News for package sox

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

Format: 3.0 (quilt)
Source: sox
Binary: sox, libsox2, libsox-fmt-base, libsox-fmt-alsa, libsox-fmt-ao, libsox-fmt-mp3, libsox-fmt-oss, libsox-fmt-pulse, libsox-fmt-all, libsox-dev
Architecture: any
Version: 14.4.1-5
Maintainer: Pascal Giard <[email protected]>
Homepage: http://sox.sourceforge.net
Standards-Version: 3.9.3
Vcs-Browser: http://sox.git.sourceforge.net/git/gitweb.cgi?p=sox/sox
Vcs-Git: git://sox.git.sourceforge.net/gitroot/sox/sox
Build-Depends: dh-autoreconf, debhelper (>= 9), ladspa-sdk, libao-dev, libasound2-dev [linux-any], libgsm1-dev, libid3tag0-dev, libltdl3-dev, libmad0-dev, libmagic-dev, libmp3lame-dev, libopencore-amrnb-dev, libopencore-amrwb-dev, libpng-dev, libpulse-dev, libsamplerate0-dev, libsndfile1-dev (>= 1.0.12), libtwolame-dev, libvorbis-dev, libwavpack-dev
Package-List:
 libsox-dev deb libdevel optional arch=any
 libsox-fmt-all deb libs optional arch=any
 libsox-fmt-alsa deb libs optional arch=linux-any
 libsox-fmt-ao deb libs optional arch=any
 libsox-fmt-base deb libs optional arch=any
 libsox-fmt-mp3 deb libs optional arch=any
 libsox-fmt-oss deb libs optional arch=any
 libsox-fmt-pulse deb libs optional arch=any
 libsox2 deb libs optional arch=any
 sox deb sound optional arch=any
Checksums-Sha1:
 71f05afc51e3d9b03376b2f98fd452d3a274d595 1111653 sox_14.4.1.orig.tar.gz
 65e215bc9eb323345209f181f303cd12c44a9784 13448 sox_14.4.1-5.debian.tar.xz
Checksums-Sha256:
 9a8c2c6fe51e608da346a157e111508a957af9e3ecf3de26781d36e9a67fa89b 1111653 sox_14.4.1.orig.tar.gz
 5df459a30998ce4c07be1fd7b1f6243210edfa9006101441f6ecf27069a48642 13448 sox_14.4.1-5.debian.tar.xz
Files:
 670307f40763490a2bc0d1f322071e7a 1111653 sox_14.4.1.orig.tar.gz
 59499ced90faa13cab4018ae49349e33 13448 sox_14.4.1-5.debian.tar.xz

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIcBAEBCAAGBQJUmxu/AAoJEL5c9ofcWrfCW/EQAK8tJjLrCYXsMnkQ73nklA61
rlOQVum6BDCGaULqWnIlxxF4ES20a1MtnKcMXAeL6qxeJi3MhsCsb5fz/hcn/BbO
Lnu8owJrCQfe3uffhTEQtyLhV8vyMMNhq04AW59DPNAT5B4ZI4c97gQm97TdQ+Si
Wirn1NRjYbsRWRkLbMgT2aFYBQ0gwcFw6YKLw38kz+4fVJ/GmWGDujBqJWnfH7xa
FhvKalZuNG4UA8hFQduf8DAIEp7PVC6AdF/YWdYKOWAFnRu4P/V05R9LTwA3KyJq
gXShjurmSsDveAoFq0k+34VWt7TzPaEGh3VPFq4ioPMkRwWEw7bujoRPF6QVGYZT
zQ1E/c5e7jpbK+UIR+otEXovQywm8/CfCyh2cHqZ2WwjjL2gwWDq1aVIbEld6NM/
OH4AWsYScOwl1sDuQEZtf6/dY/gv/bjlxLTW6FZrScasb+l2ox9f8egdKOy27wjH
icDTxNh93oAomeduW7auDfjCNdICvG/K4ApP9kbnSojg04Ky+tSaMGLjA2y+0Ute
cdQzxA/0y7/IneydvuBsaOhDdg4+ScvuVd6F57LiqgeRuA/shom5FErL6YQ3oG3l
vYPNf7Wqv/TmJV3ho+Ulzk0rZB9ylE+SncKdm/4o9sMY9zddTCc/8W2B0QYBbP0x
hiKFSNVXyMHT06ptfAbx
=6yES
-----END PGP SIGNATURE-----

Changes:
sox (14.4.1-5) unstable; urgency=medium

  * Patches to fix memory corruptions on the heap, CVE-2014-8145
    (closes: #773720):
    + 0001-Check-for-minimum-size-sphere-headers.patch
    + 0002-More-checks-for-invalid-MS-ADPCM-blocks.patch

 -- Pascal Giard <[email protected]>  Wed, 24 Dec 2014 14:33:55 -0500