-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Fri, 27 Sep 2024 16:25:38 +0300 Source: nghttp2 Binary: libnghttp2-14 libnghttp2-14-dbgsym libnghttp2-dev nghttp2-client nghttp2-client-dbgsym nghttp2-proxy nghttp2-proxy-dbgsym nghttp2-server nghttp2-server-dbgsym Architecture: i386 Version: 1.52.0-1+deb12u2 Distribution: bookworm Urgency: medium Maintainer: i386 Build Daemon (x86-grnet-01) Changed-By: Adrian Bunk Description: libnghttp2-14 - library implementing HTTP/2 protocol (shared library) libnghttp2-dev - library implementing HTTP/2 protocol (development files) nghttp2-client - client implementing HTTP/2 protocol nghttp2-proxy - reverse proxy implementing HTTP/2 protocol nghttp2-server - server implementing HTTP/2 protocol Closes: 1068415 Changes: nghttp2 (1.52.0-1+deb12u2) bookworm; urgency=medium . * Non-maintainer upload. * CVE-2024-28182: unbounded number of HTTP/2 CONTINUATION frames DoS (Closes: #1068415) * nghttp2_option_set_stream_reset_rate_limit was added in 1.52.0-1+deb12u1, add to debian/libnghttp2-14.symbols Checksums-Sha1: 80c5371218c8a83215940c66ea7bf3913fb99ce1 193980 libnghttp2-14-dbgsym_1.52.0-1+deb12u2_i386.deb ae04162a1825b34f402c7e2e09d2186003bd5a0d 80836 libnghttp2-14_1.52.0-1+deb12u2_i386.deb 17f278933307bed7142aa0f91eb75a74cc13300a 119504 libnghttp2-dev_1.52.0-1+deb12u2_i386.deb 3ae30444321e0f801d838c7962bf2aba1b73e5ac 1961380 nghttp2-client-dbgsym_1.52.0-1+deb12u2_i386.deb cf015bcdc9efb6cf09207afc5b43a90eccf3d80a 186652 nghttp2-client_1.52.0-1+deb12u2_i386.deb bd9d24c5cb512b3c318e6bba6c0b923abff9358b 5753248 nghttp2-proxy-dbgsym_1.52.0-1+deb12u2_i386.deb f349c387a50263ae2049a618c96b77a1aedcfa9f 431556 nghttp2-proxy_1.52.0-1+deb12u2_i386.deb b958d1435aa2cc7e6c5593f4c0f7c2935bec1e24 935608 nghttp2-server-dbgsym_1.52.0-1+deb12u2_i386.deb 7f1170d5f3cf6645fb7bea83e52ac112334808e3 107876 nghttp2-server_1.52.0-1+deb12u2_i386.deb b3dbf9f5dbd741484fc684f755675e5162be197e 8816 nghttp2_1.52.0-1+deb12u2_i386-buildd.buildinfo Checksums-Sha256: bb846a4abc0eabd5081ea1788974463fbc38affd952e5f94b47ebf5783755bb1 193980 libnghttp2-14-dbgsym_1.52.0-1+deb12u2_i386.deb 71e7b6feebeafb0fc679fbc1922fefaee29c1f5e14098e21f9b2e10d474314e2 80836 libnghttp2-14_1.52.0-1+deb12u2_i386.deb 00fc412ea81b8ad43b01b1aa0fb844dbd389a324e41ee0b4f62e206e1a151abf 119504 libnghttp2-dev_1.52.0-1+deb12u2_i386.deb eff87a25c37c97c540103c7b05f8e188acc2ee213d25927478f2b0bcc9b2908e 1961380 nghttp2-client-dbgsym_1.52.0-1+deb12u2_i386.deb 6ddadeab6a4446a75f5725c16d9f9bb5188bb987e8919aeacfc5ef3e72051758 186652 nghttp2-client_1.52.0-1+deb12u2_i386.deb fb901bed1b4002587045e7668150e937ed2f72680a86ddc82f23b9aeb22ad919 5753248 nghttp2-proxy-dbgsym_1.52.0-1+deb12u2_i386.deb 95ebd559e5eac5d2079c12462a7f87601587314ccb75bd062d90badf155f823a 431556 nghttp2-proxy_1.52.0-1+deb12u2_i386.deb 0b7dac6f3a8b887d9e908c82be8504c6cd8c2db28c98937751b3ca0081000634 935608 nghttp2-server-dbgsym_1.52.0-1+deb12u2_i386.deb 103dc542d5e5bb5f47ececa0893ebfb9ddf5b075cf8b900624a1170e5fe92965 107876 nghttp2-server_1.52.0-1+deb12u2_i386.deb c3de97ddaa80c954ed60d2f279e6fd925117aa396696dff31bbd2d4bd1192cba 8816 nghttp2_1.52.0-1+deb12u2_i386-buildd.buildinfo Files: ded439bcbf90571c1289a33e34e7fd59 193980 debug optional libnghttp2-14-dbgsym_1.52.0-1+deb12u2_i386.deb b3f10575b6cca5e18bbb1cb5dec48d83 80836 libs optional libnghttp2-14_1.52.0-1+deb12u2_i386.deb beda7305973ce086eae3c505eba91c9f 119504 libdevel optional libnghttp2-dev_1.52.0-1+deb12u2_i386.deb a9d172b1e209cb6b040a1c031532874b 1961380 debug optional nghttp2-client-dbgsym_1.52.0-1+deb12u2_i386.deb 7622009d0c1426b64c53574ec621d0f0 186652 httpd optional nghttp2-client_1.52.0-1+deb12u2_i386.deb 4c1d91ecef0b7f1ac306ad7f6fdfbdb7 5753248 debug optional nghttp2-proxy-dbgsym_1.52.0-1+deb12u2_i386.deb e20544c832cd858ea7c22766f87ce8a9 431556 httpd optional nghttp2-proxy_1.52.0-1+deb12u2_i386.deb 6bd63433907673c7c6fd4dafa430fc10 935608 debug optional nghttp2-server-dbgsym_1.52.0-1+deb12u2_i386.deb bff03a577f5997eca7e201fcf204dc2b 107876 httpd optional nghttp2-server_1.52.0-1+deb12u2_i386.deb b7a18c717de8384720c223586ed31f18 8816 httpd optional nghttp2_1.52.0-1+deb12u2_i386-buildd.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEyTfXx8sBpQ0Lh3cUU9a0/LcaTpMFAmb5S7UACgkQU9a0/Lca TpO7kQ//bNZrraM7AIeRnsMYUhcgNtw5oBYGaUuzam4Ax0/RKv3I/8xRWey75YAS QpiL/ybyWCbSwuwoNOqA2oUABtmdnXj2A+JlVE7mG5GgSN7cSwXcHkhFDKjsYdEc npmTybuzdkqfi54ChAe2WEgvIkh93hqKU+gAXh8IH0tPBr6rxQX7+qWTOugF+jiv Ftq3HD0MSv4aFj9Q+wUu4vNO9iD80sUWwN/1QpOC49TgpuqgvbmviIbO2B5gA9CF Em9tAZfohqjLfW8HgA6IdJiUBFMnyuIdKfaC3CbkVBcS+ipXFYnvJyhxU/SVLCd8 yZl9MkcALChLLj2214VVUN0d/MC82JTD+N/9n3jTfSs6gwn4XVSYIwkuI7ycg4ob vFe0CP4TTT/xqipaLicEyd5l/1PO0XxQe8xoBuElIkm5F8MwMkkvHqjeEcxNovNG +I5gv1PAGiNS+E5vlIb8XckdUBz5xv4SFG4NV1QzGBmedO9PgoXDV9TBSZd0JY2Y tw1H4uEmjm1AsA0xTpqdmothzIINsea+ZelYLbsz8q0D8AeqbjcRi98si6Q7H+rT Au/vLUVfBSADVWJLTNBqKZ53XfmduKM4LrGz/AZKtwh+BeYcgZaahxjdHH3PmORF G26HLsBDgW6TkK2m8whbb3chgs7vW1AuSK8OuM8PTBactf/Rd84= =XcaF -----END PGP SIGNATURE-----