Change logs for libmodplug source package in Lucid

  • libmodplug (1:0.8.7-1ubuntu0.3) lucid-security; urgency=low
    
      * SECURITY UPDATE: integer overflow in CSoundFile::ReadWav()
        - properly calculate length in src/load_wav.cpp.
        - http://modplug-xmms.git.sourceforge.net/git/gitweb.cgi?p=modplug-xmms/modplug-xmms;a=commit;h=2d4c56de314ab13e4437bd8b609f0b751066eee8
        - CVE-2011-2911
      * SECURITY UPDATE: boundary error in CSoundFile::ReadS3M()
        - validate offsets and ignore duplicate samples in src/load_s3m.cpp.
        - http://modplug-xmms.git.sourceforge.net/git/gitweb.cgi?p=modplug-xmms/modplug-xmms;a=commit;h=4e5295658fff000379caa122e75c9200205fe20
        - CVE-2011-2912
      * SECURITY UPDATE: off-by-one in CSoundFile::ReadAMS()
        - fix calculation in src/load_ams.cpp.
        - http://modplug-xmms.git.sourceforge.net/git/gitweb.cgi?p=modplug-xmms/modplug-xmms;a=commit;h=26243ab9fe1171f70053e9aec4b20e9f7de9e4ef
        - CVE-2011-2913
      * SECURITY UPDATE: off-by-one in CSoundFile::ReadDSM()
        - fix calculation in src/load_dsm.cpp.
        - http://modplug-xmms.git.sourceforge.net/git/gitweb.cgi?p=modplug-xmms/modplug-xmms;a=commit;h=26243ab9fe1171f70053e9aec4b20e9f7de9e4ef
        - CVE-2011-2914
      * SECURITY UPDATE: off-by-one in CSoundFile::ReadAMS2()
        - fix calculation in src/load_ams.cpp.
        - http://modplug-xmms.git.sourceforge.net/git/gitweb.cgi?p=modplug-xmms/modplug-xmms;a=commit;h=16d7a78efe14d345a6c5b241f88422ad0ee483ea
        - CVE-2011-2915
     -- Marc Deslauriers <email address hidden>   Fri, 14 Oct 2011 13:44:03 -0400
  • libmodplug (1:0.8.7-1ubuntu0.2) lucid-security; urgency=low
    
      * SECURITY UPDATE: buffer overflow in S3M loader
        - src/load_s3m.cpp: ignore corrupted headers.
        - http://modplug-xmms.git.sourceforge.net/git/gitweb.cgi?p=modplug-xmms/modplug-xmms;a=commit;h=aecef259828a89bb00c2e6f78e89de7363b2237b
        - CVE-2011-1574
      * SECURITY UPDATE: multiple security issues in ABC loader
        - src/load_abc.cpp: fix various issues.
        - http://modplug-xmms.git.sourceforge.net/git/gitweb.cgi?p=modplug-xmms/modplug-xmms;a=commit;h=d7c36959757fc6c8e4d487be8a72383093d9d26f
        - http://modplug-xmms.git.sourceforge.net/git/gitweb.cgi?p=modplug-xmms/modplug-xmms;a=commit;h=5d437ad2f741c08fc3862cd4d5157492ead0fe84
        - http://modplug-xmms.git.sourceforge.net/git/gitweb.cgi?p=modplug-xmms/modplug-xmms;a=commit;h=a13e067a82fa195b1732ad9fb8341c1b0f141bf5
        - http://modplug-xmms.git.sourceforge.net/git/gitweb.cgi?p=modplug-xmms/modplug-xmms;a=commit;h=22aa681cd12f8547a8866112c7e443166115b701
        - http://modplug-xmms.git.sourceforge.net/git/gitweb.cgi?p=modplug-xmms/modplug-xmms;a=commit;h=bd5363f31274d6e79b8ace5a94686c9ac6ef415b
        - http://modplug-xmms.git.sourceforge.net/git/gitweb.cgi?p=modplug-xmms/modplug-xmms;a=commit;h=51f4b152060be23a4514da2a65c83e205bfb21ba
        - http://modplug-xmms.git.sourceforge.net/git/gitweb.cgi?p=modplug-xmms/modplug-xmms;a=commit;h=56436fac0a37b1746dab594e4aefba9d2bb92e09
        - http://modplug-xmms.git.sourceforge.net/git/gitweb.cgi?p=modplug-xmms/modplug-xmms;a=commit;h=ad305187322171eab3a66f4b5ce2a067b1580b3e
        - http://modplug-xmms.git.sourceforge.net/git/gitweb.cgi?p=modplug-xmms/modplug-xmms;a=commit;h=497a27ba2555399d7aa243dbb51ca81e4e7a32cf
        - CVE-2011-1761
     -- Marc Deslauriers <email address hidden>   Mon, 13 Jun 2011 10:14:19 -0400
  • libmodplug (1:0.8.7-1build1) lucid; urgency=low
    
      * rebuild rest of main for armel armv7/thumb2 optimization;
        UbuntuSpec:mobile-lucid-arm-gcc-v7-thumb2
     -- Alexander Sack <email address hidden>   Sat, 06 Mar 2010 13:35:27 +0100
  • libmodplug (1:0.8.7-1) unstable; urgency=high
    
      * New upstream version
        * Fixes integer overflow in CSoundFile::ReadMed (CVE-2009-1438)
          (closes: #526657)
        * Fixes PATinst() Buffer Overflow (SA34927) (closes: #526084)
        * Fixes 24/32-bit conversion routine
    
    libmodplug (1:0.8.4-5) unstable; urgency=low
    
      * Fix ftbfs on all architectures (Closes: #524417):
        * Build-depends: automake1.9
        * re-order autotools/libtool calls.
        * Thanks to Fathi Boudra for the patch.
      
    
    libmodplug (1:0.8.4-4) unstable; urgency=low
    
      * libmodplug-dev depends on libstdc++-dev now (closes: #524259)
    
     -- Marc Deslauriers <email address hidden>   Thu,  14 May 2009 10:48:41 +0100