<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 3.2//EN"> <HTML> <HEAD> <TITLE> [Mageia-dev] Freeze push: libzip (security update) </TITLE> <LINK REL="Index" HREF="index.html" > <LINK REL="made" HREF="mailto:mageia-dev%40mageia.org?Subject=Re%3A%20%5BMageia-dev%5D%20Freeze%20push%3A%20libzip%20%28security%20update%29&In-Reply-To=%3C20120328164738.GY21938%40mars-attacks.org%3E"> <META NAME="robots" CONTENT="index,nofollow"> <META http-equiv="Content-Type" content="text/html; charset=us-ascii"> <LINK REL="Previous" HREF="013604.html"> <LINK REL="Next" HREF="013611.html"> </HEAD> <BODY BGCOLOR="#ffffff"> <H1>[Mageia-dev] Freeze push: libzip (security update)</H1> <B>nicolas vigier</B> <A HREF="mailto:mageia-dev%40mageia.org?Subject=Re%3A%20%5BMageia-dev%5D%20Freeze%20push%3A%20libzip%20%28security%20update%29&In-Reply-To=%3C20120328164738.GY21938%40mars-attacks.org%3E" TITLE="[Mageia-dev] Freeze push: libzip (security update)">boklm at mars-attacks.org </A><BR> <I>Wed Mar 28 18:47:38 CEST 2012</I> <P><UL> <LI>Previous message: <A HREF="013604.html">[Mageia-dev] Freeze push: libzip (security update) </A></li> <LI>Next message: <A HREF="013611.html">[Mageia-dev] Freeze push: libzip (security update) </A></li> <LI> <B>Messages sorted by:</B> <a href="date.html#13609">[ date ]</a> <a href="thread.html#13609">[ thread ]</a> <a href="subject.html#13609">[ subject ]</a> <a href="author.html#13609">[ author ]</a> </LI> </UL> <HR> <!--beginarticle--> <PRE>On Wed, 28 Mar 2012, David Walser wrote: ><i> New vulnerabilities CVE-2012-1162 (heap overflow) and CVE-2012-1163 (integer </I>><i> overflow) in libzip were recently announced. </I>><i> </I>><i> libzip 0.10.1 has been released to fix these. I have updated it in SVN and </I>><i> confirmed it builds on current Cauldron. I mentioned this earlier and Anne </I>><i> submitted it to the build system, and it built, but one of the make check </I>><i> tests failed. I can't reproduce this, even on a stripped-down VM with no </I>><i> extra -devel packages installed, so I'm thinking it was a transient issue on </I>><i> the build system (as I've seen this happen before). Can we please try </I>><i> submitting it again? </I> It still fails : <A HREF="http://pkgsubmit.mageia.org/uploads/failure/cauldron/core/release/20120328164050.boklm.valstar.7233/log/libzip-0.10.1-1.mga2/build.0.20120328164051.log">http://pkgsubmit.mageia.org/uploads/failure/cauldron/core/release/20120328164050.boklm.valstar.7233/log/libzip-0.10.1-1.mga2/build.0.20120328164051.log</A> </PRE> <!--endarticle--> <HR> <P><UL> <!--threads--> <LI>Previous message: <A HREF="013604.html">[Mageia-dev] Freeze push: libzip (security update) </A></li> <LI>Next message: <A HREF="013611.html">[Mageia-dev] Freeze push: libzip (security update) </A></li> <LI> <B>Messages sorted by:</B> <a href="date.html#13609">[ date ]</a> <a href="thread.html#13609">[ thread ]</a> <a href="subject.html#13609">[ subject ]</a> <a href="author.html#13609">[ author ]</a> </LI> </UL> <hr> <a href="https://www.mageia.org/mailman/listinfo/mageia-dev">More information about the Mageia-dev mailing list</a><br> </body></html>