HomeFreeBSD

www/mod_security: Update to 2.9.6

Description

www/mod_security: Update to 2.9.6

ChangeLog: https://github.com/SpiderLabs/ModSecurity/releases/tag/v2.9.6

New features and security impacting issues

Adjust parser activation rules in modsecurity.conf-recommended
Multipart parsing fixes and new MULTIPART_PART_HEADERS collection

Bug fixes

  • Limit rsub null termination to where necessary
  • IIS: Update dependencies for next planned release
  • XML parser cleanup: NULL duplicate pointer
  • Properly cleanup XML parser contexts upon completion
  • Fix memory leak in streams
  • Fix: negative usec on log line when data type long is 32b
  • mlogc log-line parsing fails due to enhanced timestamp
  • Allow no-key, single-value JSON body
  • Set SecStatusEngine Off in modsecurity.conf-recommended
  • Fix memory leak that occurs on JSON parsing error
  • Multipart names/filenames may include single quote if double-quote enclosed
  • Add SecRequestBodyJsonDepthLimit to modsecurity.conf-recommended

PR: 266318
Reported by: pascal.christen@hostpoint.ch
Reviewed by: tuc03516@gmail.com
Approved by: joneum@ (maintainer, timeout > 1 month)

Details

Provenance
pascal.christen_hostpoint.chAuthored on Oct 19 2022, 5:43 AM
fernapeCommitted on Oct 19 2022, 4:11 PM
Parents
R11:aca3e8cd7595: textproc/CLDR: upgrade to 42
Branches
Unknown
Tags
Unknown