CHANGES and release notes for CVE-2022-2881 [GL #3493]
This commit is contained in:
7
CHANGES
7
CHANGES
@@ -6,7 +6,12 @@
|
||||
|
||||
5959. [placeholder]
|
||||
|
||||
5958. [placeholder]
|
||||
5958. [security] When an HTTP connection was reused to get
|
||||
statistics from the stats channel, and zlib
|
||||
compression was in use, each successive
|
||||
response sent larger and larger blocks of memory,
|
||||
potentially reading past the end of the allocated
|
||||
buffer. (CVE-2022-2881) [GL #3493]
|
||||
|
||||
5957. [security] Prevent excessive resource use while processing large
|
||||
delegations. (CVE-2022-2795) [GL #3394]
|
||||
|
||||
@@ -24,6 +24,11 @@ Security Fixes
|
||||
Bremler-Barr & Shani Stajnrod from Reichman University for bringing
|
||||
this vulnerability to our attention. :gl:`#3394`
|
||||
|
||||
- When an HTTP connection was reused to request statistics from the
|
||||
stats channel, the content length of successive responses could grow
|
||||
in size past the end of the allocated buffer. This has been fixed.
|
||||
(CVE-2022-2881) :gl:`#3493`
|
||||
|
||||
Known Issues
|
||||
~~~~~~~~~~~~
|
||||
|
||||
|
||||
Reference in New Issue
Block a user