Bug#317989: dar-static: CAN-2005-2096: Linked staticly to zlib

2005-07-13 Thread Brian May
Kurt == Kurt Roeckx [EMAIL PROTECTED] writes: Kurt You dar-static package is linked staticly against zlib which Kurt recently had a security bug fixed. See CAN-2005-2096 and Kurt DSA-740. Kurt Note that you might have fixed it in unstable already with Kurt the 2.2.1-2

Bug#317989: dar-static: CAN-2005-2096: Linked staticly to zlib

2005-07-13 Thread Michael Stone
On Thu, Jul 14, 2005 at 11:13:24AM +1000, Brian May wrote: sarge will need to get rebuilt. How is the dar-static package used? Is there actually a security issue here? (IOW, is there a scenario where dar-static is used to uncompress untrusted input?) Mike Stone -- To UNSUBSCRIBE, email to

Bug#317989: dar-static: CAN-2005-2096: Linked staticly to zlib

2005-07-13 Thread Brian May
Michael == Michael Stone [EMAIL PROTECTED] writes: Michael How is the dar-static package used? Is there actually a Michael security issue here? (IOW, is there a scenario where Michael dar-static is used to uncompress untrusted input?) I wouldn't have thought so. It could

Bug#317989: dar-static: CAN-2005-2096: Linked staticly to zlib

2005-07-12 Thread Kurt Roeckx
Package: dar-static Version: 2.2.1-1 Severity: important Tags: security Hi, You dar-static package is linked staticly against zlib which recently had a security bug fixed. See CAN-2005-2096 and DSA-740. Note that you might have fixed it in unstable already with the 2.2.1-2 version depending on