First Last Prev Next    No search results available      Search page      Enter new bug
Bug#: 69920
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo's Team for Core System packages <base-system@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Tobias Sager <moixa@gmx.ch>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:

Filename Description Type Creator Created Size Actions
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 69920 depends on: Show dependency tree
Bug 69920 blocks:
Votes: 0    Show votes for this bug    Vote for this bug

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2004-11-02 23:53 0000
<snip>
Version 1.2.2 eliminates a potential security vulnerability in zlib 1.2.1, so all users of 1.2.1 should upgrade immediately. The following important fixes are provided in zlib 1.2.2:

    * Eliminate a potential security vulnerability when decoding invalid compressed data
    * Fix bug when decompressing dynamic blocks with no distance codes
    * Do not return an error when using gzread() on an empty file 
</snip>

Vulnerability was fixed in bug 61749.

------- Comment #1 From SpanKY 2004-11-03 10:21:22 0000 -------
i just went to zlib's homepage and saw no mention of 1.2.2

nor is 1.2.2 at the normal download locations

re-open once 1.2.2 does become available

------- Comment #2 From SpanKY 2004-11-03 16:09:03 0000 -------
seems they've posted the info

------- Comment #3 From SpanKY 2004-11-03 16:09:09 0000 -------
*** Bug 69988 has been marked as a duplicate of this bug. ***

------- Comment #4 From SpanKY 2004-11-03 16:27:38 0000 -------
updated in cvs, thanks :)

------- Comment #5 From Tobias Sager 2004-11-03 23:38:37 0000 -------
Just for the archive: there is http://zlib.net and http://zlib.org (which
redirects to http://www.gzip.org/zlib/). Somehow the .org page is still not
updated. And I don't know how those pages are related anyway.

------- Comment #6 From John Ratliff 2004-11-04 01:54:25 0000 -------
http://www.gzip.org/zlib/ is supposed to be the official page with
http://www.zlib.net/ being the mirror. http://www.zlib.org/ is a pointer to
http://www.gzip.org/zlib/.

I wanted to make sure zlib 1.2.2 was official, so I wrote zlib@gzip.org and
asked since it wasn't on the official page.

This response is from Mark Adler, co-author of zlib

On Nov 1, 2004, at 2:42 AM, jdratlif@indiana.edu wrote:
> I want to know if this is an official site and I should trust this, 
> because the official site seems to be gzip.org/zlib.

Yes, zlib.net is official, and 1.2.2 is the latest version.  
Unfortunately, we have not been able to get in touch with Jean-loup to update
the gzip.org site.

mark

First Last Prev Next    No search results available      Search page      Enter new bug