Opened 2 months ago

Closed 2 months ago

#23612 closed enhancement (fixed)

HTTP-Date-6.08

Reported by: Joe Locash Owned by: SecurityAdvisory
Priority: elevated Milestone: 98-Security
Component: BOOK Version: git
Severity: medium Keywords:
Cc:

Description

New point release. Fixes CVE-2026-14741.

Change History (2)

comment:1 by Joe Locash, 2 months ago

Milestone: 13.1 → 98-Security
Owner: changed from Joe Locash to SecurityAdvisory
Status: assigned → new
6.08      2026-07-09 02:04:21Z

    - [SECURITY] Reject input longer than 64 characters in parse_date()
      to prevent quadratic regex backtracking (a denial of service) on
      hostile date strings. Fixes CVE-2026-14741. (Olaf Alders)

6.07      2026-06-25 15:12:09Z

    - Add test with Time::Zone (GH#25) (Michal Josef Špaček)
    - Add test with bad Time::Zone string (GH#26) (Michal Josef Špaček)
    - Add tests with negative time (GH#26) (Michal Josef Špaček)
    - Replace all instances of \d with [0-9] in regular expressions to
      reject non-ASCII Unicode digits, with a regression test (GH#27)
      (Robert Rothenberg)
    - Reject malformed ISO 8601 timezones with a doubled colon (GH#31)
      (Olaf Alders)
    - Document day/month/year ordering for numeric dates (GH#32) (Olaf
      Alders)

Fixed at c18cf7423e. Leaving open for SA.

comment:2 by Bruce Dubbs, 2 months ago

Resolution: → fixed
Status: new → closed

Advisory sa-13.0-154 has been issued.

Note: See TracTickets for help on using tickets.