[ANNOUNCE] Apache Traffic Server is vulnerable to smuggle, cache poison, and DOS attacks

2022-12-15 Thread Bryan Call
Description: ATS is vulnerable to smuggle, cache poison, and DOS attacks. CVE (8.1.x and 9.1.x): CVE-2022-32749 - Improperly handled requests can cause crashes in specific plugins CVE-2022-37392 - Improperly reading the client request body CVE (9.1.x): CVE-2022-40743 - Security issues with the x

[ANNOUNCE] Apache Traffic Server 9.1.4 and 8.1.6 are Released

2022-12-15 Thread Bryan Call
Apache Traffic Server 9.1.4 and 8.1.6 are Released The Apache Software Foundation and the Apache Traffic Server (ATS) Project are pleased to announce the release of Apache Traffic Server 9.1.4 and 8.1.6! ATS is a high performance, scalable HTTP Intermediary and proxy cache. It is used by sever

Re: [VOTE] Release Apache Traffic Server 9.1.4 (RC0)

2022-12-15 Thread Leif Hedstrom
+1 > On Dec 15, 2022, at 12:40, Bryan Call wrote: > > I am calling the vote with 4 +1 votes. We will publish the final release > today. > > -Bryan > >> On Dec 14, 2022, at 10:54 AM, Bryan Call wrote: >> >> I've prepared a release for 9.1.4. The release notes are available at: >> >>

Re: [VOTE] Release Apache Traffic Server 8.1.6 (RC0)

2022-12-15 Thread Bryan Call
I am calling the vote with 4 +1 votes. We will publish the final release today. -Bryan > On Dec 15, 2022, at 9:48 AM, Randall Meyer > wrote: > > +1 - tested on macOS 13, builds, checks > > >On Thursday, December 15, 2022 at 09:38:33 AM PST, Evan Zelkowitz > wrote: > > +1 - tested o

Re: [VOTE] Release Apache Traffic Server 9.1.4 (RC0)

2022-12-15 Thread Bryan Call
I am calling the vote with 4 +1 votes. We will publish the final release today. -Bryan > On Dec 14, 2022, at 10:54 AM, Bryan Call wrote: > > I've prepared a release for 9.1.4. The release notes are available at: > > > https://github.com/apache/trafficserver/pulls?q=is:closed+is:pr+mil

Re: [VOTE] Release Apache Traffic Server 8.1.6 (RC0)

2022-12-15 Thread Randall Meyer
+1 - tested on macOS 13, builds, checks On Thursday, December 15, 2022 at 09:38:33 AM PST, Evan Zelkowitz wrote: +1 - tested on Ubuntu 20, checksums, build, checks On Thu, Dec 15, 2022 at 10:11 AM Bryan Call wrote: > +1 - tested on Fedora 37.  Tested checksums, build, unit tests, a

Re: [VOTE] Release Apache Traffic Server 9.1.4 (RC0)

2022-12-15 Thread Randall Meyer
+1 - tested on macOS 13, builds, checks On Thursday, December 15, 2022 at 09:38:53 AM PST, Evan Zelkowitz wrote: +1 - tested on ubuntu 20, build, checksums, checks On Thu, Dec 15, 2022 at 10:11 AM Bryan Call wrote: > +1 - tested on Fedora 37.  Tested checksums, build, unit tests, an

Re: [VOTE] Release Apache Traffic Server 9.1.4 (RC0)

2022-12-15 Thread Evan Zelkowitz
+1 - tested on ubuntu 20, build, checksums, checks On Thu, Dec 15, 2022 at 10:11 AM Bryan Call wrote: > +1 - tested on Fedora 37. Tested checksums, build, unit tests, and > regression tests. > > -Bryan > > > On Dec 14, 2022, at 10:54 AM, Bryan Call wrote: > > > > I've prepared a release for 9.

Re: [VOTE] Release Apache Traffic Server 8.1.6 (RC0)

2022-12-15 Thread Evan Zelkowitz
+1 - tested on Ubuntu 20, checksums, build, checks On Thu, Dec 15, 2022 at 10:11 AM Bryan Call wrote: > +1 - tested on Fedora 37. Tested checksums, build, unit tests, and > regression tests. > > -Bryan > > > On Dec 14, 2022, at 11:09 AM, Evan Zelkowitz wrote: > > > > I've prepared a release fo

Re: [VOTE] Release Apache Traffic Server 8.1.6 (RC0)

2022-12-15 Thread Bryan Call
+1 - tested on Fedora 37. Tested checksums, build, unit tests, and regression tests. -Bryan > On Dec 14, 2022, at 11:09 AM, Evan Zelkowitz wrote: > > I've prepared a release for 8.1.6. The release notes are available at: > > > https://github.com/apache/trafficserver/pulls?q=is:closed+is:pr

Re: [VOTE] Release Apache Traffic Server 9.1.4 (RC0)

2022-12-15 Thread Bryan Call
+1 - tested on Fedora 37. Tested checksums, build, unit tests, and regression tests. -Bryan > On Dec 14, 2022, at 10:54 AM, Bryan Call wrote: > > I've prepared a release for 9.1.4. The release notes are available at: > > > https://github.com/apache/trafficserver/pulls?q=is:closed+is: