[Buildroot] [PATCH 1/1] package/lrzip: security bump to version 0.641
Peter Korsgaard
peter at korsgaard.com
Tue Oct 26 18:39:40 UTC 2021
>>>>> "Fabrice" == Fabrice Fontaine <fontaine.fabrice at gmail.com> writes:
> - Fix CVE-2021-27347: Use after free in lzma_decompress_buf function in
> stream.c in Irzip 0.631 allows attackers to cause Denial of Service
> (DoS) via a crafted compressed file.
> - Fix CVE-2021-27345: A null pointer dereference was discovered in
> ucompthread in stream.c in Irzip 0.631 which allows attackers to cause
> a denial of service (DOS) via a crafted compressed file.
> - Fix CVE-2020-25467: A null pointer dereference was discovered
> lzo_decompress_buf in stream.c in Irzip 0.621 which allows an attacker
> to cause a denial of service (DOS) via a crafted compressed file.
> - lz4 is a mandatory dependency since version 0.640 and
> https://github.com/ckolivas/lrzip/commit/3345a239b7f5353a1c1296d6a5d6b90729d4b669
> https://github.com/ckolivas/lrzip/compare/7f3bf46203bf45ea115d8bd9f310ea219be88af4...v0.641
> Signed-off-by: Fabrice Fontaine <fontaine.fabrice at gmail.com>
Committed, thanks.
--
Bye, Peter Korsgaard
More information about the buildroot
mailing list