Commit graph

4 commits

Author SHA1 Message Date
wiz
6934d2b65d Do not accept libtunepimp>=0.5. Noted by joerg@ 2006-08-23 06:18:33 +00:00
salo
e2e79f4f10 Security fix for CVE-2006-3600:
"A vulnerability in libtunepimp can be potentially exploited by
 malicious people to compromise a user's system.

 The vulnerability is caused due to a boundary error in the
 "LookupTRM::lookup()" function when retrieving album release dates.
 This can be exploited to cause a buffer overflow by returning an overly
 long release date string (more than 100 bytes).

 Successful exploitation may allow execution of arbitrary code in context
 of an application using the vulnerable library."

http://secunia.com/advisories/21026/
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3600

Patch from MusicBrainz SVN.  Bump PKGREVISION.
2006-08-21 17:55:01 +00:00
wiz
3f65464442 Mention that this is an older release. 2006-07-12 13:30:33 +00:00
wiz
69f51bcea3 Reimport libtunepimp as libtunepimp0.4, in preparation for the libtunepimp
update, for packages which still need the 0.4 API.
2006-07-12 13:07:19 +00:00