Changelog for libvorbis0-1.3.5-3.2.x86_64.rpm :

* Tue Dec 19 2017 Fix VUL-0: out-of-bounds array read vulnerability exists in function mapping0_forward() (CVE-2017-14633, bsc#1059811): 0001-CVE-2017-14633-Don-t-allow-for-more-than-256-channel.patch- Fix VUL-0: Remote Code Execution upon freeing uninitialized memory in function vorbis_analysis_headerout(CVE-2017-14632, bsc#1059809): 0002-CVE-2017-14632-vorbis_analysis_header_out-Don-t-clea.patch
* Tue Nov 29 2016 Added 32bit libvorbis-devel in baselibs.conf
* Fri Mar 06 2015 Cleanup spec file with spec-cleaner- Update to 1.3.5
* Tolerate single-entry codebooks.
* Fix decoder crash with invalid input.
* Fix encoder crash with non-positive sample rates.
* Fix issues in vorbisfile\'s seek bisection code.
* Spec errata.
* Reject multiple headers of the same type.
* Various build fixes and code cleanup.
* Mon Aug 18 2014 Fix obsoletes and provides in baselibs.conf.
* Sun Feb 23 2014 Xiph libvorbis 1.3.4
* reduced static data size in libvorbisenc
* associated minor changes required to libvorbis and libvorbisfile
* minor build fixes and build system updates
* no functional changes over the previous 1.3.3 release- removed libvorbis-pkgconfig.patch, in upstream- updated vorbis-fix-linking.patch for context changes
* Tue Apr 16 2013 Added url as source. Please see
* Sat Mar 02 2013 fix build with automake-1.13.1
* Wed Jun 20 2012 updated to 1.3.3
* vorbis: additional proofing against invalid/malicious streams in decode (see SVN for details).
* vorbis: fix a memory leak in vorbis_commentheader_out().
* updates, corrections and clarifications in the Vorbis I specification document
* build warning fixes
* Tue Feb 21 2012 VUL-0: CVE-2012-0444: libvorbis: heap-based buffer overflow (bnc#747912)
* Sun Dec 25 2011 -O20 optimization level doesn\'t exist, use -O3
* Fri Nov 25 2011 open files with O_CLOEXEC, in order to avoid fd leaks when calling applications fork() ..execve()... This patch does not cover the executable tools since it is not critical for them.
* Tue Nov 22 2011 add libtool as buildrequire to avoid implicit dependency
* Mon Aug 29 2011 Fix build with no-add-needed
* Thu May 05 2011 fix provides/obsoletes in baselibs
* Thu Dec 09 2010 Split libvorbisenc2 and libvorbisfile3 from libvorbis0- Removed services.
* Wed Dec 08 2010 fix the package split
* Wed Dec 08 2010 updated to version 1.3.2
* vorbis: additional proofing against invalid/malicious streams in floor, residue, and bos/eos packet trimming code (see SVN for details).
* vorbis: Added programming documentation tree for the low-level calls
* vorbisfile: Correct handling of serial numbers array element [0] on non-seekable streams
* vorbisenc: Back out an [old] AoTuV HF weighting that was first enabled in 1.3.0; there are a few samples where I really don\'t like the effect it causes.
* vorbis: return correct timestamp for granule positions with high bit set.
* vorbisfile: the [undocumented] half-rate decode api made no attempt to keep the pcm offset tracking consistent in seeks. Fix and add a testing mode to seeking_example.c to torture test seeking in halfrate mode. Also remove requirement that halfrate mode only work with seekable files.
* vorbisfile: Fix a chaining bug in raw_seeks where seeking out of the current link would fail due to not reinitializing the decode machinery.
* vorbisfile: improve seeking strategy. Reduces the necessary number of seek callbacks in an open or seek operation by well over 2/3.- updated to version 1.3.1
* tweak + minor arithmetic fix in floor1 fit
* revert noise norm to conservative 1.2.3 behavior pending more listening testing- updated to versio 1.3.0
* Optimized surround support for 5.1 encoding at 44.1/48kHz
* Added encoder control call to disable channel coupling
* Correct an overflow bug in very low-bitrate encoding on 32 bit machines that caused inflated bitrates
* Numerous API hardening, leak and build fixes
* Correct bug in 22kHz compand setup that could cause a crash
* Correct bug in 16kHz codebooks that could cause unstable pure tones at high bitrates- run spec-cleaner- removed libvorbis-automake-fix.diff, libvorbis-doc-fixes.diff, libvorbis-r16326-CVE-2009-3379.diff and libvorbis-r16597-CVE-2009-3379.diff (upstream fixed)- follow library packaging policy- run make check
* Wed May 26 2010 VUL-0: libvorbis: memory corruption while parsing ogg files (bnc#608192, CVE-2009-3379)
* Wed Dec 16 2009 add baselibs.conf as a source- enable parallel building- package documentation as noarch
* Wed Nov 11 2009 updated to version 1.2.3:
* correct a vorbisfile bug that prevented proper playback of Vorbis files where all audio in a logical stream is in a single page
* Additional decode setup hardening against malicious streams
* Add \'OV_EXCLUDE_STATIC_CALLBACKS\' define for developers who wish to avoid avoid unused symbol warnings from the static callbacks defined in vorbisfile.h- updated to version 1.2.2:
* define VENDOR and ENCODER strings
* seek correctly in files bigger than 2 GB (Windows)
* fix regression from CVE-2008-1420; 1.0b1 files work again
* mark all tables as constant to reduce memory occupation
* additional decoder hardening against malicious streams
* substantially reduce amount of seeking performed by Vorbisfile
* Multichannel decode bugfix
* build system updates
* minor specification clarifications/fixes- dropped aotuv patch temporarily
* Thu Jul 23 2009 updated to aoTuV patch version beta5.7:
* including security fixes
* improved encoding speed of low bitrate mode
* reduced distrotion by clipping at low sampling frequency
* fixed noise control part of impulse block
* tuning of each part was redone
* expanded noise control of the impulse block
* fixed pre-echo reduction code
* noise normalization reviewed
* detailed tuning done again
* Mon Jun 22 2009 fix build with automake 1.11