Skip to content
This repository has been archived by the owner on Jun 30, 2021. It is now read-only.

Version 1.2.14 (SECURITY RELATED)

Compare
Choose a tag to compare
@NathanFrench NathanFrench released this 20 Nov 20:59
· 155 commits to develop since this release

SECURITY UPDATE

Oniguruma (the regex library used by libevhtp) was packaged with the source; this was dumb. There were several CVE's recently published that made libevhtp insecure when regex was enabled.

NOTE TO USERS

Libevhtp will no longer ship Oniguruma with the source. Instead, the build process will attempt and find a system-installed version. There is a big red warning if it is not found.

A big thanks must go to @flokli (GitHub) for pointing this out!