View | Details | Raw Unified | Return to bug 203410
Collapse All | Expand All

(-)multimedia/libvpx/Makefile (-3 / +9 lines)
Lines 5-10 PORTNAME= libvpx Link Here
5
DISTVERSIONPREFIX=	v
5
DISTVERSIONPREFIX=	v
6
DISTVERSION=	1.4.0-488 # tracking www/firefox
6
DISTVERSION=	1.4.0-488 # tracking www/firefox
7
DISTVERSIONSUFFIX=	-ge67d45d
7
DISTVERSIONSUFFIX=	-ge67d45d
8
PORTREVISION=	1
8
CATEGORIES=	multimedia
9
CATEGORIES=	multimedia
9
10
10
MAINTAINER=	ashish@FreeBSD.org
11
MAINTAINER=	ashish@FreeBSD.org
Lines 24-35 HAS_CONFIGURE= yes Link Here
24
USE_PERL5=	build
25
USE_PERL5=	build
25
USE_LDCONFIG=	yes
26
USE_LDCONFIG=	yes
26
27
27
OPTIONS_DEFINE=	DEBUG POSTPROC RUNTIME THREADS SHARED
28
OPTIONS_DEFINE=	DEBUG MULTIRES POSTPROC RUNTIME SHARED SIZE_LIMIT THREADS
28
OPTIONS_DEFAULT=	POSTPROC RUNTIME THREADS SHARED
29
OPTIONS_DEFAULT=MULTIRES POSTPROC RUNTIME SHARED SIZE_LIMIT THREADS
29
OPTIONS_EXCLUDE_armv6=	RUNTIME
30
OPTIONS_EXCLUDE_armv6=	RUNTIME
31
MULTIRES_DESC=	Enable multiple-resolution encoding
30
POSTPROC_DESC=	Enable postprocessing
32
POSTPROC_DESC=	Enable postprocessing
31
RUNTIME_DESC=	Enable runtime CPU detection
33
RUNTIME_DESC=	Enable runtime CPU detection
32
SHARED_DESC=	Enable shared-library support
34
SHARED_DESC=	Enable shared-library support
35
SIZE_LIMIT_DESC=Max size to allow in the decoder (default: ${SIZE_LIMIT})
33
36
34
ALL_TARGET=
37
ALL_TARGET=
35
CONFIGURE_ARGS+=--prefix=${PREFIX} \
38
CONFIGURE_ARGS+=--prefix=${PREFIX} \
Lines 44-53 MAKE_ENV= LC_ALL=C Link Here
44
OPTIONS_SUB=		SHARED
47
OPTIONS_SUB=		SHARED
45
48
46
DEBUG_CONFIGURE_ON=	--enable-debug
49
DEBUG_CONFIGURE_ON=	--enable-debug
50
MULTIRES_CONFIGURE_ON=	--enable-multi-res-encoding
47
POSTPROC_CONFIGURE_ON=	--enable-postproc
51
POSTPROC_CONFIGURE_ON=	--enable-postproc
48
RUNTIME_CONFIGURE_ON=	--enable-runtime-cpu-detect
52
RUNTIME_CONFIGURE_ON=	--enable-runtime-cpu-detect
49
THREADS_CONFIGURE_OFF=	--disable-multithread
50
SHARED_CONFIGURE_ON=	--enable-shared
53
SHARED_CONFIGURE_ON=	--enable-shared
54
SIZE_LIMIT_CONFIGURE_ON=--size-limit=${SIZE_LIMIT}
55
SIZE_LIMIT?=		4000x3000 # same as VideoUtils.h in Firefox
56
THREADS_CONFIGURE_OFF=	--disable-multithread
51
57
52
SHEBANG_FILES=	build/make/ads2gas.pl
58
SHEBANG_FILES=	build/make/ads2gas.pl
53
59
(-)security/vuxml/vuln.xml (+30 lines)
Lines 58-63 Notes: Link Here
58
58
59
-->
59
-->
60
<vuxml xmlns="http://www.vuxml.org/apps/vuxml-1">
60
<vuxml xmlns="http://www.vuxml.org/apps/vuxml-1">
61
  <vuln vid="6ca7eddd-d436-486a-b169-b948436bcf14">
62
    <topic>libvpx -- buffer overflow in vp9_init_context_buffers</topic>
63
    <affects>
64
      <package>
65
	<name>libvpx</name>
66
	<range><lt>1.4.0.488_1</lt></range>
67
      </package>
68
    </affects>
69
    <description>
70
      <body xmlns="http://www.w3.org/1999/xhtml">
71
	<p>The Mozilla Project reports:</p>
72
	<blockquote cite="https://www.mozilla.org/security/advisories/mfsa2015-101/">
73
	  <p>Security researcher Khalil Zhani reported that a
74
	    maliciously crafted vp9 format video could be used to
75
	    trigger a buffer overflow while parsing the file. This leads
76
	    to a potentially exploitable crash due to a flaw in the
77
	    libvpx library.</p>
78
	</blockquote>
79
      </body>
80
    </description>
81
    <references>
82
      <cvename>CVE-2015-4506</cvename>
83
      <url>https://www.mozilla.org/security/advisories/mfsa2015-101/</url>
84
    </references>
85
    <dates>
86
      <discovery>2015-09-22</discovery>
87
      <entry>2015-09-28</entry>
88
    </dates>
89
  </vuln>
90
61
  <vuln vid="5114cd11-6571-11e5-9909-002590263bf5">
91
  <vuln vid="5114cd11-6571-11e5-9909-002590263bf5">
62
    <topic>codeigniter -- SQL injection vulnerability</topic>
92
    <topic>codeigniter -- SQL injection vulnerability</topic>
63
    <affects>
93
    <affects>

Return to bug 203410