Format: 1.8 Date: Wed, 03 Apr 2019 10:37:52 -0400 Source: apache2 Binary: apache2 apache2-data apache2-bin apache2-mpm-worker apache2-mpm-prefork apache2-mpm-event apache2-mpm-itk apache2.2-bin libapache2-mod-proxy-html libapache2-mod-macro apache2-utils apache2-suexec apache2-suexec-pristine apache2-suexec-custom apache2-doc apache2-dev apache2-dbg Architecture: amd64 Version: 2.4.7-1ubuntu4.22 Distribution: trusty Urgency: medium Maintainer: Launchpad Build Daemon Changed-By: Marc Deslauriers Description: apache2 - Apache HTTP Server apache2-bin - Apache HTTP Server (binary files and modules) apache2-data - Apache HTTP Server (common files) apache2-dbg - Apache debugging symbols apache2-dev - Apache HTTP Server (development headers) apache2-doc - Apache HTTP Server (on-site documentation) apache2-mpm-event - transitional event MPM package for apache2 apache2-mpm-itk - transitional itk MPM package for apache2 apache2-mpm-prefork - transitional prefork MPM package for apache2 apache2-mpm-worker - transitional worker MPM package for apache2 apache2-suexec - transitional package for apache2-suexec-pristine apache2-suexec-custom - Apache HTTP Server configurable suexec program for mod_suexec apache2-suexec-pristine - Apache HTTP Server standard suexec program for mod_suexec apache2-utils - Apache HTTP Server (utility programs for web servers) apache2.2-bin - Transitional package for apache2-bin libapache2-mod-macro - Transitional package for apache2-bin libapache2-mod-proxy-html - Transitional package for apache2-bin Changes: apache2 (2.4.7-1ubuntu4.22) trusty-security; urgency=medium . * SECURITY UPDATE: mod_session expiry time issue - debian/patches/CVE-2018-17199-pre1.patch: properly handle sessions that could not be decoded in modules/session/mod_session.c. - debian/patches/CVE-2018-17199.patch: always decode session attributes early in modules/session/mod_session.c. - CVE-2018-17199 * SECURITY UPDATE: mod_auth_digest access control bypass - debian/patches/CVE-2019-0217.patch: fix a race condition in modules/aaa/mod_auth_digest.c. - CVE-2019-0217 * SECURITY UPDATE: URL normalization inconsistincy - debian/patches/CVE-2019-0220-1.patch: merge consecutive slashes in the path in include/http_core.h, include/httpd.h, server/core.c, server/request.c, server/util.c. - debian/patches/CVE-2019-0220-2.patch: fix r->parsed_uri.path safety in server/request.c, server/util.c. - debian/patches/CVE-2019-0220-3.patch: maintainer mode fix in server/util.c. - CVE-2019-0220 Checksums-Sha1: 47e616730e7b29024aece6a2fac592ce45dd0fbd 1452 libapache2-mod-proxy-html_2.4.7-1ubuntu4.22_amd64.deb 905ad269ed4f8e39a3002b2e8abd587493de03f3 1448 libapache2-mod-macro_2.4.7-1ubuntu4.22_amd64.deb ecf8f93e50466edcac1886da939c4783a7bcb867 87406 apache2_2.4.7-1ubuntu4.22_amd64.deb a9211f82a52fdff70660ca141e2e61657f3b8e08 844734 apache2-bin_2.4.7-1ubuntu4.22_amd64.deb 082b2fe2f4befd3cde437dafc98f76bb0c1c518b 1456 apache2-mpm-worker_2.4.7-1ubuntu4.22_amd64.deb 49f84cfff79bf1170ba873de2c0288b68d3acdb7 1456 apache2-mpm-prefork_2.4.7-1ubuntu4.22_amd64.deb 67ee5c531b53a48a8dfad4fe37d0084e5c31b7f0 1452 apache2-mpm-event_2.4.7-1ubuntu4.22_amd64.deb 2a580d62374a59a575a96046160cb476a2afd885 1450 apache2-mpm-itk_2.4.7-1ubuntu4.22_amd64.deb 2c8c4a8fd4f22e26fa271f8b2e010971d7e5643e 1472 apache2.2-bin_2.4.7-1ubuntu4.22_amd64.deb e1c96a768b657279fd38641f1f50f6a3a8cee07f 82462 apache2-utils_2.4.7-1ubuntu4.22_amd64.deb 5755a730bb749851c59139b6bfac283ec88d920a 1434 apache2-suexec_2.4.7-1ubuntu4.22_amd64.deb 98b9d71a393cf88a68584a750baa716966655642 13738 apache2-suexec-pristine_2.4.7-1ubuntu4.22_amd64.deb 225c670a8cc5307e71f141439b6e56b192c093dc 15302 apache2-suexec-custom_2.4.7-1ubuntu4.22_amd64.deb 27efeda091e4ecd2a23279c7d4b27b45402351c9 167244 apache2-dev_2.4.7-1ubuntu4.22_amd64.deb 21db878ae83617920e1f0e87db173097054e6db7 1964568 apache2-dbg_2.4.7-1ubuntu4.22_amd64.deb 0d3f1fc2c1b6d58c3d9cb8cfffb83a0463ec94b9 1858598 apache2-bin-dbgsym_2.4.7-1ubuntu4.22_amd64.ddeb 584d811570d95fceab462094fe615e2079c95ffa 96394 apache2-utils-dbgsym_2.4.7-1ubuntu4.22_amd64.ddeb 0e63fbe75ebec889ea94a97a60ce24c4c4a4b874 9426 apache2-suexec-pristine-dbgsym_2.4.7-1ubuntu4.22_amd64.ddeb 10785ec835d17198c92731ec2777fc2141b1e74a 10448 apache2-suexec-custom-dbgsym_2.4.7-1ubuntu4.22_amd64.ddeb Checksums-Sha256: 457e854997bbc20306d5ec7ff6b3ae6afa870eeff58973c7e24892e09a693dd4 1452 libapache2-mod-proxy-html_2.4.7-1ubuntu4.22_amd64.deb 2564569e60a1d467b65579d9302f4e7193edc5d839631a930b0551b48a7e7fc7 1448 libapache2-mod-macro_2.4.7-1ubuntu4.22_amd64.deb 74881f8359589539853b2a49b894abb7bac579cf13af128fdc64620779cf1b8c 87406 apache2_2.4.7-1ubuntu4.22_amd64.deb f473393599b352dae9e6493a0eb38c16b876bc74aeb4f0f15652f53879e7e7d9 844734 apache2-bin_2.4.7-1ubuntu4.22_amd64.deb f9fd6e91db710196cfcf6c1925910ce90558c4cbb1297149bd94b7165022d778 1456 apache2-mpm-worker_2.4.7-1ubuntu4.22_amd64.deb 7fd573f3ba4df939b4d4de6f335d1f68b6ecfae9ff49e093c9511eaa67e9e7f9 1456 apache2-mpm-prefork_2.4.7-1ubuntu4.22_amd64.deb cd58c5d6ca09462e1846fef8ac791ac5c18c944ea47490d6b9ce1065cb57d18f 1452 apache2-mpm-event_2.4.7-1ubuntu4.22_amd64.deb c2cffb9260c9010847f44ff026fea452da02e55202c8ba56ccd78536101883dc 1450 apache2-mpm-itk_2.4.7-1ubuntu4.22_amd64.deb 12615b3c39bab1581237bddb49eb4444b04c4efe74dc285129bffdc88646deac 1472 apache2.2-bin_2.4.7-1ubuntu4.22_amd64.deb 95871a147cb4ffd9771f60d90218e505df947205990ea2e76401e7458c131805 82462 apache2-utils_2.4.7-1ubuntu4.22_amd64.deb 30862b618e39ef375d4ac2ba117d13ab0a533b04c5efbfd30455967474d1636a 1434 apache2-suexec_2.4.7-1ubuntu4.22_amd64.deb 01fbda55ca16f7e49d33923b565f0517ea2aed461820e7ad29d85350c8297140 13738 apache2-suexec-pristine_2.4.7-1ubuntu4.22_amd64.deb a773cdff13d733afca69c1ffbbdd3e8862ac336a99c857db81c63d5747b120dc 15302 apache2-suexec-custom_2.4.7-1ubuntu4.22_amd64.deb 0d1aeed8ce8109a988d62749e476e19a7a6c8981f43bf1dc50aba0cfe9ef567e 167244 apache2-dev_2.4.7-1ubuntu4.22_amd64.deb 864585d3a4d3785e4da5a8ec135eeeb4a78a505c957e70a7644c8d22c4b31700 1964568 apache2-dbg_2.4.7-1ubuntu4.22_amd64.deb 001c14f7714fc52f958a3c8b78756d64be3ee53a3bc44e3e56c6025b2202e2b4 1858598 apache2-bin-dbgsym_2.4.7-1ubuntu4.22_amd64.ddeb 20226bfb77aae6ac00e03b31b4e69fc9cc3bd8914e222f3a11bdb46df3ad2e6c 96394 apache2-utils-dbgsym_2.4.7-1ubuntu4.22_amd64.ddeb 676c463e4b87f234802895b67d08bf57beba5a146f098435f102d79a659ce2ed 9426 apache2-suexec-pristine-dbgsym_2.4.7-1ubuntu4.22_amd64.ddeb 294494181850fb23b38ec2313dbf5ffb28bd2de84b4b45d53be20c3bd0fef061 10448 apache2-suexec-custom-dbgsym_2.4.7-1ubuntu4.22_amd64.ddeb Files: 12349b6cf6636a5bc5e2c599529c5d5c 1452 oldlibs extra libapache2-mod-proxy-html_2.4.7-1ubuntu4.22_amd64.deb 70525590295bca8b5acff3c2ec47528d 1448 oldlibs extra libapache2-mod-macro_2.4.7-1ubuntu4.22_amd64.deb 66a53c1b53e457a6d55b5bcfcefdc194 87406 httpd optional apache2_2.4.7-1ubuntu4.22_amd64.deb c9e7ff548dd8efb41289a4ca0b042967 844734 httpd optional apache2-bin_2.4.7-1ubuntu4.22_amd64.deb c2a48c6d2514dccc884ca5e869366ccb 1456 oldlibs extra apache2-mpm-worker_2.4.7-1ubuntu4.22_amd64.deb 7fd22e13fca62d4e90d1125c79529f27 1456 oldlibs extra apache2-mpm-prefork_2.4.7-1ubuntu4.22_amd64.deb e92fdd0b524e39255810efc2a4211003 1452 oldlibs extra apache2-mpm-event_2.4.7-1ubuntu4.22_amd64.deb 23aa4986a7a115351eee054ec0c76890 1450 oldlibs extra apache2-mpm-itk_2.4.7-1ubuntu4.22_amd64.deb 6caf3dd2ab450659e0ea430bc8fa60d2 1472 oldlibs extra apache2.2-bin_2.4.7-1ubuntu4.22_amd64.deb 9e9f90b17e4b554109a647a9928ffbf0 82462 httpd optional apache2-utils_2.4.7-1ubuntu4.22_amd64.deb 083bbf7fb853e8fded6fe65beff9f67a 1434 oldlibs extra apache2-suexec_2.4.7-1ubuntu4.22_amd64.deb 64a4bafe1924518e41ef546d59fe7bda 13738 httpd optional apache2-suexec-pristine_2.4.7-1ubuntu4.22_amd64.deb b62edad625e6fe5c1111c2e21f8d9ab8 15302 httpd extra apache2-suexec-custom_2.4.7-1ubuntu4.22_amd64.deb a94a57bd7fdac1803f51d592785215e0 167244 httpd optional apache2-dev_2.4.7-1ubuntu4.22_amd64.deb 31e8c74641f2bd66014d1bbb02af7761 1964568 debug extra apache2-dbg_2.4.7-1ubuntu4.22_amd64.deb 8078119121029a6142ea0687424a280d 1858598 httpd extra apache2-bin-dbgsym_2.4.7-1ubuntu4.22_amd64.ddeb ccfcbbe5fb06376e9e0c724270b6df3f 96394 httpd extra apache2-utils-dbgsym_2.4.7-1ubuntu4.22_amd64.ddeb 1dd7fcdc0905a5237820b2d2107823b3 9426 httpd extra apache2-suexec-pristine-dbgsym_2.4.7-1ubuntu4.22_amd64.ddeb a9b9c5d83b3a50623de11e91917d4e23 10448 httpd extra apache2-suexec-custom-dbgsym_2.4.7-1ubuntu4.22_amd64.ddeb Original-Maintainer: Debian Apache Maintainers