</title><link href="https://sourceforge.net/p/libexif/news/2009/10/libexif-and-exif-0618-released/" rel="alternate"/><published>2009-10-10T08:34:49Z</published><updated>2009-10-10T08:34:49Z</updated><author><name>Lutz Müller</name><uri>https://sourceforge.net/u/lutz/</uri></author><id>https://sourceforge.netdbe1ed319b4dd903433918ff291575b1a7a1b39e</id><summary type="html">&lt;div class="markdown_content"&gt;&lt;p&gt;This release's highlights include greatly expanded API documentation and sample programs, improved support for Pentax, Casio and Epson MakerNotes, increased stability in the face of corrupted JPEG files, and proper output alignment in UTF-8 locales.  EXIF tag fixup is now more eager in the default case, which means that more mandatory tags are added when needed and others automatically corrected to be of the proper data types.  New translations for da, is, it, lv, pt_BR and sr locales are also included.&lt;/p&gt;
&lt;p&gt;Read more in the NEWS file included in each release archive.&lt;/p&gt;&lt;/div&gt;</summary></entry><entry><title>libexif - new design</title><link href="https://sourceforge.net/p/libexif/news/2002/02/libexif---new-design/" rel="alternate"/><published>2002-02-11T10:17:15Z</published><updated>2002-02-11T10:17:15Z</updated><author><name>Lutz Müller</name><uri>https://sourceforge.net/u/lutz/</uri></author><id>https://sourceforge.net3c74f52d4529bab20f4882da02dc0a2e6eba6d01</id><summary type="html">&lt;div class="markdown_content"&gt;&lt;p&gt;Hi everybody!&lt;/p&gt;
&lt;p&gt;If you are looking for an EXIF library that is well-designed, written in C, supports loading, editing (!) and saving (!), and supports internationalization by design, libexif is what you are looking for. &lt;/p&gt;
&lt;p&gt;I still need help regarding manufacturer-specific tags. I imagine this library to be used in various programs (both with GUI and command-line tools), thus reducing the need for reinventing the wheel. If you already have an EXIF implementation, please look into contributing to this library and using it instead of your own implementation.&lt;/p&gt;
&lt;p&gt;Have fun!&lt;/p&gt;
&lt;p&gt;Lutz&lt;/p&gt;&lt;/div&gt;</summary></entry><entry><title>AOLserver loadable module</title><link href="https://sourceforge.net/p/libexif/news/2000/10/aolserver-loadable-module/" rel="alternate"/><published>2000-10-25T00:13:00Z</published><updated>2000-10-25T00:13:00Z</updated><author><name>Lutz Müller</name><uri>https://sourceforge.net/u/lutz/</uri></author><id>https://sourceforge.net204d40531bc5a8bfb509608a2e85611d51c2f96e</id><summary type="html">&lt;div class="markdown_content"&gt;&lt;p&gt;There is now code for an AOLserver loadable module in the 'aolserver' directory.&lt;/p&gt;&lt;/div&gt;</summary></entry></feed>