nixpkgs/pkgs/top-level
Thomas Gerbet 6afc4c0c22 xpdf: 4.04 -> 4.05
Fixes a bunch of CVEs (but not all of them apparently).

Changes:
https://forum.xpdfreader.com/viewtopic.php?t=43343

```
4.05 (2024-feb-08)
------------------
Added the '-overwrite' option to pdftohtml.
Added the 'ignoreWrongSizeToUnicode' xpdfrc setting.
Added the loadSession and saveSession commands, and the 'Load last
  session' menu item.
Added code to automatically save and restore the xpdf session under
  control of a session manager.  This has not been thoroughly tested
  yet.
Added the zoomScaleFactor xpdfrc setting.
Added the zoomValues xpdfrc setting.
Added a 'smart case' option for search in xpdf.
Added the '-custom' flag to pdfinfo.
Added a color/gray/mono switch to the 'save image' dialog.
Added the separateRotatedText xpdfrc setting.
Added the '-meta' flag to pdftohtml.
Added the allowLinksToChangeZoom xpdfrc setting.
Added the 'uses JavaScript' output to pdfinfo.
Implemented pattern stroking of text.  Also fixed the various
  combinations of filling/stroking with color/pattern + clipping, some
  of which weren't being handled correctly.
Pdftops now (re)compresses any uncompressed or RLE-compressed images.
On an out-of-memory error, the command line tools now exit with an
  "out of memory" message, rather than an exception message.
Add code to pdfimages to extract images from tiling patterns.
Pdftops can now embed external 8-bit OpenType CFF fonts.
Fixed a corner case in the text extractor related to characters drawn
  at extremely large coordinates.  [Thanks to elvadisas for the bug
  report.]
Fixed an integer overflow in the transparency group code.  [Thanks to
  elvadisas for the bug report.]
Modify Annots::Annots() to skip annotations that have been turned into
  AcroFormFields -- invalid Widget-type annots will now be rendered as
  annots.
Added a missing integer overflow check in the JBIG2 decoder.  [Thanks
  to sangjun for the bug report.]
Added some sanity checks to the JBIG2 decoder.  [Thanks to sangjun and
  ycdxsb for the bug reports.]
Tiling patterns that use non-Normal blend modes can't be cached.
Fixed a bitmap size sanity check in the JBIG2 decoder.  [Thanks to Han
  Zheng (NCNIPC of China, Hexhive), for the bug report.]
Fixed a missing bounds check in FoFiType1C::convertToOpenType (used in
  pdftohtml).  [Thanks to cyth for the bug report.]
Fixed a use-after-free bug in pdftohtml.  [Thanks to FeRDNYC for the
  bug report.]
Merged aconf2.h into aconf.h; corrected the cmake config settings for
  paths; added the BASE14_FONT_DIR config option.  [Thanks to FeRDNYC
  for the suggestions.]
Fixed a missing check for a zero-length index in the CFF (Type1C) font
  parser.  [Thanks to Yuhang Huang (NCNIPC of China), Han Zheng

  (NCNIPC of China, Hexhive), Wanying Cao, Jiayu Zhao (NCNIPC of
  China) for the bug report.]
Add an object loop check to Catalog::countPageTree().
The DCT decoder wasn't checking for an SOF before the first SOS.
  [Thanks to cyth for the bug report.]
The inline image decoder was skipping to end-of-stream in the wrong
  stream object.  [Thanks to cyth for the bug report.]
Fixed a bug in the JPEG 2000 decoder when nLayers > 1 and the
  'termination on each coding pass' flag is set.
Removed the #pragma interface/implementation stuff (which is outdated
  and useless at this point).
Fixed a bug in the ICCBased color space parser that was allowing the
  number of components to be zero.  (CVE-2023-2662)  [Thanks to
  huckleberry for the bug report.]
Added checks for PDF object loops in AcroForm::scanField()
  (CVE-2018-7453, CVE-2018-16369, CVE-2022-36561, CVE-2022-41844),
  Catalog::readPageLabelTree2() (CVE-2023-2663), and
  Catalog::readEmbeddedFileTree() (CVE-2023-2664).
The zero-width character problem can also happen if the page size is
  very large -- that needs to be limited too, the same way as
  character position coordinates.  (CVE-2023-3044) [Thanks to jlinliu
  for the bug report.]
Add some missing bounds check code in DCTStream.  [Thanks to Jiahao
  Liu for the bug report.]
Fix a deadlock when an object stream's length field is contained in
  another object stream.  (CVE-2023-3436) [Thanks to Jiahao Liu for
  the bug report.]
Correctly handle tiling patterns with negative step values.
Ignore overprint in soft masks (to match Adobe's behavior).
```
2024-02-14 22:48:47 +01:00
..
pkg-config
agda-packages.nix
aliases.nix Merge pull request #285047 from Aleksanaa/tootle 2024-02-11 12:15:33 +01:00
all-packages.nix xpdf: 4.04 -> 4.05 2024-02-14 22:48:47 +01:00
beam-packages.nix
by-name-overlay.nix
config.nix
coq-packages.nix coqPackages.vscoq-language-server: init at 2.0.3 (#256515) 2024-02-01 10:10:43 +01:00
cubocore-packages.nix
cuda-packages.nix cudaPackages.cuda{,-library}-samples: move to cuda-modules/ 2024-01-12 20:24:50 +00:00
darwin-packages.nix
default.nix
dhall-packages.nix
dotnet-packages.nix
emacs-packages.nix
emscripten-packages.nix
gnuradio-packages.nix gnuradio: disabledForGRafter -> disabled 2024-01-28 18:22:23 +08:00
hare-third-party.nix Merge pull request #276437 from patwid/hare-ssh 2024-01-16 05:11:46 +01:00
haskell-packages.nix haskell.compiler.ghc8102Binary: remove at 8.10.2 2024-01-25 15:20:35 +01:00
haxe-packages.nix
impure.nix
java-packages.nix javaPackages.jogl_2_4_0: rename to jogl 2024-02-10 18:00:38 +01:00
kodi-packages.nix kodiPackages.sponsorblock: init at 0.5.0 2024-02-07 18:13:36 +08:00
linux-kernels.nix Merge pull request #275805 from oluceps/shufflecake 2024-02-10 10:28:53 -05:00
lua-packages.nix luaPackages.lua-pam: init at unstable-2015-07-03 2024-01-07 18:08:33 +01:00
make-tarball.nix
metrics.nix
nim-overrides.nix
nixpkgs-basic-release-checks.nix release-checks: remove unnecessary escape 2024-01-12 10:28:42 +03:00
ocaml-packages.nix ocamlPackages.capnp: init at 3.6.0 2024-02-07 07:01:55 +01:00
octave-packages.nix
packages-config.nix
perl-packages.nix libvirt: 9.10.0 -> 10.0.0 2024-01-29 22:33:24 +01:00
php-packages.nix php82Extensions.zstd: init at 0.13.3 2024-02-04 20:08:39 +01:00
python2-packages.nix
python-aliases.nix Merge master into staging-next 2024-02-06 00:02:21 +00:00
python-packages.nix Merge pull request #283019 from bcdarwin/update-mne 2024-02-11 10:32:24 -05:00
qt5-packages.nix Merge remote-tracking branch 'origin/master' into staging-next 2024-01-08 16:34:52 +01:00
qt6-packages.nix qt6Packages.wayqt: init at 0.2.0 2024-02-04 10:08:07 +08:00
release-alternatives.nix
release-attrpaths-superset.nix add pkgsExtraHardening package set 2024-01-21 11:16:07 +00:00
release-cross.nix windows.wxMSW: drop 2024-01-06 01:09:13 +01:00
release-cuda.nix
release-haskell.nix haskell.compiler.ghc8102Binary: remove at 8.10.2 2024-01-25 15:20:35 +01:00
release-lib.nix
release-outpaths.nix
release-python.nix
release-r.nix
release-small.nix release-small: drop kvm 2024-01-16 16:19:48 -05:00
release.nix pkgs/top-level/release.nix: expose .build as a direct jobset for hydra 2024-01-26 20:09:43 +00:00
ruby-packages.nix rubyPackages: update 2024-02-10 04:20:00 +00:00
splice.nix
stage.nix add pkgsExtraHardening package set 2024-01-21 11:16:07 +00:00
unixtools.nix xxd: reduce closure size by splitting it into it's own output 2024-01-09 22:29:32 +01:00
wine-packages.nix