package/haproxy: security bump to version 2.4.4
authorPeter Korsgaard <peter@korsgaard.com>
Fri, 10 Sep 2021 14:02:40 +0000 (16:02 +0200)
committerYann E. MORIN <yann.morin.1998@free.fr>
Fri, 10 Sep 2021 20:03:15 +0000 (22:03 +0200)
commit36c115d0bc9dca5ddfc5e054f0a73691a08ef4f1
tree40fd8720c288de24971fb891d049cc74b146d3f1
parent05125113fcb93d990ecb9395224d3fda5d911dc4
package/haproxy: security bump to version 2.4.4

Fixes the following security issues:

- CVE-2021-40346: An integer overflow exists in HAProxy 2.0 through 2.5 in
  the htx_add_header() can be exploited to perform an HTTP request smuggling
  attack, allowing an attacker to bypass all configured http-request HAProxy
  ACLs and possibly other ACLs.

For more details, see the advisory:
https://www.mail-archive.com/haproxy@formilux.org/msg41114.html

Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
Signed-off-by: Yann E. MORIN <yann.morin.1998@free.fr>
package/haproxy/haproxy.hash
package/haproxy/haproxy.mk