openwrt-mirror/tools
Petr Štetiar b3aa2909a7 zlib: backport security fix for a reproducible crash in compressor
Tavis has just reported, that he was recently trying to track down a
reproducible crash in a compressor. Believe it or not, it really was a
bug in zlib-1.2.11 when compressing (not decompressing!) certain inputs.

Tavis has reported it upstream, but it turns out the issue has been
public since 2018, but the patch never made it into a release. As far as
he knows, nobody ever assigned it a CVE.

Suggested-by: Tavis Ormandy <taviso@gmail.com>
References: https://www.openwall.com/lists/oss-security/2022/03/24/1
Signed-off-by: Petr Štetiar <ynezz@true.cz>
2022-03-24 08:15:24 +01:00
..
autoconf
autoconf-archive
automake
b43-tools
bash
bc
bison
cbootimage
cbootimage-configs
ccache
cmake
coreutils
cpio
dosfstools
e2fsprogs
elftosb
expat
fakeroot
findutils
firmware-utils
flex
flock
genext2fs
gengetopt
gmp
include
isl
kernel2minor
libressl
libtool
llvm-bpf
lzma
lzma-old
m4
make-ext4fs
meson
missing-macros
mkimage
mklibs
mpc
mpfr
mtd-utils
mtools
ninja
padjffs2
patch
patch-image
patchelf
pkgconf
quilt
sdimage
sed
sparse
squashfs
squashfskit4
sstrip
tar
xxd
xz
zip
zlib zlib: backport security fix for a reproducible crash in compressor 2022-03-24 08:15:24 +01:00
zstd
Makefile