Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date: Thu, 29 Sep 2011 04:41:53 +0400
From: Solar Designer <solar@...nwall.com>
To: Tomas Hoger <thoger@...hat.com>
Cc: oss-security@...ts.openwall.com, Colin Percival <cperciva@...ebsd.org>
Subject: Re: LZW decompression issues

Tomas -

On Wed, Sep 28, 2011 at 08:22:28PM +0200, Tomas Hoger wrote:
> Let me try to explain some.

Thank you!  This is very helpful.

> > Do we possibly want to add the "maxbits < 12" check as well?  And does
> > it matter for security?
> 
> I'm not aware of any security impact of that.  Not sure if there's any
> spec that requires maxbits >= 12, if not, INIT_BITS (9) may be a safer
> lower bound.

I am asking Joerg about it in another message.

Colin - thank you for your prompt response (redirecting us to NetBSD).
Some further postings went without CC to you, I hope that's OK.

Alexander

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.