Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
bzip2: Update version from 1.0.6 to 1.0.7
From the [announcement][1]: > We are happy to announce the release of bzip2 1.0.7. > > This is an emergency release because the old bzip2 home > is gone and there were outstanding security issues. > The original bzip2 home, downloads and documentation > can now be found at: https://sourceware.org/bzip2/ > > bzip2 1.0.7 contains only the following bug/security fixes: > > * Fix undefined behavior in the macros SET_BH, CLEAR_BH, & ISSET_BH > * bzip2: Fix return value when combining --test,-t and -q. > * bzip2recover: Fix buffer overflow for large argv[0] > * bzip2recover: Fix use after free issue with outFile (CVE-2016-3189) > * Make sure nSelectors is not out of range (CVE-2019-12900) > > A future 1.1.x release is being prepared by Federico Mena Quintero > which will include more fixes, an updated build system and possibly > an updated SONAME default. > > Please read his blog for more background on this: > https://people.gnome.org/~federico/blog/tag/bzip2.html More details can be found in [2] and [3]. [1]: https://sourceware.org/ml/bzip2-devel/2019-q2/msg00022.html [2]: https://people.gnome.org/~federico/blog/preparing-the-bzip2-107-release.html [3]: https://gnu.wildebeest.org/blog/mjw/2019/06/27/bzip2-1-0-7/
- Loading branch information