trafficserver (8.1.11+ds-0+deb11u1) bullseye-security; urgency=medium
authorAdrian Bunk <bunk@debian.org>
Thu, 26 Sep 2024 13:41:35 +0000 (16:41 +0300)
committerAdrian Bunk <bunk@debian.org>
Thu, 26 Sep 2024 13:41:35 +0000 (16:41 +0300)
commit9d00d5fb6f938a40ec3cabd7ee67a6f9159a55af
tree8fa30a527aefc3880dd4643b33e1f89e54cfbff3
parente4e48ee741ed69cc3df0d137623ac0ccdc495494
parente8cab91a8977e2dee74e91d0eace22eaffa1c41f
trafficserver (8.1.11+ds-0+deb11u1) bullseye-security; urgency=medium

  * New upstream release.
    - CVE-2023-38522: Incomplete field name check allows request smuggling
    - CVE-2024-35161: Incomplete check for chunked trailer section allows
      request smuggling
    - CVE-2024-35296: Invalid Accept-Encoding can force forwarding requests

[dgit import unpatched trafficserver 8.1.11+ds-0+deb11u1]
41 files changed:
debian/CONFIGURATION.Debian
debian/NEWS
debian/README.Debian
debian/README.conf-remap.Debian
debian/change_config.pl
debian/changelog
debian/control
debian/copyright
debian/docs
debian/gbp.conf
debian/not-installed
debian/patches/0003-reproductible-build.patch
debian/patches/0006-fix-doc-build.patch
debian/patches/0008-fix-python-check-unused-dependencies.patch
debian/patches/0009-fix-mysql-8-build.patch
debian/patches/0011-fix-segfault.patch
debian/patches/0012-fix-spelling-checks.patch
debian/patches/0013-fix-perl-interpreter-path.patch
debian/patches/0014-use_system_yaml-cpp.patch
debian/patches/0016-fix_python_3.8.patch
debian/patches/series
debian/rules
debian/salsa-ci.yml
debian/source/format
debian/source/options
debian/trafficserver-dev.examples
debian/trafficserver-dev.install
debian/trafficserver-dev.manpages
debian/trafficserver-experimental-plugins.install
debian/trafficserver.default
debian/trafficserver.dirs
debian/trafficserver.example
debian/trafficserver.init
debian/trafficserver.install
debian/trafficserver.maintscript
debian/trafficserver.manpages
debian/trafficserver.postinst
debian/trafficserver.service
debian/trafficserver.tmpfile
debian/upstream/signing-key.asc
debian/watch