CVE-2024-32663-2
authorPierre Chifflier <pollux@debian.org>
Sun, 30 Mar 2025 10:03:02 +0000 (12:03 +0200)
committerThorsten Alteholz <debian@alteholz.de>
Sun, 30 Mar 2025 10:03:02 +0000 (12:03 +0200)
commitd33531aff7ec4c52ed4d2f667b15e7b729f24c7c
tree9d6b024491d5837220050f87d76fa1b60ff38f33
parent6fbc7721ca4ef80bc864df6543f80bda912cf33a
CVE-2024-32663-2

commit d24b37a103c04bb2667e449e080ba4c8e56bb019
Author: Philippe Antoine <pantoine@oisf.net>
Date:   Thu Mar 28 11:15:51 2024 +0100

    http2: do not log duplicate headers

    Ticket: 6900

    And thus avoid DOS by logging a request using a compressed
    header block repeated many times and having a long value...

    (cherry picked from commit 03442c9071b8d863d26b609d54c6eacf4de9e340)

Gbp-Pq: Name CVE-2024-32663-2.patch
rust/src/http2/logger.rs