Alerts This Week
Warning Icon 1 540
Alerts This Week
Warning Icon 1 540

Fedora 29: FEDORA-2018-7d138cfd7b Moderate: Zchunk Sanity Check

fedora
Calendar Grey November 7, 2018
Dist Fedora Esm H88
Enhanced zchunk integrity verification in Fedora 29 to avert failures caused by non-hexadecimal characters during security patching.
This update does sanity checking when an application passes in a checksum to verify

Summary

zchunk is a compressed file format that splits the file into independent

chunks. This allows you to only download the differences when downloading a

new version of the file, and also makes zchunk files efficient over rsync.

zchunk files are protected with strong checksums to verify that the file you

downloaded is in fact the file you wanted.

This update does sanity checking when an application passes in a checksum to

verify. Before this release, applications could pass in non-hex values for the

checksum, which could cause zchunk to crash. Now non-hex values will be

rejected.

* Thu Nov 1 2018 Jonathan Dieter - 0.9.14-1

- Sanity check hex hashes passed in as an option

* Mon Oct 8 2018 Jonathan Dieter - 0.9.13-1

- Add read support for zchunk files with optional flags

- Fix tests for zstd-1.3.6

su -c 'dnf upgrade --advisory FEDORA-2018-7d138cfd7b' at the command

line. For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/

List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines

List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/

Change Log

References

Update Instructions

Severity
important
Lowest
Low
Medium
High
Critical

Product: Fedora 29
Version: 0.9.14
Release: 1.fc29
Summary: Compressed file format that allows easy deltas

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here