-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Wed, 27 Nov 2019 17:07:57 +0100 Source: haproxy Architecture: source Version: 1.8.19-1+deb10u1 Distribution: buster-security Urgency: high Maintainer: Debian HAProxy Maintainers <haproxy@tracker.debian.org> Changed-By: Vincent Bernat <bernat@debian.org> Changes: haproxy (1.8.19-1+deb10u1) buster-security; urgency=high . * Apply two patches around HTTP/2 header validation allowing an attacker to use a CRLF inside an HTTP header. Fix CVE-2019-19330. Checksums-Sha1: 6a39dc15857ef706931af8b159f32c0e15af3277 2319 haproxy_1.8.19-1+deb10u1.dsc 0731f1274a4028019c1c2753fff3cd69a6c1628f 2080757 haproxy_1.8.19.orig.tar.gz bdbafcb379e10f88ac984033046be3e993283d2d 70972 haproxy_1.8.19-1+deb10u1.debian.tar.xz 049628912f755552fe154075e4d79582bb99194a 8502 haproxy_1.8.19-1+deb10u1_amd64.buildinfo Checksums-Sha256: 0a6fbfed355ea10dbed24a5fa9f3f36b1a01dd2ba756d090b4094e9cd214fa50 2319 haproxy_1.8.19-1+deb10u1.dsc 64f5fbfd4e09ffeaf26cb6667398ba780704a14e96e60000caa8bf69962ba734 2080757 haproxy_1.8.19.orig.tar.gz df7397f6de7d8184b26df6caff55fc16ee598617f9bfab7ba7b4919795ac5078 70972 haproxy_1.8.19-1+deb10u1.debian.tar.xz 0e4a6e7ce2f0590552e71aee9a7890fb23e25fc0d382612d677faa45ac7db8c4 8502 haproxy_1.8.19-1+deb10u1_amd64.buildinfo Files: 2a189a0982fa5ed380390a5a5300a059 2319 net optional haproxy_1.8.19-1+deb10u1.dsc 713d995d8b072a4ca8561ab389b82b7a 2080757 net optional haproxy_1.8.19.orig.tar.gz e90c4779170a706d6f030212d81a9f68 70972 net optional haproxy_1.8.19-1+deb10u1.debian.tar.xz 86cd5b977f6c0e5570368b9e152c870d 8502 net optional haproxy_1.8.19-1+deb10u1_amd64.buildinfo -----BEGIN PGP SIGNATURE----- iQJGBAEBCAAwFiEErvI0h2bzccaJpzYAlaQv6DU1JfkFAl3eoPUSHGJlcm5hdEBk ZWJpYW4ub3JnAAoJEJWkL+g1NSX5FIIP/RPNLxRlrkBJyj/yd5l+diVQFHoY/YVM 8MLG8v3Bz3uHpp7mOu1jcbkK4qz7hIzKESuJPwjN8p8+O/EYDLgg+hsX/FxlMpmI YPQ3urtsinDSlwdmGqUsrXoU/j3uh7/AmwofDUClQ7PQpJvmxSci1KBIwDSuAi8x AeHE28yuwSlNFUmJj5JqvY70veIJLZ9JbwGAooHIiqwiFKYfFvLbUX0TZE3e323H /0Gd9D/U502HckC1wSW+7t8fCuyNX6M9MlRp2siYvJ1dxdn8a1PgS/ldxEli4Hjg B1+tIv44+jlOab07I3Hlpc8NZmPTiYTW573yoOAVaxEgLoAlNXA84MNp0fLXZnkF wKMwn26qm/oHGfnx0wv988+GPaR80lRZ1t5MkRQoDS+rjmd3If3z0nIFQ/tFaxYT 5mRNjwW886rSFkT4KmUQGMJuZqn18Va9hF67zXhChn5jdYLdp3Bl0hgmeMS4VoZb O/3Eu6dY2iWb5tHxRGvg8SRqeEPkb25nJ7KoM2p5jlkvMRAlePmIs/dVwIVXK7Og OWiPzYScu0RwNIsleNIO8JDFNJdQOddfSnf0MBVsBLCc3GzhT/GYfAO6sBl7xG4j e4+PqNKKB3o2nfOzYMtvkjGR8EuJlKOe3aCpVtWh5IisIYROC56nxPXfwcgQgWMV vnn7x860brYy =MOIF -----END PGP SIGNATURE-----