From 0393ba6656ce6cf679a2c4663275b3ed0f1a34b9 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Parm=C3=A9nides=20GV?= Date: Thu, 31 Jul 2014 12:09:49 +0200 Subject: Updated ics-openvpn to rev 859 + no 2nd notification. --- app/lzo/NEWS | 16 ++++++++++++++++ 1 file changed, 16 insertions(+) (limited to 'app/lzo/NEWS') diff --git a/app/lzo/NEWS b/app/lzo/NEWS index 15eedeff..103c4d87 100644 --- a/app/lzo/NEWS +++ b/app/lzo/NEWS @@ -2,6 +2,22 @@ User visible changes for LZO -- a real-time data compression library ============================================================================ +Changes in 2.07 (25 Jun 2014) + * Fixed a potential integer overflow condition in the "safe" decompressor + variants which could result in a possible buffer overrun when + processing maliciously crafted compressed input data. + + As this issue only affects 32-bit systems and also can only happen if + you use uncommonly huge buffer sizes where you have to decompress more + than 16 MiB (2^24 bytes) compressed bytes within a single function call, + the practical implications are limited. + + POTENTIAL SECURITY ISSUE. + + * Removed support for ancient configurations like 16-bit "huge" pointers - + LZO now requires a flat 32-bit or 64-bit memory model. + * Assorted cleanups. + Changes in 2.06 (12 Aug 2011) * Some minor optimizations for big-endian architectures. * Fixed overly strict malloc() misalignment check in examples. -- cgit v1.2.3