sthen 9ecbdf1562 security update to LZO 2.07, CVE-2014-4607
'Fixed a potential integer overflow condition in the "safe" decompressor
variants which could result in a possible buffer overrun when processing
maliciously crafted compressed input data.

As this issue only affects 32-bit systems and also can only happen if
you use uncommonly huge buffer sizes where you have to decompress more
than 16 MiB (2^24 bytes) compressed bytes within a single function call,
the practical implications are limited.'

See http://www.openwall.com/lists/oss-security/2014/06/26/20 for more
details, there are also some embedded copies of "minilzo" from the same
source in various other programs which are also affected by this
2014-06-26 22:52:52 +00:00
..
2014-01-28 01:01:52 +00:00
2013-11-09 23:19:01 +00:00
2014-05-12 21:35:30 +00:00
2013-07-19 06:49:31 +00:00
2014-04-18 22:59:32 +00:00
2013-08-06 19:13:06 +00:00
2014-01-21 22:27:34 +00:00
2013-11-12 20:00:50 +00:00
2014-04-18 21:53:54 +00:00
2013-12-01 09:56:52 +00:00
2014-03-28 03:08:41 +00:00
2013-10-06 19:12:08 +00:00
2013-11-09 09:51:50 +00:00
2013-10-10 20:30:16 +00:00
2013-09-06 13:28:15 +00:00
2013-05-08 20:38:38 +00:00
2013-09-20 20:37:15 +00:00
2013-07-07 17:57:44 +00:00
2014-01-10 16:12:52 +00:00