varnish and pcre2
Geoff Simmons
geoff at uplex.de
Wed Nov 23 15:15:08 CET 2016
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256
On 11/23/2016 09:47 AM, David CARLIER wrote:
>
> ... some people start to install pcre2 over pcre due to pcre's
> security flaws
Is there something to be worried about? I'm looking at the CVEs for
pcre, and it looks to me like there's nothing that can't be fixed by
updating the libraries. The most recent one (March of this year)
applies to both pcre and pcre2.
On 11/23/2016 10:44 AM, Poul-Henning Kamp wrote:
>
> If we find that practically everybody "import pcre2" in their VCL,
> we will probably drag that VMOD into the main project, otherwise it
> will live independently.
Philip Hazel's plan is to continue maintaining the original pcre lib
only for bug fixes, and all new features will go into pcre2. At some
point in the mid to long term, old pcre might become just too old. I
suspect that will be when everyone will be importing a VMOD for regexen.
Best,
Geoff
- --
** * * UPLEX - Nils Goroll Systemoptimierung
Scheffelstraße 32
22301 Hamburg
Tel +49 40 2880 5731
Mob +49 176 636 90917
Fax +49 40 42949753
http://uplex.de
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2
iQIcBAEBCAAGBQJYNaRsAAoJEOUwvh9pJNURbHYP/iKBWkJqryFdSHZxxQRxim6U
LGtiJbC4JIu9il68sMNn/I+Pqa/7xp1ChWe3GpZLlcBaM9/aOamJrR8WvRaRPHhv
dGIILXBotzMPnUJyk3mEott2O6W+4sXbknNJJITizo5gEvNgHU4T7c11GxHL+dp/
o0Fav0eh9pL+5FzLSdBuBx4vQefxfjB8XR1XCVBSplZzbQsfs7xbeN9qWvQYzEw1
qyWlzHBRKz2Ao9e2PUfZU5wfDp56KFQV5kXRGU1cm+HER+Q+0/gU5/w0ze8TaIcx
v6QqK5Xxawd0Ju/pf5ve/ujsHHqGdeD5R5ZrG371gE9MsOvtzxaNurZFK9speRd/
v71lSEk+EOvSy76JJM+ggIL3GZIHKlnWRs2FTIu0dtpIyUwvQX8b0VaZzr/q4QGc
0vmRmW53FYApyj37naYJMZVspBikVJaltbiXR9e8gVWikWVsluAgKMx1CLNLzWhg
1LYrGvxwOpOdqg/efkPfP+RwqhEnG5pl7Wbug9fHYmJiwsVhICE1jBaBmiS6GyNF
yw+x2Ynh79oxyShBMMmWxkh/hKbAUMVqgY7oTpqUG8v00ynhqR4bZDs6r4l6SULs
2GPFrcknkZiYwO16YlXsNVDC9BxO4OpmB26lyc00C8DhW0HuYmkRKw3hkBJTEiDf
dwcejzdIdWbKso8vd9Ue
=jY5K
-----END PGP SIGNATURE-----
More information about the varnish-dev
mailing list