Format: 1.8 Date: Thu, 16 Dec 2021 14:09:26 -0800 Source: apache2 Binary: apache2 apache2-bin apache2-data apache2-dev apache2-doc apache2-ssl-dev apache2-suexec-custom apache2-suexec-pristine apache2-utils libapache2-mod-md libapache2-mod-proxy-uwsgi Built-For-Profiles: noudeb Architecture: amd64 all Version: 2.4.51-2ubuntu1 Distribution: jammy-proposed Urgency: medium Maintainer: Launchpad Build Daemon Changed-By: Bryce Harrington Description: apache2 - Apache HTTP Server apache2-bin - Apache HTTP Server (modules and other binary files) apache2-data - Apache HTTP Server (common files) apache2-dev - Apache HTTP Server (development headers) apache2-doc - Apache HTTP Server (on-site documentation) apache2-ssl-dev - Apache HTTP Server (mod_ssl development headers) apache2-suexec-custom - Apache HTTP Server configurable suexec program for mod_suexec apache2-suexec-pristine - Apache HTTP Server standard suexec program for mod_suexec apache2-utils - Apache HTTP Server (utility programs for web servers) libapache2-mod-md - transitional package libapache2-mod-proxy-uwsgi - transitional package Changes: apache2 (2.4.51-2ubuntu1) jammy; urgency=medium . * Merge with Debian unstable. Remaining changes: - debian/{control, apache2.install, apache2-utils.ufw.profile, apache2.dirs}: Add ufw profiles. (LP 261198) - debian/apache2.py, debian/apache2-bin.install: Add apport hook. (LP 609177) - d/index.html, d/icons/ubuntu-logo.png, d/apache2.postrm, d/s/include-binaries: replace Debian with Ubuntu on default page and add Ubuntu icon file. (LP 1288690) - d/p/support-openssl3-*.patch: Backport various patches from https://github.com/apache/httpd/pull/258 in order to fix mod_ssl's failure to load when using OpenSSL 3. (LP #1951476) * Dropped: - d/apache2ctl: Also use systemd for graceful if it is in use. (LP: 1832182) [This introduced a performance regression.] - d/apache2ctl: Also use /run/systemd to check for systemd usage. (LP 1918209) [Not needed] - debian/patches/CVE-2021-33193.patch: refactor request parsing in include/ap_mmn.h, include/http_core.h, include/http_protocol.h, include/http_vhost.h, modules/http2/h2_request.c, server/core.c, server/core_filters.c, server/protocol.c, server/vhost.c. [Fixed in 2.4.48-4] - debian/patches/CVE-2021-34798.patch: add NULL check in server/scoreboard.c. [Fixed in 2.4.49-1] - debian/patches/CVE-2021-36160.patch: fix PATH_INFO setting for generic worker in modules/proxy/mod_proxy_uwsgi.c. [Fixed in 2.4.49-1] - debian/patches/CVE-2021-39275.patch: fix ap_escape_quotes substitution logic in server/util.c. [Fixed in 2.4.49-1] - arbitrary origin server via crafted request uri-path + debian/patches/CVE-2021-40438-pre1.patch: faster unix socket path parsing in the "proxy:" URL in modules/proxy/mod_proxy.c, modules/proxy/proxy_util.c. + debian/patches/CVE-2021-40438.patch: add sanity checks on the configured UDS path in modules/proxy/proxy_util.c. [Fixed in 2.4.49-3] - SECURITY REGRESSION: Issues in UDS URIs. (LP #1945311) + debian/patches/CVE-2021-40438-2.patch: Fix UDS unix: scheme for P rules in modules/mappers/mod_rewrite.c. + debian/patches/CVE-2021-40438-3.patch: Handle UDS URIs with empty hostname in modules/mappers/mod_rewrite.c, modules/proxy/proxy_util.c. [Fixed in 2.4.49-3] Checksums-Sha1: 82489ce1b6dfed227e348b2effd61e16f34b57a8 3883074 apache2-bin-dbgsym_2.4.51-2ubuntu1_amd64.ddeb a7076c70ff58b52694d261e138501e0fadbd848d 1339294 apache2-bin_2.4.51-2ubuntu1_amd64.deb 9724646b6b4753a2ee35ba1cc772be8b72c3941a 164902 apache2-data_2.4.51-2ubuntu1_all.deb a00b8139dfbc5ab01f23d4a0225407872aa99b10 189478 apache2-dev_2.4.51-2ubuntu1_amd64.deb eeac42714628a9a1c617b8cebcebf0a08ce223f6 3865880 apache2-doc_2.4.51-2ubuntu1_all.deb b1de21152fe509ed2e610379436147bf120ca1f5 2978 apache2-ssl-dev_2.4.51-2ubuntu1_amd64.deb fb0bc0a99858ebd9f6223866f893fb019ce31c98 12902 apache2-suexec-custom-dbgsym_2.4.51-2ubuntu1_amd64.ddeb 365358e7a9ea0f23a909c7662654d4b410351e7e 16524 apache2-suexec-custom_2.4.51-2ubuntu1_amd64.deb 1e1db72d76314549caef47e31a9a403aa220a417 11542 apache2-suexec-pristine-dbgsym_2.4.51-2ubuntu1_amd64.ddeb 2a5129206acae377d97bc695bb61868b24f673c2 14862 apache2-suexec-pristine_2.4.51-2ubuntu1_amd64.deb 1e5161c978f610c90410ea1c93215b5dbd18df95 120076 apache2-utils-dbgsym_2.4.51-2ubuntu1_amd64.ddeb ef752938520cfbfa31c168c05a895a9a1be6065c 88442 apache2-utils_2.4.51-2ubuntu1_amd64.deb 69a416fa3cb14875f11882b768b8dd48b0d773e1 11941 apache2_2.4.51-2ubuntu1_amd64.buildinfo 943792ab2c427346f30484fdc3b5dda5505ee574 97970 apache2_2.4.51-2ubuntu1_amd64.deb ea5091defb713072c372903a3522f95dd5c2ddc7 798 libapache2-mod-md_2.4.51-2ubuntu1_amd64.deb 9c0da9ff215aea6c10800b11ed99470509055514 984 libapache2-mod-proxy-uwsgi_2.4.51-2ubuntu1_amd64.deb Checksums-Sha256: 3f7735e601d1fa2435ae845b7281c72adfcaf66d22eb250593ca61658447d34a 3883074 apache2-bin-dbgsym_2.4.51-2ubuntu1_amd64.ddeb 1b916a1f0edf3402bfbadcd8f7a2b233313648250cf1a3a619addfa21c401e9d 1339294 apache2-bin_2.4.51-2ubuntu1_amd64.deb 41a22ef0f1bfd7a672eb88bbddb7216dee1e30878811a7f37930336048d48502 164902 apache2-data_2.4.51-2ubuntu1_all.deb 8541235ecf018954e94e0f6d23b4204b2fc2b157caf102a022e98c9738679e3e 189478 apache2-dev_2.4.51-2ubuntu1_amd64.deb 8f34bd1bf8dc89781aa8bd6d4d43a2111edc7aa5833bd3322996da301a9d02b3 3865880 apache2-doc_2.4.51-2ubuntu1_all.deb d7c52f1e419c9ada96141b663d8fa05719c2a06487f8bbcb90d03c99f4842b1e 2978 apache2-ssl-dev_2.4.51-2ubuntu1_amd64.deb 7a0ceb55e0775b09069ef4f09aabcd00a762d55d9e09411cc5e6180b692dc695 12902 apache2-suexec-custom-dbgsym_2.4.51-2ubuntu1_amd64.ddeb 50cdc9c3000e36a3ecc104aeb15268e668fc70ad11783149ca948ee12e79e64a 16524 apache2-suexec-custom_2.4.51-2ubuntu1_amd64.deb 40de6cf70640109962390853e9e4a1dda264f990034b715566091d3223063301 11542 apache2-suexec-pristine-dbgsym_2.4.51-2ubuntu1_amd64.ddeb 8dd59d99e1f0cf3ca8368d7d75b4ecf6571169a41bc1c2a0d101b567713e12a1 14862 apache2-suexec-pristine_2.4.51-2ubuntu1_amd64.deb 711bf41546ead4546f989df0ee5909e76cff4bd74274fbd7a18d8d17d91fc7e3 120076 apache2-utils-dbgsym_2.4.51-2ubuntu1_amd64.ddeb f4ba42b5fcbdd2884f1d1125db7f0e751eeccb54ecde48c881f771adac86fd1b 88442 apache2-utils_2.4.51-2ubuntu1_amd64.deb 8d8cff1623e6745c8710a62030c5337cafe43cb22096e2d4e454848add1f27b2 11941 apache2_2.4.51-2ubuntu1_amd64.buildinfo 27a2b2dc6b223566d3eece8ba8844b8f4b1af80a2f87c82909f988aa08ab0b51 97970 apache2_2.4.51-2ubuntu1_amd64.deb 946c4c0dfb93dec96ce4cd523fb1ca130c87dfc4121959df7e0be0cb6d63fb6c 798 libapache2-mod-md_2.4.51-2ubuntu1_amd64.deb a11c6c136c8090bdfedc1bff562bd96ec7f081c422f9387c911d38e4a5089177 984 libapache2-mod-proxy-uwsgi_2.4.51-2ubuntu1_amd64.deb Files: b4b941ee9f996d38936cdf97c0a84a64 3883074 debug optional apache2-bin-dbgsym_2.4.51-2ubuntu1_amd64.ddeb ecc783a09b91533fe9d8c129e95094e1 1339294 httpd optional apache2-bin_2.4.51-2ubuntu1_amd64.deb b64ad630cbdb62b984b31fe6ebe74e7b 164902 httpd optional apache2-data_2.4.51-2ubuntu1_all.deb 4969122005a6353df248855413214b34 189478 httpd optional apache2-dev_2.4.51-2ubuntu1_amd64.deb 9efa8491d51e1fb4edff436030324279 3865880 doc optional apache2-doc_2.4.51-2ubuntu1_all.deb c9220cb632b98a0e852bb36fb4557dec 2978 httpd optional apache2-ssl-dev_2.4.51-2ubuntu1_amd64.deb 1c00a46daac8eda1b38d7815678afd2d 12902 debug optional apache2-suexec-custom-dbgsym_2.4.51-2ubuntu1_amd64.ddeb c0e2e99078b7762454e5c3b3291ad1c4 16524 httpd optional apache2-suexec-custom_2.4.51-2ubuntu1_amd64.deb 0a8852e70de02e37c852ca4ce863a5f5 11542 debug optional apache2-suexec-pristine-dbgsym_2.4.51-2ubuntu1_amd64.ddeb 9ba7e44e349c77d7f06a508052c55a30 14862 httpd optional apache2-suexec-pristine_2.4.51-2ubuntu1_amd64.deb 857953d06cb711642cfda08067892f67 120076 debug optional apache2-utils-dbgsym_2.4.51-2ubuntu1_amd64.ddeb 850faca33890f26e2de3ed2909413f3f 88442 httpd optional apache2-utils_2.4.51-2ubuntu1_amd64.deb f9384b7473c9346234e4d6655e7bfb5b 11941 httpd optional apache2_2.4.51-2ubuntu1_amd64.buildinfo 615cb7071b9c8498d2063e5f1dbc9f48 97970 httpd optional apache2_2.4.51-2ubuntu1_amd64.deb d28261d5eaebe72111d5e35b40dc92e8 798 oldlibs optional libapache2-mod-md_2.4.51-2ubuntu1_amd64.deb 9b2771e31be1bca476c87b2ca321cb42 984 oldlibs optional libapache2-mod-proxy-uwsgi_2.4.51-2ubuntu1_amd64.deb Original-Maintainer: Debian Apache Maintainers