trafficserver (8.1.1+ds-1.1) unstable; urgency=medium
authorSalvatore Bonaccorso <carnil@debian.org>
Thu, 15 Jul 2021 19:48:17 +0000 (20:48 +0100)
committerSalvatore Bonaccorso <carnil@debian.org>
Thu, 15 Jul 2021 19:48:17 +0000 (20:48 +0100)
commit0019a903334672acfc132ce3d616b24189d8ed9f
tree76728fb4bd16dd8a9116fdc2db8baa5e7da4625b
parent0f3e933c655db9dc24ded1b505626f9ca9def5a4
parentf251e26998a1dd4e5d627d28b57ad9c28f89eb31
trafficserver (8.1.1+ds-1.1) unstable; urgency=medium

  * Non-maintainer upload.
  * Address CVE-2021-27577, CVE-2021-32565, CVE-2021-32566, CVE-2021-32567 and
    CVE-2021-35474.
    - CVE-2021-27577: Incorrect handling of url fragment leads to cache
      poisoning
    - CVE-2021-32565: HTTP Request Smuggling, content length with invalid
      charters
    - CVE-2021-32566: Specific sequence of HTTP/2 frames can cause ATS to
      crash
    - CVE-2021-32567: Reading HTTP/2 frames too many times
    - CVE-2021-35474: Dynamic stack buffer overflow in cachekey plugin
    (Closes: #990303)

[dgit import unpatched trafficserver 8.1.1+ds-1.1]
45 files changed:
debian/CONFIGURATION.Debian
debian/NEWS
debian/README.Debian
debian/README.conf-remap.Debian
debian/change_config.pl
debian/changelog
debian/control
debian/copyright
debian/docs
debian/gbp.conf
debian/not-installed
debian/patches/0001-Use-mcx16-on-x86-platforms-only.patch
debian/patches/0003-reproductible-build.patch
debian/patches/0006-fix-doc-build.patch
debian/patches/0008-fix-python-check-unused-dependencies.patch
debian/patches/0009-fix-mysql-8-build.patch
debian/patches/0011-fix-segfault.patch
debian/patches/0012-fix-spelling-checks.patch
debian/patches/0013-fix-perl-interpreter-path.patch
debian/patches/0014-use_system_yaml-cpp.patch
debian/patches/0015-as-needed-fix.patch
debian/patches/0016-fix_python_3.8.patch
debian/patches/0017-fix_sphinx_3.0.patch
debian/patches/0018-Fixes-7971.patch
debian/patches/series
debian/rules
debian/salsa-ci.yml
debian/source/format
debian/source/options
debian/trafficserver-dev.examples
debian/trafficserver-dev.install
debian/trafficserver-dev.manpages
debian/trafficserver-experimental-plugins.install
debian/trafficserver.default
debian/trafficserver.dirs
debian/trafficserver.example
debian/trafficserver.init
debian/trafficserver.install
debian/trafficserver.maintscript
debian/trafficserver.manpages
debian/trafficserver.postinst
debian/trafficserver.service
debian/trafficserver.tmpfile
debian/upstream/signing-key.asc
debian/watch