Bump to the latest git commit as this will fix the following CVEs: git log|grep CVE sox-fmt: validate comments_bytes before use (CVE-2019-13590) [bug #325] fix possible null pointer deref in lsx_make_lpf() (CVE-2019-8357) fft4g: bail if size too large (CVE-2019-8356) fix possible overflow in lsx_(re)valloc() size calculation (CVE-2019-8355) fix possible buffer size overflow in lsx_make_lpf() (CVE-2019-8354) xa: validate channel count (CVE-2017-18189) aiff: fix crash on empty comment chunk (CVE-2017-15642) adpcm: fix stack overflow with >4 channels (CVE-2017-15372) flac: fix crash on corrupt metadata (CVE-2017-15371) wav: ima_adpcm: fix buffer overflow on corrupt input (CVE-2017-15370) wav: fix crash writing header when channel count >64k (CVE-2017-11359) hcom: fix crash on input with corrupt dictionary (CVE-2017-11358) wav: fix crash if channel count is zero (CVE-2017-11332) - Tweak configuration options due to6ff0e9322f- libgsm is now an optional dependency sincee548827ffc- Add patch to put back --disable-stack-protector Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com> Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
1.8 KiB
1.8 KiB