Format: 1.8 Date: Thu, 26 Oct 2023 09:54:09 -0400 Source: apache2 Binary: apache2 apache2-bin apache2-dev apache2-ssl-dev apache2-suexec-custom apache2-suexec-pristine apache2-utils libapache2-mod-md libapache2-mod-proxy-uwsgi Architecture: i386 Version: 2.4.41-4ubuntu3.15 Distribution: focal Urgency: medium Maintainer: Launchpad Build Daemon Changed-By: Marc Deslauriers Description: apache2 - Apache HTTP Server apache2-bin - Apache HTTP Server (modules and other binary files) apache2-dev - Apache HTTP Server (development headers) apache2-ssl-dev - Apache HTTP Server (mod_ssl development headers) apache2-suexec-custom - Apache HTTP Server configurable suexec program for mod_suexec apache2-suexec-pristine - Apache HTTP Server standard suexec program for mod_suexec apache2-utils - Apache HTTP Server (utility programs for web servers) libapache2-mod-md - transitional package libapache2-mod-proxy-uwsgi - transitional package Changes: apache2 (2.4.41-4ubuntu3.15) focal-security; urgency=medium . * SECURITY UPDATE: mod_macro buffer over-read - debian/patches/CVE-2023-31122.patch: fix length in modules/core/mod_macro.c. - CVE-2023-31122 * SECURITY UPDATE: Multiple issues in HTTP/2 - CVE-2023-43622: DoS in HTTP/2 with initial windows size 0 - CVE-2023-45802: HTTP/2 stream memory not reclaimed right away on RST - debian/tests/run-test-suite: run with HARNESS_VERBOSE=1. - debian/patches/update_tests.patch: backport tests from jammy's 2.4.52 to improve test coverage. - debian/patches/update_http2.patch: backport version 2.0.22 of mod_http2 from httpd 2.4.58. - CVE-2023-43622 - CVE-2023-45802 Checksums-Sha1: 0f908a9221f2c723247b4e6822a7577fefb74efb 4332104 apache2-bin-dbgsym_2.4.41-4ubuntu3.15_i386.ddeb 7d931306f2b8404fbbd596f9cd11a7c973e90a64 1256756 apache2-bin_2.4.41-4ubuntu3.15_i386.deb f3a8ecc6a239dc805492aa41bd67b187dccc57b5 179412 apache2-dev_2.4.41-4ubuntu3.15_i386.deb 1249b272616eb4b73544bdc17f8a4e4e0cb543d8 3156 apache2-ssl-dev_2.4.41-4ubuntu3.15_i386.deb e2fc33336997080f40807f66e6bd78582a0d25be 11892 apache2-suexec-custom-dbgsym_2.4.41-4ubuntu3.15_i386.ddeb 5add370ec991b29f0b3bded20a0869b6bba0a625 15552 apache2-suexec-custom_2.4.41-4ubuntu3.15_i386.deb 47f989a27bce450a392901c764425b29c8ec534c 10688 apache2-suexec-pristine-dbgsym_2.4.41-4ubuntu3.15_i386.ddeb e01724806fa4af23f3ac179753dbc406665261e6 14028 apache2-suexec-pristine_2.4.41-4ubuntu3.15_i386.deb 23d74cab6fd46181ad51bcc51c3bb51fa68b6b71 131172 apache2-utils-dbgsym_2.4.41-4ubuntu3.15_i386.ddeb c83a32958da3df91306c3369d0057b32967d6caa 88764 apache2-utils_2.4.41-4ubuntu3.15_i386.deb 54340386fce0d92eb78e92d43bf363d8b37ca323 11966 apache2_2.4.41-4ubuntu3.15_i386.buildinfo 20dffedd37e31f0ce10c28ca506330a715e3f2a0 95592 apache2_2.4.41-4ubuntu3.15_i386.deb b15749286827c25e43c0c559fbe4eac41d25b779 988 libapache2-mod-md_2.4.41-4ubuntu3.15_i386.deb da1386720daa5650102c91f74d7dca9b1ee4e6da 1184 libapache2-mod-proxy-uwsgi_2.4.41-4ubuntu3.15_i386.deb Checksums-Sha256: bec90a07aaa8bb962a42bf0b33a541ea7261d0eb09f48adb52f5a0d18462629b 4332104 apache2-bin-dbgsym_2.4.41-4ubuntu3.15_i386.ddeb e8c2f4aae1032684b7d5c343fad1351e2c5aa4fcea47cadba0f238334a88cb86 1256756 apache2-bin_2.4.41-4ubuntu3.15_i386.deb 365bbb7c90f1a6cf5b003fe90f46ba9d7316e9c82b2407dc090bf1625478e384 179412 apache2-dev_2.4.41-4ubuntu3.15_i386.deb 80a0e750573e7c359b337365e205b460789380e242bd3ad3db78f7da1e98d5ac 3156 apache2-ssl-dev_2.4.41-4ubuntu3.15_i386.deb 651e9726de5499fbb72e3a61156af6d28f90fce268d80fec2c72b5ab0d12cce4 11892 apache2-suexec-custom-dbgsym_2.4.41-4ubuntu3.15_i386.ddeb 7da0a6b76cc15c80c4926c551be3d0aa4cf084a2f3cea52197bce3030e403a69 15552 apache2-suexec-custom_2.4.41-4ubuntu3.15_i386.deb 100846ada83f88465b30207c374809b9e37a10c76a09baa9053f65f308b86d3c 10688 apache2-suexec-pristine-dbgsym_2.4.41-4ubuntu3.15_i386.ddeb d2d62cd07dc203b20a1db4510fc19738a8185c19f7358044d7b2c269b1776da7 14028 apache2-suexec-pristine_2.4.41-4ubuntu3.15_i386.deb 2a76220bd27d940cb9dfdeaddb63bb115ee9582b3e1430df7d8e4d16550b5aa6 131172 apache2-utils-dbgsym_2.4.41-4ubuntu3.15_i386.ddeb 4c9939fa5e2383e3e531801d7f6a9433bce804d0adc43b2652befb0cb011b158 88764 apache2-utils_2.4.41-4ubuntu3.15_i386.deb b0bd5cfa768c8870de8989a5bd77cd8d22838b6d5cb58660d8f78dd75a53e073 11966 apache2_2.4.41-4ubuntu3.15_i386.buildinfo 5f565bb9c23d46de2053c86b4c90bd83d6bef36b88acda67b5758ce0e8ae25e3 95592 apache2_2.4.41-4ubuntu3.15_i386.deb 2cf83c71eab3b0d4ef3baf4d278c6501156de6597570e81e8d7b9aa18c5addb8 988 libapache2-mod-md_2.4.41-4ubuntu3.15_i386.deb 9a951b06d77f0362fb43a4f49c10b36c97d4db04650ed4db2270bc367b5cd5bd 1184 libapache2-mod-proxy-uwsgi_2.4.41-4ubuntu3.15_i386.deb Files: 0b290f8a2da672837ed5978a24def315 4332104 debug optional apache2-bin-dbgsym_2.4.41-4ubuntu3.15_i386.ddeb adb4afb8f36b49a0dc5b97629e8db2d6 1256756 httpd optional apache2-bin_2.4.41-4ubuntu3.15_i386.deb 31da2daf15973d3443387c7d402c740a 179412 httpd optional apache2-dev_2.4.41-4ubuntu3.15_i386.deb 807a20002be5ccbfeff9e7474a224060 3156 httpd optional apache2-ssl-dev_2.4.41-4ubuntu3.15_i386.deb 8155e9c4843f8ef756f0bbdc87ddbb66 11892 debug optional apache2-suexec-custom-dbgsym_2.4.41-4ubuntu3.15_i386.ddeb 3ac85489ef7e824e35d894b463c88dcb 15552 httpd optional apache2-suexec-custom_2.4.41-4ubuntu3.15_i386.deb 8f7d7b4c8acc08b7a6967e7bb75a5928 10688 debug optional apache2-suexec-pristine-dbgsym_2.4.41-4ubuntu3.15_i386.ddeb c6c455b22f72bf3d8afeb3b7af235687 14028 httpd optional apache2-suexec-pristine_2.4.41-4ubuntu3.15_i386.deb 68f9339ffbbc746e405455dfc8aabbf7 131172 debug optional apache2-utils-dbgsym_2.4.41-4ubuntu3.15_i386.ddeb 1a2fd3daeb99ce9ee889e0a61570f344 88764 httpd optional apache2-utils_2.4.41-4ubuntu3.15_i386.deb 33450fed288cdee251f0e38a6518cb6b 11966 httpd optional apache2_2.4.41-4ubuntu3.15_i386.buildinfo c07e2aaaf557d34148b51bdedd474371 95592 httpd optional apache2_2.4.41-4ubuntu3.15_i386.deb 067a7e2b9fee514e639d24fe50cdcfb0 988 oldlibs optional libapache2-mod-md_2.4.41-4ubuntu3.15_i386.deb 791324777992a415e151e00c10c52af4 1184 oldlibs optional libapache2-mod-proxy-uwsgi_2.4.41-4ubuntu3.15_i386.deb Original-Maintainer: Debian Apache Maintainers