Format: 1.8 Date: Wed, 08 Mar 2023 12:31:20 -0500 Source: apache2 Binary: apache2 apache2-bin apache2-dev apache2-ssl-dev apache2-suexec-custom apache2-suexec-pristine apache2-utils libapache2-mod-md libapache2-mod-proxy-uwsgi Built-For-Profiles: noudeb Architecture: ppc64el Version: 2.4.54-2ubuntu1.2 Distribution: kinetic Urgency: medium Maintainer: Launchpad Build Daemon Changed-By: Marc Deslauriers Description: apache2 - Apache HTTP Server apache2-bin - Apache HTTP Server (modules and other binary files) apache2-dev - Apache HTTP Server (development headers) apache2-ssl-dev - Apache HTTP Server (mod_ssl development headers) apache2-suexec-custom - Apache HTTP Server configurable suexec program for mod_suexec apache2-suexec-pristine - Apache HTTP Server standard suexec program for mod_suexec apache2-utils - Apache HTTP Server (utility programs for web servers) libapache2-mod-md - transitional package libapache2-mod-proxy-uwsgi - transitional package Changes: apache2 (2.4.54-2ubuntu1.2) kinetic-security; urgency=medium . * SECURITY UPDATE: HTTP request splitting with mod_rewrite and mod_proxy - debian/patches/CVE-2023-25690-1.patch: don't forward invalid query strings in modules/http2/mod_proxy_http2.c, modules/mappers/mod_rewrite.c, modules/proxy/mod_proxy_ajp.c, modules/proxy/mod_proxy_balancer.c, modules/proxy/mod_proxy_http.c, modules/proxy/mod_proxy_wstunnel.c. - debian/patches/CVE-2023-25690-2.patch: Fix missing APLOGNO in modules/http2/mod_proxy_http2.c. - CVE-2023-25690 * SECURITY UPDATE: mod_proxy_uwsgi HTTP response splitting - debian/patches/CVE-2023-27522.patch: stricter backend HTTP response parsing/validation in modules/proxy/mod_proxy_uwsgi.c. - CVE-2023-27522 Checksums-Sha1: d07237988c259615cd7d76a45f53980f5cb526bf 3973368 apache2-bin-dbgsym_2.4.54-2ubuntu1.2_ppc64el.ddeb dc10538a784f0fd4df887d10dced71bf05657b1e 1513340 apache2-bin_2.4.54-2ubuntu1.2_ppc64el.deb c73baf3d7fb27320fdf389ebbabce759e8b29f77 191098 apache2-dev_2.4.54-2ubuntu1.2_ppc64el.deb 8264344f12bdb40273833bb7e8039db283ad1fa1 2980 apache2-ssl-dev_2.4.54-2ubuntu1.2_ppc64el.deb 97da71c72526cab40d2bcee35cba39da41ce1fc6 13324 apache2-suexec-custom-dbgsym_2.4.54-2ubuntu1.2_ppc64el.ddeb 5f465574ee405a10d065b04073ee40e9d7c387f7 15992 apache2-suexec-custom_2.4.54-2ubuntu1.2_ppc64el.deb f037bc10e0d98e047a0ce62895839eddb543e272 11968 apache2-suexec-pristine-dbgsym_2.4.54-2ubuntu1.2_ppc64el.ddeb 1465b12477591ce0dec3e137446ed4d9bfa594ec 14284 apache2-suexec-pristine_2.4.54-2ubuntu1.2_ppc64el.deb d2064c6a3a3a77fe4e9c6194d90332a310f8d2e2 129196 apache2-utils-dbgsym_2.4.54-2ubuntu1.2_ppc64el.ddeb 9447e6fd2daf47439e1f101c47897bf53a2f6e1d 93324 apache2-utils_2.4.54-2ubuntu1.2_ppc64el.deb 2a2b71a02aef21f3f8235da7b6d288fcd84e87f5 12179 apache2_2.4.54-2ubuntu1.2_ppc64el.buildinfo ceccbbefdca6834b5450a2e424d85be40dd69d8e 97306 apache2_2.4.54-2ubuntu1.2_ppc64el.deb 59da4b0989b6c94ea877ddff92f32fed9dab3362 800 libapache2-mod-md_2.4.54-2ubuntu1.2_ppc64el.deb 0228ba5b5757444d49a8f148af1f3ef31365f49e 988 libapache2-mod-proxy-uwsgi_2.4.54-2ubuntu1.2_ppc64el.deb Checksums-Sha256: 66d127c0efe4f56ebb0af7984b53f7b6d8dcacc7c4c6505de0d39ead11095f6d 3973368 apache2-bin-dbgsym_2.4.54-2ubuntu1.2_ppc64el.ddeb 7f49187f4402af56a178e84eca2fefb051c4e4964ba2690615a7963ce6dc25f0 1513340 apache2-bin_2.4.54-2ubuntu1.2_ppc64el.deb 4112b95e5ff355bc31bb6d9152ccaf0186c0c535e6fdf1d31ba72ea4d9096bc1 191098 apache2-dev_2.4.54-2ubuntu1.2_ppc64el.deb 11d47ec922dbc77cc8851a4e8046038376e2a376318daefe640021763e2ec423 2980 apache2-ssl-dev_2.4.54-2ubuntu1.2_ppc64el.deb 85589ac413968b9927a0936488cfc7d96ba2c0ae27e158a079c84225b4da3745 13324 apache2-suexec-custom-dbgsym_2.4.54-2ubuntu1.2_ppc64el.ddeb 756535bcacd60c428c34e8a3c31532671e30cbd07e8cbcb3492f5ef345745fe9 15992 apache2-suexec-custom_2.4.54-2ubuntu1.2_ppc64el.deb 89eba5b2f9356641223b2c7b978be8fcccb7ced8352d28f672f2fe37da28570f 11968 apache2-suexec-pristine-dbgsym_2.4.54-2ubuntu1.2_ppc64el.ddeb b518a0db841e79883db209fb3726df9b93fd8ba14f15639ee3c598785d4e8064 14284 apache2-suexec-pristine_2.4.54-2ubuntu1.2_ppc64el.deb e31a640219f0d40e2cb831964de3ead67e6d590b54d77adab01738d6dc78367e 129196 apache2-utils-dbgsym_2.4.54-2ubuntu1.2_ppc64el.ddeb b0ae4d75bf430dbbcf2babfbf24234ad3eef0ab917a4cdba012a47c087dcd3b9 93324 apache2-utils_2.4.54-2ubuntu1.2_ppc64el.deb 861f4381bad941f1eaf54376c21131385d14ca8c55cf47f50994d4f2ed89e98d 12179 apache2_2.4.54-2ubuntu1.2_ppc64el.buildinfo 4201d966784e174148e6dc933ab4903a2e4538fca7fbe04c0933149866ec7138 97306 apache2_2.4.54-2ubuntu1.2_ppc64el.deb 829ae23b3dedc0242f523a82dd73648a6bbee000055ff8e7d13ec9490b506654 800 libapache2-mod-md_2.4.54-2ubuntu1.2_ppc64el.deb f10209ce7356bec819e40e0a7b5eadddbc8f55514cbf97041fd7227b35bef552 988 libapache2-mod-proxy-uwsgi_2.4.54-2ubuntu1.2_ppc64el.deb Files: 998b183a9818b3c083988f886ea54fe2 3973368 debug optional apache2-bin-dbgsym_2.4.54-2ubuntu1.2_ppc64el.ddeb ea7d8730a9a6a9a969ad2005409e0fa3 1513340 httpd optional apache2-bin_2.4.54-2ubuntu1.2_ppc64el.deb 2197888bdf0c17501518c7eec3373473 191098 httpd optional apache2-dev_2.4.54-2ubuntu1.2_ppc64el.deb 26843a296b8dc8a799a977ea2ac20897 2980 httpd optional apache2-ssl-dev_2.4.54-2ubuntu1.2_ppc64el.deb 7da67fd1bd0e781d386898e7209f69d5 13324 debug optional apache2-suexec-custom-dbgsym_2.4.54-2ubuntu1.2_ppc64el.ddeb 8bfc962821d411a182da15007b52df84 15992 httpd optional apache2-suexec-custom_2.4.54-2ubuntu1.2_ppc64el.deb e68b997853b746e478c3151109f4aeb9 11968 debug optional apache2-suexec-pristine-dbgsym_2.4.54-2ubuntu1.2_ppc64el.ddeb e96624cc8a3e06bbf641950837edd304 14284 httpd optional apache2-suexec-pristine_2.4.54-2ubuntu1.2_ppc64el.deb e09e83fdba69eb82c56793c2391d1143 129196 debug optional apache2-utils-dbgsym_2.4.54-2ubuntu1.2_ppc64el.ddeb 0ed732958f327c910fc8268648835da8 93324 httpd optional apache2-utils_2.4.54-2ubuntu1.2_ppc64el.deb 0ba151e61a7c75349e3b9491457c236f 12179 httpd optional apache2_2.4.54-2ubuntu1.2_ppc64el.buildinfo 5661b01a6a997316fb5b050d1fb71688 97306 httpd optional apache2_2.4.54-2ubuntu1.2_ppc64el.deb 59c4fbfbb8c2c0e8efc5d8023243b8bd 800 oldlibs optional libapache2-mod-md_2.4.54-2ubuntu1.2_ppc64el.deb e536997a906a2a5b7ab62f3d132809ff 988 oldlibs optional libapache2-mod-proxy-uwsgi_2.4.54-2ubuntu1.2_ppc64el.deb Original-Maintainer: Debian Apache Maintainers