stable

llhttp-9.1.3-1.el9 and python-aiohttp-3.9.1-1.el9

FEDORA-EPEL-2023-4b1b8b8b25 created by music 2 years ago for Fedora EPEL 9

Security fix for CVE-2023-47627, CVE-2023-49081, CVE-2023-49082.

https://pagure.io/epel/issue/262

python-aiohttp 3.9.1 (2023-11-26)

https://github.com/aio-libs/aiohttp/blob/v3.9.1/CHANGES.rst#391-2023-11-26

python-aiohttp 3.9.0 (2023-11-17)

https://github.com/aio-libs/aiohttp/blob/v3.9.1/CHANGES.rst#390-2023-11-18

python-aiohttp 3.8.6 (2023-10-07)

https://github.com/aio-libs/aiohttp/blob/v3.9.1/CHANGES.rst#386-2023-10-07


llhttp 9.1.3

Fixes

  • Restart the parser on HTTP 100
  • Fix chunk extensions quoted-string value parsing
  • Fix lenient_flags truncated on reset
  • Fix chunk extensions’ parameters parsing when more then one name-value pair provided

llhttp 9.1.2

What's Changed

  • Fix HTTP 1xx handling

llhttp 9.1.1

What's Changed

  • feat: Expose new lenient methods

llhttp 9.1.0

What's Changed

  • New lenient flag to make CR completely optional
  • New lenient flag to have spaces after chunk header

This update's test gating status has been changed to 'waiting'.

2 years ago

This update has been submitted for testing by bodhi.

2 years ago

This update's test gating status has been changed to 'ignored'.

2 years ago

This update has been pushed to testing.

2 years ago

This update can be pushed to stable now if the maintainer wishes

2 years ago

This update has been submitted for stable by music.

2 years ago

This update has been pushed to stable.

2 years ago

Please log in to add feedback.

Metadata
Type
security
Severity
high
Karma
0
Signed
Content Type
RPM
Test Gating
Autopush Settings
Unstable by Karma
-3
Stable by Karma
disabled
Stable by Time
disabled
Dates
submitted
2 years ago
in testing
2 years ago
in stable
2 years ago
BZ#2250614 CVE-2023-47627 python-aiohttp: numerous issues in HTTP parser with header parsing [epel-all]
0
0
BZ#2252239 TRIAGE CVE-2023-49081 python-aiohttp: aiohttp: HTTP request modification [epel-all]
0
0
BZ#2252250 TRIAGE CVE-2023-49082 python-aiohttp: aiohttp: CRLF injection if user controls the HTTP method using aiohttp client [epel-all]
0
0

Automated Test Results