-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Fri, 27 Sep 2024 16:25:38 +0300 Source: nghttp2 Binary: libnghttp2-14 libnghttp2-14-dbgsym libnghttp2-dev nghttp2-client nghttp2-client-dbgsym nghttp2-proxy nghttp2-proxy-dbgsym nghttp2-server nghttp2-server-dbgsym Architecture: amd64 Version: 1.52.0-1+deb12u2 Distribution: bookworm Urgency: medium Maintainer: amd64 / i386 Build Daemon (x86-ubc-01) Changed-By: Adrian Bunk Description: libnghttp2-14 - library implementing HTTP/2 protocol (shared library) libnghttp2-dev - library implementing HTTP/2 protocol (development files) nghttp2-client - client implementing HTTP/2 protocol nghttp2-proxy - reverse proxy implementing HTTP/2 protocol nghttp2-server - server implementing HTTP/2 protocol Closes: 1068415 Changes: nghttp2 (1.52.0-1+deb12u2) bookworm; urgency=medium . * Non-maintainer upload. * CVE-2024-28182: unbounded number of HTTP/2 CONTINUATION frames DoS (Closes: #1068415) * nghttp2_option_set_stream_reset_rate_limit was added in 1.52.0-1+deb12u1, add to debian/libnghttp2-14.symbols Checksums-Sha1: b3024640afb1759e7d27ae1c21eb5ce3d9709a69 218848 libnghttp2-14-dbgsym_1.52.0-1+deb12u2_amd64.deb 3e9d445eee1908ba22607514915f6d7cdbebf012 72956 libnghttp2-14_1.52.0-1+deb12u2_amd64.deb b58b25d4628dbb83e37eba5d6363a6a5d0864366 110220 libnghttp2-dev_1.52.0-1+deb12u2_amd64.deb baa1f028ed922571e94d381638fe069dbee64679 2010936 nghttp2-client-dbgsym_1.52.0-1+deb12u2_amd64.deb a5a4c9a6a67aa6cf00e14be11711ae510854bb2f 171408 nghttp2-client_1.52.0-1+deb12u2_amd64.deb 0e0d262ae145b0e196b4fb39319b91ac43d3f561 5884792 nghttp2-proxy-dbgsym_1.52.0-1+deb12u2_amd64.deb ec7d011c4d8c655b26324d951a1fc28c368d6a97 398276 nghttp2-proxy_1.52.0-1+deb12u2_amd64.deb ee6c4de2b141915672a28f98e822a2fd32847d25 954716 nghttp2-server-dbgsym_1.52.0-1+deb12u2_amd64.deb ffb1a865d7f00064709662142feeacee73ebe66f 98252 nghttp2-server_1.52.0-1+deb12u2_amd64.deb e76600865aef98c6a03e89f094eee78bb2682f44 8878 nghttp2_1.52.0-1+deb12u2_amd64-buildd.buildinfo Checksums-Sha256: a24c6cb64214e60804057d6fa5e3f9b1085b490523798c89256922eb8b74d932 218848 libnghttp2-14-dbgsym_1.52.0-1+deb12u2_amd64.deb dbe3eb8c831e654ac7d5cf045d605d53fd763e8ebc238607c25f301996103bb9 72956 libnghttp2-14_1.52.0-1+deb12u2_amd64.deb ddbdd672a74893055d3bfb1553e20141854e65e9ae31d89a1bc09c5df938e806 110220 libnghttp2-dev_1.52.0-1+deb12u2_amd64.deb 15ef7b2cec5f74c41c91ca9b81b7671e00a9d68e0b7cf1bdbf0a4120bac7f8b9 2010936 nghttp2-client-dbgsym_1.52.0-1+deb12u2_amd64.deb 194c57f19645300ce991cdbfe15d35edc0097bc78a7478f420d5bf39c5b7f788 171408 nghttp2-client_1.52.0-1+deb12u2_amd64.deb 62000cba1eae109fe736b276b489abe263d78c9aa32716e75f36fd2c13c90686 5884792 nghttp2-proxy-dbgsym_1.52.0-1+deb12u2_amd64.deb 1cf58200b36c892d82e5b6d4941a24ba75a5c3ac68ff95adf6bef6a083445833 398276 nghttp2-proxy_1.52.0-1+deb12u2_amd64.deb 4c6747ef5af695e9ae9f938cc1610d16ccd4045424ec9669ef9bd00b49732166 954716 nghttp2-server-dbgsym_1.52.0-1+deb12u2_amd64.deb f237cb16e809fdc4404a970da83368738e4a28f6122a3d4e0a07a712fe889dcc 98252 nghttp2-server_1.52.0-1+deb12u2_amd64.deb 1e511a97cc16d6cbb70f31b413ccd5febeeeee8854324d74e2075418a18795e1 8878 nghttp2_1.52.0-1+deb12u2_amd64-buildd.buildinfo Files: 4cc68ff5ce0c1098a053cbeb2fb09058 218848 debug optional libnghttp2-14-dbgsym_1.52.0-1+deb12u2_amd64.deb ece467e644497f898d202ea0e5955cb2 72956 libs optional libnghttp2-14_1.52.0-1+deb12u2_amd64.deb efd680b9799468fc802ce0fd365fb32e 110220 libdevel optional libnghttp2-dev_1.52.0-1+deb12u2_amd64.deb 513928a47a01e00f6a3f8cb6b5dddeb8 2010936 debug optional nghttp2-client-dbgsym_1.52.0-1+deb12u2_amd64.deb 76e2601fa040f079f58d04db6c9b1053 171408 httpd optional nghttp2-client_1.52.0-1+deb12u2_amd64.deb 170ac2bcd1302fbbc7ad752d10a772e4 5884792 debug optional nghttp2-proxy-dbgsym_1.52.0-1+deb12u2_amd64.deb 78d670cf3cbd01c5b12e7ba2c2f54450 398276 httpd optional nghttp2-proxy_1.52.0-1+deb12u2_amd64.deb 8d2acf8b244409e58843b3898102fa3f 954716 debug optional nghttp2-server-dbgsym_1.52.0-1+deb12u2_amd64.deb d2c56b69df436ec73bd93405d5c4a6b0 98252 httpd optional nghttp2-server_1.52.0-1+deb12u2_amd64.deb 63211ebc79c758881911927a360c4713 8878 httpd optional nghttp2_1.52.0-1+deb12u2_amd64-buildd.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE4Unr4QHS5Yi4rr9Q3KGKEAtjIVgFAmb5S5UACgkQ3KGKEAtj IVi6jQ//b6nHCtkpZE8x3NJKDVNgQEOMewzuE1lWCsMaiEgHc8NHn7gLFFqv5AUW k7PC9wYmLMeTjunHPcq4Wbaj/bD84YdvJqauLqF6rMAzJ0+TRddB3N+SWN9ju8IU 3VY786uG6SwHV6mdcBLxFONZsm8h6so0Z8g8TetDtruiDRluaYYdb/gagT0qzBJa KI0YbIAtFKByVjkT9StUR5UufkOnczwylqCPrZbcX6YbrKlevIIa85NN65KwBRpI XfH9lNHM4I4V2tLj/bK8Z0krO+fPbdDYzUTHrS37Vxe1SEj7kKBd1++AL0rKBiw6 pFzwNeAw4Rt6Xa97lvt9k8uukonGhtfv90DiRjC88xeFV8ydftcfKS6Zm2sH5xFn L1uMUcDlJ910s1COBOgJ35VNUj08jMa8cSpA3Th01pfKMpaPz27CS2askD73wbqT bgWh9LqcAzHFGNkkfVJMaiKSlXHDGBuykQcSSdeTvke48gfxXBCKse/hLo1wX4fJ VdF4nXIlFC/r/CFgzToJGGTU5tI2cUMnAnqB7k0fgD2SlEvopHZqIHre+ZdfdRiS ZhDUc/DPo087vfpCFO3DBMoPmv6Qw82dWqPBtOhgZNKWBE3pJcPEEcBO+Papf+3e Eh5dBfFzyUFtrZFpdTG4M0s6uBCsx1jmiTuKo+F6NV8R6paCzUo= =slQF -----END PGP SIGNATURE-----