Opened 12 months ago

Closed 11 months ago

Last modified 8 months ago

#22235 closed enhancement (fixed)

brotli-1.2.0

Reported by: Bruce Dubbs Owned by: Xi Ruoyao
Priority: elevated Milestone: 13.0
Component: BOOK Version: git
Severity: medium Keywords:
Cc:

Description

New minor version.

Change History (12)

comment:1 by Bruce Dubbs, 12 months ago

Owner: changed from blfs-book to Bruce Dubbs
Status: new → assigned

comment:2 by Bruce Dubbs, 12 months ago

Summary: brotli-1.2.0 → brotli-1.2.0-rc1 (Wait for stable release)

This is version 1.2.0 RC1 right now.

comment:3 by Bruce Dubbs, 12 months ago

Owner: changed from Bruce Dubbs to blfs-book
Status: assigned → new

comment:4 by pierre, 12 months ago

Milestone: 12.5 → 99-Waiting

comment:5 by Xi Ruoyao, 11 months ago

Milestone: 99-Waiting → 12.5
Summary: brotli-1.2.0-rc1 (Wait for stable release) → brotli-1.2.0

comment:6 by Xi Ruoyao, 11 months ago

Owner: changed from blfs-book to Xi Ruoyao
Status: new → assigned

Mine, the instruction for building Python module needs to be updated.

comment:7 by Xi Ruoyao, 11 months ago

SECURITY

  • python: added Decompressor::can_accept_more_data method and optional output_buffer_limit argument Decompressor::process; that allows mitigation of unexpectedly large output; reported by Charles Chan (​https://github.com/charleswhchan)

Added

  • decoder / encoder: added static initialization to reduce binary size
  • python: allow limiting decoder output (see SECURITY section)
  • CLI: brcat alias; allow decoding concatenated brotli streams
  • kt: pure Kotlin decoder
  • cgo: support "raw" dictionaries
  • build: Bazel modules

Removed

  • java: dropped finalize() for native entities

Fixed

  • java: in compress pass correct length to native encoder

Improved

  • build: install man pages
  • build: updated / fixed / refined Bazel buildfiles
  • encoder: faster encoding
  • cgo: link via pkg-config
  • python: modernize extension / allow multi-phase module initialization

Changed

  • decoder / encoder: static tables use "small" model (allows 2GiB+ binaries)

comment:9 by Xi Ruoyao, 11 months ago

Resolution: → fixed
Status: assigned → closed

comment:10 by Douglas R. Reno, 11 months ago

Priority: normal → elevated

I'm going to mark this as elevated even though there is no CVE, because of the security changes that allow mitigation of unexpectedly large output.

comment:11 by Douglas R. Reno, 11 months ago

SA-12.4-027 issued

I mostly filed this one so that attention could be brought to the mitigations for users who are using Brotli's python bindings.

comment:12 by Bruce Dubbs, 8 months ago

Milestone: 12.5 → 13.0

Milestone renamed

Note: See TracTickets for help on using tickets.