From 8ff61daa672f051d8ecb537edc94036b6cdaaf3f Mon Sep 17 00:00:00 2001 From: DongHun Kwak Date: Thu, 22 Jun 2017 16:59:16 +0900 Subject: Imported Upstream version 2.09 Change-Id: Iff3c94491fe695b43f1d6998f93f56af871806a2 Signed-off-by: DongHun Kwak --- NEWS | 4 ++++ 1 file changed, 4 insertions(+) (limited to 'NEWS') diff --git a/NEWS b/NEWS index 1bac34a..80da4ea 100644 --- a/NEWS +++ b/NEWS @@ -2,6 +2,10 @@ User visible changes for LZO -- a real-time data compression library ============================================================================ +Changes in 2.09 (04 Feb 2015) + * Work around gcc bug #64516 that could affect architectures like + armv4, armv5 and sparc. + Changes in 2.08 (29 Jun 2014) * Updated the Autoconf scripts to fix some reported build problems. * Added CMake build support. -- cgit v1.2.3 From 57de6cacd32854c3b7942dde1803894341f78cee Mon Sep 17 00:00:00 2001 From: DongHun Kwak Date: Thu, 22 Jun 2017 16:59:51 +0900 Subject: Imported Upstream version 2.10 Change-Id: Ic72ac9c6134dff3a335d581378095e0011abcb08 Signed-off-by: DongHun Kwak --- NEWS | 12 +++++++++--- 1 file changed, 9 insertions(+), 3 deletions(-) (limited to 'NEWS') diff --git a/NEWS b/NEWS index 80da4ea..4c2bbda 100644 --- a/NEWS +++ b/NEWS @@ -2,6 +2,12 @@ User visible changes for LZO -- a real-time data compression library ============================================================================ +Changes in 2.10 (01 Mar 2017) + * Improve CMake build support. + * Add support for pkg-config. + * Do not redefine "snprintf" so that the examples build with MSVC 2015. + * Assorted cleanups. + Changes in 2.09 (04 Feb 2015) * Work around gcc bug #64516 that could affect architectures like armv4, armv5 and sparc. @@ -16,10 +22,10 @@ Changes in 2.07 (25 Jun 2014) variants which could result in a possible buffer overrun when processing maliciously crafted compressed input data. - Fortunately this issue only affects 32-bit systems and also can only happen + Note that this issue only affects 32-bit systems and also can only happen if you use uncommonly huge buffer sizes where you have to decompress more - than 16 MiB (> 2^24 bytes) untrusted compressed bytes within a single - function call, so the practical implications are limited. + than 16 MiB (> 2^24 bytes) untrusted compressed bytes within a + *single* function call, so the practical implications are limited. POTENTIAL SECURITY ISSUE. CVE-2014-4607. -- cgit v1.2.3