Comment 3 for bug 625849

Revision history for this message
Scott Kitterman (kitterman) wrote :

Got the answer:

<ScottK> aCaB: Our packages are already using the system bzip2? If not, can they?
<aCaB> they are using both
<aCaB> system bzip2 for bzip compression
<aCaB> hacked bzip2 from sources, for hacked bzip compression
<aCaB> latter is in use by certain packers
<aCaB> both are vulnerable anyway
<aCaB> btw it's CVE-2010-0405