Selaa lähdekoodia

Updated ChangeLog and NEWS for v0.9.76

Evgeny Grin (Karlson2k) 3 vuotta sitten
vanhempi
sitoutus
32311bfe06
2 muutettua tiedostoa jossa 15 lisäystä ja 1 poistoa
  1. 1 1
      ChangeLog
  2. 14 0
      NEWS

+ 1 - 1
ChangeLog

@@ -1,6 +1,6 @@
 Sun Feb 26 05:49:30 PM CET 2023
     Fix potential DoS vector in MHD_PostProcessor discovered
-    by Gynvael Coldwind and Dejan Alvadzijevic. -CG
+    by Gynvael Coldwind and Dejan Alvadzijevic (CVE-2023-27371). -CG
     Releasing GNU libmicrohttpd 0.9.76 hotfix. -CG
 
 Sun 26 Dec 2021 20:30:00 MSK

+ 14 - 0
NEWS

@@ -1,3 +1,17 @@
+Sun 26 Feb 2023 17:49:30 CET
+Released GNU libmicrohttpd 0.9.76 hotfix. -CG
+
+    This is a hotfix release.
+    This only change since previous release is fixed potential DoS vector
+    in MHD_PostProcessor discovered by Gynvael Coldwind and Dejan
+    Alvadzijevic (CVE-2023-27371).
+    While the researchers have not been able to exploit this attack vector
+    when libmicrohttpd is compiled with the standard GNU C library, it is
+    recommended that you update MHD as soon as possible if your
+    applications are using (optional) MHD_PostProcessor functionality.
+
+    -- Evgeny Grin (Karlson2k)
+
 Sun 26 Dec 2021 20:30:00 MSK
 Released GNU libmicrohttpd 0.9.75 -EG