http://bugzilla.suse.com/show_bug.cgi?id=1140733 Bug ID: 1140733 Summary: lbzip2 - don't exceed 18002 selectors Classification: openSUSE Product: openSUSE Tumbleweed Version: Current Hardware: x86-64 OS: openSUSE Factory Status: NEW Severity: Normal Priority: P5 - None Component: Other Assignee: bnc-team-screening@forge.provo.novell.com Reporter: kstreitova@suse.com QA Contact: qa-bugs@suse.de Found By: --- Blocker: --- Bzip2 recently got a fix [1] (CVE-2019-12900) that causes that files compressed by lbzip2 before this commit [2] fail to uncompress. Before that lbzip2 b6dc48 commit, lbzip2 abused bzip2 bug that allowed to accept more than 18002 selectors. As this bzip2 bug is now fixed, it's needed to adjust lbzip2 in the same manner. [1] https://gitlab.com/federicomenaquintero/bzip2/commit/74de1e2e6ffc9d51ef9824d... [2] https://github.com/kjn/lbzip2/commit/b6dc48a7b9bfe6b340ed1f6d72133608ad57144... -- You are receiving this mail because: You are on the CC list for the bug.