puma (5.6.5-3+deb12u1) bookworm; urgency=medium
authorAbhijith PA <abhijith@debian.org>
Wed, 29 Jan 2025 01:56:33 +0000 (07:26 +0530)
committerAbhijith PA <abhijith@debian.org>
Wed, 29 Jan 2025 01:56:33 +0000 (07:26 +0530)
commit4b77c3e0a2cb68e04cb2a3fa71802f4494c0c17c
treec3fe11b471c65e52df6ffc96fad64511acbb9662
parent0532c5aa35586c0cb4215a28ef23a0616b4c8e3d
parentbbae1b28e6f6f265c6f89dda34c24ae2e192d064
puma (5.6.5-3+deb12u1) bookworm; urgency=medium

  * Team upload
  * d/patches/
   + CVE-2023-40175.patch: Fix CVE-2023-40175, incorrect behavior when
     parsing chunked transfer encoding bodies and zero-length
     Content-Length headers in a way that allowed HTTP request
     smuggling. (Closes: #1050079)

   + CVE-2024-21647.patch: Fix CVE-2024-21647 by limiting the size of
     chunk extensions. (Closes: #1060345)

   + CVE-2024-45614.patch: Fix CVE-2024-45614, clients could clobber
     values set by intermediate proxies (such as X-Forwarded-For) by
     providing a underscore version of the same header.
     (Closes: #1082379)

[dgit import unpatched puma 5.6.5-3+deb12u1]
29 files changed:
debian/README.source
debian/changelog
debian/clean
debian/control
debian/copyright
debian/gbp.conf
debian/patches/0004-puma.gemspec-drop-git-usage.patch
debian/patches/0011-disable-minitest-extensions.patch
debian/patches/0012-disable-cli-ssl-tests.patch
debian/patches/0013-fix-test-term-not-accepts-new-connections.patch
debian/patches/0014-disable-test-failing-on-amd64.patch
debian/patches/CVE-2023-40175.patch
debian/patches/CVE-2024-21647.patch
debian/patches/CVE-2024-45614.patch
debian/patches/series
debian/puma.1
debian/puma.docs
debian/puma.examples
debian/puma.lintian-overrides
debian/puma.manpages
debian/pumactl.1
debian/ruby-tests.rake
debian/rules
debian/salsa-ci.yml
debian/source/format
debian/source/lintian-overrides
debian/tests/control
debian/upstream/metadata
debian/watch