Debian Patches

Status for amule/1:3.1.0-3

Patch Description Author Forwarded Bugs Origin Last update
cas_configfile.c_good_default_paths.diff point cas' generated config at a font that exists on Debian The upstream default (corefonts/times.ttf) is not shipped by any Debian
package; use DejaVu Serif from fonts-dejavu-core, which amule-utils
recommends.
not-needed
PR1594.patch fix: read binary collections as little-endian on big-endian hosts (#1594)

The binary .emulecollection parser read integers in host byte order, so on
s390x, powerpc, ppc64, sparc64 and hppa a valid binary collection was not
recognised and went to the text parser instead. That loaded nothing from
real collections and let links hidden in filename fields through, which the
parser split exists to prevent. CMuleCollectionTest caught it and failed the
Debian 3.1.0 build on every big-endian architecture.

Decode with a portable helper. ArchSpecific.h is not usable here because
the ed2k tool builds this file without wx.

reports, not the trap handler. Expect that there.
got3nks <got3nks@users.noreply.github.com> no upstream, https://github.com/amule-org/amule/commit/1d1dd904928b7c6c20275040d8170cfd4d6d61b7 2026-09-24
PR1703.patch fix(ed2k): cap compressed-part inflation at the requested block (#1703)

unzip() doubled its output buffer without a ceiling, and the requested-block bounds check ran only after inflation, so one 2 MB OP_COMPRESSEDPART packet could inflate to about 2 GB and exhaust memory. Grow the buffer only up to what is left of the block, plus one byte for the stream trailer, and fail the stream past that.

Reported by @itlezy (GHSA-hv8p-rp6f-rmf7).
got3nks <got3nks@users.noreply.github.com> yes upstream upstream, https://github.com/amule-org/amule/commit/08064d20550d083343cb784f50270b57eb31c49c 2026-10-02
PR1701.patch fix(ed2k): reject an OP_HASHSETANSWER shorter than a file hash (#1701)

ProcessHashSet compared the first 16 bytes of an OP_HASHSETANSWER against the requested file hash before checking the packet size, so a 0-15 byte answer read past the receive buffer. Reject a payload shorter than a file hash first.

Reported by @itlezy.
got3nks <got3nks@users.noreply.github.com> no upstream, https://github.com/amule-org/amule/commit/47236eb11fd1d456b33ad9243d2559ab006337e7 2026-10-02
PR1704.patch bound update-archive unpacking in size and depth UnpackArchive() unpacked ZIP and GZip members with no size limit and
re-unpacked its own output with no depth limit, so a small update archive
(ipfilter.dat, server.met, the GeoIP database, fetched from a URL a
server-list link can name) could fill the disk or, as a gzip that unpacks to
itself, recurse until the stack overflowed. Cap each unpacked member at 256
MiB and refuse more than three archive layers.
.
Backported to 3.1.0: the Tar unpacker and the FileFunctionsTest unit test
that the upstream commit also changes came later upstream (#1569, #1624), so
those hunks are dropped; the Zip and GZip hunks are the same as upstream.
got3nks <got3nks@users.noreply.github.com> yes upstream backport, https://github.com/amule-org/amule/commit/3e6321ff4370edccf5b7ac424e6baf1c422aa761 2026-10-02
ec_notifier_uninitialised.patch initialise the EC notifier pointer when EC is refused With AcceptExternalConnections=1 and an empty ECPassword, the ExternalConn
constructor returns before it creates its ECNotifier, so m_ec_notifier is
left uninitialised. The NULL checks in GuiEvents.cpp then pass on the
garbage value, and amuled crashes in ECNotifier::DownloadFile_SetDirty while
CamuleApp::OnInit loads the part files, before CamuleDaemonApp::OnRun gets
to report the missing password. Start the pointer at NULL so those checks
hold.
Sandro Tosi <morph@debian.org> no debian 2026-10-02

All known versions for source package 'amule'

Links