-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Fri, 28 May 2021 12:28:20 +0200 Source: squid Architecture: source Version: 4.13-10 Distribution: unstable Urgency: medium Maintainer: Luigi Gangitano <luigi@debian.org> Changed-By: Santiago Garcia Mantinan <manty@debian.org> Closes: 988891 988892 988893 989043 Changes: squid (4.13-10) unstable; urgency=medium . [ Francisco Vilmar Cardoso Ruviaro ] * Add debian/patches/0007-CVE-2021-28651.patch to fix a Denial of Service in URN processing. (Closes: #988893, CVE-2021-28651) . [ Santiago Garcia Mantinan ] * Add patch to fix a Denial of Service in HTTP Response Processing. Fixes: CVE-2021-28662. Closes: #988891. * Add patch to fix a Denial of Service issue in Cache Manager. Fixes: CVE-2021-28652. Closes: #988892. * Add patch to fix Multiple Issues in HTTP Range header. Fixes: CVE-2021-31806 CVE-2021-31807 CVE-2021-31808. Closes: #989043. * Add patch to fix a Denial of Service in HTTP Response processing. Fixes: GHSA-572g-rvwr-6c7f. Checksums-Sha1: 2420289a0ac276e96c81cb8ed0bae43a5f0bd599 2956 squid_4.13-10.dsc 192286b7bf7d54028c3fc8304463f110aee80ec0 52936 squid_4.13-10.debian.tar.xz f1878431898e211bc1a65e40d3e6e4f23408ab4d 7800 squid_4.13-10_source.buildinfo Checksums-Sha256: c3fcfcb6378a900ea78a76d76d1eba0425646d2236464c7ee7f61ef9fbfdd603 2956 squid_4.13-10.dsc 120f8b867ec6c8abfeada7b4db6ef401c3a92e55e177a1a9d5bc1067a140270c 52936 squid_4.13-10.debian.tar.xz b5417b705db391002ffcfe118023cdc99c4f1acdee2b38d031271117656527ab 7800 squid_4.13-10_source.buildinfo Files: a902743425c59c5e16e919ccf5d44c53 2956 web optional squid_4.13-10.dsc bb6425a65ef6b7b87b464ca49816caaa 52936 web optional squid_4.13-10.debian.tar.xz f0911c3661b9c5ef099ec183e7777e58 7800 web optional squid_4.13-10_source.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEBqPldg9hG0uxqQ5ouGiMo9h21aMFAmCw3lMACgkQuGiMo9h2 1aNHohAAg6pZUqXob2S0DhCGHO8wXO5ZmHyE46Kc5XvKevEejyP9ouodfNwxKCTL OegDQjqYt2FQIENqir09nR0DJflUjSVdInmCBapomcoyS0VqBcka7mQ6ltXwfY7K hy93OW3/O5oxMZFlIAvuwqC+06A39eplCOy5aOmVgRt4QS+6SDp85tSXDrBEHZI+ 69g928MFrVw+hHYtdIzZDAIS8pYa3aSha9dKjwlgghSWieL8eW2+fuwa6mlZhmt5 pVAGRRWc6CG3mLA/YcHeEEv1G67oioA41qZB7tA70UKREO+we8LaYgP7o2RNqA8M lYBgd6zD/BUoKXmif7tQVq2sluFGtD//xaJ3L3xsL4hs1g2f37Zf7KDPJHJdXZ9U k41RdPVIoy0VmeuQ6alYmmsJ+nbGuEIrtc4IqCxL26nF1p/cUEgin97nBgO2hfbh /wYb+DSUI+fmg58nhSoqIZVEREwAwsnJVfwNkwP629Wi+AziFMfhatkldm/uL/DZ +nZ54DyhOumd34cTi2Muy5vG5FRr3EgdHyzUz60YmVYzH4jyqR7ykL5D2/7ZS/5z 1cXZaTNTafINqibUliCsIS3RJNDragnfzGgTPsRSSoP9WkBg/BDu7pOjEdiG592S FAHwtWL9g3vQiD3q58cUOis5cd6LYK4Cc2w+9rqq0SBFurKPgZk= =3vsv -----END PGP SIGNATURE-----