[Bug 935864] New: zlib: package minizip?

http://bugzilla.suse.com/show_bug.cgi?id=935864 Bug ID: 935864 Summary: zlib: package minizip? Classification: openSUSE Product: openSUSE Factory Version: 201505* Hardware: Other OS: Other Status: NEW Severity: Normal Priority: P5 - None Component: Basesystem Assignee: tchvatal@suse.com Reporter: lnussel@suse.com QA Contact: qa-bugs@suse.de CC: security-team@suse.de Found By: --- Blocker: --- zlib contains contrib/minizip which at least by judging from the use of unzip.h is contained as copy in 30 other packages. What about building minizip as separate sub package? -- You are receiving this mail because: You are on the CC list for the bug.

http://bugzilla.suse.com/show_bug.cgi?id=935864 http://bugzilla.suse.com/show_bug.cgi?id=935864#c1 --- Comment #1 from Tomáš Chvátal <tchvatal@suse.com> --- Noot really, that piece of code is buggy to hell. If something really uses it apart from being example they should <quote>die most painful death</quote> :) If you really want it we can provide it sure, but I would love to know who will be responsible for rewriting the script so we could actually trust it. -- You are receiving this mail because: You are on the CC list for the bug.

http://bugzilla.suse.com/show_bug.cgi?id=935864 http://bugzilla.suse.com/show_bug.cgi?id=935864#c2 --- Comment #2 from Ludwig Nussel <lnussel@suse.com> --- are we talking about the same thing? libminizip? -- You are receiving this mail because: You are on the CC list for the bug.

http://bugzilla.suse.com/show_bug.cgi?id=935864 http://bugzilla.suse.com/show_bug.cgi?id=935864#c3 --- Comment #3 from Ludwig Nussel <lnussel@suse.com> --- https://github.com/XQF/xqf/issues/141#issuecomment-114556333 -- You are receiving this mail because: You are on the CC list for the bug.

http://bugzilla.suse.com/show_bug.cgi?id=935864 http://bugzilla.suse.com/show_bug.cgi?id=935864#c4 --- Comment #4 from Tomáš Chvátal <tchvatal@suse.com> --- (In reply to Ludwig Nussel from comment #2)
are we talking about the same thing? libminizip?
No we are not, mistaken it for one tiny beast, anyway will sent updated zlib soon TM. -- You are receiving this mail because: You are on the CC list for the bug.

http://bugzilla.suse.com/show_bug.cgi?id=935864 http://bugzilla.suse.com/show_bug.cgi?id=935864#c5 Tomáš Chvátal <tchvatal@suse.com> changed: What |Removed |Added ---------------------------------------------------------------------------- Status|NEW |RESOLVED Resolution|--- |FIXED --- Comment #5 from Tomáš Chvátal <tchvatal@suse.com> --- Submitted to factory -> Closing as fixed. -- You are receiving this mail because: You are on the CC list for the bug.

http://bugzilla.suse.com/show_bug.cgi?id=935864 http://bugzilla.suse.com/show_bug.cgi?id=935864#c7 --- Comment #7 from Ludwig Nussel <lnussel@suse.com> --- thanks! FWIW Fedora has two minizip related patches in their package. Maybe they are worth including. -- You are receiving this mail because: You are on the CC list for the bug.

http://bugzilla.suse.com/show_bug.cgi?id=935864 http://bugzilla.suse.com/show_bug.cgi?id=935864#c8 --- Comment #8 from Tomáš Chvátal <tchvatal@suse.com> --- (In reply to Ludwig Nussel from comment #7)
thanks! FWIW Fedora has two minizip related patches in their package. Maybe they are worth including.
Changes stuff in the crypto which aint supported at all, so not sure if it is worth it... -- You are receiving this mail because: You are on the CC list for the bug.

http://bugzilla.suse.com/show_bug.cgi?id=935864 http://bugzilla.suse.com/show_bug.cgi?id=935864#c11 --- Comment #11 from Bernhard Wiedemann <bwiedemann@suse.com> --- This is an autogenerated message for OBS integration: This bug (935864) was mentioned in https://build.opensuse.org/request/show/425611 13.2 / zlib -- You are receiving this mail because: You are on the CC list for the bug.

http://bugzilla.suse.com/show_bug.cgi?id=935864 Swamp Workflow Management <swamp@suse.de> changed: What |Removed |Added ---------------------------------------------------------------------------- Whiteboard| |obs:running:5596:low -- You are receiving this mail because: You are on the CC list for the bug.

http://bugzilla.suse.com/show_bug.cgi?id=935864 Swamp Workflow Management <swamp@suse.de> changed: What |Removed |Added ---------------------------------------------------------------------------- Whiteboard|obs:running:5596:low | -- You are receiving this mail because: You are on the CC list for the bug.

http://bugzilla.suse.com/show_bug.cgi?id=935864 http://bugzilla.suse.com/show_bug.cgi?id=935864#c13 --- Comment #13 from Swamp Workflow Management <swamp@suse.de> --- openSUSE-RU-2016:2340-1: An update that has two recommended fixes can now be installed. Category: recommended (low) Bug References: 890228,935864 CVE References: Sources used: openSUSE 13.2 (src): zlib-1.2.8-5.3.1 -- You are receiving this mail because: You are on the CC list for the bug.

http://bugzilla.suse.com/show_bug.cgi?id=935864 http://bugzilla.suse.com/show_bug.cgi?id=935864#c14 --- Comment #14 from Swamp Workflow Management <swamp@suse.de> --- This is an autogenerated message for OBS integration: This bug (935864) was mentioned in https://build.opensuse.org/request/show/747777 Backports:SLE-12 / zlib -- You are receiving this mail because: You are on the CC list for the bug.
participants (1)
-
bugzilla_noreply@novell.com