Skip to content
Commit eca03d67 authored by Peter Korsgaard's avatar Peter Korsgaard
Browse files

libvorbis: security bump to version 1.3.6



Fixes CVE-2018-5146: Prevent out-of-bounds write in codebook decoding.

Drop 0001-CVE-2017-14633-Don-t-allow-for-more-than-256-channel.patch and
0002-CVE-2017-14632-vorbis_analysis_header_out-Don-t-clea.patch as they are
now upstream, and add a hash for the license file while we're at it.

Signed-off-by: default avatarPeter Korsgaard <peter@korsgaard.com>
parent b71a4e20
Loading
Loading
Loading
Loading
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment