#284 closed defect (fixed)
gzip-1.2.4b
| Reported by: | Owned by: | ||
|---|---|---|---|
| Priority: | highest | Milestone: | |
| Component: | Book | Version: | CVS |
| Severity: | normal | Keywords: | |
| Cc: |
Description
This is important. There's a buffer overflow in gzip-1.2.4a which presents a security risk. Suggest we move to gzip-1.2.4b before LFS-3.2 is released.
Change History (13)
comment:1 by , 24 years ago
| dependson: | → 30 |
|---|
comment:2 by , 24 years ago
| Resolution: | → fixed |
|---|---|
| Status: | new → closed |
comment:3 by , 24 years ago
| Resolution: | fixed |
|---|---|
| Status: | closed → reopened |
comment:4 by , 24 years ago
| Owner: | changed from to |
|---|---|
| Status: | reopened → assigned |
comment:5 by , 24 years ago
| Owner: | changed from to |
|---|---|
| Status: | assigned → new |
I don't seen an officially released 1.2.4b version anywhere on ftp.gnu.org I did find via freshmeat a Debian related article relating to gzip and there's a gzip patch on the Debian site. I'm not going to provide two gzip patches (one to fix the compile problem, one to fix the security problem), they may not even work together.
From what I have read, the security hole isn't all that serious so I'll leave this to be dealt with for after LFS-3.2 so we can investigate better and perhaps combine the two patches into on.
comment:6 by , 24 years ago
| Priority: | highest → high |
|---|
comment:7 by , 24 years ago
the patch is available from www.gzip.org (the official gzip homepage) and is designed to be applied to gzip-1.2.4a. They are saying that there'll be a complete new official version of gzip coming out soon so maybe we can just leave it for 3.2 and hope that gzip-1.4.x comes out before 3.3.
comment:8 by , 24 years ago
okay we'll do that, makes it easier for me now. All P1 bugs are gone, I'll check for obvious glaring errors then release lfs-3.2-rc1
comment:9 by , 24 years ago
3.3 is released now, have we decided yet what to do with this one? I'd say leave it as long as possible, but when there's still no new gzip out when we're getting ready for 4.0, use it.
comment:11 by , 23 years ago
| Priority: | high → highest |
|---|
comment:12 by , 23 years ago
| Resolution: | → fixed |
|---|---|
| Status: | new → closed |
Added gzip-1.2.4b to book, closing this bug.
comment:13 by , 22 years ago
| dependson: | 30 |
|---|

how did i end up closing this one...wanted to assign it to me