Subject: CVS commit: [pkgsrc-2019Q2] pkgsrc/audio/libsndfile
From: Benny Siegert
Date: 2019-07-18 15:08:19
Message id: 20190718130819.E5B4AFBF4@cvs.NetBSD.org

Log Message:
Pullup ticket #5998 - requested by nia
audio/libsndfile: security fix

Revisions pulled up:
- audio/libsndfile/Makefile                                     1.76
- audio/libsndfile/distinfo                                     1.43
- audio/libsndfile/patches/patch-CVE-2017-14634                 1.1
- audio/libsndfile/patches/patch-CVE-2018-13139                 1.1
- audio/libsndfile/patches/patch-src_alaw.c                     1.1
- audio/libsndfile/patches/patch-src_ulaw.c                     1.1
- audio/libsndfile/patches/patch-src_wav.c                      1.1

---
   Module Name:	pkgsrc
   Committed By:	nia
   Date:		Sun Jul 14 15:39:32 UTC 2019

   Modified Files:
   	pkgsrc/audio/libsndfile: Makefile distinfo
   Added Files:
   	pkgsrc/audio/libsndfile/patches: patch-CVE-2017-14634
   	    patch-CVE-2018-13139 patch-src_alaw.c patch-src_ulaw.c
   	    patch-src_wav.c

   Log Message:
   libsndfile: Apply patches from upstream's github for these CVEs:

   CVE-2017-14245 - information-disclosure
   CVE-2017-14246 - information-disclosure
   CVE-2017-14634 - denial-of-service
   CVE-2017-17456 - denial-of-service
   CVE-2017-17457 - denial-of-service
   CVE-2017-8362 - denial-of-service
   CVE-2017-8363 - heap-overflow
   CVE-2017-8365 - buffer-overflow
   CVE-2018-13139 - stack-overflow
   CVE-2018-19432 - null-pointer-dereference
   CVE-2018-19661 - denial-of-service
   CVE-2018-19662 - denial-of-service
   CVE-2018-19758 - denial-of-service
   CVE-2019-3832 - denial-of-service

   Bump PKGREVISION.

Files:
RevisionActionfile
1.75.20.1modifypkgsrc/audio/libsndfile/Makefile
1.42.20.1modifypkgsrc/audio/libsndfile/distinfo
1.1.2.2addpkgsrc/audio/libsndfile/patches/patch-CVE-2017-14634
1.1.2.2addpkgsrc/audio/libsndfile/patches/patch-CVE-2018-13139
1.1.2.2addpkgsrc/audio/libsndfile/patches/patch-src_alaw.c
1.1.2.2addpkgsrc/audio/libsndfile/patches/patch-src_ulaw.c
1.1.2.2addpkgsrc/audio/libsndfile/patches/patch-src_wav.c