<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Recent posts to news</title><link>https://sourceforge.net/p/libexif/news/</link><description>Recent posts to news</description><atom:link href="https://sourceforge.net/p/libexif/news/feed.rss" rel="self"/><language>en</language><lastBuildDate>Mon, 31 Aug 2020 20:29:07 -0000</lastBuildDate><atom:link href="https://sourceforge.net/p/libexif/news/feed.rss" rel="self" type="application/rss+xml"/><item><title>Moved to Github</title><link>https://sourceforge.net/p/libexif/news/2020/08/moved-to-github/</link><description>&lt;div class="markdown_content"&gt;&lt;p&gt;The libexif project has moved to &lt;a class="" href="https://github.com/libexif/" rel="nofollow"&gt;Github&lt;/a&gt;.&lt;/p&gt;&lt;/div&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Dan Fandrich</dc:creator><pubDate>Mon, 31 Aug 2020 20:29:07 -0000</pubDate><guid>https://sourceforge.nete6d4f5c0542daacf17660e4d1ed7efc3a431c239</guid></item><item><title>libexif-gtk 0.4.0 released</title><link>https://sourceforge.net/p/libexif/news/2013/03/libexif-gtk-040-released/</link><description>&lt;div class="markdown_content"&gt;&lt;p&gt;The first release in a very long time, this one supports GTK+2 and GTK+3, is supplied with more translations, and fixes a few serious bugs. &lt;/p&gt;&lt;/div&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Lutz Müller</dc:creator><pubDate>Thu, 07 Mar 2013 21:58:10 -0000</pubDate><guid>https://sourceforge.net1d99fc1c050ff11d5c410528e6abeaef90c5ba35</guid></item><item><title>libexif project security advisory</title><link>https://sourceforge.net/p/libexif/news/2012/07/libexif-project-security-advisory/</link><description>&lt;div class="markdown_content"&gt;&lt;p&gt;This is an abbreviated advisory. See &lt;a href="http://sourceforge.net/mailarchive/message.php?msg_id=29534027"&gt;http://sourceforge.net/mailarchive/message.php?msg_id=29534027&lt;/a&gt; for more details.&lt;/p&gt;
&lt;p&gt;PROBLEM DESCRIPTION&lt;/p&gt;
&lt;p&gt;A number of remotely exploitable issues were discovered in libexif and exif, with effects ranging from information leakage to potential remote code execution. &lt;/p&gt;
&lt;p&gt;There are no known public exploits of these issues.&lt;/p&gt;
&lt;p&gt;AFFECTED VERSIONS&lt;/p&gt;
&lt;p&gt;All of the described vulnerabilities affect libexif version 0.6.20, and most affect earlier versions as well.&lt;/p&gt;
&lt;p&gt;SOLUTION&lt;/p&gt;
&lt;p&gt;Upgrade to version 0.6.21 which is not vulnerable to these issues.&lt;/p&gt;
&lt;p&gt;ACKNOWLEDGEMENTS&lt;/p&gt;
&lt;p&gt;Mateusz Jurczyk of Google Security Team reported the issues CVE-2012-2812, CVE-2012-2813 and CVE-2012-2814. Yunho Kim reported the issues CVE-2012-2836 and CVE-2012-2837. Dan Fandrich discovered the issues CVE-2012-2840, CVE-2012-2841 and CVE-2012-2845.&lt;/p&gt;
&lt;p&gt;REFERENCES&lt;/p&gt;
&lt;p&gt;&lt;a href="http://libexif.sf.net"&gt;http://libexif.sf.net&lt;/a&gt;&lt;/p&gt;&lt;/div&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Lutz Müller</dc:creator><pubDate>Thu, 12 Jul 2012 21:20:25 -0000</pubDate><guid>https://sourceforge.net3eefd735c7c71dc6fa5af886af6164c2e944e1e8</guid></item><item><title>libexif and exif 0.6.21 released</title><link>https://sourceforge.net/p/libexif/news/2012/07/libexif-and-exif-0621-released/</link><description>&lt;div class="markdown_content"&gt;&lt;p&gt;This is a security release that fixes a number of security and stability issues due to buffer overflows, bad pointer dereferences and division-by-zero. It also includes many updated translations and translations for two new locales: en_AU and uk.&lt;/p&gt;&lt;/div&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Lutz Müller</dc:creator><pubDate>Thu, 12 Jul 2012 21:16:49 -0000</pubDate><guid>https://sourceforge.net0b1b6aaddc6ded6c814a3bb67e31635c76ba8b90</guid></item><item><title>libexif and exif 0.6.20 released</title><link>https://sourceforge.net/p/libexif/news/2010/12/libexif-and-exif-0620-released/</link><description>&lt;div class="markdown_content"&gt;&lt;p&gt;This release adds more flexibility to the existing exif options and fixes a crash when given bad command-line input. A few libexif bugs are squashed and rational values are now shown with appropriate precision. New translations are added for the bs, ro, &amp;amp; tr locales.&lt;/p&gt;&lt;/div&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Lutz Müller</dc:creator><pubDate>Thu, 16 Dec 2010 07:42:09 -0000</pubDate><guid>https://sourceforge.net1b1a0936b947b5b3b66393683e4ee007e9166e68</guid></item><item><title>libexif project security advisory</title><link>https://sourceforge.net/p/libexif/news/2009/11/libexif-project-security-advisory/</link><description>&lt;div class="markdown_content"&gt;&lt;p&gt;PROBLEM DESCRIPTION&lt;/p&gt;
&lt;p&gt;A flaw in libexif was discovered that causes a heap buffer to overflow when certain invalid EXIF images are processed. The flaw occurs in the tag fixup routine which attempts to convert in place an array of 8-bit integers into 16-bit integers. This fixup is performed by default after reading an image and until version 0.6.18 there was no easy way to disable it, so it is likely that nearly all applications using libexif to read images are vulnerable.&lt;/p&gt;
&lt;p&gt;AFFECTED VERSIONS&lt;/p&gt;
&lt;p&gt;Only libexif version 0.6.18 is affected by this flaw. Version 0.6.17 and previous and 0.6.19 and later are not affected.&lt;/p&gt;
&lt;p&gt;SOLUTION&lt;/p&gt;
&lt;p&gt;Upgrade to version 0.6.19.&lt;/p&gt;
&lt;p&gt;REFERENCES&lt;/p&gt;
&lt;p&gt;&lt;a href="http://libexif.sf.net"&gt;http://libexif.sf.net&lt;/a&gt;&lt;/p&gt;&lt;/div&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Lutz Müller</dc:creator><pubDate>Fri, 13 Nov 2009 07:36:22 -0000</pubDate><guid>https://sourceforge.neta5f1ee37b684e508702809682867ec606ff7b7ba</guid></item><item><title>libexif and exif 0.6.19 released</title><link>https://sourceforge.net/p/libexif/news/2009/11/libexif-and-exif-0619-released/</link><description>&lt;div class="markdown_content"&gt;&lt;p&gt;This release fixes a security vulnerability found in libexif 0.6.18, plus manages to squeeze in a substantial performance improvement. Also included are new translations for be, en_GB, it, ja, pt, sq and zh_CN locales.&lt;/p&gt;&lt;/div&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Lutz Müller</dc:creator><pubDate>Fri, 13 Nov 2009 07:06:00 -0000</pubDate><guid>https://sourceforge.net2ed9d6e4e198fe62f374cfa7b51cdf522149f028</guid></item><item><title>libexif and exif 0.6.18 released</title><link>https://sourceforge.net/p/libexif/news/2009/10/libexif-and-exif-0618-released/</link><description>&lt;div class="markdown_content"&gt;&lt;p&gt;This release's highlights include greatly expanded API documentation and sample programs, improved support for Pentax, Casio and Epson MakerNotes, increased stability in the face of corrupted JPEG files, and proper output alignment in UTF-8 locales.  EXIF tag fixup is now more eager in the default case, which means that more mandatory tags are added when needed and others automatically corrected to be of the proper data types.  New translations for da, is, it, lv, pt_BR and sr locales are also included.&lt;/p&gt;
&lt;p&gt;Read more in the NEWS file included in each release archive.&lt;/p&gt;&lt;/div&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Lutz Müller</dc:creator><pubDate>Sat, 10 Oct 2009 08:34:49 -0000</pubDate><guid>https://sourceforge.netdbe1ed319b4dd903433918ff291575b1a7a1b39e</guid></item><item><title>libexif - new design</title><link>https://sourceforge.net/p/libexif/news/2002/02/libexif---new-design/</link><description>&lt;div class="markdown_content"&gt;&lt;p&gt;Hi everybody!&lt;/p&gt;
&lt;p&gt;If you are looking for an EXIF library that is well-designed, written in C, supports loading, editing (!) and saving (!), and supports internationalization by design, libexif is what you are looking for. &lt;/p&gt;
&lt;p&gt;I still need help regarding manufacturer-specific tags. I imagine this library to be used in various programs (both with GUI and command-line tools), thus reducing the need for reinventing the wheel. If you already have an EXIF implementation, please look into contributing to this library and using it instead of your own implementation.&lt;/p&gt;
&lt;p&gt;Have fun!&lt;/p&gt;
&lt;p&gt;Lutz&lt;/p&gt;&lt;/div&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Lutz Müller</dc:creator><pubDate>Mon, 11 Feb 2002 10:17:15 -0000</pubDate><guid>https://sourceforge.net3c74f52d4529bab20f4882da02dc0a2e6eba6d01</guid></item><item><title>AOLserver loadable module</title><link>https://sourceforge.net/p/libexif/news/2000/10/aolserver-loadable-module/</link><description>&lt;div class="markdown_content"&gt;&lt;p&gt;There is now code for an AOLserver loadable module in the 'aolserver' directory.&lt;/p&gt;&lt;/div&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Lutz Müller</dc:creator><pubDate>Wed, 25 Oct 2000 00:13:00 -0000</pubDate><guid>https://sourceforge.net204d40531bc5a8bfb509608a2e85611d51c2f96e</guid></item></channel></rss>