HomeFreeBSD

www/h2o: patch for HTTP2 rapid reset attack, deprecate

Description

www/h2o: patch for HTTP2 rapid reset attack, deprecate

  • downstream dnsdist project has backported a fix for this specific issue
  • deprecation is still planned, and port should not be considered secure
  • pet port in line with www/h2o-devel

See https://github.com/h2o/h2o/pull/3293 for further details

Obtained from: Remi Gacogne <remi.gacogne@powerdns.com>
Security: CVE-2023-44487
Security: https://github.com/h2o/h2o/security/advisories/GHSA-2m7v-gc89-fjqf

(cherry picked from commit dcd7c23bd4dd801ec1a5a415612a66cb97032dde)

Details

Provenance
dchAuthored on Oct 28 2023, 10:13 PM
Parents
R11:6d27c97e0391: x11/hyprpicker: update to 0.2.0
Branches
Unknown
Tags
Unknown