mirror of
git://git.openwrt.org/openwrt/openwrt.git
synced 2025-12-10 22:52:11 -05:00
Tavis has just reported, that he was recently trying to track down a reproducible crash in a compressor. Believe it or not, it really was a bug in zlib-1.2.11 when compressing (not decompressing!) certain inputs. Tavis has reported it upstream, but it turns out the issue has been public since 2018, but the patch never made it into a release. As far as he knows, nobody ever assigned it a CVE. Suggested-by: Tavis Ormandy <taviso@gmail.com> References: https://www.openwall.com/lists/oss-security/2022/03/24/1 Signed-off-by: Petr Štetiar <ynezz@true.cz> |
||
|---|---|---|
| .. | ||
| 001-neon-implementation-of-adler32.patch | ||
| 002-arm-specific-optimisations-for-inflate.patch | ||
| 003-arm-specific-optimisations-for-inflate.patch | ||
| 004-attach-sourcefiles-in-patch-002-to-buildsystem.patch | ||
| 005-relative-pkg-config-paths.patch | ||
| 006-fix-compressor-crash-on-certain-inputs.patch | ||