--- multimedia/libvpx/Makefile +++ multimedia/libvpx/Makefile @@ -5,6 +5,7 @@ PORTNAME= libvpx DISTVERSIONPREFIX= v DISTVERSION= 1.4.0-488 # tracking www/firefox DISTVERSIONSUFFIX= -ge67d45d +PORTREVISION= 1 CATEGORIES= multimedia MAINTAINER= ashish@FreeBSD.org @@ -24,12 +25,14 @@ HAS_CONFIGURE= yes USE_PERL5= build USE_LDCONFIG= yes -OPTIONS_DEFINE= DEBUG POSTPROC RUNTIME THREADS SHARED -OPTIONS_DEFAULT= POSTPROC RUNTIME THREADS SHARED +OPTIONS_DEFINE= DEBUG MULTIRES POSTPROC RUNTIME SHARED SIZE_LIMIT THREADS +OPTIONS_DEFAULT=MULTIRES POSTPROC RUNTIME SHARED SIZE_LIMIT THREADS OPTIONS_EXCLUDE_armv6= RUNTIME +MULTIRES_DESC= Enable multiple-resolution encoding POSTPROC_DESC= Enable postprocessing RUNTIME_DESC= Enable runtime CPU detection SHARED_DESC= Enable shared-library support +SIZE_LIMIT_DESC=Max size to allow in the decoder (default: ${SIZE_LIMIT}) ALL_TARGET= CONFIGURE_ARGS+=--prefix=${PREFIX} \ @@ -44,10 +47,13 @@ MAKE_ENV= LC_ALL=C OPTIONS_SUB= SHARED DEBUG_CONFIGURE_ON= --enable-debug +MULTIRES_CONFIGURE_ON= --enable-multi-res-encoding POSTPROC_CONFIGURE_ON= --enable-postproc RUNTIME_CONFIGURE_ON= --enable-runtime-cpu-detect -THREADS_CONFIGURE_OFF= --disable-multithread SHARED_CONFIGURE_ON= --enable-shared +SIZE_LIMIT_CONFIGURE_ON=--size-limit=${SIZE_LIMIT} +SIZE_LIMIT?= 4000x3000 # same as VideoUtils.h in Firefox +THREADS_CONFIGURE_OFF= --disable-multithread SHEBANG_FILES= build/make/ads2gas.pl --- security/vuxml/vuln.xml +++ security/vuxml/vuln.xml @@ -58,6 +58,36 @@ Notes: --> + + libvpx -- buffer overflow in vp9_init_context_buffers + + + libvpx + 1.4.0.488_1 + + + + +

The Mozilla Project reports:

+
+

Security researcher Khalil Zhani reported that a + maliciously crafted vp9 format video could be used to + trigger a buffer overflow while parsing the file. This leads + to a potentially exploitable crash due to a flaw in the + libvpx library.

+
+ +
+ + CVE-2015-4506 + https://www.mozilla.org/security/advisories/mfsa2015-101/ + + + 2015-09-22 + 2015-09-28 + +
+ codeigniter -- SQL injection vulnerability