openwrt/package
Petr Štetiar 3965dda0fa zlib: backport security fix for a reproducible crash in compressor
Tavis has just reported, that he was recently trying to track down a
reproducible crash in a compressor. Believe it or not, it really was a
bug in zlib-1.2.11 when compressing (not decompressing!) certain inputs.

Tavis has reported it upstream, but it turns out the issue has been
public since 2018, but the patch never made it into a release. As far as
he knows, nobody ever assigned it a CVE.

Suggested-by: Tavis Ormandy <taviso@gmail.com>
References: https://www.openwall.com/lists/oss-security/2022/03/24/1
Signed-off-by: Petr Štetiar <ynezz@true.cz>
(cherry picked from commit b3aa2909a7)
2022-03-24 08:18:21 +01:00
..
base-files OpenWrt v22.03: set branch defaults 2022-03-20 13:05:00 +00:00
boot mediatek: Add support for Xiaomi Redmi Router AX6S 2022-03-21 13:11:56 +00:00
devel strace: Update to version 5.16 2022-02-01 21:25:02 +01:00
firmware cypress-firmware: update it to version 5.4.18-2021_0812 2022-03-19 16:13:58 +01:00
kernel kmod-lzo: include the lzo-rle kmod in the package 2022-03-22 09:25:40 +00:00
libs zlib: backport security fix for a reproducible crash in compressor 2022-03-24 08:18:21 +01:00
network qosify: update to the latest version 2022-03-22 10:29:18 +01:00
system procd: move service command to procd 2022-03-19 16:13:58 +01:00
utils util-linux: add lsns 2022-03-05 21:05:45 +01:00
Makefile build: fix opkg install step for large package selection 2021-05-12 11:13:53 +02:00