trafficserver (8.0.2+ds-1+deb10u7) buster-security; urgency=medium
authorAbhijith PA <abhijith@debian.org>
Sat, 29 Oct 2022 12:33:47 +0000 (13:33 +0100)
committerAbhijith PA <abhijith@debian.org>
Sat, 29 Oct 2022 12:33:47 +0000 (13:33 +0100)
commit09439e84eb91208c33c542fc7c23535cb271ef46
treede0c5fcc648a09605379581e8eb6b662f8a33b39
parentd855e0677355c6ab9962d702ed8d03c2cef9d5a9
parent72fca7405f158fc5a95738903998944397530dc8
trafficserver (8.0.2+ds-1+deb10u7) buster-security; urgency=medium

  * Non-maintainer upload by the Debian LTS Team.
  * Multiple CVE fixes
    + CVE-2021-37150: Protocol vs scheme mismatch
    + CVE-2022-25763 Improper input validation on HTTP/2 headers
    + CVE-2022-28129  Insufficient Validation of HTTP/1.x Headers
    + CVE-2022-31780 HTTP/2 framing vulnerabilities

[dgit import unpatched trafficserver 8.0.2+ds-1+deb10u7]
61 files changed:
debian/CONFIGURATION.Debian
debian/NEWS
debian/README.Debian
debian/README.conf-remap.Debian
debian/change_config.pl
debian/changelog
debian/compat
debian/control
debian/copyright
debian/docs
debian/gbp.conf
debian/gitlab-ci.yml
debian/not-installed
debian/patches/0001-Use-mcx16-on-x86-platforms-only.patch
debian/patches/0003-reproductible-build.patch
debian/patches/0006-fix-doc-build.patch
debian/patches/0008-fix-python-check-unused-dependencies.patch
debian/patches/0009-fix-mysql-8-build.patch
debian/patches/0011-fix-segfault.patch
debian/patches/0012-fix-spelling-checks.patch
debian/patches/0013-fix-perl-interpreter-path.patch
debian/patches/0014-use_system_yaml-cpp.patch
debian/patches/0015-8.0.4-CVE-backport.patch
debian/patches/0015-8.0.5-CVE-backport.patch
debian/patches/0016-CVE-2019-17559.patch
debian/patches/0016-CVE-2019-17565.patch
debian/patches/0016-CVE-2020-1944.patch
debian/patches/0016-CVE-2020-9481.patch
debian/patches/0017-CVE-2020-9494.patch
debian/patches/0018-CVE-2020-17508.patch
debian/patches/0018-CVE-2020-17509.patch
debian/patches/0019-CVE-2021-35474_32567_32566_32565_27577.patch
debian/patches/0020-CVE-2021-37147.patch
debian/patches/0020-CVE-2021-37148.patch
debian/patches/0020-CVE-2021-37149.patch
debian/patches/0020-CVE-2021-38161.patch
debian/patches/0021-CVE_2021_44040.patch
debian/patches/0021-CVE_2021_44759.patch
debian/patches/CVE-2021-37150.patch
debian/patches/CVE-2022-25763.patch
debian/patches/series
debian/rules
debian/source/format
debian/source/options
debian/trafficserver-dev.examples
debian/trafficserver-dev.install
debian/trafficserver-dev.manpages
debian/trafficserver-experimental-plugins.install
debian/trafficserver-experimental-plugins.lintian-overrides
debian/trafficserver.default
debian/trafficserver.dirs
debian/trafficserver.example
debian/trafficserver.init
debian/trafficserver.install
debian/trafficserver.maintscript
debian/trafficserver.manpages
debian/trafficserver.postinst
debian/trafficserver.service
debian/trafficserver.tmpfile
debian/upstream/signing-key.asc
debian/watch