[ubuntu/bionic-security] apache2 2.4.29-1ubuntu4.27 (Accepted)

Marc Deslauriers marc.deslauriers at canonical.com
Thu Mar 9 14:25:23 UTC 2023


apache2 (2.4.29-1ubuntu4.27) bionic-security; urgency=medium

  * SECURITY UPDATE: HTTP request splitting with mod_rewrite and mod_proxy
    - debian/patches/CVE-2023-25690-1.patch: don't forward invalid query
      strings in modules/http2/mod_proxy_http2.c,
      modules/mappers/mod_rewrite.c, modules/proxy/mod_proxy_ajp.c,
      modules/proxy/mod_proxy_balancer.c, modules/proxy/mod_proxy_http.c,
      modules/proxy/mod_proxy_wstunnel.c.
    - debian/patches/CVE-2023-25690-2.patch: Fix missing APLOGNO in
      modules/http2/mod_proxy_http2.c.
    - CVE-2023-25690

Date: 2023-03-08 18:32:09.421066+00:00
Changed-By: Marc Deslauriers <marc.deslauriers at canonical.com>
https://launchpad.net/ubuntu/+source/apache2/2.4.29-1ubuntu4.27
-------------- next part --------------
Sorry, changesfile not available.


More information about the Bionic-changes mailing list