From 7a4e228169ba9c6c3d014337dcbf4b6109825f28 Mon Sep 17 00:00:00 2001 From: snj Date: Sat, 16 Apr 2005 19:23:22 +0000 Subject: Pullup ticket 447 - requested by Lubomir Sedlacik security fix for libcdaudio Revisions pulled up: - pkgsrc/audio/libcdaudio/Makefile 1.25 - pkgsrc/audio/libcdaudio/buildlink3.mk 1.3 - pkgsrc/audio/libcdaudio/distinfo 1.11 - pkgsrc/audio/libcdaudio/patches/patch-ac 1.1 Module Name: pkgsrc Committed By: rh Date: Fri Apr 15 01:50:57 UTC 2005 Modified Files: pkgsrc/audio/libcdaudio: Makefile buildlink3.mk distinfo Added Files: pkgsrc/audio/libcdaudio/patches: patch-ac Log Message: Fix vulnerability pointed out in http://secunia.com/advisories/14877/ Bump PKGREVISION Update BUILDLINK_RECOMMENDED --- audio/libcdaudio/Makefile | 3 ++- audio/libcdaudio/buildlink3.mk | 4 ++-- audio/libcdaudio/distinfo | 3 ++- audio/libcdaudio/patches/patch-ac | 13 +++++++++++++ 4 files changed, 19 insertions(+), 4 deletions(-) create mode 100644 audio/libcdaudio/patches/patch-ac (limited to 'audio') diff --git a/audio/libcdaudio/Makefile b/audio/libcdaudio/Makefile index 7f74bf0ea42..34180a9e0ca 100644 --- a/audio/libcdaudio/Makefile +++ b/audio/libcdaudio/Makefile @@ -1,6 +1,7 @@ -# $NetBSD: Makefile,v 1.23 2004/11/26 13:38:30 adam Exp $ +# $NetBSD: Makefile,v 1.23.4.1 2005/04/16 19:23:22 snj Exp $ DISTNAME= libcdaudio-0.99.12 +PKGREVISION= 1 CATEGORIES= audio MASTER_SITES= ${MASTER_SITE_SOURCEFORGE:=libcdaudio/} diff --git a/audio/libcdaudio/buildlink3.mk b/audio/libcdaudio/buildlink3.mk index d6e3d4ec88c..778db75571a 100644 --- a/audio/libcdaudio/buildlink3.mk +++ b/audio/libcdaudio/buildlink3.mk @@ -1,4 +1,4 @@ -# $NetBSD: buildlink3.mk,v 1.2 2004/10/03 00:13:07 tv Exp $ +# $NetBSD: buildlink3.mk,v 1.2.4.1 2005/04/16 19:23:22 snj Exp $ BUILDLINK_DEPTH:= ${BUILDLINK_DEPTH}+ LIBCDAUDIO_BUILDLINK3_MK:= ${LIBCDAUDIO_BUILDLINK3_MK}+ @@ -12,7 +12,7 @@ BUILDLINK_PACKAGES+= libcdaudio .if !empty(LIBCDAUDIO_BUILDLINK3_MK:M+) BUILDLINK_DEPENDS.libcdaudio+= libcdaudio>=0.99.4nb1 -BUILDLINK_RECOMMENDED.libcdaudio+= libcdaudio>=0.99.10nb1 +BUILDLINK_RECOMMENDED.libcdaudio+= libcdaudio>=0.99.12nb1 BUILDLINK_PKGSRCDIR.libcdaudio?= ../../audio/libcdaudio .endif # LIBCDAUDIO_BUILDLINK3_MK diff --git a/audio/libcdaudio/distinfo b/audio/libcdaudio/distinfo index c6e9724c0cc..4a53a475ddf 100644 --- a/audio/libcdaudio/distinfo +++ b/audio/libcdaudio/distinfo @@ -1,7 +1,8 @@ -$NetBSD: distinfo,v 1.10 2005/02/23 20:39:47 agc Exp $ +$NetBSD: distinfo,v 1.10.2.1 2005/04/16 19:23:22 snj Exp $ SHA1 (libcdaudio-0.99.12.tar.gz) = 1862d3f387634a216faa867164d840b6f5552294 RMD160 (libcdaudio-0.99.12.tar.gz) = 57f7446db6c65c968eb58a9404652718d6517b74 Size (libcdaudio-0.99.12.tar.gz) = 357150 bytes SHA1 (patch-aa) = 1054c1b5854dfb2484e55d2e56bd0b46d5615505 SHA1 (patch-ab) = 9df8c234de3cb5a6b262fae093e430e471afa1f0 +SHA1 (patch-ac) = 073ceed3794fbd889b0efec49cd2dfe63c7fda07 diff --git a/audio/libcdaudio/patches/patch-ac b/audio/libcdaudio/patches/patch-ac new file mode 100644 index 00000000000..ff4a4cf707b --- /dev/null +++ b/audio/libcdaudio/patches/patch-ac @@ -0,0 +1,13 @@ +$NetBSD: patch-ac,v 1.1.2.2 2005/04/16 19:23:22 snj Exp $ + +--- src/cddb.c.orig 2004-09-09 11:26:39.000000000 +1000 ++++ src/cddb.c +@@ -1052,7 +1052,7 @@ cddb_query(int cd_desc, int sock, + } + + query->query_matches = 0; +- while(!cddb_read_line(sock, inbuffer, 256)) { ++ while(query->query_matches < MAX_INEXACT_MATCHES && !cddb_read_line(sock, inbuffer, 256)) { + slashed = 0; + if(strchr(inbuffer, '/') != NULL && parse_disc_artist) { + index = 0; -- cgit v1.2.3