Re: ATS is vulnerable to a HTTP/2 attack with empty frames

2019-08-20 Thread Bryan Call
This also affects 7.1.7 and 8.0.4. I updated the version range below. -Bryan > On Aug 20, 2019, at 11:36 AM, Bryan Call wrote: > > Description: > ATS is vulnerable to a HTTP/2 attack with empty frames > > CVE: > CVE-2019-9518 Empty Frames Flood > > Reported By: > Piotr Sikora > > Vendor: >

ATS is vulnerable to a HTTP/2 attack with empty frames

2019-08-20 Thread Bryan Call
Description: ATS is vulnerable to a HTTP/2 attack with empty frames CVE: CVE-2019-9518 Empty Frames Flood Reported By: Piotr Sikora Vendor: The Apache Software Foundation Version Affected: ATS 6.0.0 to 6.2.3 ATS 7.0.0 to 7.1.6 ATS 8.0.0 to 8.0.3 Mitigation: Turn off HTTP/2 or upgrade ATS to a

[ANNOUNCE] Apache Traffic Server 8.0.5 and 7.1.8 are Released

2019-08-20 Thread Bryan Call
Apache Traffic Server 8.0.5 and 7.1.8 Released The Apache Software Foundation and the Apache Traffic Server (ATS) project are pleased to announce the release of Apache Traffic Server 8.0.5 and 7.1.8! ATS is a high performance, scalable HTTP Intermediary and proxy cache. It is used by several la

Re: [VOTE] Release Apache Traffic Server 7.1.8

2019-08-20 Thread Bryan Call
+1 from me and I am calling the vote with 4 +1 binding votes. Thank you for voting! -Bryan > On Aug 20, 2019, at 10:39 AM, Bryan Call wrote: > > I've prepared a release for 7.1.8. The release notes for 7.1.8 are available > at: > > > https://github.com/apache/trafficserver/pulls?ut

Re: [VOTE] Release Apache Traffic Server 8.0.5

2019-08-20 Thread Bryan Call
+1 from me and I am calling the vote with 3 +1 binding votes. Thank you for voting! -Bryan > On Aug 20, 2019, at 10:39 AM, Bryan Call wrote: > > I've prepared a release for 8.0.5. The release notes for 8.0.5 are available > at: > > > https://github.com/apache/trafficserver/pulls?ut

Re: [VOTE] Release Apache Traffic Server 8.0.5

2019-08-20 Thread Randall Meyer
+1 On Tuesday, August 20, 2019, 10:58:51 AM PDT, Sudheer Vinukonda wrote: +1     On Tuesday, August 20, 2019, 10:39:39 AM PDT, Bryan Call wrote:  I've prepared a release for 8.0.5.  The release notes for 8.0.5 are available at:     https://github.com/apache/trafficserver/pulls

Re: [VOTE] Release Apache Traffic Server 8.0.5

2019-08-20 Thread Sudheer Vinukonda
+1 On Tuesday, August 20, 2019, 10:39:39 AM PDT, Bryan Call wrote: I've prepared a release for 8.0.5.  The release notes for 8.0.5 are available at:     https://github.com/apache/trafficserver/pulls?utf8=✓&q=is%3Aclosed+is%3Apr+milestone%3A8.0.5 or for a brief ChangeLog:     https:

Re: [VOTE] Release Apache Traffic Server 7.1.8

2019-08-20 Thread Sudheer Vinukonda
+1 On Tuesday, August 20, 2019, 10:51:57 AM PDT, Randall Meyer wrote: +1  On Tuesday, August 20, 2019, 10:41:18 AM PDT, Evan Zelkowitz wrote: +1 On Tue, Aug 20, 2019 at 11:39 AM Bryan Call wrote: > > I've prepared a release for 7.1.8.  The release notes for 7.1.8 are avail

Re: [VOTE] Release Apache Traffic Server 7.1.8

2019-08-20 Thread Randall Meyer
+1  On Tuesday, August 20, 2019, 10:41:18 AM PDT, Evan Zelkowitz wrote: +1 On Tue, Aug 20, 2019 at 11:39 AM Bryan Call wrote: > > I've prepared a release for 7.1.8.  The release notes for 7.1.8 are available > at: > >        >https://github.com/apache/trafficserver/pulls?utf8=✓&q=is

Re: [VOTE] Release Apache Traffic Server 7.1.8

2019-08-20 Thread Evan Zelkowitz
+1 On Tue, Aug 20, 2019 at 11:39 AM Bryan Call wrote: > > I've prepared a release for 7.1.8. The release notes for 7.1.8 are available > at: > > > https://github.com/apache/trafficserver/pulls?utf8=✓&q=is%3Aclosed+is%3Apr+milestone%3A7.1.8 > > or for a brief ChangeLog: > > http

[VOTE] Release Apache Traffic Server 8.0.5

2019-08-20 Thread Bryan Call
I've prepared a release for 8.0.5. The release notes for 8.0.5 are available at: https://github.com/apache/trafficserver/pulls?utf8=✓&q=is%3Aclosed+is%3Apr+milestone%3A8.0.5 or for a brief ChangeLog: https://github.com/apache/trafficserver/blob/8.0.x/CHANGELOG-8.0.5 For some

[VOTE] Release Apache Traffic Server 7.1.8

2019-08-20 Thread Bryan Call
I've prepared a release for 7.1.8. The release notes for 7.1.8 are available at: https://github.com/apache/trafficserver/pulls?utf8=✓&q=is%3Aclosed+is%3Apr+milestone%3A7.1.8 or for a brief ChangeLog: https://github.com/apache/trafficserver/blob/7.1.x/CHANGELOG-7.1.8 For some