-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 20 Jul 2016 06:50:37 +0200 Source: apache2 Binary: apache2 apache2-data apache2-bin apache2-mpm-worker apache2-mpm-prefork apache2-mpm-event apache2-mpm-itk apache2.2-bin apache2.2-common libapache2-mod-proxy-html libapache2-mod-macro apache2-utils apache2-suexec apache2-suexec-pristine apache2-suexec-custom apache2-doc apache2-dev apache2-dbg Architecture: source amd64 all Version: 2.4.10-10+deb8u5 Distribution: jessie-security Urgency: high Maintainer: Debian Apache Maintainers <debian-apache@lists.debian.org> Changed-By: Salvatore Bonaccorso <carnil@debian.org> Description: apache2 - Apache HTTP Server apache2-bin - Apache HTTP Server (modules and other binary files) apache2-data - Apache HTTP Server (common files) apache2-dbg - Apache debugging symbols apache2-dev - Apache HTTP Server (development headers) apache2-doc - Apache HTTP Server (on-site documentation) apache2-mpm-event - transitional event MPM package for apache2 apache2-mpm-itk - transitional itk MPM package for apache2 apache2-mpm-prefork - transitional prefork MPM package for apache2 apache2-mpm-worker - transitional worker MPM package for apache2 apache2-suexec - transitional package for apache2-suexec-pristine apache2-suexec-custom - Apache HTTP Server configurable suexec program for mod_suexec apache2-suexec-pristine - Apache HTTP Server standard suexec program for mod_suexec apache2-utils - Apache HTTP Server (utility programs for web servers) apache2.2-bin - Transitional package for apache2-bin apache2.2-common - Transitional package for apache2 libapache2-mod-macro - Transitional package for apache2-bin libapache2-mod-proxy-html - Transitional package for apache2-bin Changes: apache2 (2.4.10-10+deb8u5) jessie-security; urgency=high . * Non-maintainer upload by the Security Team. * CVE-2016-5387: Sets environmental variable based on user supplied Proxy request header. Don't pass through HTTP_PROXY in server/util_script.c Checksums-Sha1: de2ec4de04dcd75f98d070be0111ecbb9f0c462a 3245 apache2_2.4.10-10+deb8u5.dsc a614866f4f3e296e27a3531fca1920cc3b47eae7 536096 apache2_2.4.10-10+deb8u5.debian.tar.xz 9355881bc70358712f43c5cd5168383370d4a18c 1152 libapache2-mod-proxy-html_2.4.10-10+deb8u5_amd64.deb 0668f7ad305638580c41ac527b88f790cf9967a0 1142 libapache2-mod-macro_2.4.10-10+deb8u5_amd64.deb 40df0996db5d551bf670095f90bfdd7e67841a0c 205736 apache2_2.4.10-10+deb8u5_amd64.deb ad64c9a76c844a4291a284cf5d861aecbb889e7d 162778 apache2-data_2.4.10-10+deb8u5_all.deb f7b5d6ca4389da3a840b552cad7b90fd7c368dc0 1031854 apache2-bin_2.4.10-10+deb8u5_amd64.deb 598e6c7c535366a6df04ef680c78ad1696db6da3 1522 apache2-mpm-worker_2.4.10-10+deb8u5_amd64.deb d3d1aba4704fadee950aed27787ce6626e1b93d6 1522 apache2-mpm-prefork_2.4.10-10+deb8u5_amd64.deb 8d41cdbc84b81d828d25f11a92fab34b5695e908 1522 apache2-mpm-event_2.4.10-10+deb8u5_amd64.deb 1bc041bba3d78ea8524e71e76f556bfab3cad707 1518 apache2-mpm-itk_2.4.10-10+deb8u5_amd64.deb 6af6c97790c5e78c7e1ef7a85c8b761ce0ae1df4 1704 apache2.2-bin_2.4.10-10+deb8u5_amd64.deb 87e4b2f10d737321a495ca09a5abbadfc17262bf 124670 apache2.2-common_2.4.10-10+deb8u5_amd64.deb 7a231d70f5ad8acc8bb58ab81543f337a50e6ed8 194938 apache2-utils_2.4.10-10+deb8u5_amd64.deb 7b3867b23dd2f09950f89eee6896053cc40e129d 1658 apache2-suexec_2.4.10-10+deb8u5_amd64.deb 3f235365a51c1d779a3deb101479a539c83c4ba3 129850 apache2-suexec-pristine_2.4.10-10+deb8u5_amd64.deb 4064d99db82c31e488fe474a26430886435ec87d 131378 apache2-suexec-custom_2.4.10-10+deb8u5_amd64.deb 76e9e4fcb363ada6974b12d65d53055eaf065380 2725630 apache2-doc_2.4.10-10+deb8u5_all.deb 4772f8ddc07cf04679f19d6f45dc71eeb2d5a7b9 281090 apache2-dev_2.4.10-10+deb8u5_amd64.deb 9a658fa38f7c1770aede4cab5d709eda7e0c0453 1703456 apache2-dbg_2.4.10-10+deb8u5_amd64.deb Checksums-Sha256: a9bd9c037e74463e24a0d8c1cf540cc676c271bfc6d35296d6881f60d191fa2f 3245 apache2_2.4.10-10+deb8u5.dsc 5e5c8384ab3014c2760af5e43028d94338476ef325af731a8d4b74941e0f87bd 536096 apache2_2.4.10-10+deb8u5.debian.tar.xz b53f6b0ec2f0cf6be65efb75d96609c1f10f01b93459d00e24eab40957f3c3e9 1152 libapache2-mod-proxy-html_2.4.10-10+deb8u5_amd64.deb 23ec7d06a4a1916a4e945e84470a27eeb696c554078f61418b849c3bbe93c69d 1142 libapache2-mod-macro_2.4.10-10+deb8u5_amd64.deb b4c46262504d085899b51bb0c33d257cde0c5369be7b1bc5aa34b3510fcf548c 205736 apache2_2.4.10-10+deb8u5_amd64.deb 3d08bc29898b6888745f4ff1b410cbb6d23c51a6bb2276b14e9f34c15e676429 162778 apache2-data_2.4.10-10+deb8u5_all.deb a244ac096eb73af2d0007c6e6d0fd86e51a2b92bef878a25339aaf55ba4999ba 1031854 apache2-bin_2.4.10-10+deb8u5_amd64.deb fc39de54414ea03d7c49dc7c1fd81f5732a3c8a333f223542157e24d729f03f8 1522 apache2-mpm-worker_2.4.10-10+deb8u5_amd64.deb cb80a4bce75ae334ff3f9af1cf081d5592dc6a4d48cc800452fdb04522b2c4f9 1522 apache2-mpm-prefork_2.4.10-10+deb8u5_amd64.deb df2fa4bd3909f9e09127bd4c51bd820c05a184a6c2708dfc2845485135c10bfa 1522 apache2-mpm-event_2.4.10-10+deb8u5_amd64.deb f091d477d945647b364a6b2f4c2c8d74699cd0985f949dc8f240ea33d5e96ef8 1518 apache2-mpm-itk_2.4.10-10+deb8u5_amd64.deb 0de5efe6ff72d6cdcae918cb6d4ea04053e07af3f4745c008bf996a9eb0ded3a 1704 apache2.2-bin_2.4.10-10+deb8u5_amd64.deb f49c1dc871ad8a16dd8d83b2b8490bda86a7d2b33ca286caf2f0268e6a791898 124670 apache2.2-common_2.4.10-10+deb8u5_amd64.deb 2359f3baf3009ccba7350b0f29623a92fb04d6ac4c750231737b2ec4ad131ff6 194938 apache2-utils_2.4.10-10+deb8u5_amd64.deb 1a43202cf779e0c10677c5c4f1c58bf9262a457bd473b0e672a85a58f67308cc 1658 apache2-suexec_2.4.10-10+deb8u5_amd64.deb 8a48e611fff9adca16686a78b71047b19350a61aa2c6bac391919d58c2f79139 129850 apache2-suexec-pristine_2.4.10-10+deb8u5_amd64.deb 7bc6fce299d3eb5bba567a7ff49e61b51fcf7d74124a5a7a6746ce813c70a253 131378 apache2-suexec-custom_2.4.10-10+deb8u5_amd64.deb e4a10f4df4098eebf9b38a47f3fb0c3a61a87d3dbb8345bfd5275473bba1a324 2725630 apache2-doc_2.4.10-10+deb8u5_all.deb 892e710392b4293765900d7fb48b0bd318a1d9389bcafe96fc75d64f4fb1b37b 281090 apache2-dev_2.4.10-10+deb8u5_amd64.deb 02f8cc357f7fcd6cb1ea3df9a53f3f6889eb789e1ef4f9ba4aa3bc070192652d 1703456 apache2-dbg_2.4.10-10+deb8u5_amd64.deb Files: dbd6ac9286a679628ddea3b583f625f1 3245 httpd optional apache2_2.4.10-10+deb8u5.dsc e578a2c7dd59cafaec588e5211845cef 536096 httpd optional apache2_2.4.10-10+deb8u5.debian.tar.xz 9b0872cd7af5a296c850cb46cf390edc 1152 oldlibs extra libapache2-mod-proxy-html_2.4.10-10+deb8u5_amd64.deb 1af791e3c8de30438bd29ae2dfee3534 1142 oldlibs extra libapache2-mod-macro_2.4.10-10+deb8u5_amd64.deb fe2f5a608510291b37f93fce5be986b5 205736 httpd optional apache2_2.4.10-10+deb8u5_amd64.deb 59f764097e8eea75612914cfd94cb02c 162778 httpd optional apache2-data_2.4.10-10+deb8u5_all.deb 6374b2b0ff2152a1f4162431ef2a5913 1031854 httpd optional apache2-bin_2.4.10-10+deb8u5_amd64.deb 7bc2aa13cb422ce6de6346b7583eefc2 1522 oldlibs extra apache2-mpm-worker_2.4.10-10+deb8u5_amd64.deb d4b4ec34a686cb658c171779adbfa010 1522 oldlibs extra apache2-mpm-prefork_2.4.10-10+deb8u5_amd64.deb 898250750acaac94eb70d379f789c5a9 1522 oldlibs extra apache2-mpm-event_2.4.10-10+deb8u5_amd64.deb 340a6ea4b07b09590d565388980b74a9 1518 oldlibs extra apache2-mpm-itk_2.4.10-10+deb8u5_amd64.deb 781e27175bf80f839b61b9fc6c82b7c0 1704 oldlibs extra apache2.2-bin_2.4.10-10+deb8u5_amd64.deb f50aa566119a8355c91f9e03133cb117 124670 oldlibs extra apache2.2-common_2.4.10-10+deb8u5_amd64.deb 9e5ffb91cf6e55214603332729b3d522 194938 httpd optional apache2-utils_2.4.10-10+deb8u5_amd64.deb 846829158557b506174ed33407d36f45 1658 oldlibs extra apache2-suexec_2.4.10-10+deb8u5_amd64.deb e013533b3b3c25ba43607a95853a8468 129850 httpd optional apache2-suexec-pristine_2.4.10-10+deb8u5_amd64.deb e5d3b8332d2e0e3e0108f0b4cb56d83a 131378 httpd extra apache2-suexec-custom_2.4.10-10+deb8u5_amd64.deb 117762ad8adc38b57b542ea9575d7f6b 2725630 doc optional apache2-doc_2.4.10-10+deb8u5_all.deb 495231122981880cc643564aaf35f304 281090 httpd optional apache2-dev_2.4.10-10+deb8u5_amd64.deb 70a8dc7b79517f1bc3b2aefd2da4fa5a 1703456 debug extra apache2-dbg_2.4.10-10+deb8u5_amd64.deb -----BEGIN PGP SIGNATURE----- iQIcBAEBCgAGBQJXjyARAAoJEMaHXzVBzv3guEMQAKGP7c7aJSpQ5rC/MeV4cP+h woxr31/3smF8vENKF2JAKnI7bm5ElL3Veg95rVaYSApGKtQKEhAM+nhCLpikAUJ8 OykXVEz7LCiJPGlgt2j4Juu0QJP1BInbFmMlHTkaJF+0hQBUyvIhsNJgBK0UGv7i uzknlQBOQT+QbHrzhIyYejCkYn184w6luSEacgtZMYAc03BwLt6VJApYdCUJd7Dr BRzExP1I/+kiy3XV8HgC3An5nfnvAgVcmp3J3yEHk5+rysXPB+hlUxM5i2Qw0Xgu VbrePIVk4VP8P/AUbQ8+LtVMeyq0J6ftdt6zY0PTpMxbic8Lgv27SqKaKQAd30AO h6Ic8SP0oBlkGePYnCjpc3GqZJ8ShimmgjI3J82WmPQhe7HLxS/MnlVD6QMQE25Y 0UN3HiDTg+pWnCCio8XoavUbMrsc0Mc7lgkvxzQAB0JsDMPCvRmIldwkWtY9bTS5 TtKOkkdQeflA+OfC97EDGL0IU5jlS4HmzFsAq+M7hIipCEfJHOKcxW7CifNjHzo8 znkeM351S77TI6j0mD3IQUnBW/pmB+uDdxOomq8g1bEelwee+0ggzsWEroeKIkeM IrqvpDhu7qDiIZ1Z6MWjPaq5FONDgu3zS1TDpGB50WDEMoelHY4d0OAJY9cSsS7+ fh8HDjfkPWoXLnhWYFV7 =Ck70 -----END PGP SIGNATURE-----