Format: 1.8 Date: Wed, 12 Aug 2020 17:35:50 -0400 Source: apache2 Binary: apache2 apache2-data apache2-bin apache2-utils apache2-suexec-pristine apache2-suexec-custom apache2-doc apache2-dev apache2-dbg Architecture: amd64 all Version: 2.4.18-2ubuntu3.17 Distribution: xenial Urgency: medium Maintainer: Launchpad Build Daemon Changed-By: Marc Deslauriers Description: apache2 - Apache HTTP Server apache2-bin - Apache HTTP Server (modules and other binary files) apache2-data - Apache HTTP Server (common files) apache2-dbg - Apache debugging symbols apache2-dev - Apache HTTP Server (development headers) apache2-doc - Apache HTTP Server (on-site documentation) apache2-suexec-custom - Apache HTTP Server configurable suexec program for mod_suexec apache2-suexec-pristine - Apache HTTP Server standard suexec program for mod_suexec apache2-utils - Apache HTTP Server (utility programs for web servers) Changes: apache2 (2.4.18-2ubuntu3.17) xenial-security; urgency=medium . * SECURITY UPDATE: mod_rewrite redirect issue - debian/patches/CVE-2020-1927-1.patch: factor out default regex flags in include/ap_regex.h, server/core.c, server/util_pcre.c. - debian/patches/CVE-2020-1927-2.patch: add AP_REG_NO_DEFAULT to allow opt-out of pcre defaults in include/ap_regex.h, modules/filters/mod_substitute.c, server/util_pcre.c, server/util_regex.c. - CVE-2020-1927 * SECURITY UPDATE: mod_proxy_ftp uninitialized memory issue - debian/patches/CVE-2020-1934.patch: trap bad FTP responses in modules/proxy/mod_proxy_ftp.c. - CVE-2020-1934 Checksums-Sha1: 6ef331b8169151e3222eb422dc0a0b81002c9f90 992 apache2-bin-dbgsym_2.4.18-2ubuntu3.17_amd64.ddeb f475de3cf8ff3d98a7b96aeb72766363150ebf88 926540 apache2-bin_2.4.18-2ubuntu3.17_amd64.deb 375a95bc3e7f8b49c16f59aeb1b210aacdd381c7 161936 apache2-data_2.4.18-2ubuntu3.17_all.deb 730ac66c743df8b4b274c87bd5045e685eedace8 2029454 apache2-dbg_2.4.18-2ubuntu3.17_amd64.deb c6b1c4cd8478096cd05bf025d925f45ca79c3528 970 apache2-dbgsym_2.4.18-2ubuntu3.17_amd64.ddeb 7debeae811d01f4e1d5371d67f95678675ea24b0 1114 apache2-dev-dbgsym_2.4.18-2ubuntu3.17_amd64.ddeb eb60796bbe553f6a02493d7a1f964c2958f81937 173304 apache2-dev_2.4.18-2ubuntu3.17_amd64.deb eed41e819a5a7dac0abbd12b36ce6cb5aa20d5f8 2701814 apache2-doc_2.4.18-2ubuntu3.17_all.deb 6f36bcaddad82b4a4503c7be3bebea68e85b7800 976 apache2-suexec-custom-dbgsym_2.4.18-2ubuntu3.17_amd64.ddeb 6f9704d155173a93cb122a8a31c3fdf448c407d7 15128 apache2-suexec-custom_2.4.18-2ubuntu3.17_amd64.deb 0afeb1a919deb26ccc166b20c53d063839e6d442 922 apache2-suexec-pristine-dbgsym_2.4.18-2ubuntu3.17_amd64.ddeb 0dc48ddfffa32995fd7c231e9fc1616e4a4caf2d 13616 apache2-suexec-pristine_2.4.18-2ubuntu3.17_amd64.deb f7f33cda41108618a786aadc997853ebdf703160 1196 apache2-utils-dbgsym_2.4.18-2ubuntu3.17_amd64.ddeb a7c349d109632e576cc26e4a92ef03ef86289c32 81914 apache2-utils_2.4.18-2ubuntu3.17_amd64.deb 051a7aead517278bfab9c36206d0ad2da9d17ae2 86756 apache2_2.4.18-2ubuntu3.17_amd64.deb Checksums-Sha256: cd572d7d6ef1069e1c6bdc5f9d2f92fc25066033afa2b4d265503959050e0f48 992 apache2-bin-dbgsym_2.4.18-2ubuntu3.17_amd64.ddeb 6a9b055492686969f4b5ad0c8e27cf526b6f9bea34634b5c10c7b17a18cc8255 926540 apache2-bin_2.4.18-2ubuntu3.17_amd64.deb ad2acfad01b096ffbf88f3030b1ac7d121a3975f083daaf2793e47689e658a64 161936 apache2-data_2.4.18-2ubuntu3.17_all.deb a1c04f59e4eb645c3b25cbf4f8f59f459f2c3f0cf0104fb632e395f74a802c94 2029454 apache2-dbg_2.4.18-2ubuntu3.17_amd64.deb cc935f41a44b969e6063751cd6cc796fd85636035c50c6489500f50dc4e58add 970 apache2-dbgsym_2.4.18-2ubuntu3.17_amd64.ddeb 7e59a46c6461058026c79e47843f08edc1566cd4b622f72a66366d186d3fb70c 1114 apache2-dev-dbgsym_2.4.18-2ubuntu3.17_amd64.ddeb c6fc445d9296fcded1a18ab7ac12c9efc112db041916d9d5e8b43a9266ca63f4 173304 apache2-dev_2.4.18-2ubuntu3.17_amd64.deb f4fcfa4207c177e2fcc423310163aeb40779fd33b86517476ad84a47e8295a79 2701814 apache2-doc_2.4.18-2ubuntu3.17_all.deb 290d5dd7a88a7dd517ae14074413c7ba04cd72c35217227923283a5d040d68d6 976 apache2-suexec-custom-dbgsym_2.4.18-2ubuntu3.17_amd64.ddeb bc5eb6143cf8c7ffb57033e94ae7c22824d432581888dfcb76c20175ead10adf 15128 apache2-suexec-custom_2.4.18-2ubuntu3.17_amd64.deb 5d3c48e5f7854da6ea3a03d5886422bc9a91731969fc3d5b70f1baadff7699c0 922 apache2-suexec-pristine-dbgsym_2.4.18-2ubuntu3.17_amd64.ddeb 1b803e381e2d0da63ee0dd767e51a1e5d437356ada962a081b0a4b3282bce4b5 13616 apache2-suexec-pristine_2.4.18-2ubuntu3.17_amd64.deb f91bd1f349e37dd9ac8a26eafdd6a58e6deee3cd1f9b964bcc22ac6cd74c204c 1196 apache2-utils-dbgsym_2.4.18-2ubuntu3.17_amd64.ddeb 71663465726ffb13601f2bc3a7a15d90e9039c42001aefbe3782d53622522460 81914 apache2-utils_2.4.18-2ubuntu3.17_amd64.deb 784800b93c8d43ae538419216bf0dcf6e869e5b9314f9b42ec902af5933c572b 86756 apache2_2.4.18-2ubuntu3.17_amd64.deb Files: 87419f91ef819f9964b88cf050d8517f 992 httpd extra apache2-bin-dbgsym_2.4.18-2ubuntu3.17_amd64.ddeb af1b27c67a602a0b8529da88672a693b 926540 httpd optional apache2-bin_2.4.18-2ubuntu3.17_amd64.deb 82ee244d77f3e7f8abf6cf9cbf93a09f 161936 httpd optional apache2-data_2.4.18-2ubuntu3.17_all.deb 5f59996e30d0d631c3a7d937475cf787 2029454 debug extra apache2-dbg_2.4.18-2ubuntu3.17_amd64.deb a5bdef56072a42065cc113e461f737d0 970 httpd extra apache2-dbgsym_2.4.18-2ubuntu3.17_amd64.ddeb 1062efd1b2350fd5e851489be8ed1ac9 1114 httpd extra apache2-dev-dbgsym_2.4.18-2ubuntu3.17_amd64.ddeb 0e5d190cc0aa13665dc97d94918c6491 173304 httpd optional apache2-dev_2.4.18-2ubuntu3.17_amd64.deb c4222914796d2ff92b059177c226707f 2701814 doc optional apache2-doc_2.4.18-2ubuntu3.17_all.deb 328a66c9fc5a3731a8a4480b9ac9ec89 976 httpd extra apache2-suexec-custom-dbgsym_2.4.18-2ubuntu3.17_amd64.ddeb 96dea6055017409ef8438dd49eb92f36 15128 httpd extra apache2-suexec-custom_2.4.18-2ubuntu3.17_amd64.deb 26bdbef400455852fdc7e4b638d7371b 922 httpd extra apache2-suexec-pristine-dbgsym_2.4.18-2ubuntu3.17_amd64.ddeb 6393ad3db404af974900f1c501cafd45 13616 httpd optional apache2-suexec-pristine_2.4.18-2ubuntu3.17_amd64.deb 95b9640fd86a6bac6da4c91255ba3507 1196 httpd extra apache2-utils-dbgsym_2.4.18-2ubuntu3.17_amd64.ddeb 6d383b195fce1783b055ab1dc14f17c1 81914 httpd optional apache2-utils_2.4.18-2ubuntu3.17_amd64.deb 3b096db9d1810332174782f21858a6dd 86756 httpd optional apache2_2.4.18-2ubuntu3.17_amd64.deb Original-Maintainer: Debian Apache Maintainers