Hello community, here is the log from the commit of package ZynAddSubFX checked in at Mon Jan 21 01:18:57 CET 2008. -------- --- ZynAddSubFX/ZynAddSubFX.changes 2007-04-26 12:19:07.000000000 +0200 +++ /mounts/work_src_done/STABLE/ZynAddSubFX/ZynAddSubFX.changes 2008-01-18 13:32:21.000000000 +0100 @@ -1,0 +2,5 @@ +Fri Jan 18 13:32:13 CET 2008 - tiwai@suse.de + +- fix strncat usage to avoid overflow. + +------------------------------------------------------------------- New: ---- ZynAddSubFX-strncat-fix.diff ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Other differences: ------------------ ++++++ ZynAddSubFX.spec ++++++ --- /var/tmp/diff_new_pack.q28212/_old 2008-01-21 01:18:24.000000000 +0100 +++ /var/tmp/diff_new_pack.q28212/_new 2008-01-21 01:18:24.000000000 +0100 @@ -1,7 +1,7 @@ # # spec file for package ZynAddSubFX (Version 2.2.1) # -# Copyright (c) 2007 SUSE LINUX Products GmbH, Nuernberg, Germany. +# Copyright (c) 2008 SUSE LINUX Products GmbH, Nuernberg, Germany. # This file and all modifications and additions to the pristine # package are under the same license as the package itself. # @@ -11,19 +11,25 @@ # norootforbuild Name: ZynAddSubFX -BuildRequires: alsa-devel fftw3-devel fltk-devel gcc-c++ jack-devel libjpeg-devel libpng-devel mxml-devel update-desktop-files xorg-x11-devel +BuildRequires: alsa-devel fftw3-devel fltk-devel gcc-c++ jack-devel libjpeg-devel libpng-devel update-desktop-files xorg-x11-devel +%if %suse_version > 1020 +BuildRequires: mxml-devel +%else +BuildRequires: mxml +%endif Version: 2.2.1 -Release: 60 +Release: 133 Summary: A Real-Time Software Synthesizer for Linux -License: GNU General Public License (GPL) +License: GPL v2 or later Group: Productivity/Multimedia/Sound/Midi -URL: http://zynaddsubfx.sourceforge.net/ +Url: http://zynaddsubfx.sourceforge.net/ BuildRoot: %{_tmppath}/%{name}-%{version}-build Source: %{name}-%{version}.tar.bz2 Source1: ZynAddSubFX.desktop Source2: ZynAddSubFX.png Patch: ZynAddSubFX.dif Patch1: ZynAddSubFX-array-overflow-fix.diff +Patch2: ZynAddSubFX-strncat-fix.diff %description ZynAddSubFX is a many-featured real-time software synthesizer for @@ -39,9 +45,10 @@ Nasca Octavian Paul %prep -%setup +%setup -q %patch %patch1 +%patch2 %build cd src @@ -80,42 +87,44 @@ %{_datadir}/zynaddsubfx %changelog -* Thu Apr 26 2007 - tiwai@suse.de +* Fri Jan 18 2008 tiwai@suse.de +- fix strncat usage to avoid overflow. +* Thu Apr 26 2007 tiwai@suse.de - fix buildrequires, use mxml-devel - fix desktop file, use GenericName -* Mon Feb 26 2007 - tiwai@suse.de +* Mon Feb 26 2007 tiwai@suse.de - fix array overflow (#247335) -* Wed Jan 25 2006 - mls@suse.de +* Wed Jan 25 2006 mls@suse.de - converted neededforbuild to BuildRequires -* Wed Oct 12 2005 - tiwai@suse.de +* Wed Oct 12 2005 tiwai@suse.de - removed glib* from neededforbuild. -* Wed Jul 27 2005 - tiwai@suse.de +* Wed Jul 27 2005 tiwai@suse.de - updated to version 2.2.1. -* Fri Apr 15 2005 - tiwai@suse.de +* Fri Apr 15 2005 tiwai@suse.de - updated to version 2.2.0. - fixed for gcc-4.0. -* Fri Jan 21 2005 - tiwai@suse.de +* Fri Jan 21 2005 tiwai@suse.de - updated to version 2.1.1. added desktop file again. -* Wed Sep 15 2004 - tiwai@suse.de +* Wed Sep 15 2004 tiwai@suse.de - removed desktop file (not working from menu). -* Sun Jan 11 2004 - adrian@suse.de +* Sun Jan 11 2004 adrian@suse.de - build as user -* Tue Nov 18 2003 - tiwai@suse.de +* Tue Nov 18 2003 tiwai@suse.de - updated to version 1.4.3. -* Mon Sep 15 2003 - tiwai@suse.de +* Mon Sep 15 2003 tiwai@suse.de - added desktop file and icon. -* Fri Jul 18 2003 - tiwai@suse.de +* Fri Jul 18 2003 tiwai@suse.de - updated to version 1.4.2. -* Wed Jul 02 2003 - tiwai@suse.de +* Wed Jul 02 2003 tiwai@suse.de - updated to version 1.4.1. -* Thu Mar 27 2003 - tiwai@suse.de +* Thu Mar 27 2003 tiwai@suse.de - updated to version 1.2.0. -* Fri Feb 14 2003 - tiwai@suse.de +* Fri Feb 14 2003 tiwai@suse.de - updated to version 1.0.8. -* Fri Feb 07 2003 - tiwai@suse.de +* Fri Feb 07 2003 tiwai@suse.de - updated to version 1.0.7. - linked with sfftw correctly now. - fixed compile warnings. -* Wed Feb 05 2003 - tiwai@suse.de +* Wed Feb 05 2003 tiwai@suse.de - initial version: 1.0.6. ++++++ ZynAddSubFX-strncat-fix.diff ++++++ --- src/Misc/Bank.C-dist 2008-01-18 13:25:58.000000000 +0100 +++ src/Misc/Bank.C 2008-01-18 13:31:24.000000000 +0100 @@ -289,9 +289,9 @@ int Bank::newbank(const char *newbankdir snprintf(bankdir,MAX_STRING_SIZE,"%s",config.cfg.bankRootDirList[0]); if (((bankdir[strlen(bankdir)-1])!='/')&&((bankdir[strlen(bankdir)-1])!='\\')){ - strncat(bankdir,"/",MAX_STRING_SIZE); + strncat(bankdir,"/",MAX_STRING_SIZE-strlen(bankdir)-1); }; - strncat(bankdir,newbankdirname,MAX_STRING_SIZE); + strncat(bankdir,newbankdirname,MAX_STRING_SIZE-strlen(bankdir)-1); #ifdef OS_WINDOWS result=mkdir(bankdir); #else ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Remember to have fun... --------------------------------------------------------------------- To unsubscribe, e-mail: opensuse-commit+unsubscribe@opensuse.org For additional commands, e-mail: opensuse-commit+help@opensuse.org
participants (1)
-
root@Hilbert.suse.de