HTTPS clone URL
Subversion checkout URL
eu-ams-1 master ntp release-20110901 release-20120528 release-20120626 release-20120712 release-20120726 release-20120809 release-20120823 release-20120906 release-20120920 release-20121004 release-20121101 release-20121115 release-20121129 release-20121213 release-20121227 release-20130110 release-20130124 release-20130207 release-20130221 release-20130307 release-20130321 release-20130404 release-20130418 release-20130502 release-20130515 release-20130530 release-20130613 release-20130627 release-20130711 release-20130725 release-20130822 release-20130905 release-20130919 release-20131003 release-20131017 release-20131031 release-20131128 release-20131212 release-20140109 release-20140123 release-20140206 release-20140220 release-20140307 release-20140320 release-20140403 release-20140417 release-20140501 release-20140515 release-20140529 release-20140612 release-20140626 release-20140703 release-20140710 release-20140724 release-20140807 release-20140821 release-20140904 release-20140918 release-20141002 release-20141016 release-20141030 release-20141113 release-20141127 release-20141211 release-20141225 release-20150108 release-20150122 release-20150205 release-20150219 release-20150305 release-20150319 release-20150402 release-20150416 release-20150430 release-20150514 release-20150528 release-20150611 release-20150625 release-20150709 release-20150723 release-20150806 release-20150820 release-20150903 release-20150917 release-20151001 release-20151015 release-20151029 release-20151112 release-20151126 us-west-2
Nothing to show
Nothing to show
Fetching latest commit...
Cannot retrieve the latest commit at this time.
|Failed to load latest commit information.|
----------------- 6 Oct. 2006 - update ---------------------- Previous source patch (gzip.1.3.3.patch) was revised to gzip-6294656-6283819-diff Security issue CVE-2006-4334 synopsis: gzip multiple issues (CVE-2006-4335, CVE-2006-4336 , CVE-2006-4337, CVE-2006-4338) Is fixed by gzip-security-diff "gzip --version" info is updated by gzip.c-message-diff ------------------- original text --------------------------- The version of Gzip contained in this gate, 1.3.3, is the latest version released by the official maintainers. Following the release of this version, a number of issues were discovered which affected Solaris and for which it was deemed important to release a patch. However, the Gzip source code is no longer being maintained by the community. As a result, the diff file gzip-1.3.3.patch was created which contains the differences between our released version and the current official release. This is applied using gpatch during the build process. In order to distinguish the Sun patched version from the official community version, the version number as reported by the utility at runtime has been changed to: 1.3.3-patch.1 If in the future a new official version of Gzip is released, it should be determined whether that later version still contains the problems fixed by this patch. If it does not, this patch can be removed from the gate and the build process when the later version is integrated into the gate. If they are still present, this patch will have to be modified to be applicable to that later version before it is integrated into the gate. The patch file contains the following changes: 1) configure : The version number used during build time has been modifed as described above. 2) gzip.c: [ 6283819 gzip TOCTOU file-permissions vulnerability ] The code for this fix came from the patch used by the Debian community to address the same issue in their distribution, and was extracted from the patch downloaded from: http://security.debian.org/pool/updates/main/g/gzip/gzip_1.3.2-3woody5.diff.gz 3) gzip.c: [ 6294656 gzip vulnerability <=1.3.5: a malicious archive may write unintended files when uncompressed with -N ] The code for this fix came from the patch used by the Debian community to address the same issue in their distribution, and was extracted from the patch downloaded from: http://security.debian.org/pool/updates/main/g/gzip/gzip_1.3.2-3woody5.diff.gz