Re: [CVE] zlib (< 1.2.12) memory corruption

Nick Clifton via Gcc <[email protected]>
Newsgroups gmane.comp.gcc.devel,gmane.comp.gnu.binutils,gmane.comp.gdb.devel
Message-ID <[email protected]>
Hi Luis,

> There is a CVE [1] for zlib < 1.2.12 (released march 27th).
> 
> GCC currently uses zlib 1.2.11, and binutils-gdb imports the zlib directory from GCC. The recommendation is to get it updated to 1.2.12, which contains the proper fix [2].
> 

Right - I have now updated the binutils-gdb mainline sources with this release.

Whilst it is true that the gcc version of zlib sources had diverged slightly from
the 1.2.11 release sources, I think that it was just some changes cherry picked
from the developments that went in to 1.2.12.  So a simple rebase should be safe.

Cheers
   Nick
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.