summaryrefslogtreecommitdiff
path: root/user/libid3tag/APKBUILD
diff options
context:
space:
mode:
authorMax Rees <maxcrees@me.com>2019-08-04 02:28:57 -0500
committerMax Rees <maxcrees@me.com>2019-08-04 02:28:57 -0500
commitf66041941e3b1ab8ec01bad5b41717f75c65c8db (patch)
tree3bebce46e89218789ac81321d6334c383d579886 /user/libid3tag/APKBUILD
parentaa1a18ae17509f67feccf03066c61f3266a44ece (diff)
downloadpackages-f66041941e3b1ab8ec01bad5b41717f75c65c8db.tar.gz
packages-f66041941e3b1ab8ec01bad5b41717f75c65c8db.tar.bz2
packages-f66041941e3b1ab8ec01bad5b41717f75c65c8db.tar.xz
packages-f66041941e3b1ab8ec01bad5b41717f75c65c8db.zip
user/libid3tag: CVE-2017-11550, change fix for CVE-2008-2109 (#126)
Diffstat (limited to 'user/libid3tag/APKBUILD')
-rw-r--r--user/libid3tag/APKBUILD20
1 files changed, 13 insertions, 7 deletions
diff --git a/user/libid3tag/APKBUILD b/user/libid3tag/APKBUILD
index df96d8b79..0984fc93f 100644
--- a/user/libid3tag/APKBUILD
+++ b/user/libid3tag/APKBUILD
@@ -2,7 +2,7 @@
# Maintainer:
pkgname=libid3tag
pkgver=0.15.1b
-pkgrel=9
+pkgrel=10
pkgdesc="Library for manipulating IDv3 tags in MP3 audio files"
url="http://www.underbit.com/products/mad/"
arch="all"
@@ -11,17 +11,24 @@ depends=""
makedepends="zlib-dev"
subpackages="$pkgname-dev"
source="ftp://ftp.mars.org/pub/mpeg/libid3tag-$pkgver.tar.gz
- CVE-2008-2109.patch
+ CVE-2004-2779.patch
+ CVE-2017-11550.patch
"
+# secfixes:
+# 0.15.1b-r8:
+# - CVE-2008-2109
+# 0.15.1b-r10:
+# - CVE-2004-2779
+# - CVE-2017-11550
+# - CVE-2017-11551
+
prepare() {
- cd "$builddir"
update_config_sub
default_prepare
}
build() {
- cd "$builddir"
./configure \
--build=$CBUILD \
--host=$CHOST \
@@ -33,12 +40,10 @@ build() {
}
check() {
- cd "$builddir"
make check
}
package() {
- cd "$builddir"
make DESTDIR="$pkgdir" install
mkdir -p "$pkgdir"/usr/lib/pkgconfig
cat > "$pkgdir"/usr/lib/pkgconfig/id3tag.pc <<EOF
@@ -57,4 +62,5 @@ EOF
}
sha512sums="ade7ce2a43c3646b4c9fdc642095174b9d4938b078b205cd40906d525acd17e87ad76064054a961f391edcba6495441450af2f68be69f116549ca666b069e6d3 libid3tag-0.15.1b.tar.gz
-fc79d44ca9d1435ab5b11d4da6b46d3684827a1384a0156cd88242225f98f3a0668c0d6e6a88159f0c4985fcbdc636777c2f100d7f371eef258a6050d6fde567 CVE-2008-2109.patch"
+4c27e104d45ae34affc1bef8ec613e65c7e4791185d2ef1cb27974ec7025c06c35d30d6278ce7e3107dff959bd55a708246c3c1a9d5ad7b093424cfb93b79f63 CVE-2004-2779.patch
+6627d6e73958309b199a02cd6fa1008a81554151238d8a099dc27e535b8d14f7a9c1ba19894fdf2c927e59c0ca855d50b2f1289f116b45bc41e02d31659d1535 CVE-2017-11550.patch"