oss-sec mailing list archives

Re: Crash / fix in bzip2


From: Thomas Deutschmann <whissi () gentoo org>
Date: Tue, 4 Jun 2019 03:13:14 +0200

Hi,

in Gentoo Linux we are shipping [1] for a while.

Please note that this change will break some bzip2 archives which were
created with lbzip2 because lbzip2 sometimes exceeded BZ_MAX_SELECTORS.

There's a patch for lbzip2 [2] (not yet published in a release) to avoid
that problem for new archives...


See also:
=========
[1] https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=1948811390283ff8e5f122bd9ec68f2e7b907450
[2] https://github.com/kjn/lbzip2/commit/b6dc48a7b9bfe6b340ed1f6d72133608ad57144b


-- 
Regards,
Thomas Deutschmann / Gentoo Security Team
C4DD 695F A713 8F24 2AA1 5638 5849 7EE5 1D5D 74A5

Attachment: signature.asc
Description: OpenPGP digital signature


Current thread: