Kees Cook kees at
Thu Aug 28 16:30:18 BST 2008

 OK: apache2_2.2.9.orig.tar.gz
 OK: apache2_2.2.9-7ubuntu1.diff.gz
 OK: apache2_2.2.9-7ubuntu1.dsc
     -> Component: main Section: web

Format: 1.8
Date: Thu, 28 Aug 2008 08:10:59 -0700
Source: apache2
Binary: apache2.2-common apache2-mpm-worker apache2-mpm-prefork apache2-mpm-event apache2-utils apache2-suexec apache2-suexec-custom apache2 apache2-doc apache2-prefork-dev apache2-threaded-dev apache2-src apache2-dbg
Architecture: source
Version: 2.2.9-7ubuntu1
Distribution: intrepid
Urgency: high
Maintainer: Ubuntu Core Developers <ubuntu-devel-discuss at>
Changed-By: Kees Cook <kees at>
 apache2    - Apache HTTP Server metapackage
 apache2-dbg - Apache debugging symbols
 apache2-doc - Apache HTTP Server documentation
 apache2-mpm-event - Apache HTTP Server - event driven model
 apache2-mpm-prefork - Apache HTTP Server - traditional non-threaded model
 apache2-mpm-worker - Apache HTTP Server - high speed threaded model
 apache2-prefork-dev - Apache development headers - non-threaded MPM
 apache2-src - Apache source code
 apache2-suexec - Standard suexec program for Apache 2 mod_suexec
 apache2-suexec-custom - Configurable suexec program for Apache 2 mod_suexec
 apache2-threaded-dev - Apache development headers - threaded MPM
 apache2-utils - utility programs for webservers
 apache2.2-common - Apache HTTP Server common files
Closes: 391280 485525 489153 489215 489224 489383
 apache2 (2.2.9-7ubuntu1) intrepid; urgency=low
   * Merge from debian unstable, remaining changes:
     - debian/{control,rules}: enable PIE hardening.
     - debian/{control,rules,apache2.2-common.ufw.profile}: add ufw profiles.
 apache2 (2.2.9-7) unstable; urgency=low
   * Fix XSS in mod_proxy_ftp (CVE-2008-2939).
   * Fix mod_proxy_http losing the query string with noescape (PR 45247).
   * Make the balancer manager work in Opera and MSIE (PR 45578).
   * Fix mod_headers "edit" removing multiple headers with the same name (PR
   * Also describe how to get a backtrace from a running process in
 apache2 (2.2.9-6) unstable; urgency=high
   * Urgency high for RC bug fix.
   * Fix SIGBUS on SPARC by preventing gcc from optimizing some memcpy calls
     away. (Closes: #485525)
 apache2 (2.2.9-5) unstable; urgency=medium
   * Urgency medium to get this into testing before the freeze.
   * Remove IPv6 patch that was necessary for very old kernels but creates
     problems on systems with current kernels and net.ipv6.bindv6only = 1.
     Apache will now always create its sockets with IPV6_V6ONLY set to 0.
     (Closes: #391280)
 apache2 (2.2.9-4) unstable; urgency=low
   * Make postinst more quiet. (Closes: #489153)
   * Add Turkish language support. (Closes: #489224)
   * Remove duplicate comments in sites-available/default-ssl. (Closes: #489383)
   * Describe in NEWS.Debian how to revert to the old NameVirtualHost config.
     (Closes: #489215)
   * Redirect apache2 bug reports to apache2.2-common, to get useful dependency
Original-Maintainer: Debian Apache Maintainers <debian-apache at>

