Path to this page:
Subject: CVS commit: [pkgsrc-2019Q2] pkgsrc/audio/mpg123
From: Benny Siegert
Date: 2019-09-03 11:33:05
Message id: 20190903093305.B1ED8FBF4@cvs.NetBSD.org
Log Message:
Pullup ticket #6034 - requested by nia
audio/mpg123: security fix
Revisions pulled up:
- audio/mpg123/Makefile.common 1.50
- audio/mpg123/distinfo 1.50
---
Module Name: pkgsrc
Committed By: nia
Date: Sat Aug 31 14:24:19 UTC 2019
Modified Files:
pkgsrc/audio/mpg123: Makefile.common distinfo
Log Message:
mpg123: Update to 1.25.12
libmpg123:
Fix an out-of-bounds read of maximal two bytes for truncated RVA2 frames \
(oss-fuzz-bug 15975). The earlier fix around the same location needed one \
thought more. Actually, another though was needed, oss-fuzz-bug 16009 documents \
the incomplete fix.
Fix an invalid write of one zero byte for empty ID3v2 frames that demand \
de-unsyncing (oss-fuzz-bug 16050).
Correct preprocessor syntax in mangle.h, no #error in a #define line. \
(bug 273, thanks to nmlgc).
Files: