Petr Štetiar 3965dda0fa zlib: backport security fix for a reproducible crash in compressor
Tavis has just reported, that he was recently trying to track down a
reproducible crash in a compressor. Believe it or not, it really was a
bug in zlib-1.2.11 when compressing (not decompressing!) certain inputs.

Tavis has reported it upstream, but it turns out the issue has been
public since 2018, but the patch never made it into a release. As far as
he knows, nobody ever assigned it a CVE.

Suggested-by: Tavis Ormandy <taviso@gmail.com>
References: https://www.openwall.com/lists/oss-security/2022/03/24/1
Signed-off-by: Petr Štetiar <ynezz@true.cz>
(cherry picked from commit b3aa2909a79aeff20d594160b207a89dc807c033)
2022-03-24 08:18:21 +01:00
..
2022-02-24 15:36:28 +01:00
2021-10-05 20:59:41 +02:00
2022-03-13 19:24:13 +01:00
2022-03-13 19:24:13 +01:00
2022-01-27 13:38:48 +01:00
2022-03-13 10:10:30 +01:00
2022-03-13 19:24:13 +01:00
2018-11-25 19:23:03 +01:00
2019-07-08 16:42:26 +02:00
2020-11-21 18:49:17 +01:00
2020-03-14 13:20:06 +00:00
2021-10-21 20:37:20 +01:00
2021-09-20 15:21:17 +02:00
2022-02-26 13:44:14 +01:00
2022-03-01 00:08:08 +01:00
2022-03-01 00:08:08 +01:00
2020-11-21 18:49:27 +01:00
2020-08-23 19:40:32 +02:00
2022-03-13 19:24:13 +01:00
2020-09-02 16:29:22 +02:00
2022-02-25 14:12:39 +01:00
2020-02-18 21:39:14 +01:00
2021-09-20 15:21:17 +02:00
2021-09-20 15:21:17 +02:00
2021-09-05 21:26:48 +02:00
2021-03-01 16:39:17 +00:00
2020-04-09 22:09:13 +02:00
2022-03-01 00:08:08 +01:00
2022-03-01 00:08:08 +01:00