head 1.2; access; symbols pkgsrc-2013Q2:1.2.0.24 pkgsrc-2013Q2-base:1.2 pkgsrc-2012Q4:1.2.0.22 pkgsrc-2012Q4-base:1.2 pkgsrc-2011Q4:1.2.0.20 pkgsrc-2011Q4-base:1.2 pkgsrc-2011Q2:1.2.0.18 pkgsrc-2011Q2-base:1.2 pkgsrc-2009Q4:1.2.0.16 pkgsrc-2009Q4-base:1.2 pkgsrc-2008Q4:1.2.0.14 pkgsrc-2008Q4-base:1.2 pkgsrc-2008Q3:1.2.0.12 pkgsrc-2008Q3-base:1.2 cube-native-xorg:1.2.0.10 cube-native-xorg-base:1.2 pkgsrc-2008Q2:1.2.0.8 pkgsrc-2008Q2-base:1.2 pkgsrc-2008Q1:1.2.0.6 pkgsrc-2008Q1-base:1.2 pkgsrc-2007Q4:1.2.0.4 pkgsrc-2007Q4-base:1.2 pkgsrc-2007Q3:1.2.0.2 pkgsrc-2007Q3-base:1.2 pkgsrc-2007Q2:1.1.0.6 pkgsrc-2007Q2-base:1.1 pkgsrc-2007Q1:1.1.0.4 pkgsrc-2007Q1-base:1.1 pkgsrc-2006Q4:1.1.0.2; locks; strict; comment @# @; 1.2 date 2007.07.15.19.41.30; author xtraeme; state dead; branches; next 1.1; 1.1 date 2007.02.17.22.48.16; author salo; state Exp; branches 1.1.2.1; next ; 1.1.2.1 date 2007.02.17.22.48.16; author ghen; state dead; branches; next 1.1.2.2; 1.1.2.2 date 2007.03.05.12.11.42; author ghen; state Exp; branches; next ; desc @@ 1.2 log @Update to 0.99.5: After long time, a new xine-ui version is now available. There are fixes for security issues with playlists (upgrade recommended!), fixes for crashes, memleaks and bugs. Functional enhancements and features are added, appearance of non-skinned windows is harmonized (with more space for text), translations are updated. @ text @$NetBSD: patch-au,v 1.1 2007/02/17 22:48:16 salo Exp $ --- src/fb/osd.c.orig 2003-12-01 18:23:27.000000000 +0100 +++ src/fb/osd.c 2007-02-17 21:56:02.000000000 +0100 @@@@ -589,7 +589,7 @@@@ void osd_display_spu_lang(void) { } sprintf(buffer, "Subtitles: %s", lang); - osd_display_info(buffer); + osd_display_info("%s", buffer); } void osd_display_audio_lang(void) { @@@@ -618,5 +618,5 @@@@ void osd_display_audio_lang(void) { } sprintf(buffer, "Audio Channel: %s", lang); - osd_display_info(buffer); + osd_display_info("%s", buffer); } @ 1.1 log @Security fixes for CVE-2007-0254 (and more): "A vulnerability has been reported in xine-ui, which potentially can be exploited by malicious people to compromise a user's system. The vulnerability is caused due to a format string error within the "errors_create_window()" function in errors.c. This may be exploited to execute arbitrary code by e.g. tricking a user into opening a specially crafted playlist file." Patch from SUSE. Bump PKGREVISION. XXX: The sources are a real mess. My condolences to everyone using it. And good luck, you'll need it!.. @ text @d1 1 a1 1 $NetBSD$ @ 1.1.2.1 log @file patch-au was added on branch pkgsrc-2006Q4 on 2007-02-17 22:48:16 +0000 @ text @d1 20 @ 1.1.2.2 log @Pullup ticket 2026 - requested by salo security update for xine-ui - pkgsrc/multimedia/xine-ui/Makefile 1.30, 1.34 via patch - pkgsrc/multimedia/xine-ui/distinfo 1.12, 1.14 via patch - pkgsrc/multimedia/xine-ui/patches/patch-ai 1.2 - pkgsrc/multimedia/xine-ui/patches/patch-aq 1.2 - pkgsrc/multimedia/xine-ui/patches/patch-ar 1.2 - pkgsrc/multimedia/xine-ui/patches/patch-as 1.1 - pkgsrc/multimedia/xine-ui/patches/patch-au 1.1 - pkgsrc/multimedia/xine-ui/patches/patch-av 1.1 - pkgsrc/multimedia/xine-ui/patches/patch-aw 1.1 - pkgsrc/multimedia/xine-ui/patches/patch-ax 1.1 - pkgsrc/multimedia/xine-ui/patches/patch-ay 1.1 - pkgsrc/multimedia/xine-ui/patches/patch-az 1.1 - pkgsrc/multimedia/xine-ui/patches/patch-ba 1.1 - pkgsrc/multimedia/xine-ui/patches/patch-bb 1.1 - pkgsrc/multimedia/xine-ui/patches/patch-bc 1.1 Module Name: pkgsrc Committed By: drochner Date: Tue Jan 9 14:52:41 UTC 2007 Modified Files: pkgsrc/multimedia/xine-ui: Makefile distinfo pkgsrc/multimedia/xine-ui/patches: patch-ar Added Files: pkgsrc/multimedia/xine-ui/patches: patch-as Log Message: fix PR pkg/35375: xine-ui freezes konsole sessions from Sergey Svishchev, patch from xine CVS --- Module Name: pkgsrc Committed By: salo Date: Sat Feb 17 22:48:18 UTC 2007 Modified Files: pkgsrc/multimedia/xine-ui: Makefile distinfo pkgsrc/multimedia/xine-ui/patches: patch-ai patch-aq Added Files: pkgsrc/multimedia/xine-ui/patches: patch-au patch-av patch-aw patch-ax patch-ay patch-az patch-ba patch-bb patch-bc Log Message: Security fixes for CVE-2007-0254 (and more): "A vulnerability has been reported in xine-ui, which potentially can be exploited by malicious people to compromise a user's system. The vulnerability is caused due to a format string error within the "errors_create_window()" function in errors.c. This may be exploited to execute arbitrary code by e.g. tricking a user into opening a specially crafted playlist file." Patch from SUSE. Bump PKGREVISION. XXX: The sources are a real mess. My condolences to everyone using it. And good luck, you'll need it!.. @ text @a0 20 $NetBSD: patch-au,v 1.1.2.1 2007/03/05 12:11:42 ghen Exp $ --- src/fb/osd.c.orig 2003-12-01 18:23:27.000000000 +0100 +++ src/fb/osd.c 2007-02-17 21:56:02.000000000 +0100 @@@@ -589,7 +589,7 @@@@ void osd_display_spu_lang(void) { } sprintf(buffer, "Subtitles: %s", lang); - osd_display_info(buffer); + osd_display_info("%s", buffer); } void osd_display_audio_lang(void) { @@@@ -618,5 +618,5 @@@@ void osd_display_audio_lang(void) { } sprintf(buffer, "Audio Channel: %s", lang); - osd_display_info(buffer); + osd_display_info("%s", buffer); } @