-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 - ----------------------------------------------------------------------- Debian LTS Advisory DLA-3224-1 debian-...@lists.debian.org https://www.debian.org/lts/security/ Utkarsh Gupta December 05, 2022 https://wiki.debian.org/LTS - -----------------------------------------------------------------------
Package : http-parser Version : 2.8.1-1+deb10u3 CVE ID : CVE-2020-8287 Debian Bug : 1016690 There was a potential HTTP request smuggling vulnerability in http-parser, a popular library for parsing HTTP messages. For Debian 10 buster, this problem has been fixed in version 2.8.1-1+deb10u3. We recommend that you upgrade your http-parser packages. For the detailed security status of http-parser please refer to its security tracker page at: https://security-tracker.debian.org/tracker/http-parser Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS -----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFiEEbJ0QSEqa5Mw4X3xxgj6WdgbDS5YFAmON6+MACgkQgj6WdgbD S5b3RRAAoDlzVOmJDpcKAEjLwPws0tOSMVP92/RaOxmOJ59fES82SIKLGdZzScX2 zZ/g3Si8fgi699d0ybRuc8ng264wV7G8Wm1FCci77C1YVvZW5Ih5l1A3zONTrR7q d+gMJMISBHC0r+HwSUCQ3Q3wVu7AZCGZNjGe2ImcdXnrbUlaouwbf75JAfpcjPQj 1UIveysxW2NxdCsT0aD71+NZNLtx+qIykuTHK30GHbqbLGjdzkDfhBe+oYTqcUSU 8MHo7sJsx4JKPwlGEt+Av40nsW3ukyiU9sIdxjgeywgl/8c+DTUwn3gSm8Igc8TU ea02L4IAULmQf2Tl5Ks0ri2XRxHWHgY3ZmU7ZaLJRI62WD/k55qga2cmZGz9Saxc jcqSGvpDF93bEILX3xCoqNpEmknDOvFcDECQpFbzCoGa8Gg89MA34DRKA47caDzC CNRNx8qbim/EqMFk7TiqxD1NEZWyGz7dgrMOam0HO+FK1wSKKeOjC29dKhsSPmmV k4g5tqe6CBdASjvnC9QIxhhJFd93O6TvO445l2VNznKgRyWhVo+NGE6HW+BrJ2Q5 d5Eun2o9dh4a/FkI6PYUglBMSWV7bYwD9W5FrHyoxiZKrPkJmTsuhJylUUjfvfRu O6y92AZH9fpqGI4TdvlJX3atm5UHpIXLf5327KGRJtcKLkyU9KA= =/UST -----END PGP SIGNATURE-----