[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
gzip 1.3.7 released
gzip 1.3.7 released
Thu, 07 Dec 2006 00:12:34 -0800
Gnus/5.1008 (Gnus v5.10.8) Emacs/21.4 (gnu/linux)
I'm happy to announce the release of gzip 1.3.7.
gzip (GNU zip) is a popular data compression program written by
Jean-Loup Gailly for the GNU project; Mark Adler wrote the
This gzip release follows up on last month's 1.3.6 test
release, and attempts to fix correctness bugs and porting
bugs discovered and reported since then. With these bugs
shaken out, 1.3.7 has a greater chance of becoming an
official release. However, the number of fixes makes it
advisable to issue it as a test release first.
Please report any problems to <address@hidden>.
The compressed sources are here:
ftp://alpha.gnu.org/gnu/gzip/gzip-1.3.7.tar.gz (544 KB)
The GPG detached signature is here:
Here are the MD5 and SHA512 digests:
Here are URLs to the ChangeLog entries since the most recent
test version (1.3.6) and stable version (1.2.4),
Here are the major changes since 1.3.6, reported in the NEWS file:
* Fix some gzip problems:
- Refuse to compress setuid or setgid files, or files with the sticky bit.
- Fix more race conditions in setting file permissions and owner,
removing output files, following symbolic links, and dealing with
- Remove most of the code working around ENAMETOOLONG deficiencies.
Systems with those deficiencies are long-dead, and the workarounds
had race conditions on modern hosts.
- Catch CPU time and file size limit signals, too.
- Check for read errors when closing files.
- Fix a core dump caused by a stray abort mistakenly introduced in 1.3.6.
* Fix some gzexe problems:
- Improve resistance to denial-of-service attacks.
- Fix some quoting and escaping bugs.
- Do not assume /tmp is sticky (though it should be!).
- Do not assume the working directory can be written.
- Rely on PATH in the generated executable, as the man page says.
- Don't assume IFS is sane.
- Exit with signal's status, if signaled.
|[Prev in Thread]
||[Next in Thread]|
- gzip 1.3.7 released,
Paul Eggert <=