Bug#888786: pound: CVE-2016-10711

2018-02-12 Thread Markus Koschany
Control: tags -1 patch Dear maintainer, please find attached a patch to fix CVE-2016-10711. This is simply the security relevant diff between version 2.7 and 2.8a. Regards, Markus diff -Nru pound-2.7/debian/changelog pound-2.7/debian/changelog --- pound-2.7/debian/changelog 2017-02-19

Bug#888786: pound: CVE-2016-10711

2018-01-29 Thread Salvatore Bonaccorso
Source: pound Version: 2.6-6 Severity: important Tags: security upstream Hi, the following vulnerability was published for pound. CVE-2016-10711[0]: | Apsis Pound before 2.8a allows request smuggling via crafted headers, a | different vulnerability than CVE-2005-3751. If you fix the