[Buildroot] [PATCH 1/1] package/lrzip: security bump to version 0.641

Peter Korsgaard peter at korsgaard.com
Tue Oct 26 18:39:40 UTC 2021


>>>>> "Fabrice" == Fabrice Fontaine <fontaine.fabrice at gmail.com> writes:

 > - Fix CVE-2021-27347: Use after free in lzma_decompress_buf function in
 >   stream.c in Irzip 0.631 allows attackers to cause Denial of Service
 >   (DoS) via a crafted compressed file.
 > - Fix CVE-2021-27345: A null pointer dereference was discovered in
 >   ucompthread in stream.c in Irzip 0.631 which allows attackers to cause
 >   a denial of service (DOS) via a crafted compressed file.
 > - Fix CVE-2020-25467: A null pointer dereference was discovered
 >   lzo_decompress_buf in stream.c in Irzip 0.621 which allows an attacker
 >   to cause a denial of service (DOS) via a crafted compressed file.
 > - lz4 is a mandatory dependency since version 0.640 and
 >   https://github.com/ckolivas/lrzip/commit/3345a239b7f5353a1c1296d6a5d6b90729d4b669

 > https://github.com/ckolivas/lrzip/compare/7f3bf46203bf45ea115d8bd9f310ea219be88af4...v0.641

 > Signed-off-by: Fabrice Fontaine <fontaine.fabrice at gmail.com>

Committed, thanks.

-- 
Bye, Peter Korsgaard


More information about the buildroot mailing list