From ffc967d9e8097739d9d441459ab3db201cf530e2 Mon Sep 17 00:00:00 2001 From: snj Date: Tue, 21 Mar 2017 08:00:26 +0000 Subject: prune patch for CVE-2017-5847, which is already part of 1.10.4. --- multimedia/gst-plugins1-ugly/distinfo | 3 +- .../patches/patch-gst_asfdemux_gstasfdemux.c | 36 ---------------------- 2 files changed, 1 insertion(+), 38 deletions(-) delete mode 100644 multimedia/gst-plugins1-ugly/patches/patch-gst_asfdemux_gstasfdemux.c (limited to 'multimedia') diff --git a/multimedia/gst-plugins1-ugly/distinfo b/multimedia/gst-plugins1-ugly/distinfo index ed8aa552e65..605258b681c 100644 --- a/multimedia/gst-plugins1-ugly/distinfo +++ b/multimedia/gst-plugins1-ugly/distinfo @@ -1,8 +1,7 @@ -$NetBSD: distinfo,v 1.25 2017/03/16 14:35:23 wiz Exp $ +$NetBSD: distinfo,v 1.26 2017/03/21 08:00:26 snj Exp $ SHA1 (gst-plugins-ugly-1.10.4.tar.xz) = a01ab3ac71bdd0d52e4a120349a8f26fde48f317 RMD160 (gst-plugins-ugly-1.10.4.tar.xz) = f47d6fd3dfed385fdd9e389c6b7f23e856c31c15 SHA512 (gst-plugins-ugly-1.10.4.tar.xz) = 7d8d47c7d5c3bfc7ae549abb6ee7f3812b9a46c114057d42eed46af03c6f1354d9190df9ba58ac810251dab87f95d128c754209961e3b62f5aa7bd9d88836cb6 Size (gst-plugins-ugly-1.10.4.tar.xz) = 908424 bytes SHA1 (patch-configure) = 4bba5af550b211d45533ee001fb1bc77bcfa6213 -SHA1 (patch-gst_asfdemux_gstasfdemux.c) = 6ec643fbb59b27b87b2621a2b2aaff6a0c3939af diff --git a/multimedia/gst-plugins1-ugly/patches/patch-gst_asfdemux_gstasfdemux.c b/multimedia/gst-plugins1-ugly/patches/patch-gst_asfdemux_gstasfdemux.c deleted file mode 100644 index d05ba179da3..00000000000 --- a/multimedia/gst-plugins1-ugly/patches/patch-gst_asfdemux_gstasfdemux.c +++ /dev/null @@ -1,36 +0,0 @@ -$NetBSD: patch-gst_asfdemux_gstasfdemux.c,v 1.1 2017/03/06 08:01:40 snj Exp $ - -CVE-2017-5847 - -https://github.com/GStreamer/gst-plugins-ugly/commit/d21017b52a585f145e8d62781bcc1c5fefc7ee37 - ---- gst/asfdemux/gstasfdemux.c.orig 2017-01-30 05:41:35.000000000 -0800 -+++ gst/asfdemux/gstasfdemux.c 2017-03-05 23:45:12.000000000 -0800 -@@ -3439,7 +3439,12 @@ gst_asf_demux_process_ext_content_desc ( - break; - } - case ASF_DEMUX_DATA_TYPE_DWORD:{ -- guint uint_val = GST_READ_UINT32_LE (value); -+ guint uint_val; -+ -+ if (value_len < 4) -+ break; -+ -+ uint_val = GST_READ_UINT32_LE (value); - - /* this is the track number */ - g_value_init (&tag_value, G_TYPE_UINT); -@@ -3453,7 +3458,12 @@ gst_asf_demux_process_ext_content_desc ( - } - /* Detect 3D */ - case ASF_DEMUX_DATA_TYPE_BOOL:{ -- gboolean bool_val = GST_READ_UINT32_LE (value); -+ gboolean bool_val; -+ -+ if (value_len < 4) -+ break; -+ -+ bool_val = GST_READ_UINT32_LE (value); - - if (strncmp ("Stereoscopic", name_utf8, strlen (name_utf8)) == 0) { - if (bool_val) { -- cgit v1.2.3