-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 03 Apr 2019 12:43:39 +0200 Source: apache2 Binary: apache2 apache2-data apache2-bin apache2-mpm-worker apache2-mpm-prefork apache2-mpm-event apache2-mpm-itk apache2.2-bin apache2.2-common libapache2-mod-proxy-html libapache2-mod-macro apache2-utils apache2-suexec apache2-suexec-pristine apache2-suexec-custom apache2-doc apache2-dev apache2-dbg Architecture: source amd64 all Version: 2.4.10-10+deb8u14 Distribution: jessie-security Urgency: medium Maintainer: Debian Apache Maintainers <debian-apache@lists.debian.org> Changed-By: Jonas Meurer <jonas@freesources.org> Description: apache2 - Apache HTTP Server apache2-bin - Apache HTTP Server (modules and other binary files) apache2-data - Apache HTTP Server (common files) apache2-dbg - Apache debugging symbols apache2-dev - Apache HTTP Server (development headers) apache2-doc - Apache HTTP Server (on-site documentation) apache2-mpm-event - transitional event MPM package for apache2 apache2-mpm-itk - transitional itk MPM package for apache2 apache2-mpm-prefork - transitional prefork MPM package for apache2 apache2-mpm-worker - transitional worker MPM package for apache2 apache2-suexec - transitional package for apache2-suexec-pristine apache2-suexec-custom - Apache HTTP Server configurable suexec program for mod_suexec apache2-suexec-pristine - Apache HTTP Server standard suexec program for mod_suexec apache2-utils - Apache HTTP Server (utility programs for web servers) apache2.2-bin - Transitional package for apache2-bin apache2.2-common - Transitional package for apache2 libapache2-mod-macro - Transitional package for apache2-bin libapache2-mod-proxy-html - Transitional package for apache2-bin Changes: apache2 (2.4.10-10+deb8u14) jessie-security; urgency=medium . * Non-maintainer upload by the LTS Security Team. * CVE-2019-0217: mod_auth_digest: Access control bypass * CVE-2019-0220: URL normalization inconsistincy. Consecutive slashes in URL's are now merged before use in LocationMatch and RewriteRule. The old behavior can be restored with the new directive "MergeSlashes off". Checksums-Sha1: 162ac236a1e52d36c4c054b5435de81190c355a8 3281 apache2_2.4.10-10+deb8u14.dsc dc35fc0b44256dbee4879d367a02c1c9d3cefde5 568528 apache2_2.4.10-10+deb8u14.debian.tar.xz 16d55c7349be6004f4ef44f2080dcf739c8c9cf3 1148 libapache2-mod-proxy-html_2.4.10-10+deb8u14_amd64.deb 97bb1e97360a3a36c9f33526998caf2a9f301298 1138 libapache2-mod-macro_2.4.10-10+deb8u14_amd64.deb 65a556cfd127cd9cd4c1b7daa6e7916d07b2d94b 208876 apache2_2.4.10-10+deb8u14_amd64.deb b6f5b9c7fbc0e4eb93f1400a4c28ce413398a307 162734 apache2-data_2.4.10-10+deb8u14_all.deb 997f5c3ce5de5e8bd70b848bd064690239393e91 1039146 apache2-bin_2.4.10-10+deb8u14_amd64.deb a8d8600f12a131e18e27c2084f674de4df2cb8ab 1516 apache2-mpm-worker_2.4.10-10+deb8u14_amd64.deb 10ef08ee2b95215c21a0280c207d5335adfa1308 1516 apache2-mpm-prefork_2.4.10-10+deb8u14_amd64.deb a11edb09ef1650d7983ccfb84910bba93cb627e0 1514 apache2-mpm-event_2.4.10-10+deb8u14_amd64.deb 9daec1b26092bdcf2d0191537d5cedf756345704 1514 apache2-mpm-itk_2.4.10-10+deb8u14_amd64.deb ddb21d36de1c96038ceadeb5cc0c1bf2d2be1273 1694 apache2.2-bin_2.4.10-10+deb8u14_amd64.deb ab44c637a3ce7d2bbfb64158007f4c92d24455fc 125962 apache2.2-common_2.4.10-10+deb8u14_amd64.deb b4f9450bb861c553f1d728be692de65c209479ec 196218 apache2-utils_2.4.10-10+deb8u14_amd64.deb 101c0441c74b82c3d2cc7a44e226255f2ec38797 1654 apache2-suexec_2.4.10-10+deb8u14_amd64.deb 3c6beabdac2e7f6d998af0975c7342c7d1ef0737 131084 apache2-suexec-pristine_2.4.10-10+deb8u14_amd64.deb 5e8385248313dec2721edd60e7e13de36269984c 132584 apache2-suexec-custom_2.4.10-10+deb8u14_amd64.deb 5aaef01fb6037bd7363c4555284d29837c12a34e 2753918 apache2-doc_2.4.10-10+deb8u14_all.deb 793fc6918ad62610e80ae469d37730a413cbc07a 283108 apache2-dev_2.4.10-10+deb8u14_amd64.deb 01a10dfd40834194ad6a02b0d03488c1a8a793fa 1710886 apache2-dbg_2.4.10-10+deb8u14_amd64.deb Checksums-Sha256: e3d2e857f199244df4dc05b263f820225667c5fc823002a11829032e5b9ea334 3281 apache2_2.4.10-10+deb8u14.dsc 2ac57a16514cbc81e837f09b11d64b2cf87f6e2a46be744f32504f6aa51d08fb 568528 apache2_2.4.10-10+deb8u14.debian.tar.xz 1d6b2942b21061a899c65f917de7adcf188466ec8047fbb4d29f1c9a92751f43 1148 libapache2-mod-proxy-html_2.4.10-10+deb8u14_amd64.deb 736eab22dbd83d2a761bfb29872f7f3638fa075c2ba7a77f02f1c64ef126cc17 1138 libapache2-mod-macro_2.4.10-10+deb8u14_amd64.deb 16ea591061a6191f2123fe4ebe6bbd3628f992e7b293f2ab67373bc3ab44eae6 208876 apache2_2.4.10-10+deb8u14_amd64.deb 8937db6eb1554aac2fdb289d584afd8a24b0f61bdb187b92fc3b1be568685ed7 162734 apache2-data_2.4.10-10+deb8u14_all.deb d2a90807a424f1cd2c925f85b53baf111b7e82b2bd80f8f9a84a42ca77354118 1039146 apache2-bin_2.4.10-10+deb8u14_amd64.deb 8b4674d103f43e93c8a26361f62bfc53a4a259db319e50483a1df4952e2a221d 1516 apache2-mpm-worker_2.4.10-10+deb8u14_amd64.deb ed1ae5a409988460a37ada3a7e326bb7f1591fdaafb0d6668dfa3938133dcb59 1516 apache2-mpm-prefork_2.4.10-10+deb8u14_amd64.deb 2340d8010040790ae064476473be46078dedce6f071e5584ca0501e52810a88b 1514 apache2-mpm-event_2.4.10-10+deb8u14_amd64.deb 033579fea44729ef793dc13e60304ac01f92107c669faa38b2d5421a9f70b751 1514 apache2-mpm-itk_2.4.10-10+deb8u14_amd64.deb b97ee436c7ee85079fb6d24c9b33a10fb033d9c2ba94b1db4d42e856cf92eada 1694 apache2.2-bin_2.4.10-10+deb8u14_amd64.deb 771fa1f2661aaaa02381942b9616312df32275a3c9d61cdfdd9316041f18c0f7 125962 apache2.2-common_2.4.10-10+deb8u14_amd64.deb 6595ed2ea1939cff7b9750085e820bb975b69705fd4156acc2ef85b8a8cdb773 196218 apache2-utils_2.4.10-10+deb8u14_amd64.deb c7ab3f781d26980c2719607fbaf6a04edcd9003345a3ebe7d26af1d1994de0cd 1654 apache2-suexec_2.4.10-10+deb8u14_amd64.deb 8c6b91cc6697a7c398a61a2ac3f8e90beda69b79701dff56cb74fc4d0c2e3612 131084 apache2-suexec-pristine_2.4.10-10+deb8u14_amd64.deb 0d6b3c2c232e725a6c992c4c8b02f0c78652dd495e830d13dc93a3733e52fe9d 132584 apache2-suexec-custom_2.4.10-10+deb8u14_amd64.deb f3092bc5bf66b7955ef88291166e2d7679efe03e1f2c192fc424092b07e168d9 2753918 apache2-doc_2.4.10-10+deb8u14_all.deb 7873fe7dd0750ef53f3274e589211d985feeb966343584a29ed096afcc256160 283108 apache2-dev_2.4.10-10+deb8u14_amd64.deb a323584cce88a8df9f6082ddaa090519df99c898b928bad625fcefdee2af144e 1710886 apache2-dbg_2.4.10-10+deb8u14_amd64.deb Files: e1e6fe2cb1210f9a27d40789135998c4 3281 httpd optional apache2_2.4.10-10+deb8u14.dsc b07594dd87bc2c31d795895869b16461 568528 httpd optional apache2_2.4.10-10+deb8u14.debian.tar.xz d1e394f7d5d0434e79570bbebebc08cf 1148 oldlibs extra libapache2-mod-proxy-html_2.4.10-10+deb8u14_amd64.deb 4e33e3443ed55da4a96ead966818ae20 1138 oldlibs extra libapache2-mod-macro_2.4.10-10+deb8u14_amd64.deb 12f979aa0ab10bbdc4ecc116dca1399e 208876 httpd optional apache2_2.4.10-10+deb8u14_amd64.deb 0fed36649219b5950c604de15ed659b8 162734 httpd optional apache2-data_2.4.10-10+deb8u14_all.deb 59a0a8972a69adf9c154dbe7e39084f8 1039146 httpd optional apache2-bin_2.4.10-10+deb8u14_amd64.deb 77f610fd6f8fa1d31f94762092f7e3f3 1516 oldlibs extra apache2-mpm-worker_2.4.10-10+deb8u14_amd64.deb 9feed73687bef66be6c54154acb72ade 1516 oldlibs extra apache2-mpm-prefork_2.4.10-10+deb8u14_amd64.deb 36f3e47358304a0be22efcf549ff982f 1514 oldlibs extra apache2-mpm-event_2.4.10-10+deb8u14_amd64.deb 7e2138cb93d920ed991d9a47defae5a2 1514 oldlibs extra apache2-mpm-itk_2.4.10-10+deb8u14_amd64.deb 8adff806a91c12fdd81d1df6cdecd91d 1694 oldlibs extra apache2.2-bin_2.4.10-10+deb8u14_amd64.deb 310797a97d0a4e9039a15a21cf2511fd 125962 oldlibs extra apache2.2-common_2.4.10-10+deb8u14_amd64.deb 5fcd118a1aea2a356179d12168946cbe 196218 httpd optional apache2-utils_2.4.10-10+deb8u14_amd64.deb de301bc7cc7f7de205f142cfb13020f7 1654 oldlibs extra apache2-suexec_2.4.10-10+deb8u14_amd64.deb c247292949b775de1b32a77e24034b0c 131084 httpd optional apache2-suexec-pristine_2.4.10-10+deb8u14_amd64.deb 3816e39f541184dff3d8837243c9be0f 132584 httpd extra apache2-suexec-custom_2.4.10-10+deb8u14_amd64.deb dfc20aaf721fb2f03c6b6edf2ae63e4b 2753918 doc optional apache2-doc_2.4.10-10+deb8u14_all.deb abc06a3372c4f5075a0590cc250df21b 283108 httpd optional apache2-dev_2.4.10-10+deb8u14_amd64.deb 893f0e8962b46419b4662d5a2713e715 1710886 debug extra apache2-dbg_2.4.10-10+deb8u14_amd64.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEELIzSg9Pv30M4kOeDUmLn/0kQSf4FAlykuDAACgkQUmLn/0kQ Sf72uxAAimXTVuhNkH0yaDjPfXAknVBTDPS5156HLkcZZQ+vBVEqGBSR39/MTWZB 1cVjggbVxzfxe5H7pqDcAjT8bFv2skV2xfr9QkFSF4NzR3AIXctLAzvRIkEnIAA7 VN96ynY4kx1rrEE7zPwQNQe5qdk4nb2GBiAlcZjXEJqfuoecdDjL+HrikdFnrmsR Ky4HaOhjmue8MWGa+6SnsJh0i32mbtayQRCR4BPAHw/B2Rt/4/HdVBh3y/GD37uG TMIkNSlRKB0NiJwtLq2inZ0XVDZOBQ9BNpOUKXi0zVE8R/bO+n0sSYrg5j3WzzQu hMFOvQCfzK7y5xNfv5we4RUtUc9WDDrNsFIpTX96EhYQuc+nNPQiOQ7/ydqAQ79J j5+HhnBfzsFA2eya0u9+S+EbU7AoAkS1CFRTZBfRtGL9MfxUWlJ5entQ6JKsbLD4 8C+HOW5fGIZ66p1bjjZhn49VtLDPIngKIwsmr+lb5ltOfI5jk/HwBLUpR06YinXK spHI8nBjsa3+JBxPqmEWmznFewopiU5420zy0RkiX1q4RKOyFxr54foV6G6BfNtb rfLdAKDWRetGNH0qM8YflAA1TKThjcrlG4N2jS1excq0BJzBPQ4/ODPxf9+2X4SF YSNoJ1DNkX5dn8PGSeuXDFAq0ZrKz+6LDR5S2kuv5ou/i8BtXVs= =gfv0 -----END PGP SIGNATURE-----