[SECURITY] bzip2

Corinna Vinschen corinna-cygwin@cygwin.com
Tue Mar 18 14:02:00 GMT 2008


Hi Charles,

I just read that a security problem which has been found in F-Secure
is also a problem for other packages, namely 7zip and bzip2(*).

While this is apparently fixed in our 7zip release 4.57 (called 4.5.7
in the below URL), it's only fixed in bzip2 1.0.5.  We're still at
1.0.3.  Any problem to update?


Thanks,
Corinna

(*) https://www.cert.fi/haavoittuvuudet/joint-advisory-archive-formats.html

-- 
Corinna Vinschen                  Please, send mails regarding Cygwin to
Cygwin Project Co-Leader          cygwin AT cygwin DOT com
Red Hat



More information about the Cygwin-apps mailing list