X-Original-To: alpine-aports@lists.alpinelinux.org Received: from mail-lf0-f65.google.com (mail-lf0-f65.google.com [209.85.215.65]) by lists.alpinelinux.org (Postfix) with ESMTP id D199C5C434E for ; Mon, 6 Feb 2017 14:33:33 +0000 (GMT) Received: by mail-lf0-f65.google.com with SMTP id v186so4131474lfa.2 for ; Mon, 06 Feb 2017 06:33:33 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=from:to:cc:subject:date:message-id; bh=uPS2ouUZcA7miYDDjNEfWYPUDtOG+xh18Rz/cLHHqIs=; b=W0Wcf0tb2Tp44FxtNNo6756620XON8JXhYAzOX1nGKiA0sKdzglPsRW5EoJwBR3qwC oPcnNggdZ2Nm7T/DetChHxtXL2Z5yTTU5FqHNdVp/KDTyt/DDPef7Z6yqFNUXgThbRR+ KjCzFJz44wHIQq5TDkJbWIOGU4ys7qsiX/U4cvXEnFKSUOoojwwCu5uTn0an64InR+PE JZvtZtEVTAMwS/4cI0/AZeoouPsdPbF9W71XM0gvhzLg69AmtCUF6soaEmf40wPoXGmr ASb5yHrd+g9eSDUKuOvGBXRnLuhYR/EU9g34hlo5VCF76uXf62HyobfloIQZT6RKGuTp OtsA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:from:to:cc:subject:date:message-id; bh=uPS2ouUZcA7miYDDjNEfWYPUDtOG+xh18Rz/cLHHqIs=; b=oqvQ04bZu4C8CRp56gOxGhqxY9SzjvIbjgUTmGB4qLMXm6+ovl6Nb7hOPyeJsMaDaK bOt1YnzeNOt1rAVEhCj2mkdK7I/bkQnpLZM5q2ZgYBlTO9n5Trq+gvbK7vBbqLc0q/8b L608rIOIhRHAgShu2ltt19z5NsKbfmbCJm1t6wlFBp+CaTZxm2In+E4gahop2HCUT0Ya uT9yBL+VPcDGxalfHiDfZkIW8+WCe63X08RzVaaOGPdugu2Rw8QJiSPf3Rs/mIgiRlo1 sHaZlCHpHfEgk3R4/D+IG+6xNyspdARjhnDeYyc3Lfls1c6z5f6KT0oHNpv5/HNBAxDe Awkw== X-Gm-Message-State: AIkVDXISNdyPdKZSWQ5NpAkbS1Z+yQ88TQhU5WZUxG9rE6bE3tTy/VA9zS0U7hBkv7V2zg== X-Received: by 10.46.7.25 with SMTP id 25mr4035571ljh.41.1486391612973; Mon, 06 Feb 2017 06:33:32 -0800 (PST) Received: from v3-2.util.wtbts.net ([83.145.235.199]) by smtp.gmail.com with ESMTPSA id c65sm325737ljd.44.2017.02.06.06.33.32 (version=TLS1_2 cipher=ECDHE-RSA-AES128-SHA bits=128/128); Mon, 06 Feb 2017 06:33:32 -0800 (PST) From: Sergei Lukin To: alpine-aports@lists.alpinelinux.org Cc: Sergei Lukin Subject: [alpine-aports] [PATCH v3.2] main/wavpack: security upgrade to 5.1.0 - fixes #6821 Date: Mon, 6 Feb 2017 14:33:11 +0000 Message-Id: <1486391591-15531-1-git-send-email-sergej.lukin@gmail.com> X-Mailer: git-send-email 2.4.11 X-Mailinglist: alpine-aports Precedence: list List-Id: Alpine Development List-Unsubscribe: List-Post: List-Help: List-Subscribe: CVE-2016-10169: global buffer overread in read_code / read_words.c CVE-2016-10170: Heap out of bounds read in WriteCaffHeader / caff.c CVE-2016-10171: heap out of bounds read in unreorder_channels / wvunpack.c CVE-2016-10172: Heap out of bounds read in read_new_config_info / open_utils.c --- A comment from upstream says: The current release [5.1.0] has been extensively tested by AFL and is probably the most robust WavPack release to date. It is also 100% functionally compatible with 4.80 (no broken apps). https://github.com/dbry/WavPack/commit/4bc05fc490b66ef2d45b1de26abf1455b486b0dc#commitcomment-20691383 http://www.wavpack.com/changelog.txt main/wavpack/APKBUILD | 25 ++++++++++++++----------- 1 file changed, 14 insertions(+), 11 deletions(-) diff --git a/main/wavpack/APKBUILD b/main/wavpack/APKBUILD index 86aa3e6..ff92c64 100644 --- a/main/wavpack/APKBUILD +++ b/main/wavpack/APKBUILD @@ -1,8 +1,9 @@ +# Contributor: Sergei Lukin # Contributor: Carlo Landmeter # Maintainer: Natanael Copa pkgname=wavpack -pkgver=4.70.0 -pkgrel=3 +pkgver=5.1.0 +pkgrel=0 pkgdesc="Audio compression format with lossless, lossy, and hybrid compression modes" url="http://www.wavpack.com/" arch="all" @@ -11,13 +12,18 @@ depends="" makedepends="autoconf automake libtool" install= subpackages="$pkgname-dev $pkgname-doc" -source="http://www.wavpack.com/${pkgname}-${pkgver}.tar.bz2 - iconv-underlinking.patch" +source="http://www.wavpack.com/${pkgname}-${pkgver}.tar.bz2" + +# secfixes: +# 5.1.0-r0: +# - CVE-2016-10169 +# - CVE-2016-10170 +# - CVE-2016-10171 +# - CVE-2016-10172 _builddir="$srcdir"/$pkgname-$pkgver prepare() { cd "$_builddir" - update_config_sub || return 1 for i in $source; do case $i in *.patch) msg $i; patch -p1 -i "$srcdir"/$i || return 1;; @@ -53,9 +59,6 @@ package() { rm "$pkgdir"/usr/lib/*.la } -md5sums="4c0186ef0dc8367ce5cd7cc0f398b714 wavpack-4.70.0.tar.bz2 -262979a78da1ff825243352c7bfb691e iconv-underlinking.patch" -sha256sums="2cade379b0aba99fbc4e442ccc6dac6c609f6212e46516a083e24c8c364430a4 wavpack-4.70.0.tar.bz2 -e6245c0ee10fa6600dbe7947fb1cb5cf8fad7b3b0409d026ead0c1faf6ac11e0 iconv-underlinking.patch" -sha512sums="6a93e36b3bea5b410142416b4b0329c5f65031418cdd303d395ca2aaad2a1ab02987b9a329dec6d14fe9387a3d5978caaf6345056eece24c5ad0ae9273349449 wavpack-4.70.0.tar.bz2 -d0af2b03753ecfec1a9e36460dd85970c4cae0b6dec36ac7e6a7a9a06aaa22e19467224104f3c6b14efdd59a4df28f2c6e6177866ce2b7feed1b7c4b7bb5f33c iconv-underlinking.patch" +md5sums="7f06272651f0c2292c1d0ba353386782 wavpack-5.1.0.tar.bz2" +sha256sums="1939627d5358d1da62bc6158d63f7ed12905552f3a799c799ee90296a7612944 wavpack-5.1.0.tar.bz2" +sha512sums="4c31616ae63c3a875afa20f26ce935f7a8f9921e2892b4b8388eca3ccd83b2d686f43eed8b9ec1dead934a1148401b9dced3b05f509b7942c48d7af31cf80a54 wavpack-5.1.0.tar.bz2" -- 2.4.11 --- Unsubscribe: alpine-aports+unsubscribe@lists.alpinelinux.org Help: alpine-aports+help@lists.alpinelinux.org ---