Publishing details
Changelog
apache2 (2.4.7-1ubuntu4.22) trusty-security; urgency=medium
* SECURITY UPDATE: mod_session expiry time issue
- debian/patches/CVE-2018-17199-pre1.patch: properly handle sessions
that could not be decoded in modules/session/mod_session.c.
- debian/patches/CVE-2018-17199.patch: always decode session attributes
early in modules/session/mod_session.c.
- CVE-2018-17199
* SECURITY UPDATE: mod_auth_digest access control bypass
- debian/patches/CVE-2019-0217.patch: fix a race condition in
modules/aaa/mod_auth_digest.c.
- CVE-2019-0217
* SECURITY UPDATE: URL normalization inconsistincy
- debian/patches/CVE-2019-0220-1.patch: merge consecutive slashes in
the path in include/http_core.h, include/httpd.h, server/core.c,
server/request.c, server/util.c.
- debian/patches/CVE-2019-0220-2.patch: fix r->parsed_uri.path safety
in server/request.c, server/util.c.
- debian/patches/CVE-2019-0220-3.patch: maintainer mode fix in
server/util.c.
- CVE-2019-0220
-- Marc Deslauriers <email address hidden> Wed, 03 Apr 2019 10:37:52 -0400
Builds
Built packages
-
apache2
Apache HTTP Server
-
apache2-bin
Apache HTTP Server (binary files and modules)
-
apache2-bin-dbgsym
debug symbols for package apache2-bin
-
apache2-data
Apache HTTP Server (common files)
-
apache2-dbg
Apache debugging symbols
-
apache2-dev
Apache HTTP Server (development headers)
-
apache2-doc
Apache HTTP Server (on-site documentation)
-
apache2-mpm-event
transitional event MPM package for apache2
-
apache2-mpm-itk
transitional itk MPM package for apache2
-
apache2-mpm-prefork
transitional prefork MPM package for apache2
-
apache2-mpm-worker
transitional worker MPM package for apache2
-
apache2-suexec
transitional package for apache2-suexec-pristine
-
apache2-suexec-custom
Apache HTTP Server configurable suexec program for mod_suexec
-
apache2-suexec-custom-dbgsym
debug symbols for package apache2-suexec-custom
-
apache2-suexec-pristine
Apache HTTP Server standard suexec program for mod_suexec
-
apache2-suexec-pristine-dbgsym
debug symbols for package apache2-suexec-pristine
-
apache2-utils
Apache HTTP Server (utility programs for web servers)
-
apache2-utils-dbgsym
debug symbols for package apache2-utils
-
apache2.2-bin
Transitional package for apache2-bin
-
libapache2-mod-macro
Transitional package for apache2-bin
-
libapache2-mod-proxy-html
Transitional package for apache2-bin
Package files