diff --git a/mingw-w64-libmodplug/PKGBUILD b/mingw-w64-libmodplug/PKGBUILD index eab935bd41..594a67a1cc 100644 --- a/mingw-w64-libmodplug/PKGBUILD +++ b/mingw-w64-libmodplug/PKGBUILD @@ -3,8 +3,8 @@ _realname=libmodplug pkgname="${MINGW_PACKAGE_PREFIX}-${_realname}" -pkgver=0.8.8.4 -pkgrel=2 +pkgver=0.8.8.5 +pkgrel=1 pkgdesc="A MOD playing library (mingw-w64)" arch=('any') url="http://modplug-xmms.sourceforge.net/" @@ -13,19 +13,13 @@ makedepends=("${MINGW_PACKAGE_PREFIX}-gcc" "${MINGW_PACKAGE_PREFIX}-pkg-config") depends=("${MINGW_PACKAGE_PREFIX}-gcc-libs") options=('strip' 'staticlibs') source=("http://downloads.sourceforge.net/modplug-xmms/${_realname}-${pkgver}.tar.gz" - 0001-stdafx-mingw-w64.mingw.patch - libmodplug-CVE-2013-4233-Fix.patch - libmodplug-CVE-2013-4234-Fix.patch) -md5sums=('fddc3c704c5489de2a3cf0fedfec59db' - '0853de6307501e2f2e9c7aae4b6ca226' - '5ca8a0159bb37bd9bd31ad9f83d4f79e' - '0b12fa5592daab8519c34f5e8f4203ea') + 0001-stdafx-mingw-w64.mingw.patch) +md5sums=('5f30241db109d647781b784e62ddfaa1' + '0853de6307501e2f2e9c7aae4b6ca226') prepare() { cd "${srcdir}/${_realname}-${pkgver}" patch -p1 -i "${srcdir}/0001-stdafx-mingw-w64.mingw.patch" - patch -p2 -i "${srcdir}/libmodplug-CVE-2013-4233-Fix.patch" - patch -p2 -i "${srcdir}/libmodplug-CVE-2013-4234-Fix.patch" } build() { @@ -36,7 +30,8 @@ build() { --build=${MINGW_CHOST} \ --host=${MINGW_CHOST} \ --target=${MINGW_CHOST} \ - --enable-shared + --enable-shared \ + --enable-static make } @@ -45,5 +40,5 @@ package() { make DESTDIR="${pkgdir}" install # Install license - #install -m644 ${srcdir}/${_realname}-${pkgver}/COPYING ${pkgdir}${MINGW_PREFIX}/share/licenses/${_realname}/LICENSE + install -Dm644 ${srcdir}/${_realname}-${pkgver}/COPYING ${pkgdir}${MINGW_PREFIX}/share/licenses/${_realname}/LICENSE } diff --git a/mingw-w64-libmodplug/libmodplug-CVE-2013-4233-Fix.patch b/mingw-w64-libmodplug/libmodplug-CVE-2013-4233-Fix.patch deleted file mode 100644 index 2e02bc6627..0000000000 --- a/mingw-w64-libmodplug/libmodplug-CVE-2013-4233-Fix.patch +++ /dev/null @@ -1,41 +0,0 @@ -From c4d4e047862649a75f6dba905c613aff0df81309 Mon Sep 17 00:00:00 2001 -From: Konstanty Bialkowski -Date: Wed, 14 Aug 2013 14:15:27 +1000 -Subject: [PATCH] CVE-2013-4233 Fix - -Integer overflow in j variable - --- reported by Florian "Agix" Gaultier ---- - libmodplug/src/load_abc.cpp | 7 ++++--- - 1 file changed, 4 insertions(+), 3 deletions(-) - -diff --git a/libmodplug/src/load_abc.cpp b/libmodplug/src/load_abc.cpp -index 9f4b328..ecb7b62 100644 ---- a/libmodplug/src/load_abc.cpp -+++ b/libmodplug/src/load_abc.cpp -@@ -1814,7 +1814,7 @@ static int abc_extract_tempo(const char *p, int invoice) - - static void abc_set_parts(char **d, char *p) - { -- int i,j,k,m,n; -+ int i,j,k,m,n,size; - char *q; - #ifdef NEWMIKMOD - static MM_ALLOC *h; -@@ -1852,10 +1852,11 @@ static void abc_set_parts(char **d, char *p) - i += n-1; - } - } -- q = (char *)_mm_calloc(h, j+1, sizeof(char)); // enough storage for the worst case -+ size = (j + 1) > 0 ? j+1 : j; -+ q = (char *)_mm_calloc(h, size, sizeof(char)); // enough storage for the worst case - // now copy bytes from p to *d, taking parens and digits in account - j = 0; -- for( i=0; p[i] && p[i] != '%'; i++ ) { -+ for( i=0; p[i] && p[i] != '%' && j < size; i++ ) { - if( isdigit(p[i]) || isupper(p[i]) || p[i] == '(' || p[i] == ')' ) { - if( p[i] == ')' ) { - for( n=j; n > 0 && q[n-1] != '('; n-- ) ; // find open paren in q --- -1.8.4 diff --git a/mingw-w64-libmodplug/libmodplug-CVE-2013-4234-Fix.patch b/mingw-w64-libmodplug/libmodplug-CVE-2013-4234-Fix.patch deleted file mode 100644 index e6a42dd278..0000000000 --- a/mingw-w64-libmodplug/libmodplug-CVE-2013-4234-Fix.patch +++ /dev/null @@ -1,94 +0,0 @@ -From 5de53a46283e7c463115444a9339978011dab961 Mon Sep 17 00:00:00 2001 -From: Konstanty Bialkowski -Date: Wed, 14 Aug 2013 15:15:09 +1000 -Subject: [PATCH] CVE-2013-4234 Fix - -Heap overflow in abc_MIDI_drum + abc_MIDI_gchord - --- reported by Florian "Agix" Gaultier ---- - libmodplug/src/load_abc.cpp | 34 +++++++++++++++++++++++----------- - 1 file changed, 23 insertions(+), 11 deletions(-) - -diff --git a/libmodplug/src/load_abc.cpp b/libmodplug/src/load_abc.cpp -index ecb7b62..dd9cc6b 100644 ---- a/libmodplug/src/load_abc.cpp -+++ b/libmodplug/src/load_abc.cpp -@@ -3205,27 +3205,33 @@ static void abc_MIDI_chordname(const char *p) - static int abc_MIDI_drum(const char *p, ABCHANDLE *h) - { - char *q; -- int i,n,m; -+ int i, n, m, len; - while( isspace(*p) ) p++; - if( !strncmp(p,"on",2) && (isspace(p[2]) || p[2] == '\0') ) return 2; - if( !strncmp(p,"off",3) && (isspace(p[3]) || p[3] == '\0') ) return 1; -- n = 0; -+ n = 0; len = 0; - for( q = h->drum; *p && !isspace(*p); p++ ) { - if( !strchr("dz0123456789",*p) ) break; -- *q++ = *p; -- if( !isdigit(*p) ) { -- if( !isdigit(p[1]) ) *q++ = '1'; -+ *q++ = *p; len++; -+ if( !isdigit(*p) && len < sizeof(h->drum)-1 ) { -+ if( !isdigit(p[1]) ) { *q++ = '1'; len ++; } - n++; // count the silences too.... - } -+ if (len >= sizeof(h->drum)-1) { -+ // consume the rest of the input -+ // definitely enough "drum last state" stored. -+ while ( *p && !isspace(*p) ) p++; -+ break; -+ } - } - *q = '\0'; - q = h->drumins; - for( i = 0; idrum[i*2] == 'd' ) { -- while( isspace(*p) ) p++; -+ while( *p && isspace(*p) ) p++; - if( !isdigit(*p) ) { - m = 0; -- while( !isspace(*p) ) p++; -+ while( *p && !isspace(*p) ) p++; - } - else - p += abc_getnumber(p,&m); -@@ -3236,10 +3242,10 @@ static int abc_MIDI_drum(const char *p, ABCHANDLE *h) - q = h->drumvol; - for( i = 0; idrum[i*2] == 'd' ) { -- while( isspace(*p) ) p++; -+ while( *p && isspace(*p) ) p++; - if( !isdigit(*p) ) { - m = 0; -- while( !isspace(*p) ) p++; -+ while( *p && !isspace(*p) ) p++; - } - else - p += abc_getnumber(p,&m); -@@ -3254,13 +3260,19 @@ static int abc_MIDI_drum(const char *p, ABCHANDLE *h) - static int abc_MIDI_gchord(const char *p, ABCHANDLE *h) - { - char *q; -+ int len = 0; - while( isspace(*p) ) p++; - if( !strncmp(p,"on",2) && (isspace(p[2]) || p[2] == '\0') ) return 2; - if( !strncmp(p,"off",3) && (isspace(p[3]) || p[3] == '\0') ) return 1; - for( q = h->gchord; *p && !isspace(*p); p++ ) { - if( !strchr("fbcz0123456789ghijGHIJ",*p) ) break; -- *q++ = *p; -- if( !isdigit(*p) && !isdigit(p[1]) ) *q++ = '1'; -+ *q++ = *p; len++; -+ if( !isdigit(*p) && len < sizeof(h->gchord)-1 && !isdigit(p[1]) ) { *q++ = '1'; len ++; } -+ if (len >= sizeof(h->gchord)-1) { -+ // consume the rest of the input -+ // definitely enough "drum last state" stored. -+ while ( *p && !isspace(*p) ) p++; -+ } - } - *q = '\0'; - return 0; --- -1.8.4