Page MenuHomeFreeBSD

devel/apr1: Update to 1.7.5
ClosedPublic

Authored by ngie on Sep 2 2023, 5:21 PM.
Tags
None
Referenced Files
Unknown Object (File)
Thu, Nov 21, 6:45 AM
Unknown Object (File)
Thu, Nov 14, 8:01 PM
Unknown Object (File)
Oct 3 2024, 9:19 PM
Unknown Object (File)
Oct 1 2024, 12:29 PM
Unknown Object (File)
Sep 18 2024, 10:20 AM
Unknown Object (File)
Sep 14 2024, 12:15 PM
Unknown Object (File)
Sep 8 2024, 7:47 AM
Unknown Object (File)
Sep 5 2024, 7:30 PM
Subscribers

Details

Summary

This change updates the libapr component to 1.7.5 which addresses some
minor functional issues and security issues.

See the APR 1.7 changelog for more details.

PR: 274053

Diff Detail

Lint
Lint Skipped
Unit
Tests Skipped
Build Status
Buildable 59704
Build 56590: arc lint + arc unit

Event Timeline

joneum requested review of this revision.Sep 2 2023, 5:21 PM

Please check D40366 as well re. removal of/support for BDB 1.85, license issues

devel/apr1/Makefile
48

IIRC BDB 5 is required for users that don't want to change licenses. Can we check on prior tickets?

We're now 2 subminor versions behind and this component is impacted by at least one CVE: CVE-2023-49582 (resolved in 1.7.5). Could this update please be done (along with considering my other patch in D40366)?

Update the diff to the latest version: 1.7.5

ngie retitled this revision from devel/apr1: Update to 1.7.4 to devel/apr1: Update to 1.7.5.Oct 5 2024, 3:48 AM
ngie edited the summary of this revision. (Show Details)
ngie edited the summary of this revision. (Show Details)
ngie edited the summary of this revision. (Show Details)
ngie added a reviewer: joneum.
kevans added a subscriber: kevans.

LGTM, but please give apache@ just another few days to speak up. I suspect no objection given known security issues and having dropped the potentially problematic BDB5 removal.

This revision is now accepted and ready to land.Oct 5 2024, 4:10 AM

Thanks for the heads-up! Done.