-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Fri, 04 Oct 2024 15:21:08 +0000 Source: apache2 Binary: apache2 apache2-bin apache2-bin-dbgsym apache2-dev apache2-ssl-dev apache2-suexec-custom apache2-suexec-custom-dbgsym apache2-suexec-pristine apache2-suexec-pristine-dbgsym apache2-utils apache2-utils-dbgsym libapache2-mod-md libapache2-mod-proxy-uwsgi Architecture: s390x Version: 2.4.62-1~deb12u2 Distribution: bookworm-security Urgency: medium Maintainer: s390x Build Daemon (zandonai) Changed-By: Bastien Roucariès Description: apache2 - Apache HTTP Server apache2-bin - Apache HTTP Server (modules and other binary files) apache2-dev - Apache HTTP Server (development headers) apache2-ssl-dev - Apache HTTP Server (mod_ssl development headers) apache2-suexec-custom - Apache HTTP Server configurable suexec program for mod_suexec apache2-suexec-pristine - Apache HTTP Server standard suexec program for mod_suexec apache2-utils - Apache HTTP Server (utility programs for web servers) libapache2-mod-md - transitional package libapache2-mod-proxy-uwsgi - transitional package Closes: 1079172 1079206 Changes: apache2 (2.4.62-1~deb12u2) bookworm-security; urgency=medium . * Fix CVE-2024-38474 regression: Better question mark tracking to avoid UnsafeAllow3F (Closes: #1079172) * Fix CVE-2024-39884 regression: Trust strings from configuration in mod_proxy (Closes: #1079206) * Add myself as maintainer with Yadd agreement Checksums-Sha1: 20fcf0a437c0e5c5294fe5292c743c45c17fe5b1 3343292 apache2-bin-dbgsym_2.4.62-1~deb12u2_s390x.deb 6a010387eb39c61ea118ff3ba88db6108e762023 1258004 apache2-bin_2.4.62-1~deb12u2_s390x.deb 3c8a20900ac7117f6a87901b54cb2aba7c9a348c 315560 apache2-dev_2.4.62-1~deb12u2_s390x.deb 0efc921c318c34529939c7fe4d2fcb3d96b8eabb 3140 apache2-ssl-dev_2.4.62-1~deb12u2_s390x.deb d57bc27361585be365c9dd486a1084589cbe6294 12252 apache2-suexec-custom-dbgsym_2.4.62-1~deb12u2_s390x.deb db325afa37c3511ddfb8db7f12aa72c47b0cdb47 142900 apache2-suexec-custom_2.4.62-1~deb12u2_s390x.deb 89f1f08b0b0d4e058a18c5a1560106056dec6675 10972 apache2-suexec-pristine-dbgsym_2.4.62-1~deb12u2_s390x.deb e4ecd0572b58ff3067ddf521851e6327e64f1698 141364 apache2-suexec-pristine_2.4.62-1~deb12u2_s390x.deb 072eb09bcd33d9b4ff1de9d93ce830f73310ce2e 115096 apache2-utils-dbgsym_2.4.62-1~deb12u2_s390x.deb 0fdb7db1f6390e91bf12de96ab0735829743a70b 206864 apache2-utils_2.4.62-1~deb12u2_s390x.deb 0d35972a3fdd6fde465e6f33aa752a87adfe0351 11549 apache2_2.4.62-1~deb12u2_s390x-buildd.buildinfo e5b4a8f34c5d75d93a31dfdee0b64751ebaef48e 222756 apache2_2.4.62-1~deb12u2_s390x.deb 20b97888316ae12a568b8ce817bc348ee0a57037 952 libapache2-mod-md_2.4.62-1~deb12u2_s390x.deb 251ab65d897d33aad2e4ed1b076420049d49f620 1136 libapache2-mod-proxy-uwsgi_2.4.62-1~deb12u2_s390x.deb Checksums-Sha256: 8562ecf9df99b5547fe0a5cc722cf0aff64a577b1cec1ecd0892d0e29eb6baf8 3343292 apache2-bin-dbgsym_2.4.62-1~deb12u2_s390x.deb c8013c0356630c573bc5c0b33ba388cfc7b4b936a8254ec35ab913c656205cf6 1258004 apache2-bin_2.4.62-1~deb12u2_s390x.deb 9a8118251dd72ed0dd372d684115fdc0a960d6cc596e1ef96e1be85827084fe4 315560 apache2-dev_2.4.62-1~deb12u2_s390x.deb 2006ce34903a08e1b1bd3aa08a730e6435924667615a5aabfac88e768208aa30 3140 apache2-ssl-dev_2.4.62-1~deb12u2_s390x.deb 4b408afa43c3717e4bd03170f82f9e191b40ce0dea8c9f7510fa7850159882bd 12252 apache2-suexec-custom-dbgsym_2.4.62-1~deb12u2_s390x.deb c5fb462bd5742562384e524f7c451de718713fc120cf0a191908bd1170b9b514 142900 apache2-suexec-custom_2.4.62-1~deb12u2_s390x.deb 50b7524c97f95ba2d5cf70e01272d4cf9b5a80ad1f4ad1672279b29cc406e7e4 10972 apache2-suexec-pristine-dbgsym_2.4.62-1~deb12u2_s390x.deb 253ec57b14861afa4fae7ff81e41b4ec3e074713b731b8edb8cd12d141e1995d 141364 apache2-suexec-pristine_2.4.62-1~deb12u2_s390x.deb 2eaa893897337f7529f50d71a5571631526b55432cd2bf9b860a548055347180 115096 apache2-utils-dbgsym_2.4.62-1~deb12u2_s390x.deb 4c1c7e631311efedd44fa330cfa257bfbd48b4eced076ab8617ccce4155e593d 206864 apache2-utils_2.4.62-1~deb12u2_s390x.deb ba427b64fc26bd01c1cbb0c3c9be248fc38f1bd54beac4f33559e8a055f72a7d 11549 apache2_2.4.62-1~deb12u2_s390x-buildd.buildinfo a8d657a3d26edc8240a7066e048945f2f2eb3980ef8a3e4c23df320da3d04279 222756 apache2_2.4.62-1~deb12u2_s390x.deb 90f2f8728184dcf1fd9501d390fa588c1cbc996dd99a547b21de6b100e411db0 952 libapache2-mod-md_2.4.62-1~deb12u2_s390x.deb c323e60cabd20ed9c3f4b588bf4d75fd2208e5d1cab8e7af539a5b5e958383cb 1136 libapache2-mod-proxy-uwsgi_2.4.62-1~deb12u2_s390x.deb Files: bd3cf1bc20a1d7022c75fb35f4b399af 3343292 debug optional apache2-bin-dbgsym_2.4.62-1~deb12u2_s390x.deb 1b009ed07c5b3a3193e7d4fb7e5c5b8f 1258004 httpd optional apache2-bin_2.4.62-1~deb12u2_s390x.deb 088a389428638f3444822a06c0b4032e 315560 httpd optional apache2-dev_2.4.62-1~deb12u2_s390x.deb a77cee275295c5ebb6f84c2112fdddc2 3140 httpd optional apache2-ssl-dev_2.4.62-1~deb12u2_s390x.deb 355702773226819dff71aea77921b990 12252 debug optional apache2-suexec-custom-dbgsym_2.4.62-1~deb12u2_s390x.deb 1a553fc9b39ce47f8626739273db5593 142900 httpd optional apache2-suexec-custom_2.4.62-1~deb12u2_s390x.deb de4b165133f511e43095321186655d82 10972 debug optional apache2-suexec-pristine-dbgsym_2.4.62-1~deb12u2_s390x.deb df148e67da5ec1c5f166ced81a1b1f7a 141364 httpd optional apache2-suexec-pristine_2.4.62-1~deb12u2_s390x.deb 8471ca6bae6fe604ae79b67004bbc547 115096 debug optional apache2-utils-dbgsym_2.4.62-1~deb12u2_s390x.deb 57c6942b8fc5e6673d1ef380e0d7f018 206864 httpd optional apache2-utils_2.4.62-1~deb12u2_s390x.deb 7d888d7ed7903b94f14d062df2882330 11549 httpd optional apache2_2.4.62-1~deb12u2_s390x-buildd.buildinfo c2b3f8a25b056e5ea39d5a473da96cf6 222756 httpd optional apache2_2.4.62-1~deb12u2_s390x.deb 4f75e864836f5876e6e932e994622082 952 oldlibs optional libapache2-mod-md_2.4.62-1~deb12u2_s390x.deb 26f350f4706e2d3f61b692af8cf7f072 1136 oldlibs optional libapache2-mod-proxy-uwsgi_2.4.62-1~deb12u2_s390x.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEctqRAwcjFMIrbct74euoNlQ3ywQFAmcAMlQACgkQ4euoNlQ3 ywRcTw//cT4fTkEN1ZqoVYPGMWV6AD+Cp54b3vWobHOONBHJIx66aZI7YUELKT9q QqGBuWzyVYGxg+B/+eRiPGyWwfSbSD4vr8yg9+Xt+U8i0dxJUMda0Pujy1CphT36 +DLQ0da1BxQ8d1xB1OCY8QQAbcuLKCQGoQOFVFPIbYPUP/D9N+JtBZKPnZ8dQGKz mynukLX0ZuuwFPKGXrBoajSpe9+vDsE7VNfbRbKdsB2tKs3AiajxXxIZGD6U5KHo 0CPiRe34WLFAAdDByPaHYO5M9XrNKfO1LAy8H93Ukef03l7gtMSzOozqA+LGB94w ZXiqHfi5SXJG/Mmrv2jE7YLwz6/4jJ4M2nDdLWZlf6R7lGu3/Y/493kQlFuBd8fU tP5t7NBbbucTYL2/pNC4iSFGAPDL+46g5Lmsu9d9QOlp2Pb/3mOUJsSPo5eZgtn7 nGayMjGYpwKR6aqK3jJTMWoRtWrOXjZth3HUZi7LLVzH6QKgAg3OTzqG88sPdy9Q B4c01orGCl1ivLZqucpvJnyn+QzHEd3KKmdO6apFooapMGMKQtTN6ZRoQyjyk2ks 6U6OETkziQcVgwTiiNTEUdyo/IHNro0+qfDWh+THv2Y8Zi8FukML69kKQ8M9a9Qu 01VdI/xThaf4WNAUBcy8H6SXuCbgP9oXXNy47qzGm1NB++jWdCY= =TuJz -----END PGP SIGNATURE-----