Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Security] Shipped source code is vulnerable to CVE-2019-12900 #4

Closed
hasufell opened this issue Mar 8, 2024 · 7 comments
Closed

[Security] Shipped source code is vulnerable to CVE-2019-12900 #4

hasufell opened this issue Mar 8, 2024 · 7 comments

Comments

@hasufell
Copy link
Contributor

hasufell commented Mar 8, 2024

Although it is reported that the vulnerability is not actually exploitable (under current compilers): https://gnu.wildebeest.org/blog/mjw/2019/08/02/bzip2-and-the-cve-that-wasnt/

How much of that is true with current compilers on different platforms, configurations and compilation flags is not clear to me.

@Bodigrim
Copy link

Bodigrim commented Mar 8, 2024

Shall we move this discussion to https://github.com/haskell/bzlib, which is kinda an upstream repo?

@hasufell
Copy link
Contributor Author

hasufell commented Mar 9, 2024

I have no idea. The cabal file references this repo.

@phadej
Copy link

phadej commented Mar 9, 2024

That's because the latest release is NMU from 2020 haskell-infra/hackage-trustees#262

I'd suggest you take over the package. I doubt Duncan (who is the only in uploader group at the moment) could complain.

In particular, I also doubt that Duncan will notice any GitHub discussion, here or in haskell/bzlib (AFAIK he doesn't have GitHub notifications enabled). You should sent him an email.

@Bodigrim
Copy link

Bodigrim commented Mar 9, 2024

In particular, I also doubt that Duncan will notice any GitHub discussion, here or in haskell/bzlib (AFAIK he doesn't have GitHub notifications enabled). You should sent him an email.

I asked Duncan by email for bzlib takeover twice in 2023, but he never replied. Let me send a takeover request later today.

@Bodigrim
Copy link

Bodigrim commented Mar 9, 2024

@Bodigrim
Copy link

Bodigrim commented Mar 9, 2024

All set now, Duncan granted me upload rights: https://hackage.haskell.org/package/bzlib/maintainers/

@hasufell let's continue at https://github.com/haskell/bzlib please.

@phadej phadej closed this as completed Mar 9, 2024
@Bodigrim
Copy link

@phadej shall we archive this repo?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants