grub-devel
[Top][All Lists]
Advanced

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [PATCH v2] Update to minilzo-2.08


From: Daniel Kiper
Subject: Re: [PATCH v2] Update to minilzo-2.08
Date: Wed, 29 Jan 2020 13:30:46 +0100
User-agent: NeoMutt/20170113 (1.7.2)

On Mon, Jan 20, 2020 at 03:07:49PM +0100, Javier Martinez Canillas wrote:
> From: Peter Jones <address@hidden>
>
> This patch updates the miniLZO library to a newer version, which among other
> things fixes "CVE-2014-4607 - lzo: lzo1x_decompress_safe() integer overflow"
> that is present in the current used in GRUB.
>
> It also updates the "GRUB Developers Manual", to mention that the library is
> used and describes the process to update it to a newer release when needed.
>
> Resolves: http://savannah.gnu.org/bugs/?42635
>
> Signed-off-by: Peter Jones <address@hidden>
> Signed-off-by: Javier Martinez Canillas <address@hidden>

Reviewed-by: Daniel Kiper <address@hidden>

Daniel



reply via email to

[Prev in Thread] Current Thread [Next in Thread]