diff options
author | Petr Štetiar <ynezz@true.cz> | 2022-03-24 06:45:04 +0100 |
---|---|---|
committer | Petr Štetiar <ynezz@true.cz> | 2022-03-24 08:18:21 +0100 |
commit | 3965dda0fa70dc9408f1a2e55a3ddefde78bd50e (patch) | |
tree | c685b569ed0beda949e5fb8095b5de188ed3b560 /toolchain/wrapper | |
parent | 68b008756fae2d05a46f684dd4908667389d217a (diff) | |
download | upstream-3965dda0fa70dc9408f1a2e55a3ddefde78bd50e.tar.gz upstream-3965dda0fa70dc9408f1a2e55a3ddefde78bd50e.tar.bz2 upstream-3965dda0fa70dc9408f1a2e55a3ddefde78bd50e.zip |
zlib: backport security fix for a reproducible crash in compressor
Tavis has just reported, that he was recently trying to track down a
reproducible crash in a compressor. Believe it or not, it really was a
bug in zlib-1.2.11 when compressing (not decompressing!) certain inputs.
Tavis has reported it upstream, but it turns out the issue has been
public since 2018, but the patch never made it into a release. As far as
he knows, nobody ever assigned it a CVE.
Suggested-by: Tavis Ormandy <taviso@gmail.com>
References: https://www.openwall.com/lists/oss-security/2022/03/24/1
Signed-off-by: Petr Štetiar <ynezz@true.cz>
(cherry picked from commit b3aa2909a79aeff20d594160b207a89dc807c033)
Diffstat (limited to 'toolchain/wrapper')
0 files changed, 0 insertions, 0 deletions