-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 21 Dec 2021 17:50:43 +0100 Source: apache2 Architecture: source Version: 2.4.38-3+deb10u7 Distribution: buster-security Urgency: medium Maintainer: Debian Apache Maintainers <debian-apache@lists.debian.org> Changed-By: Yadd <yadd@debian.org> Changes: apache2 (2.4.38-3+deb10u7) buster-security; urgency=medium . * Fix possible NULL dereference or SSRF in forward proxy configurations (CVE-2021-44224) * lua: improve error handling (Closes: CVE-2021-44790) * mod_proxy_uwsgi: Remove duplicate slashes at the beginning of PATH_INFO (relaxes the behaviour introduced by the CVE-2021-36160 fix) Checksums-Sha1: af92041eafe3ffbf425ed9428bee9be46ba19588 3263 apache2_2.4.38-3+deb10u7.dsc 9c8dfeca75bd436a724be6df2b4d913ca333c1b9 1080536 apache2_2.4.38-3+deb10u7.debian.tar.xz Checksums-Sha256: 32f8e410e2ad1fd75c33d6899d92abc6c63fbabcb7948d855df603893c9ba040 3263 apache2_2.4.38-3+deb10u7.dsc 23cba5d65a0ad5cc70dcb9d13ecea359c5cc4efe2d602ed01251245da3d7ef33 1080536 apache2_2.4.38-3+deb10u7.debian.tar.xz Files: 169c9622307036e340adbe729351923c 3263 httpd optional apache2_2.4.38-3+deb10u7.dsc 6af24721dd0e169e86103d2a301037d4 1080536 httpd optional apache2_2.4.38-3+deb10u7.debian.tar.xz -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEAN/li4tVV3nRAF7J9tdMp8mZ7ukFAmHLRbkACgkQ9tdMp8mZ 7un+Mg//ZQkVOs+vKxT/Wyfn0e8Kag6wMwWwFO0bp8c+vSy1gGU0XSrqjySA+D+U mGlq+pDwxwc/vgnKHJKJGhznd1gbXOIPHIcYpf/fyN2aF1CXl4Z6+uZOz4VldIee EUkFGXy3EB7EfQe1wUB3ecqEdJJg6nyFtZCgXu0S02P8DgYyoKfSJXXFQT5l+QIa EXwRG7AX9gPOxYlukjPBi7r/Zwxuyi5la2781SD4Wlnz6NiIKYLE/0Q8fLnReF8L SY4ZJy5EqLgxKxR/hno6eaim9V2nDF6aR045mW1w9iP4R/5hW2+2/jI1iKvZGrbp PYj32PFeq1LX8eevsL8noEG8dyC46DDxMU/ussm/cOhFvDOJoOVnQRJk5qPN2vgu hwnz1WwDk26v4NIH2NnMBMhqQjTbdBfEqJVJFvXqSwxGkwWuH+uNp5hrKyuX6QHn ghrzx91SvOKMKzEGTchvLfjVeJpRZ0JQfVo68M7TQUEzdXHPGok1iCqLunnzLgWe A6UfJg5NPfZmixf5Y+2OFvPIgYaVNrTPjmzxhCYd9tmMFSIrdKaJAghEHoeGfLOQ TvxzBO+2VvEnIWdQLyYB1IvmljzeRd3Le+sT0CFyreaF07mPtYbocbF3q4+MYUOT l2Hsn/dYvK/ufqBaOIpV6Fd4GAiBfecbj2M/DkEN1CeIWa9aa3g= =EOJP -----END PGP SIGNATURE-----