www/angie: Update 1.3.2 → 1.8.1
Security fixes:
- Processing a specially crafted MP4 file with the ngx_http_mp4_module could cause a worker process crash (CVE-2024-7347); the fix was ported from nginx 1.27.1.
- When using HTTP/3, processing of a specially crafted QUIC session could cause a worker process crash, worker process memory disclosure on systems with MTU larger than 4096 bytes, or have other impact (CVE-2024-32760, CVE-2024-31079, CVE-2024-35200, CVE-2024-34161); the fix has been ported from nginx 1.26.1.
- When using HTTP/3, a segmentation error may have occured in a worker process while processing a specially crafted QUIC session (CVE-2024-24989); note that Angie as of 1.4.0 is already not vulnerable to CVE-2024-24990.
Changelogs:
https://github.com/webserver-llc/angie/releases/tag/Angie-1.4.0
https://github.com/webserver-llc/angie/releases/tag/Angie-1.4.1
https://github.com/webserver-llc/angie/releases/tag/Angie-1.5.0
https://github.com/webserver-llc/angie/releases/tag/Angie-1.5.1
https://github.com/webserver-llc/angie/releases/tag/Angie-1.5.2
https://github.com/webserver-llc/angie/releases/tag/Angie-1.6.0
https://github.com/webserver-llc/angie/releases/tag/Angie-1.6.1
https://github.com/webserver-llc/angie/releases/tag/Angie-1.6.2
https://github.com/webserver-llc/angie/releases/tag/Angie-1.7.0
https://github.com/webserver-llc/angie/releases/tag/Angie-1.8.0
https://github.com/webserver-llc/angie/releases/tag/Angie-1.8.1
PR: 282394
Approved by: oleg@mamontov.net (maintainer, timeout 3 mounts)
(cherry picked from commit 8b183145b96b912496c831e8216db7abaee0b00b)