[ubuntu/bionic-proposed] nghttp2 1.30.0-1ubuntu1 (Accepted)

Marc Deslauriers marc.deslauriers at ubuntu.com
Fri Apr 13 08:28:19 UTC 2018


nghttp2 (1.30.0-1ubuntu1) bionic; urgency=medium

  * SECURITY UPDATE: DoS via too large frame
    - debian/patches/CVE-2018-1000168.patch: fix frame handling in
      lib/nghttp2_frame.c, add test to tests/nghttp2_session_test.c.
    - CVE-2018-1000168

Date: Tue, 10 Apr 2018 13:45:02 -0400
Changed-By: Marc Deslauriers <marc.deslauriers at ubuntu.com>
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
https://launchpad.net/ubuntu/+source/nghttp2/1.30.0-1ubuntu1
-------------- next part --------------
Format: 1.8
Date: Tue, 10 Apr 2018 13:45:02 -0400
Source: nghttp2
Binary: libnghttp2-dev libnghttp2-doc libnghttp2-14 nghttp2-client nghttp2-proxy nghttp2-server nghttp2
Architecture: source
Version: 1.30.0-1ubuntu1
Distribution: bionic
Urgency: medium
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
Changed-By: Marc Deslauriers <marc.deslauriers at ubuntu.com>
Description:
 libnghttp2-14 - library implementing HTTP/2 protocol (shared library)
 libnghttp2-dev - library implementing HTTP/2 protocol (development files)
 libnghttp2-doc - library implementing HTTP/2 protocol (documentation)
 nghttp2    - server, proxy and client implementing HTTP/2
 nghttp2-client - client implementing HTTP/2 protocol
 nghttp2-proxy - reverse proxy implementing HTTP/2 protocol
 nghttp2-server - server implementing HTTP/2 protocol
Changes:
 nghttp2 (1.30.0-1ubuntu1) bionic; urgency=medium
 .
   * SECURITY UPDATE: DoS via too large frame
     - debian/patches/CVE-2018-1000168.patch: fix frame handling in
       lib/nghttp2_frame.c, add test to tests/nghttp2_session_test.c.
     - CVE-2018-1000168
Checksums-Sha1:
 0575d62e69ac1f2b7b0879b1f4dd77ab0359a7cd 2674 nghttp2_1.30.0-1ubuntu1.dsc
 e5cd0687ad3dc9e616d9db41ef2c241296560761 13244 nghttp2_1.30.0-1ubuntu1.debian.tar.xz
 25d147241757b1bd1056c45313a99cb3e8aa87e8 7710 nghttp2_1.30.0-1ubuntu1_source.buildinfo
Checksums-Sha256:
 1848fdc28933b7ee23dbebe3c9dcd0ca9182f95a278d627758d5ccfa2e0b44ad 2674 nghttp2_1.30.0-1ubuntu1.dsc
 eb99f2c10cd872ce750964fc59734aa70b89ad04179291a23bfbee0e1a2903d3 13244 nghttp2_1.30.0-1ubuntu1.debian.tar.xz
 7bc02eea637b07c0438f342194e91a91f2890b2f546976e7e0366d01b250f7c2 7710 nghttp2_1.30.0-1ubuntu1_source.buildinfo
Files:
 ba680976fbf4f93657459c15d816b581 2674 httpd optional nghttp2_1.30.0-1ubuntu1.dsc
 d360812197a2a3d269ee8f874e427942 13244 httpd optional nghttp2_1.30.0-1ubuntu1.debian.tar.xz
 97505431f417e43be6ef728da178237d 7710 httpd optional nghttp2_1.30.0-1ubuntu1_source.buildinfo
Original-Maintainer: Tomasz Buchert <tomasz at debian.org>


More information about the Bionic-changes mailing list