Skip to content
Commit f6f9b093 authored by Frank Vanbever's avatar Frank Vanbever Committed by Peter Korsgaard
Browse files

package/libmodsecurity: security bump to version 3.0.9

Fixes the following security issue:
- CVE-2023-28882: Trustwave ModSecurity 3.0.5 through 3.0.8 before 3.0.9 allows
  a denial of service (worker crash and unresponsiveness) because some inputs
  cause a segfault in the Transaction class for some configurations.

  https://security-tracker.debian.org/tracker/CVE-2023-28882



- Drop 0003-Revert-Fix-maxminddb-link-on-FreeBSD.patch, handling of libmaxminddb
  was fixed upstream in d2b700d
- Drop 0004-build-pcre.m4-fix-build-without-pcre.patch, handling of PCRE was
  fixed upstream in 791964a

Signed-off-by: default avatarFrank Vanbever <frank.vanbever@mind.be>
Signed-off-by: default avatarPeter Korsgaard <peter@korsgaard.com>
(cherry picked from commit a1e0e727)
Signed-off-by: default avatarPeter Korsgaard <peter@korsgaard.com>
parent 63dc6f6d
Loading
Loading
Loading
Loading
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment