Compare commits

..

No commits in common. "c8s" and "imports/c8-beta/vorbis-tools-1.4.0-28.el8" have entirely different histories.

15 changed files with 3 additions and 31 deletions

2
.gitignore vendored
View File

@ -1 +1 @@
vorbis-tools-1.4.0.tar.gz SOURCES/vorbis-tools-1.4.0.tar.gz

1
.vorbis-tools.metadata Normal file
View File

@ -0,0 +1 @@
fc6a820bdb5ad6fcac074721fab5c3f96eaf6562 SOURCES/vorbis-tools-1.4.0.tar.gz

View File

@ -1,7 +1,7 @@
Summary: The Vorbis General Audio Compression Codec tools Summary: The Vorbis General Audio Compression Codec tools
Name: vorbis-tools Name: vorbis-tools
Version: 1.4.0 Version: 1.4.0
Release: 29%{?dist} Release: 28%{?dist}
Epoch: 1 Epoch: 1
Group: Applications/Multimedia Group: Applications/Multimedia
License: GPLv2 License: GPLv2
@ -27,9 +27,6 @@ Patch5: vorbis-tools-1.4.0-CVE-2014-9638-CVE-2014-9639.patch
# oggenc: fix large alloca on bad AIFF input (CVE-2015-6749) # oggenc: fix large alloca on bad AIFF input (CVE-2015-6749)
Patch6: vorbis-tools-1.4.0-CVE-2015-6749.patch Patch6: vorbis-tools-1.4.0-CVE-2015-6749.patch
# fix out-of-bounds read in oggenc (CVE-2023-43361)
Patch7: vorbis-tools-1.4.0-CVE-2023-43361.patch
BuildRequires: flac-devel BuildRequires: flac-devel
BuildRequires: gettext BuildRequires: gettext
BuildRequires: gcc BuildRequires: gcc
@ -58,7 +55,6 @@ comment editor.
%patch4 -p1 %patch4 -p1
%patch5 -p1 %patch5 -p1
%patch6 -p1 %patch6 -p1
%patch7 -p1
%build %build
@ -86,9 +82,6 @@ rm -rf $RPM_BUILD_ROOT%{_docdir}/%{name}*
%changelog %changelog
* Thu Jan 18 2024 Lukáš Zaoral <lzaoral@redhat.com> - 1:1.4.0-29
- fix out-of-bounds read in oggenc (CVE-2023-43361)
* Mon Feb 19 2018 Kamil Dudka <kdudka@redhat.com> - 1:1.4.0-28 * Mon Feb 19 2018 Kamil Dudka <kdudka@redhat.com> - 1:1.4.0-28
- add explicit BR for the gcc compiler - add explicit BR for the gcc compiler

View File

@ -1,6 +0,0 @@
--- !Policy
product_versions:
- rhel-8
decision_context: osci_compose_gate
rules:
- !PassingTestCaseRule {test_case_name: desktop-qe.desktop-ci.tier1-gating.functional}

View File

@ -1 +0,0 @@
SHA512 (vorbis-tools-1.4.0.tar.gz) = d2473f2e8e6726b5a5083f567797ae42bbb7fa3f26aec3f7b83e641e028c64726299f71a9d75258595a53cf29c18acb84841bcbc39509258d2c8df859e4e3b99

View File

@ -1,13 +0,0 @@
diff --git a/oggenc/platform.c b/oggenc/platform.c
index 6d9f4ef..c63304b 100644
--- a/oggenc/platform.c
+++ b/oggenc/platform.c
@@ -147,7 +147,7 @@ int create_directories(char *fn, int isutf8)
start = start+2;
#endif
- while((end = strpbrk(start+1, PATH_SEPS)) != NULL)
+ while((end = strpbrk(start + strspn(start, PATH_SEPS), PATH_SEPS)) != NULL)
{
int rv;
memcpy(segment, fn, end-fn);

View File

@ -1 +0,0 @@
567e0fb8d321b2cd7124f8208b8b90e6 vorbis-tools-1.4.0.tar.gz

View File

@ -1 +0,0 @@
fc6a820bdb5ad6fcac074721fab5c3f96eaf6562 vorbis-tools-1.4.0.tar.gz