trafficserver (8.1.6+ds-1~deb10u1) buster-security; urgency=high
authorMarkus Koschany <apo@debian.org>
Wed, 5 Apr 2023 20:24:05 +0000 (21:24 +0100)
committerMarkus Koschany <apo@debian.org>
Wed, 5 Apr 2023 20:24:05 +0000 (21:24 +0100)
commit94811e31e1646578ef6a4234d8b084a4bb750691
treee36de7976cbb0ed410b1bc4b546c75555d049de5
parent953fa71433f6518e129e67dbbb820d29fcb52bc4
parenta2304df31878d26fa86882f2869762d8eb05172c
trafficserver (8.1.6+ds-1~deb10u1) buster-security; urgency=high

  * Non-maintainer upload by the LTS team.
  * Backport upstream version 8.1.6 to Buster.
  * Fix CVE-2022-31778, CVE-2022-31779, CVE-2022-32749, CVE-2022-37392.
    Several vulnerabilities were discovered in Apache Traffic Server, a reverse
    and forward proxy server, which could result in HTTP request smuggling,
    cache poisoning or information disclosure.

[dgit import unpatched trafficserver 8.1.6+ds-1~deb10u1]
42 files changed:
debian/CONFIGURATION.Debian
debian/NEWS
debian/README.Debian
debian/README.conf-remap.Debian
debian/change_config.pl
debian/changelog
debian/control
debian/copyright
debian/docs
debian/gbp.conf
debian/not-installed
debian/patches/0001-Use-mcx16-on-x86-platforms-only.patch
debian/patches/0003-reproductible-build.patch
debian/patches/0006-fix-doc-build.patch
debian/patches/0008-fix-python-check-unused-dependencies.patch
debian/patches/0009-fix-mysql-8-build.patch
debian/patches/0011-fix-segfault.patch
debian/patches/0012-fix-spelling-checks.patch
debian/patches/0013-fix-perl-interpreter-path.patch
debian/patches/0014-use_system_yaml-cpp.patch
debian/patches/0016-fix_python_3.8.patch
debian/patches/series
debian/rules
debian/salsa-ci.yml
debian/source/format
debian/source/options
debian/trafficserver-dev.examples
debian/trafficserver-dev.install
debian/trafficserver-dev.manpages
debian/trafficserver-experimental-plugins.install
debian/trafficserver.default
debian/trafficserver.dirs
debian/trafficserver.example
debian/trafficserver.init
debian/trafficserver.install
debian/trafficserver.maintscript
debian/trafficserver.manpages
debian/trafficserver.postinst
debian/trafficserver.service
debian/trafficserver.tmpfile
debian/upstream/signing-key.asc
debian/watch