HomeFreeBSD

Security update www/unit from 1.7.0 to 1.7.1.

Description

Security update www/unit from 1.7.0 to 1.7.1.

<ChangeLog>

Everybody is strongly advised to update to a new version.

*) Security: a heap memory buffer overflow might have been caused in the

router process by a specially crafted request, potentially resulting
in a segmentation fault or other unspecified behavior
(CVE-2019-7401).

*) Bugfix: install of Go module failed without prior building of Unit

daemon; the bug had appeared in 1.7.

</ChangeLog>

Details

Provenance
osaAuthored on
Parents
rP492402: Document unit vulnerability.
Branches
Unknown
Tags
Unknown