libsndfile: security bump to version 1.0.26
authorGustavo Zacarias <gustavo@zacarias.com.ar>
Tue, 15 Dec 2015 17:44:45 +0000 (14:44 -0300)
committerThomas Petazzoni <thomas.petazzoni@free-electrons.com>
Tue, 15 Dec 2015 20:36:02 +0000 (21:36 +0100)
Fixes:
CVE-2014-9496 - SD2 buffer read overflow.
CVE-2014-9756 - file_io.c divide by zero.
CVE-2015-7805 - AIIF heap write overflow.

Signed-off-by: Gustavo Zacarias <gustavo@zacarias.com.ar>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@free-electrons.com>
package/libsndfile/libsndfile.hash
package/libsndfile/libsndfile.mk

index a19c2620c6b0f631c30c8266483def98089a72b9..04d091b58bc1b4b19305beac7339691cf29d8e74 100644 (file)
@@ -1,2 +1,2 @@
 # Locally calculated after checking pgp signature
-sha256 59016dbd326abe7e2366ded5c344c853829bebfd1702ef26a07ef662d6aa4882        libsndfile-1.0.25.tar.gz
+sha256 cd6520ec763d1a45573885ecb1f8e4e42505ac12180268482a44b28484a25092        libsndfile-1.0.26.tar.gz
index 88db57696fd603a43d32fd41688d1ee3e2a167bb..107a356604fee9daa586b23fecf0dd3cbe5bd647 100644 (file)
@@ -4,7 +4,7 @@
 #
 ################################################################################
 
-LIBSNDFILE_VERSION = 1.0.25
+LIBSNDFILE_VERSION = 1.0.26
 LIBSNDFILE_SITE = http://www.mega-nerd.com/libsndfile/files
 LIBSNDFILE_INSTALL_STAGING = YES
 LIBSNDFILE_LICENSE = LGPLv2.1+