diff options
Diffstat (limited to 'CHANGES')
| -rw-r--r-- | CHANGES | 20 |
1 files changed, 18 insertions, 2 deletions
| @@ -2,8 +2,8 @@ | |||
| 2 | This file is part of bzip2/libbzip2, a program and library for | 2 | This file is part of bzip2/libbzip2, a program and library for |
| 3 | lossless, block-sorting data compression. | 3 | lossless, block-sorting data compression. |
| 4 | 4 | ||
| 5 | bzip2/libbzip2 version 1.0.7 of 27 June 2019 | 5 | bzip2/libbzip2 version 1.0.8 of 13 July 2019 |
| 6 | Copyright (C) 1996-2010 Julian Seward <jseward@acm.org> | 6 | Copyright (C) 1996-2019 Julian Seward <jseward@acm.org> |
| 7 | 7 | ||
| 8 | Please read the WARNING, DISCLAIMER and PATENTS sections in the | 8 | Please read the WARNING, DISCLAIMER and PATENTS sections in the |
| 9 | README file. | 9 | README file. |
| @@ -338,3 +338,19 @@ Security fix only. Fixes CERT-FI 20469 as it applies to bzip2. | |||
| 338 | * bzip2recover: Fix use after free issue with outFile (CVE-2016-3189) | 338 | * bzip2recover: Fix use after free issue with outFile (CVE-2016-3189) |
| 339 | 339 | ||
| 340 | * Make sure nSelectors is not out of range (CVE-2019-12900) | 340 | * Make sure nSelectors is not out of range (CVE-2019-12900) |
| 341 | |||
| 342 | 1.0.8 (13 Jul 19) | ||
| 343 | ~~~~~~~~~~~~~~~~~ | ||
| 344 | |||
| 345 | * Accept as many selectors as the file format allows. | ||
| 346 | This relaxes the fix for CVE-2019-12900 from 1.0.7 | ||
| 347 | so that bzip2 allows decompression of bz2 files that | ||
| 348 | use (too) many selectors again. | ||
| 349 | |||
| 350 | * Fix handling of large (> 4GB) files on Windows. | ||
| 351 | |||
| 352 | * Cleanup of bzdiff and bzgrep scripts so they don't use | ||
| 353 | any bash extensions and handle multiple archives correctly. | ||
| 354 | |||
| 355 | * There is now a bz2-files testsuite at | ||
| 356 | https://sourceware.org/git/bzip2-tests.git | ||
