-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Fri, 04 Oct 2024 15:21:08 +0000 Source: apache2 Binary: apache2 apache2-bin apache2-bin-dbgsym apache2-dev apache2-ssl-dev apache2-suexec-custom apache2-suexec-custom-dbgsym apache2-suexec-pristine apache2-suexec-pristine-dbgsym apache2-utils apache2-utils-dbgsym libapache2-mod-md libapache2-mod-proxy-uwsgi Architecture: armhf Version: 2.4.62-1~deb12u2 Distribution: bookworm-security Urgency: medium Maintainer: arm Build Daemon (arm-conova-01) Changed-By: Bastien Roucariès Description: apache2 - Apache HTTP Server apache2-bin - Apache HTTP Server (modules and other binary files) apache2-dev - Apache HTTP Server (development headers) apache2-ssl-dev - Apache HTTP Server (mod_ssl development headers) apache2-suexec-custom - Apache HTTP Server configurable suexec program for mod_suexec apache2-suexec-pristine - Apache HTTP Server standard suexec program for mod_suexec apache2-utils - Apache HTTP Server (utility programs for web servers) libapache2-mod-md - transitional package libapache2-mod-proxy-uwsgi - transitional package Closes: 1079172 1079206 Changes: apache2 (2.4.62-1~deb12u2) bookworm-security; urgency=medium . * Fix CVE-2024-38474 regression: Better question mark tracking to avoid UnsafeAllow3F (Closes: #1079172) * Fix CVE-2024-39884 regression: Trust strings from configuration in mod_proxy (Closes: #1079206) * Add myself as maintainer with Yadd agreement Checksums-Sha1: fc25f8a94a1119fe25b0d6a34701671bb4b81010 3338364 apache2-bin-dbgsym_2.4.62-1~deb12u2_armhf.deb 6fe52dc9808ea8482e2a4d133174118356d038d0 1207192 apache2-bin_2.4.62-1~deb12u2_armhf.deb f317946fa6918f1905e50b97bc08fc4e76742ad0 315564 apache2-dev_2.4.62-1~deb12u2_armhf.deb bdb58b90a031b6d49a06ffb647d0a82205ccc248 3140 apache2-ssl-dev_2.4.62-1~deb12u2_armhf.deb 83d6bf4d9d6b5d4c6285139cadc1ac3ca742e72b 12252 apache2-suexec-custom-dbgsym_2.4.62-1~deb12u2_armhf.deb fb16868ae1f16ae3f02b0d67294be58e0af78c8b 142476 apache2-suexec-custom_2.4.62-1~deb12u2_armhf.deb 2c809ce3d6f3d4f11389f433158b6375922cfa42 11032 apache2-suexec-pristine-dbgsym_2.4.62-1~deb12u2_armhf.deb c6e49fd6a5b588c4dee36b4022da9beef38a7ab4 140968 apache2-suexec-pristine_2.4.62-1~deb12u2_armhf.deb 5cc50ab91119eb831127780bc7997b4b8d39e9d6 118244 apache2-utils-dbgsym_2.4.62-1~deb12u2_armhf.deb 7091c2de665be600133b805511dbe2fec5983eb1 209756 apache2-utils_2.4.62-1~deb12u2_armhf.deb feb32015c2e8a4a3ee544c57897b9671facc8459 11529 apache2_2.4.62-1~deb12u2_armhf-buildd.buildinfo f2d38723ec2c5508660358c2f4508353e8163b05 222752 apache2_2.4.62-1~deb12u2_armhf.deb 22d6e13de55c7b379de3b69dc3a5e4e49be0cfcd 948 libapache2-mod-md_2.4.62-1~deb12u2_armhf.deb 582d91aaf971fac31eb67eb90d8468d7aae88073 1136 libapache2-mod-proxy-uwsgi_2.4.62-1~deb12u2_armhf.deb Checksums-Sha256: 9e210f033892e8206c4b84a8c3e043602c02626836f760ba370f0669aeddaddd 3338364 apache2-bin-dbgsym_2.4.62-1~deb12u2_armhf.deb d6aa3a0331eaeb42e1f67f18e5d96f2ffe180509df6f2389d5b8065b009002b8 1207192 apache2-bin_2.4.62-1~deb12u2_armhf.deb 0b0d25186eb12bcaf9e03e9f70bb66eadef655e4e24e2b4b31d45437460abdae 315564 apache2-dev_2.4.62-1~deb12u2_armhf.deb 25e131b49867d7de05aa0bcf99da01b011f8af8fb4fc407062d76d24da956dcd 3140 apache2-ssl-dev_2.4.62-1~deb12u2_armhf.deb 45b19959dddfbd4af004962af55958f6c8003a2157103e26e74dfe3f4f48a9ce 12252 apache2-suexec-custom-dbgsym_2.4.62-1~deb12u2_armhf.deb 1e2c6370eba860a87a0ce29b279dda787e01ee2646c58cc4084c19f0a32309c2 142476 apache2-suexec-custom_2.4.62-1~deb12u2_armhf.deb 1516357139e6ed100645dd76352267047e4007b27a3bad62ffc465eb4ce0b67b 11032 apache2-suexec-pristine-dbgsym_2.4.62-1~deb12u2_armhf.deb 98abf1709d378a27a39c5edeb562ba892961e0a6c275380997a8c59ca2af2216 140968 apache2-suexec-pristine_2.4.62-1~deb12u2_armhf.deb 863fe1125098acbdd0b31c86ebc5399eff199e6f9dc1a78513e4ea395e8d7faf 118244 apache2-utils-dbgsym_2.4.62-1~deb12u2_armhf.deb cfb975df33cb1781ed08acd278a31ac809287f222829780b3ac9bbdf88b39977 209756 apache2-utils_2.4.62-1~deb12u2_armhf.deb a44a5b509ce4a130654ec68dee7bd85737a121a4889af9a56933a1a95fdab1b1 11529 apache2_2.4.62-1~deb12u2_armhf-buildd.buildinfo 4f0c7f47342de3a1b939d4d797ca4bd804dcc83729f8bbdb44bc0d60d365d494 222752 apache2_2.4.62-1~deb12u2_armhf.deb a3eaec5dbc1fab7eefdae83dc7f9821a9ae9f5a06c0ebc9a1257b700824d6b8c 948 libapache2-mod-md_2.4.62-1~deb12u2_armhf.deb 417827bae87ee748a016d24936cfc52f4e6e0918855a7e9dbb9a99e5d3c40432 1136 libapache2-mod-proxy-uwsgi_2.4.62-1~deb12u2_armhf.deb Files: 359e5a45f23beeca3f26b8cf6fcfe8b3 3338364 debug optional apache2-bin-dbgsym_2.4.62-1~deb12u2_armhf.deb e69ce0d70a17e91aec102f4d81151661 1207192 httpd optional apache2-bin_2.4.62-1~deb12u2_armhf.deb f4a9d8d763a7c1534d44dfa52b20347a 315564 httpd optional apache2-dev_2.4.62-1~deb12u2_armhf.deb 93dfe2afe5a266cc87325d176116e045 3140 httpd optional apache2-ssl-dev_2.4.62-1~deb12u2_armhf.deb 17bb6fc87c508468e612d14ca0d4ad71 12252 debug optional apache2-suexec-custom-dbgsym_2.4.62-1~deb12u2_armhf.deb 0ddac0a0405b5b69d5604a58c110d297 142476 httpd optional apache2-suexec-custom_2.4.62-1~deb12u2_armhf.deb 36830143d88088a249d84ac658e5797c 11032 debug optional apache2-suexec-pristine-dbgsym_2.4.62-1~deb12u2_armhf.deb 872a2b979aa7bab256000b62f7f4c7f3 140968 httpd optional apache2-suexec-pristine_2.4.62-1~deb12u2_armhf.deb 9883cf057e7239ce34cbb0615516ce86 118244 debug optional apache2-utils-dbgsym_2.4.62-1~deb12u2_armhf.deb 579f50fe94496d5eda386b7ea4d8459d 209756 httpd optional apache2-utils_2.4.62-1~deb12u2_armhf.deb b3578595cc1434feb36fe5dd78745b11 11529 httpd optional apache2_2.4.62-1~deb12u2_armhf-buildd.buildinfo f4d51f5ff0ee9183ce7a15c09ec7c4d9 222752 httpd optional apache2_2.4.62-1~deb12u2_armhf.deb a82a35af6035ef419c24c302889d4ebb 948 oldlibs optional libapache2-mod-md_2.4.62-1~deb12u2_armhf.deb ce98fb766318c25c069cb94218839052 1136 oldlibs optional libapache2-mod-proxy-uwsgi_2.4.62-1~deb12u2_armhf.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEw2TRpv7HYIvK+TsIbEMdCP/rlD8FAmcAMn4ACgkQbEMdCP/r lD8YXRAA9ZSUc1iZYjOsT36SoIRrtb+VTuVhYbqJ/L2QEUomVi70SAVsRQmiUCYM HwCPi/nYzHUyuzc4OclkRb8kzZ/f0RM+Pmi1+TO2ynKk64I+xQKv1OTioxfitL6C w/eitM/1/puax+oy3ApiE653Mhw69pD6FzGNEHz6xf42m1iPxA2pq3E6WwgNt7Qg g78cTheKSJ2E05wUfCOwDOvxhCuc0Aa43aUCpxWw3kQoh0AaE1Wz02YS49uwVUz+ ULxL1DhF7bGKAneCPyjN6xreNu64ppniUjs45zdMha0gPZBeNC9LkgzCAm29hTXD o5cV2BxAp6LhXoapjddDquVLQQvimHFT2EBbROuqgoVTYMchOFumVx+/eCY6h/PB dHTtYAJMtOuImyuR5pUx2+4LiVN7H7RdcHkNF1P5fJf9UgnqT4Wb/EgKvRDJSroN sHi6Q0LhMSOQYAyD8tvIMJ5etVhFUmU5tKQzlC9ZlECW2e72CZyoKqHHJgw0KhY7 PDKa3wu0FqRAySbt5EXGVy/Qc5aPTrYvtYNJj7k7ZiJr5DjMsaYVvGE0krthn1jU JVOxbwlj+z9gkFxMJ+o+u41OsT70WNK4om0HfszAElZ2qTWx2zRa79eX3ufszo4l k0QWC5GiNNbqPQDWSslrox3sxmNW8iyLTXoXfo3e9EYI5DmeRLw= =C7Dx -----END PGP SIGNATURE-----