Sat Mar 27 15:59:34 2010 UTC ()
Add a patch to fix CVE-2010-0421, DoS security fix.

Bump PKGREVISION.


(taca)
diff -r1.140 -r1.141 pkgsrc/devel/pango/Makefile
diff -r1.82 -r1.83 pkgsrc/devel/pango/distinfo
diff -r0 -r1.1 pkgsrc/devel/pango/patches/patch-am

cvs diff -r1.140 -r1.141 pkgsrc/devel/pango/Makefile (expand / switch to unified diff)

--- pkgsrc/devel/pango/Makefile 2010/02/21 23:51:25 1.140
+++ pkgsrc/devel/pango/Makefile 2010/03/27 15:59:33 1.141
@@ -1,17 +1,17 @@ @@ -1,17 +1,17 @@
1# $NetBSD: Makefile,v 1.140 2010/02/21 23:51:25 tron Exp $ 1# $NetBSD: Makefile,v 1.141 2010/03/27 15:59:33 taca Exp $
2 2
3DISTNAME= pango-1.26.2 3DISTNAME= pango-1.26.2
4PKGREVISION= 1 4PKGREVISION= 2
5CATEGORIES= devel fonts 5CATEGORIES= devel fonts
6MASTER_SITES= ${MASTER_SITE_GNOME:=sources/pango/1.26/} 6MASTER_SITES= ${MASTER_SITE_GNOME:=sources/pango/1.26/}
7EXTRACT_SUFX= .tar.bz2 7EXTRACT_SUFX= .tar.bz2
8 8
9MAINTAINER= pkgsrc-users@NetBSD.org 9MAINTAINER= pkgsrc-users@NetBSD.org
10HOMEPAGE= http://www.pango.org/ 10HOMEPAGE= http://www.pango.org/
11COMMENT= Library for layout and rendering of text 11COMMENT= Library for layout and rendering of text
12LICENSE= gnu-lgpl-v2 12LICENSE= gnu-lgpl-v2
13 13
14PKG_INSTALLATION_TYPES= overwrite pkgviews 14PKG_INSTALLATION_TYPES= overwrite pkgviews
15PKG_DESTDIR_SUPPORT= user-destdir 15PKG_DESTDIR_SUPPORT= user-destdir
16 16
17USE_TOOLS+= gmake pkg-config 17USE_TOOLS+= gmake pkg-config

cvs diff -r1.82 -r1.83 pkgsrc/devel/pango/distinfo (expand / switch to unified diff)

--- pkgsrc/devel/pango/distinfo 2010/02/21 23:51:25 1.82
+++ pkgsrc/devel/pango/distinfo 2010/03/27 15:59:33 1.83
@@ -1,8 +1,9 @@ @@ -1,8 +1,9 @@
1$NetBSD: distinfo,v 1.82 2010/02/21 23:51:25 tron Exp $ 1$NetBSD: distinfo,v 1.83 2010/03/27 15:59:33 taca Exp $
2 2
3SHA1 (pango-1.26.2.tar.bz2) = 051b6f7b5f98a4c8083ef6a5178cb5255a992b98 3SHA1 (pango-1.26.2.tar.bz2) = 051b6f7b5f98a4c8083ef6a5178cb5255a992b98
4RMD160 (pango-1.26.2.tar.bz2) = 6613bddf643d5c912e6656d84c6671aa6ce88a9d 4RMD160 (pango-1.26.2.tar.bz2) = 6613bddf643d5c912e6656d84c6671aa6ce88a9d
5Size (pango-1.26.2.tar.bz2) = 1536011 bytes 5Size (pango-1.26.2.tar.bz2) = 1536011 bytes
6SHA1 (patch-aa) = 1a87d055dc722eff28517a11d0832ae19df5eb59 6SHA1 (patch-aa) = 1a87d055dc722eff28517a11d0832ae19df5eb59
7SHA1 (patch-ab) = 12c09b12ba31be19fa0d602f89909811e6221bd8 7SHA1 (patch-ab) = 12c09b12ba31be19fa0d602f89909811e6221bd8
8SHA1 (patch-ae) = 9eb458be84f6dfce27fb469d45cc78e34acd9c36 8SHA1 (patch-ae) = 9eb458be84f6dfce27fb469d45cc78e34acd9c36
 9SHA1 (patch-am) = dc7387b4da24356a56ab8d07ef0462b6f4b3b209

File Added: pkgsrc/devel/pango/patches/Attic/patch-am
$NetBSD: patch-am,v 1.1 2010/03/27 15:59:34 taca Exp $

Fix for CVE-2010-0421.

--- pango/opentype/hb-ot-layout.cc.orig	2009-11-26 00:44:17.000000000 +0000
+++ pango/opentype/hb-ot-layout.cc
@@ -44,6 +44,8 @@ _hb_ot_layout_init (hb_face_t *face)
 {
   hb_ot_layout_t *layout = &face->ot_layout;
 
+  memset (layout, 0, sizeof (*layout));
+
   layout->gdef_blob = Sanitizer<GDEF>::sanitize (hb_face_get_table (face, HB_OT_TAG_GDEF));
   layout->gdef = &Sanitizer<GDEF>::lock_instance (layout->gdef_blob);
 
@@ -293,7 +295,7 @@ hb_ot_layout_build_glyph_classes (hb_fac
     return;
 
   if (layout->new_gdef.len == 0) {
-    layout->new_gdef.klasses = (unsigned char *) calloc (num_total_glyphs, sizeof (unsigned char));
+    layout->new_gdef.klasses = (unsigned char *) calloc (count, sizeof (unsigned char));
     layout->new_gdef.len = count;
   }