-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Format: 1.7 Date: Mon, 3 Jan 2005 23:11:32 +0100 Source: mpg123 Binary: mpg123-esd mpg123-oss-3dnow mpg123-nas mpg123-oss-i486 mpg123 Architecture: arm i386 m68k powerpc source sparc Version: 0.59r-18 Distribution: unstable Urgency: high Maintainer: Daniel Kobras <kobras@debian.org> Changed-By: Daniel Kobras <kobras@debian.org> Description: mpg123 - MPEG layer 1/2/3 audio player Closes: 287043 Changes: mpg123 (0.59r-18) unstable; urgency=high . * common.c, layer2.c: Fix insufficient validation of MPEG header values, discovered by Yuri D'Elia (CAN-2004-0991). * mpg123.c: Fix buffer overflow in playlist parser, discovered by Bartlomiej Sieka (CAN-2004-1284). Thanks to Steve Kemp for the patch. Closes: #287043 * httpget.c: Fix further heap overflows in http parser. Backported from the Gentoo patch for CAN-2004-0982. Original path was coded by Jeremy Huddleston for version pre0.59s. * mpg123.c: Fix NULL pointer dereference if http_open() fails. * httpget.c, xfermem.c: Do not explicitly declare errno variable. * audio.c: Include stdlib.h to silence compiler warning. Files: 067224a5af19c2907517cbdde20d5feb 97604 non-free/sound optional mpg123-esd_0.59r-18_powerpc.deb 12646fbca3d09e0fec3a78e9e6451da0 101544 non-free/sound optional mpg123_0.59r-18_arm.deb 3e9a87590179653b44a5df3a637dd904 89878 non-free/sound optional mpg123-oss-3dnow_0.59r-18_i386.deb 9f95fbc8255189e0ca5cb1da3d5ec133 739 non-free/sound optional mpg123_0.59r-18.dsc 69d30b26a1e9db429c32b774c7352a32 89612 non-free/sound optional mpg123-nas_0.59r-18_i386.deb 6ab92269f67441ee01cab112b884f1ac 86712 non-free/sound optional mpg123-esd_0.59r-18_i386.deb 78db22a98fc677662d2a877ecc884ceb 93354 non-free/sound optional mpg123-oss-i486_0.59r-18_i386.deb b75e20b827a1edb2c55702d46dca42a2 91144 non-free/sound optional mpg123_0.59r-18_sparc.deb c83aa276a7f6091faca7ec4e1ff0cbf6 86644 non-free/sound optional mpg123_0.59r-18_i386.deb ca3a38b779fbcd6484372399bb044ec7 40807 non-free/sound optional mpg123_0.59r-18.diff.gz d942f09be0d528dcaa957abd3aac40ac 79810 non-free/sound optional mpg123_0.59r-18_m68k.deb ed3f90e485ab4bfed2381e575f70a898 96184 non-free/sound optional mpg123_0.59r-18_powerpc.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.2.5 (GNU/Linux) iD8DBQFB2suapOKIA4m/fisRAlGlAJ0Uwkpy8z6Vu7WJ8eXVXUekW44ZpgCgvfMG v6GnAS+8d0PmnHiIs8Pov34= =e3o8 -----END PGP SIGNATURE----- Accepted: mpg123-esd_0.59r-18_i386.deb to pool/non-free/m/mpg123/mpg123-esd_0.59r-18_i386.deb mpg123-esd_0.59r-18_powerpc.deb to pool/non-free/m/mpg123/mpg123-esd_0.59r-18_powerpc.deb mpg123-nas_0.59r-18_i386.deb to pool/non-free/m/mpg123/mpg123-nas_0.59r-18_i386.deb mpg123-oss-3dnow_0.59r-18_i386.deb to pool/non-free/m/mpg123/mpg123-oss-3dnow_0.59r-18_i386.deb mpg123-oss-i486_0.59r-18_i386.deb to pool/non-free/m/mpg123/mpg123-oss-i486_0.59r-18_i386.deb mpg123_0.59r-18.diff.gz to pool/non-free/m/mpg123/mpg123_0.59r-18.diff.gz mpg123_0.59r-18.dsc to pool/non-free/m/mpg123/mpg123_0.59r-18.dsc mpg123_0.59r-18_arm.deb to pool/non-free/m/mpg123/mpg123_0.59r-18_arm.deb mpg123_0.59r-18_i386.deb to pool/non-free/m/mpg123/mpg123_0.59r-18_i386.deb mpg123_0.59r-18_m68k.deb to pool/non-free/m/mpg123/mpg123_0.59r-18_m68k.deb mpg123_0.59r-18_powerpc.deb to pool/non-free/m/mpg123/mpg123_0.59r-18_powerpc.deb mpg123_0.59r-18_sparc.deb to pool/non-free/m/mpg123/mpg123_0.59r-18_sparc.deb -- To UNSUBSCRIBE, email to debian-devel-changes-REQUEST@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.org