Format: 1.8 Date: Thu, 14 Jul 2016 08:40:55 -0400 Source: apache2 Binary: apache2 apache2-data apache2-bin apache2-mpm-worker apache2-mpm-prefork apache2-mpm-event apache2-mpm-itk apache2.2-bin libapache2-mod-proxy-html libapache2-mod-macro apache2-utils apache2-suexec apache2-suexec-pristine apache2-suexec-custom apache2-doc apache2-dev apache2-dbg Architecture: source Version: 2.4.7-1ubuntu4.13 Distribution: trusty-security Urgency: medium Maintainer: Ubuntu Developers Changed-By: Marc Deslauriers Description: apache2 - Apache HTTP Server apache2-bin - Apache HTTP Server (binary files and modules) apache2-data - Apache HTTP Server (common files) apache2-dbg - Apache debugging symbols apache2-dev - Apache HTTP Server (development headers) apache2-doc - Apache HTTP Server (on-site documentation) apache2-mpm-event - transitional event MPM package for apache2 apache2-mpm-itk - transitional itk MPM package for apache2 apache2-mpm-prefork - transitional prefork MPM package for apache2 apache2-mpm-worker - transitional worker MPM package for apache2 apache2-suexec - transitional package for apache2-suexec-pristine apache2-suexec-custom - Apache HTTP Server configurable suexec program for mod_suexec apache2-suexec-pristine - Apache HTTP Server standard suexec program for mod_suexec apache2-utils - Apache HTTP Server (utility programs for web servers) apache2.2-bin - Transitional package for apache2-bin libapache2-mod-macro - Transitional package for apache2-bin libapache2-mod-proxy-html - Transitional package for apache2-bin Changes: apache2 (2.4.7-1ubuntu4.13) trusty-security; urgency=medium . * SECURITY UPDATE: proxy request header vulnerability (httpoxy) - debian/patches/CVE-2016-5387.patch: don't pass through HTTP_PROXY in server/util_script.c. - CVE-2016-5387 * This update does _not_ contain the changes from (2.4.7-1ubuntu4.12) in trusty-proposed. Checksums-Sha1: 2eefb93d0eed1805f56588b7b361bf02046e1a2e 3171 apache2_2.4.7-1ubuntu4.13.dsc d58592ede75a451e5fdb2634ba596743a922cdc6 524861 apache2_2.4.7-1ubuntu4.13.debian.tar.gz Checksums-Sha256: 943d072a041c3004931f10be8f2bbf94712569fa5a68c1c0be1a978ebd9017e1 3171 apache2_2.4.7-1ubuntu4.13.dsc 2ac1ac6a301dbd25c5923b4cfa8ad83dd42f44c66c2928c736e0dc10c2fcbc92 524861 apache2_2.4.7-1ubuntu4.13.debian.tar.gz Files: 3c349c2dfd01a72a74b2e8bbcda08b5f 3171 httpd optional apache2_2.4.7-1ubuntu4.13.dsc 2ed5712d2d21e4b131f757fd040509ca 524861 httpd optional apache2_2.4.7-1ubuntu4.13.debian.tar.gz Original-Maintainer: Debian Apache Maintainers