-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 25 Aug 2020 22:08:29 +0200 Source: apache2 Architecture: source Version: 2.4.38-3+deb10u4 Distribution: buster-security Urgency: high Maintainer: Debian Apache Maintainers <debian-apache@lists.debian.org> Changed-By: Xavier Guimard <yadd@debian.org> Changes: apache2 (2.4.38-3+deb10u4) buster-security; urgency=high . * Import http2 modules from 2.4.46 (Closes: CVE-2020-9490, CVE-2020-11993) * Fix error out on HTTP header larger than 16K (Closes: CVE-2020-11984) * Fix bad regexp in mod_rewrite (Closes: CVE-2020-1927) * Fix uninitialized memory when proxying to a malicious FTP server (Closes: CVE-2020-1934) Checksums-Sha1: aeaf4e898dc44beacefc791347eca1caec807bbb 3263 apache2_2.4.38-3+deb10u4.dsc c9804c19a4933cc5826049dd9405e87865446a72 1074524 apache2_2.4.38-3+deb10u4.debian.tar.xz Checksums-Sha256: 88ea8d599a4bdf6b08ef63871e5106128c09af3d8128a24b3f1a348051cb06da 3263 apache2_2.4.38-3+deb10u4.dsc de047a9a944bdb10cb6fa58512ed91a1af0a264e99bffa00adcced5b85641080 1074524 apache2_2.4.38-3+deb10u4.debian.tar.xz Files: 9227abcc757add051991aac139236f31 3263 httpd optional apache2_2.4.38-3+deb10u4.dsc 0f0d8eb258cbf4a44225d311ce29d98f 1074524 httpd optional apache2_2.4.38-3+deb10u4.debian.tar.xz -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEAN/li4tVV3nRAF7J9tdMp8mZ7ukFAl9KlRwACgkQ9tdMp8mZ 7ulmtg/8DYDRN52OPGev0J6TMY2P6hQAz8yfqPAF5kcK0k+rZHAcVB/7yEvwMeX7 4qEnT+SPOSKwsk+Bg25nkycWADYHlLz6BDPdqQ+Jv054kRqgM2pKey53efhufavY OlEfi8hGZbufvGa+OQYZtyAu2S3Awi8ma7CZRqYqk7uKJr9dNaxQFHW0ADoCokDL fIy0aBitZ4f1h+6FeC45QjL0pvfMPHh0WlEtnUEhHFqGXHMnXNzelNe7fC/QM3JD gNkBD+72TgAAusnPms28M5+bZmq8AbmlwG8Ov5hyMjGjuFXTByaWUvGWVQPjz00P dCU5LmD6pPo+eyP6Dm1tL6XEVhJlu3mwyZmplkprkOcJq1fidsPopk//ZoJ/5Lrc I4HVL7L2YFJlK4vYPdBaxRj9qfsSEfvkc+htxYKUfYzHvJungXGyb4VHht6CSbCQ tDx9gfL1RXukf7eCkmwHLxBJGS4tTnb0NiV1OY6lk5Xu1WPeLXuTKNwtvRR6DRxf QK5l47zN6MsGMpknxqBfrvTcAsQEKFljlxVa0lrt4kHzCnzP6Qt6jnn29WbD3pgf 1Q2RQei8dRuOCnErMl/xNzbjPBxLGdpv2AKFIGSrKeCexy6rjaHdPTQEi1sB3aR2 Z48MIPsdequrCjgqrXNPOnSl8SkVpOw11cRFB6bo2Hz3sASRADQ= =AxPD -----END PGP SIGNATURE-----