Re: bzip2 (CAN-2005-1260)
Ken Moffat <[email protected]> Fri, 2 Dec 2005 14:22:03 +0000 (GMT)
| Newsgroups | gmane.linux.lfs.security |
|---|---|
| Message-ID | <[email protected]> |
This message is in MIME format. The first part should be readable text, while the remaining parts are likely unreadable without MIME-aware tools. ---1463809536-260770601-1133531158=:14144 Content-Type: TEXT/PLAIN; CHARSET=X-UNKNOWN; format=flowed Content-ID: <[email protected]> Content-Transfer-Encoding: quoted-printable On Fri, 2 Dec 2005, [email protected] wrote: > I know it's already some months old, but isn't this issue still valid f= or=20 > lfs-svn? > > thanks > Gottfried Haider=20 > A quick google suggests that distros patched their versions of=20 bzip2-1.0.{1,2}, and RH at least said their patch was a backport. The latest version of bzip2 from fedora that I can find is 1.0.2-16. I= =20 assume that the problem is the one fixed by the "bomb" patch within=20 that, which we are already using. Having said that, I'm not aware of a publically-accessible bzip2=20 development tree, so I might be wrong. The fedora specfile doesn't=20 mention this vulnerability number. Ubuntu does mention this number for=20 1.0.2, but I'm unclear which of their patches fix it, and I don't always=20 trust their analysis. The only "big guys" using 1.0.3 seem to be=20 gentoo, and they don't mention this as far as I can see. Ken --=20 das eine Mal als Trag=F6die, das andere Mal als Farce ---1463809536-260770601-1133531158=:14144 Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline -- http://linuxfromscratch.org/mailman/listinfo/lfs-security FAQ: http://www.linuxfromscratch.org/faq/ Unsubscribe: See the above information page ---1463809536-260770601-1133531158=:14144--