Mailing List ArchiveSupport open source code!
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]Re: [tlug] zlib bug
- To: tlug@example.com
- Subject: Re: [tlug] zlib bug
- From: Ben Gertzfield <che@example.com>
- Date: Sun, 31 Mar 2002 23:20:27 +0900
- Content-type: text/plain; charset=us-ascii
- In-reply-to: <20020331132102.GC1994@example.com> (Christopher SEKIYA'smessage of "Sun, 31 Mar 2002 22:21:02 +0900")
- Organization: Debian GNU/Linux
- References: <20020330203725.3d093819.gstewart@example.com><000b01c1d8b1$62c39380$0100a8c0@example.com><20020331132102.GC1994@example.com>
- Sender: ben@example.com
- User-agent: Gnus/5.090006 (Oort Gnus v0.06) XEmacs/21.4 (Civil Service,i386-debian-linux)
>>>>> "Christopher" == Christopher SEKIYA <wileyc@example.com> writes: Pietro> Let's see at Pietro> http://www.cert.org/advisories/CA-2002-07.html Christopher> Known problem, fixed in new zlib release, only bad if Christopher> one's free() implementation segfaults when Christopher> double-freeing (good design choice, Doug Lea). It definitely was quickly fixed in the new zlib release, but there are hundreds if not thousands of software products that took the zlib source and made it part of their program directly, without linking against a dynamic library. These cannot be fixed with a new upstream release, and we all know how long it takes commercial products to fix security flaws of this sort. Try grepping a few Windows programs for common zlib symbol names sometime. Ben -- Brought to you by the letters G and P and the number 7. "To Perl, or not to Perl, that is the kvetching." Debian GNU/Linux maintainer of Gimp and Nethack -- http://www.debian.org/
- References:
- Re: [tlug] can't post to Mandrake expert.
- From: Godwin Stewart
- [tlug] zlib bug
- From: Pietro Zuco
- Re: [tlug] zlib bug
- From: Christopher SEKIYA
Home | Main Index | Thread Index
- Prev by Date: [tlug] only a test message
- Previous by thread: Re: [tlug] zlib bug
- Next by thread: [tlug] change email
- Index(es):
Home Page Mailing List Linux and Japan TLUG Members Links