Path to this page:
Subject: CVS commit: [pkgsrc-2019Q2] pkgsrc/audio/libsndfile
From: Benny Siegert
Date: 2019-07-18 15:08:19
Message id: 20190718130819.E5B4AFBF4@cvs.NetBSD.org
Log Message:
Pullup ticket #5998 - requested by nia
audio/libsndfile: security fix
Revisions pulled up:
- audio/libsndfile/Makefile 1.76
- audio/libsndfile/distinfo 1.43
- audio/libsndfile/patches/patch-CVE-2017-14634 1.1
- audio/libsndfile/patches/patch-CVE-2018-13139 1.1
- audio/libsndfile/patches/patch-src_alaw.c 1.1
- audio/libsndfile/patches/patch-src_ulaw.c 1.1
- audio/libsndfile/patches/patch-src_wav.c 1.1
---
Module Name: pkgsrc
Committed By: nia
Date: Sun Jul 14 15:39:32 UTC 2019
Modified Files:
pkgsrc/audio/libsndfile: Makefile distinfo
Added Files:
pkgsrc/audio/libsndfile/patches: patch-CVE-2017-14634
patch-CVE-2018-13139 patch-src_alaw.c patch-src_ulaw.c
patch-src_wav.c
Log Message:
libsndfile: Apply patches from upstream's github for these CVEs:
CVE-2017-14245 - information-disclosure
CVE-2017-14246 - information-disclosure
CVE-2017-14634 - denial-of-service
CVE-2017-17456 - denial-of-service
CVE-2017-17457 - denial-of-service
CVE-2017-8362 - denial-of-service
CVE-2017-8363 - heap-overflow
CVE-2017-8365 - buffer-overflow
CVE-2018-13139 - stack-overflow
CVE-2018-19432 - null-pointer-dereference
CVE-2018-19661 - denial-of-service
CVE-2018-19662 - denial-of-service
CVE-2018-19758 - denial-of-service
CVE-2019-3832 - denial-of-service
Bump PKGREVISION.
Files: