Format: 1.8 Date: Mon, 26 Jun 2017 07:57:04 -0400 Source: apache2 Binary: apache2 apache2-data apache2-bin apache2-utils apache2-suexec-pristine apache2-suexec-custom apache2-doc apache2-dev apache2-dbg Architecture: ppc64el Version: 2.4.18-2ubuntu4.2 Distribution: yakkety Urgency: medium Maintainer: Launchpad Build Daemon Changed-By: Marc Deslauriers Description: apache2 - Apache HTTP Server apache2-bin - Apache HTTP Server (modules and other binary files) apache2-data - Apache HTTP Server (common files) apache2-dbg - Apache debugging symbols apache2-dev - Apache HTTP Server (development headers) apache2-doc - Apache HTTP Server (on-site documentation) apache2-suexec-custom - Apache HTTP Server configurable suexec program for mod_suexec apache2-suexec-pristine - Apache HTTP Server standard suexec program for mod_suexec apache2-utils - Apache HTTP Server (utility programs for web servers) Changes: apache2 (2.4.18-2ubuntu4.2) yakkety-security; urgency=medium . * SECURITY UPDATE: authentication bypass in ap_get_basic_auth_pw() - debian/patches/CVE-2017-3167.patch: deprecate and replace ap_get_basic_auth_pw in include/ap_mmn.h, include/http_protocol.h, server/protocol.c, server/request.c. - CVE-2017-3167 * SECURITY UPDATE: NULL pointer deref in ap_hook_process_connection() - debian/patches/CVE-2017-3169.patch: fix ctx passed to ssl_io_filter_error() in modules/ssl/ssl_engine_io.c. - CVE-2017-3169 * SECURITY UPDATE: denial of service and possible incorrect value return in HTTP strict parsing changes - debian/patches/CVE-2017-7668.patch: short-circuit on NULL in server/util.c. - CVE-2017-7668 * SECURITY UPDATE: mod_mime DoS via crafted Content-Type response header - debian/patches/CVE-2017-7679.patch: fix quoted pair scanning in modules/http/mod_mime.c. - CVE-2017-7679 Checksums-Sha1: 39584b944106f05fbbb70fad47f7b30c708925dd 988 apache2-bin-dbgsym_2.4.18-2ubuntu4.2_ppc64el.ddeb 59c79bb289acc0fa208ff0b00b4afe0f9a8b3ab4 871966 apache2-bin_2.4.18-2ubuntu4.2_ppc64el.deb d5510e43d929798c687b91d67a5ce77189964d46 2364288 apache2-dbg_2.4.18-2ubuntu4.2_ppc64el.deb af5c8908470fa69370c476cdca679ae4712b33a3 970 apache2-dbgsym_2.4.18-2ubuntu4.2_ppc64el.ddeb 44c62d3df0506abd21a6f804f1d4cb3c5365e986 1108 apache2-dev-dbgsym_2.4.18-2ubuntu4.2_ppc64el.ddeb fe9c1f71ad6bd4932161bcf52a2ebe0b5de024d5 172928 apache2-dev_2.4.18-2ubuntu4.2_ppc64el.deb c182266b37e6f08e435f15868508838d34bfa158 974 apache2-suexec-custom-dbgsym_2.4.18-2ubuntu4.2_ppc64el.ddeb 5ca3f3591a7df37a0492f9aca41277e8ea65147b 15076 apache2-suexec-custom_2.4.18-2ubuntu4.2_ppc64el.deb eee8496e506bc26b9db513342e756c896a5f5bb9 918 apache2-suexec-pristine-dbgsym_2.4.18-2ubuntu4.2_ppc64el.ddeb a6a916b2a8ef3793b6c78108fa97888638da49d8 13544 apache2-suexec-pristine_2.4.18-2ubuntu4.2_ppc64el.deb c3ad1cab5828a9ac575047206836bd0ee763acda 1190 apache2-utils-dbgsym_2.4.18-2ubuntu4.2_ppc64el.ddeb 253d35e59897e368d2f4de3c795680d3acaf19ff 80626 apache2-utils_2.4.18-2ubuntu4.2_ppc64el.deb a17ae1fd922f5206f238d1681e8ee74eb1d26e5e 86344 apache2_2.4.18-2ubuntu4.2_ppc64el.deb Checksums-Sha256: d3bb18e9729233090c87de4cbba200a6732a3a3e37e9b02e2d4a524e0695dc83 988 apache2-bin-dbgsym_2.4.18-2ubuntu4.2_ppc64el.ddeb be1f20fdaefa9d03a21055c33fbb621771da94b98900ce006407f6dc82e9f478 871966 apache2-bin_2.4.18-2ubuntu4.2_ppc64el.deb ca9e9c5d5e94966f82b5cb618701bae3f7a86792fe7966ed59000e0b43ef26f2 2364288 apache2-dbg_2.4.18-2ubuntu4.2_ppc64el.deb 38d2fabba4f3d90d546e51a32b4b1fa91a54995e8a90b7e63c9d885aaeea8c5e 970 apache2-dbgsym_2.4.18-2ubuntu4.2_ppc64el.ddeb f6ac6957ab0dae14c2f4eeccd17493c97448f6b68ca23886e6a6f7e8754c27ab 1108 apache2-dev-dbgsym_2.4.18-2ubuntu4.2_ppc64el.ddeb 0d1b59580b321eaf96b3878abb61a22a486cd598e1095fd004b9ea0167d78cdf 172928 apache2-dev_2.4.18-2ubuntu4.2_ppc64el.deb e25dde6179bcf6b4f7e5717239c8578fb738f1287f2ccf96d3ad749312b4fa37 974 apache2-suexec-custom-dbgsym_2.4.18-2ubuntu4.2_ppc64el.ddeb 37c08ab8511e6ae1047e8cc1e0d047f6127b0a37b935259512206d8267bc037e 15076 apache2-suexec-custom_2.4.18-2ubuntu4.2_ppc64el.deb 99ac803b4f60629462c9997e6f3e4480070237c14c8b5bd11315a711ddb8b94b 918 apache2-suexec-pristine-dbgsym_2.4.18-2ubuntu4.2_ppc64el.ddeb 03a89f605a8aae880025adfac01a7856878d037b3cf805b708f83f0501caaff7 13544 apache2-suexec-pristine_2.4.18-2ubuntu4.2_ppc64el.deb c39a37c6431e7ccfd3b67ff167c9c31214cc3dafb0d54890b6eea68023cff384 1190 apache2-utils-dbgsym_2.4.18-2ubuntu4.2_ppc64el.ddeb 0e850e98bbaa4cde577b94090ad26f487ff4dd32975288b8d3097c797306187e 80626 apache2-utils_2.4.18-2ubuntu4.2_ppc64el.deb a05fd5a0999631ccfcdf1f90c1924307af2287f812b9fb7f7f01a70d88cde980 86344 apache2_2.4.18-2ubuntu4.2_ppc64el.deb Files: 1a12b6d7f1b478da2b677f2f8d9a03ad 988 httpd extra apache2-bin-dbgsym_2.4.18-2ubuntu4.2_ppc64el.ddeb ea79673601bd858c236fc06b26b20850 871966 httpd optional apache2-bin_2.4.18-2ubuntu4.2_ppc64el.deb 795695ee7cbc3e70c5f24a83a2c36cff 2364288 debug extra apache2-dbg_2.4.18-2ubuntu4.2_ppc64el.deb 147e70485df054f3b7a83a497fb6f2af 970 httpd extra apache2-dbgsym_2.4.18-2ubuntu4.2_ppc64el.ddeb 5fd18936e4525910e9223a6f5c27ea86 1108 httpd extra apache2-dev-dbgsym_2.4.18-2ubuntu4.2_ppc64el.ddeb 1ee587f8c371bd7ec639a9a4705937ec 172928 httpd optional apache2-dev_2.4.18-2ubuntu4.2_ppc64el.deb 2f899be2dad97f928d82ebbd0b17e13d 974 httpd extra apache2-suexec-custom-dbgsym_2.4.18-2ubuntu4.2_ppc64el.ddeb 0493072c19922bbdef57837425490680 15076 httpd extra apache2-suexec-custom_2.4.18-2ubuntu4.2_ppc64el.deb 21ab1a00f10e94d4e161735af3cf7ada 918 httpd extra apache2-suexec-pristine-dbgsym_2.4.18-2ubuntu4.2_ppc64el.ddeb ec9bb3cebf756b01a5e6d6e1d361df61 13544 httpd optional apache2-suexec-pristine_2.4.18-2ubuntu4.2_ppc64el.deb 427f8cdce48f9a90e8d74d9fe183f908 1190 httpd extra apache2-utils-dbgsym_2.4.18-2ubuntu4.2_ppc64el.ddeb ae28ffac24caade94ddc99da1e63f71f 80626 httpd optional apache2-utils_2.4.18-2ubuntu4.2_ppc64el.deb 500852a1915a04389e97ce87b7ee6142 86344 httpd optional apache2_2.4.18-2ubuntu4.2_ppc64el.deb Original-Maintainer: Debian Apache Maintainers