From df17da57cf07136bd5a63d0e10c2df2f9684c0fc Mon Sep 17 00:00:00 2001 From: Ryan O'Hara Date: Wed, 13 Oct 2021 11:31:44 -0500 Subject: [PATCH] Update to 2.4.7 Resolves: (#1966688, #1998196, #1998198, #1998200, #2000621) --- haproxy.spec | 9 ++++++++- sources | 2 +- 2 files changed, 9 insertions(+), 2 deletions(-) diff --git a/haproxy.spec b/haproxy.spec index 018bf1f..98ac95c 100644 --- a/haproxy.spec +++ b/haproxy.spec @@ -7,7 +7,7 @@ %global _hardened_build 1 Name: haproxy -Version: 2.4.3 +Version: 2.4.7 Release: 1%{?dist} Summary: HAProxy reverse proxy for high availability environments @@ -134,6 +134,13 @@ exit 0 %{_mandir}/man1/* %changelog +* Wed Oct 13 2021 Ryan O'Hara - 2.4.7-1 +- Update to 2.4.7 (#1966688) +- Fix domain parts in :scheme and :path fields (CVE-2021-39240, #1998196) +- Fix spaces in the :method field (CVE-2021-39241, #1998198) +- Fix mismatch between :authority and Host fields (CVE-2021-39242, #1998200) +- Fix request smuggling attack or response splitting (CVE-2021-40346, #2000621) + * Tue Aug 17 2021 Ryan O'Hara - 2.4.3-1 - Update to 2.4.3 (#1966688) diff --git a/sources b/sources index 583cd71..395c84e 100644 --- a/sources +++ b/sources @@ -1 +1 @@ -SHA512 (haproxy-2.4.3.tar.gz) = 4ee11b6fd4c76d6ec3060f26bda67a8916c4f52bf1a800b921e04d2cec78b47b8b1343081935bc211f1e081b92db88130ec365161460b35ab88aa982917f82ee +SHA512 (haproxy-2.4.7.tar.gz) = 7ad8e9bd506d6f5919ff9ea97b08a4ec283bf580baefc7945632ea5a88a73081bb3d82586855efc7b7b9194558f12823c26b7a7498ac08c3efc158ea6583ec9f