Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Date: Wed, 19 Mar 2008 20:54:15 -0400
From: Josh Bressers <bressers@...hat.com>
To: oss-security@...ts.openwall.com
cc: Robert Buchholz <rbu@...too.org>
Subject: Re: CVE request: bzip2 CERT-FI: 20469

> 
> I'm running version 1.0.4 through the bzip2 files now (it takes a long time
> to run, there are a lot of files).  If I find the reproducer, I'll let you
> know.
> 
> I saw no crashes when I ran the CERT-FI suite over bzip2 versions 1.0.1,
> 1.0.2, and 1.0.3.
> 

I mailed upstream, the file we want is 1203ea663ea8545c9b66ad3ef46425d0.bz2

The problem I had with my testrunner is that the bunzip2 has a segfault
handler.  Rather that properly segfaulting, it's doing an exit(2).  I'm
going to rerun the suite with this new knowledge now to see what's affected
and how.

-- 
    JB

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.