Accepted: apache2 2.2.9-1ubuntu1 (source)

Chuck Short zulcss at ubuntu.com
Mon Jun 16 13:35:25 BST 2008


Accepted:
 OK: apache2_2.2.9.orig.tar.gz
 OK: apache2_2.2.9-1ubuntu1.diff.gz
 OK: apache2_2.2.9-1ubuntu1.dsc
     -> Component: main Section: web

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Format: 1.7
Date: Sun, 15 Jun 2008 05:01:28 +0100
Source: apache2
Binary: apache2.2-common apache2-mpm-worker apache2-mpm-prefork apache2-mpm-event apache2-utils apache2-suexec apache2-suexec-custom apache2 apache2-doc apache2-prefork-dev apache2-threaded-dev apache2-src apache2-dbg
Architecture: source
Version: 2.2.9-1ubuntu1
Distribution: intrepid
Urgency: low
Maintainer: Ubuntu Core Developers <ubuntu-devel-discuss at lists.ubuntu.com>
Changed-By: Chuck Short <zulcss at ubuntu.com>
Description: 
 apache2    - Next generation, scalable, extendable web server
 apache2-dbg - Apache debugging symbols
 apache2-doc - documentation for apache2
 apache2-mpm-event - Event driven model for Apache HTTPD
 apache2-mpm-prefork - Traditional model for Apache HTTPD
 apache2-mpm-worker - High speed threaded model for Apache HTTPD
 apache2-prefork-dev - development headers for apache2
 apache2-src - Apache source code
 apache2-suexec - Standard suexec program for Apache 2 mod_suexec
 apache2-suexec-custom - Configurable suexec program for Apache 2 mod_suexec
 apache2-threaded-dev - development headers for apache2
 apache2-utils - utility programs for webservers
 apache2.2-common - Next generation, scalable, extendable web server
Closes: 266835 312252 349716 373969 409970 475150 477522 479136 480893 484800
Launchpad-Bugs-Fixed: 235294
Changes: 
 apache2 (2.2.9-1ubuntu1) intrepid; urgency=low
 .
   * Merge from debian unstable, remaining changes:
     - Dropped debian/patches/100_mpm_wokers_crash.dpatch. Already included
       upstream. (LP: #235294)
     - Dropped debian/patches/059_ssl_memleak_fix_PR44975.dpatch. Already included      upstream.
     - Updated maintainer field according to spec.
 .
 apache2 (2.2.9-1) unstable; urgency=low
 .
   * New upstream release. Notable changes:
     - mod_proxy_http: Better handling of excessive interim responses from
       origin server to prevent potential denial of service and high memory
       usage (CVE-2008-2364).
     - mod_proxy_balancer: Prevent CSRF attacks against the balancer-manager
       (CVE-2007-6420).
     - Worker / Event MPM: Fix race condition in pool recycling that leads to
       segmentation faults under load. (Closes: #484800)
     - mod_proxy: Keep connections to the backend persistent in the HTTPS case.
     - mod_proxy: Support environment variable interpolation in reverse
       proxying directives.
     - mod_headers: Add 'merge' option to avoid duplicate values within the
       same header.
     - mod_substitute: The default is now flattening the buckets after each
       substitution. The newly added 'q' flag allows for the quicker, more
       efficient bucket-splitting.
   * Shorten the init script's waiting period during 'restart' from 10 to 4
     seconds. This should still be plenty to allow the apache processes to
     close their listening sockets. Make the wait even shorter if apache dies
     faster. (Closes: #479136)
   * Fix some lintian warnings:
     - Add some missing patch descriptions.
     - Point to /usr/share/common-licenses instead of including the license in
       the copyright file.
 .
 apache2 (2.2.8-5) unstable; urgency=low
 .
   * Replace a2{en,dis}{mod,site} by a rewritten version that
     - supports wildcards (Closes: #373969).
     - can be influenced with environment variables (Closes: #349716).
     - checks existing symlinks for correctness (Closes: #409970).
     - allows to remove dead symlinks (Closes: #480893).
   * Move suexec suid helper program to a separate package apache2-suexec,
     which is not installed by default. Provide an alternative version of
     suexec, which can be customized with a config file. This can be found in
     the apache2-suexec-custom package. Closes: #312252, #266835
   * Some more suexec fixes:
     - Fix race condition when changing directories.
     - Accept only /var/www/*, and not /var/www*. The same for public_html/*
       instead of public_html* (CVE-2007-1742).
     - Raise the minimum userid that suexec may change to from 100 to 1000.
   * Enable mod_deflate in new installs.
   * Include config.nice in apache2-src. This hopefully allows apache2-mpm-itk
     to drop the build-dependency on apache2-prefork-dev.
   * Mention environment variables in apache2 and apache2ctl man pages and point
     to README.Debian. (Closes: #475150)
   * Drop unneeded build-dep on libtool.
   * Drop obsolete apache2-mpm-perchild package (closes: #477522).
   * Don't fail in postinst if there is a dangling symlink /var/www/index.html.
   * Fix typo in bug number in 2.2.8-3 changelog entry.
   * Use dh_lintian in debian/rules.
Files: 
 38d636773cd889e1aa80e0fef715eb95 1359 web optional apache2_2.2.9-1ubuntu1.dsc
 80d3754fc278338033296f0d41ef2c04 6396996 web optional apache2_2.2.9.orig.tar.gz
 fe07d54a6c3d50fa02aa3f0a02724ae4 121524 web optional apache2_2.2.9-1ubuntu1.diff.gz
Original-Maintainer: Debian Apache Maintainers <debian-apache at lists.debian.org>

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)

iD8DBQFIVlvRIHZ33voUATsRAuA7AKCCx1+FB81WLNLM8E5/fZ9NizYduQCeOhw2
aLKZu69Lw2nv8lZdv2oBmo8=
=TlmA
-----END PGP SIGNATURE-----





More information about the Intrepid-changes mailing list