[ubuntu/eoan-proposed] haproxy 2.0.3-1ubuntu1 (Accepted)
Andreas Hasenack
andreas at canonical.com
Mon Jul 29 12:22:12 UTC 2019
haproxy (2.0.3-1ubuntu1) eoan; urgency=medium
* Merge with Debian unstable. Remaining changes:
- d/t/control, d/t/proxy-localhost: simple DEP8 test to actually
generate traffic through haproxy.
[Updated to use "service" instead of "systemctl" to match what was
submitted to Debian.]
* Dropped:
- SECURITY UPDATE: DoS in htx_manage_client_side_cookies
+ debian/patches/CVE-2019-14241.patch: fix parsing of malformed cookies
which start by a delimiter in src/proto_htx.c.
+ CVE-2019-14241
[Fixed upstream]
haproxy (2.0.3-1) experimental; urgency=medium
* New upstream version.
- BUG/CRITICAL: http_ana: Fix parsing of malformed cookies which start by
a delimiter (CVE-2019-14241)
- BUG/MEDIUM: checks: Don't attempt to receive data if we already
subscribed.
- BUG/MEDIUM: http/htx: unbreak option http_proxy
- DOC: htx: Update comments in HTX files
- BUG/MEDIUM: mux-h1: Trim excess server data at the end of a transaction
- BUG/MEDIUM: tcp-checks: do not dereference inexisting conn_stream
* Bump Standards-Version to 4.4.0; no changes needed
haproxy (2.0.2-1) experimental; urgency=medium
* New upstream version.
- BUG/MAJOR: listener: fix thread safety in resume_listener()
Date: Sat, 27 Jul 2019 10:15:10 -0300
Changed-By: Andreas Hasenack <andreas at canonical.com>
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
https://launchpad.net/ubuntu/+source/haproxy/2.0.3-1ubuntu1
-------------- next part --------------
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Sat, 27 Jul 2019 10:15:10 -0300
Source: haproxy
Architecture: source
Version: 2.0.3-1ubuntu1
Distribution: eoan
Urgency: medium
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
Changed-By: Andreas Hasenack <andreas at canonical.com>
Changes:
haproxy (2.0.3-1ubuntu1) eoan; urgency=medium
.
* Merge with Debian unstable. Remaining changes:
- d/t/control, d/t/proxy-localhost: simple DEP8 test to actually
generate traffic through haproxy.
[Updated to use "service" instead of "systemctl" to match what was
submitted to Debian.]
* Dropped:
- SECURITY UPDATE: DoS in htx_manage_client_side_cookies
+ debian/patches/CVE-2019-14241.patch: fix parsing of malformed cookies
which start by a delimiter in src/proto_htx.c.
+ CVE-2019-14241
[Fixed upstream]
.
haproxy (2.0.3-1) experimental; urgency=medium
.
* New upstream version.
- BUG/CRITICAL: http_ana: Fix parsing of malformed cookies which start by
a delimiter (CVE-2019-14241)
- BUG/MEDIUM: checks: Don't attempt to receive data if we already
subscribed.
- BUG/MEDIUM: http/htx: unbreak option http_proxy
- DOC: htx: Update comments in HTX files
- BUG/MEDIUM: mux-h1: Trim excess server data at the end of a transaction
- BUG/MEDIUM: tcp-checks: do not dereference inexisting conn_stream
* Bump Standards-Version to 4.4.0; no changes needed
.
haproxy (2.0.2-1) experimental; urgency=medium
.
* New upstream version.
- BUG/MAJOR: listener: fix thread safety in resume_listener()
Checksums-Sha1:
9a7e1e468f9535b7c6b2bd66369f59f0a469ae45 2377 haproxy_2.0.3-1ubuntu1.dsc
32426b727f88a90b0e8ed04190ba1d138d535394 2534678 haproxy_2.0.3.orig.tar.gz
3a86ad5d1c12ab743cb669c684e93348adf95f91 68184 haproxy_2.0.3-1ubuntu1.debian.tar.xz
aef13cd4b4709a37450fb114e770bee7e179a362 6556 haproxy_2.0.3-1ubuntu1_source.buildinfo
Checksums-Sha256:
dd83efd1f7ff0858fecee5702ce2a86cd5ed8e028e5bd2291df6190ad2dfa065 2377 haproxy_2.0.3-1ubuntu1.dsc
aac1ff3e5079997985b6560f46bf265447d0cd841f11c4d77f15942c9fe4b770 2534678 haproxy_2.0.3.orig.tar.gz
53a699685fd594caca0fafd74e7c0d2495060270e2a43b5bec25f1303bbbadf2 68184 haproxy_2.0.3-1ubuntu1.debian.tar.xz
c9df5e81c5e5b0aaadff00816634a3931541042e094a659e2af34dbaff606071 6556 haproxy_2.0.3-1ubuntu1_source.buildinfo
Files:
010e65c15c3e409929024142e2b262d7 2377 net optional haproxy_2.0.3-1ubuntu1.dsc
cbe13aad74e839a3a055908ab545279d 2534678 net optional haproxy_2.0.3.orig.tar.gz
00290824895787e7d957b06bb266e748 68184 net optional haproxy_2.0.3-1ubuntu1.debian.tar.xz
78f48a3f4937060a4c7ca6bc3c0bed63 6556 net optional haproxy_2.0.3-1ubuntu1_source.buildinfo
Original-Maintainer: Debian HAProxy Maintainers <haproxy at tracker.debian.org>
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEiGZB1jWM2kalbBxyrJg+tb9ry6kFAl0+4xYACgkQrJg+tb9r
y6k03g/+JVp2Ly8iO9kZmIFGHzr1LBRS4m1onDvvWsIGieANWg9rWBaCWJzQ30gh
IXufiBx2CJCnCsrTZ6VtuX9M3itEipLeErYgDVIWW705nsZqS9JaZnEfpPsQ3PMt
DfcsLeOKmSz69l+F0hNLKTkF9CROkUW7adXYvuNL42fBIzTZhoQknx90ivv19Q4B
uDTydTtaMnLsiF/Sy4cRBDi+PZAC86kxrZI4TFHVjRZK0R1gXKM3C+eM/WBhEupn
M92mLLJKikPTSQS3pLl2eyYYi8v5W8xGkDsQ1rhEOW2Y0ltLFXXH3tjbd9+zYgXb
xUu1I1fvbpalKzf8tmYeJYsV7BXYQtL+9uYpe54CasngfE9DOZRIPMY15luAyFLF
lWtV1vjrWaqBYmGzeS0AVU/tBAm+SsuvMhNZn79ZieE2365mOSDg11CYhH/sPYpF
25BXVqwU/EDpHq2MKkvxLFMU5rBwEqSojbJRnBlBqNcckfaIplApiWeo1y4CYrWt
Apxn5c5aQQTB6vAVP8JoG07PDnZzyZWsm40BfLZeja0lvHZcwWVZE8oGzaDn46Rq
LFXAm8TdQTPnkTl1TPXVaCmM8vD1jPAGQA2SGnCI2FkBBrm1rRWqzHWSygp1k/8p
qScxGQjuOCDFQdO3U7E+Mo+xpUzk6xTayKCBBz+E4kvw8saElQU=
=JBzM
-----END PGP SIGNATURE-----
More information about the Eoan-changes
mailing list