Change History (12)
comment:1 by , 12 months ago
| Owner: | changed from to |
|---|---|
| Status: | new → assigned |
comment:2 by , 12 months ago
| Summary: | brotli-1.2.0 → brotli-1.2.0-rc1 (Wait for stable release) |
|---|
comment:3 by , 12 months ago
| Owner: | changed from to |
|---|---|
| Status: | assigned → new |
comment:4 by , 12 months ago
| Milestone: | 12.5 → 99-Waiting |
|---|
comment:5 by , 11 months ago
| Milestone: | 99-Waiting → 12.5 |
|---|---|
| Summary: | brotli-1.2.0-rc1 (Wait for stable release) → brotli-1.2.0 |
comment:6 by , 11 months ago
| Owner: | changed from to |
|---|---|
| Status: | new → assigned |
Mine, the instruction for building Python module needs to be updated.
comment:7 by , 11 months ago
SECURITY
- python: added
Decompressor::can_accept_more_datamethod and optionaloutput_buffer_limitargumentDecompressor::process; that allows mitigation of unexpectedly large output; reported by Charles Chan (https://github.com/charleswhchan)
Added
- decoder / encoder: added static initialization to reduce binary size
- python: allow limiting decoder output (see SECURITY section)
- CLI:
brcatalias; allow decoding concatenated brotli streams - kt: pure Kotlin decoder
- cgo: support "raw" dictionaries
- build: Bazel modules
Removed
- java: dropped
finalize()for native entities
Fixed
- java: in
compresspass correct length to native encoder
Improved
- build: install man pages
- build: updated / fixed / refined Bazel buildfiles
- encoder: faster encoding
- cgo: link via pkg-config
- python: modernize extension / allow multi-phase module initialization
Changed
- decoder / encoder: static tables use "small" model (allows 2GiB+ binaries)
comment:9 by , 11 months ago
| Resolution: | → fixed |
|---|---|
| Status: | assigned → closed |
comment:10 by , 11 months ago
| Priority: | normal → elevated |
|---|
I'm going to mark this as elevated even though there is no CVE, because of the security changes that allow mitigation of unexpectedly large output.
comment:11 by , 11 months ago
SA-12.4-027 issued
I mostly filed this one so that attention could be brought to the mitigations for users who are using Brotli's python bindings.
Note:
See TracTickets
for help on using tickets.

This is version 1.2.0 RC1 right now.