openSUSE-SU-2019:1845-1
Dashboard / Vulnerabilities / openSUSE-SU-2019:1845-1
openSUSE-SU-2019:1845-1
Summary: Security update for zstd
Details: This update for zstd to version 1.4.2 fixes the following issues: Security issues fixed: - CVE-2019-11922: Fixed race condition in one-pass compression functions that could allow out of bounds write (boo#1142941). Non-security issues fixed: - Added --[no-]compress-literals CLI flag to enable or disable literal compression. - Added new --rsyncable mode. - Added handling of -f flag to zstdgrep. - Added CPU load indicator for each file on -vv mode. - Changed --no-progress flag to preserve the final summary. - Added new command --adapt for compressed network piping of data adjusted to the perceived network conditions.
References: https://lists.opensuse.org/archives/list/[email protected]/thread/QXHXFC7RU7NI42XMFKHE6KI6JEJOMZ3W/#QXHXFC7RU7NI42XMFKHE6KI6JEJOMZ3W, https://bugzilla.suse.com/1082318, https://bugzilla.suse.com/1133297, https://bugzilla.suse.com/1142941, https://www.suse.com/security/cve/CVE-2019-11922
Affected packages
Package
Name: zstd
Purl: pkg:rpm/opensuse/zstd&distro=openSUSE%20Leap%2015.1
Affected ranges
Type: ECOSYSTEM
Events:
