[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

[SECURITY] [DLA 3374-1] libmicrohttpd security update



-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

- -------------------------------------------------------------------------
Debian LTS Advisory DLA-3374-1                debian-lts@lists.debian.org
https://www.debian.org/lts/security/                    Thorsten Alteholz
March 30, 2023                                https://wiki.debian.org/LTS
- -------------------------------------------------------------------------

Package        : libmicrohttpd
Version        : 0.9.62-1+deb10u1
CVE ID         : CVE-2023-27371


An issue has been found in linmicrohttpd, a library embedding HTTP server functionality. Parsing crafted POST requests result in an out of bounds read, which might cause a DoS (Denial of Service).


For Debian 10 buster, this problem has been fixed in version
0.9.62-1+deb10u1.

We recommend that you upgrade your libmicrohttpd packages.

For the detailed security status of libmicrohttpd please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/libmicrohttpd

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS

-----BEGIN PGP SIGNATURE-----

iQKTBAEBCgB9FiEEYgH7/9u94Hgi6ruWlvysDTh7WEcFAmQl/PVfFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDYy
MDFGQkZGREJCREUwNzgyMkVBQkI5Njk2RkNBQzBEMzg3QjU4NDcACgkQlvysDTh7
WEdeJQ/8C1CsqBK80uJHoPthtut8HoE3iRRunEl+UUox914bfLRIHeuYOleOdXi9
11hUFMAnbgtYc4tZSs/pN/rRzjg9HjsZpDSlkTSyfRK0TsMBmbfPfW7xU9p72wJs
UY9UmQVXDX82Fuo9oeylsUiCuclJpYxRO/UwfhHM3hH4Ioukm6hQH69R/MFoAf8r
de5v2fXEaGsGBzxNCgorSd6iTFoyrc20+m7/7gM5tvQtarlaM+oRynU7QlFjvZVO
G74Avfnx2OBVbnZqhbQeHG0S9arJw+wbtDZYijXgwihDoEPnVpHQ5shVgfpSQRqA
9UTCJhOPQ/UQHyXTjeitENUNMjTqZkABnWpg/qvAhPEd2xi3BO6Ea+miJEWVrhFW
AZ+EAcua1G0OZuhdg/kPZgoECs1kubTLgcQXj71muQAELCjO3x+MNQj+2CT4vrjc
3rX+Gt2m6bv9Crb8vrFssIVc/h96b6VVnYuuY5u9gnbjr0peVTPSiuTcNkS4G4c8
7bNbHjdIqebu2wzawOMxFlArSYuRPpGRE5NhJk9XL8HUBFM3+Dh5NgJ6nrvEyi91
40dzlmfaYQc66ki7fQQ5RPWPsE+cvTWFySy7y2WRCXT+dzpttZWRSPF9ZdJFBW3L
Ci0bVn7AZ/R69U7hXEy2OIiPlKcpLAUlg8M4dfE60VPAi1gFKX4=
=OLXW
-----END PGP SIGNATURE-----


Reply to: