-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 28 Aug 2019 15:01:48 +0200 Source: apache2 Binary: apache2 apache2-data apache2-bin apache2-mpm-worker apache2-mpm-prefork apache2-mpm-event apache2-mpm-itk apache2.2-bin apache2.2-common libapache2-mod-proxy-html libapache2-mod-macro apache2-utils apache2-suexec apache2-suexec-pristine apache2-suexec-custom apache2-doc apache2-dev apache2-dbg Architecture: source amd64 all Version: 2.4.10-10+deb8u15 Distribution: jessie-security Urgency: high Maintainer: Debian Apache Maintainers <debian-apache@lists.debian.org> Changed-By: Markus Koschany <apo@debian.org> Description: apache2 - Apache HTTP Server apache2-bin - Apache HTTP Server (modules and other binary files) apache2-data - Apache HTTP Server (common files) apache2-dbg - Apache debugging symbols apache2-dev - Apache HTTP Server (development headers) apache2-doc - Apache HTTP Server (on-site documentation) apache2-mpm-event - transitional event MPM package for apache2 apache2-mpm-itk - transitional itk MPM package for apache2 apache2-mpm-prefork - transitional prefork MPM package for apache2 apache2-mpm-worker - transitional worker MPM package for apache2 apache2-suexec - transitional package for apache2-suexec-pristine apache2-suexec-custom - Apache HTTP Server configurable suexec program for mod_suexec apache2-suexec-pristine - Apache HTTP Server standard suexec program for mod_suexec apache2-utils - Apache HTTP Server (utility programs for web servers) apache2.2-bin - Transitional package for apache2-bin apache2.2-common - Transitional package for apache2 libapache2-mod-macro - Transitional package for apache2-bin libapache2-mod-proxy-html - Transitional package for apache2-bin Changes: apache2 (2.4.10-10+deb8u15) jessie-security; urgency=high . * Non-maintainer upload by the LTS team. * Fix CVE-2019-10092: Matei "Mal" Badanoiu reported a limited cross-site scripting vulnerability in the mod_proxy error page. * Fix CVE-2019-10098: Yukitsugu Sasaki reported a potential open redirect vulnerability in the mod_rewrite module. Checksums-Sha1: eddda6e3b62e63fdf82f71244b4807a2baf838df 3432 apache2_2.4.10-10+deb8u15.dsc 66da4aecac639ac9f6af9e1264a7e0209a6df3e5 570580 apache2_2.4.10-10+deb8u15.debian.tar.xz 31c0202d289a619b4cd57847a9018bd2c47b543f 1158 libapache2-mod-proxy-html_2.4.10-10+deb8u15_amd64.deb 75cc4af610f1183a6364ea254a6ba329cc9eab1f 1142 libapache2-mod-macro_2.4.10-10+deb8u15_amd64.deb 3342551cc5eab2928542b183b6ef2ec0da0d4e6a 209044 apache2_2.4.10-10+deb8u15_amd64.deb 5bfdb616634c4aca35c38f6621fcbdc140840e17 162564 apache2-data_2.4.10-10+deb8u15_all.deb 118e6b0a289258994d68ded3ad1e6b746cc0f307 1040362 apache2-bin_2.4.10-10+deb8u15_amd64.deb 5105a5d5b6aeefe1d06a3108ed1280971157c018 1518 apache2-mpm-worker_2.4.10-10+deb8u15_amd64.deb b9b7a8ca77ae3835919d55a70af8d81f08df2d49 1520 apache2-mpm-prefork_2.4.10-10+deb8u15_amd64.deb b87f9f2f69fa050cea63f198c57b962c24e25d27 1522 apache2-mpm-event_2.4.10-10+deb8u15_amd64.deb 7bca32dc4ccf448611ed88a855e106d6357c8c00 1516 apache2-mpm-itk_2.4.10-10+deb8u15_amd64.deb bd80850a35bbd053b349eb72dbea8df5e2734c80 1704 apache2.2-bin_2.4.10-10+deb8u15_amd64.deb 92f3695c9f8e27685b8f2feeb837eadb86b4a402 126122 apache2.2-common_2.4.10-10+deb8u15_amd64.deb 22c5d16ffa532fc6819f4444fcbaa6fad6cab1a0 196446 apache2-utils_2.4.10-10+deb8u15_amd64.deb ac2f739c3c7ef8dc05fb4d2a6360dddcc98d9762 1656 apache2-suexec_2.4.10-10+deb8u15_amd64.deb 9ea95e1a7c6095ee08f3f9ad1fecd7adb50eb870 131234 apache2-suexec-pristine_2.4.10-10+deb8u15_amd64.deb 4541228726933d757931c3d67fcc269373891cc5 132866 apache2-suexec-custom_2.4.10-10+deb8u15_amd64.deb 13bf97d8cb519d7fcb2df4870865e44a065afcfd 2722672 apache2-doc_2.4.10-10+deb8u15_all.deb 7de4255917f44de3668196e345c0e6188c47a581 283498 apache2-dev_2.4.10-10+deb8u15_amd64.deb 63e9fcdc5c1ab4780773552f3eb72264b0ff5f62 1709908 apache2-dbg_2.4.10-10+deb8u15_amd64.deb Checksums-Sha256: 4d2ad1ec10cb0dd9d04545a90d25d981b55a13e4044196e0aa808cbfdb303a47 3432 apache2_2.4.10-10+deb8u15.dsc 9a1fc3f547ac4d0336ee1fc23cc58d29e84e81075e1b4985e34f54b0882554b7 570580 apache2_2.4.10-10+deb8u15.debian.tar.xz 1544aa138c423f26773605b592bc2b0f4e3ff1f5edcbeab7427c0ae4ed5a143a 1158 libapache2-mod-proxy-html_2.4.10-10+deb8u15_amd64.deb 6b7ef0237b6737c829c3d2d45723ecee66f2354b3f26750c37557a34372910e3 1142 libapache2-mod-macro_2.4.10-10+deb8u15_amd64.deb 4cf9c423d535842e9e3e007f3d8e9d8e18454f80fdbe9b7e8a91a54634936af6 209044 apache2_2.4.10-10+deb8u15_amd64.deb e2408cefb9d69064e716095477a2b359c4333388d026ab78582d9a35367e0f0c 162564 apache2-data_2.4.10-10+deb8u15_all.deb 451d91133e883af18e105cac2eb72a66027859f9b5e5cc37cf971df2d649c9bf 1040362 apache2-bin_2.4.10-10+deb8u15_amd64.deb 972db8cd3b73b1f780cee11c7618f7967aba7e14bb2356a0e2176201b5192642 1518 apache2-mpm-worker_2.4.10-10+deb8u15_amd64.deb ffb73f28ba41d41337267f8448a44f9f252b38c7d53d00a15c1c4036217a2a28 1520 apache2-mpm-prefork_2.4.10-10+deb8u15_amd64.deb c925eb898368a3dad83d3dbe28c8203f3dd2aec47e5bdbbf9384ebcb294c6a25 1522 apache2-mpm-event_2.4.10-10+deb8u15_amd64.deb bd9d23bf2791aa80392739c02908e54b71b740709a844827ae265712e166da9f 1516 apache2-mpm-itk_2.4.10-10+deb8u15_amd64.deb e8c5f89f61254511e67248666486d759ae4ed9c65cfd0d687d800df23839e2be 1704 apache2.2-bin_2.4.10-10+deb8u15_amd64.deb 3f0ff39e13062b830ddbfea963cc89b5ee8ad74f04ff775a2fc554d0644999d2 126122 apache2.2-common_2.4.10-10+deb8u15_amd64.deb ab2f291475df6d8b545d1a5c1c1e54b65887a030aa3a77a357b844e6623310a7 196446 apache2-utils_2.4.10-10+deb8u15_amd64.deb 32d58eaa3895072a86ea0504d7ffff0fcd967d9df770f7b005b0cb17671a9584 1656 apache2-suexec_2.4.10-10+deb8u15_amd64.deb 19adf1125d9b96044753e6ad741da7fccf633f440bcdf6c9b81352621a89b214 131234 apache2-suexec-pristine_2.4.10-10+deb8u15_amd64.deb 83caf2d3cf45ac56dc91353819d319ec6c169de7863d12ee55d4a22891186447 132866 apache2-suexec-custom_2.4.10-10+deb8u15_amd64.deb 85ce147d0d7f84c45140f9e987c666ccbf89f680ace845cd134ac45f619a5982 2722672 apache2-doc_2.4.10-10+deb8u15_all.deb 1ce981beaed4e21ddf069f7d94922e63c986892dba9eb93ebe345f2a6036b906 283498 apache2-dev_2.4.10-10+deb8u15_amd64.deb 1d574fde5d15c5aa1302be61d20bf68acc32476de8378704a9b4ef2e5398c349 1709908 apache2-dbg_2.4.10-10+deb8u15_amd64.deb Files: 77de7b617d987114c783bcb13e60d251 3432 httpd optional apache2_2.4.10-10+deb8u15.dsc 72108024b65100da3692a9c809aaee29 570580 httpd optional apache2_2.4.10-10+deb8u15.debian.tar.xz 1aa371cc7833fcd3547373dc7276b483 1158 oldlibs extra libapache2-mod-proxy-html_2.4.10-10+deb8u15_amd64.deb f065f392a0cf095218580bba7a08a4cc 1142 oldlibs extra libapache2-mod-macro_2.4.10-10+deb8u15_amd64.deb 650322e2003ecabf18f074a68682f3c7 209044 httpd optional apache2_2.4.10-10+deb8u15_amd64.deb eb9ca9f04385ee5751f4518e78834199 162564 httpd optional apache2-data_2.4.10-10+deb8u15_all.deb 5d007e3d58b2978317f7ad86da52d5db 1040362 httpd optional apache2-bin_2.4.10-10+deb8u15_amd64.deb 1c6104b1c0552697723ad064cabe5427 1518 oldlibs extra apache2-mpm-worker_2.4.10-10+deb8u15_amd64.deb 25eb5aff0cd57144da832c4dec5249e4 1520 oldlibs extra apache2-mpm-prefork_2.4.10-10+deb8u15_amd64.deb 2a9b8d7ac4914b5f56afae2892786146 1522 oldlibs extra apache2-mpm-event_2.4.10-10+deb8u15_amd64.deb b37608bfe80a9eebcbe627f1ea40320e 1516 oldlibs extra apache2-mpm-itk_2.4.10-10+deb8u15_amd64.deb 5d287fadf1056093b879a415643f306d 1704 oldlibs extra apache2.2-bin_2.4.10-10+deb8u15_amd64.deb 40a74361d11668190018ae9602e6525a 126122 oldlibs extra apache2.2-common_2.4.10-10+deb8u15_amd64.deb 75253d62cb838d142b38aade5ff896a7 196446 httpd optional apache2-utils_2.4.10-10+deb8u15_amd64.deb 720ddee005a55be6d0e995aaeeb247ac 1656 oldlibs extra apache2-suexec_2.4.10-10+deb8u15_amd64.deb 4101260766f61c07c1a4a6c6acfb028c 131234 httpd optional apache2-suexec-pristine_2.4.10-10+deb8u15_amd64.deb 7abf451b852cd2e3e4837775971a6b72 132866 httpd extra apache2-suexec-custom_2.4.10-10+deb8u15_amd64.deb c875247bcf80958c91a3ddf6336d8c19 2722672 doc optional apache2-doc_2.4.10-10+deb8u15_all.deb 08b08c11af72e4f6713f82bdd4e4ed37 283498 httpd optional apache2-dev_2.4.10-10+deb8u15_amd64.deb 3624b6aee33a7092f7d9cf95a8982711 1709908 debug extra apache2-dbg_2.4.10-10+deb8u15_amd64.deb -----BEGIN PGP SIGNATURE----- iQKjBAEBCgCNFiEErPPQiO8y7e9qGoNf2a0UuVE7UeQFAl1m+SJfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldEFD RjNEMDg4RUYzMkVERUY2QTFBODM1RkQ5QUQxNEI5NTEzQjUxRTQPHGFwb0BkZWJp YW4ub3JnAAoJENmtFLlRO1HkdM4P/AsI/DwotpEn9D4QrZERrEV7dG2xbwwuTKAw 2BZwKrx6UK/7nLbPus74j2fbkGUBCT+RldBBi6thhaX2LPKat5Ivrk9TDZ61tFUE lbWwr7A2CysY5MAHYu+IiJ+IS/icTZoI6E4BCn0gkVO+Edgp+tJl2C+SP/GoYKvV JWZE7U/qgyHhvxdZaSoM8mLEnCNadjrgMLu178jngudUInSkjpFkkSdM05nADzfG jrADx2fuPDwK80cT1HtBOSdvAW0m4+sCmn7rr2fXum9Vj7rrluGqIDmN3YEk9kvj qPH3Sfz3mx7odQ6XRqPXtMqv9inoFYjlBgnif/TAGVFFPQzUP68wPiEoeZyltR7D 160BFhzdxZSb3XtoL2VLOcU3/SWFEd7j8WSB3HTPEpepPrA4+VJK2U5Wbkw3NqDY Ctcbd6UXeS5rymaSUGgC8glt9NHVsy825rTv+uuVI6y6DyugzkVcIYp5JP6frixJ Aq1JLE0qqhCPAGFskuIdwwxn71vzTWDo70iPeykEVynFy1IMS0FiK4hHYtW2mzQD m6ExsjRXGNaDRg3VKTRfhpQX3co3GJAzS+H/l6MCT+8ye79y9CtlUzPOJpzIbsYS q9akpAqjzLfH2VcX2P08N7++ZHVeN2L8EPm75mkXH+OHPCUUtqnmRi6BNwex/8cF zZPad586 =51ZG -----END PGP SIGNATURE-----