Format: 1.8 Date: Thu, 16 Dec 2021 14:09:26 -0800 Source: apache2 Binary: apache2 apache2-bin apache2-dev apache2-ssl-dev apache2-suexec-custom apache2-suexec-pristine apache2-utils libapache2-mod-md libapache2-mod-proxy-uwsgi Built-For-Profiles: noudeb Architecture: armhf Version: 2.4.51-2ubuntu1 Distribution: jammy-proposed Urgency: medium Maintainer: Launchpad Build Daemon Changed-By: Bryce Harrington Description: apache2 - Apache HTTP Server apache2-bin - Apache HTTP Server (modules and other binary files) apache2-dev - Apache HTTP Server (development headers) apache2-ssl-dev - Apache HTTP Server (mod_ssl development headers) apache2-suexec-custom - Apache HTTP Server configurable suexec program for mod_suexec apache2-suexec-pristine - Apache HTTP Server standard suexec program for mod_suexec apache2-utils - Apache HTTP Server (utility programs for web servers) libapache2-mod-md - transitional package libapache2-mod-proxy-uwsgi - transitional package Changes: apache2 (2.4.51-2ubuntu1) jammy; urgency=medium . * Merge with Debian unstable. Remaining changes: - debian/{control, apache2.install, apache2-utils.ufw.profile, apache2.dirs}: Add ufw profiles. (LP 261198) - debian/apache2.py, debian/apache2-bin.install: Add apport hook. (LP 609177) - d/index.html, d/icons/ubuntu-logo.png, d/apache2.postrm, d/s/include-binaries: replace Debian with Ubuntu on default page and add Ubuntu icon file. (LP 1288690) - d/p/support-openssl3-*.patch: Backport various patches from https://github.com/apache/httpd/pull/258 in order to fix mod_ssl's failure to load when using OpenSSL 3. (LP #1951476) * Dropped: - d/apache2ctl: Also use systemd for graceful if it is in use. (LP: 1832182) [This introduced a performance regression.] - d/apache2ctl: Also use /run/systemd to check for systemd usage. (LP 1918209) [Not needed] - debian/patches/CVE-2021-33193.patch: refactor request parsing in include/ap_mmn.h, include/http_core.h, include/http_protocol.h, include/http_vhost.h, modules/http2/h2_request.c, server/core.c, server/core_filters.c, server/protocol.c, server/vhost.c. [Fixed in 2.4.48-4] - debian/patches/CVE-2021-34798.patch: add NULL check in server/scoreboard.c. [Fixed in 2.4.49-1] - debian/patches/CVE-2021-36160.patch: fix PATH_INFO setting for generic worker in modules/proxy/mod_proxy_uwsgi.c. [Fixed in 2.4.49-1] - debian/patches/CVE-2021-39275.patch: fix ap_escape_quotes substitution logic in server/util.c. [Fixed in 2.4.49-1] - arbitrary origin server via crafted request uri-path + debian/patches/CVE-2021-40438-pre1.patch: faster unix socket path parsing in the "proxy:" URL in modules/proxy/mod_proxy.c, modules/proxy/proxy_util.c. + debian/patches/CVE-2021-40438.patch: add sanity checks on the configured UDS path in modules/proxy/proxy_util.c. [Fixed in 2.4.49-3] - SECURITY REGRESSION: Issues in UDS URIs. (LP #1945311) + debian/patches/CVE-2021-40438-2.patch: Fix UDS unix: scheme for P rules in modules/mappers/mod_rewrite.c. + debian/patches/CVE-2021-40438-3.patch: Handle UDS URIs with empty hostname in modules/mappers/mod_rewrite.c, modules/proxy/proxy_util.c. [Fixed in 2.4.49-3] Checksums-Sha1: 91853d1113edd0ba7ef63fdbc7e62da05b338f8a 3314590 apache2-bin-dbgsym_2.4.51-2ubuntu1_armhf.ddeb 39c21d5356a048c6a33619f6369ef4d9e5b58573 1189952 apache2-bin_2.4.51-2ubuntu1_armhf.deb ee45b48f3040aedec3e8a433ab237f678bcf38be 189468 apache2-dev_2.4.51-2ubuntu1_armhf.deb eca5591ace4fe0460bd4ea7a13467ad69630881e 2978 apache2-ssl-dev_2.4.51-2ubuntu1_armhf.deb 7162b0d552ff0892f54b830f53091ee40c5728f4 12446 apache2-suexec-custom-dbgsym_2.4.51-2ubuntu1_armhf.ddeb 4391a6ca1cb5903529fd60b790a1e80b83b29724 15502 apache2-suexec-custom_2.4.51-2ubuntu1_armhf.deb feb6142c53db9a98264fffd8e5fd1d62ea45c17a 11114 apache2-suexec-pristine-dbgsym_2.4.51-2ubuntu1_armhf.ddeb 79cdc5e0a1ab17d5eac9422cd757a2c00d1e4544 13996 apache2-suexec-pristine_2.4.51-2ubuntu1_armhf.deb 59fa7075b86c780d4ec63d4f129b90827975bb1d 119398 apache2-utils-dbgsym_2.4.51-2ubuntu1_armhf.ddeb 2c363ffcbe31bc125a324996cf8f3be2782ae67b 89656 apache2-utils_2.4.51-2ubuntu1_armhf.deb 11fe86f5d85f0f3e6638be630e65590503ea0770 11236 apache2_2.4.51-2ubuntu1_armhf.buildinfo da7fe00f315af1d3be3b4da9ac2fffd0d827d7a9 97970 apache2_2.4.51-2ubuntu1_armhf.deb 36c70b694ec8dea670e3502813cfe549f49c25e2 798 libapache2-mod-md_2.4.51-2ubuntu1_armhf.deb a8877e65ffaca84879afd7615001991e8517d481 982 libapache2-mod-proxy-uwsgi_2.4.51-2ubuntu1_armhf.deb Checksums-Sha256: e62848c514de7eec0ec6ab1bbd593d3676e5c775efd1495a28fb25c797926ea7 3314590 apache2-bin-dbgsym_2.4.51-2ubuntu1_armhf.ddeb e14e280432be8a0672e2a17b0e749ee5c7bb960cc4902b136edb0f64dea0d264 1189952 apache2-bin_2.4.51-2ubuntu1_armhf.deb c5999d255f043c5bbbb94d0b273014b7c5f59e99295ec35a812aa5051093139d 189468 apache2-dev_2.4.51-2ubuntu1_armhf.deb a4d659cce6e5af8863a74850d9fda7ed4cbaff8308b853b42897b6a9eca7e5e5 2978 apache2-ssl-dev_2.4.51-2ubuntu1_armhf.deb 705169606c614ad5b61142999178436621aea5733eafaa3459c3c52dcf5658dd 12446 apache2-suexec-custom-dbgsym_2.4.51-2ubuntu1_armhf.ddeb dd8da1fc0416e5d094faa9249f70fcf3fde13273a818b5563a9ada454d3f96c2 15502 apache2-suexec-custom_2.4.51-2ubuntu1_armhf.deb 7893a68e7ad779c627b29cb51a3a5919f3fe577dab4c1af86eb409a752a518e2 11114 apache2-suexec-pristine-dbgsym_2.4.51-2ubuntu1_armhf.ddeb 86a85cbe85cb9e658860cdb4a47370710d5b20a4d315f7b232d76ab524cf23ff 13996 apache2-suexec-pristine_2.4.51-2ubuntu1_armhf.deb 4babc362942a42756c68218680e76f9b90dcd6e5ea7799e2cdb6be7ec66339af 119398 apache2-utils-dbgsym_2.4.51-2ubuntu1_armhf.ddeb 9752b6eff2dab7622dbbb4c8c40f49308f83ec0dd4fa2c68068256adc3a0deac 89656 apache2-utils_2.4.51-2ubuntu1_armhf.deb 6c863320a9e98173af7e7dcd8eaaf4853e2068fdd3b510d74517fb2ca77c194c 11236 apache2_2.4.51-2ubuntu1_armhf.buildinfo c6ac947f3a46018fc658bb43ba05616630a49c94fd14a96b6e3545c45b0eb5bb 97970 apache2_2.4.51-2ubuntu1_armhf.deb 039f04c9adddff0f99ad681b7534b5a533de0311a9be843cbdfb68f602d6e9f6 798 libapache2-mod-md_2.4.51-2ubuntu1_armhf.deb 8946ccdd6dda1300f51321b21c84a31f057e32028454f81c84e33401d839797a 982 libapache2-mod-proxy-uwsgi_2.4.51-2ubuntu1_armhf.deb Files: b268e9392db49e90174d50642defe978 3314590 debug optional apache2-bin-dbgsym_2.4.51-2ubuntu1_armhf.ddeb 9146db457f1fb2a954fe19c8860dbdae 1189952 httpd optional apache2-bin_2.4.51-2ubuntu1_armhf.deb 2b6b6610af1fc8d62c5df29c19f170c7 189468 httpd optional apache2-dev_2.4.51-2ubuntu1_armhf.deb aa15fab8cb7790fd23192e836c49ea07 2978 httpd optional apache2-ssl-dev_2.4.51-2ubuntu1_armhf.deb ca09b805942e9ad2e68f93281dfa05b7 12446 debug optional apache2-suexec-custom-dbgsym_2.4.51-2ubuntu1_armhf.ddeb 6da64efe57a730bd7c5d21d2339f90e1 15502 httpd optional apache2-suexec-custom_2.4.51-2ubuntu1_armhf.deb 74aff7bf3e251320f20483a9627ceea7 11114 debug optional apache2-suexec-pristine-dbgsym_2.4.51-2ubuntu1_armhf.ddeb 5107438116f15c7ee55e1cea31340318 13996 httpd optional apache2-suexec-pristine_2.4.51-2ubuntu1_armhf.deb 470310b823315ca3ef6e6a899b214e04 119398 debug optional apache2-utils-dbgsym_2.4.51-2ubuntu1_armhf.ddeb cf1cfba6f8d512db31e625c0860663a3 89656 httpd optional apache2-utils_2.4.51-2ubuntu1_armhf.deb 2a540396961559b5dd68aa8cc291c596 11236 httpd optional apache2_2.4.51-2ubuntu1_armhf.buildinfo c57ee8627284389279aeb341ecd978c0 97970 httpd optional apache2_2.4.51-2ubuntu1_armhf.deb 6aefb4fcb1d51ea40a08501b00837191 798 oldlibs optional libapache2-mod-md_2.4.51-2ubuntu1_armhf.deb c285004341ffcf44406702c3f14629fb 982 oldlibs optional libapache2-mod-proxy-uwsgi_2.4.51-2ubuntu1_armhf.deb Original-Maintainer: Debian Apache Maintainers