jacquesg/p5-Git-Raw

There are various CVEs for embedded libraries

robrwo opened this issue · 5 comments

The version of zlib seems to be affected by CVE-2018-25032

The version of http-parser seems to be affected by CVE-2019-9900

These are bundled by libgit2. When they are addressed upstream, I can attempt an upgrade.

I have emailed security@libgit2.com about that issue.

I've gotten a confirmation from Ed Thomson re libgit2 security issues. He expects to publish fixes next week.

Great, thanks for the update. I'll push a fix as soon as I can.

Version 0.89 is now available, which should address these.