Re: [ANNOUNCE] HTX vulnerability from 2.0 to 2.5-dev

2021-09-09 Thread Willy Tarreau
Hi Bjoern, On Thu, Sep 09, 2021 at 08:18:24PM +0200, bjun...@gmail.com wrote: > Hi, > > is HAProxy 2.0.x with "no option http-use-htx" also affected by > this vulnerability? No it's not. I thought I mentioned it but it's possible that I forgot it in the end. Regards, Willy

Re: [ANNOUNCE] HTX vulnerability from 2.0 to 2.5-dev

2021-09-09 Thread bjun...@gmail.com
Hi, is HAProxy 2.0.x with "no option http-use-htx" also affected by this vulnerability? Best regards / Mit freundlichen Grüßen Bjoern Am Di., 7. Sept. 2021 um 17:30 Uhr schrieb Willy Tarreau : > Hi everyone, > > Right after the previous announce of HTTP/2 vulnerabilities, a group > of security

Re: [ANNOUNCE] HTX vulnerability from 2.0 to 2.5-dev

2021-09-08 Thread Vincent Bernat
❦ 8 September 2021 09:02 +02, Artur: > Hello, > > Thank you. > > Could you please explain the version numbering differences between official > haproxy release and the linux distributions > packages ? > > For example : 2.4.4 (official) -> 2.4.3-2~bpo10+1 (Debian 10 > backports) 2.4.3-2~bpo10+1

Re: [ANNOUNCE] HTX vulnerability from 2.0 to 2.5-dev

2021-09-07 Thread Willy Tarreau
On Tue, Sep 07, 2021 at 09:39:41PM +0200, Vincent Bernat wrote: > ? 7 September 2021 17:27 +02, Willy Tarreau: > > > I'd like to thank the usual distro maintainers for having accepted to > > produce yet another version of their packages in a short time. Hopefully > > now we can all get back to

Re: [ANNOUNCE] HTX vulnerability from 2.0 to 2.5-dev

2021-09-07 Thread Vincent Bernat
❦ 7 September 2021 17:27 +02, Willy Tarreau: > I'd like to thank the usual distro maintainers for having accepted to > produce yet another version of their packages in a short time. Hopefully > now we can all get back to development! For Debian/Ubuntu, the fixed versions are: 2.4.3-2