From 3d676b40cbd4b371e5b3145158aecd951b9eac59 Mon Sep 17 00:00:00 2001 From: CentOS Sources Date: Tue, 28 Apr 2020 04:50:17 -0400 Subject: [PATCH] import haproxy-1.8.23-3.el8 --- .gitignore | 2 +- .haproxy.metadata | 2 +- ...ix-handling-hpack-zero-bytes-overwrite.patch} | 0 SOURCES/haproxy.service | 1 + SPECS/haproxy.spec | 16 +++++++++++----- 5 files changed, 14 insertions(+), 7 deletions(-) rename SOURCES/{bz1819518-fix-handling-hpack-zero-bytes-overwrite.patch => bz1819519-fix-handling-hpack-zero-bytes-overwrite.patch} (100%) diff --git a/.gitignore b/.gitignore index ec3a304..b3c4ea2 100644 --- a/.gitignore +++ b/.gitignore @@ -1 +1 @@ -SOURCES/haproxy-1.8.15.tar.gz +SOURCES/haproxy-1.8.23.tar.gz diff --git a/.haproxy.metadata b/.haproxy.metadata index 8bda435..3d2a7e7 100644 --- a/.haproxy.metadata +++ b/.haproxy.metadata @@ -1 +1 @@ -ed7dfe5c7fc39fbb3b54e981eb709fd8bcd87042 SOURCES/haproxy-1.8.15.tar.gz +c1b6c1d4d5de55bcad874a0a7a02a94db5638b1f SOURCES/haproxy-1.8.23.tar.gz diff --git a/SOURCES/bz1819518-fix-handling-hpack-zero-bytes-overwrite.patch b/SOURCES/bz1819519-fix-handling-hpack-zero-bytes-overwrite.patch similarity index 100% rename from SOURCES/bz1819518-fix-handling-hpack-zero-bytes-overwrite.patch rename to SOURCES/bz1819519-fix-handling-hpack-zero-bytes-overwrite.patch diff --git a/SOURCES/haproxy.service b/SOURCES/haproxy.service index b32d00c..2b3a35e 100644 --- a/SOURCES/haproxy.service +++ b/SOURCES/haproxy.service @@ -8,6 +8,7 @@ ExecStartPre=/usr/sbin/haproxy -f $CONFIG -c -q ExecStart=/usr/sbin/haproxy -Ws -f $CONFIG -p $PIDFILE ExecReload=/usr/sbin/haproxy -f $CONFIG -c -q ExecReload=/bin/kill -USR2 $MAINPID +SuccessExitStatus=143 KillMode=mixed Type=notify diff --git a/SPECS/haproxy.spec b/SPECS/haproxy.spec index c3efda6..fe10158 100644 --- a/SPECS/haproxy.spec +++ b/SPECS/haproxy.spec @@ -7,8 +7,8 @@ %global _hardened_build 1 Name: haproxy -Version: 1.8.15 -Release: 6%{?dist}.1 +Version: 1.8.23 +Release: 3%{?dist} Summary: HAProxy reverse proxy for high availability environments Group: System Environment/Daemons @@ -23,7 +23,7 @@ Source4: %{name}.sysconfig Source5: halog.1 Patch0: bz1664533-fix-handling-priority-flag-HTTP2-decoder.patch -Patch1: bz1819518-fix-handling-hpack-zero-bytes-overwrite.patch +Patch1: bz1819519-fix-handling-hpack-zero-bytes-overwrite.patch BuildRequires: lua-devel BuildRequires: pcre-devel @@ -140,8 +140,14 @@ exit 0 %{_mandir}/man1/* %changelog -* Wed Apr 01 2020 Ryan O'Hara - 1.8.15-6.1 -- - Fix hapack zero byte input causing overwrite (CVE-2020-11100, #1819518) +* Wed Apr 01 2020 Ryan O'Hara - 1.8.23-3 +- Fix hapack zero byte input causing overwrite (CVE-2020-11100, #1819519) + +* Fri Dec 13 2019 Ryan O'Hara - 1.8.23-2 +- Consider exist status 143 as success (#1778844) + +* Mon Dec 02 2019 Ryan O'Hara - 1.8.23-1 +- Update to 1.8.23 (#1774745) * Fri Jul 19 2019 Ryan O'Hara - 1.8.15-6 - Add gating tests (#1682106)