-
-
Notifications
You must be signed in to change notification settings - Fork 706
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Fix Issue 23288 - zlib: Fix potential buffer overflow #8528
Conversation
|
Thanks for your pull request and interest in making D better, @ibara! We are looking forward to reviewing it, and you should be hearing from a maintainer soon.
Please see CONTRIBUTING.md for more information. If you have addressed all reviews or aren't sure how to proceed, don't hesitate to ping us with a simple comment. Bugzilla references
Testing this PR locallyIf you don't have a local development environment setup, you can use Digger to test this PR: dub run digger -- build "master + phobos#8528" |
|
Is this part of a zlib release? |
Not yet, no. The latest release is 1.2.12, which we already have in Phobos. These commits are from the zlib master branch after 1.2.12 was released. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Why are we not using a git submodule and keep a copy of the original?
I think I'd prefer to just "sync" with the development branch then, as there are other regression fixes for bugs that occurred in the .12 release. Surely they'll be a release soon though if this is critical? |
Zlib does not have a good history of timely releases for security critical items: https://orca.security/resources/blog/zlib-memory-corruption-vulnerability-cve-2018-25032/ |
I'm not sure why. There are some diffs to upstream zlib in Phobos zlib. |
Hello --
As mentioned in the bug report, this fixes a potential buffer overflow in zlib. It is a combined diff from
madler/zlib@eff308a
and
madler/zlib@1eb7682
I wasn't sure whether this should go in master or stable, so I chose master. In any event, we probably want this.