Skip to content

Update Bzip2 from 1.0.6 to 1.0.7 #1163

Merged
merged 4 commits into from
Jul 8, 2019
Merged

Conversation

pmenzel
Copy link
Collaborator

@pmenzel pmenzel commented Jul 5, 2019

Tested on rabammel.

From the [announcement][1]:

> We are happy to announce the release of bzip2 1.0.7.
>
> This is an emergency release because the old bzip2 home
> is gone and there were outstanding security issues.
> The original bzip2 home, downloads and documentation
> can now be found at: https://sourceware.org/bzip2/
>
> bzip2 1.0.7 contains only the following bug/security fixes:
>
> * Fix undefined behavior in the macros SET_BH, CLEAR_BH, & ISSET_BH
> * bzip2: Fix return value when combining --test,-t and -q.
> * bzip2recover: Fix buffer overflow for large argv[0]
> * bzip2recover: Fix use after free issue with outFile (CVE-2016-3189)
> * Make sure nSelectors is not out of range (CVE-2019-12900)
>
> A future 1.1.x release is being prepared by Federico Mena Quintero
> which will include more fixes, an updated build system and possibly
> an updated SONAME default.
>
> Please read his blog for more background on this:
> https://people.gnome.org/~federico/blog/tag/bzip2.html

More details can be found in [2] and [3].

[1]: https://sourceware.org/ml/bzip2-devel/2019-q2/msg00022.html
[2]: https://people.gnome.org/~federico/blog/preparing-the-bzip2-107-release.html
[3]: https://gnu.wildebeest.org/blog/mjw/2019/06/27/bzip2-1-0-7/
@pmenzel pmenzel force-pushed the update-bzip2-from-1.0.6-to-1.0.7 branch from 2194cf4 to 5b62bd7 Compare July 5, 2019 09:07
@pmenzel pmenzel merged commit 807aeed into master Jul 8, 2019
Sign in to join this conversation on GitHub.
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

1 participant