Format: 1.8 Date: Thu, 26 Oct 2023 09:54:09 -0400 Source: apache2 Binary: apache2 apache2-bin apache2-dev apache2-ssl-dev apache2-suexec-custom apache2-suexec-pristine apache2-utils libapache2-mod-md libapache2-mod-proxy-uwsgi Architecture: arm64 Version: 2.4.41-4ubuntu3.15 Distribution: focal Urgency: medium Maintainer: Launchpad Build Daemon Changed-By: Marc Deslauriers Description: apache2 - Apache HTTP Server apache2-bin - Apache HTTP Server (modules and other binary files) apache2-dev - Apache HTTP Server (development headers) apache2-ssl-dev - Apache HTTP Server (mod_ssl development headers) apache2-suexec-custom - Apache HTTP Server configurable suexec program for mod_suexec apache2-suexec-pristine - Apache HTTP Server standard suexec program for mod_suexec apache2-utils - Apache HTTP Server (utility programs for web servers) libapache2-mod-md - transitional package libapache2-mod-proxy-uwsgi - transitional package Changes: apache2 (2.4.41-4ubuntu3.15) focal-security; urgency=medium . * SECURITY UPDATE: mod_macro buffer over-read - debian/patches/CVE-2023-31122.patch: fix length in modules/core/mod_macro.c. - CVE-2023-31122 * SECURITY UPDATE: Multiple issues in HTTP/2 - CVE-2023-43622: DoS in HTTP/2 with initial windows size 0 - CVE-2023-45802: HTTP/2 stream memory not reclaimed right away on RST - debian/tests/run-test-suite: run with HARNESS_VERBOSE=1. - debian/patches/update_tests.patch: backport tests from jammy's 2.4.52 to improve test coverage. - debian/patches/update_http2.patch: backport version 2.0.22 of mod_http2 from httpd 2.4.58. - CVE-2023-43622 - CVE-2023-45802 Checksums-Sha1: 2b2da0d0483f90f5e256670e4f920943362f8683 4838240 apache2-bin-dbgsym_2.4.41-4ubuntu3.15_arm64.ddeb 320a40fb2666275b40c60c024f767c784f8973c3 1081184 apache2-bin_2.4.41-4ubuntu3.15_arm64.deb 5093d026a6e1f5e1c342cd67c941f4c57ecf3953 179400 apache2-dev_2.4.41-4ubuntu3.15_arm64.deb 1c60e8e6978732711e763c2a22a6837c4d51bfcc 3156 apache2-ssl-dev_2.4.41-4ubuntu3.15_arm64.deb d7ddebd900a4b88a3bc6a9545b26f386f9d7a968 13008 apache2-suexec-custom-dbgsym_2.4.41-4ubuntu3.15_arm64.ddeb 8daa540e2972e0a9a5eab43b87a93e2cdd6709da 15208 apache2-suexec-custom_2.4.41-4ubuntu3.15_arm64.deb 4645b4bd33fbe0c4ce2a8ba2af01a3d09b0dc485 11832 apache2-suexec-pristine-dbgsym_2.4.41-4ubuntu3.15_arm64.ddeb 8b6648fc564fd6833cfd9f2b07c6e0297dff1c96 13724 apache2-suexec-pristine_2.4.41-4ubuntu3.15_arm64.deb 0c1fafbb20cca8d138f56050528ee655154168b8 140940 apache2-utils-dbgsym_2.4.41-4ubuntu3.15_arm64.ddeb 136bde5445a8bd4f8a32151d8a30d676a7af5f0d 81048 apache2-utils_2.4.41-4ubuntu3.15_arm64.deb 94687b7e3aa139c5f3beaa86d75333d2b0e7aec0 12045 apache2_2.4.41-4ubuntu3.15_arm64.buildinfo a0bad56249f20a4d58766e88e4799ca27fda5821 95592 apache2_2.4.41-4ubuntu3.15_arm64.deb f91f52abf8c425617495b7cc7e595d2730c3154e 988 libapache2-mod-md_2.4.41-4ubuntu3.15_arm64.deb 373a6dd01690486b084439964415835bf7ebfc04 1184 libapache2-mod-proxy-uwsgi_2.4.41-4ubuntu3.15_arm64.deb Checksums-Sha256: 3f9c2f0149eab1b93e44bc417e412d7bd3cfcce18c4d535607b0ede3ea586168 4838240 apache2-bin-dbgsym_2.4.41-4ubuntu3.15_arm64.ddeb 730df4d140012269ab3a49c2b44df0afc23fac428bfdf15b3d905c176cea983c 1081184 apache2-bin_2.4.41-4ubuntu3.15_arm64.deb 5fd49705afbf913f8d4063f05affbc344e990f8055fe6b210c7b9e9beb915f44 179400 apache2-dev_2.4.41-4ubuntu3.15_arm64.deb f60bc18c61bdfb01e0c93a80c1e7e4d40af54a0df1ed0bbfaefb6bb84f0dfb18 3156 apache2-ssl-dev_2.4.41-4ubuntu3.15_arm64.deb b076285b81732651f8a3b387734fed1d598d893fcded0c2e4d526bbc139b6e0a 13008 apache2-suexec-custom-dbgsym_2.4.41-4ubuntu3.15_arm64.ddeb 45a0f501409b2699762427d758d49ba7f00a83e2a9195a523654fac60751c8b1 15208 apache2-suexec-custom_2.4.41-4ubuntu3.15_arm64.deb 33c5041c34a9d63662605ec4f45ed1f2ecac312c05a0c0739194ba49192a5633 11832 apache2-suexec-pristine-dbgsym_2.4.41-4ubuntu3.15_arm64.ddeb a88bc535b001372041e57d48dcc0dcd55b560f824bc1c815eb0090a80ffc3522 13724 apache2-suexec-pristine_2.4.41-4ubuntu3.15_arm64.deb f191e0bafb3c8a6ea0e1dc7689c19fa6167dc93d25c1c120eb82a06c4b72e340 140940 apache2-utils-dbgsym_2.4.41-4ubuntu3.15_arm64.ddeb a2d70da5eb6832e49bd19f10d1496dcd1920c709e2a529789d02340a420f3fd2 81048 apache2-utils_2.4.41-4ubuntu3.15_arm64.deb 37c0aafc5c295a46cbb964d6ba1687712ed4883db692b08dcb33216c59c7e4df 12045 apache2_2.4.41-4ubuntu3.15_arm64.buildinfo 53ac5dd96fa76d20d31d6adb9889c4555d46d999bd01ea72a28c3244b47ba406 95592 apache2_2.4.41-4ubuntu3.15_arm64.deb 4bcaa874b1bde78a50c86199d477c5de1d9bc712e4fd37422831f4a98119e185 988 libapache2-mod-md_2.4.41-4ubuntu3.15_arm64.deb e30377de2bca561a675b8d6b5cc46cdae63f69906025d7cf8dce53aea23db084 1184 libapache2-mod-proxy-uwsgi_2.4.41-4ubuntu3.15_arm64.deb Files: 522f48d6a340f8ea6d637c3a98843e7e 4838240 debug optional apache2-bin-dbgsym_2.4.41-4ubuntu3.15_arm64.ddeb dfeb6295732f65893544fa427c21d6fc 1081184 httpd optional apache2-bin_2.4.41-4ubuntu3.15_arm64.deb c1b128a011c1a351e879d95c4893bcf8 179400 httpd optional apache2-dev_2.4.41-4ubuntu3.15_arm64.deb c6a7eb40ce15ceaad42a58bb972dd785 3156 httpd optional apache2-ssl-dev_2.4.41-4ubuntu3.15_arm64.deb ae498beee6e6bfc0925612b5e47d795c 13008 debug optional apache2-suexec-custom-dbgsym_2.4.41-4ubuntu3.15_arm64.ddeb bb7bcdeef77f31da068d07282c18cfc4 15208 httpd optional apache2-suexec-custom_2.4.41-4ubuntu3.15_arm64.deb 8e50fe00ca85aaa1a9e9f09e866998ce 11832 debug optional apache2-suexec-pristine-dbgsym_2.4.41-4ubuntu3.15_arm64.ddeb 16cc55eb3dc2b205689449e01a3c416b 13724 httpd optional apache2-suexec-pristine_2.4.41-4ubuntu3.15_arm64.deb 4d51140623c434c835d7831022caeb5e 140940 debug optional apache2-utils-dbgsym_2.4.41-4ubuntu3.15_arm64.ddeb 02a03b271019c7a4d94f642d869affe3 81048 httpd optional apache2-utils_2.4.41-4ubuntu3.15_arm64.deb 3bfd5f7189401de5747abc97cad9e014 12045 httpd optional apache2_2.4.41-4ubuntu3.15_arm64.buildinfo 20d0ce16573632ed817db7a94752d853 95592 httpd optional apache2_2.4.41-4ubuntu3.15_arm64.deb 4ae3243973362cfe8352e17b6e5936b1 988 oldlibs optional libapache2-mod-md_2.4.41-4ubuntu3.15_arm64.deb 2ed15c87debf1635003f20b25402752b 1184 oldlibs optional libapache2-mod-proxy-uwsgi_2.4.41-4ubuntu3.15_arm64.deb Original-Maintainer: Debian Apache Maintainers