summaryrefslogtreecommitdiffstats
path: root/main
diff options
context:
space:
mode:
authorNatanael Copa <ncopa@alpinelinux.org>2017-08-07 17:48:37 +0200
committerNatanael Copa <ncopa@alpinelinux.org>2017-08-07 18:07:00 +0200
commitfa16ba1f57b1ddf30ec6b90884142a9fab471315 (patch)
tree6bdffb7b440d5b4b9f9d3ffaba396b54993f7d4e /main
parentbac940573393e980a46ef49d809df53058bba8b4 (diff)
main/mpg123: security upgrade to 1.25.4 (CVE-2017-9545,CVE-2017-11126)
fixes #7598
Diffstat (limited to 'main')
-rw-r--r--main/mpg123/APKBUILD13
1 files changed, 9 insertions, 4 deletions
diff --git a/main/mpg123/APKBUILD b/main/mpg123/APKBUILD
index 5bba0ae18ba..e9428b68e07 100644
--- a/main/mpg123/APKBUILD
+++ b/main/mpg123/APKBUILD
@@ -1,6 +1,6 @@
# Maintainer: Natanael Copa <ncopa@alpinelinux.org>
pkgname=mpg123
-pkgver=1.22.4
+pkgver=1.25.4
pkgrel=0
pkgdesc="A console based real time MPEG Audio Player for Layer 1, 2 and 3"
url="http://sourceforge.net/projects/mpg123"
@@ -12,6 +12,11 @@ makedepends="libtool alsa-lib-dev linux-headers"
source="http://downloads.sourceforge.net/sourceforge/$pkgname/$pkgname-$pkgver.tar.bz2"
options="libtool"
+# secfixes:
+# 1.25.4-r0:
+# - CVE-2017-9545
+# - CVE-2017-11126
+
build() {
cd "$srcdir"/$pkgname-$pkgver
./configure \
@@ -33,6 +38,6 @@ package() {
make DESTDIR="$pkgdir" install || return 1
}
-md5sums="2dfafae3bbc532b4c8b04a77c6a6de89 mpg123-1.22.4.tar.bz2"
-sha256sums="5069e02e50138600f10cc5f7674e44e9bf6f1930af81d0e1d2f869b3c0ee40d2 mpg123-1.22.4.tar.bz2"
-sha512sums="d8552b3522fa58647cee7c43227737993851452a15dc6d3ae6948c6c62d4a8f6064e2b284f170413aa3f805a3f3e1a6f1faac7d19daddd25c6790863e4925212 mpg123-1.22.4.tar.bz2"
+md5sums="810e9d00fd75c92c4afafa20245317b5 mpg123-1.25.4.tar.bz2"
+sha256sums="cdb5620e8aab83f75a27dab3394a44b9cc4017fc77b2954b8425ca416db6b3e7 mpg123-1.25.4.tar.bz2"
+sha512sums="aea1f225f6addfea8a22cbe020f3216531b8e988d11cf5d588733e7ce22c03d4649df5ae3f596a0e15507e1d9f2c83a16a71affb479dd4156d270b0d23c2f072 mpg123-1.25.4.tar.bz2"