-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Mon, 30 Sep 2019 21:21:12 +0200 Source: apache2 Binary: apache2 apache2-data apache2-bin apache2-mpm-worker apache2-mpm-prefork apache2-mpm-event apache2-mpm-itk apache2.2-bin apache2.2-common libapache2-mod-proxy-html libapache2-mod-macro apache2-utils apache2-suexec apache2-suexec-pristine apache2-suexec-custom apache2-doc apache2-dev apache2-dbg Architecture: source amd64 all Version: 2.4.10-10+deb8u16 Distribution: jessie-security Urgency: high Maintainer: Debian Apache Maintainers <debian-apache@lists.debian.org> Changed-By: Markus Koschany <apo@debian.org> Description: apache2 - Apache HTTP Server apache2-bin - Apache HTTP Server (modules and other binary files) apache2-data - Apache HTTP Server (common files) apache2-dbg - Apache debugging symbols apache2-dev - Apache HTTP Server (development headers) apache2-doc - Apache HTTP Server (on-site documentation) apache2-mpm-event - transitional event MPM package for apache2 apache2-mpm-itk - transitional itk MPM package for apache2 apache2-mpm-prefork - transitional prefork MPM package for apache2 apache2-mpm-worker - transitional worker MPM package for apache2 apache2-suexec - transitional package for apache2-suexec-pristine apache2-suexec-custom - Apache HTTP Server configurable suexec program for mod_suexec apache2-suexec-pristine - Apache HTTP Server standard suexec program for mod_suexec apache2-utils - Apache HTTP Server (utility programs for web servers) apache2.2-bin - Transitional package for apache2-bin apache2.2-common - Transitional package for apache2 libapache2-mod-macro - Transitional package for apache2-bin libapache2-mod-proxy-html - Transitional package for apache2-bin Closes: 941202 Changes: apache2 (2.4.10-10+deb8u16) jessie-security; urgency=high . * Non-maintainer upload by the LTS team. * Fix incomplete fix for CVE-2019-10092. Revert the old patch that introduced a new CSRF protection but also caused a small regression. (Closes: #941202) Use the correct patch from upstream. https://svn.apache.org/r1864191 Checksums-Sha1: d0bc1aaf7f1bc6eb19f36cff534c8111f2b93867 3432 apache2_2.4.10-10+deb8u16.dsc 6ba90af44ddec40b51f0d56db2f256a275fd6e06 570212 apache2_2.4.10-10+deb8u16.debian.tar.xz 58bbdedcaeccbf3ef390454de5d42b02cc96ab38 1146 libapache2-mod-proxy-html_2.4.10-10+deb8u16_amd64.deb 676502412c4c6179a101252866ef9ecf5d3e1949 1138 libapache2-mod-macro_2.4.10-10+deb8u16_amd64.deb 7192470d7b0c35bf9c73a64d4e39f8ea04cadfaf 209216 apache2_2.4.10-10+deb8u16_amd64.deb a1132fad4b6f57fbdb841574d77e3cd4fc056ea2 162528 apache2-data_2.4.10-10+deb8u16_all.deb cfc03d8c6019a4f5b1ea780a6f1f45710f1d0bad 1041016 apache2-bin_2.4.10-10+deb8u16_amd64.deb 29df62db277b06a3c46434c81e120eb31914b477 1502 apache2-mpm-worker_2.4.10-10+deb8u16_amd64.deb 55cc9c21b4aece72f042de6ebb3873141d820d91 1504 apache2-mpm-prefork_2.4.10-10+deb8u16_amd64.deb 5032774614a3c0d77bc19b382f1b8263b8a682e3 1504 apache2-mpm-event_2.4.10-10+deb8u16_amd64.deb b30328ecdc4d622f9f9edbce04f8fe51fae71d1e 1504 apache2-mpm-itk_2.4.10-10+deb8u16_amd64.deb 9c64554e5c518a44b4897710583c894c00f61ee6 1694 apache2.2-bin_2.4.10-10+deb8u16_amd64.deb 2ffc18d1a4e951ba8b18c2558f612e62ecb21688 126212 apache2.2-common_2.4.10-10+deb8u16_amd64.deb 7605876ef390767b67c6a568753cf7f3f62da099 196496 apache2-utils_2.4.10-10+deb8u16_amd64.deb 1cfcb6c45e3510085b9250dbe285f2fd264c105d 1646 apache2-suexec_2.4.10-10+deb8u16_amd64.deb be36567949dec086023ee3aaef46e2988579c44c 131398 apache2-suexec-pristine_2.4.10-10+deb8u16_amd64.deb dfb3e7ddd459f02ed64e4206b0af32bd18602119 132906 apache2-suexec-custom_2.4.10-10+deb8u16_amd64.deb 0ff67f0f580d27b1cef55028d38144d6314ce769 2755358 apache2-doc_2.4.10-10+deb8u16_all.deb 3bcff10f76e62655fbbd1e723002b5be1c745cd4 283646 apache2-dev_2.4.10-10+deb8u16_amd64.deb 85b94a1979e71d52dbd3855114a0d4f27027fb09 1712932 apache2-dbg_2.4.10-10+deb8u16_amd64.deb Checksums-Sha256: 9065182ee32b97d4e27283bdb5cafba2b10556241fe17122f57210da2245249a 3432 apache2_2.4.10-10+deb8u16.dsc 85ec5e71e28d2fd20c367c2f40f88c0f235cae61f1767676fc4975965ecb6cd2 570212 apache2_2.4.10-10+deb8u16.debian.tar.xz b28ad9b3f29c12b747050d51696fbb4063ba39afefcbe616bc364683f1732ed6 1146 libapache2-mod-proxy-html_2.4.10-10+deb8u16_amd64.deb 0db337eb467164b1f367ee42fa4a4b76cdaa474aa15bfb9fb8c452ec16bfbfe7 1138 libapache2-mod-macro_2.4.10-10+deb8u16_amd64.deb 7e6ac94653298ee7bb5e0d14a43414f7b25d19cdbb248b8681735b21bd3cd4c0 209216 apache2_2.4.10-10+deb8u16_amd64.deb 1680227257de5a85489e0b40024e1dc180be1e3a032f3af742e24e689065002d 162528 apache2-data_2.4.10-10+deb8u16_all.deb df57a29d9ea4224050dccb8a0b9182017d8a3fcda24d53b5d5cdf0457895b9b4 1041016 apache2-bin_2.4.10-10+deb8u16_amd64.deb 5158f9c9e2f34e891f645e616cfa6fa7b1f212fdf88eb3077a88131aa3756f29 1502 apache2-mpm-worker_2.4.10-10+deb8u16_amd64.deb c05c95f57b22a0a577e8b62ef44d9e727b2dafef47f6bab6e2a91d920aa81e82 1504 apache2-mpm-prefork_2.4.10-10+deb8u16_amd64.deb cbd3bb384524a88a50db2ca435c7c61b8b1f79c058be98e79f833086fe8a2771 1504 apache2-mpm-event_2.4.10-10+deb8u16_amd64.deb 30ea12f36bf8fc815a3d3531ba95c243a482792158955411cab2d807caab50c9 1504 apache2-mpm-itk_2.4.10-10+deb8u16_amd64.deb 67a4c46f2b6e5840bc2f5c1d1d418e5f96dd8d2aeb6a55f5a054d4175de21206 1694 apache2.2-bin_2.4.10-10+deb8u16_amd64.deb e2267cf04490d16ee3ec0671e97613f75d97cd0d1f614f43ff69aef6c0a3902d 126212 apache2.2-common_2.4.10-10+deb8u16_amd64.deb 0f6aed369adfa06496e8ee68dbafaa1f8967ff922b23bb4c867e1bafa5f11532 196496 apache2-utils_2.4.10-10+deb8u16_amd64.deb 26b03d560d3a2d4af25423da0edeca4818fd16bd7074014a0cb88ee9d3f60b87 1646 apache2-suexec_2.4.10-10+deb8u16_amd64.deb c4e41f918100e9afeb2666c115b04b8fba4406a2dc7f97bd69eb806a06bf8f32 131398 apache2-suexec-pristine_2.4.10-10+deb8u16_amd64.deb aac4c27d6c0d707f131e83e27d10b97fa4dc28d728d6f91165f4bd0a5d4b2f4e 132906 apache2-suexec-custom_2.4.10-10+deb8u16_amd64.deb b1fbb21250d8e3e34b40f4a1c51ceeb306427d73c528c5b7fecd5d6b93707460 2755358 apache2-doc_2.4.10-10+deb8u16_all.deb 60eee44e466096e7969ba726dc6331186e6fc38aa5fe4375a797fbdc8eea77cb 283646 apache2-dev_2.4.10-10+deb8u16_amd64.deb 3b5414bcfe84647aef0f37022d989a4230f253a724c4cd08cab88bb11187c6e4 1712932 apache2-dbg_2.4.10-10+deb8u16_amd64.deb Files: fca018a394c621697abae06808c6d283 3432 httpd optional apache2_2.4.10-10+deb8u16.dsc 9043d4dc108c8f5ff651ecd993f4deda 570212 httpd optional apache2_2.4.10-10+deb8u16.debian.tar.xz da921e47bdf10510f3a75fb352fc9f3a 1146 oldlibs extra libapache2-mod-proxy-html_2.4.10-10+deb8u16_amd64.deb 79e8f054c53d7dbe42826e580de616e0 1138 oldlibs extra libapache2-mod-macro_2.4.10-10+deb8u16_amd64.deb 8a8a45295fb320957304816d008a93b0 209216 httpd optional apache2_2.4.10-10+deb8u16_amd64.deb 60535f8a062e98c98499d3bc6c057b6f 162528 httpd optional apache2-data_2.4.10-10+deb8u16_all.deb c1017ea2db725e7c034db98489e8a5a8 1041016 httpd optional apache2-bin_2.4.10-10+deb8u16_amd64.deb 1bd125d0d066e0e14baf7bd725408eb5 1502 oldlibs extra apache2-mpm-worker_2.4.10-10+deb8u16_amd64.deb 640db5614d5eb0d8165479a81bacd082 1504 oldlibs extra apache2-mpm-prefork_2.4.10-10+deb8u16_amd64.deb 384d8c5ce7a9699dcab882536efdf4a6 1504 oldlibs extra apache2-mpm-event_2.4.10-10+deb8u16_amd64.deb a46096aebf444c8189049fef2ba506f0 1504 oldlibs extra apache2-mpm-itk_2.4.10-10+deb8u16_amd64.deb 5fc0dc0b41c6004ca256677d044623c9 1694 oldlibs extra apache2.2-bin_2.4.10-10+deb8u16_amd64.deb 74206ee8fe0db9891394e6a578601609 126212 oldlibs extra apache2.2-common_2.4.10-10+deb8u16_amd64.deb 42e7d706910f3565323fd7480d2f7797 196496 httpd optional apache2-utils_2.4.10-10+deb8u16_amd64.deb fc8f813ea690adba34dcb93addcf61fc 1646 oldlibs extra apache2-suexec_2.4.10-10+deb8u16_amd64.deb 8ee23ceffb0c2d7194e46c1cf0de398a 131398 httpd optional apache2-suexec-pristine_2.4.10-10+deb8u16_amd64.deb bede16099dbd20ff20ac431af7b2e78c 132906 httpd extra apache2-suexec-custom_2.4.10-10+deb8u16_amd64.deb 4b7c9be3e49652cb10329c00efac5935 2755358 doc optional apache2-doc_2.4.10-10+deb8u16_all.deb f4d46a0c4c617a3f9d626a68fb50f31e 283646 httpd optional apache2-dev_2.4.10-10+deb8u16_amd64.deb f110cbdcadbb173f0bd1bfc01d1a3e25 1712932 debug extra apache2-dbg_2.4.10-10+deb8u16_amd64.deb -----BEGIN PGP SIGNATURE----- iQKjBAEBCgCNFiEErPPQiO8y7e9qGoNf2a0UuVE7UeQFAl2SWjFfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldEFD RjNEMDg4RUYzMkVERUY2QTFBODM1RkQ5QUQxNEI5NTEzQjUxRTQPHGFwb0BkZWJp YW4ub3JnAAoJENmtFLlRO1HkA6YQALNsyTo8FhcW02UTuEPQezCp2yq1/pyhTVwN XC3oKjZboWy9Va6vqYKXC3O//upnwPqchw+h506bpT617hENuSKMHqqwP8aqin6z xqbdYRWJjujsj6xW2njgSzip3V+qmangDZypctLUPVIimcGj1gXje6pe4LJHVEP2 K6VT9utPMmaktQeu/bGmvGzvB4glWoFfoLcdgBzaMedgqdXu6NGu42s18bDhliCC tsd6BBiaFFTv5qe8Kk49CZPSXAVdaUiKN1Rye1lGEbQ65aNYZf4XdtCNT4/OOmLP 8+RqIwZ3KCzr3pPk6i7rpwZoPdI6600W/V+U9LWCu25rZSzvjNbKZk2AE3UJbVcV jhpIzdhujoxDnJ6T+GI2Otcj7pBmeaNG1ppzk9x2Pmdz59C5s0Ktpy5b7gwz73xU 2QnW09VtVv+x4Pd3CH6lIL2LsINVwkKze8qF5/wl44rFuky3+AoGQnAQvBzJzLgN cscVFD0r2E6Dk4fVmGuPS7TU+imDh8e7KStzXE8e9219zRp6bsz4BPmwrg1QnJOr rnAItEqz90DI+Uoqx2JO7YN7qy4jJRkXe3luGOjkv7HliBAbK6q0R4l/FTFWptSc 1dcfHLLepzztxiszFDSRuzxACavDQPGiOydcziYgfkZvdGgXSBdd+wl0arlqyD+0 mpBdZvqP =G3y1 -----END PGP SIGNATURE-----