boostorg / boost_install

8 stars 31 forks source link

bzip2 upgrade #35

Closed sebrowne closed 4 years ago

sebrowne commented 4 years ago

Can bzip2 please be upgraded to 1.0.8 in order to mitigate CVE-2019-12900?

pdimov commented 4 years ago

The bzip2 directory in this repo is only used for CI testing, but I'll update in anyway.

sebrowne commented 4 years ago

Thank you, much appreciated!

pdimov commented 4 years ago

Updated with https://github.com/boostorg/boost_install/commit/34e380ac63586856acc5589bff583db4e04d048b.