#284 closed defect (fixed)
gzip-1.2.4b
Reported by: | Owned by: | ||
---|---|---|---|
Priority: | highest | Milestone: | |
Component: | Book | Version: | CVS |
Severity: | normal | Keywords: | |
Cc: |
Description
This is important. There's a buffer overflow in gzip-1.2.4a which presents a security risk. Suggest we move to gzip-1.2.4b before LFS-3.2 is released.
Change History (13)
comment:1 by , 23 years ago
dependson: | → 30 |
---|
comment:2 by , 23 years ago
Resolution: | → fixed |
---|---|
Status: | new → closed |
comment:3 by , 23 years ago
Resolution: | fixed |
---|---|
Status: | closed → reopened |
comment:4 by , 23 years ago
Owner: | changed from | to
---|---|
Status: | reopened → assigned |
comment:5 by , 23 years ago
Owner: | changed from | to
---|---|
Status: | assigned → new |
I don't seen an officially released 1.2.4b version anywhere on ftp.gnu.org I did find via freshmeat a Debian related article relating to gzip and there's a gzip patch on the Debian site. I'm not going to provide two gzip patches (one to fix the compile problem, one to fix the security problem), they may not even work together.
From what I have read, the security hole isn't all that serious so I'll leave this to be dealt with for after LFS-3.2 so we can investigate better and perhaps combine the two patches into on.
comment:6 by , 23 years ago
Priority: | highest → high |
---|
comment:7 by , 23 years ago
the patch is available from www.gzip.org (the official gzip homepage) and is designed to be applied to gzip-1.2.4a. They are saying that there'll be a complete new official version of gzip coming out soon so maybe we can just leave it for 3.2 and hope that gzip-1.4.x comes out before 3.3.
comment:8 by , 23 years ago
okay we'll do that, makes it easier for me now. All P1 bugs are gone, I'll check for obvious glaring errors then release lfs-3.2-rc1
comment:9 by , 23 years ago
3.3 is released now, have we decided yet what to do with this one? I'd say leave it as long as possible, but when there's still no new gzip out when we're getting ready for 4.0, use it.
comment:11 by , 22 years ago
Priority: | high → highest |
---|
comment:12 by , 22 years ago
Resolution: | → fixed |
---|---|
Status: | new → closed |
Added gzip-1.2.4b to book, closing this bug.
comment:13 by , 21 years ago
dependson: | 30 |
---|
how did i end up closing this one...wanted to assign it to me