Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

SUSE: 2020:0722-1 Moderate: nghttp2 Software Security Update

suse
Calendar Grey March 19, 2020
Dist Suse Esm H88
This release tackles a notable vulnerability in libcurl, enhancing both software security and overall reliability.
An update that solves one vulnerability and has one errata is now available

Summary

This update for nghttp2 fixes the following issues: nghttp2 was update to version 1.40.0 (bsc#1166481) - lib: Add nghttp2_check_authority as public API - lib: Fix the bug that stream is closed with wrong error code - lib: Faster huffman encoding and decoding - build: Avoid filename collision of static and dynamic lib - build: Add new flag ENABLE_STATIC_CRT for Windows - build: cmake: Support building nghttpx with systemd - third-party: Update neverbleed to fix memory leak - nghttpx: Fix bug that mruby is incorrectly shared between backends - nghttpx: Reconnect h1 backend if it lost connection before sending headers - nghttpx: Returns 408 if backend timed out before sending headers - nghttpx: Fix request stal Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods

References

#1159003 #1166481

Cross- CVE-2019-18802

Affected Products:

SUSE Linux Enterprise Module for Open Buildservice Development Tools 15-SP1

SUSE Linux Enterprise Module for Basesystem 15-SP1

https://www.suse.com/security/cve/CVE-2019-18802.html

https://bugzilla.suse.com/1159003

https://bugzilla.suse.com/1166481

Announcement ID: SUSE-SU-2020:0722-1
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here