ELA-670-1 http-parser security update

HTTP request smuggling vulnerability

2022-08-31
Packagehttp-parser
Version2.1-2+deb8u1 (jessie), 2.1-2+deb9u1 (stretch)
Related CVEs CVE-2020-8287


There was a potential HTTP request smuggling vulnerability in http-parser, a popular library for parsing HTTP messages.



For Debian 8 jessie, these problems have been fixed in version 2.1-2+deb8u1.

For Debian 9 jessie, these problems have been fixed in version 2.1-2+deb9u1.

We recommend that you upgrade your http-parser packages.

Further information about Extended LTS security advisories can be found in the dedicated section of our website.