Re: [OE-core] [PATCH] unzip: CVE-2015-7696, CVE-2015-7697

2015-11-05 Thread Joshua Lock
On 29/10/15 03:02, akuster808 wrote: Patches should apply to Fido and Dizzy. both are have the same version. Thanks for the patches. Patch applies and I've pushed this change to my joshuagl/fido-next branch of openembedded-core-contrib and am testing it now. Thanks, Joshua 1.

Re: [OE-core] [PATCH] unzip: CVE-2015-7696, CVE-2015-7697

2015-10-28 Thread akuster808
Patches should apply to Fido and Dizzy. both are have the same version. Thanks for the patches. regards, - armin On 10/28/2015 05:14 PM, Tudor Florea wrote: > CVE-2015-7696: Fixes a heap overflow triggered by unzipping a file with > password > CVE-2015-7697: Fixes a denial of service with a

[OE-core] [PATCH] unzip: CVE-2015-7696, CVE-2015-7697

2015-10-28 Thread Tudor Florea
CVE-2015-7696: Fixes a heap overflow triggered by unzipping a file with password CVE-2015-7697: Fixes a denial of service with a file that never finishes unzipping References: http://www.openwall.com/lists/oss-security/2015/10/11/5 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-7696