pkgsrc/www/logswan/distinfo
fcambus 56fb9f8dd5 logswan: update to 2.1.12.
Logswan 2.1.12 (2021-12-02)

- Fix a use-after-free (read) triggered by strcmp(3) calls.

  The parse_request() function didn't zero out the parsed_request struct
  between each call. Since the parsing loop was switched to using getline(3)
  instead of a fixed size buffer to process log lines, it could reference
  already freed memory in certain cases.

  Thanks to Brian Carpenter (@geeknik) for finding and reporting the issue.
2021-12-02 10:39:17 +00:00

5 lines
364 B
Text

$NetBSD: distinfo,v 1.24 2021/12/02 10:39:17 fcambus Exp $
BLAKE2s (logswan-2.1.12.tar.gz) = fa26443e40047210577782dbd26b614b0d37745597f31097b4844c0885132b7e
SHA512 (logswan-2.1.12.tar.gz) = 27e8feec27b5d56b426aa39142d1e42967cfffd08a61408a3a3cbd17bc95d676a19e774af4cb406a31f76eac0b7b160bb45f36b4f3c8c3537468bde85f6c9620
Size (logswan-2.1.12.tar.gz) = 23813 bytes