• [SECURITY] [DSA 5558-1] netty security update

    From Markus Koschany@21:1/5 to All on Sat Nov 18 18:00:01 2023
    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA512

    - ------------------------------------------------------------------------- Debian Security Advisory DSA-5558-1 security@debian.org https://www.debian.org/security/ Markus Koschany November 18, 2023 https://www.debian.org/security/faq
    - -------------------------------------------------------------------------

    Package : netty
    CVE ID : CVE-2023-34462 CVE-2023-44487
    Debian Bug : 1038947 1054234

    Two security vulnerabilities have been discovered in Netty, a Java NIO client/server socket framework.

    CVE-2023-34462

    It might be possible for a remote peer to send a client hello packet during
    a TLS handshake which lead the server to buffer up to 16 MB of data per
    connection. This could lead to a OutOfMemoryError and so result in a denial
    of service.

    CVE-2023-44487

    The HTTP/2 protocol allowed a denial of service (server resource
    consumption) because request cancellation can reset many streams quickly.
    This problem is also known as Rapid Reset Attack.

    For the oldstable distribution (bullseye), these problems have been fixed
    in version 1:4.1.48-4+deb11u2.

    For the stable distribution (bookworm), these problems have been fixed in version 1:4.1.48-7+deb12u1.

    We recommend that you upgrade your netty packages.

    For the detailed security status of netty please refer to
    its security tracker page at:
    https://security-tracker.debian.org/tracker/netty

    Further information about Debian Security Advisories, how to apply
    these updates to your system and frequently asked questions can be
    found at: https://www.debian.org/security/

    Mailing list: debian-security-announce@lists.debian.org
    -----BEGIN PGP SIGNATURE-----

    iQKTBAEBCgB9FiEErPPQiO8y7e9qGoNf2a0UuVE7UeQFAmVY5TZfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldEFD RjNEMDg4RUYzMkVERUY2QTFBODM1RkQ5QUQxNEI5NTEzQjUxRTQACgkQ2a0UuVE7 UeRHiBAAzFhW85Ho37J02wrSDVwhIMTsVjNO9lnA08Pswdohr9K1wxeCJ/hBAx97 UNIrjTxyOfCJWi1Kj5pITXEHBRu6w1fj/5y9yoMpAKEu+oGQroHbSf4CPmqP2Of0 eamkfbGx2Dh7Ug3qYxe+elcqRtU3gu8I8DYcWJnm2VpWq7/pbNJ+9iqtmMjhkPLH 1etLI/5HAkwpPimZSrHzcimn39gEVaIbZLc86ZBAoAPghc+iJR1JFHERmkEutWkB eAnL3kD1mr6F711eZvDfPaRfEUVorW67ZEpPX68MJExuYHNXd268EhQOhf/ZYv8g SUSBJuKw4w2OnL4fn8lhqnQgYHUVkcYBtfYii6E9bEVAIPoaT+4gvdSg9zkF6cza Da8SXkEY2ysaX+A24iVnCNMpCMSOUOxWsFFvkCcfi8A4HxGGqWzVOsBbDJKjktS1 g6FyeqWsGh9QG/CPYeMN7LB7lW1l2XzO6GQ9QR1rzU/whgUVxprkye5wx2BaQmom rrWVHBijH1cNWd1IbryAm+prduL1l/CNR0785ZPTjB3SsMFPCAtRHf9G976rqVs0 P3jGg+BdeDj+sd3EFHcHnNXQOaETgR07RWzngbjEkgmJYhB2B43hCQ2LwsNlHsmg O6otUI2k274IF9KHh0T1h1hopbUTU8VPy3dpcLloCzk7KiAv1RI=
    =4ExT
    -----END PGP SIGNATURE-----

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)