Fwd: XZ Utils 5.8.4 and a security fix
XZ Utils 5.8.4 fixes an invalid memory write that occurs when a decoder is reinitialized after allocation failure in 5.8.3 and older.
XZ Utils 5.8.4 has been released with a security fix for versions 5.8.3 and older. The flaw is an invalid memory write that can occur when a decoder is reinitialized after an allocation failure. The announcement was posted on the oss-security mailing list by Sam James pointing to the upstream stable release. Users and distributions running affected versions should upgrade to 5.8.4.
- Fixed in XZ Utils 5.8.4; affected versions are 5.8.3 and older.
- Triggered when a decoder is reinitialized following an allocation failure.
- Announced via the oss-security mailing list with details on the Tukaani project page.
Posted by Sam James on Sep 09 -------------------- Start of forwarded message -------------------- https://tukaani.org/xz/#_stable>. In XZ Utils 5.8.3 and older, an invalid memory write can occur if a decoder is reinitialized after allocation failure. For details, see the...
This source does not provide full text. Read it at seclists.org.