Re: [gdal-dev] Question: CPL minizip affected by CVE-2023-45853?

2023-11-03 Thread James Addison via gdal-dev
Brilliant - thank you, Even! On Fri, 3 Nov 2023 at 15:44, Even Rouault wrote: > > Hi James, > > thanks for the notice. GDAL copy has diverged a bit, but I've just > managed to apply the upstream fix per > https://github.com/OSGeo/gdal/pull/8658 > > Even > > Le 03/11/2023 à 16:17, James Addison

Re: [gdal-dev] Question: CPL minizip affected by CVE-2023-45853?

2023-11-03 Thread Even Rouault via gdal-dev
Hi James, thanks for the notice. GDAL copy has diverged a bit, but I've just managed to apply the upstream fix per https://github.com/OSGeo/gdal/pull/8658 Even Le 03/11/2023 à 16:17, James Addison via gdal-dev a écrit : Hi folks, I've arrived at the gdal mailing list after reading the

[gdal-dev] Question: CPL minizip affected by CVE-2023-45853?

2023-11-03 Thread James Addison via gdal-dev
Hi folks, I've arrived at the gdal mailing list after reading the security policy[1] on the GitHub repository, but then decided that this is as much a question as it is a bug, so I'm following the issue template comment advice[2] to post here. The Common Portability Library within gdal includes