Peter Korsgaard
f6e32b6910
package/libmodsecurity: fix locally typo
...
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com >
2024-09-14 10:19:25 +02:00
Frank Vanbever
d4b065e35c
package/libmodsecurity: security bump to 3.0.12
...
The project has been transferred from Trustwave (SpiderLabs) to OWASP, hence the
change in URLs. The upstream CPE vendor ID will likely also change in the future
but the upstream is still working on this [1].
- Fixes:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-1019
[1] https://github.com/owasp-modsecurity/ModSecurity/issues/3083
Signed-off-by: Frank Vanbever <frank.vanbever@mind.be >
Signed-off-by: Yann E. MORIN <yann.morin.1998@free.fr >
2024-02-21 18:09:35 +01:00
Frank Vanbever
cec73bb5f8
package/libmodsecurity: bump to version 3.0.11
...
Signed-off-by: Frank Vanbever <frank.vanbever@mind.be >
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com >
2023-12-23 14:41:45 +01:00
Frank Vanbever
670329f057
package/libmodsecurity: security bump to version 3.0.10
...
- Fixes CVE-2023-38285 [1]
- Adapted 0001-configure.ac-drop-usage-of-git-at-configure-time.patch due to
upstream moving to autoconf portable shell constructs.
Signed-off-by: Frank Vanbever <frank.vanbever@mind.be >
[1] https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/modsecurity-v3-dos-vulnerability-in-four-transformations-cve-2023-38285/
Signed-off-by: Frank Vanbever <frank.vanbever@mind.be >
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com >
2023-08-24 20:55:47 +02:00
Frank Vanbever
a1e0e7276c
package/libmodsecurity: bump to version 3.0.9
...
- Drop 0003-Revert-Fix-maxminddb-link-on-FreeBSD.patch, handling of libmaxminddb
was fixed upstream in d2b700d
- Drop 0004-build-pcre.m4-fix-build-without-pcre.patch, handling of PCRE was
fixed upstream in 791964a
Signed-off-by: Frank Vanbever <frank.vanbever@mind.be >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2023-05-01 09:26:55 +02:00
Fabrice Fontaine
1b20c52a5b
package/libmodsecurity: bump to version 3.0.8
...
https://github.com/SpiderLabs/ModSecurity/releases/tag/v3.0.8
Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2023-01-27 13:46:23 +01:00
Fabrice Fontaine
ea746f3128
package/libmodsecurity: bump to version 3.0.7
...
Switch to pcre2 as pcre is deprecated
https://github.com/SpiderLabs/ModSecurity/releases/tag/v3.0.7
Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com >
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com >
2022-07-27 16:43:56 +02:00
Fabrice Fontaine
d317b76458
package/libmodsecurity: security bump to version 3.0.6
...
Support configurable limit on depth of JSON parsing (possible DoS issue)
https://github.com/SpiderLabs/ModSecurity/releases/tag/v3.0.6
Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2021-11-28 14:35:43 +01:00
Fabrice Fontaine
464d0be380
package/libmodsecurity: security bump to version 3.0.5
...
Security Impacting Issues
Handle URI received with uri-fragment
[@martinhsv]
- Drop patches (already in version) and so drop autoreconf
- Static linking is supported since
f76a1a667b
- Update indentation in hash file (two spaces)
https://github.com/SpiderLabs/ModSecurity/releases/tag/v3.0.5
Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com >
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com >
2021-07-15 22:42:12 +02:00
Frank Vanbever
d9205b4da5
package/libmodsecurity: new package
...
The dependency on !BR2_STATIC_LIBS is due to missing Libs.private in the
libmodconfig pkg-config file making builds that statically link against
libmodsecurity fail.
Lua is disabled due to using the host libraries.
Yajl is disabled as enabling it forces the tests to be built. These tests have a
hard dependency on libmodsecurity.a which is not built when --disable-static is
used in the configuration. There is no flag to disable these tests.
Signed-off-by: Frank Vanbever <frank.vanbever@essensium.com >
Signed-off-by: Peter Korsgaard <peter@korsgaard.com >
2020-01-30 11:26:05 +01:00