-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sat, 14 Jan 2017 19:27:34 +0100 Source: apache2 Binary: apache2 apache2-data apache2-bin apache2-utils apache2-suexec-pristine apache2-suexec-custom apache2-doc apache2-dev apache2-ssl-dev apache2-dbg Architecture: source amd64 all Version: 2.4.25-2 Distribution: unstable Urgency: medium Maintainer: Debian Apache Maintainers <debian-apache@lists.debian.org> Changed-By: Stefan Fritsch <sf@debian.org> Description: apache2 - Apache HTTP Server apache2-bin - Apache HTTP Server (modules and other binary files) apache2-data - Apache HTTP Server (common files) apache2-dbg - Apache debugging symbols apache2-dev - Apache HTTP Server (development headers) apache2-doc - Apache HTTP Server (on-site documentation) apache2-ssl-dev - Apache HTTP Server (mod_ssl development headers) apache2-suexec-custom - Apache HTTP Server configurable suexec program for mod_suexec apache2-suexec-pristine - Apache HTTP Server standard suexec program for mod_suexec apache2-utils - Apache HTTP Server (utility programs for web servers) Closes: 839227 851122 Changes: apache2 (2.4.25-2) unstable; urgency=medium . * Activate mod_reqtimeout in new installs and during updates from before 2.4.25-2. It was wrongly not activated in new installs since jessie. This made the default installation vulnerable to some DoS attacks. * Restart htcacheclean on updates and tighten dependency on apache2-utils to ensure that apache2-utils cannot be upgraded without apache2. Closes: #851122 * When running on systems with systemd, make 'apache2ctl start' invoke systemctl instead. Otherwise systemd will think apache2 is not running and ignore further commands like reload. Closes: #839227 * Avoid segfault in mpm_event if a signal is received too soon after start. PR 60487 * Add test for some modules to be enabled. * Remove mention of CVE-2016-5387 in 2.4.25-1 changelog. It was already fixed in 2.4.23-2. Checksums-Sha1: 8b7284179eb5dcbeb54f644a6cacc06c8c6c4fd5 2832 apache2_2.4.25-2.dsc 30693183707be284bc9708d044b8c5a03c4b8dfa 353924 apache2_2.4.25-2.debian.tar.xz 2d8e42edd94bf79e628332d4850dc917ad389aab 1177622 apache2-bin_2.4.25-2_amd64.deb fe099b483bc8b7e012b5308e8db759bd11ad7f96 162122 apache2-data_2.4.25-2_all.deb 08eb90223549a14728a682cb337f7cc9d21528bd 3969850 apache2-dbg_2.4.25-2_amd64.deb e3f4a5b690aec3fbdfed1a6b4bc40b8d79332122 312456 apache2-dev_2.4.25-2_amd64.deb 9302aab4ff952223a1859e5adfa3c55b07c1fd5d 3769600 apache2-doc_2.4.25-2_all.deb b89cbb12be20c6d2690e5f319c2075bf4003052c 2258 apache2-ssl-dev_2.4.25-2_amd64.deb f6a29073edffa289cfd0693dd3d0215b3ab4a14b 154134 apache2-suexec-custom_2.4.25-2_amd64.deb 5741b460e8f53db51b82428b386418f0df4b28c6 152650 apache2-suexec-pristine_2.4.25-2_amd64.deb f48fe10ff4f668b4e0fa6112694ffe8f9c5db2f5 216096 apache2-utils_2.4.25-2_amd64.deb 15bc1ca3ca7d641f9b433c609277e78b84342639 8751 apache2_2.4.25-2_amd64.buildinfo 57b6c9ff227d3cedc252ac3a59afb765109bd16a 234676 apache2_2.4.25-2_amd64.deb Checksums-Sha256: b72a4038be2a1aea5b220ddfbbf5fb0eb675e7b18c49692fb89a85af8f0d3b3d 2832 apache2_2.4.25-2.dsc 1b508d9b685d885773bfeacd973bb7c9cd6c1fb971ea715be57f8c3069490750 353924 apache2_2.4.25-2.debian.tar.xz 4e6780ee01b6f6756fd0fe45402bb085a59edf86d1c9ebf118bd24876d40aa86 1177622 apache2-bin_2.4.25-2_amd64.deb 8317f7ab9ec5a6cccc812f8642982792c2bd16bd3baaba056cb3b996de5492a1 162122 apache2-data_2.4.25-2_all.deb 29900fbb7fdd0595b77977a813380c0349897e024c33435edef0cb6e9d5ac97d 3969850 apache2-dbg_2.4.25-2_amd64.deb 6e3dbfa2c4e6970d9bb55427ea2680e6edafe63bbc8c8c3d1737ce797cb5d86a 312456 apache2-dev_2.4.25-2_amd64.deb 8b4206b423d60861044eb0509fdc2d1f5a800a418edf1da9092ce101fdc599b1 3769600 apache2-doc_2.4.25-2_all.deb 9c9035f3273026a2c59b46ea686e19ee2ab0c2549d57a9542975fbbe65ccd49d 2258 apache2-ssl-dev_2.4.25-2_amd64.deb 11ed07a7e95c306bbd0468a0a7231c06e98cf6af34a8390f72fd987ce038d084 154134 apache2-suexec-custom_2.4.25-2_amd64.deb 277b2b9422d9ca14ca65911fa0f801138a96246464c18a6a4c68ba675ba06c4c 152650 apache2-suexec-pristine_2.4.25-2_amd64.deb c2d883a19d9dc6479e8490836337dd095079a6fa5fcb584a4d19830927957daf 216096 apache2-utils_2.4.25-2_amd64.deb d21674f1246267992bba4d6db67d280a542165e6a8227d130c7421a6813429cf 8751 apache2_2.4.25-2_amd64.buildinfo 11e24eafef88d382e16a7577ef3683ccac08c0a68dee4b0ebaabc1415da9aca6 234676 apache2_2.4.25-2_amd64.deb Files: 1febd7511303af0dfedd8aa036e5fe08 2832 httpd optional apache2_2.4.25-2.dsc 33e0e8f630c907b143d601eaeacd883c 353924 httpd optional apache2_2.4.25-2.debian.tar.xz d33d27999ff322c93de914d6af98ead2 1177622 httpd optional apache2-bin_2.4.25-2_amd64.deb 426bc4f1347fa963d22b3156fd9486ee 162122 httpd optional apache2-data_2.4.25-2_all.deb 4d1fb3bdf1531293659431375d62b74c 3969850 debug extra apache2-dbg_2.4.25-2_amd64.deb 3b308b5c85a75da61b9ae318061a4d2d 312456 httpd optional apache2-dev_2.4.25-2_amd64.deb bd6e7e5da20a319e5abb933f89349a10 3769600 doc optional apache2-doc_2.4.25-2_all.deb 9f9b21d17e329ac7019743f117fc33e2 2258 httpd optional apache2-ssl-dev_2.4.25-2_amd64.deb 77de5b640478b38454788cad46d07314 154134 httpd extra apache2-suexec-custom_2.4.25-2_amd64.deb 9e52e9c9719d0ae14cc3bfa46c646b4f 152650 httpd optional apache2-suexec-pristine_2.4.25-2_amd64.deb cff278581d8e88a9f35f682336e5f991 216096 httpd optional apache2-utils_2.4.25-2_amd64.deb f948f726440efc2092dda81e86cd1f47 8751 httpd optional apache2_2.4.25-2_amd64.buildinfo a0e849227a748872d73b89476338ed73 234676 httpd optional apache2_2.4.25-2_amd64.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEOpiNza8JqByyYYsxxodfNUHO/eAFAlh6dEcACgkQxodfNUHO /eAo1RAAhYZAwfXAhSkIrOrQOIhXjq5kn7Pt9wAQXngpD0K+ulkKw2vvyAwdGc7p jG625he23e7VvlVR1mARroqzSjMfKUDCgX2ov534VfQVdJ39gZMCwVeBWKmtPx8x HUtCvOR0uDhw2gStEV7FGrZatNp5VZpXLU3+jmUiZxlmbMm52TW8v8/fMLUpsdM8 E6X+8IKHX/dK7sOd2onqyutv8/WM+WToFmcaXPBrD05ljoGma/1v59rG62VZFfbm 35cs1WpDuQVx3v1CiB5udJH/lZp/LYJKOzfZy9Dm5LBYuSW+NdZDuZZOR1CO7+mt a7lN4bmCU80nQwSu9W8U8SOKQ2BWjfhlK2T4SjQtd/FKzwugMPjQ3PSGCExVR8CI hvmWi5MIi1AZZ8XwJMIFbLnGHzcwQ/FxLaJzquX7DEn51f0vux+hakie6kBsD26n k3dCSWQUs0GNLkw5sJVPqoFuNdI8NkK1D5TPL2ju0mHGAjMN9nVYQKFzK3nDXHka DtAI9MiWtcig4BzvlXipdR/wgQ0+/q+DWUZBIaF3EuPbJP1TCBSVgztB/Si9V3mh yJ0yadK6BbGt/x60zHNTblcyqxiE6yH3Tdm/EaDbCSah/aFYNu45Tazu/c9AXx5v 8Yzow9QJYZkfFXpZ05RundesBcZahig1aCY7IBkAPE9P3LpRQJY= =yO1h -----END PGP SIGNATURE-----