-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Format: 1.8 Date: Wed, 01 Feb 2012 21:49:04 +0100 Source: apache2 Binary: apache2.2-common apache2.2-bin apache2-mpm-worker apache2-mpm-prefork apache2-mpm-event apache2-mpm-itk apache2-utils apache2-suexec apache2-suexec-custom apache2 apache2-doc apache2-prefork-dev apache2-threaded-dev apache2-dbg Architecture: source i386 all Version: 2.2.22-1 Distribution: unstable Urgency: medium Maintainer: Debian Apache Maintainers <debian-apache@lists.debian.org> Changed-By: Stefan Fritsch <sf@debian.org> Description: apache2 - Apache HTTP Server metapackage apache2-dbg - Apache debugging symbols apache2-doc - Apache HTTP Server documentation apache2-mpm-event - Apache HTTP Server - event driven model apache2-mpm-itk - multiuser MPM for Apache 2.2 apache2-mpm-prefork - Apache HTTP Server - traditional non-threaded model apache2-mpm-worker - Apache HTTP Server - high speed threaded model apache2-prefork-dev - Apache development headers - non-threaded MPM apache2-suexec - Standard suexec program for Apache 2 mod_suexec apache2-suexec-custom - Configurable suexec program for Apache 2 mod_suexec apache2-threaded-dev - Apache development headers - threaded MPM apache2-utils - utility programs for webservers apache2.2-bin - Apache HTTP Server common binary files apache2.2-common - Apache HTTP Server common files Closes: 653801 Changes: apache2 (2.2.22-1) unstable; urgency=medium . [ Stefan Fritsch ] * New upstream release, urgency medium due to security fixes: - Fix CVE-2012-0021: mod_log_config: DoS with '%{cookiename}C' log format - Fix CVE-2012-0031: Unprivileged child process could cause the parent to crash at shutdown - Fix CVE-2012-0053: Exposure of "httpOnly" cookies in code 400 error message. * Move httxt2dbm to apache2-utils * Adjust debian/control to point to new git repository. . [ Arno Töll ] * Fix "typo in /etc/apache2/apache2.conf" (Closes: #653801) Checksums-Sha1: 4e819491ddd67171edcc943d371185fb07056803 2216 apache2_2.2.22-1.dsc bf3bbfda967ac900348e697f26fe86b25695efe9 7200529 apache2_2.2.22.orig.tar.gz d310358b34a89fb7c9000edda19af74f91eb69d7 209342 apache2_2.2.22-1.debian.tar.gz 15c80559b8f23d8a810c05f82c51455553b00cf6 316382 apache2.2-common_2.2.22-1_i386.deb d74bcd9f44f94d4c88131e81007b9b9d1ec1ca3e 1456028 apache2.2-bin_2.2.22-1_i386.deb 78cc1ea735b29c53c1685693ed6e0efd96a823c4 2188 apache2-mpm-worker_2.2.22-1_i386.deb f698a29a3dc32a0933e6a6afbcc3d4ef8cda0e1f 2292 apache2-mpm-prefork_2.2.22-1_i386.deb 2ba44dcd596fc3c82edaf78ce2e5fb808b169eb5 2254 apache2-mpm-event_2.2.22-1_i386.deb 6145422fbfb10f51690861d3a9940960f4b8ff2f 2280 apache2-mpm-itk_2.2.22-1_i386.deb a7eaa7cafefd2bffb6527e2c88c6375cb98e682c 174832 apache2-utils_2.2.22-1_i386.deb b3f6d534b289eac663f3b183e4d8bdb1b285371a 105248 apache2-suexec_2.2.22-1_i386.deb bc971fcaea2132fb0296eb76b08f2159b236ba34 106904 apache2-suexec-custom_2.2.22-1_i386.deb 8256d803f7d40d4a5524be644443557dfb043db3 1390 apache2_2.2.22-1_i386.deb cebbc54eee3cdb0d5abbf281d5a41859636a0a9a 2703724 apache2-doc_2.2.22-1_all.deb 08932781202c1b250345da5f33c7a5a3bd8b6293 137946 apache2-prefork-dev_2.2.22-1_i386.deb 9b86f06a11fb60ea70fe94a0ab5405cbdc52c079 139120 apache2-threaded-dev_2.2.22-1_i386.deb 591b7662025af94b0364fbf0647116e61a6f4a42 2801012 apache2-dbg_2.2.22-1_i386.deb Checksums-Sha256: 1d9d8680cf7189f0d8818bc67a1cb82233e672da9a3d715847bc05dd605cb302 2216 apache2_2.2.22-1.dsc 74c1ffffefe1a502339b004ad6488fbd858eb425a05968cd67c05695dbc0fe7c 7200529 apache2_2.2.22.orig.tar.gz 85cfb26965d93a6aee1967de568b737074d30c9a8b06d02d75f4cd28164e0e51 209342 apache2_2.2.22-1.debian.tar.gz a33a371ed6be3f7170cb84f2925678d42b3c9ae0fe4c13eaee2971cc4ea5596d 316382 apache2.2-common_2.2.22-1_i386.deb b612cf01ca338b30ed46b2679563c1343369116576ef6bb503ef978b456fb161 1456028 apache2.2-bin_2.2.22-1_i386.deb bf414e63ae7ec43ec745161957c0c2f0cd660b3715989f3f2dc8e39f59fac395 2188 apache2-mpm-worker_2.2.22-1_i386.deb e8f8bd7a7b32850a4c026b572f243f763899bb2fad1fdc970132abce05f3d7fe 2292 apache2-mpm-prefork_2.2.22-1_i386.deb b95a7acdf92916b7e5eb01ec6bb8ede13dda3107848c30ced2d17999cddc45da 2254 apache2-mpm-event_2.2.22-1_i386.deb 2a640adf7aae7f1c8601b76c6eaa444cf2732b8bfa061ae0daf97ee108a24ace 2280 apache2-mpm-itk_2.2.22-1_i386.deb 96199fc8a7fba4398cb6a908c0396c601bc81c7d2616a3dba5844ebe3e6de8f0 174832 apache2-utils_2.2.22-1_i386.deb f41c30302eb4aff9855344b0c875ad4791b80910e551614617c589f4b6f4935a 105248 apache2-suexec_2.2.22-1_i386.deb d25b67f7b0aba72e27dd9ca5f4c0cb0f092474a91e6efc9c92543ec817881619 106904 apache2-suexec-custom_2.2.22-1_i386.deb 4979152ff2e62dfe8d0f85812e59d193a85981ea9d72a5aef623d44eacac9db3 1390 apache2_2.2.22-1_i386.deb c48d9705567d39625135690c4d6974ebfa1fb138306ad03a57d64e902035b3ac 2703724 apache2-doc_2.2.22-1_all.deb a1d102b615d42bb4793b8d722ddc4feaf283eb4ecccdd0859aa42f92969093ea 137946 apache2-prefork-dev_2.2.22-1_i386.deb a6b3621759b0db3ac6eb4c74e7cbf368424c58ea5687bc3ef617fdb095b7c22a 139120 apache2-threaded-dev_2.2.22-1_i386.deb cac3147367728cf124b66d55d42901845fe6a017d1cc5544e16e34aa1d99292a 2801012 apache2-dbg_2.2.22-1_i386.deb Files: 301cb5d0d32a42275071bbab5ecca7aa 2216 httpd optional apache2_2.2.22-1.dsc d77fa5af23df96a8af68ea8114fa6ce1 7200529 httpd optional apache2_2.2.22.orig.tar.gz 08a521c4eca44abf902d924ebb6bc45a 209342 httpd optional apache2_2.2.22-1.debian.tar.gz d34e9d32ce4bac1fa760c0d43e6afa13 316382 httpd optional apache2.2-common_2.2.22-1_i386.deb 73bbae772548c787ff284e5a152932ff 1456028 httpd optional apache2.2-bin_2.2.22-1_i386.deb 87ae361a1e385092ac843cd7b1a20add 2188 httpd optional apache2-mpm-worker_2.2.22-1_i386.deb da8cfb6b0e6a8cc51a66d2bb809a539e 2292 httpd optional apache2-mpm-prefork_2.2.22-1_i386.deb 7c24765d568502a75b3f5318adf2815a 2254 httpd optional apache2-mpm-event_2.2.22-1_i386.deb a566fa28c11f662260f6bfc3f32efcbd 2280 httpd extra apache2-mpm-itk_2.2.22-1_i386.deb ebefd35d778af81ef4b6ba7091d5b788 174832 httpd optional apache2-utils_2.2.22-1_i386.deb 9f0e8fddafb809586a86fc7e60c99b6e 105248 httpd optional apache2-suexec_2.2.22-1_i386.deb d0c480ef4e5a59cf7b0ecb596c0c3e44 106904 httpd extra apache2-suexec-custom_2.2.22-1_i386.deb fb5264239e57bd37c656f1e60f8ac05e 1390 httpd optional apache2_2.2.22-1_i386.deb bdd114fd708a806096647cbc6c58a3c3 2703724 doc optional apache2-doc_2.2.22-1_all.deb 099a13e021835f5741e421939cd2f424 137946 httpd extra apache2-prefork-dev_2.2.22-1_i386.deb a204dcc91cc5f9956892b309b12fd693 139120 httpd extra apache2-threaded-dev_2.2.22-1_i386.deb 5a73064b8a144e59a2da9a9d90b3512f 2801012 debug extra apache2-dbg_2.2.22-1_i386.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.11 (GNU/Linux) iD8DBQFPKagkbxelr8HyTqQRAkhKAKCMuK/H+h+aiNcLcphpW9UwYH7pNwCeI/7E RcftC8FYIhkoz9Ggx2TOR4E= =zfXe -----END PGP SIGNATURE----- Accepted: apache2-dbg_2.2.22-1_i386.deb to main/a/apache2/apache2-dbg_2.2.22-1_i386.deb apache2-doc_2.2.22-1_all.deb to main/a/apache2/apache2-doc_2.2.22-1_all.deb apache2-mpm-event_2.2.22-1_i386.deb to main/a/apache2/apache2-mpm-event_2.2.22-1_i386.deb apache2-mpm-itk_2.2.22-1_i386.deb to main/a/apache2/apache2-mpm-itk_2.2.22-1_i386.deb apache2-mpm-prefork_2.2.22-1_i386.deb to main/a/apache2/apache2-mpm-prefork_2.2.22-1_i386.deb apache2-mpm-worker_2.2.22-1_i386.deb to main/a/apache2/apache2-mpm-worker_2.2.22-1_i386.deb apache2-prefork-dev_2.2.22-1_i386.deb to main/a/apache2/apache2-prefork-dev_2.2.22-1_i386.deb apache2-suexec-custom_2.2.22-1_i386.deb to main/a/apache2/apache2-suexec-custom_2.2.22-1_i386.deb apache2-suexec_2.2.22-1_i386.deb to main/a/apache2/apache2-suexec_2.2.22-1_i386.deb apache2-threaded-dev_2.2.22-1_i386.deb to main/a/apache2/apache2-threaded-dev_2.2.22-1_i386.deb apache2-utils_2.2.22-1_i386.deb to main/a/apache2/apache2-utils_2.2.22-1_i386.deb apache2.2-bin_2.2.22-1_i386.deb to main/a/apache2/apache2.2-bin_2.2.22-1_i386.deb apache2.2-common_2.2.22-1_i386.deb to main/a/apache2/apache2.2-common_2.2.22-1_i386.deb apache2_2.2.22-1.debian.tar.gz to main/a/apache2/apache2_2.2.22-1.debian.tar.gz apache2_2.2.22-1.dsc to main/a/apache2/apache2_2.2.22-1.dsc apache2_2.2.22-1_i386.deb to main/a/apache2/apache2_2.2.22-1_i386.deb apache2_2.2.22.orig.tar.gz to main/a/apache2/apache2_2.2.22.orig.tar.gz