trafficserver (8.1.7-0+deb10u3) buster-security; urgency=medium
authorAdrian Bunk <bunk@debian.org>
Sun, 5 Nov 2023 19:52:00 +0000 (21:52 +0200)
committerAdrian Bunk <bunk@debian.org>
Sun, 5 Nov 2023 19:52:00 +0000 (21:52 +0200)
commitdeb32a12ecc014b6c48f0a4d2298a2bd322963f3
treeee854ba46a1fd303b538b140b3158a25c2e9190b
parentbec1eb02a3b691b363ff762287291b4cad9615e5
parent6da607a264aab75d857caa8c1a0acf1abcc26a26
trafficserver (8.1.7-0+deb10u3) buster-security; urgency=medium

  * Non-maintainer upload by the LTS Security Team.
  * CVE-2023-41752: s3_auth plugin exposes AWSAccessKeyId
  * CVE-2023-44487: HTTP/2 Rapid Reset denial of service

[dgit import unpatched trafficserver 8.1.7-0+deb10u3]
47 files changed:
debian/CONFIGURATION.Debian
debian/NEWS
debian/README.Debian
debian/README.conf-remap.Debian
debian/change_config.pl
debian/changelog
debian/control
debian/copyright
debian/docs
debian/gbp.conf
debian/not-installed
debian/patches/0001-Correctly-handle-encoding-for-cache-hash-generation-.patch
debian/patches/0001-Use-mcx16-on-x86-platforms-only.patch
debian/patches/0001-s3_auth-Fix-hash-calculation-10567.patch
debian/patches/0002-8.1.x-Fix-a-crash-triggered-by-invalid-range-header-.patch
debian/patches/0002-Add-an-HTTP-2-related-rate-limiting-10565.patch
debian/patches/0003-Remove-duplicate-slashes-at-the-beginning-of-the-inc.patch
debian/patches/0003-reproductible-build.patch
debian/patches/0006-fix-doc-build.patch
debian/patches/0008-fix-python-check-unused-dependencies.patch
debian/patches/0009-fix-mysql-8-build.patch
debian/patches/0011-fix-segfault.patch
debian/patches/0012-fix-spelling-checks.patch
debian/patches/0013-fix-perl-interpreter-path.patch
debian/patches/0014-use_system_yaml-cpp.patch
debian/patches/0016-fix_python_3.8.patch
debian/patches/series
debian/rules
debian/salsa-ci.yml
debian/source/format
debian/source/options
debian/trafficserver-dev.examples
debian/trafficserver-dev.install
debian/trafficserver-dev.manpages
debian/trafficserver-experimental-plugins.install
debian/trafficserver.default
debian/trafficserver.dirs
debian/trafficserver.example
debian/trafficserver.init
debian/trafficserver.install
debian/trafficserver.maintscript
debian/trafficserver.manpages
debian/trafficserver.postinst
debian/trafficserver.service
debian/trafficserver.tmpfile
debian/upstream/signing-key.asc
debian/watch