|
|
Subscribe / Log in / New account

Slackware alert SSA:2023-284-02 (nghttp2)

From:  Slackware Security Team <security@slackware.com>
To:  slackware-security@slackware.com
Subject:  [slackware-security] nghttp2 (SSA:2023-284-02)
Date:  Tue, 10 Oct 2023 23:45:34 -0700
Message-ID:  <alpine.LNX.2.02.2310102345180.21858@connie.slackware.com>

-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 [slackware-security] nghttp2 (SSA:2023-284-02) New nghttp2 packages are available for Slackware 15.0 and -current to fix a security issue. Here are the details from the Slackware 15.0 ChangeLog: +--------------------------+ patches/packages/nghttp2-1.57.0-i586-1_slack15.0.txz: Upgraded. This release has a fix to mitigate the HTTP/2 Rapid Reset vulnerability. For more information, see: https://github.com/nghttp2/nghttp2/security/advisories/GH... https://www.cve.org/CVERecord?id=CVE-2023-44487 (* Security fix *) +--------------------------+ Where to find the new packages: +-----------------------------+ Thanks to the friendly folks at the OSU Open Source Lab (http://osuosl.org) for donating FTP and rsync hosting to the Slackware project! :-) Also see the "Get Slack" section on http://slackware.com for additional mirror sites near you. Updated package for Slackware 15.0: ftp://ftp.slackware.com/pub/slackware/slackware-15.0/patc... Updated package for Slackware x86_64 15.0: ftp://ftp.slackware.com/pub/slackware/slackware64-15.0/pa... Updated package for Slackware -current: ftp://ftp.slackware.com/pub/slackware/slackware-current/s... Updated package for Slackware x86_64 -current: ftp://ftp.slackware.com/pub/slackware/slackware64-current... MD5 signatures: +-------------+ Slackware 15.0 package: 929c1ce292b851c1d574b0dd81a8aaae nghttp2-1.57.0-i586-1_slack15.0.txz Slackware x86_64 15.0 package: 3ec9af02aeb83c9de0df75fcb7859466 nghttp2-1.57.0-x86_64-1_slack15.0.txz Slackware -current package: e8e7d34aca72bcc7392617db1ffef37d n/nghttp2-1.57.0-i586-1.txz Slackware x86_64 -current package: 591e23a6c50d8644653e90bb1a22c34f n/nghttp2-1.57.0-x86_64-1.txz Installation instructions: +------------------------+ Upgrade the package as root: # upgradepkg nghttp2-1.57.0-i586-1_slack15.0.txz +-----+ Slackware Linux Security Team http://slackware.com/gpg-key security@slackware.com +------------------------------------------------------------------------+ | To leave the slackware-security mailing list: | +------------------------------------------------------------------------+ | Send an email to majordomo@slackware.com with this text in the body of | | the email message: | | | | unsubscribe slackware-security | | | | You will get a confirmation message back containing instructions to | | complete the process. Please do not reply to this email address. | +------------------------------------------------------------------------+ -----BEGIN PGP SIGNATURE----- iEYEARECAAYFAmUmQ+4ACgkQakRjwEAQIjNr+gCdFqgdnPsw5NY4Py4nxiRBP1/1 6jcAn3iAoVa0aZnEFVw99agchgjf4Dx5 =xEaM -----END PGP SIGNATURE-----


to post comments


Copyright © 2025, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds