-------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2021-cf7585f0ca 2021-07-25 01:00:30.686549 --------------------------------------------------------------------------------
Name : varnish Product : Fedora 34 Version : 6.5.2 Release : 1.fc34 URL : https://www.varnish-cache.org/ Summary : High-performance HTTP accelerator Description : This is Varnish Cache, a high-performance HTTP accelerator.
Varnish Cache stores web pages in memory so web servers don���t have to create the same web page over and over again. Varnish Cache serves pages much faster than any application server; giving the website a significant speed up.
Documentation wiki and additional information about Varnish Cache is available on: https://www.varnish-cache.org/
-------------------------------------------------------------------------------- Update Information:
New upstream release. This is a security release for CVE-2021-36740 aka VSV00007 -------------------------------------------------------------------------------- ChangeLog:
* Fri Jul 16 2021 Ingvar Hagelund ingvar@redpill-linpro.com 6.5.2-1 - New upstream release - Includes fix for VSV00007 aka CVE-2021-36740, bz#1982412 -------------------------------------------------------------------------------- References:
[ 1 ] Bug #1982412 - CVE-2021-36740 varnish: HTTP/2 request smuggling attack via a large Content-Length header for a POST request [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1982412 --------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-cf7585f0ca' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys --------------------------------------------------------------------------------
package-announce@lists.fedoraproject.org