trafficserver (8.1.5+ds-1~deb11u1) bullseye-security; urgency=high
authorJean Baptiste Favre <debian@jbfavre.org>
Fri, 12 Aug 2022 07:16:08 +0000 (08:16 +0100)
committerJean Baptiste Favre <debian@jbfavre.org>
Fri, 12 Aug 2022 07:16:08 +0000 (08:16 +0100)
commit95c7fcacae1daac1bfddc575189e68780787a03c
treec4c99e4032d59a20c030cd36cdaad1c0ee0a35a4
parent492e6f6518ba72007d570723384f9a772cdad912
parent47cec32f6e6b20c5f749e1c0bb1e65f2f52d9807
trafficserver (8.1.5+ds-1~deb11u1) bullseye-security; urgency=high

  * Update d/watch to stick to 8.1.X serie
  * Update upstream gpg keys
  * UPdate d/salsa-ci.yaml
  * New upstream version 8.1.5+ds
  * Patches refresh for 8.1.5
  * Update experimental plugins list
  * Multiple CVE fixes for 8.1.x
    + CVE-2021-37150: Protocol vs scheme mismatch
    + CVE-2022-25763: Improper input validation on HTTP/2 headers
    + CVE-2022-28129: Insufficient Validation of HTTP/1.x Headers
    + CVE-2022-31778: Transfer-Encoding not treated as hop-by-hop
    + CVE-2022-31779: Improper HTTP/2 scheme and method validation
    + CVE-2022-31780: HTTP/2 framing vulnerabilities

[dgit import unpatched trafficserver 8.1.5+ds-1~deb11u1]
42 files changed:
debian/CONFIGURATION.Debian
debian/NEWS
debian/README.Debian
debian/README.conf-remap.Debian
debian/change_config.pl
debian/changelog
debian/control
debian/copyright
debian/docs
debian/gbp.conf
debian/not-installed
debian/patches/0001-Use-mcx16-on-x86-platforms-only.patch
debian/patches/0003-reproductible-build.patch
debian/patches/0006-fix-doc-build.patch
debian/patches/0008-fix-python-check-unused-dependencies.patch
debian/patches/0009-fix-mysql-8-build.patch
debian/patches/0011-fix-segfault.patch
debian/patches/0012-fix-spelling-checks.patch
debian/patches/0013-fix-perl-interpreter-path.patch
debian/patches/0014-use_system_yaml-cpp.patch
debian/patches/0016-fix_python_3.8.patch
debian/patches/series
debian/rules
debian/salsa-ci.yml
debian/source/format
debian/source/options
debian/trafficserver-dev.examples
debian/trafficserver-dev.install
debian/trafficserver-dev.manpages
debian/trafficserver-experimental-plugins.install
debian/trafficserver.default
debian/trafficserver.dirs
debian/trafficserver.example
debian/trafficserver.init
debian/trafficserver.install
debian/trafficserver.maintscript
debian/trafficserver.manpages
debian/trafficserver.postinst
debian/trafficserver.service
debian/trafficserver.tmpfile
debian/upstream/signing-key.asc
debian/watch