--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2018-cec96a9c41
2018-04-21 03:38:52.949232
--------------------------------------------------------------------------------
Name : nghttp2
Product : Fedora 27
Version : 1.31.1
Release : 1.fc27
URL :
https://nghttp2.org/
Summary : Experimental HTTP/2 client, server and proxy
Description :
This package contains the HTTP/2 client, server and proxy programs.
--------------------------------------------------------------------------------
Update Information:
- update to the latest upstream release (fixes CVE-2018-1000168)
--------------------------------------------------------------------------------
ChangeLog:
* Fri Apr 13 2018 Kamil Dudka <kdudka(a)redhat.com> 1.31.1-1
- update to the latest upstream release (fixes CVE-2018-1000168)
* Thu Mar 15 2018 Kamil Dudka <kdudka(a)redhat.com> 1.31.0-2
- make fetch-ocsp-response use Python 3
* Tue Feb 27 2018 Kamil Dudka <kdudka(a)redhat.com> 1.31.0-1
- update to the latest upstream release
* Mon Feb 19 2018 Kamil Dudka <kdudka(a)redhat.com> 1.30.0-3
- add explicit BR for the gcc-c++ compiler
* Thu Feb 8 2018 Fedora Release Engineering <releng(a)fedoraproject.org> - 1.30.0-2
- Rebuilt for
https://fedoraproject.org/wiki/Fedora_28_Mass_Rebuild
* Mon Feb 5 2018 Kamil Dudka <kdudka(a)redhat.com> 1.30.0-1
- update to the latest upstream release
* Sat Feb 3 2018 Igor Gnatenko <ignatenkobrain(a)fedoraproject.org> - 1.29.0-2
- Switch to %ldconfig_scriptlets
* Tue Dec 19 2017 Kamil Dudka <kdudka(a)redhat.com> 1.29.0-1
- update to the latest upstream release
* Sun Nov 26 2017 Kamil Dudka <kdudka(a)redhat.com> 1.28.0-1
- update to the latest upstream release
* Wed Oct 25 2017 Kamil Dudka <kdudka(a)redhat.com> 1.27.0-1
- update to the latest upstream release
* Wed Sep 20 2017 Kamil Dudka <kdudka(a)redhat.com> 1.26.0-1
- update to the latest upstream release
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1566990 - CVE-2018-1000168 nghttp2: Null pointer dereference when too large
ALTSVC frame is received [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=1566990
[ 2 ] Bug #1566772 - nghttp2-1.31.1 is available
https://bugzilla.redhat.com/show_bug.cgi?id=1566772
--------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2018-cec96a9c41' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------