Files
buildroot/package
Fabrice Fontaine 0a860f21e1 package/mp4v2: security bump to version 4.1.3
- Switch site to an active fork
- Send patch upstream
- Update indentation in hash file (two spaces)
- Fix the following CVEs:
  - CVE-2018-14054: A double free exists in the MP4StringProperty class
    in mp4property.cpp in MP4v2 2.0.0. A dangling pointer is freed again
    in the destructor once an exception is triggered.
    Fixed by
    f09cceeee5
  - CVE-2018-14325: In MP4v2 2.0.0, there is an integer underflow (with
    resultant memory corruption) when parsing MP4Atom in mp4atom.cpp.
    Fixed by
    e475013c6e
  - CVE-2018-14326: In MP4v2 2.0.0, there is an integer overflow (with
    resultant memory corruption) when resizing MP4Array for the ftyp
    atom in mp4array.h.
    Fixed by
    70d823ccd8
  - CVE-2018-14379: MP4Atom::factory in mp4atom.cpp in MP4v2 2.0.0
    incorrectly uses the MP4ItemAtom data type in a certain case where
    MP4DataAtom is required, which allows remote attackers to cause a
    denial of service (memory corruption) or possibly have unspecified
    other impact via a crafted MP4 file, because access to the data
    structure has different expectations about layout as a result of
    this type confusion.
    Fixed by
    73f38b4296
  - CVE-2018-14403: MP4NameFirstMatches in mp4util.cpp in MP4v2 2.0.0
    mishandles substrings of atom names, leading to use of an
    inappropriate data type for associated atoms. The resulting type
    confusion can cause out-of-bounds memory access.
    Fixed by
    51cb6b36f6

Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
2020-05-29 22:05:51 +02:00
..
2020-04-07 08:01:28 +02:00
2020-03-22 21:57:07 +01:00
2020-04-11 09:48:58 +02:00
2020-05-09 16:51:17 +02:00
2020-05-09 23:11:23 +02:00
2020-04-27 22:28:44 +02:00
2020-04-19 22:48:58 +02:00
2020-04-23 23:38:10 +02:00
2020-05-02 21:31:21 +02:00
2020-05-25 22:04:35 +02:00
2020-04-07 07:49:08 +02:00
2020-04-10 22:43:08 +02:00
2020-05-01 14:09:42 +02:00
2020-04-25 21:28:53 +02:00
2020-04-13 23:08:46 +02:00
2020-03-29 18:35:22 +02:00
2020-03-29 16:32:51 +02:00
2020-04-10 22:31:29 +02:00
2020-04-21 21:35:54 +02:00
2020-05-01 15:08:04 +02:00
2020-04-06 22:13:57 +02:00
2020-04-13 21:55:59 +02:00
2020-04-21 21:37:38 +02:00
2020-05-26 12:02:13 +02:00
2020-04-19 10:23:22 +02:00
2020-03-28 14:53:50 +01:00
2020-04-13 22:34:50 +02:00
2020-04-05 16:25:43 +02:00
2020-04-21 22:12:51 +02:00
2020-04-12 23:17:02 +02:00
2020-04-12 23:13:57 +02:00
2020-04-08 16:53:23 +02:00
2020-04-08 21:18:57 +02:00
2020-04-12 23:14:12 +02:00
2020-04-06 21:40:23 +02:00
2020-05-01 14:04:51 +02:00
2020-04-25 22:34:43 +02:00
2020-05-02 18:34:30 +02:00
2020-05-25 22:52:53 +02:00
2020-04-25 21:29:18 +02:00
2020-03-22 22:05:03 +01:00
2020-04-21 21:37:24 +02:00
2020-04-04 17:30:37 +02:00
2020-03-26 23:01:10 +01:00
2020-05-25 22:48:44 +02:00
2020-05-17 21:38:47 +02:00
2020-04-21 21:35:43 +02:00
2020-04-01 21:51:06 +02:00
2020-04-11 10:07:02 +02:00
2020-04-21 21:35:33 +02:00
2020-03-29 16:52:01 +02:00
2020-05-02 18:54:05 +02:00
2020-03-29 21:52:51 +02:00
2020-04-27 22:26:40 +02:00
2020-04-27 22:20:16 +02:00
2020-05-03 21:21:04 +02:00
2020-05-25 22:48:44 +02:00
2020-04-19 15:30:20 +02:00
2020-05-03 21:57:44 +02:00