mpg123: security bump to version 1.23.8
authorGustavo Zacarias <gustavo@zacarias.com.ar>
Tue, 27 Sep 2016 10:10:20 +0000 (07:10 -0300)
committerPeter Korsgaard <peter@korsgaard.com>
Tue, 27 Sep 2016 14:59:40 +0000 (16:59 +0200)
commitac5fa840df09cf532240df8ef4c773c4d84fa2f7
treee61d531be794d1bef1c88f60add7edd0d6c1636b
parentb62fdfdc274e592675a4894b893841991e72c913
mpg123: security bump to version 1.23.8

Fixes an out-of-bounds memory read in the ID3v2 parser for tags that
claim an unrealistically small length. This crashes mpg123 or any
application using libmpg123 with activated ID3v2 parsing.

Signed-off-by: Gustavo Zacarias <gustavo@zacarias.com.ar>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
package/mpg123/mpg123.hash
package/mpg123/mpg123.mk