diff options
author | Petr Štetiar <ynezz@true.cz> | 2022-03-24 06:45:04 +0100 |
---|---|---|
committer | Petr Štetiar <ynezz@true.cz> | 2022-03-24 08:15:24 +0100 |
commit | b3aa2909a79aeff20d594160b207a89dc807c033 (patch) | |
tree | d050d232017664938e296939cf5d2a0e58ab10e5 /package/libs/zlib/Makefile | |
parent | 29d7461d1135b91905120a44dc028b786693ecc4 (diff) | |
download | upstream-b3aa2909a79aeff20d594160b207a89dc807c033.tar.gz upstream-b3aa2909a79aeff20d594160b207a89dc807c033.tar.bz2 upstream-b3aa2909a79aeff20d594160b207a89dc807c033.zip |
zlib: backport security fix for a reproducible crash in compressor
Tavis has just reported, that he was recently trying to track down a
reproducible crash in a compressor. Believe it or not, it really was a
bug in zlib-1.2.11 when compressing (not decompressing!) certain inputs.
Tavis has reported it upstream, but it turns out the issue has been
public since 2018, but the patch never made it into a release. As far as
he knows, nobody ever assigned it a CVE.
Suggested-by: Tavis Ormandy <taviso@gmail.com>
References: https://www.openwall.com/lists/oss-security/2022/03/24/1
Signed-off-by: Petr Štetiar <ynezz@true.cz>
Diffstat (limited to 'package/libs/zlib/Makefile')
-rw-r--r-- | package/libs/zlib/Makefile | 2 |
1 files changed, 1 insertions, 1 deletions
diff --git a/package/libs/zlib/Makefile b/package/libs/zlib/Makefile index c7a8415c79..7321ec51c5 100644 --- a/package/libs/zlib/Makefile +++ b/package/libs/zlib/Makefile @@ -9,7 +9,7 @@ include $(TOPDIR)/rules.mk PKG_NAME:=zlib PKG_VERSION:=1.2.11 -PKG_RELEASE:=3 +PKG_RELEASE:=4 PKG_SOURCE:=$(PKG_NAME)-$(PKG_VERSION).tar.xz PKG_SOURCE_URL:=@SF/libpng http://www.zlib.net |