-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sat, 24 Jun 2017 20:36:48 -0400 Source: apache2 Binary: apache2.2-common apache2.2-bin apache2-mpm-worker apache2-mpm-prefork apache2-mpm-event apache2-mpm-itk apache2-utils apache2-suexec apache2-suexec-custom apache2 apache2-doc apache2-prefork-dev apache2-threaded-dev apache2-dbg Architecture: source amd64 all Version: 2.2.22-13+deb7u9 Distribution: wheezy-security Urgency: high Maintainer: Debian Apache Maintainers <debian-apache@lists.debian.org> Changed-By: Roberto C. Sanchez <roberto@debian.org> Description: apache2 - Apache HTTP Server metapackage apache2-dbg - Apache debugging symbols apache2-doc - Apache HTTP Server documentation apache2-mpm-event - Apache HTTP Server - event driven model apache2-mpm-itk - multiuser MPM for Apache 2.2 apache2-mpm-prefork - Apache HTTP Server - traditional non-threaded model apache2-mpm-worker - Apache HTTP Server - high speed threaded model apache2-prefork-dev - Apache development headers - non-threaded MPM apache2-suexec - Standard suexec program for Apache 2 mod_suexec apache2-suexec-custom - Configurable suexec program for Apache 2 mod_suexec apache2-threaded-dev - Apache development headers - threaded MPM apache2-utils - utility programs for webservers apache2.2-bin - Apache HTTP Server common binary files apache2.2-common - Apache HTTP Server common files Changes: apache2 (2.2.22-13+deb7u9) wheezy-security; urgency=high . * Non-maintainer upload by the LTS Security Team. * CVE-2017-3167: Authentication bypass with ap_get_basic_auth_pw() * CVE-2017-3169: mod_ssl NULL pointer dereference * CVE-2017-7668: Buffer overrun in ap_find_token() * CVE-2017-7679: mod_mime buffer overread Checksums-Sha1: feb54e803822112c8c0b43bdd054f8fdf522cec8 2907 apache2_2.2.22-13+deb7u9.dsc 0d59168a775351e63c7e1a572320eba2bd925e34 263838 apache2_2.2.22-13+deb7u9.debian.tar.gz 3f8891552d3ba22a5655c175a46c9c3349e30b54 293816 apache2.2-common_2.2.22-13+deb7u9_amd64.deb a3db6874e8a49d6004bcb3963e997879209af2ed 794546 apache2.2-bin_2.2.22-13+deb7u9_amd64.deb 67b180a1800e3f9723bc67f9ea93776070cf3a24 2222 apache2-mpm-worker_2.2.22-13+deb7u9_amd64.deb 6edf18a0648b271f635887231dc7cd7e47f414a5 2334 apache2-mpm-prefork_2.2.22-13+deb7u9_amd64.deb 05135411da1726d92bec5985a603765432c017ee 2292 apache2-mpm-event_2.2.22-13+deb7u9_amd64.deb 6589023f1cff5b1b13f70b13bc2763da5a1bd890 2324 apache2-mpm-itk_2.2.22-13+deb7u9_amd64.deb d7fb919b09bba1e4ac46693e40a08f966e63276e 164266 apache2-utils_2.2.22-13+deb7u9_amd64.deb 8454d79749af5214e6368eae2647d6a97a6be2b0 107808 apache2-suexec_2.2.22-13+deb7u9_amd64.deb 538b3c4ce80e2941c061f32d180544b4ad30f22b 109296 apache2-suexec-custom_2.2.22-13+deb7u9_amd64.deb c0591e27d4a7c0493a8df4f7c31659d723a234ed 1438 apache2_2.2.22-13+deb7u9_amd64.deb 918aa2a788e570ecc5b1490e59a71c4a0399238d 1777136 apache2-doc_2.2.22-13+deb7u9_all.deb 4f58c02840fabade958ae1776718fa7182fc9043 115174 apache2-prefork-dev_2.2.22-13+deb7u9_amd64.deb 3295146175c37076d4995a2ba70d43c0f8a21a86 116010 apache2-threaded-dev_2.2.22-13+deb7u9_amd64.deb 8287f62938dab827098fa67f71bc3b8ecf7f98ee 1733024 apache2-dbg_2.2.22-13+deb7u9_amd64.deb Checksums-Sha256: 1aec2c78a5a7346aa553393ae3fba00e094f46b77f7323f788e4ade096d353de 2907 apache2_2.2.22-13+deb7u9.dsc f0966e7062f63437ee49d737ec9322a11db95d036cbd5f76b3e5829010854186 263838 apache2_2.2.22-13+deb7u9.debian.tar.gz b25892ffbabee2f659b21f6c1ec7cfdb4596ae7db982db5133cc342016584e55 293816 apache2.2-common_2.2.22-13+deb7u9_amd64.deb dee98111c2408a7778a3236eb4180a34f2163c988e779da90edd099612f5efe9 794546 apache2.2-bin_2.2.22-13+deb7u9_amd64.deb c345b2589f2c263fdf78bd636abcf88854cb12002cc95391a3e0f1f0a63054af 2222 apache2-mpm-worker_2.2.22-13+deb7u9_amd64.deb 54782422b9508694e4a21f603bc9c2ddc8b0543f3e8881e16e907b843b97e414 2334 apache2-mpm-prefork_2.2.22-13+deb7u9_amd64.deb 0ffe667ed7e0b04b059246378612ec1c750d03e81c533120893cc98f45cc77e6 2292 apache2-mpm-event_2.2.22-13+deb7u9_amd64.deb 63e7700e7a3dfe841179a0dc5d5e41b39c63c4f33cf9f72b7ed533cdf695cc2b 2324 apache2-mpm-itk_2.2.22-13+deb7u9_amd64.deb ffce76d79e91ebce91601450d5caa9894dbaefed80dd7744af6f6e22ab997705 164266 apache2-utils_2.2.22-13+deb7u9_amd64.deb 2f3c4410442e885a8130e37225e678ee114df9c7d284c31906dd7f1580fe44e3 107808 apache2-suexec_2.2.22-13+deb7u9_amd64.deb 7969f241dd1a8f3ee59a5c996fdb9aa1701cd2064dfdca6fbf6a5809049f56bd 109296 apache2-suexec-custom_2.2.22-13+deb7u9_amd64.deb 2fab71de11215db382d063f894451635312b25c38ae42a853ca2135442911b50 1438 apache2_2.2.22-13+deb7u9_amd64.deb f4f65df6dac0236e465335080987ac16c51614280b5a33c95a042e19c871039b 1777136 apache2-doc_2.2.22-13+deb7u9_all.deb 964e9f79547fc49c5cede32bb0c193596a8753d4332c4ed2bd6f36166c9f2e98 115174 apache2-prefork-dev_2.2.22-13+deb7u9_amd64.deb 7d7f80df7a062c744b3d04850caa891136286d853c86da60f95402840ffc0d94 116010 apache2-threaded-dev_2.2.22-13+deb7u9_amd64.deb 4231d6cb59742ea308ed242a8c3677afe7958fb86f6c8d2a88264557dbf9991f 1733024 apache2-dbg_2.2.22-13+deb7u9_amd64.deb Files: 4186a9d9dbf803db3d43ae564d24ff21 2907 httpd optional apache2_2.2.22-13+deb7u9.dsc 6e4d08c4946b2c425f853eb6d2c329d0 263838 httpd optional apache2_2.2.22-13+deb7u9.debian.tar.gz 35fef46d8011572d2c10ffe80e2a2a58 293816 httpd optional apache2.2-common_2.2.22-13+deb7u9_amd64.deb d3daa72b0cf07d779ebbf79810f68409 794546 httpd optional apache2.2-bin_2.2.22-13+deb7u9_amd64.deb 74750e71de6da471e39c6361caa72f47 2222 httpd optional apache2-mpm-worker_2.2.22-13+deb7u9_amd64.deb f6ad52b6f3200774936252bcb60e1420 2334 httpd optional apache2-mpm-prefork_2.2.22-13+deb7u9_amd64.deb 379622af0c2eb5c1ed14d673b4f02dcb 2292 httpd optional apache2-mpm-event_2.2.22-13+deb7u9_amd64.deb bae90cf02b4585b5af2a23c1a15d89f1 2324 httpd extra apache2-mpm-itk_2.2.22-13+deb7u9_amd64.deb ef675acee83f193bfde8b35d64f4fdd4 164266 httpd optional apache2-utils_2.2.22-13+deb7u9_amd64.deb 45a6d0da561ad67ceb9053cb8121b625 107808 httpd optional apache2-suexec_2.2.22-13+deb7u9_amd64.deb 67ff978815e504e8e93afbdfec3779d0 109296 httpd extra apache2-suexec-custom_2.2.22-13+deb7u9_amd64.deb 05a49d0187587bf36a2fe557c5c5ec5b 1438 httpd optional apache2_2.2.22-13+deb7u9_amd64.deb c8e327378a375e45b533d2127fdec4ef 1777136 doc optional apache2-doc_2.2.22-13+deb7u9_all.deb ff6a03a932b02716b6505790b9bb38ad 115174 httpd extra apache2-prefork-dev_2.2.22-13+deb7u9_amd64.deb 569c739eebedb3d55bd63c29d3344bcf 116010 httpd extra apache2-threaded-dev_2.2.22-13+deb7u9_amd64.deb af8296d4bec599ab6315e58caee81458 1733024 debug extra apache2-dbg_2.2.22-13+deb7u9_amd64.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIcBAEBCgAGBQJZUCA5AAoJECzXeF7dp7IP2JcP/1sH8Y5LGaLzbxDfbg3op3DY uWpW+Ejy5VM/oPjPVkQd/5V93xmWvGhw/if7xyy/De6YHOi1mrojSn5ScY8Otqvp Jt+wikPWXDxDOtvKcHNHQBM1pcP5nAu8ne9htTyemFi7xFvdtG/4ta+f1Sz3Xv+5 E663XnWhSfRQ7Z7HO9wEdRoPZP3ioAaPqRUdFYIxLfnwC0RfXA71E40SHaDuYke9 ejZCuvC9K3d/m1YReOdGi1sfDkJRKZIdHEVe6jUdInPzIHny9FcX8IW069GKgFSX K6ryojqV2cN3YjckjDpjkyUWY0MIj7TtyU96rmmmberKkBFzeaN1g8fGhF3pfCQo 179t56NSvOqS6MZiRtZCHaREqMUAQmVuDtJcGN7kmEh7v8Jz2m3ThOFmbjGZTl7B TjCqVA+1RCfUWIMg4DD3d37sz+v3h4cmL8ObLcdID1AgEb2KZKTvGvef62pLVAaK tfG16vajhJr6LChoyxcK6liB0I5HZqZzUL7RiaNgCyRyn3+YBDRyDrZh/yKxr4gq NHyG5629Kr6fXfccEu4EZ5fDgDPXBc+CxStyO1MV7wi5ELEsn9L98q7bAAvWMav/ veyBOK68YWSbLGbC4d2Ww2uwKCNrR2AvWmoz78YXZZQTlU1KnxfwU3X9L4k3BTky bkMH2ypguTlMNRjOsE9V =xQFO -----END PGP SIGNATURE-----