DSA-5153-1 trafficserver -- security update

Related Vulnerabilities: CVE-2021-37147   CVE-2021-37148   CVE-2021-37149   CVE-2021-38161   CVE-2021-44040   CVE-2021-44759  

Several vulnerabilities were discovered in Apache Traffic Server, a reverse and forward proxy server, which could result in HTTP request smuggling or MITM attacks. For the oldstable distribution (buster), these problems have been fixed in version 8.0.2+ds-1+deb10u6. For the stable distribution (bullseye), these problems have been fixed in version 8.1.1+ds-1.1+deb11u1. We recommend that you upgrade your trafficserver packages. For the detailed security status of trafficserver please refer to its security tracker page at: https://security-tracker.debian.org/tracker/trafficserver

Debian Security Advisory

DSA-5153-1 trafficserver -- security update

Date Reported:
30 May 2022
Affected Packages:
trafficserver
Vulnerable:
Yes
Security database references:
In Mitre's CVE dictionary: CVE-2021-37147, CVE-2021-37148, CVE-2021-37149, CVE-2021-38161, CVE-2021-44040, CVE-2021-44759.
More information:

Several vulnerabilities were discovered in Apache Traffic Server, a reverse and forward proxy server, which could result in HTTP request smuggling or MITM attacks.

For the oldstable distribution (buster), these problems have been fixed in version 8.0.2+ds-1+deb10u6.

For the stable distribution (bullseye), these problems have been fixed in version 8.1.1+ds-1.1+deb11u1.

We recommend that you upgrade your trafficserver packages.

For the detailed security status of trafficserver please refer to its security tracker page at: https://security-tracker.debian.org/tracker/trafficserver