Format: 1.8
Date: Mon, 27 Nov 2023 08:31:07 +0100
Source: rabbitmq-server
Binary: rabbitmq-server
Architecture: all
Version: 3.10.8-3
Distribution: sid
Urgency: high
Maintainer: Debian OpenStack <team+openstack@tracker.debian.org>
Changed-By: Thomas Goirand <zigo@debian.org>
Description:
rabbitmq-server - AMQP server written in Erlang
Closes: 1056723
Changes:
rabbitmq-server (3.10.8-3) unstable; urgency=high
.
* CVE-2023-46118: Denial of Service by publishing large messages over the
HTTP API. Applied upstream patches that introduce a limit of 10MB:
- Reduce_default_HTTP_API_request_body_size_limit_to_10_MiB.patch
- Introduce_HTTP_request_body_limit_for_definition_uploads.patch
(Closes: #1056723).
Checksums-Sha1:
35d9195b0cca39108b308e2bbf8d29221a3d332b 14930352 rabbitmq-server_3.10.8-3_all.deb
89fb397ce16c595c7bae4d8277e5077d43c17a0f 7767 rabbitmq-server_3.10.8-3_arm64.buildinfo
Checksums-Sha256:
bfa3f6aa2e31695539170a294dde0fc860c6fa7624db8f52ee162f6bd3534ba5 14930352 rabbitmq-server_3.10.8-3_all.deb
4c2bc0bff711b5acb58a98871859027a3be12fdfcf3f6e8a13b8f1d532e2c25b 7767 rabbitmq-server_3.10.8-3_arm64.buildinfo
Files:
92f2127fe4f72f440c55b8d2906f7a11 14930352 net optional rabbitmq-server_3.10.8-3_all.deb
8a645ea5ad44e7e59ac09e545fbadb60 7767 net optional rabbitmq-server_3.10.8-3_arm64.buildinfo