Re: bzip2 (CAN-2005-1260)

Ken Moffat <[email protected]> Fri, 2 Dec 2005 14:22:03 +0000 (GMT)
Newsgroups gmane.linux.lfs.security
Message-ID <[email protected]>
  This message is in MIME format.  The first part should be readable text,
  while the remaining parts are likely unreadable without MIME-aware tools.

---1463809536-260770601-1133531158=:14144
Content-Type: TEXT/PLAIN; CHARSET=X-UNKNOWN; format=flowed
Content-ID: <[email protected]>
Content-Transfer-Encoding: quoted-printable

On Fri, 2 Dec 2005, [email protected] wrote:

> I know it's already some months old, but isn't this issue still valid f=
or=20
> lfs-svn?
>
> thanks
> Gottfried Haider=20
>

  A quick google suggests that distros patched their versions of=20
bzip2-1.0.{1,2}, and RH at least said their patch was a backport.

  The latest version of bzip2 from fedora that I can find is 1.0.2-16.  I=
=20
assume that the problem is the one fixed by the "bomb" patch within=20
that, which we are already using.

  Having said that, I'm not aware of a publically-accessible bzip2=20
development tree, so I might be wrong.  The fedora specfile doesn't=20
mention this vulnerability number.  Ubuntu does mention this number for=20
1.0.2, but I'm unclear which of their patches fix it, and I don't always=20
trust their analysis.  The only "big guys" using 1.0.3 seem to be=20
gentoo, and they don't mention this as far as I can see.

Ken
--=20
  das eine Mal als Trag=F6die, das andere Mal als Farce
---1463809536-260770601-1133531158=:14144
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

-- 
http://linuxfromscratch.org/mailman/listinfo/lfs-security
FAQ: http://www.linuxfromscratch.org/faq/
Unsubscribe: See the above information page

---1463809536-260770601-1133531158=:14144--