-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Mon, 19 Aug 2019 21:25:31 +0200 Source: apache2 Binary: apache2 apache2-data apache2-bin apache2-utils apache2-suexec-pristine apache2-suexec-custom apache2-doc apache2-dev apache2-ssl-dev apache2-dbg Architecture: source amd64 all Version: 2.4.25-3+deb9u8 Distribution: stretch-security Urgency: high Maintainer: Debian Apache Maintainers <debian-apache@lists.debian.org> Changed-By: Stefan Fritsch <sf@debian.org> Description: apache2 - Apache HTTP Server apache2-bin - Apache HTTP Server (modules and other binary files) apache2-data - Apache HTTP Server (common files) apache2-dbg - Apache debugging symbols apache2-dev - Apache HTTP Server (development headers) apache2-doc - Apache HTTP Server (on-site documentation) apache2-ssl-dev - Apache HTTP Server (mod_ssl development headers) apache2-suexec-custom - Apache HTTP Server configurable suexec program for mod_suexec apache2-suexec-pristine - Apache HTTP Server standard suexec program for mod_suexec apache2-utils - Apache HTTP Server (utility programs for web servers) Changes: apache2 (2.4.25-3+deb9u8) stretch-security; urgency=high . [ Xavier Guimard ] * Add patch to limit cross-site scripting in mod_proxy (Closes: CVE-2019-10092) * Import http2 modules from 2.4.41 (Closes: CVE-2019-9517, CVE-2019-10082, CVE-2019-10081) * Add patch to set PCRE_DOTALL by default (Closes: CVE-2019-10098) . [ Stefan Fritsch ] * Add -Werror=implicit-function-declaration to compile options to catch problems with backports. Checksums-Sha1: 9b729723a08d85053768b9ffc85e02029785620a 2986 apache2_2.4.25-3+deb9u8.dsc 38e9497cbedc8d02a03918515cee4e340706508a 816392 apache2_2.4.25-3+deb9u8.debian.tar.xz 522f3410b2e7b7ab24958eb000614334d231a04b 1184650 apache2-bin_2.4.25-3+deb9u8_amd64.deb 658c093933ca6c7d24af02de8a4d6d0f335bfe29 162326 apache2-data_2.4.25-3+deb9u8_all.deb 7a10ee59554b9bef1e5925ca93f6f65a2ccc0e11 4011302 apache2-dbg_2.4.25-3+deb9u8_amd64.deb 2869955633a664a95756b139fec888b51db4594c 314666 apache2-dev_2.4.25-3+deb9u8_amd64.deb db830d6421edfdb5f70a77c3f8d9d4924461db06 3771428 apache2-doc_2.4.25-3+deb9u8_all.deb 180cb7a0494f5b8453d3b0f679b857bc005ebc8a 2268 apache2-ssl-dev_2.4.25-3+deb9u8_amd64.deb 2bd1d492507392a9d2754b0b0403118c989a7d8c 155718 apache2-suexec-custom_2.4.25-3+deb9u8_amd64.deb f3904fbd8f80b4e1a58d442bc466e8ef5bde7574 154280 apache2-suexec-pristine_2.4.25-3+deb9u8_amd64.deb a0ab5e81e960fd5ca6ccaae3cb6d90a7fe91b9dd 217542 apache2-utils_2.4.25-3+deb9u8_amd64.deb 23b483e542dd23cf6e0fc07b503aa1a6e92a186b 10200 apache2_2.4.25-3+deb9u8_amd64.buildinfo b48f7963222ed6bcd1c42185b392d556c0db2482 236524 apache2_2.4.25-3+deb9u8_amd64.deb Checksums-Sha256: 7c4fdd2e248132f8a9951c715444aaec221c4fc2ed5daf46f78338bb952f7f3c 2986 apache2_2.4.25-3+deb9u8.dsc b5cd6f15e61f5a4ad76af8ad54d31c6eedc9f0308e4a2325ddff37c5c59e003d 816392 apache2_2.4.25-3+deb9u8.debian.tar.xz 80f459b92620e15f576b7ed8ec5ca6740ed162a324dd19cc0552386519938500 1184650 apache2-bin_2.4.25-3+deb9u8_amd64.deb aab8a73860d9b75cef8108f10301dc77c2718b484d1c83adae601b4049ab5c44 162326 apache2-data_2.4.25-3+deb9u8_all.deb ea94651f8c13352f277d8b1fbf702743c9c5423a16020c875169eaab8b64a569 4011302 apache2-dbg_2.4.25-3+deb9u8_amd64.deb f9dd15bd6d55e40b645db73ba5e11cd49a9baea0c253ecae6ea3cca956ec9117 314666 apache2-dev_2.4.25-3+deb9u8_amd64.deb 03d71a5c721be4e1acbdb17b1898ba224c67ce0bcc0294324738834b1533bb1d 3771428 apache2-doc_2.4.25-3+deb9u8_all.deb 417409d7795126ab00163785abea02a6f67fa6df66151caf22b67e698c43a5c7 2268 apache2-ssl-dev_2.4.25-3+deb9u8_amd64.deb cc67a14da6c3747452451432b6e7262c48526276613c27512829d09f97995f27 155718 apache2-suexec-custom_2.4.25-3+deb9u8_amd64.deb f07b54a29523ff0e5a05054b7f4cd0d0c23728fd816bae845030ea6e98570cf0 154280 apache2-suexec-pristine_2.4.25-3+deb9u8_amd64.deb 5801026a19c316ea744ad58aefad0e6d8747964cc05bb33046d29c5624e68fdf 217542 apache2-utils_2.4.25-3+deb9u8_amd64.deb 3f2d86264636177c002fe7382aff1a344bdd83310ec10da212137faeadd38e2e 10200 apache2_2.4.25-3+deb9u8_amd64.buildinfo 0b6a614b8bfe4289ee8a49b004e0ad8c22e810e06775846b545296f62f97e1a0 236524 apache2_2.4.25-3+deb9u8_amd64.deb Files: 6f35ea72e7c5be2cff15c0502e37dd06 2986 httpd optional apache2_2.4.25-3+deb9u8.dsc 10583b2203ee31639eb34c4c3d4e8411 816392 httpd optional apache2_2.4.25-3+deb9u8.debian.tar.xz df4f5ff8d1032eb3128f34a2fd3fbd32 1184650 httpd optional apache2-bin_2.4.25-3+deb9u8_amd64.deb e3b4a798f4d040a7ee29ca79da59a0d5 162326 httpd optional apache2-data_2.4.25-3+deb9u8_all.deb 2b2e2f87c7148ab943e9e36a6798c8a4 4011302 debug extra apache2-dbg_2.4.25-3+deb9u8_amd64.deb 23417bd69770ac86ec4cc3d98113341c 314666 httpd optional apache2-dev_2.4.25-3+deb9u8_amd64.deb 9d724efd9bf8fa68919a02d182ade5eb 3771428 doc optional apache2-doc_2.4.25-3+deb9u8_all.deb 2ad5a566c139d717e7b9aee6f3fe349c 2268 httpd optional apache2-ssl-dev_2.4.25-3+deb9u8_amd64.deb a5796ff2e2accdc6b821efd00778455b 155718 httpd extra apache2-suexec-custom_2.4.25-3+deb9u8_amd64.deb 091024a48d9662145019f1bb928d7620 154280 httpd optional apache2-suexec-pristine_2.4.25-3+deb9u8_amd64.deb cf9b48bbef1184e0040be774de335ada 217542 httpd optional apache2-utils_2.4.25-3+deb9u8_amd64.deb 4b84312a5a0b081c3ea4ef2e7048e961 10200 httpd optional apache2_2.4.25-3+deb9u8_amd64.buildinfo cb35944d7953c711fb902f3ddffe5280 236524 httpd optional apache2_2.4.25-3+deb9u8_amd64.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEOpiNza8JqByyYYsxxodfNUHO/eAFAl1a+bMACgkQxodfNUHO /eBK2w//VBSSMrz7qqpCOzoKH2Kp7cqRelMFPi+bo0IgyiVWrvCKF9nH2j9Hm60S MKNvqryvsKH1Sgypa0bWvfubjRIHNnKgCKQKi7zbUEVVYY/6nMI40996xM+moKfm dfV9kCY6fzK3qpA83qRLJb8QtkZhbjra7JoJ2hRvSLGN7Il34fs8Xv5Z+0kCD41j 1lamfVzauFWWFtaj3CAsDXJ/yVkLiyv15KkTx5HlvTePYG5HSNM6heFx5WELeG34 nkQhUnM+T66k/+SF8so+2fUbrkEHK9ufdt57QrXetBJSEvIUuKXY23rnB3jF3okJ 8m6cv+QnyFf/i8SprVTGfJPNI0B2P9Gmp4WDWkcA8o0lYPKVqHpRo69Zt5CjaWkn 5shdX/hgcsuUPtqIa2vNWfVMX38hE8vx/3KANWcDWU6Exl6g+xf81FAb4yJYtXUj TU8MqyoTpLwMhpFnGOS90veb8cvXUuC3e37jK4U+f9mHFgb+7j2TGzEiGf37wc00 JL4ovxgNFMlCwsAr6lfKpfFznMaZzTnbysvWlIjT9k7bgg/AvFuDGFJpkLrlumqX ACaNdxr8eTNPLIZRN1Jc4Qmbm/WhQJcjogHB9z8FF9fVnwBCfLj21ka1fZbEQavH KOfbAn2GTbY05gj4X/w3ZclMS+s9kdjhbR3QeQhQ/3qjLXTSMFQ= =aEQL -----END PGP SIGNATURE-----