Re: CVE-2022-22728: libapreq2: libapreq2 multipart form parse memory corruption

2023-01-02 Thread Joe Schaefer
2.17 is a dud. What’s in trunk works fine though. Joe Schaefer, Ph.D +1 (954) 253-3732 SunStar Systems, Inc. Orion - The Enterprise Jamstack Wiki From: enge...@gsuite.cloud.apache.org on behalf of Apache Security Team Sent: Monday, January 2, 2023 7:30:43 AM

Re: CVE-2022-22728: libapreq2: libapreq2 multipart form parse memory corruption

2023-01-02 Thread Apache Security Team
Hi, I noticed there was some confusion online as to whether this issue is fixed in 2.17 (https://www.openwall.com/lists/oss-security/2022/08/26/4). Unless anyone objects I'll amend the CVE text to make it explicit that users are recommended to update to 2.17 or later. Luckily with the new CVE