-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Thu, 21 Jul 2016 23:21:37 +0200 Source: apache2 Binary: apache2 apache2-data apache2-bin apache2-utils apache2-suexec-pristine apache2-suexec-custom apache2-doc apache2-dev apache2-dbg Architecture: source amd64 all Version: 2.4.23-2 Distribution: unstable Urgency: high Maintainer: Debian Apache Maintainers <debian-apache@lists.debian.org> Changed-By: Stefan Fritsch <sf@debian.org> Description: apache2 - Apache HTTP Server apache2-bin - Apache HTTP Server (modules and other binary files) apache2-data - Apache HTTP Server (common files) apache2-dbg - Apache debugging symbols apache2-dev - Apache HTTP Server (development headers) apache2-doc - Apache HTTP Server (on-site documentation) apache2-suexec-custom - Apache HTTP Server configurable suexec program for mod_suexec apache2-suexec-pristine - Apache HTTP Server standard suexec program for mod_suexec apache2-utils - Apache HTTP Server (utility programs for web servers) Changes: apache2 (2.4.23-2) unstable; urgency=high . * CVE-2016-5387: Sets environmental variable based on user supplied Proxy request header. Don't pass through HTTP_PROXY in server/util_script.c Checksums-Sha1: b61ed87b32c8bf10a1c449b7a451a97b9ad09d86 2713 apache2_2.4.23-2.dsc aef868eb2ffa0db0e5a5f393aed883ee54ce27be 350424 apache2_2.4.23-2.debian.tar.xz bac14ed4600d85ecb72e3b988d6e9e5d49c10ce4 1157180 apache2-bin_2.4.23-2_amd64.deb cfc025a05ec53b04e6782031dfa25fb0a950987a 162010 apache2-data_2.4.23-2_all.deb ae1b27d0cf5eebb331e3cbb511368ed9546d257f 2273510 apache2-dbg_2.4.23-2_amd64.deb 5659710f33e52ead3ac4b8173860884ccf626a03 305620 apache2-dev_2.4.23-2_amd64.deb 7158af3da66047ee286896d85a8a627e34910d5f 3751916 apache2-doc_2.4.23-2_all.deb 876be423a93cf5050d9700267a7f96dd70040da6 148452 apache2-suexec-custom_2.4.23-2_amd64.deb 871702ed873ba67676573ec4045efc580dba3163 146960 apache2-suexec-pristine_2.4.23-2_amd64.deb bfdeeecbce545778bb597852dc4ee62c31c5d3cb 211046 apache2-utils_2.4.23-2_amd64.deb e858e408ceadf2aae671eaaf736f75e8e9492440 219838 apache2_2.4.23-2_amd64.deb Checksums-Sha256: 54efa1320a674e98996d4add03401a20d4acc6f582d60aab3d87da541f3b7f45 2713 apache2_2.4.23-2.dsc 44a74dd202ff3f60871c7a449014977a058b255bfdee6c770b3c74696a0eb065 350424 apache2_2.4.23-2.debian.tar.xz fdb98e9f0d26282d074ceacbb10ffdbef8210b136f6a63c67a05edfd7448271e 1157180 apache2-bin_2.4.23-2_amd64.deb 42304737b6b245280a941839c55fb3e61e5b108b6d1efc41ef1497b728b71df9 162010 apache2-data_2.4.23-2_all.deb 02b93906fa5a22e482ac3a036acc3cd4003bebb3f20e4c12489e9e4f6875f38a 2273510 apache2-dbg_2.4.23-2_amd64.deb 373f2be2938ab20a1331d6dbf59791dc616585973a0189419ac39dfcd77e0aa3 305620 apache2-dev_2.4.23-2_amd64.deb 1d9740cc318c1b236b0534b55e491bb96c77f99524c7b9c33dacef165451e3f9 3751916 apache2-doc_2.4.23-2_all.deb 21eb8cecae7e0e20dc32c6e13af9e026d36eb73a557aea0eb605c2792b254859 148452 apache2-suexec-custom_2.4.23-2_amd64.deb ab5e4735fd31f8551dc7dfcd213d4a10ff42d850c595dd8006f709b19ea5647d 146960 apache2-suexec-pristine_2.4.23-2_amd64.deb 1c762e6fb2c9164a38cfc2cf81b5fa530fee0611021b563f5c0dd7d8ef875b0b 211046 apache2-utils_2.4.23-2_amd64.deb 7f05c87b10b877e0421fcefe3fdb216b93195961eb10cd08c061849552c78cfb 219838 apache2_2.4.23-2_amd64.deb Files: bcfecc293347fe5bdd580e18c15cd388 2713 httpd optional apache2_2.4.23-2.dsc 8faa841c78d604716cb8956e5c02d301 350424 httpd optional apache2_2.4.23-2.debian.tar.xz 51d07bc6f198ed322e1c89d4f2db6033 1157180 httpd optional apache2-bin_2.4.23-2_amd64.deb 3e3fd49578481ad718b03ade9e744788 162010 httpd optional apache2-data_2.4.23-2_all.deb 7902bdd8668374e032edbf2a2006e98e 2273510 debug extra apache2-dbg_2.4.23-2_amd64.deb 4cfa59ba8a43b19d74f875131d5b6557 305620 httpd optional apache2-dev_2.4.23-2_amd64.deb 63f741eafb9a42e7d8d87e78acc9f0f5 3751916 doc optional apache2-doc_2.4.23-2_all.deb 6ba9f057fe737e22da5c38201c4920df 148452 httpd extra apache2-suexec-custom_2.4.23-2_amd64.deb b5f66e87a54ab340ba99bd633915da08 146960 httpd optional apache2-suexec-pristine_2.4.23-2_amd64.deb c467ea8cda34065b16766775efa90478 211046 httpd optional apache2-utils_2.4.23-2_amd64.deb c469a09eb8d37739893610c4494c2da9 219838 httpd optional apache2_2.4.23-2_amd64.deb -----BEGIN PGP SIGNATURE----- iQIcBAEBCgAGBQJXkT3ZAAoJEMaHXzVBzv3gc0UP/1icI/2h34ahMDK7cdYLvIkw ZFNYczOGQv9/qR1qUlg7Aq618S/wHiSPUYlkTuOs6b2e6XD0OUWvv8iI8Lo4iuOG GUeC9nK4IUb+TNasvBaQPkJ2ObTq5OFp7TJM0eZxzjesOx32nXYgLHuM4GkviJjP EQOf8tX2u3Q7zCBvg8nHWrx13ov8gxUR1VFPF9Qv0UWYA7CtKBx2tNIZdzYkqWWq 7uBXKu9ufBsWjlVY07PF54DH6ZH2tCBmYRw6zpBDuMy0PTN4oOc3FUHfubQHiGHL satP8aI0hU3Q6tDvCJWQurCr0IscUp4fIf7Sjv0rXiir2IKMv4Ni9ey5q0tr0+2Z ApPPbbDlQkBhJB6TaRRDrEFD2f/en929HZXUMDakYtT1hVynHzUSDH6Q+ouNiT46 biPg9ODB5EMfnN9r2+hJDAqFsxVQMhduiuVhOJQkAA/a4VihVy38HofWU+y97Dtb OcXlC4HFB/VjUEVAYNWzySnV38p9Bu64ZjfrfhJO7U0OpSjYFB/Yg0mMmkSNxP8N w5KFhyVQzuQrleeN2NtgcrjMZmnc2LBM40C5VBjHlh35vY3lrxLphIV/w0n7iaFy knS8wr9STW0WpaPNYuWZVNntgQQis8ujEHS65ZsgBox5sK5Uz9/+filehKug1OUs X+6COgP/K1a94hgMTzTR =l1OP -----END PGP SIGNATURE-----