• [SECURITY] [DSA 4710-1] trafficserver security update

    From Moritz Muehlenhoff@1:229/2 to All on Sat Jun 27 19:40:01 2020
    From: [email protected]

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA512

    - ------------------------------------------------------------------------- Debian Security Advisory DSA-4710-1 [email protected] https://www.debian.org/security/ Moritz Muehlenhoff
    June 27, 2020 https://www.debian.org/security/faq
    - -------------------------------------------------------------------------

    Package : trafficserver
    CVE ID : CVE-2020-9494
    Debian Bug : 963629

    A vulnerability was discovered in Apache Traffic Server, a reverse and
    forward proxy server, which could result in denial of service via
    malformed HTTP/2 headers.

    For the stable distribution (buster), this problem has been fixed in
    version 8.0.2+ds-1+deb10u3.

    We recommend that you upgrade your trafficserver packages.

    For the detailed security status of trafficserver please refer to
    its security tracker page at: https://security-tracker.debian.org/tracker/trafficserver

    Further information about Debian Security Advisories, how to apply
    these updates to your system and frequently asked questions can be
    found at: https://www.debian.org/security/

    Mailing list: [email protected]
    -----BEGIN PGP SIGNATURE-----

    iQIzBAEBCgAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAl73gxMACgkQEMKTtsN8 TjZpZw//RyagU0tqhPnDoxsYBpVYe5NhupWg/Uq/Zmf6qd0sWbSrfibFRZc1o0+i 1LOHKSZzhndvERWeqJyhsPhJeyGnafwc0RqFtAPiQIbkfdMnAS+2H47ZcUk4Y9Gx x20s1o0ke4Om789XHMh1hhtQVp2Onvmpb/S8vKsmPWdBczIV+SBG5JG9mGXDe96v N45hhCNPUVN9cdBBCwtNQC9G8VLX+7RvXoqRXcdJsWROrChvd5+oozuq/atCcRxU /TA9waewnReVeiEPrGmDOY/lcBBMyW4U9DrdxJLvBnlJa7TYYKfNaQBIMNlw+CXf +B8r/Q9LscuQkUxPYww9cyCopo7qlqVattT16ZTPGSohImJqQ8yiHivU5JqeSQZ6 pxGJXqS86cjTSFhDC5rNMHduz7mARo6SSMRNoFdCwYqN4PyePhT4tm8GHPI+VM5M 127tNRLrgvl0viJiqRHrBM6AoSrHxHnrfQlywDEd7C+QVg+AQx8RG6KyaTF9RZvp lqC/0LbVyzzJuwFKcZKefg/J/TtFktpaqE18UzXyb8Y8ePeEDDH/TC3qOXYJ79wv AaNR8N2xrD7R3uAjxPcEEOyVz48/O7Gn9nWKoDGBzJWrEi7yHoFNHS/49NniTR/U uayF5S3x/x1aoPGq79Lh04+KT7mgF2rHBsBGC0sEAkkYdLzW50o=
    =o2wn
    -----END PGP SIGNATURE-----

    --- SoupGate-Win32 v1.05
    * Origin: you cannot sedate... all the things you hate (1:229/2)