From 2fcf0d21bf360af68dd87e5d8ed270ea1e72554c Mon Sep 17 00:00:00 2001 From: ghidra1 Date: Fri, 10 Dec 2021 13:03:38 -0500 Subject: [PATCH] GP-0 Updated WhatsNew and ChangeHistory for 10.1 release --- .../src/global/docs/ChangeHistory.html | 1 + .../src/global/docs/WhatsNew.html | 35 +++++++++++++++++++ 2 files changed, 36 insertions(+) diff --git a/Ghidra/Configurations/Public_Release/src/global/docs/ChangeHistory.html b/Ghidra/Configurations/Public_Release/src/global/docs/ChangeHistory.html index dec1372be0..9000873455 100644 --- a/Ghidra/Configurations/Public_Release/src/global/docs/ChangeHistory.html +++ b/Ghidra/Configurations/Public_Release/src/global/docs/ChangeHistory.html @@ -32,6 +32,7 @@
  • API. Updated API methods of the DataTypeChooserDialog. (GP-1349, Issue #3140)
  • Basic Infrastructure. Symbol performance in Ghidra was significantly improved. Specifically, new database indexes were created to improve finding primary symbols as well as improving lookups by combinations of name, namespace, and address. (GP-1082)
  • Basic Infrastructure. Added optional columns in the Functions table for several boolean-valued function attributes. (GP-1393)
  • +
  • Basic Infrastructure. Upgraded log4j dependency from 2.12.1 to 2.15.0 to resolve a security vulnerability. (GP-1588)
  • Build. Extension builds can now declare jar dependencies from standard Gradle repositories such as Maven Central. (GP-1144, Issue #2219, #2226)
  • Build. Increased minimum supported Gradle version from 6.0 to 6.4. (GP-1521, Issue #3650)
  • Data Types. Added support for zero-element arrays and zero-length components within structures and unions. Eliminated flex-array API methods and added/improved other Structure methods to handle multiple components which share the same offset. (GP-943)
  • diff --git a/Ghidra/Configurations/Public_Release/src/global/docs/WhatsNew.html b/Ghidra/Configurations/Public_Release/src/global/docs/WhatsNew.html index 68d81b1bfe..c9c3d715dc 100644 --- a/Ghidra/Configurations/Public_Release/src/global/docs/WhatsNew.html +++ b/Ghidra/Configurations/Public_Release/src/global/docs/WhatsNew.html @@ -46,6 +46,41 @@

    The not-so-fine print: Please Read!

    +

    WARNING: There has been a published CVE security vulnerability noted in Ghidra dependencies within two log4j jar files. + We strongly encourage anyone using previous versions of Ghidra or a build from source, to remediate this issue by either upgrading + to the latest Ghidra 10.1 version, or patching your current version.

    + +

    + To patch your current Ghidra installation, delete: +

    +

    + +

    + and replace with the newer log4j 2.15.0 version: +

    +

    + +

    + You can find these in the latest Ghidra 10.1 release, or from: +

    +

    + +

    + The details of the vulnerability can be found here: +

    +

    +

    Ghidra 10.1 is fully backward compatible with project data from previous releases. However, programs and data type archives which are created or modified in 10.1 will not be useable by an earlier Ghidra version.