Re: potential unfixed CVE in usr.bin/compress/zopen.c

2024-04-03 Thread Alexander Bluhm
On Wed, Apr 03, 2024 at 03:35:07PM +, Lu ChenHao wrote: > As CVE-2011-2895 said, the > LZW decompressor is vulnerable to an infinite loop or a heap-based buffer > overflow. As a mitigation, freebsd has added checks in > zopen.c

potential unfixed CVE in usr.bin/compress/zopen.c

2024-04-03 Thread Lu ChenHao
As CVE-2011-2895 said, the LZW decompressor is vulnerable to an infinite loop or a heap-based buffer overflow. As a mitigation, freebsd has added checks in zopen.c.