-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Fri, 04 Oct 2024 15:21:08 +0000 Source: apache2 Binary: apache2 apache2-bin apache2-bin-dbgsym apache2-dev apache2-ssl-dev apache2-suexec-custom apache2-suexec-custom-dbgsym apache2-suexec-pristine apache2-suexec-pristine-dbgsym apache2-utils apache2-utils-dbgsym libapache2-mod-md libapache2-mod-proxy-uwsgi Architecture: mips64el Version: 2.4.62-1~deb12u2 Distribution: bookworm-security Urgency: medium Maintainer: mipsel Build Daemon (mipsel-osuosl-05) Changed-By: Bastien Roucariès Description: apache2 - Apache HTTP Server apache2-bin - Apache HTTP Server (modules and other binary files) apache2-dev - Apache HTTP Server (development headers) apache2-ssl-dev - Apache HTTP Server (mod_ssl development headers) apache2-suexec-custom - Apache HTTP Server configurable suexec program for mod_suexec apache2-suexec-pristine - Apache HTTP Server standard suexec program for mod_suexec apache2-utils - Apache HTTP Server (utility programs for web servers) libapache2-mod-md - transitional package libapache2-mod-proxy-uwsgi - transitional package Closes: 1079172 1079206 Changes: apache2 (2.4.62-1~deb12u2) bookworm-security; urgency=medium . * Fix CVE-2024-38474 regression: Better question mark tracking to avoid UnsafeAllow3F (Closes: #1079172) * Fix CVE-2024-39884 regression: Trust strings from configuration in mod_proxy (Closes: #1079206) * Add myself as maintainer with Yadd agreement Checksums-Sha1: d7820f2615a37d06d52636a7994e9e4241255dcf 3571376 apache2-bin-dbgsym_2.4.62-1~deb12u2_mips64el.deb 5b0aa8732d6cfec7a8d78a6443bf8127e7ab2cbb 1224156 apache2-bin_2.4.62-1~deb12u2_mips64el.deb 58a0a48a636d1cb5db695542ae437516d9af90c4 315564 apache2-dev_2.4.62-1~deb12u2_mips64el.deb 5d5b48b345c13e30afec3b60f54d14d88ea78a49 3140 apache2-ssl-dev_2.4.62-1~deb12u2_mips64el.deb ee49e2d153f89cb95ffce4c7c7dcabaec8ea22d8 12936 apache2-suexec-custom-dbgsym_2.4.62-1~deb12u2_mips64el.deb 7c6dda8bbfecb669bea7b7db36311462bec46de5 143008 apache2-suexec-custom_2.4.62-1~deb12u2_mips64el.deb e556edb22ebd19efb2f5fa6b8ff5db739fc07b0d 11688 apache2-suexec-pristine-dbgsym_2.4.62-1~deb12u2_mips64el.deb 8c78e25650188ec8e15ee69d7e1697c9959256c0 141504 apache2-suexec-pristine_2.4.62-1~deb12u2_mips64el.deb 1300210becd14c4f8f042a9b34eb8d11a1189e50 122084 apache2-utils-dbgsym_2.4.62-1~deb12u2_mips64el.deb d9f8fa6bd686d18d9c141e086aec08a4fef1e1a2 209592 apache2-utils_2.4.62-1~deb12u2_mips64el.deb a1ce35ffbcde1d4cc589eafa6ab6baf33337c0c0 11605 apache2_2.4.62-1~deb12u2_mips64el-buildd.buildinfo 7abd7f1670102871ba46bd786911493e09ea4042 222752 apache2_2.4.62-1~deb12u2_mips64el.deb 0912459133c66a39821c94f3410dcedbd56c172e 952 libapache2-mod-md_2.4.62-1~deb12u2_mips64el.deb 8d3d80f63b07ea24ccf22a98907c9925dcb76e8f 1132 libapache2-mod-proxy-uwsgi_2.4.62-1~deb12u2_mips64el.deb Checksums-Sha256: 4b509b349f33e4265ff0803a45be3bf51aeec5d2b48cd70cf85e191d2f3654fa 3571376 apache2-bin-dbgsym_2.4.62-1~deb12u2_mips64el.deb f298962b8d1198447883d97e6be6e67c4e8caea77fcf8109950bd610197f8a92 1224156 apache2-bin_2.4.62-1~deb12u2_mips64el.deb 42e1e4c085af1e56976559f4e78cd3a3e5a8243dc602c90f1b7bd17631db03bb 315564 apache2-dev_2.4.62-1~deb12u2_mips64el.deb 22359f132f60333d9861ec2273dcadbc96d2318dce9340cdecf195b905e7ed6d 3140 apache2-ssl-dev_2.4.62-1~deb12u2_mips64el.deb 234bb709239efb7470a977285a1c39168a6ee1d30b12eda11d2ce3a3974d51b4 12936 apache2-suexec-custom-dbgsym_2.4.62-1~deb12u2_mips64el.deb b7616d47573d444f78bf9230e7e92f2410f4bcd1e60b015c7c413618e36a16fb 143008 apache2-suexec-custom_2.4.62-1~deb12u2_mips64el.deb 754529447186b04cbf1c9830b56f8ae4209653fa6fd02be168c93abf7700b015 11688 apache2-suexec-pristine-dbgsym_2.4.62-1~deb12u2_mips64el.deb 61410d4524bf7b7b0e1bee5d527278316ed55806bb85985fb85736813fbafadd 141504 apache2-suexec-pristine_2.4.62-1~deb12u2_mips64el.deb 135ab28473a3cba6c7244ef21d7fa3ab1665070364dcc52243f50b85e6c34e42 122084 apache2-utils-dbgsym_2.4.62-1~deb12u2_mips64el.deb f1d1266740ac8149366612ecf61262e60afddb5b454cd0a8e37993c28b67f49e 209592 apache2-utils_2.4.62-1~deb12u2_mips64el.deb b9b7f456cce38d504583cb3e99c51bae258df2b8144a8ee96f1eb216e2eb6331 11605 apache2_2.4.62-1~deb12u2_mips64el-buildd.buildinfo 47a16c472b02e2ea97703ca9b9cc5dc7e6c5fc7fac4f24ac70102a760a6e9878 222752 apache2_2.4.62-1~deb12u2_mips64el.deb d192d87cac27d6d265fa0248d3fe9f6fe0a09e82474a45f5e0c341f3ad7d4f09 952 libapache2-mod-md_2.4.62-1~deb12u2_mips64el.deb 1621cb7047c59b3bb00fb55debde23dfcae33a52d638b3065ad765b2104dd8bd 1132 libapache2-mod-proxy-uwsgi_2.4.62-1~deb12u2_mips64el.deb Files: cb6426810b1265ecd4042e84976a4d2f 3571376 debug optional apache2-bin-dbgsym_2.4.62-1~deb12u2_mips64el.deb 96154a1e9c4f814d8427dddc0ceba905 1224156 httpd optional apache2-bin_2.4.62-1~deb12u2_mips64el.deb 1d9ac6eb3a4940ca1baa2ade10a6e052 315564 httpd optional apache2-dev_2.4.62-1~deb12u2_mips64el.deb def5cb6091e25fd67e7a596835de021c 3140 httpd optional apache2-ssl-dev_2.4.62-1~deb12u2_mips64el.deb b6844c34f6adf57a4c6b1e6f11e2f2b1 12936 debug optional apache2-suexec-custom-dbgsym_2.4.62-1~deb12u2_mips64el.deb 647cc97aa2b243c0e335353204c3d83f 143008 httpd optional apache2-suexec-custom_2.4.62-1~deb12u2_mips64el.deb a1078bf8fedd7aca93ec259126b982e6 11688 debug optional apache2-suexec-pristine-dbgsym_2.4.62-1~deb12u2_mips64el.deb 8c23aa2f92b5b4bb9026aed167f438d2 141504 httpd optional apache2-suexec-pristine_2.4.62-1~deb12u2_mips64el.deb e476ab6c356615cbf8db2c08c10489f0 122084 debug optional apache2-utils-dbgsym_2.4.62-1~deb12u2_mips64el.deb be9bc69d0f84c25e73e2280f1e1649c8 209592 httpd optional apache2-utils_2.4.62-1~deb12u2_mips64el.deb 3d85db7ab63702b9580efb1d7fa7aac3 11605 httpd optional apache2_2.4.62-1~deb12u2_mips64el-buildd.buildinfo 9d2cdf4394838d676ac9c283e8e400d3 222752 httpd optional apache2_2.4.62-1~deb12u2_mips64el.deb bda135630aaea46c0211872b2335bd25 952 oldlibs optional libapache2-mod-md_2.4.62-1~deb12u2_mips64el.deb ab1e5830a4ebc326063a6049217ec97d 1132 oldlibs optional libapache2-mod-proxy-uwsgi_2.4.62-1~deb12u2_mips64el.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEuQAPGkYIXAAfq7z1C2Vm2FYVKKAFAmcANNgACgkQC2Vm2FYV KKBHEQ/+LX0Btw4nWNEqa8d2mFK8UdL/o8L/Iz5Dk7C3A4XF8I9J+COyf9CicsRs pZgsM82gAiuAvwOT0Qe6YyXWn15sGRfNnFjjsCl13sp9TkG1vT8KTs1hJ1Zsp3GD jML84tmzs/Ry78IVpjuFQ+h5pvyRTHJSqQFNbTIDAN4cd/dfViZ9RM1KI3GVDaoB P27W02h4rHZLuDOns9jQBdwJPy7wQsBUkbNByb7rnEFiDaHecPMtyuwHxpdaa0Ev xb3To9zvdHcsqyhvR1WAJ8rupa6pmuyj+MSfuNA0LDmZ7EUEMkWUNHboZcrIhnBn peHdJaqR343blnOwGOXmIhWSQoMV2dWBsKXzmRnLdbE9HHlNIfj4+Mler9lY/jCs cdcEoPay3sY5dvrnt9IRq2yYCKk71zBOf66NUy4kQASGtsdS4Mb7o8homAs7rhat 5DpSooRGA6IJ2gnnLmYHd1U67BJEK72KdQY0EJkPxDY2xipq1fcIACxP9/sRuBYw rfgqVTErbyQQw5djxLcEbPYRUTagFDBFXJDOM0IBcCmjYZ2q0l+tGjUNgbtgdESx EiRrdLKt/UPWyupe6NvCKcWpjpTrZHcKpOl/OabYVNYK41du/5PM8KIfRAW4Xezo B6Z424urLi4au4obMPrRupCJpNUGPveV3p5BuiUfjJvdYAb3rL0= =8IDn -----END PGP SIGNATURE-----