This update for varnish fixes the following issues:
varnish was updated to release 7.1.0 [boo#1195188] [CVE-2022-23959]
* VCL: It is now possible to assign a BLOB value to a BODY variable, in
addition to STRING as before.
* VMOD: New STRING strftime(TIME time, STRING format) function for UTC
formatting.
Update to release 6.6.1
* CVE-2021-36740: Fix an HTTP/2.0 request smuggling vulnerability.
[boo#1188470]
Update to release 6.6.0:
* The ban_cutoff parameter now refers to the overall length of the ban
list, including completed bans, where before only non-completed
(???active???) bans were counted towards ban_cutoff.
* Body bytes accounting has been fixed to always represent the number of
body bytes moved on the wire, exclusive of protocol-specific overhead
like HTTP/1 chunked encoding or HTTP/2 framing.
* The connection close reason has been fixed to properly report
SC_RESP_CLOSE where previously only...
Read the Full AdvisoryPatch Instructions:
To install this openSUSE Security Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Backports SLE-15-SP3:
zypper in -t patch openSUSE-2022-148=1
- openSUSE Backports SLE-15-SP3 (aarch64 i586 ppc64le s390x x86_64):
libvarnishapi3-7.1.0-bp153.2.3.1
varnish-7.1.0-bp153.2.3.1
varnish-devel-7.1.0-bp153.2.3.1
https://www.suse.com/security/cve/CVE-2021-36740.html
https://www.suse.com/security/cve/CVE-2022-23959.html
https://bugzilla.suse.com/1181400
https://bugzilla.suse.com/1188470
https://bugzilla.suse.com/1195188
Get the latest Linux and open source security news straight to your inbox.