Skip to content
This repository has been archived by the owner on Jan 9, 2019. It is now read-only.

Update irregex to 0.9.6 (security update) #92

Closed
sjamaan opened this issue Dec 14, 2016 · 1 comment
Closed

Update irregex to 0.9.6 (security update) #92

sjamaan opened this issue Dec 14, 2016 · 1 comment

Comments

@sjamaan
Copy link

sjamaan commented Dec 14, 2016

Hi,

A resource exhaustion vulnerability was found in the way irregex compiles nested + patterns. Please see this announcement/CVE request (CVE assignment is currently pending).

Updating Irregex to 0.9.6 should fix this issue. See this changeset for more information on the fix.

Regards,
Peter Bex

@marcomaggi
Copy link
Owner

I have updated in the master branch. Thanks.

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants