I hope at least it has the vulnerabilities fixed, but it's still pretty un-nice, I can think of a couple very interesting attack patterns actually, if they are not.
(In reply to comment #0) > I hope at least it has the vulnerabilities fixed, but it's still pretty > un-nice, I can think of a couple very interesting attack patterns actually, if > they are not. Can you tell me why you make this such big fuzz? If you simply did a ldd on the binary and library you see that it actually uses the system zlib. So what is your point?
I'd say you should refrain from commenting if you don't even know what ldd output means at all.
This is an upstream desicion, they dont plan to add a new dependency, adn they used the same version embbeded in kernel so it's supposed to be safe