-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Tue, 28 Jun 2022 19:03:13 +0200 Source: matrix-synapse Architecture: source Version: 1.61.0-1~bpo11+3 Distribution: bullseye-backports Urgency: medium Maintainer: Matrix Packaging Team <pkg-matrix-maintainers@lists.alioth.debian.org> Changed-By: Andrej Shadura <andrewsh@debian.org> Changes: matrix-synapse (1.61.0-1~bpo11+3) bullseye-backports; urgency=medium . * SECURITY ISSUE: GHSA-22p3-qrh9-cx32 / CVE-2022-31052. Synapse instances with the url_preview_enabled homeserver config option set to true are affected. URL previews of some web pages can lead to unbounded recursion, causing the request to either fail, or in some cases crash the running Synapse process. Checksums-Sha1: 39017e51d01e357cae42642715fafe63b3fd78a3 2632 matrix-synapse_1.61.0-1~bpo11+3.dsc a0f145a0405708a776768c8633d700352721ae2c 112160 matrix-synapse_1.61.0-1~bpo11+3.debian.tar.xz Checksums-Sha256: bb2d40611c3867486cd4c321c8fd554bbade4d42bba4994f233c7de228a4d765 2632 matrix-synapse_1.61.0-1~bpo11+3.dsc b6c84095fefebea5d3be8d9766af0cbde7697cee05ef99bd58cae3fb31f9d8ed 112160 matrix-synapse_1.61.0-1~bpo11+3.debian.tar.xz Files: 8655bc3fecbd8d726718877d5010bf1b 2632 net optional matrix-synapse_1.61.0-1~bpo11+3.dsc 18f581f58d4eacd1f8cdc355d2c20059 112160 net optional matrix-synapse_1.61.0-1~bpo11+3.debian.tar.xz -----BEGIN PGP SIGNATURE----- iHUEARYIAB0WIQSD3NF/RLIsyDZW7aHoRGtKyMdyYQUCYrs0tAAKCRDoRGtKyMdy YQ1KAQCQ/3NvZBAl1KScpcYar+YcvcJSTNmdkfL0U4A3VPjXLgEAtB9utSU1nHJp PUpDJnUYpuDXNHrkTxDUoZy8dTUKJAA= =vzYc -----END PGP SIGNATURE-----