|
Message-ID: <8aa4538b-d3fb-c09f-a08e-d6d40c5025f7@gentoo.org>
Date: Tue, 4 Jun 2019 03:13:14 +0200
From: Thomas Deutschmann <whissi@...too.org>
To: oss-security@...ts.openwall.com
Subject: Re: Crash / fix in bzip2
Hi,
in Gentoo Linux we are shipping [1] for a while.
Please note that this change will break some bzip2 archives which were
created with lbzip2 because lbzip2 sometimes exceeded BZ_MAX_SELECTORS.
There's a patch for lbzip2 [2] (not yet published in a release) to avoid
that problem for new archives...
See also:
=========
[1] https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=1948811390283ff8e5f122bd9ec68f2e7b907450
[2] https://github.com/kjn/lbzip2/commit/b6dc48a7b9bfe6b340ed1f6d72133608ad57144b
--
Regards,
Thomas Deutschmann / Gentoo Security Team
C4DD 695F A713 8F24 2AA1 5638 5849 7EE5 1D5D 74A5
Download attachment "signature.asc" of type "application/pgp-signature" (619 bytes)
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.