summaryrefslogtreecommitdiff
AgeCommit message (Collapse)AuthorLines
2017-06-06release v2.192.19Daniel Friesel-0/+10
2017-06-06install feh icons with the correct permissions (644) (closes #301)Daniel Friesel-0/+2
2017-06-01feh(1): files are saved in the current working directory (closes #300)Daniel Friesel-7/+6
2017-04-16feh(1): Note that --fullscreen and --scale-down do not affect thumbnail listsDaniel Friesel-1/+8
closes #270
2017-04-16Merge branch 'Ferada-xdg-thumbnails'Daniel Friesel-31/+76
2017-04-16Thumbnail generation: Handle HOME-less users (and some other edge cases)Daniel Friesel-2/+12
2017-04-06Fix indentation.Olof-Joachim Frahm-6/+6
2017-04-05Use temporary file to create thumbnail.Olof-Joachim Frahm-6/+18
2017-04-05`sizeof(char)` is defined to be 1.Olof-Joachim Frahm-1/+1
2017-04-05Use XDG_CACHE_HOME for thumbnails.Olof-Joachim Frahm-22/+45
2017-04-04version bump2.18.3Daniel Friesel-1/+2
2017-04-03changelogDaniel Friesel-0/+7
2017-04-02replace _emalloc with emalloc (is the same unless DMALLOC is used)Daniel Friesel-2/+2
2017-04-02Merge pull request #290 from stoeckmann/emallocDaniel Friesel-1/+1
Check malloc return value for NULL.
2017-04-02Merge pull request #289 from stoeckmann/memory-leakDaniel Friesel-0/+2
Fixed memory leak on file name collision.
2017-04-02Merge pull request #288 from stoeckmann/strncpyDaniel Friesel-6/+12
Always terminate strncpy results with '\0'.
2017-04-02Merge pull request #287 from stoeckmann/empty-fileDaniel Friesel-2/+2
Avoid out of boundary read on empty/broken file.
2017-04-02Check malloc return value for NULL.Tobias Stoeckmann-1/+1
If malloc cannot allocate enough memory, it could return NULL. This is not necessarily true for default Linux settings, but can be provoked there as well by adjusting proc entries. Other systems like the *BSD ones definitely do this. The function _emalloc exists for exactly this purpose, so use it instead of calling malloc directly. Signed-off-by: Tobias Stoeckmann <tobias@stoeckmann.org>
2017-04-02Fixed memory leak on file name collision.Tobias Stoeckmann-0/+2
If feh_unique_filename encounters a file that already exists, the memory for the temporary filename is not released. As this happens in /tmp at some code places, an attacker could use this to spray the memory of feh, or simply triggering an out of memory condition. Signed-off-by: Tobias Stoeckmann <tobias@stoeckmann.org>
2017-04-02Avoid out of boundary read on empty/broken file.Tobias Stoeckmann-2/+2
If ereadfile encounters an empty file or the file could not be read, an out ouf boundary read (and possible write) occurs. Always check the return value of fread to be > 0 before processing the result buffer. Signed-off-by: Tobias Stoeckmann <tobias@stoeckmann.org>
2017-04-02Always terminate strncpy results with '\0'.Tobias Stoeckmann-6/+12
The strncpy function does not guarantee to end the resulting character sequence with a terminating nul character if not enough space is available. This could be triggered by supplying a sufficiently long output_file option. Signed-off-by: Tobias Stoeckmann <tobias@stoeckmann.org>
2017-04-01changelogDaniel Friesel-0/+9
2017-03-29Merge pull request #286 from stoeckmann/ipcDaniel Friesel-1/+1
Fix double-free/OOB-write while receiving IPC data
2017-03-23Fix double-free/OOB-write while receiving IPC dataTobias Stoeckmann-1/+1
If a malicious client pretends to be the E17 window manager, it is possible to trigger an out of boundary heap write while receiving an IPC message. The length of the already received message is stored in an unsigned short, which overflows after receiving 64 KB of data. It's comparably small amount of data and therefore achievable for an attacker. When len overflows, realloc() will either be called with a small value and therefore chars will be appended out of bounds, or len + 1 will be exactly 0, in which case realloc() behaves like free(). This could be abused for a later double-free attack as it's even possible to overwrite the free information -- but this depends on the malloc implementation. Signed-off-by: Tobias Stoeckmann <tobias@stoeckmann.org>
2017-02-26Also update window title for thumbnail windows (closes #280)Daniel Friesel-3/+22
2017-02-23Fix memory leak when closing images opened from thumbnail modeDaniel Friesel-0/+3
2017-02-16I made a derp2.18.2Daniel Friesel-1/+7
2017-01-22release v2.18.12.18.1Daniel Friesel-2/+3
2017-01-15feh(1): Update giflib notesDaniel Friesel-4/+5
2017-01-14ChangelogDaniel Friesel-0/+5
2017-01-12Pass windidget to feh_action_run, making it possible to use format specifiersANogin-10/+10
like %o and %z in slideshow actions (I would like to use this to zoom in, pan, and then use an action to crop the window to zoomed in view).
2017-01-11rewrite window title whenever the image is rendered (closes #266)Daniel Friesel-0/+8
2017-01-02feh(1): Move --index-info to INDEX AND THUMBNAIL MODE OPTIONS (closes #267)Daniel Friesel-26/+28
2016-12-07feh(1): Add note about background setting in GNOME (#225)Daniel Friesel-0/+11
2016-12-07feh.desktop: Use %U, not %F, since we also support URLs (closes #264)Daniel Friesel-1/+1
2016-11-01Release v2.182.18Daniel Friesel-3/+4
2016-10-31feh(1): Add --auto-rotateDaniel Friesel-0/+5
2016-10-30changelogDaniel Friesel-0/+8
2016-10-30Merge branch 'teleshoes-autorotate'Daniel Friesel-12/+21
2016-10-30imlib.c: Move orientation logic inside HAVE_LIBEXIFDaniel Friesel-2/+2
2016-10-29Revert "config: exif 0 => 1"Daniel Friesel-1/+1
This reverts commit 465238bdddb11d00926dcaa76ffe2f59fb536df5.
2016-10-29add cmdline opt --auto-rotate to rotate according to EXIF infoElliot Wolk-1/+7
2016-10-29config: exif 0 => 1Elliot Wolk-1/+1
2016-10-29imlib: fix autorotate EXIF parsingElliot Wolk-12/+15
2016-10-24thumbnail mode: Add a debug printf for thumbnail image sizeDaniel Friesel-0/+1
2016-10-17Merge branch 'ErnieE5-master'Daniel Friesel-5/+22
2016-10-17Properly initialize zoom_fill key binding, set it to ! (exclamation mark)Daniel Friesel-1/+2
2016-10-15Added missing man updateErnie Ewert-0/+5
2016-10-15Added a "zoom fit" key binding for the current image.Ernie Ewert-5/+16
Fixed(?) Makefile document build issue for README.md
2016-10-01feh(1): Remove accidentally copypasted debug info from exif=1 noteDaniel Friesel-1/+1