OT: zlib clamav-0.81

nodata fedora at nodata.co.uk
Thu Jan 27 14:36:42 UTC 2005


> hi,
>
> fyi
>
> fc3 has zlib-1.2.1.2-1
> development has zlib-1.2.2.2-1
>
>
> $ rpm -q zlib
> zlib-1.2.1.2-1
>
> $ pwd
> /usr/local/clamav-0.81
>
> $ ./configure
> [...]
> checking for zlib installation... /usr
> configure: error: The installed zlib version may contain a security bug.
> Please upgrade to 1.2.2 or later: http://www.zlib.net. You can omit this
> check with --disable-zlib-vcheck but DO NOT REPORT any stablility issues
> then!
>
> --
> shrek-m
>

Oh dear. The changelog for zlib shows a last entry of Sep 13 2004.
The fixed zlib 1.2.2 was released more than two weeks later, on October
3rd, 2004

Time to get those security auditors in! :)

You should bugzilla this as "security".




More information about the fedora-test-list mailing list