Accepted apache2 2.0.54-4ubuntu2 (source)
Martin Pitt
martin.pitt at ubuntu.com
Mon Aug 8 02:35:04 CDT 2005
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Format: 1.7
Date: Mon, 8 Aug 2005 09:27:56 +0200
Source: apache2
Binary: apache2-utils apache2 apache2-prefork-dev apache2-mpm-prefork apache2-doc libapr0-dev apache2-mpm-threadpool apache2-mpm-worker libapr0 apache2-threaded-dev apache2-common apache2-mpm-perchild
Architecture: source
Version: 2.0.54-4ubuntu2
Distribution: breezy
Urgency: low
Maintainer: Debian Apache Maintainers <debian-apache at lists.debian.org>
Changed-By: Martin Pitt <martin.pitt at ubuntu.com>
Description:
apache2 - next generation, scalable, extendable web server
apache2-common - next generation, scalable, extendable web server
apache2-doc - documentation for apache2
apache2-mpm-perchild - experimental high speed perchild threaded model for Apache2
apache2-mpm-prefork - traditional model for Apache2
apache2-mpm-threadpool - experimental high speed model for Apache2 (transitional package)
apache2-mpm-worker - high speed threaded model for Apache2
apache2-prefork-dev - development headers for apache2
apache2-threaded-dev - development headers for apache2
apache2-utils - utility programs for webservers
libapr0 - the Apache Portable Runtime
libapr0-dev - development headers for libapr
Changes:
apache2 (2.0.54-4ubuntu2) breezy; urgency=low
.
* SECURITY UPDATE: Fix two vulnerabilities.
* Add debian/patches/043_CAN-2005-1268.patch:
- Fix off-by-one error in the SSL certification validation callback.
- CAN-2005-1268
* Add debian/patches/044_CAN-2005-2088.patch:
- Proxy HTTP: If a response contains both Transfer-Encoding
and a Content-Length, remove the Content-Length to eliminate
an HTTP Request Smuggling vulnerability and don't reuse the
connection, stopping some HTTP Request Spoofing attacks.
- CAN-2005-2088
Files:
63ce679f206b70c6c2710ebd17c629c8 1155 net optional apache2_2.0.54-4ubuntu2.dsc
625d3f95c4c0bfc3f5b1c6ef4c99e2ad 108813 net optional apache2_2.0.54-4ubuntu2.diff.gz
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.1 (GNU/Linux)
iD8DBQFC9wnmDecnbV4Fd/IRAmpkAKDqlAAZGjVeEXoy+y4xBos51ACWpACg1peF
IH4OXAFiA3v2oUXN8MT1YlQ=
=mPFp
-----END PGP SIGNATURE-----
Accepted:
apache2_2.0.54-4ubuntu2.diff.gz
to pool/main/a/apache2/apache2_2.0.54-4ubuntu2.diff.gz
apache2_2.0.54-4ubuntu2.dsc
to pool/main/a/apache2/apache2_2.0.54-4ubuntu2.dsc
More information about the breezy-changes
mailing list