package/mpg123: security bump to version 1.25.10
authorBernd Kuhls <bernd.kuhls@t-online.de>
Sun, 10 Jun 2018 12:09:10 +0000 (14:09 +0200)
committerThomas Petazzoni <thomas.petazzoni@bootlin.com>
Sun, 10 Jun 2018 12:14:34 +0000 (14:14 +0200)
Version 1.25.4 fixes CVE-2017-9545, for details see release notes:
http://www.mpg123.org/cgi-bin/news.cgi

Added upstream hashes.

Signed-off-by: Bernd Kuhls <bernd.kuhls@t-online.de>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
package/mpg123/mpg123.hash
package/mpg123/mpg123.mk

index cbab6f3ee904eed3f5ba6e01e43cc0ea6ed1c8c9..22db5bca3cd6a5a22402836489d2dc3fcbcbd875 100644 (file)
@@ -1,5 +1,7 @@
-# Locally calculated after checking pgp signature
-sha256 5314b0fb8ad291bfc79ff4c5c321b971916819a65233ec065434358fcf8aee38        mpg123-1.25.2.tar.bz2
-
+# From https://sourceforge.net/projects/mpg123/files/mpg123/1.25.10/
+sha1 604784ddbcfe282bffdc595d1d45c677c7cf381f  mpg123-1.25.10.tar.bz2
+md5 ea32caa61d41d8be797f0b04a1b43ad9  mpg123-1.25.10.tar.bz2
+# Locally calculated
+sha256 6c1337aee2e4bf993299851c70b7db11faec785303cfca3a5c3eb5f329ba7023  mpg123-1.25.10.tar.bz2
 # License file
 sha256  f40e0dd86b27b52e429b693a87b3ca63ae0a98a4d142e77207aa6bdf1db7a295  COPYING
index 01923d799049bab0a11b2be30f50c030513b4fe0..dd2d39d97841c3c4c6007c66930aa46b4dfb76c4 100644 (file)
@@ -4,7 +4,7 @@
 #
 ################################################################################
 
-MPG123_VERSION = 1.25.2
+MPG123_VERSION = 1.25.10
 MPG123_SOURCE = mpg123-$(MPG123_VERSION).tar.bz2
 MPG123_SITE = http://downloads.sourceforge.net/project/mpg123/mpg123/$(MPG123_VERSION)
 MPG123_CONF_OPTS = --disable-lfs-alias