immortalwrt/package
Petr Štetiar 3b17680462 zlib: backport security fix for a reproducible crash in compressor
Tavis has just reported, that he was recently trying to track down a
reproducible crash in a compressor. Believe it or not, it really was a
bug in zlib-1.2.11 when compressing (not decompressing!) certain inputs.

Tavis has reported it upstream, but it turns out the issue has been
public since 2018, but the patch never made it into a release. As far as
he knows, nobody ever assigned it a CVE.

Suggested-by: Tavis Ormandy <taviso@gmail.com>
References: https://www.openwall.com/lists/oss-security/2022/03/24/1
Signed-off-by: Petr Štetiar <ynezz@true.cz>
2022-03-25 10:35:31 +08:00
..
base-files base-files: add wrapper for procd service list command 2022-03-21 23:25:23 +08:00
boot tfa-layerscape: fix build on systems without openssl headers 2022-01-01 17:32:22 +08:00
devel strace: Update to version 5.16 2022-02-18 18:32:40 +08:00
emortal autocore: add ethtool back for x86 2022-03-22 01:26:41 +08:00
firmware cypress-firmware: update it to version 5.4.18-2021_0812 2022-03-21 23:27:29 +08:00
kernel kernel/modules: inet-diag: fix build with kernel < 4.10 2022-03-18 13:46:46 +08:00
libs zlib: backport security fix for a reproducible crash in compressor 2022-03-25 10:35:31 +08:00
network uqmi: set CID during 'query-data-status' operation 2022-03-17 11:00:33 +08:00
system procd: move service command to procd 2022-03-21 23:24:26 +08:00
utils usbmode: update to version 2022-02-24 2022-02-28 16:11:03 +08:00
Makefile build: fix opkg install step for large package selection 2021-05-12 23:27:23 +08:00