     -> Component: universe Section: web

Origin: Debian/incoming
Format: 1.7
Date: Wed,  16 Aug 2006 15:08:38 +0100
Source: apache
Binary: apache-common, apache, apache-doc, apache-ssl, apache-dbg, apache-perl, libapache-mod-perl, apache-dev
Architecture: source
Version: 1.3.34-4
Distribution: edgy
Urgency: high
Maintainer: Debian Apache Maintainers <debian-apache at>
Changed-By: Adam Conrad <adconrad at>
 apache     - versatile, high-performance HTTP server
Closes: 292333 358543 361217 364354 380231 381381 381893 383267 383285
 apache (1.3.34-4) unstable; urgency=low
   * Save and restore IFS every time we mangle it in postinst.common, to
     avoid debconf exploding (closes: #381893, #358543, #383267, #383285)
   * Updated Debconf translations (closes: #361217, #364354)
     - Update sv.po, thanks to Daniel Nylander <yeager at>
     - Added gl.po, thanks to Jacobo Tarrio <jtarrio at>
 apache (1.3.34-3) unstable; urgency=high
   * Add 908_mod_rewrite_CVE-2006-3747 to resolve an off-by-one 
     security problem in the ldap scheme handling.  For some
     RewriteRules this could lead to a pointer being written out
     of bounds. (closes: #380231)
   * Add 909_core_CVE-2006-3918 to resolve a potential cross-site 
     scripting vulnerability in the core of Apache, by HTML escaping 
     the contents of the Expect header. (closes: #381381)
   * Added patch from Robin Elfrink to allow Apache to build on
     Debian/kfreebsd (closes: #292333)
   * Build-depend (and make apache-dev depend on) libdb4.4 instead of 4.3
