Format: 1.8 Date: Wed, 08 Mar 2023 11:32:34 -0500 Source: apache2 Binary: apache2 apache2-bin apache2-dev apache2-ssl-dev apache2-suexec-custom apache2-suexec-pristine apache2-utils libapache2-mod-md libapache2-mod-proxy-uwsgi Built-For-Profiles: noudeb Architecture: i386 Version: 2.4.55-1ubuntu2 Distribution: lunar-proposed Urgency: medium Maintainer: Launchpad Build Daemon Changed-By: Marc Deslauriers Description: apache2 - Apache HTTP Server apache2-bin - Apache HTTP Server (modules and other binary files) apache2-dev - Apache HTTP Server (development headers) apache2-ssl-dev - Apache HTTP Server (mod_ssl development headers) apache2-suexec-custom - Apache HTTP Server configurable suexec program for mod_suexec apache2-suexec-pristine - Apache HTTP Server standard suexec program for mod_suexec apache2-utils - Apache HTTP Server (utility programs for web servers) libapache2-mod-md - transitional package libapache2-mod-proxy-uwsgi - transitional package Changes: apache2 (2.4.55-1ubuntu2) lunar; urgency=medium . * SECURITY UPDATE: HTTP request splitting with mod_rewrite and mod_proxy - debian/patches/CVE-2023-25690-1.patch: don't forward invalid query strings in modules/http2/mod_proxy_http2.c, modules/mappers/mod_rewrite.c, modules/proxy/mod_proxy_ajp.c, modules/proxy/mod_proxy_balancer.c, modules/proxy/mod_proxy_http.c, modules/proxy/mod_proxy_wstunnel.c. - debian/patches/CVE-2023-25690-2.patch: Fix missing APLOGNO in modules/http2/mod_proxy_http2.c. - CVE-2023-25690 * SECURITY UPDATE: mod_proxy_uwsgi HTTP response splitting - debian/patches/CVE-2023-27522.patch: stricter backend HTTP response parsing/validation in modules/proxy/mod_proxy_uwsgi.c. - CVE-2023-27522 Checksums-Sha1: fa1b99b0034778668a6aba11e6f0370455b1e320 2731934 apache2-bin-dbgsym_2.4.55-1ubuntu2_i386.ddeb aa36bf2bf9a5caab88fac83d89bba553625ec1a4 1427396 apache2-bin_2.4.55-1ubuntu2_i386.deb 4d7f13f9ae8fe512dffdd4fddb2749b151afe479 197942 apache2-dev_2.4.55-1ubuntu2_i386.deb d8a237a3da777dda921e9fddf9187b45d8bcdae5 2988 apache2-ssl-dev_2.4.55-1ubuntu2_i386.deb 42459ba4e8bab7b3e165afead94786d3825a05f1 11414 apache2-suexec-custom-dbgsym_2.4.55-1ubuntu2_i386.ddeb d533a995dff339d34904610a6e580feaee650d0b 16144 apache2-suexec-custom_2.4.55-1ubuntu2_i386.deb 6fa02f94784228641ca8d843c8b82007c2c02025 10242 apache2-suexec-pristine-dbgsym_2.4.55-1ubuntu2_i386.ddeb f1121666928d9f98ca087b3a6db63d0e06522a6e 14502 apache2-suexec-pristine_2.4.55-1ubuntu2_i386.deb 0c39b06d3f7fa93a9f036d21111c2d443b7c0700 107720 apache2-utils-dbgsym_2.4.55-1ubuntu2_i386.ddeb 99b99a724074213e128a21a243dc25acc0906927 98806 apache2-utils_2.4.55-1ubuntu2_i386.deb 4e9d25f7214a2d91f1f237a8369958752477ae34 11122 apache2_2.4.55-1ubuntu2_i386.buildinfo edf4e297a1fdd9f49f60c2e427851609641eb014 96994 apache2_2.4.55-1ubuntu2_i386.deb 0177beb0193b5e4d28913b4494e7939e635226d0 796 libapache2-mod-md_2.4.55-1ubuntu2_i386.deb d9fd154d55455850aafcddcb3e0ce489c838247b 992 libapache2-mod-proxy-uwsgi_2.4.55-1ubuntu2_i386.deb Checksums-Sha256: 0eaba879c35de8c421788c62740bac833a1be4b5bfc9d7e1718129210040749d 2731934 apache2-bin-dbgsym_2.4.55-1ubuntu2_i386.ddeb 8c463923ccb93f9fd1cd090051814fd5a98253052e759ea5435931b9578b4897 1427396 apache2-bin_2.4.55-1ubuntu2_i386.deb 0abf160cdfad15897b355686596811053452bdff2229c492313e5a72112906c1 197942 apache2-dev_2.4.55-1ubuntu2_i386.deb a8a6aed8eb0d193a38b01e8e542a85486aba101818a2d7bdf4036c25a88bdf66 2988 apache2-ssl-dev_2.4.55-1ubuntu2_i386.deb 20faf2af79b23ca5ccbc2716d45aa622a8f3384e57756fb77d86b75a6ac2eb15 11414 apache2-suexec-custom-dbgsym_2.4.55-1ubuntu2_i386.ddeb 2281a8baf4f8bbfc61fc1fd70bf61dd8fd51b7b58cf72eba57c4a2d3bce9470a 16144 apache2-suexec-custom_2.4.55-1ubuntu2_i386.deb f8cbc561cbf4401ed56038ab5a5823bbd96776d4e0886c26034c3c92af22d543 10242 apache2-suexec-pristine-dbgsym_2.4.55-1ubuntu2_i386.ddeb 89d875aefa3bef05cf3584b25046ced3f671fe88ced866bc4ae4d1c432b1ab61 14502 apache2-suexec-pristine_2.4.55-1ubuntu2_i386.deb 7c3f20de39c6e8967915b066c44c7e8935f02752f0cc5e7c2eff2e464be928df 107720 apache2-utils-dbgsym_2.4.55-1ubuntu2_i386.ddeb aaa49f85294a2e128194ebfa78fd6c9f5a9d6cdfbb2007c2ff88024669bfa890 98806 apache2-utils_2.4.55-1ubuntu2_i386.deb c8b090f3fe738f05d404e20f6144d2660eb47f656710539d2230de4c76296e7f 11122 apache2_2.4.55-1ubuntu2_i386.buildinfo 6d8db52827d081b65a715d6f4e02d1e52e43fb0287dc420ebd9b8d3624d75b4a 96994 apache2_2.4.55-1ubuntu2_i386.deb e9bf630d7cb4b7c9a224064f82d3d17c894358a529dc2328edd6a73a12ad73a6 796 libapache2-mod-md_2.4.55-1ubuntu2_i386.deb d47a61c67985f9caca09920feec734ef0a1269d3f5ed74ea23e5893ceaaeabce 992 libapache2-mod-proxy-uwsgi_2.4.55-1ubuntu2_i386.deb Files: 5aee935e01608793805bbf4029d2a587 2731934 debug optional apache2-bin-dbgsym_2.4.55-1ubuntu2_i386.ddeb fbecf0e16af604d7c648f2844dd10b7d 1427396 httpd optional apache2-bin_2.4.55-1ubuntu2_i386.deb 5c5cf4df662ff54c920789bbf7488777 197942 httpd optional apache2-dev_2.4.55-1ubuntu2_i386.deb 60c52d8318c1b0f6d932a2ac42890a9c 2988 httpd optional apache2-ssl-dev_2.4.55-1ubuntu2_i386.deb 3253033d33ee5fbf1d424b50cdb114e5 11414 debug optional apache2-suexec-custom-dbgsym_2.4.55-1ubuntu2_i386.ddeb d4f545ece79baf8c9e563b674b4da635 16144 httpd optional apache2-suexec-custom_2.4.55-1ubuntu2_i386.deb 54f4abb24c4724eb76efa737e9c35c7e 10242 debug optional apache2-suexec-pristine-dbgsym_2.4.55-1ubuntu2_i386.ddeb f2922e265d928f7ab21053de569d7871 14502 httpd optional apache2-suexec-pristine_2.4.55-1ubuntu2_i386.deb 84c6b3d44187fb3962dd2ad6c2d9a781 107720 debug optional apache2-utils-dbgsym_2.4.55-1ubuntu2_i386.ddeb 1f11df7f8a2df62d845f88c1708872f5 98806 httpd optional apache2-utils_2.4.55-1ubuntu2_i386.deb 87405a9d953f26e183b402164fa44db5 11122 httpd optional apache2_2.4.55-1ubuntu2_i386.buildinfo 453d386e3f26975fe2cb86f8438f42b4 96994 httpd optional apache2_2.4.55-1ubuntu2_i386.deb 58af669784608323c352cffb0ed49e95 796 oldlibs optional libapache2-mod-md_2.4.55-1ubuntu2_i386.deb a316ef7848a8cd83f37cd29a57ebfd7a 992 oldlibs optional libapache2-mod-proxy-uwsgi_2.4.55-1ubuntu2_i386.deb Original-Maintainer: Debian Apache Maintainers