gnu: gst-plugins-base: Update to 1.18.5.
* gnu/packages/gstreamer.scm (gst-plugins-base): Update to 1.18.5. [source]: Remove patches. [inputs]: Move wayland... [propagated-inputs]: here. * gnu/packages/patches/gst-plugins-base-fix-id3v2-invalid-read.patch: Delete file. * gnu/local.mk: De-register it.
This commit is contained in:
		
							parent
							
								
									553a8696cf
								
							
						
					
					
						commit
						a87cfa250d
					
				
					 3 changed files with 6 additions and 47 deletions
				
			
		|  | @ -1217,7 +1217,6 @@ dist_patch_DATA =						\ | ||||||
|   %D%/packages/patches/gspell-dash-test.patch			\
 |   %D%/packages/patches/gspell-dash-test.patch			\
 | ||||||
|   %D%/packages/patches/gst-libav-64channels-stack-corruption.patch	\
 |   %D%/packages/patches/gst-libav-64channels-stack-corruption.patch	\
 | ||||||
|   %D%/packages/patches/gst-plugins-bad-fix-overflow.patch	\
 |   %D%/packages/patches/gst-plugins-bad-fix-overflow.patch	\
 | ||||||
|   %D%/packages/patches/gst-plugins-base-fix-id3v2-invalid-read.patch	\
 |  | ||||||
|   %D%/packages/patches/gst-plugins-good-fix-test.patch		\
 |   %D%/packages/patches/gst-plugins-good-fix-test.patch		\
 | ||||||
|   %D%/packages/patches/gst-plugins-good-CVE-2021-3497.patch	\
 |   %D%/packages/patches/gst-plugins-good-CVE-2021-3497.patch	\
 | ||||||
|   %D%/packages/patches/gst-plugins-good-CVE-2021-3498.patch	\
 |   %D%/packages/patches/gst-plugins-good-CVE-2021-3498.patch	\
 | ||||||
|  |  | ||||||
|  | @ -543,21 +543,22 @@ This package provides the core library and elements.") | ||||||
| (define-public gst-plugins-base | (define-public gst-plugins-base | ||||||
|   (package |   (package | ||||||
|     (name "gst-plugins-base") |     (name "gst-plugins-base") | ||||||
|     (version "1.18.4") |     (version "1.18.5") | ||||||
|     (source |     (source | ||||||
|      (origin |      (origin | ||||||
|       (method url-fetch) |       (method url-fetch) | ||||||
|       (uri (string-append "https://gstreamer.freedesktop.org/src/" name "/" |       (uri (string-append "https://gstreamer.freedesktop.org/src/" name "/" | ||||||
|                           name "-" version ".tar.xz")) |                           name "-" version ".tar.xz")) | ||||||
|       (patches (search-patches "gst-plugins-base-fix-id3v2-invalid-read.patch")) |  | ||||||
|       (sha256 |       (sha256 | ||||||
|        (base32 |        (base32 | ||||||
|         "08w3ivbc6n4vdds2ap6q7l8zdk9if8417nznyqidf0adm0lk5r99")))) |         "18vg8kk7p2p8za8zaqg0v7z6898yw5a3b12vvl7xn02pb3s7l2wn")))) | ||||||
|     (build-system meson-build-system) |     (build-system meson-build-system) | ||||||
|     (propagated-inputs |     (propagated-inputs | ||||||
|      `(("glib" ,glib)              ;required by gstreamer-sdp-1.0.pc |      `(("glib" ,glib)              ;required by gstreamer-sdp-1.0.pc | ||||||
|        ("gstreamer" ,gstreamer)    ;required by gstreamer-plugins-base-1.0.pc |        ("gstreamer" ,gstreamer)    ;required by gstreamer-plugins-base-1.0.pc | ||||||
| 
 |        ;; wayland-client.h is referred to in | ||||||
|  |        ;; include/gstreamer-1.0/gst/gl/wayland/gstgldisplay_wayland.h | ||||||
|  |        ("wayland" ,wayland) | ||||||
|        ;; XXX: Do not enable Orc optimizations on ARM systems because |        ;; XXX: Do not enable Orc optimizations on ARM systems because | ||||||
|        ;; it leads to two test failures. |        ;; it leads to two test failures. | ||||||
|        ;; https://gitlab.freedesktop.org/gstreamer/gst-plugins-base/issues/683 |        ;; https://gitlab.freedesktop.org/gstreamer/gst-plugins-base/issues/683 | ||||||
|  | @ -585,8 +586,7 @@ This package provides the core library and elements.") | ||||||
|        ("libpng" ,libpng) |        ("libpng" ,libpng) | ||||||
|        ("libvisual" ,libvisual) |        ("libvisual" ,libvisual) | ||||||
|        ("mesa" ,mesa) |        ("mesa" ,mesa) | ||||||
|        ("wayland-protocols" ,wayland-protocols) |        ("wayland-protocols" ,wayland-protocols))) | ||||||
|        ("wayland" ,wayland))) |  | ||||||
|     (native-inputs |     (native-inputs | ||||||
|      `(("pkg-config" ,pkg-config) |      `(("pkg-config" ,pkg-config) | ||||||
|        ("glib:bin" ,glib "bin") |        ("glib:bin" ,glib "bin") | ||||||
|  |  | ||||||
|  | @ -1,40 +0,0 @@ | ||||||
| Fix an "invalid read during ID3v2 tag parsing". |  | ||||||
| 
 |  | ||||||
| https://security-tracker.debian.org/tracker/TEMP-0000000-57E7C1 |  | ||||||
| https://gitlab.freedesktop.org/gstreamer/gst-plugins-base/-/issues/876 |  | ||||||
| 
 |  | ||||||
| Patch copied from upstream source repository: |  | ||||||
| 
 |  | ||||||
| https://gitlab.freedesktop.org/gstreamer/gst-plugins-base/-/commit/f4a1428a6997658625d529b9db60fde812fbf1ee |  | ||||||
| 
 |  | ||||||
| From f4a1428a6997658625d529b9db60fde812fbf1ee Mon Sep 17 00:00:00 2001 |  | ||||||
| From: =?UTF-8?q?Tim-Philipp=20M=C3=BCller?= <tim@centricular.com> |  | ||||||
| Date: Wed, 3 Mar 2021 01:08:25 +0000 |  | ||||||
| Subject: [PATCH] tag: id3v2: fix frame size check and potential invalid reads |  | ||||||
| 
 |  | ||||||
| Check the right variable when checking if there's |  | ||||||
| enough data left to read the frame size. |  | ||||||
| 
 |  | ||||||
| Closes https://gitlab.freedesktop.org/gstreamer/gst-plugins-base/-/issues/876 |  | ||||||
| 
 |  | ||||||
| Part-of: <https://gitlab.freedesktop.org/gstreamer/gst-plugins-base/-/merge_requests/1065> |  | ||||||
| ---
 |  | ||||||
|  gst-libs/gst/tag/id3v2frames.c | 2 +- |  | ||||||
|  1 file changed, 1 insertion(+), 1 deletion(-) |  | ||||||
| 
 |  | ||||||
| diff --git a/gst-libs/gst/tag/id3v2frames.c b/gst-libs/gst/tag/id3v2frames.c
 |  | ||||||
| index 8e9f78254..f39659bf7 100644
 |  | ||||||
| --- a/gst-libs/gst/tag/id3v2frames.c
 |  | ||||||
| +++ b/gst-libs/gst/tag/id3v2frames.c
 |  | ||||||
| @@ -109,7 +109,7 @@ id3v2_parse_frame (ID3TagsWorking * work)
 |  | ||||||
|   |  | ||||||
|    if (work->frame_flags & (ID3V2_FRAME_FORMAT_COMPRESSION | |  | ||||||
|            ID3V2_FRAME_FORMAT_DATA_LENGTH_INDICATOR)) { |  | ||||||
| -    if (work->hdr.frame_data_size <= 4)
 |  | ||||||
| +    if (frame_data_size <= 4)
 |  | ||||||
|        return FALSE; |  | ||||||
|      if (ID3V2_VER_MAJOR (work->hdr.version) == 3) { |  | ||||||
|        work->parse_size = GST_READ_UINT32_BE (frame_data); |  | ||||||
| -- 
 |  | ||||||
| 2.31.1 |  | ||||||
| 
 |  | ||||||
		Reference in a new issue