[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

[SECURITY] [DLA 3224-1] http-parser security update



-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

- -----------------------------------------------------------------------
Debian LTS Advisory DLA-3224-1              debian-lts@lists.debian.org
https://www.debian.org/lts/security/                      Utkarsh Gupta
December 05, 2022                           https://wiki.debian.org/LTS
- -----------------------------------------------------------------------

Package        : http-parser
Version        : 2.8.1-1+deb10u3
CVE ID         : CVE-2020-8287
Debian Bug     : 1016690

There was a potential HTTP request smuggling vulnerability in
http-parser, a popular library for parsing HTTP messages.

For Debian 10 buster, this problem has been fixed in version
2.8.1-1+deb10u3.

We recommend that you upgrade your http-parser packages.

For the detailed security status of http-parser please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/http-parser

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCAAdFiEEbJ0QSEqa5Mw4X3xxgj6WdgbDS5YFAmON6+MACgkQgj6WdgbD
S5b3RRAAoDlzVOmJDpcKAEjLwPws0tOSMVP92/RaOxmOJ59fES82SIKLGdZzScX2
zZ/g3Si8fgi699d0ybRuc8ng264wV7G8Wm1FCci77C1YVvZW5Ih5l1A3zONTrR7q
d+gMJMISBHC0r+HwSUCQ3Q3wVu7AZCGZNjGe2ImcdXnrbUlaouwbf75JAfpcjPQj
1UIveysxW2NxdCsT0aD71+NZNLtx+qIykuTHK30GHbqbLGjdzkDfhBe+oYTqcUSU
8MHo7sJsx4JKPwlGEt+Av40nsW3ukyiU9sIdxjgeywgl/8c+DTUwn3gSm8Igc8TU
ea02L4IAULmQf2Tl5Ks0ri2XRxHWHgY3ZmU7ZaLJRI62WD/k55qga2cmZGz9Saxc
jcqSGvpDF93bEILX3xCoqNpEmknDOvFcDECQpFbzCoGa8Gg89MA34DRKA47caDzC
CNRNx8qbim/EqMFk7TiqxD1NEZWyGz7dgrMOam0HO+FK1wSKKeOjC29dKhsSPmmV
k4g5tqe6CBdASjvnC9QIxhhJFd93O6TvO445l2VNznKgRyWhVo+NGE6HW+BrJ2Q5
d5Eun2o9dh4a/FkI6PYUglBMSWV7bYwD9W5FrHyoxiZKrPkJmTsuhJylUUjfvfRu
O6y92AZH9fpqGI4TdvlJX3atm5UHpIXLf5327KGRJtcKLkyU9KA=
=/UST
-----END PGP SIGNATURE-----


Reply to: