Debian Multimedia Maintainers [Tue, 7 Mar 2023 11:41:07 +0000 (06:41 -0500)]
CVE-2022-1441
commit
3dbe11b37d65c8472faf0654410068e5500b3adb
Author: jeanlf <jeanlf@gpac.io>
Date: Tue Apr 19 09:15:58 2022 +0200
fixed #2175
Gbp-Pq: Name CVE-2022-1441.patch
Debian Multimedia Maintainers [Tue, 7 Mar 2023 11:41:07 +0000 (06:41 -0500)]
CVE-2022-1222
commit
7f060bbb72966cae80d6fee338d0b07fa3fc06e1
Author: jeanlf <jeanlf@gpac.io>
Date: Thu Mar 31 13:57:05 2022 +0200
fixed #2159
Gbp-Pq: Name CVE-2022-1222.patch
Debian Multimedia Maintainers [Tue, 7 Mar 2023 11:41:07 +0000 (06:41 -0500)]
CVE-2022-1172
commit
55a183e6b8602369c04ea3836e05436a79fbc7f8
Author: jeanlf <jeanlf@gpac.io>
Date: Tue Mar 29 16:51:46 2022 +0200
fixed #2153
Gbp-Pq: Name CVE-2022-1172.patch
Debian Multimedia Maintainers [Tue, 7 Mar 2023 11:41:07 +0000 (06:41 -0500)]
CVE-2022-1035
commit
3718d583c6ade191dc7979c64f48c001ca6f0243
Author: jeanlf <jeanlf@gpac.io>
Date: Thu Mar 17 12:00:55 2022 +0100
fixed #2146
Gbp-Pq: Name CVE-2022-1035.patch
Debian Multimedia Maintainers [Tue, 7 Mar 2023 11:41:07 +0000 (06:41 -0500)]
CVE-2022-30976
commit
1773b7a34bc08734aee7d3f5dfe65d06389fe15a
Author: jeanlf <jeanlf@gpac.io>
Date: Tue Apr 19 09:08:45 2022 +0200
fixed #2173
Gbp-Pq: Name CVE-2022-30976.patch
Debian Multimedia Maintainers [Tue, 7 Mar 2023 11:41:07 +0000 (06:41 -0500)]
CVE-2022-29340
commit
37592ad86c6ca934d34740012213e467acc4a3b0
Author: jeanlf <jeanlf@gpac.io>
Date: Tue Apr 12 10:35:52 2022 +0200
fixed #2163
Gbp-Pq: Name CVE-2022-29340.patch
Debian Multimedia Maintainers [Tue, 7 Mar 2023 11:41:07 +0000 (06:41 -0500)]
CVE-2022-29339
commit
c4c76cc6e71f063d7d4664fa803ffea284e69ed9 (HEAD -> master)
Author: jeanlf <jeanlf@gpac.io>
Date: Tue Apr 12 10:56:15 2022 +0200
fixed #2165
Gbp-Pq: Name CVE-2022-29339.patch
Balint Reczey [Tue, 7 Mar 2023 11:41:07 +0000 (06:41 -0500)]
Don't fail build intentionally on unknown systems
Gbp-Pq: Name dont-err-build-on-uknown-system.patch
Alessio Treglia [Tue, 7 Mar 2023 11:41:07 +0000 (06:41 -0500)]
Add -O2 to CFLAGS by default, -O0 if noopt is set.
Forwarded: not-needed
Forwarded: not-needed
Gbp-Pq: Name gcc-optflags.patch
Reinhard Tartler [Tue, 7 Mar 2023 11:41:12 +0000 (06:41 -0500)]
debian/changelog: update
Reinhard Tartler [Tue, 7 Mar 2023 11:40:15 +0000 (06:40 -0500)]
make lintian overrides backwards compatible
This makes the override work both with the lintian in sid, as well as on
'stable' to work around ftp-master autorejects.
Reinhard Tartler [Tue, 7 Mar 2023 01:09:27 +0000 (20:09 -0500)]
debian/changelog: update
Reinhard Tartler [Tue, 7 Mar 2023 00:51:23 +0000 (19:51 -0500)]
update build-depends on libfreetype-dev
libfreetype6-dev is superseeded
Reinhard Tartler [Tue, 7 Mar 2023 00:44:58 +0000 (19:44 -0500)]
fix lintian overrides
Reinhard Tartler [Sun, 5 Mar 2023 13:11:44 +0000 (08:11 -0500)]
fixup CVE-2022-29340.patch
Reinhard Tartler [Sun, 5 Mar 2023 13:05:39 +0000 (08:05 -0500)]
debian/changelog: update
Reinhard Tartler [Sun, 5 Mar 2023 13:04:16 +0000 (08:04 -0500)]
Fix NULL Pointer Dereference, CVE-2022-2549, closes: #
1016142
Reinhard Tartler [Sun, 5 Mar 2023 13:02:42 +0000 (08:02 -0500)]
heap-based buffer overflow in gf_base64_encode, CVE-2022-26967, Closes: #
1007224
Reinhard Tartler [Sat, 4 Mar 2023 18:09:32 +0000 (13:09 -0500)]
debian/changelog: update
Reinhard Tartler [Sat, 4 Mar 2023 18:04:09 +0000 (13:04 -0500)]
fix Null Pointer dereference CVE-2022-36186
Reinhard Tartler [Sat, 4 Mar 2023 17:51:07 +0000 (12:51 -0500)]
stack overflow when processing ISOM_IOD, CVE-2022-38530
Reinhard Tartler [Sat, 4 Mar 2023 17:50:03 +0000 (12:50 -0500)]
debian/changelog: update
Reinhard Tartler [Sat, 4 Mar 2023 17:49:03 +0000 (12:49 -0500)]
Fix Integer Overflow, CVE-2022-2454
Reinhard Tartler [Sat, 4 Mar 2023 17:48:16 +0000 (12:48 -0500)]
Fix Use After Free, CVE-2022-2453
Reinhard Tartler [Sat, 4 Mar 2023 17:47:21 +0000 (12:47 -0500)]
debian/changelog: update
Reinhard Tartler [Sat, 4 Mar 2023 17:47:02 +0000 (12:47 -0500)]
debian/changelog: update
Reinhard Tartler [Sat, 4 Mar 2023 17:45:26 +0000 (12:45 -0500)]
Fix use after free, CVE-2022-1795
Reinhard Tartler [Sat, 4 Mar 2023 17:44:21 +0000 (12:44 -0500)]
Fix stack overflow in MP4Box CVE-2022-1441
Reinhard Tartler [Sat, 4 Mar 2023 17:43:29 +0000 (12:43 -0500)]
Fix inf loop, CVE-2022-1222
Reinhard Tartler [Sat, 4 Mar 2023 17:41:23 +0000 (12:41 -0500)]
Fix null pointer dereference in gf_bifs_dec_sf_field, CVE-2022-1172
Reinhard Tartler [Sat, 4 Mar 2023 17:40:10 +0000 (12:40 -0500)]
fix segfault in MP4Box, CVE-2022-1035
Reinhard Tartler [Sat, 4 Mar 2023 17:38:59 +0000 (12:38 -0500)]
Fix buffer overflow in utf8_wcslen, CVE-2022-30976
Reinhard Tartler [Sat, 4 Mar 2023 17:37:28 +0000 (12:37 -0500)]
Fix Null Pointer Dereference in gf_isom_parse_movie_boxes_internal, CVE-2022-29340
Reinhard Tartler [Sat, 4 Mar 2023 17:35:12 +0000 (12:35 -0500)]
fix DoS in function BS_ReadByte, CVE-2022-29339
Reinhard Tartler [Sat, 4 Mar 2023 17:34:39 +0000 (12:34 -0500)]
refresh patches
Dennis Braun [Sat, 18 Jun 2022 12:03:41 +0000 (14:03 +0200)]
Bump Standards Version to 4.6.1
Dennis Braun [Sat, 18 Jun 2022 12:02:36 +0000 (14:02 +0200)]
Use libjack-jackd2-dev as preferable B-D and libjack-dev as optional
Sebastian Ramacher [Fri, 25 Feb 2022 19:59:38 +0000 (20:59 +0100)]
Finalie changelog
Sebastian Ramacher [Thu, 24 Feb 2022 23:27:45 +0000 (00:27 +0100)]
Finalie changelog
Sebastian Ramacher [Thu, 24 Feb 2022 23:24:20 +0000 (00:24 +0100)]
More updates for 2.0.0
Sebastian Ramacher [Thu, 24 Feb 2022 23:23:23 +0000 (00:23 +0100)]
Update override to current lintian update
Sebastian Ramacher [Thu, 24 Feb 2022 23:17:37 +0000 (00:17 +0100)]
Replace libsdl1.2-dev with libsdl2-dev
Sebastian Ramacher [Thu, 24 Feb 2022 23:13:31 +0000 (00:13 +0100)]
No longer remove .desktop file
Sebastian Ramacher [Thu, 24 Feb 2022 23:07:17 +0000 (00:07 +0100)]
SONAME bump: libgpac10 -> libgpac11
Sebastian Ramacher [Thu, 24 Feb 2022 23:01:25 +0000 (00:01 +0100)]
Remove upstream patches
Sebastian Ramacher [Thu, 24 Feb 2022 23:00:57 +0000 (00:00 +0100)]
Bump ffmpeg build dependencies
Sebastian Ramacher [Thu, 24 Feb 2022 22:55:52 +0000 (23:55 +0100)]
Update copyyright for 2.0.0 and merge entries
Sebastian Ramacher [Thu, 24 Feb 2022 22:33:15 +0000 (23:33 +0100)]
Update upstream source from tag 'upstream/2.0.0+dfsg1'
Update to upstream version '2.0.0+dfsg1'
with Debian dir
6fca2d50a4a74724f62bd51d82cf9f7b438421b4
Sebastian Ramacher [Thu, 24 Feb 2022 22:33:02 +0000 (23:33 +0100)]
New upstream version 2.0.0+dfsg1
Sebastian Ramacher [Thu, 24 Feb 2022 22:32:04 +0000 (23:32 +0100)]
Add repacksuffix
Sebastian Ramacher [Wed, 1 Sep 2021 19:58:02 +0000 (21:58 +0200)]
Finalize changelog
Sebastian Ramacher [Wed, 1 Sep 2021 19:57:41 +0000 (21:57 +0200)]
Apply patches for a bunch of CVEs
Sebastian Ramacher [Wed, 1 Sep 2021 19:44:48 +0000 (21:44 +0200)]
Set RRR: no
Sebastian Ramacher [Wed, 1 Sep 2021 19:44:22 +0000 (21:44 +0200)]
Bump Standards-Version
Sebastian Ramacher [Wed, 1 Sep 2021 19:40:40 +0000 (21:40 +0200)]
Drop unused Build-Depends
Reinhard Tartler [Tue, 25 May 2021 01:10:41 +0000 (21:10 -0400)]
debian/changelog: update
Reinhard Tartler [Tue, 25 May 2021 01:10:10 +0000 (21:10 -0400)]
Merge branch 'experimental'
Reinhard Tartler [Mon, 24 May 2021 12:31:57 +0000 (08:31 -0400)]
Make sure to clean generated share/gpac.desktop
Moritz Muehlenhoff [Sat, 15 May 2021 15:11:46 +0000 (17:11 +0200)]
update changelog
Moritz Muehlenhoff [Sat, 15 May 2021 15:06:50 +0000 (17:06 +0200)]
Cherrypicked fixes for multiple security issues:
(Closes: #987280, #987323, #987374)
- CVE-2021-30014/CVE-2021-30020/CVE-2021-30022
- CVE-2020-35979
- CVE-2020-35981
- CVE-2020-35982
- CVE-2021-28300
- CVE-2021-29279
- CVE-2021-31255
- CVE-2021-31256
- CVE-2021-31261
- CVE-2021-30015
- CVE-2021-30019
- CVE-2021-30199
- CVE-2021-31257
- CVE-2021-31258
- CVE-2021-31260
- CVE-2021-31262
Reinhard Tartler [Wed, 25 Nov 2020 20:44:35 +0000 (15:44 -0500)]
Bugfix: FTBFS on armel: missing -latomic (Closes: #975433)
Reinhard Tartler [Wed, 25 Nov 2020 20:42:41 +0000 (15:42 -0500)]
Clean share/gpac.desktop, Closes: #975779
Reinhard Tartler [Sat, 21 Nov 2020 22:13:59 +0000 (17:13 -0500)]
upload to unstable
Reinhard Tartler [Wed, 18 Nov 2020 02:55:55 +0000 (21:55 -0500)]
fix lintian override
Reinhard Tartler [Wed, 18 Nov 2020 02:41:42 +0000 (21:41 -0500)]
avoid duplicate entry in debian/copyright
Reinhard Tartler [Wed, 18 Nov 2020 02:41:23 +0000 (21:41 -0500)]
silence lintian warning "source-is-missing"
Reinhard Tartler [Wed, 18 Nov 2020 02:40:05 +0000 (21:40 -0500)]
fix 'symbols-file-contains-current-version-with-debian-revision'
From lintian output:
Debian revisions should be stripped from versions in symbols files.
Not doing so leads to dependencies unsatisfiable by backports
(1.0-1~bpo << 1.0-1 while 1.0-1~bpo >= 1.0). If the Debian revision
can't be stripped because the symbol really appeared between two
specific Debian revisions, you should postfix the version with a
single "~" (example: 1.0-3~ if the symbol appeared in 1.0-3).
.
This problem normally means that the symbols were added automatically
by dpkg-gensymbols. dpkg-gensymbols uses the full version number for
the dependency associated to any new symbol that it detects. The
maintainer must update the debian/<package>.symbols file by adding the
new symbols with the corresponding upstream version.
Reinhard Tartler [Wed, 18 Nov 2020 02:38:43 +0000 (21:38 -0500)]
no longer install menu file
The command is listed both a desktop file
Per the tech-ctte decision on Bug#741573, it must not be mentioned in both the
.desktop and the menu file at the same time. I'm choosing the .desktop file
Reinhard Tartler [Tue, 17 Nov 2020 23:32:57 +0000 (18:32 -0500)]
debian/changelog: update
Reinhard Tartler [Tue, 17 Nov 2020 23:28:14 +0000 (18:28 -0500)]
small copyright cleanups
suggested by 'cme fix dpkg-copyright'
Reinhard Tartler [Tue, 17 Nov 2020 23:22:27 +0000 (18:22 -0500)]
update debian/changelog
Reinhard Tartler [Tue, 17 Nov 2020 23:02:57 +0000 (18:02 -0500)]
Update upstream source from tag 'upstream/1.0.1+dfsg1'
Update to upstream version '1.0.1+dfsg1'
with Debian dir
a6e274d9b25f2c7366e86d8e27998bbde93f1af3
Reinhard Tartler [Tue, 17 Nov 2020 23:02:44 +0000 (18:02 -0500)]
New upstream version 1.0.1+dfsg1
Reinhard Tartler [Tue, 17 Nov 2020 22:57:56 +0000 (17:57 -0500)]
cleanup exclusions
Reinhard Tartler [Tue, 17 Nov 2020 22:50:44 +0000 (17:50 -0500)]
update symbols file
Reinhard Tartler [Tue, 17 Nov 2020 19:58:14 +0000 (14:58 -0500)]
install the pkg-config file
Reinhard Tartler [Tue, 17 Nov 2020 18:45:07 +0000 (13:45 -0500)]
install new manpages
Reinhard Tartler [Tue, 17 Nov 2020 18:34:06 +0000 (13:34 -0500)]
drop debian/gpac.manpages, no longer needed
Reinhard Tartler [Tue, 17 Nov 2020 18:27:42 +0000 (13:27 -0500)]
gpac.docs: from share/doc instead of doc/
Reinhard Tartler [Tue, 17 Nov 2020 16:00:43 +0000 (11:00 -0500)]
gpac.install: install all of share
Reinhard Tartler [Tue, 17 Nov 2020 13:06:36 +0000 (08:06 -0500)]
drop mp4box normalization (no longer installed?)
Reinhard Tartler [Tue, 17 Nov 2020 12:53:45 +0000 (07:53 -0500)]
avoid cleaning 'debian'
Reinhard Tartler [Tue, 17 Nov 2020 12:31:40 +0000 (07:31 -0500)]
refresh/drop distro patches
Reinhard Tartler [Tue, 17 Nov 2020 12:28:32 +0000 (07:28 -0500)]
debian/changelog: prepare new upload
Reinhard Tartler [Tue, 17 Nov 2020 12:27:24 +0000 (07:27 -0500)]
upstream bumped soname 7->10
Reinhard Tartler [Mon, 16 Nov 2020 12:12:50 +0000 (07:12 -0500)]
drop deprecated apps
needs further copyright review, maybe parts (or all) could be included in a
future revision
Reinhard Tartler [Tue, 17 Nov 2020 12:23:09 +0000 (07:23 -0500)]
debian/copyright: Reworked with 'cme dpkg-copyright'
Following the guides from
https://github.com/dod38fr/config-model/wiki/Updating-debian-copyright-file-with-cme
Reinhard Tartler [Mon, 16 Nov 2020 12:08:15 +0000 (07:08 -0500)]
debian/copyright: cleanups
drop entries from "Files-Excluded" section that are no longer included in the
upstream tarball
Reinhard Tartler [Sat, 14 Nov 2020 22:06:54 +0000 (17:06 -0500)]
Update upstream source from tag 'upstream/1.0.1'
Update to upstream version '1.0.1'
with Debian dir
7909422ddee0bd5d964b17a7d8516012f9c0b26c
Reinhard Tartler [Sat, 14 Nov 2020 22:06:39 +0000 (17:06 -0500)]
New upstream version 1.0.1
Reinhard Tartler [Sat, 14 Nov 2020 22:06:15 +0000 (17:06 -0500)]
ignore additional swf file without source
Reinhard Tartler [Sat, 14 Nov 2020 02:28:00 +0000 (21:28 -0500)]
update debian/changelog
Reinhard Tartler [Sat, 14 Nov 2020 02:32:48 +0000 (21:32 -0500)]
Fix FTCBFS: Pass --cross-prefix to ./configure
Closes: #945200
Reinhard Tartler [Sat, 14 Nov 2020 02:26:31 +0000 (21:26 -0500)]
Merge remote-tracking branch 'salsa/master' into master
Reinhard Tartler [Sat, 14 Nov 2020 02:11:28 +0000 (21:11 -0500)]
debian/control: cleanup
unused BSD-2 clause paragraph
Reinhard Tartler [Sat, 14 Nov 2020 02:10:51 +0000 (21:10 -0500)]
libgpac7.symbols: Add Build-Depends-Package field
suggested by lintian
Reinhard Tartler [Sat, 14 Nov 2020 02:10:27 +0000 (21:10 -0500)]
debian/control: cleanup
osmo4_wx no longer present
Sebastian Ramacher [Sun, 20 Sep 2020 17:19:15 +0000 (19:19 +0200)]
Bump to debhelper compat 13
Sebastian Ramacher [Sun, 20 Sep 2020 16:53:24 +0000 (18:53 +0200)]
Remove obsolete Pre-Depends
Sebastian Ramacher [Sun, 23 Aug 2020 14:11:14 +0000 (14:11 +0000)]
Merge branch 'lintian-fixes' into 'master'
Fix some issues reported by lintian
See merge request multimedia-team/gpac!1