Debian Security Advisory
DSA-5435-1 trafficserver -- security update
- Date Reported:
- 21 Jun 2023
- Affected Packages:
- trafficserver
- Vulnerable:
- Yes
- Security database references:
- In the Debian bugtracking system: Bug 1038248.
In Mitre's CVE dictionary: CVE-2022-47184, CVE-2023-30631, CVE-2023-33933. - More information:
-
Several vulnerabilities were discovered in Apache Traffic Server, a reverse and forward proxy server, which could result in information disclosure or denial of service.
For the stable distribution (bookworm), these problems have been fixed in version 9.2.0+ds-2+deb12u1. This is a no change rebuild of the update from DSA-5435-1 with a corrected version number.
We recommend that you upgrade your trafficserver packages.
For the detailed security status of trafficserver please refer to its security tracker page at: https://security-tracker.debian.org/tracker/trafficserver