Changelog for libsndfile1-1.0.28-5.1.x86_64.rpm :

* Tue Dec 19 2017 Fix VUL-0: divide-by-zero error exists in the function double64_init() in double64.c (CVE-2017-14634, bsc#1059911): 0030-double64_init-Check-psf-sf.channels-against-upper-bo.patch- Tentative fix for VUL-0: out of bounds read in the function d2alaw_array() in alaw.c (CVE-2017-14245, bsc#1059912) and VUL-0: out of bounds read in the function d2ulaw_array() in ulaw.c (CVE-2017-14246, bsc#1059913): 0031-sfe_copy_data_fp-check-value-of-max-variable.patch
* Tue Aug 08 2017 Fix Heap-based Buffer Overflow in the psf_binheader_writef (CVE-2017-12562, bsc#1052476): 0020-src-common.c-Fix-heap-buffer-overflows-when-writing-.patch
* Tue Jun 13 2017 Fix out-of-bounds read memory access in the aiff_read_chanmap() (CVE-2017-6892, bsc#1043978): 0010-src-aiff.c-Fix-a-buffer-read-overflow.patch
* Tue May 02 2017 Fix FLAC buffer overflows (CVE-2017-8361 CVE-2017-8363 CVE-2017-8365 CVE-2017-8362 bsc#1036944 bsc#1036945 bsc#1036946 bsc#1036943): 0001-FLAC-Fix-a-buffer-read-overrun.patch 0002-src-flac.c-Fix-a-buffer-read-overflow.patch
* Mon Apr 10 2017 Update to version 1.0.27:
* Fix a seek regression in 1.0.26
* Add metadata read/write for CAF and RF64
* FIx PAF endian-ness issue- Update to version 1.0.28
* Fix buffer overruns in FLAC and ID3 handling code (CVE-2017-7585, CVE-2017-7586, bsc#1033054, bsc#1033053)
* Reduce default header memory requirements
* Fix detection of Large File Support for 32 bit systems.- Obsoleted patch: libsndfile-psf_strlcpy_crlf-fix-CVE-2015-8075.patch
* Tue May 10 2016 Fix spec file to enable builds on non opensuse OS
* Mon Nov 23 2015 Update to version 1.0.26:
* Fix for CVE-2014-9496, CVE-2014-9756 and CVE-2015-7805.
* Add ALAC/CAF support. Minor bug fixes and improvements.- Refreshed patches: sndfile-ocloexec.patch libsndfile-psf_strlcpy_crlf-fix-CVE-2015-8075.patch- Removed obsoleted patches: libsndfile-example-fix.diff libsndfile-fix-header-read-CVE-2015-7805.patch libsndfile-paf-zero-division-fix.diff libsndfile-src-common.c-Fix-a-header-parsing-bug.patch libsndfile-src-file_io.c-Prevent-potential-divide-by-zero.patch sndfile-src-sd2.c-Fix-segfault-in-SD2-RSRC-parser.patch sndfile-src-sd2.c-Fix-two-potential-buffer-read-overflows.patch
* Wed Nov 04 2015 VUL-0: libsndfile 1.0.25 heap overflow (CVE-2015-7805, bsc#953516) libsndfile-src-common.c-Fix-a-header-parsing-bug.patch libsndfile-fix-header-read-CVE-2015-7805.patch- VUL-0: libsndfile 1.0.25 heap overflow (CVE-2015-8075, bsc#953519) libsndfile-psf_strlcpy_crlf-fix-CVE-2015-8075.patch- Fix the build with SLE11-SP3 due to AM_SILENT_RULE macro
* Wed Nov 04 2015 VUL-1: libsndfile DoS/divide-by-zero (CVE-2014-9756, bsc#953521): libsndfile-src-file_io.c-Prevent-potential-divide-by-zero.patch
* Sat Mar 21 2015 Cleanup spec file with spec-cleaner- Add gpg signature- Remove old ppc provides/obsoletes
* Wed Jan 07 2015 VUL-0: two buffer read overflows in sd2_parse_rsrc_fork() (CVE-2014-9496, bnc#911796): backported upstream fix patches sndfile-src-sd2.c-Fix-segfault-in-SD2-RSRC-parser.patch sndfile-src-sd2.c-Fix-two-potential-buffer-read-overflows.patch
* Mon Apr 15 2013 Added url as source. Please see
* Fri Dec 02 2011 add libtool as buildrequire to avoid implicit dependency
* Thu Nov 24 2011 add missing provides/obsoletes for libsndfile -> libsndfile1 rename (bnc#732565)
* Thu Nov 24 2011 use O_CLOEXEC in library code.
* Tue Nov 22 2011 fix devel dependency
* Mon Nov 21 2011 Remove redundant/unwanted tags/section (cf. specfile guidelines)
* Wed Aug 24 2011 Enable speex support- run make check
* Fri Jul 29 2011 Fix zero-division in PAF parser (bnc#708988)
* Thu Jul 28 2011 Remove -fno-strict-aliasing from cflags, no longer needed- disable automake silent rules.
* Mon Jul 18 2011 updated to version 1.0.25: Fix for Secunia Advisory SA45125 (CVE-2011-2696, bnc#705681) Minor bug fixes and improvements
* Wed Mar 23 2011 Update to version 1.0.24- Upstream changes :
* WAV files are now written with an 18 byte u-law and A-law fmt chunk
* A document on virtual I/O functionality was added
* Two new methods were added in sndfile.hh
* A fix was made for a non-zero SSND offset values on AIFF
* Minor bug fixes and improvements were done
* Mon Oct 11 2010 Update to version 1.0.23- Upstream changes :
* src/ src/ Add version string resources to the windows DLL.
* doc/api.html Update to add missing SF_FORMAT_
* values. Closed Debian bug #545257.
*.html Updates for 1.0.23 release.
* Other minor bug fixes
* Fri Oct 08 2010 Update to version 1.0.22- Upstream changes :
* Bunch of minor bug fixes.
* Mon Aug 16 2010 updated to version 1.0.21:
* Bunch of minor bug fixes.
* including VUL-1 divide-by-zero fix (bnc#631379)
* Wed Dec 16 2009 add baselibs.conf as a source- enable parallel building
* Tue Jun 02 2009 explicitely enable sqlite support to avoid random flipping
* Fri May 15 2009 updated to version 1.0.20:
* Fix for potential heap overflow- enable ogg/vorbis support
* Fri Apr 24 2009 built progs subpackage from an individual spec file to cut the circular dependency with jack.
* Wed Mar 04 2009 updated to version 1.0.19:
* Fix for CVE-2009-0186 (bnc#481769 - VUL-0: libsndfile CAF Processing Integer Overflow Vulnerability)
* Huge number of minor fixes as a result of static analysis- remove INSTALL file from filelist