mpg123: security bump to version 1.23.8
authorGustavo Zacarias <gustavo@zacarias.com.ar>
Tue, 27 Sep 2016 10:10:20 +0000 (07:10 -0300)
committerPeter Korsgaard <peter@korsgaard.com>
Tue, 27 Sep 2016 14:59:40 +0000 (16:59 +0200)
Fixes an out-of-bounds memory read in the ID3v2 parser for tags that
claim an unrealistically small length. This crashes mpg123 or any
application using libmpg123 with activated ID3v2 parsing.

Signed-off-by: Gustavo Zacarias <gustavo@zacarias.com.ar>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
package/mpg123/mpg123.hash
package/mpg123/mpg123.mk

index 66a80ac70fb4dd03156962b765ac5f2b9eda9990..fa5580948cc1a91cc04a2b59483aa33f487e276e 100644 (file)
@@ -1,2 +1,2 @@
 # Locally calculated after checking pgp signature
-sha256 934047120953159e364c790e059684b681d7e670884fe179e1954d17d1c6334b        mpg123-1.23.7.tar.bz2
+sha256 de2303c8ecb65593e39815c0a2f2f2d91f708c43b85a55fdd1934c82e677cf8e        mpg123-1.23.8.tar.bz2
index b14efe7fa3c035c22897f3f5a0fcb330defd3c36..27c46dcbc724df9d1661a57719e2254e71ee5093 100644 (file)
@@ -4,7 +4,7 @@
 #
 ################################################################################
 
-MPG123_VERSION = 1.23.7
+MPG123_VERSION = 1.23.8
 MPG123_SOURCE = mpg123-$(MPG123_VERSION).tar.bz2
 MPG123_SITE = http://downloads.sourceforge.net/project/mpg123/mpg123/$(MPG123_VERSION)
 MPG123_CONF_OPTS = --disable-lfs-alias