[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: [SECURITY] [DLA 1833-2] bzip2 regression update



-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Sorry for the noise, but the fixed version in Jessie is:
   1.0.6-7+deb8u2


On Thu, 18 Jul 2019, Thorsten Alteholz wrote:

Package        : bzip2
Version        : 1.0.6-4+deb7u2
CVE ID         : CVE-2019-12900



The original fix for CVE-2019-12900 in bzip2, a high-quality
block-sorting file compressor, introduces regressions when extracting
certain lbzip2 files which were created with a buggy libzip2.
Please see https://bugs.debian.org/931278 for more information.


For Debian 8 "Jessie", this problem has been fixed in version
1.0.6-4+deb7u2.

We recommend that you upgrade your bzip2 packages.

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS

-----BEGIN PGP SIGNATURE-----

iQKTBAEBCgB9FiEEYgH7/9u94Hgi6ruWlvysDTh7WEcFAl0w3JdfFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDYy
MDFGQkZGREJCREUwNzgyMkVBQkI5Njk2RkNBQzBEMzg3QjU4NDcACgkQlvysDTh7
WEcfBRAAkKyTyRHqhMWCCDNOk+mUT/rDRoIcL36tCYyveCezBIz2nAhJti4+tlN6
n0gaitfdEFTPzDEbuBkd5KDGT9HPrt0w2EUGRs8WubSMbe9YfmflChhHdYDkYQW4
ndlecHfEQK2xbxVcwRN+Z5hDvqrE/aLjKD18CB8js8yds1xLcDCyXhIgv3ZKHMz/
GuVdsFXyQPNZ6mYH8fPZeWSBXz0e/zKD0T/aVeXY17Z6op2TWrBtwTImkcQ16B7b
VOSk9xLVr+gtCJs3H3PQ/phu0fLQqw7e4OcxRnt2HeyqC75hS1xqDLCBsuBUbHws
7XLdixn/h9i/1DJWipL9zQ7Ni+At3nY5r3hg+BMdb4bxo/srbuLwqanujy6U4Xrd
ZfPBhsMYa1pgUs0/f76DElotuTkpOXmg1bCGbOl6w1T+SB3Cm+h+4tYbPxoWG1t8
zrYfe52x55rnkNyOU+U5uIqlvPfPxZd52b8UG7/TVGQRDTu0Hi783zf95A0vP9Vg
qhBYI2UM0ANCHlUDK/hcRJys0TbdpEH3ZQKFBu9bOxETq2DheiFc5is5xL+ewGN+
2RQIW6nm8Ib8+ovi1cuY1vtEivp4YDbapkfaYs62bje2xjT1HAq7TtoVLbFZzcUd
gb8TBM73OJuaAWkBK22ezWtExpc5yzUGVBkiMbb4Rhvly4mMjXQ=
=X9EG
-----END PGP SIGNATURE-----


Reply to: