Format: 1.8 Date: Thu, 16 Dec 2021 14:09:26 -0800 Source: apache2 Binary: apache2 apache2-bin apache2-dev apache2-ssl-dev apache2-suexec-custom apache2-suexec-pristine apache2-utils libapache2-mod-md libapache2-mod-proxy-uwsgi Built-For-Profiles: noudeb Architecture: i386 Version: 2.4.51-2ubuntu1 Distribution: jammy-proposed Urgency: medium Maintainer: Launchpad Build Daemon Changed-By: Bryce Harrington Description: apache2 - Apache HTTP Server apache2-bin - Apache HTTP Server (modules and other binary files) apache2-dev - Apache HTTP Server (development headers) apache2-ssl-dev - Apache HTTP Server (mod_ssl development headers) apache2-suexec-custom - Apache HTTP Server configurable suexec program for mod_suexec apache2-suexec-pristine - Apache HTTP Server standard suexec program for mod_suexec apache2-utils - Apache HTTP Server (utility programs for web servers) libapache2-mod-md - transitional package libapache2-mod-proxy-uwsgi - transitional package Changes: apache2 (2.4.51-2ubuntu1) jammy; urgency=medium . * Merge with Debian unstable. Remaining changes: - debian/{control, apache2.install, apache2-utils.ufw.profile, apache2.dirs}: Add ufw profiles. (LP 261198) - debian/apache2.py, debian/apache2-bin.install: Add apport hook. (LP 609177) - d/index.html, d/icons/ubuntu-logo.png, d/apache2.postrm, d/s/include-binaries: replace Debian with Ubuntu on default page and add Ubuntu icon file. (LP 1288690) - d/p/support-openssl3-*.patch: Backport various patches from https://github.com/apache/httpd/pull/258 in order to fix mod_ssl's failure to load when using OpenSSL 3. (LP #1951476) * Dropped: - d/apache2ctl: Also use systemd for graceful if it is in use. (LP: 1832182) [This introduced a performance regression.] - d/apache2ctl: Also use /run/systemd to check for systemd usage. (LP 1918209) [Not needed] - debian/patches/CVE-2021-33193.patch: refactor request parsing in include/ap_mmn.h, include/http_core.h, include/http_protocol.h, include/http_vhost.h, modules/http2/h2_request.c, server/core.c, server/core_filters.c, server/protocol.c, server/vhost.c. [Fixed in 2.4.48-4] - debian/patches/CVE-2021-34798.patch: add NULL check in server/scoreboard.c. [Fixed in 2.4.49-1] - debian/patches/CVE-2021-36160.patch: fix PATH_INFO setting for generic worker in modules/proxy/mod_proxy_uwsgi.c. [Fixed in 2.4.49-1] - debian/patches/CVE-2021-39275.patch: fix ap_escape_quotes substitution logic in server/util.c. [Fixed in 2.4.49-1] - arbitrary origin server via crafted request uri-path + debian/patches/CVE-2021-40438-pre1.patch: faster unix socket path parsing in the "proxy:" URL in modules/proxy/mod_proxy.c, modules/proxy/proxy_util.c. + debian/patches/CVE-2021-40438.patch: add sanity checks on the configured UDS path in modules/proxy/proxy_util.c. [Fixed in 2.4.49-3] - SECURITY REGRESSION: Issues in UDS URIs. (LP #1945311) + debian/patches/CVE-2021-40438-2.patch: Fix UDS unix: scheme for P rules in modules/mappers/mod_rewrite.c. + debian/patches/CVE-2021-40438-3.patch: Handle UDS URIs with empty hostname in modules/mappers/mod_rewrite.c, modules/proxy/proxy_util.c. [Fixed in 2.4.49-3] Checksums-Sha1: 42457d85bbd617d4fa163cdf99cc9d1ecd7672e3 3224200 apache2-bin-dbgsym_2.4.51-2ubuntu1_i386.ddeb 0ef11b0fe80ab28ac7a8289bfa596162371c3871 1425302 apache2-bin_2.4.51-2ubuntu1_i386.deb 6aeeb2ed13b11edd0a7fc1c0a7c346a670267ac8 189470 apache2-dev_2.4.51-2ubuntu1_i386.deb ee090fdddcfdc79da2c6524b60755920d4d88e54 2980 apache2-ssl-dev_2.4.51-2ubuntu1_i386.deb 552e9b564a1e6c3398b34c8e17f6ebbe11122f86 11570 apache2-suexec-custom-dbgsym_2.4.51-2ubuntu1_i386.ddeb a314e695bf789cdfdf93e664af88ef5f0b52ae4a 16368 apache2-suexec-custom_2.4.51-2ubuntu1_i386.deb 4d256e228dc5990b6c37b6148702bf285a8f1a5b 10268 apache2-suexec-pristine-dbgsym_2.4.51-2ubuntu1_i386.ddeb cb5d7de12656860ae6c8cc350fb70725d7d6572e 14746 apache2-suexec-pristine_2.4.51-2ubuntu1_i386.deb 4e45f62547212e999b6e08b2afa7ba5d9166fccc 109410 apache2-utils-dbgsym_2.4.51-2ubuntu1_i386.ddeb 396048be953668e047bdb2319943d5524984e616 92450 apache2-utils_2.4.51-2ubuntu1_i386.deb a4143440932935b86ea3f27586392aa04f703b33 11257 apache2_2.4.51-2ubuntu1_i386.buildinfo 40e2dd4d8e8f171a2b9084f822339c5eb59f8253 97968 apache2_2.4.51-2ubuntu1_i386.deb ca63c37373773683a966d04138532dc8c1b3c46e 802 libapache2-mod-md_2.4.51-2ubuntu1_i386.deb 8a46831b673876394513c108a524f40ada443a64 990 libapache2-mod-proxy-uwsgi_2.4.51-2ubuntu1_i386.deb Checksums-Sha256: 4c7332895232a338853316ba4798e91e310ca4e21e3b730d40819e2f4bb683f9 3224200 apache2-bin-dbgsym_2.4.51-2ubuntu1_i386.ddeb 267bc63a25e55148d444d878743c5b426715874a7d5ca0e1e615b7e8d0e1edda 1425302 apache2-bin_2.4.51-2ubuntu1_i386.deb 363e0a0fdd6dabdbbd1dee8909d61c7d89d1d332596d3917ba55d9e99746943d 189470 apache2-dev_2.4.51-2ubuntu1_i386.deb b9064b3f65d92440a35ad73ef0afb3835dc12df429cfee204a4e69051af0f50d 2980 apache2-ssl-dev_2.4.51-2ubuntu1_i386.deb fd8e14c786d0b7e7a1646bb8cb5a5cbfa0792f21a7a8ad3f15576685c9a623f3 11570 apache2-suexec-custom-dbgsym_2.4.51-2ubuntu1_i386.ddeb 272937bcf64eaa70e37dc06d30139d29b67956a1375f8d8231d596ed4ec825d2 16368 apache2-suexec-custom_2.4.51-2ubuntu1_i386.deb f7cfbb747eb4f5a488d342d971becc396bf505825e87509c25cdd50c5443cbb0 10268 apache2-suexec-pristine-dbgsym_2.4.51-2ubuntu1_i386.ddeb f78d8d6e90a1e5fe879a3f839bd5bab0b73c7a59c12e5b3d4c666778fc37b8e4 14746 apache2-suexec-pristine_2.4.51-2ubuntu1_i386.deb f6d77001e62ff26f3cb48a59dfc1c31baff4191a95ce1b873159dd0ef2a4810c 109410 apache2-utils-dbgsym_2.4.51-2ubuntu1_i386.ddeb 085addfbc7e5a4cd9da98fc82f634c6929601f496e766d2f279d8ba3ae333094 92450 apache2-utils_2.4.51-2ubuntu1_i386.deb 6567eea41c9ede5626b5e6bc86eb1a2baffedea967f9e14f815a404fa020933b 11257 apache2_2.4.51-2ubuntu1_i386.buildinfo 98d4b613a8dc002e3ef15a36b14361e2d583e7c0151f42b8b0797c5bd6c92425 97968 apache2_2.4.51-2ubuntu1_i386.deb fdb179f30b215b71a06d8948225cd231495a039185e68cf65bef0eb31e85c99d 802 libapache2-mod-md_2.4.51-2ubuntu1_i386.deb 613f01abfaf064f66f76ab4d6f4e0067ed0237403f7aa311c7ccba4ecebc712e 990 libapache2-mod-proxy-uwsgi_2.4.51-2ubuntu1_i386.deb Files: 904ac5f9bf41a900d9a71de0fd705cbc 3224200 debug optional apache2-bin-dbgsym_2.4.51-2ubuntu1_i386.ddeb a2ff15b65f21b7762700969ad0f5e866 1425302 httpd optional apache2-bin_2.4.51-2ubuntu1_i386.deb ba0b6c66b1724313b21669a1fa92f5d8 189470 httpd optional apache2-dev_2.4.51-2ubuntu1_i386.deb b0dea2209b2187db878a2dc87b6b917a 2980 httpd optional apache2-ssl-dev_2.4.51-2ubuntu1_i386.deb 4f324c516de142de555a4c21898b776c 11570 debug optional apache2-suexec-custom-dbgsym_2.4.51-2ubuntu1_i386.ddeb 18d19c1ad086c4bddb9063a0820d9dee 16368 httpd optional apache2-suexec-custom_2.4.51-2ubuntu1_i386.deb 7dfede8b628300a4dce18ac539465b81 10268 debug optional apache2-suexec-pristine-dbgsym_2.4.51-2ubuntu1_i386.ddeb 620e07a024d60c9b0e54d4de1af9f3e4 14746 httpd optional apache2-suexec-pristine_2.4.51-2ubuntu1_i386.deb 44613dee4967d0369618b72729146ff4 109410 debug optional apache2-utils-dbgsym_2.4.51-2ubuntu1_i386.ddeb 8a86943d1af3b662fd2f2f39d7bc9630 92450 httpd optional apache2-utils_2.4.51-2ubuntu1_i386.deb b9b7424f9fe8573d63b5f7ef6b290a22 11257 httpd optional apache2_2.4.51-2ubuntu1_i386.buildinfo 35271672f2d1f0290dc3cde55062583b 97968 httpd optional apache2_2.4.51-2ubuntu1_i386.deb 254a06f885b5f94d0d58b1d784e18a7d 802 oldlibs optional libapache2-mod-md_2.4.51-2ubuntu1_i386.deb 90fec053a5f2873286ae13a7fb99d91f 990 oldlibs optional libapache2-mod-proxy-uwsgi_2.4.51-2ubuntu1_i386.deb Original-Maintainer: Debian Apache Maintainers