-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Fri, 27 Sep 2024 16:25:38 +0300 Source: nghttp2 Binary: libnghttp2-14 libnghttp2-14-dbgsym libnghttp2-dev nghttp2-client nghttp2-client-dbgsym nghttp2-proxy nghttp2-proxy-dbgsym nghttp2-server nghttp2-server-dbgsym Architecture: arm64 Version: 1.52.0-1+deb12u2 Distribution: bookworm Urgency: medium Maintainer: arm Build Daemon (arm-ubc-01) Changed-By: Adrian Bunk Description: libnghttp2-14 - library implementing HTTP/2 protocol (shared library) libnghttp2-dev - library implementing HTTP/2 protocol (development files) nghttp2-client - client implementing HTTP/2 protocol nghttp2-proxy - reverse proxy implementing HTTP/2 protocol nghttp2-server - server implementing HTTP/2 protocol Closes: 1068415 Changes: nghttp2 (1.52.0-1+deb12u2) bookworm; urgency=medium . * Non-maintainer upload. * CVE-2024-28182: unbounded number of HTTP/2 CONTINUATION frames DoS (Closes: #1068415) * nghttp2_option_set_stream_reset_rate_limit was added in 1.52.0-1+deb12u1, add to debian/libnghttp2-14.symbols Checksums-Sha1: 6b40878bf2d5552bfdae3493f4c99ac5a8136f39 219796 libnghttp2-14-dbgsym_1.52.0-1+deb12u2_arm64.deb a3a848a5e96d4196667b0bedb9996aa585ca11ff 68620 libnghttp2-14_1.52.0-1+deb12u2_arm64.deb 8bbb6c82387c93c4c6975a4a39b62f075d053707 107496 libnghttp2-dev_1.52.0-1+deb12u2_arm64.deb 636d7ab537060a688bf99dd6982b185998fb3b73 1975860 nghttp2-client-dbgsym_1.52.0-1+deb12u2_arm64.deb a4ede3106274414943e56eeb9523fc44f714ec7d 155512 nghttp2-client_1.52.0-1+deb12u2_arm64.deb 638d45552996318f8e9f0683dbbe3ca1b7c65136 5758616 nghttp2-proxy-dbgsym_1.52.0-1+deb12u2_arm64.deb a35dde7b2726f8f8525f1e7637c81c6e9137887d 352564 nghttp2-proxy_1.52.0-1+deb12u2_arm64.deb 8db4c4de8058caa0db15d144ed4797435950a3d0 936032 nghttp2-server-dbgsym_1.52.0-1+deb12u2_arm64.deb e2ce406a9a089eb9462414c14713cf8c7543f876 90604 nghttp2-server_1.52.0-1+deb12u2_arm64.deb e4d9eadb28eae27784503beb424e921239a7394c 8877 nghttp2_1.52.0-1+deb12u2_arm64-buildd.buildinfo Checksums-Sha256: 55367fc24382e06828469642a5d7d7cab1c7dcf744152f9d3fcd73a157716437 219796 libnghttp2-14-dbgsym_1.52.0-1+deb12u2_arm64.deb 77cc590ef1bc97767a0ab3366f29a8c1854c6bd37b541719beae5d43962b39a5 68620 libnghttp2-14_1.52.0-1+deb12u2_arm64.deb 764260ec76ea82af5fd913eaa61df50c1230d53cebf64488d467d4d7d269e428 107496 libnghttp2-dev_1.52.0-1+deb12u2_arm64.deb 52f8ab738204660f9f88cc6f9f157ae1233ec3e8f67b40d38f31b8b3fdd79273 1975860 nghttp2-client-dbgsym_1.52.0-1+deb12u2_arm64.deb 004a838170e64384f80119875c247222e70955e66b0e1f9a556685700b71903c 155512 nghttp2-client_1.52.0-1+deb12u2_arm64.deb 6b333d1e567214474d1a4948d3a5d5e97824d00dee7b1fb5494912e9bbac7763 5758616 nghttp2-proxy-dbgsym_1.52.0-1+deb12u2_arm64.deb 02805d5216d5ef9bd04915aa1d91260940e929f3077b718948b3ede8a5cce4fe 352564 nghttp2-proxy_1.52.0-1+deb12u2_arm64.deb 1fa545b65bf60b26b4cdeaefdc50a1f7f520e9d757fa928721722bdf90712676 936032 nghttp2-server-dbgsym_1.52.0-1+deb12u2_arm64.deb f3ff3233d1a9cef320f8096ff03e900303db31a8eada9c6d148f741b495f4041 90604 nghttp2-server_1.52.0-1+deb12u2_arm64.deb d1312eb8e475d1054892815d0607bf1ca2562c00b92b60624efa4833bcc00b70 8877 nghttp2_1.52.0-1+deb12u2_arm64-buildd.buildinfo Files: 1859bbedc3472085ad662c16affb9370 219796 debug optional libnghttp2-14-dbgsym_1.52.0-1+deb12u2_arm64.deb 9aae8565b50785c5da19853d0035ce5b 68620 libs optional libnghttp2-14_1.52.0-1+deb12u2_arm64.deb ea02c88da50c79e4130ee931fadcf2bc 107496 libdevel optional libnghttp2-dev_1.52.0-1+deb12u2_arm64.deb 6b3e8b184b54649aee8b49d7eab8c6db 1975860 debug optional nghttp2-client-dbgsym_1.52.0-1+deb12u2_arm64.deb d6f5408ce6571c6d567d8fa48c9b0d34 155512 httpd optional nghttp2-client_1.52.0-1+deb12u2_arm64.deb d86c8141dc058d8c9aac87188430fc1e 5758616 debug optional nghttp2-proxy-dbgsym_1.52.0-1+deb12u2_arm64.deb 651bfcdcf9d67b83caa0f902151fafa4 352564 httpd optional nghttp2-proxy_1.52.0-1+deb12u2_arm64.deb b1667255db5822e04a4ad7dbb55e6671 936032 debug optional nghttp2-server-dbgsym_1.52.0-1+deb12u2_arm64.deb 83dcf3b408c0f26b743f4bac081504e2 90604 httpd optional nghttp2-server_1.52.0-1+deb12u2_arm64.deb b8be22252c35532bf9b3a30eeb89fb64 8877 httpd optional nghttp2_1.52.0-1+deb12u2_arm64-buildd.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEH43oX1cK+BEEs9Pe/9j0ct/+ZwwFAmb5TJMACgkQ/9j0ct/+ ZwydKQ/8C8IXHxvZTuyfNlpD463BeKLemYvhDYYi3Y40B2Qmse7/7ACut+vhMBRR 344tIVQTaOKIe55tZOgwSzWbYvs97dQfiJM6Dwg0QysMwli34xBiJPDOvB/b9HRp Uz93+KsR4AuybILGwUJe4fsLO1voQ9v4DtKqZ5XgWr98rwKXHBOQSgxWek3tbY2C Leeq4BV8djjEcAcP9QFbEomv9eEBdMKCnnqxklo2hj+ZOAhHqB8A3uNWhUKn2Y/s pL9oAwfEJIIofav/DDjsPksdo1trgCYNmSNYlYMaH+HUfW2vHrvVO3Xng+wUf+d+ CY44Cuhr6Aol5PPHDnCLmWaXGycA2DQqzqeNrTu5nkpIqrWSxtwNCnR4uLfJo6AK qP3ujiTg/5C0fYAv2YjHZXTyqrZcthIjCxB1fbs/W2CKstnFgg0FwN6Oj/uaRntu X/Ls9HXpRzPQHMIDqfdeNMkryr86lcTSQVrcoTMpd48mLiHs/ITO0YyrQiDLQJIm wz3I/1EAI1KmUyVVzNr2irzK1VQINHo7+iToSecp7ZQNCvu1t+BuFcUKa3Ru9T1e UgkrdCAioof/dkRLK9lnfWDlXn3mnhZ+6U46BUTSrtOVj2oh379eCcvzhpn0U61G 6geIU6oY1QDE3QkbUniMPtCGUrvRBw/CPzA4asPlTkP/1aYOLgw= =g6ek -----END PGP SIGNATURE-----