Subject: CVS commit: pkgsrc/multimedia
To: None <pkgsrc-changes@NetBSD.org>
From: Matthias Drochner <drochner@netbsd.org>
List: pkgsrc-changes
Date: 09/13/2007 19:16:02
Module Name:	pkgsrc
Committed By:	drochner
Date:		Thu Sep 13 19:16:02 UTC 2007

Modified Files:
	pkgsrc/multimedia/gmplayer: Makefile distinfo
	pkgsrc/multimedia/mencoder: Makefile
	pkgsrc/multimedia/mplayer: Makefile
	pkgsrc/multimedia/mplayer-share: distinfo
Added Files:
	pkgsrc/multimedia/mplayer-share/patches: patch-al

Log Message:
apply a security fix from upstream CVS:
Check wLongsPerEntry before using it.
This fixes a potential crash for some values of it.
As a side effect it works around broken callocs with an integer
overflow vulnerability, but using MPlayer on such systems should
never be assumed to be safe!

This should fix SA26806 (http://secunia.com/advisories/26806/).

bump PKGREVISIONs


To generate a diff of this commit:
cvs rdiff -r1.62 -r1.63 pkgsrc/multimedia/gmplayer/Makefile
cvs rdiff -r1.48 -r1.49 pkgsrc/multimedia/gmplayer/distinfo
cvs rdiff -r1.33 -r1.34 pkgsrc/multimedia/mencoder/Makefile
cvs rdiff -r1.45 -r1.46 pkgsrc/multimedia/mplayer/Makefile
cvs rdiff -r1.41 -r1.42 pkgsrc/multimedia/mplayer-share/distinfo
cvs rdiff -r0 -r1.1 pkgsrc/multimedia/mplayer-share/patches/patch-al

Please note that diffs are not public domain; they are subject to the
copyright notices on the relevant files.