Security fix trivial update:

http://www.altroot.org/chmlib-0.39.patch

This fixes the vulnerability which might lead to a code execution:

http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=468

Info about the release:

    *  2007-01-24, 6:10 PM PST: Released chmlib 0.39.

Version 0.39 is a security release. All of the dynamically-sized buffers
which were allocated on the stack before have been changed to heap
allocations. This circumvents some dangerous security flaws.

--
Martynas Venckus

Reply via email to