package/wavpack: security bump to version 5.4.0
authorFabrice Fontaine <fontaine.fabrice@gmail.com>
Wed, 13 Jan 2021 06:45:11 +0000 (07:45 +0100)
committerPeter Korsgaard <peter@korsgaard.com>
Wed, 13 Jan 2021 09:05:02 +0000 (10:05 +0100)
WavPack 5.4.0 contains a fix for CVE-2020-35738 wherein a specially
crafted WAV file could cause the WAVPACK command-line program to crash
with an out-of-bounds write (see issue #91).

Update hash of COPYING (update in year:
https://github.com/dbry/WavPack/commit/2ce3c069be548e82ea9c05741ace6583e549c6de)

https://github.com/dbry/WavPack/blob/5.4.0/NEWS

Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
package/wavpack/wavpack.hash
package/wavpack/wavpack.mk

index eeef7303211f41e1927dff78a01cb1264537024d..abc9ab69059aab754c2d8e97e53d876c555908c2 100644 (file)
@@ -1,3 +1,3 @@
 # locally computed hash
-sha256  b444379a0bee0330f137cb3e9a100e6a12a63a6d01987ba66b3729f85e282307  wavpack-5.3.0.tar.xz
-sha256  a0bbe245dfe263f73946b72306e8336818009ff1e52b119784c288f2785fc260  COPYING
+sha256  4bde6a6b2a86614a6bd2579e60dcc974e2c8f93608d2281110a717c1b3c28b79  wavpack-5.4.0.tar.xz
+sha256  f38defde000d62c4ff158f1445cb85a0c2f67cbc1d3cfa34ed882f439f6e3b43  COPYING
index 6403f93ac9e5083304783077eab97046f09c22e9..d44982232d96cae85b78a806bdf45b5df1c6c781 100644 (file)
@@ -4,7 +4,7 @@
 #
 ################################################################################
 
-WAVPACK_VERSION = 5.3.0
+WAVPACK_VERSION = 5.4.0
 WAVPACK_SITE = \
        https://github.com/dbry/WavPack/releases/download/$(WAVPACK_VERSION)
 WAVPACK_SOURCE = wavpack-$(WAVPACK_VERSION).tar.xz