head 1.1; access; symbols pkgsrc-2026Q1:1.1.0.60 pkgsrc-2026Q1-base:1.1 pkgsrc-2025Q4:1.1.0.58 pkgsrc-2025Q4-base:1.1 pkgsrc-2025Q3:1.1.0.56 pkgsrc-2025Q3-base:1.1 pkgsrc-2025Q2:1.1.0.54 pkgsrc-2025Q2-base:1.1 pkgsrc-2025Q1:1.1.0.52 pkgsrc-2025Q1-base:1.1 pkgsrc-2024Q4:1.1.0.50 pkgsrc-2024Q4-base:1.1 pkgsrc-2024Q3:1.1.0.48 pkgsrc-2024Q3-base:1.1 pkgsrc-2024Q2:1.1.0.46 pkgsrc-2024Q2-base:1.1 pkgsrc-2024Q1:1.1.0.44 pkgsrc-2024Q1-base:1.1 pkgsrc-2023Q4:1.1.0.42 pkgsrc-2023Q4-base:1.1 pkgsrc-2023Q3:1.1.0.40 pkgsrc-2023Q3-base:1.1 pkgsrc-2023Q2:1.1.0.38 pkgsrc-2023Q2-base:1.1 pkgsrc-2023Q1:1.1.0.36 pkgsrc-2023Q1-base:1.1 pkgsrc-2022Q4:1.1.0.34 pkgsrc-2022Q4-base:1.1 pkgsrc-2022Q3:1.1.0.32 pkgsrc-2022Q3-base:1.1 pkgsrc-2022Q2:1.1.0.30 pkgsrc-2022Q2-base:1.1 pkgsrc-2022Q1:1.1.0.28 pkgsrc-2022Q1-base:1.1 pkgsrc-2021Q4:1.1.0.26 pkgsrc-2021Q4-base:1.1 pkgsrc-2021Q3:1.1.0.24 pkgsrc-2021Q3-base:1.1 pkgsrc-2021Q2:1.1.0.22 pkgsrc-2021Q2-base:1.1 pkgsrc-2021Q1:1.1.0.20 pkgsrc-2021Q1-base:1.1 pkgsrc-2020Q4:1.1.0.18 pkgsrc-2020Q4-base:1.1 pkgsrc-2020Q3:1.1.0.16 pkgsrc-2020Q3-base:1.1 pkgsrc-2020Q2:1.1.0.14 pkgsrc-2020Q2-base:1.1 pkgsrc-2020Q1:1.1.0.10 pkgsrc-2020Q1-base:1.1 pkgsrc-2019Q4:1.1.0.12 pkgsrc-2019Q4-base:1.1 pkgsrc-2019Q3:1.1.0.8 pkgsrc-2019Q3-base:1.1 pkgsrc-2019Q2:1.1.0.6 pkgsrc-2019Q2-base:1.1 pkgsrc-2019Q1:1.1.0.4 pkgsrc-2019Q1-base:1.1 pkgsrc-2018Q4:1.1.0.2 pkgsrc-2018Q4-base:1.1; locks; strict; comment @// @; 1.1 date 2018.10.12.13.51.59; author martin; state Exp; branches; next ; commitid MQ0pop7UnkbMVFVA; desc @@ 1.1 log @Fix a buffer overflow caused by miscalculation of the maximal VBR header size. Bump revision. @ text @$NetBSD$ Fix a miscalculation of the VBR maximal header size, upstream has already been notified (there is a user review about this issue) --- src/mp3_parse.cpp.orig 2003-03-02 01:23:00.000000000 +0100 +++ src/mp3_parse.cpp 2018-10-12 15:46:21.863323611 +0200 @@@@ -465,7 +465,7 @@@@ bool Mp3Info::Parse(ID3_Reader& reader, // from http://www.xingtech.com/developer/mp3/ const size_t VBR_HEADER_MIN_SIZE = 8; // "xing" + flags are fixed - const size_t VBR_HEADER_MAX_SIZE = 116; // frames, bytes, toc and scale are optional + const size_t VBR_HEADER_MAX_SIZE = 120; // frames, bytes, toc and scale are optional if (mp3size >= vbr_header_offest + VBR_HEADER_MIN_SIZE) { @