Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Vulnerability in xz version v0.5.6 #69

Closed
Niksko opened this issue Mar 15, 2021 · 1 comment · Fixed by #70
Closed

Vulnerability in xz version v0.5.6 #69

Niksko opened this issue Mar 15, 2021 · 1 comment · Fixed by #70

Comments

@Niksko
Copy link
Contributor

Niksko commented Mar 15, 2021

This version of xz is vulnerable to a denial of service and an infinite loop.

Your bz2 encoder seems to be the only one out there at the moment. This means that packages that need to do bz2 encoding (or test bz2 decoding) require this package eventually, which means this vulnerability is likely to cause headaches.

@dsnet
Copy link
Owner

dsnet commented Mar 15, 2021

Hi, thanks for the report. Did you mean to post this at github.com/ulikunitz/xz instead? This repository does not have an xz implementation.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging a pull request may close this issue.

2 participants