-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Fri, 04 Oct 2024 15:21:08 +0000 Source: apache2 Binary: apache2 apache2-bin apache2-bin-dbgsym apache2-dev apache2-ssl-dev apache2-suexec-custom apache2-suexec-custom-dbgsym apache2-suexec-pristine apache2-suexec-pristine-dbgsym apache2-utils apache2-utils-dbgsym libapache2-mod-md libapache2-mod-proxy-uwsgi Architecture: ppc64el Version: 2.4.62-1~deb12u2 Distribution: bookworm-security Urgency: medium Maintainer: ppc64el Build Daemon (ppc64el-osuosl-01) Changed-By: Bastien Roucariès Description: apache2 - Apache HTTP Server apache2-bin - Apache HTTP Server (modules and other binary files) apache2-dev - Apache HTTP Server (development headers) apache2-ssl-dev - Apache HTTP Server (mod_ssl development headers) apache2-suexec-custom - Apache HTTP Server configurable suexec program for mod_suexec apache2-suexec-pristine - Apache HTTP Server standard suexec program for mod_suexec apache2-utils - Apache HTTP Server (utility programs for web servers) libapache2-mod-md - transitional package libapache2-mod-proxy-uwsgi - transitional package Closes: 1079172 1079206 Changes: apache2 (2.4.62-1~deb12u2) bookworm-security; urgency=medium . * Fix CVE-2024-38474 regression: Better question mark tracking to avoid UnsafeAllow3F (Closes: #1079172) * Fix CVE-2024-39884 regression: Trust strings from configuration in mod_proxy (Closes: #1079206) * Add myself as maintainer with Yadd agreement Checksums-Sha1: 442231e499ffc91275832696b128e73f82b46a5b 3489004 apache2-bin-dbgsym_2.4.62-1~deb12u2_ppc64el.deb 030073a2b90bec026fe1d03983d50fe88376ebd1 1447224 apache2-bin_2.4.62-1~deb12u2_ppc64el.deb 4b4e9fda6d4a91a5573b5f7edf071f71d7e288a8 315564 apache2-dev_2.4.62-1~deb12u2_ppc64el.deb 6866bfaeab7fcd951feacfbd16344109c8ff8efa 3140 apache2-ssl-dev_2.4.62-1~deb12u2_ppc64el.deb 1aa2eb3e47cb5f3c906a5f21793e9ed8b51ca83b 12792 apache2-suexec-custom-dbgsym_2.4.62-1~deb12u2_ppc64el.deb f07aa765a8fcc50e92a6484cd2707854e57d9d11 143384 apache2-suexec-custom_2.4.62-1~deb12u2_ppc64el.deb ddb798db5737d313600b72730672ad37d8a94d97 11428 apache2-suexec-pristine-dbgsym_2.4.62-1~deb12u2_ppc64el.deb 3832427bc35e1abca40f0a376380a53996ec1ef1 141628 apache2-suexec-pristine_2.4.62-1~deb12u2_ppc64el.deb 839a0660261edd6c33168cde15abcf0b402636e6 119440 apache2-utils-dbgsym_2.4.62-1~deb12u2_ppc64el.deb 13b3245bad1cbc03d679b5ce95a44095cfcd400e 212300 apache2-utils_2.4.62-1~deb12u2_ppc64el.deb c44c1390c879a6c2b0a787d43ddc0344bd406a71 11716 apache2_2.4.62-1~deb12u2_ppc64el-buildd.buildinfo dcd458622dc9dff930fce25a759c4043bdc37b93 222752 apache2_2.4.62-1~deb12u2_ppc64el.deb 534704736923d9f9895f428c48a60a6b4cc64999 952 libapache2-mod-md_2.4.62-1~deb12u2_ppc64el.deb bc09e1d132e1038b13e90a3004831cef26053141 1132 libapache2-mod-proxy-uwsgi_2.4.62-1~deb12u2_ppc64el.deb Checksums-Sha256: 961b71ce04d1c876e05383e926783e08933a03ae62a323b0fd0a45e4f6f82806 3489004 apache2-bin-dbgsym_2.4.62-1~deb12u2_ppc64el.deb 2831eba98b81c7c9d9b22ec6889f1a6b714ed66c950f968fb701cea44d9b98de 1447224 apache2-bin_2.4.62-1~deb12u2_ppc64el.deb 1fac011a64f1cfc3ac1945515f44e06fa46dd7f26bd3fec6683ba71247b3165c 315564 apache2-dev_2.4.62-1~deb12u2_ppc64el.deb 0d02c6d789a2582585dcf976cc54c3d530094aed7bf6b0ab12b101a40ae7da94 3140 apache2-ssl-dev_2.4.62-1~deb12u2_ppc64el.deb 5a16098a8bd823971396e05c5a43a6c90d5eb8c6d4e47a0a219d08d5fafcccb0 12792 apache2-suexec-custom-dbgsym_2.4.62-1~deb12u2_ppc64el.deb f0f6298857fb8b0c4b0f09c428a11919544feda08e4fa1530b48904f3ffa776a 143384 apache2-suexec-custom_2.4.62-1~deb12u2_ppc64el.deb 84c0cf8626e6ef655ebf6e07a23affe6d1f6ce3a4a37f5cee6a9540de813dced 11428 apache2-suexec-pristine-dbgsym_2.4.62-1~deb12u2_ppc64el.deb 7e43412781b9bb5791518b018a0f2c21468a6b9ceb0bc36ff70ab099ef458bb8 141628 apache2-suexec-pristine_2.4.62-1~deb12u2_ppc64el.deb c659a6c27d3d7140c67ac0558af08d127e70f9be01def377184fc0548c67fc73 119440 apache2-utils-dbgsym_2.4.62-1~deb12u2_ppc64el.deb c419007ce84530707dcc75022c57cf5c5303ea71e068e8ed3d325a17dd49a4b4 212300 apache2-utils_2.4.62-1~deb12u2_ppc64el.deb 73a2a6390c3667402a7a9d135cae87227b866b7b57b80e16a1c1421eb6266c48 11716 apache2_2.4.62-1~deb12u2_ppc64el-buildd.buildinfo a094aed62ff1cf5941f40f4a87b9c553e5b3f681f9c5d9370410953e049db1d5 222752 apache2_2.4.62-1~deb12u2_ppc64el.deb 3050446cb7841578c956a7799ddaf4edfeeb54ea6fa47cdfd4625eedb50a21a6 952 libapache2-mod-md_2.4.62-1~deb12u2_ppc64el.deb 427fab24a19a17c24fafb2513d1ee5b075c1f57d155df6b97245f16495a41c3c 1132 libapache2-mod-proxy-uwsgi_2.4.62-1~deb12u2_ppc64el.deb Files: dbf15a9c769bc4d362fb38e1fddec430 3489004 debug optional apache2-bin-dbgsym_2.4.62-1~deb12u2_ppc64el.deb 20b38b827c0d851034303efbda73aa1f 1447224 httpd optional apache2-bin_2.4.62-1~deb12u2_ppc64el.deb 3638e65a1ab12d0e21debc676207c6d5 315564 httpd optional apache2-dev_2.4.62-1~deb12u2_ppc64el.deb ef8950e2425305bfb5230a98a7358464 3140 httpd optional apache2-ssl-dev_2.4.62-1~deb12u2_ppc64el.deb 88b3bee221547dbea6f810aee461504b 12792 debug optional apache2-suexec-custom-dbgsym_2.4.62-1~deb12u2_ppc64el.deb 1bac30a96f623664b71c4177eee3780d 143384 httpd optional apache2-suexec-custom_2.4.62-1~deb12u2_ppc64el.deb a0229527268420b914725933a7383f0f 11428 debug optional apache2-suexec-pristine-dbgsym_2.4.62-1~deb12u2_ppc64el.deb 46769290d43d6f731e0048acac97db92 141628 httpd optional apache2-suexec-pristine_2.4.62-1~deb12u2_ppc64el.deb 23213a50c60c3445da575d5b7aac4670 119440 debug optional apache2-utils-dbgsym_2.4.62-1~deb12u2_ppc64el.deb 672a42f454173ecaeac3210df788064b 212300 httpd optional apache2-utils_2.4.62-1~deb12u2_ppc64el.deb a3d9b1d869368dbfe8e3694bedd5b635 11716 httpd optional apache2_2.4.62-1~deb12u2_ppc64el-buildd.buildinfo 2983b9bd092c83cff348a5bc92dbcbbe 222752 httpd optional apache2_2.4.62-1~deb12u2_ppc64el.deb 76807685fa60655f507b8a19f173e6af 952 oldlibs optional libapache2-mod-md_2.4.62-1~deb12u2_ppc64el.deb a2ed44d66f8ec8b0472c484954bfcf16 1132 oldlibs optional libapache2-mod-proxy-uwsgi_2.4.62-1~deb12u2_ppc64el.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE5v3ycPFoB5xoBEprvMjydu+xvRMFAmcAMkIACgkQvMjydu+x vROEfhAAio/61hIbmBMoKqVupJhJIl3EMRIsoRVjuIrQ477y6i8hX6Cg0KtVebxE qsUq1c2j37K3jNfZRVkmNEVuOd+LPXzA3/2nc7weojjpUc3FA9vzcF/KZRMTCjBz ExKoX5I9FpbbMbIcGHFh5yhOCEWRmt5mRmOLoFY9LS1Ytfuh0WdP7s97dj2++z9y xBi7jAcEF47h/6JNCYev73lECeJvgTYMIFasXz6yVfhojORGLyqDfZ75qOOgUHBM IfnmX7xy9mk71LjkAL1xsaQ14H5qvodZFBvWk8zFH16+Wq7HtHBz/Mfa66EFPkVV a/NOWLDLgdTaqJMkbFJf6AunG6pZP9YAED3oqaYIlA0iiObwsyUMOO/zh42FRado D3++KUD4KDEKKB6pid3YLA5OSheZ0UROAJ5g+XZkKLowhmuK2fNFo3J+Zt9al3WV 6aCbe7m/9/ArNvoBkXmgPxXrICLoQl4zRYKh4XWnOBVGv7P1IxNlHYKo7xCJh/Tr +1YRBQh0TTz2hIHujbPmmNYgeBXNX/zi5lAi+RcuHehOo+Aw06dSPrimAGjmWkJo jFap1L+4nx0TuSmKAC5JWDaipLgWscPWiztxIOuHCDAUKeQ7YoS9Vjs2uVUGM36B BvS1lqEb+ODDmOeTqsh2bt9a92KlPL5TCUl4UR5Jm3rnOOix99s= =jRNJ -----END PGP SIGNATURE-----