Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Upgrade brotli to 1.0.9: integer overflow flaw #53

Open
jhiswin opened this issue Jul 13, 2021 · 1 comment
Open

Upgrade brotli to 1.0.9: integer overflow flaw #53

jhiswin opened this issue Jul 13, 2021 · 1 comment

Comments

@jhiswin
Copy link

jhiswin commented Jul 13, 2021

https://github.com/google/brotli#security-note

Version 1.0.9 contains a fix to "integer overflow" problem.

IIS.Compression is currently using 1.0.7 (like a lot of other vulnerable projects).
Integer overflow should be an emergency critical update.

Someone should probably do a PSA, because it looks like an endemic problem. Many projects appear to be copying the same 1.0.7 patches even though it has a known integer overflow, and who knows if someone will pull off a 0-day hat trick and release a worm.

@fredericDelaporte
Copy link

This seems fixed in latest release by #54.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants