-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Fri, 04 Oct 2024 15:21:08 +0000 Source: apache2 Binary: apache2 apache2-bin apache2-bin-dbgsym apache2-dev apache2-ssl-dev apache2-suexec-custom apache2-suexec-custom-dbgsym apache2-suexec-pristine apache2-suexec-pristine-dbgsym apache2-utils apache2-utils-dbgsym libapache2-mod-md libapache2-mod-proxy-uwsgi Architecture: mipsel Version: 2.4.62-1~deb12u2 Distribution: bookworm-security Urgency: medium Maintainer: mipsel Build Daemon (mipsel-osuosl-05) Changed-By: Bastien Roucariès Description: apache2 - Apache HTTP Server apache2-bin - Apache HTTP Server (modules and other binary files) apache2-dev - Apache HTTP Server (development headers) apache2-ssl-dev - Apache HTTP Server (mod_ssl development headers) apache2-suexec-custom - Apache HTTP Server configurable suexec program for mod_suexec apache2-suexec-pristine - Apache HTTP Server standard suexec program for mod_suexec apache2-utils - Apache HTTP Server (utility programs for web servers) libapache2-mod-md - transitional package libapache2-mod-proxy-uwsgi - transitional package Closes: 1079172 1079206 Changes: apache2 (2.4.62-1~deb12u2) bookworm-security; urgency=medium . * Fix CVE-2024-38474 regression: Better question mark tracking to avoid UnsafeAllow3F (Closes: #1079172) * Fix CVE-2024-39884 regression: Trust strings from configuration in mod_proxy (Closes: #1079206) * Add myself as maintainer with Yadd agreement Checksums-Sha1: c0f35169fb589bf001cbb1532569409fd1600964 3480412 apache2-bin-dbgsym_2.4.62-1~deb12u2_mipsel.deb ff2451a11b69d8e1a44ce62e95ac46aebd89631c 1249088 apache2-bin_2.4.62-1~deb12u2_mipsel.deb 1c43409fe7ab4277130656d5116f830134785d16 315568 apache2-dev_2.4.62-1~deb12u2_mipsel.deb a55ecaefc95e1562bb8c67328951a25b36ed247f 3140 apache2-ssl-dev_2.4.62-1~deb12u2_mipsel.deb b8a98bf7a3e56aa92f7f9d8d73d0952fd6430a6c 12620 apache2-suexec-custom-dbgsym_2.4.62-1~deb12u2_mipsel.deb 4396215694c435e3159fc3eb5da44eec86cf2ff9 142856 apache2-suexec-custom_2.4.62-1~deb12u2_mipsel.deb b82c6042d0a35e548b59207c4e7913c380d09a2f 11344 apache2-suexec-pristine-dbgsym_2.4.62-1~deb12u2_mipsel.deb 7d04a957e1c2f0d0c2f455ef3034e5d9eca33f98 141348 apache2-suexec-pristine_2.4.62-1~deb12u2_mipsel.deb 7de02cf88a391032005d1b874e3cfe5880da0845 120652 apache2-utils-dbgsym_2.4.62-1~deb12u2_mipsel.deb b674aebeccba9bef0dc18869d561913eb9ab454f 214252 apache2-utils_2.4.62-1~deb12u2_mipsel.deb bd3792441d828210bbf6c762e8cf9869d16a2416 11516 apache2_2.4.62-1~deb12u2_mipsel-buildd.buildinfo 6dc57361af6bdfd314c33ae751a3c94053dbd67e 222752 apache2_2.4.62-1~deb12u2_mipsel.deb 3adf46a04a4f0c2258f6a98e62374ec955c5730b 948 libapache2-mod-md_2.4.62-1~deb12u2_mipsel.deb 888d1fa78188577f6a200002adb15d168e37ada9 1132 libapache2-mod-proxy-uwsgi_2.4.62-1~deb12u2_mipsel.deb Checksums-Sha256: 405689e846c14de5e9077acaabd2b11db9897d9080bb5b9ad7b1f95e80054158 3480412 apache2-bin-dbgsym_2.4.62-1~deb12u2_mipsel.deb 4df14d1e8a0f9604561e5c1426fb4395d72d6b04636ae4e51873221dc5dd9d03 1249088 apache2-bin_2.4.62-1~deb12u2_mipsel.deb cb94ccf9175d4d42174aa929b55899c493e0765889dabd6b491707966a8fb03c 315568 apache2-dev_2.4.62-1~deb12u2_mipsel.deb 717dd4b5a3af3548cad778e93f11857cb37c9b1acc5b13e750a567f9733fec0a 3140 apache2-ssl-dev_2.4.62-1~deb12u2_mipsel.deb e508dc128c2e25da22c7d5cec067a8808e008dabd3445771d8af974df5ab81da 12620 apache2-suexec-custom-dbgsym_2.4.62-1~deb12u2_mipsel.deb 2c6c55b62afeaf56cf66f41aae89188562315e7ef1dc84c8ae3fcdbd3e93e6ed 142856 apache2-suexec-custom_2.4.62-1~deb12u2_mipsel.deb 93d51ebfff1515c0a2960a50119519df22cb6fda59ac1882148f14f771208fb9 11344 apache2-suexec-pristine-dbgsym_2.4.62-1~deb12u2_mipsel.deb b2f5f68768d04774b539142c426f13141445fa072c68dd3b720fa38b8c71b796 141348 apache2-suexec-pristine_2.4.62-1~deb12u2_mipsel.deb 86c00b3ee308f473ae2795fbac73dc7a6a17a6cf104fafe55bbca8d93844d708 120652 apache2-utils-dbgsym_2.4.62-1~deb12u2_mipsel.deb eef17d72f8700904026c43e9e9a311dbadbd6432fc7848e6266d2a3a2ce5e1cd 214252 apache2-utils_2.4.62-1~deb12u2_mipsel.deb 601f643309bfe7e45a85e32606049c55f449ee78180e5c22db06cdb33f312303 11516 apache2_2.4.62-1~deb12u2_mipsel-buildd.buildinfo 2f9389ea78d169f5a8131fb0a0b0dd1c74d5a1d11a51105ef10dbf965523a945 222752 apache2_2.4.62-1~deb12u2_mipsel.deb 7a1ec68cfd1f9fc1ad7b2352088fa55e5c059e704318570fd4966dc27eb2f6a8 948 libapache2-mod-md_2.4.62-1~deb12u2_mipsel.deb 2ab6a5428ebd75699b7077dbe26f92bfa80dfd96046b94e82d6c2a391caf89cf 1132 libapache2-mod-proxy-uwsgi_2.4.62-1~deb12u2_mipsel.deb Files: 91147aa863167087139ec0ee7ab10fea 3480412 debug optional apache2-bin-dbgsym_2.4.62-1~deb12u2_mipsel.deb 7fddfec5c1e020f9308cc09b4168f6ef 1249088 httpd optional apache2-bin_2.4.62-1~deb12u2_mipsel.deb e535983b534029f9661d2d3871c8b619 315568 httpd optional apache2-dev_2.4.62-1~deb12u2_mipsel.deb 2653aeebdca16e59b4ce3726952c6f6c 3140 httpd optional apache2-ssl-dev_2.4.62-1~deb12u2_mipsel.deb 293e7d7032b4924e8223acbe56f75ec3 12620 debug optional apache2-suexec-custom-dbgsym_2.4.62-1~deb12u2_mipsel.deb e46e69da174ff9ab1edff86554476aad 142856 httpd optional apache2-suexec-custom_2.4.62-1~deb12u2_mipsel.deb e2a59730d1ef063663748bec7fcc0418 11344 debug optional apache2-suexec-pristine-dbgsym_2.4.62-1~deb12u2_mipsel.deb 27d3a332939bb27f78655bcc53819669 141348 httpd optional apache2-suexec-pristine_2.4.62-1~deb12u2_mipsel.deb 474160963ca780b82c48cba643b203eb 120652 debug optional apache2-utils-dbgsym_2.4.62-1~deb12u2_mipsel.deb fdf4aa5db89bba8eb1b53362562807f4 214252 httpd optional apache2-utils_2.4.62-1~deb12u2_mipsel.deb b2bb06675535d55b4783e2e9a998017e 11516 httpd optional apache2_2.4.62-1~deb12u2_mipsel-buildd.buildinfo 00c99d53ea3356a682e2a89c875bc01c 222752 httpd optional apache2_2.4.62-1~deb12u2_mipsel.deb 8fcf3c1d644e98c612aefa43e40e8f75 948 oldlibs optional libapache2-mod-md_2.4.62-1~deb12u2_mipsel.deb eaba0732ada9d9da5bf58bf5a9ce181b 1132 oldlibs optional libapache2-mod-proxy-uwsgi_2.4.62-1~deb12u2_mipsel.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEuQAPGkYIXAAfq7z1C2Vm2FYVKKAFAmcAM2EACgkQC2Vm2FYV KKCmTQ//ZwXUEZ1arFgVVDylM+k2Upy8FeHkVNLuQs1xrrQguZGbH/QaM3BaTqoN qfXk6b6SHsTV5ZELur6CU6SXeeirPSpHeVQMg1cgtDU/2NHOAjofg0N9jqkn+emi 6nTW7A8DsdT+Y9rOrWMnskEr9jGwm3c/lPi6a11wREAFLgTz3Kq/O6YblYqOiv/W 9PiM3PR1tKw58Krhd/R5/gB3mEp5Mco8ZhpsRp3J9RvclFy2q78IhDsBqX/5aqqn G5Rvd+vCetjH4OtVVoP5KYBTn/RW1KphkeDlqfCym/DLeSAGXEhvrwk1jjOGbWK8 a8rUhqvwHQreiXAOxwewZkZW0iC/XGqKyXPEWiWKkxjMov1dXOBKgrSNyLMQEcrm xArlB9jZONfrIDDWe3Pzks4qxbqNy2ovsNTh5sGXnn/HTiebhYsGLKe/zmADrAUe yzKKPVcCMRORoTc2qrQ3239CoMsiO/Wv59N+5fHVNQITyscTMgKblkeXMyr/66vi bkM0qI+DKx7QaCV3hPe4bIk5liR/JkO5rgSxhdfFWrQOpDsGESolPgXCdEqasHIs 278o41t2Bk5mRKcBvfgr/snV3t0MPs9IYkJ17kggX9/3CB+7EBv/uWnsmk726xAn FQ/2koZTLLGRaFuSBt9TKYaGKCIlUOlEYk6ndcPlyfyKtPcJjs0= =9I/r -----END PGP SIGNATURE-----