1
0
mirror of https://git.openwrt.org/openwrt/openwrt.git synced 2024-10-19 05:58:53 +02:00
openwrt/tools
Petr Štetiar b3aa2909a7 zlib: backport security fix for a reproducible crash in compressor
Tavis has just reported, that he was recently trying to track down a
reproducible crash in a compressor. Believe it or not, it really was a
bug in zlib-1.2.11 when compressing (not decompressing!) certain inputs.

Tavis has reported it upstream, but it turns out the issue has been
public since 2018, but the patch never made it into a release. As far as
he knows, nobody ever assigned it a CVE.

Suggested-by: Tavis Ormandy <taviso@gmail.com>
References: https://www.openwall.com/lists/oss-security/2022/03/24/1
Signed-off-by: Petr Štetiar <ynezz@true.cz>
2022-03-24 08:15:24 +01:00
..
autoconf
autoconf-archive
automake
b43-tools
bash tools: build bash on macOS and use it for ipkg-build 2022-01-27 13:38:48 +01:00
bc tools: use https for bc mirrors 2022-02-24 15:36:28 +01:00
bison
cbootimage
cbootimage-configs
ccache tools/ccache: update to 4.6 2022-03-13 19:24:13 +01:00
cmake tools/cmake: update to 3.22.3 2022-03-13 19:24:13 +01:00
coreutils tools/coreutils: build chown 2022-01-27 13:38:48 +01:00
cpio
dosfstools
e2fsprogs
elftosb
expat tools/expat: enable DTD 2022-03-13 10:10:30 +01:00
fakeroot tools/fakeroot: update to 1.28 2022-03-13 19:24:13 +01:00
findutils tools/findutils: update to 4.9.0 2022-03-01 00:08:08 +01:00
firmware-utils firmware-utils: bump to git HEAD 2022-02-28 13:12:00 +02:00
flex
flock
genext2fs
gengetopt
gmp
include
isl
kernel2minor
libressl tools/libressl: update to version 3.4.2 2022-03-01 00:08:08 +01:00
libtool
llvm-bpf
lzma
lzma-old
m4
make-ext4fs
meson tools/meson: update to 0.61.2 2022-02-26 13:44:14 +01:00
missing-macros
mkimage tools/mkimage: update to 2022.01 2022-03-01 00:08:08 +01:00
mklibs tools/mklibs: update to 0.1.45 2022-03-01 00:08:08 +01:00
mpc
mpfr
mtd-utils
mtools tools/mtools: update to 4.0.38 2022-03-13 19:24:13 +01:00
ninja
padjffs2
patch
patch-image
patchelf
pkgconf
quilt tools/quilt: update to 0.67 2022-02-25 14:12:39 +01:00
sdimage
sed
sparse
squashfs
squashfskit4
sstrip
tar
xxd
xz
zip tools: zip: make encrypted archives reproducible 2022-03-09 15:38:23 +09:00
zlib zlib: backport security fix for a reproducible crash in compressor 2022-03-24 08:15:24 +01:00
zstd tools/zstd: update to 1.5.2 2022-03-01 00:08:08 +01:00
Makefile tools/mkimage: update to 2022.01 2022-03-01 00:08:08 +01:00