UbuntuUpdates.org

Package "rabbitmq-server"

Name: rabbitmq-server

Description:

AMQP server written in Erlang

Latest version: 3.8.3-0ubuntu0.1
Release: focal (20.04)
Level: updates
Repository: main
Homepage: https://www.rabbitmq.com/

Links


Download "rabbitmq-server"


Other versions of "rabbitmq-server" in Focal

Repository Area Version
base main 3.8.2-0ubuntu1
security main 3.8.2-0ubuntu1.5

Changelog

Version: 3.8.3-0ubuntu0.1 2024-11-05 16:06:55 UTC

  rabbitmq-server (3.8.3-0ubuntu0.1) focal; urgency=medium

  * New upstream verison 3.8.3 (LP: #2060248).
    - RabbitMQ nodes will now gracefully shutdown when receiving a `SIGTERM`
      signal. Previously the runtime would invoke a default handler that
      terminates the VM giving RabbitMQ no chance to execute its shutdown
      steps.
    - Speedup execution of boot steps by a factor of 2N, where N is the number
      of attributes per step.
    - New health checks that can be used to determine if it's a good moment to
      shut down a node for an upgrade.
    - details about these changes can be found at
      https://github.com/rabbitmq/rabbitmq-server/blob/main/release-notes/3.8.3.md
  * Packaging changes needed by this update:
    - d/watch: update to find upstream tarball, and verify its signature
    - d/upstream/signing-key.asc: added, downloaded from
      https://github.com/rabbitmq/signing-keys/releases/download/3.0/rabbitmq-release-signing-key.asc
    - d/p/CVE-2023-46118-{1,2}.patch: refresh
    - d/p/lp1999816-fix-rabbitmqctl-status-disk-free-timeout.patch: fix offset
    - d/p/lets-use-python3-not-python-binary.patch: refresh
  * Added new dep8 tests (LP: #1679386):
    - d/t/smoke-test
    - d/t/hello-world
    - d/t/publish-subscribe
    - d/t/rpc
    - d/t/work-queue

 -- Mitchell Dzurick <email address hidden> Wed, 01 May 2024 17:02:31 -0700

Source diff to previous version
2060248 MRE updates of rabbitmq-server for Jammy,Focal
1679386 Missing dep8 tests
CVE-2023-46118 RabbitMQ is a multi-protocol messaging and streaming broker. HTTP API did not enforce an HTTP request body limit, making it vulnerable for denial of

Version: 3.8.2-0ubuntu1.5 2023-11-21 20:06:53 UTC

  rabbitmq-server (3.8.2-0ubuntu1.5) focal-security; urgency=medium

  * SECURITY UPDATE: Denial of service
    - debian/patches/CVE-2023-46118-*.patch: Introduce HTTP request body limit
      for definition uploads and Reduce default HTTP API request body size limit
      to 10 MiB in deps/rabbitmq_management/Makefile, include/rabbit_mgmt.hrl,
      priv/schema/rabbitmq_management.schema, src/rabbit_mgmt_util.erl,
      src/rabbit_mgmt_wm_definitions.erl.
    - CVE-2023-46118

 -- Leonidas Da Silva Barbosa <email address hidden> Tue, 07 Nov 2023 09:37:31 -0300

Source diff to previous version
CVE-2023-46118 RabbitMQ is a multi-protocol messaging and streaming broker. HTTP API did not enforce an HTTP request body limit, making it vulnerable for denial of

Version: 3.8.2-0ubuntu1.4 2023-03-23 17:06:51 UTC

  rabbitmq-server (3.8.2-0ubuntu1.4) focal; urgency=medium

  * d/p/lp1999816-fix-rabbitmqctl-status-disk-free-timeout.patch:
    Fix rabbitmqctl status when free disk space cannot be determined
    (LP: #1999816).

 -- Jorge Merlino <email address hidden> Wed, 22 Feb 2023 19:47:18 -0300

Source diff to previous version
1999816 Failure to get free disk space breaks \

Version: 3.8.2-0ubuntu1.3 2021-06-24 18:06:21 UTC

  rabbitmq-server (3.8.2-0ubuntu1.3) focal-security; urgency=medium

  * SECURITY UPDATE: Denial of service
    - debian/patches/CVE-2021-22116.patch: treat arrays with extra or
      missing input as fatal errors in src/amqp10_binary_parser.erl,
      test/binary_parser_SUITE.erl.
    - CVE-2021-22116

 -- Leonidas Da Silva Barbosa <email address hidden> Wed, 23 Jun 2021 10:05:38 -0300

Source diff to previous version
CVE-2021-22116 RabbitMQ all versions prior to 3.8.16 are prone to a denial of service vulnerability due to improper input validation in AMQP 1.0 client connection e

Version: 3.8.2-0ubuntu1.2 2021-05-06 11:07:18 UTC

  rabbitmq-server (3.8.2-0ubuntu1.2) focal; urgency=medium

  [ Thomas Goirand ]
  * d/rabbitmq-server.logrotate: Do not use a sharedscripts, as
    rabbitmq-server detects the log rotation by itself. (LP: #1921425)

 -- Utkarsh Gupta <email address hidden> Tue, 06 Apr 2021 15:48:23 +0530

1921425 rabbitmq-server logrotate issue



About   -   Send Feedback to @ubuntu_updates