Subject: CVS commit: [pkgsrc-2019Q2] pkgsrc/audio/mpg123
From: Benny Siegert
Date: 2019-09-03 11:33:05
Message id: 20190903093305.B1ED8FBF4@cvs.NetBSD.org

Log Message:
Pullup ticket #6034 - requested by nia
audio/mpg123: security fix

Revisions pulled up:
- audio/mpg123/Makefile.common                                  1.50
- audio/mpg123/distinfo                                         1.50

---
   Module Name:	pkgsrc
   Committed By:	nia
   Date:		Sat Aug 31 14:24:19 UTC 2019

   Modified Files:
   	pkgsrc/audio/mpg123: Makefile.common distinfo

   Log Message:
   mpg123: Update to 1.25.12

   libmpg123:

       Fix an out-of-bounds read of maximal two bytes for truncated RVA2 frames \ 
(oss-fuzz-bug 15975). The earlier fix around the same location needed one \ 
thought more. Actually, another though was needed, oss-fuzz-bug 16009 documents \ 
the incomplete fix.
       Fix an invalid write of one zero byte for empty ID3v2 frames that demand \ 
de-unsyncing (oss-fuzz-bug 16050).
       Correct preprocessor syntax in mangle.h, no #error in a #define line. \ 
(bug 273, thanks to nmlgc).

Files:
RevisionActionfile
1.48.10.2modifypkgsrc/audio/mpg123/Makefile.common
1.48.10.2modifypkgsrc/audio/mpg123/distinfo