Format: 1.8 Date: Wed, 03 Apr 2019 10:37:52 -0400 Source: apache2 Binary: apache2 apache2-data apache2-bin apache2-mpm-worker apache2-mpm-prefork apache2-mpm-event apache2-mpm-itk apache2.2-bin libapache2-mod-proxy-html libapache2-mod-macro apache2-utils apache2-suexec apache2-suexec-pristine apache2-suexec-custom apache2-doc apache2-dev apache2-dbg Architecture: i386 all Version: 2.4.7-1ubuntu4.22 Distribution: trusty Urgency: medium Maintainer: Launchpad Build Daemon Changed-By: Marc Deslauriers Description: apache2 - Apache HTTP Server apache2-bin - Apache HTTP Server (binary files and modules) apache2-data - Apache HTTP Server (common files) apache2-dbg - Apache debugging symbols apache2-dev - Apache HTTP Server (development headers) apache2-doc - Apache HTTP Server (on-site documentation) apache2-mpm-event - transitional event MPM package for apache2 apache2-mpm-itk - transitional itk MPM package for apache2 apache2-mpm-prefork - transitional prefork MPM package for apache2 apache2-mpm-worker - transitional worker MPM package for apache2 apache2-suexec - transitional package for apache2-suexec-pristine apache2-suexec-custom - Apache HTTP Server configurable suexec program for mod_suexec apache2-suexec-pristine - Apache HTTP Server standard suexec program for mod_suexec apache2-utils - Apache HTTP Server (utility programs for web servers) apache2.2-bin - Transitional package for apache2-bin libapache2-mod-macro - Transitional package for apache2-bin libapache2-mod-proxy-html - Transitional package for apache2-bin Changes: apache2 (2.4.7-1ubuntu4.22) trusty-security; urgency=medium . * SECURITY UPDATE: mod_session expiry time issue - debian/patches/CVE-2018-17199-pre1.patch: properly handle sessions that could not be decoded in modules/session/mod_session.c. - debian/patches/CVE-2018-17199.patch: always decode session attributes early in modules/session/mod_session.c. - CVE-2018-17199 * SECURITY UPDATE: mod_auth_digest access control bypass - debian/patches/CVE-2019-0217.patch: fix a race condition in modules/aaa/mod_auth_digest.c. - CVE-2019-0217 * SECURITY UPDATE: URL normalization inconsistincy - debian/patches/CVE-2019-0220-1.patch: merge consecutive slashes in the path in include/http_core.h, include/httpd.h, server/core.c, server/request.c, server/util.c. - debian/patches/CVE-2019-0220-2.patch: fix r->parsed_uri.path safety in server/request.c, server/util.c. - debian/patches/CVE-2019-0220-3.patch: maintainer mode fix in server/util.c. - CVE-2019-0220 Checksums-Sha1: f3a24d6fc8a9915ce2a6203dacf3532394c5bf23 1462 libapache2-mod-proxy-html_2.4.7-1ubuntu4.22_i386.deb d2c03ef17b638741feafde8b265c3ab6083a8adb 1446 libapache2-mod-macro_2.4.7-1ubuntu4.22_i386.deb 9e333c0a2cce46e2d0771e6a5cd71122ffad5652 87372 apache2_2.4.7-1ubuntu4.22_i386.deb bcf99684dac8a8861d613295fd4d23d10fe302ef 159764 apache2-data_2.4.7-1ubuntu4.22_all.deb 6b48389449617dcfa38a5d4d885698d2d1ddf1fd 829586 apache2-bin_2.4.7-1ubuntu4.22_i386.deb 575699f47e7a2c147bf148c51943992787671665 1456 apache2-mpm-worker_2.4.7-1ubuntu4.22_i386.deb b5655c2b8a143cb8f1a5fe4a46433d7069998cf8 1458 apache2-mpm-prefork_2.4.7-1ubuntu4.22_i386.deb 9307892172bac40afd0c25c9c3dad6a78cdd098d 1456 apache2-mpm-event_2.4.7-1ubuntu4.22_i386.deb 5956b6a9cb78f0eb65aee2b187d8d0cf787a33dd 1458 apache2-mpm-itk_2.4.7-1ubuntu4.22_i386.deb f85e9103c7b6b5abfb5df18cfa4d47ffe01c2589 1476 apache2.2-bin_2.4.7-1ubuntu4.22_i386.deb c405a7b8251b9a5ed1224c4f7e992359bf40bcfc 82962 apache2-utils_2.4.7-1ubuntu4.22_i386.deb 09e8fbcc69a0ec9165e875a85ccd7dc55933fe08 1438 apache2-suexec_2.4.7-1ubuntu4.22_i386.deb b2d57cc51502b75b44e6290425b6db33537444cf 13594 apache2-suexec-pristine_2.4.7-1ubuntu4.22_i386.deb 28415a644b3b51c09cc130815836b994b8dc4e5c 15064 apache2-suexec-custom_2.4.7-1ubuntu4.22_i386.deb 7cd0a16afccc88032bc84f17a83d489d57898228 2602382 apache2-doc_2.4.7-1ubuntu4.22_all.deb 8ede650072c6b7c2e11b27624cd1e59a6d92c297 167250 apache2-dev_2.4.7-1ubuntu4.22_i386.deb 7f5b122472758ce4cc81672a1c2108323cbee64b 1860472 apache2-dbg_2.4.7-1ubuntu4.22_i386.deb 756beef3a5634b865bc0c8b92e1db0ec3aa14ac3 1756582 apache2-bin-dbgsym_2.4.7-1ubuntu4.22_i386.ddeb 5d0a08b0a2e722767b3506e1a06aae77346a59f1 95222 apache2-utils-dbgsym_2.4.7-1ubuntu4.22_i386.ddeb 805e36467fbcb601c94763f70a195dd8c6ed17b5 9148 apache2-suexec-pristine-dbgsym_2.4.7-1ubuntu4.22_i386.ddeb 7288da2d519997de1ee6f2cd1c7c8fc41737711a 10064 apache2-suexec-custom-dbgsym_2.4.7-1ubuntu4.22_i386.ddeb Checksums-Sha256: 8eae5607324827c6a6f85fc387b6f0ae75041920802dba173030e0b7e3b1574b 1462 libapache2-mod-proxy-html_2.4.7-1ubuntu4.22_i386.deb effe250a5ee6144017446d757c6ff6d79496849b25e70fa5081f2ffde807dc4a 1446 libapache2-mod-macro_2.4.7-1ubuntu4.22_i386.deb b5b01579fc83f9636c35d0f21e5b97ea460cc1fc6ffa390ee291a3be62da1f58 87372 apache2_2.4.7-1ubuntu4.22_i386.deb 030edd796c164f7fea97c4225f4a328d68a9b1e445dd19482a6ec07171126319 159764 apache2-data_2.4.7-1ubuntu4.22_all.deb 2804106ef40da36d9c04581d6eb53209ac31eac4309c852fa2c0aef26432e7e2 829586 apache2-bin_2.4.7-1ubuntu4.22_i386.deb 66923d6da74dddaee5d05774d3312fdb3247709460370dfd74b189bc3ad356ea 1456 apache2-mpm-worker_2.4.7-1ubuntu4.22_i386.deb d8d4619d1fb3c83d18e96f2801a0bb0a85283c5035bee812ff78e0f42a12e9fd 1458 apache2-mpm-prefork_2.4.7-1ubuntu4.22_i386.deb 6686d60aebdede5743b9988cb12fe615ff05ebe933119bf17779b3ec6f5966a5 1456 apache2-mpm-event_2.4.7-1ubuntu4.22_i386.deb 59b6515471a25f9e605bfad992d91bc48d02929d3578bc1f12409a5a3160b7ed 1458 apache2-mpm-itk_2.4.7-1ubuntu4.22_i386.deb 5d76e7ac5e9f3e88d38fbfa133402091ffb93ccb8a8edf15e3f7a296fd5ab31d 1476 apache2.2-bin_2.4.7-1ubuntu4.22_i386.deb 05f81e5035575d845ebc30f5699921b1815f12a006b006f131b29595db1dce39 82962 apache2-utils_2.4.7-1ubuntu4.22_i386.deb ca28aff0d308a7c8d96f2dcb1ad26a4fbd9f83a3799c3c8a6ba76a8f68ac6ed6 1438 apache2-suexec_2.4.7-1ubuntu4.22_i386.deb 45f9de05a69c95b37d272660edcaa947200f242432bc94582da514451bd76ae8 13594 apache2-suexec-pristine_2.4.7-1ubuntu4.22_i386.deb 42020763c54817176c86bb61550d1167b0a04ad0112168f90b6a8b3c4d8d9d89 15064 apache2-suexec-custom_2.4.7-1ubuntu4.22_i386.deb dadda92c658d1aa4f4835e32bf31df0f796911c7485e7282f889ef92c2b4ce62 2602382 apache2-doc_2.4.7-1ubuntu4.22_all.deb 85b6d86f892cec26663a7c7a8bd40eda52e24b3285fc3896846227f58d9b7bbf 167250 apache2-dev_2.4.7-1ubuntu4.22_i386.deb 042233a79346f74b27a8090d7384c73798711755912d6b61a9c155e52138cf9d 1860472 apache2-dbg_2.4.7-1ubuntu4.22_i386.deb c886a3a8e67f7b53f60d6a129a57ef17bb41c0f5a3e54779f9959e442881c3a7 1756582 apache2-bin-dbgsym_2.4.7-1ubuntu4.22_i386.ddeb c96d81ee7c541b7a0a0bd3af578f7157bb7eaf8d0cf6234212f1c6a04a2cbcc3 95222 apache2-utils-dbgsym_2.4.7-1ubuntu4.22_i386.ddeb 489a7238a312d8e6125a0af21e239bc4eadbc555d6e3a60dd0b34e3165cf4e12 9148 apache2-suexec-pristine-dbgsym_2.4.7-1ubuntu4.22_i386.ddeb 681298b6ec9d25e134bc7d50a41e5541f39cbf89128a73f8a1cafc3af987e495 10064 apache2-suexec-custom-dbgsym_2.4.7-1ubuntu4.22_i386.ddeb Files: ed508c6c8964b34d2dceefe00ea7a732 1462 oldlibs extra libapache2-mod-proxy-html_2.4.7-1ubuntu4.22_i386.deb 05dc0aba0398b861faace1b11f95f242 1446 oldlibs extra libapache2-mod-macro_2.4.7-1ubuntu4.22_i386.deb da79507565d04bff4e7fcfb2f3afb9ad 87372 httpd optional apache2_2.4.7-1ubuntu4.22_i386.deb 115203dc7f5a1b6c25e1679a216e918f 159764 httpd optional apache2-data_2.4.7-1ubuntu4.22_all.deb e09423e484e8ee1af117c0bcfa09118a 829586 httpd optional apache2-bin_2.4.7-1ubuntu4.22_i386.deb b6c526fca31db2723e4d2869827f2ed4 1456 oldlibs extra apache2-mpm-worker_2.4.7-1ubuntu4.22_i386.deb 424c8c3e227d943ea1fdc1f1e7fae06b 1458 oldlibs extra apache2-mpm-prefork_2.4.7-1ubuntu4.22_i386.deb 69b3293ea0abcd9b13519b562c422c98 1456 oldlibs extra apache2-mpm-event_2.4.7-1ubuntu4.22_i386.deb 0f45079840c4d88a4fef611bee01a664 1458 oldlibs extra apache2-mpm-itk_2.4.7-1ubuntu4.22_i386.deb 4dc14c7df519c858d696de7ab009fc87 1476 oldlibs extra apache2.2-bin_2.4.7-1ubuntu4.22_i386.deb 5ff2ac2ce284f4930777d3f4aaf12275 82962 httpd optional apache2-utils_2.4.7-1ubuntu4.22_i386.deb dcba830530e9a94881e7810a1c8e9a0c 1438 oldlibs extra apache2-suexec_2.4.7-1ubuntu4.22_i386.deb 444a62fc4c2fe024736ec6238c28f461 13594 httpd optional apache2-suexec-pristine_2.4.7-1ubuntu4.22_i386.deb f4b400c49b407a26e175d8a039b9fa36 15064 httpd extra apache2-suexec-custom_2.4.7-1ubuntu4.22_i386.deb cef9815902c489b4dd65a46551cdbcac 2602382 doc optional apache2-doc_2.4.7-1ubuntu4.22_all.deb 9fe8d63d225282689cb945ffd22a780d 167250 httpd optional apache2-dev_2.4.7-1ubuntu4.22_i386.deb 09a6b62f89a57607d48a1d1212827091 1860472 debug extra apache2-dbg_2.4.7-1ubuntu4.22_i386.deb 4e033237da1201219f20d3ee70aa2194 1756582 httpd extra apache2-bin-dbgsym_2.4.7-1ubuntu4.22_i386.ddeb 74558ad012523c69a28798023f3183c5 95222 httpd extra apache2-utils-dbgsym_2.4.7-1ubuntu4.22_i386.ddeb 12703f1ad2a7165f442d5eb7679a4dca 9148 httpd extra apache2-suexec-pristine-dbgsym_2.4.7-1ubuntu4.22_i386.ddeb a1d81b2e93b9c5f6625b8aec5973c4c9 10064 httpd extra apache2-suexec-custom-dbgsym_2.4.7-1ubuntu4.22_i386.ddeb Original-Maintainer: Debian Apache Maintainers