[SECURITY] [DSA 4508-1] h2o security update

Moritz Muehlenhoff <[email protected]>
Newsgroups gmane.comp.security.bugtraq
Message-ID <20190824144401.xrgvpey4dcd6gtyi__33154.7489318595$1566800762$gmane$org@seger.debian.org>
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

- -------------------------------------------------------------------------
Debian Security Advisory DSA-4508-1                   [email protected]
https://www.debian.org/security/                       Moritz Muehlenhoff
August 24, 2019                       https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package        : h2o
CVE ID         : CVE-2019-9512 CVE-2019-9514 CVE-2019-9515

Three vulnerabilities were discovered in the HTTP/2 code of the H2O HTTP
server, which could result in denial of service.

For the stable distribution (buster), these problems have been fixed in
version 2.2.5+dfsg2-2+deb10u1.

We recommend that you upgrade your h2o packages.

For the detailed security status of h2o please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/h2o

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/

Mailing list: [email protected]
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAl1hTPUACgkQEMKTtsN8
TjYYfxAAk1VfiMGg6RQdHtPGwCFbMF7OVV26ZZqwaVqI4nWnA9w6U0ymrg8liYRi
JrBfz5xacONkHRLD70YQ59ueH0AKN0+AX16WCpdFflP8b4+wPuqFKqkOFvNbYy+e
B9gUcFieFE/bJG/pzYyahPvE90DpVewEgjtFPWhD3bNK/p83nDHaP+/rwFRbI0mp
P8t0Wy1kIAjLCXq624Yc34x5AOwnxl5qIUNgm9Y8si1aLHs/geJg8IAohR2KKf2I
KoNE3+yHSMp/uvZbDOx8u/TOAwfiEpkkQgOnAm3ANkh6IP9w5QV68hZXpJtg1zQv
RQ9rSfnfReQQFOD9mDlCFE1Z6thzmL8cFJPTlj6ozVR0St/dK0VMJZ5HLjueSyoW
PWeTwGusAdH8wm2U8o9iGjw3KKxyE1HCT47v7w+iZfNV1PSgiEnklROmHcLWxpun
vbujcynAItmAnx9uzqZpieBMqwK0Je5bP1Ctq0aYyvPGf+HemBSV1tzDgHto3Jrf
jQ52+264QZpIcXvnhLhjJBgBP7mFXnyhJUT02rOw8gvsWw97+eVzkLVkvNJDApI9
sfWe17p5G6Q2YImNzHgrpr2PbJoHnmJt6X27hnznL4O9Ut5SNlajTjlpxwSzAT4P
8/1tljvMOD/HaGih1XPsYCrhq9h+GOiU/QghSi7FH/Oiq2mczD0=
=wvZn
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.