-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sat, 16 Oct 2021 21:06:46 +0200 Source: nghttp2 Architecture: source Version: 1.18.1-1+deb9u2 Distribution: stretch-security Urgency: medium Maintainer: Dave Beckett <dajobe@debian.org> Changed-By: Anton Gladky <gladk@debian.org> Changes: nghttp2 (1.18.1-1+deb9u2) stretch-security; urgency=medium . * Non-maintainer upload by the LTS Security Team. * Fix CVE-2020-11080. Implement max settings option to mitigate denial of service. * Fix CVE-2018-1000168. Avoid segmentation fault. Checksums-Sha1: 76dece25c70bf650766f95b79aaba9710c1b0744 2632 nghttp2_1.18.1-1+deb9u2.dsc 603bb9944d335c25226b2900733be55057950e07 1780766 nghttp2_1.18.1.orig.tar.bz2 d4cf94cf8134472856d3430dceb4d6dabb94b0df 15672 nghttp2_1.18.1-1+deb9u2.debian.tar.xz d36d0c655ff151e637d0e64849399fbd779d2098 6476 nghttp2_1.18.1-1+deb9u2_source.buildinfo Checksums-Sha256: f6e631ce9d549e553ce95d74221397831da2c6ec5c2149804e2ef6d16b0197f9 2632 nghttp2_1.18.1-1+deb9u2.dsc 5d8bb930eb90c552ec836c7b1862406b69cafcda5520bf266c8f5d914d9b447c 1780766 nghttp2_1.18.1.orig.tar.bz2 ff8ac30f419a5496735e97f4dc9ed6a1e26358077ba04a5849c3b67c1d814e9c 15672 nghttp2_1.18.1-1+deb9u2.debian.tar.xz 5ff6314425b7ef1018fe23110d5f24dbaceb6ce81a9ddec210399d71ceaee68c 6476 nghttp2_1.18.1-1+deb9u2_source.buildinfo Files: 129ecbe852ea5557d7e20ee5cf75e887 2632 httpd optional nghttp2_1.18.1-1+deb9u2.dsc 9c7afde465804aac1dd4acf975559d25 1780766 httpd optional nghttp2_1.18.1.orig.tar.bz2 7a9757136c682af38de2e2394a5d354a 15672 httpd optional nghttp2_1.18.1-1+deb9u2.debian.tar.xz 70f68107175161846ea33c4a92cb421e 6476 httpd optional nghttp2_1.18.1-1+deb9u2_source.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEu71F6oGKuG/2fnKF0+Fzg8+n/wYFAmFrOLwACgkQ0+Fzg8+n /wbAxA//ciVJLtJSEGRX8p4uzByngi3StiM7AMozFT4SMkbBrX3pDl/M3an17+vo yYvmIMJe+jDPoghfRFpfnMeK5I3Fl7yubfcu5B1FufHVW+x0ctC+IzKmFrFFEzMu CNT/Ir8l1R7cbjfGk8AHUwDX55t+z7W0clNrBASB2vDbIvc5SvrOnJjr3sSlIW0W WiSm0kZLMmL6cLkXYZ/HoVU9837+06UY0H1+TcZ9A1wHZFPIJ7PVc+qoq1/lUkVw KUZuqh79lGca1OXrPs/0TjVXzlahI1OZOJXx24ASutBwzq+/Y28pidn/HgLvVaUi SFY7fN1nKtKTwbtDywFB/eRP+Xswc4UuYM+t7CBeeMXFoixLi+AU6knXHeiYhIn0 jacjkT/VirJN+KVuJ3m1jcLEO706PlnWdHV6cbltx3IhrThuiI8BuuPHj6oA/YWo NvuIaNVExkPQzfgXrsSndddrbReh5lWQS6ksHo81S6jAYaP8IGaGk1Iwm8Dg4Lh7 eCiOUnBWHM91N6Yj8UlE5BwZ5CMA9soNuNi53rZmIT6wRMbSVn1HSIc53L1w4YMu 437J+/ltCrTj/EA1txbvUBX7GU6zBmsqUr7baMwW6BGbKnhhrKdn8GVgE0Ys2S1q pAij/YqzPFBwbUviR1GWF1fFu8CrmnmEMLiOkRaH4ueLPZooUa0= =oo/n -----END PGP SIGNATURE-----