[ubuntu/lucid-security] apr, apr (delayed) 1.3.8-1ubuntu0.3 (Accepted)

Ubuntu Installer archive at ubuntu.com
Tue May 24 19:03:34 UTC 2011


apr (1.3.8-1ubuntu0.3) lucid-security; urgency=low

  * SECURITY UPDATE: denial of service in apr_fnmatch exploitable via
    apache's mod_index
    - debian/patches/028_fnmatch_CVE-2011-0419.dpatch: rewrite
      apr_fnmatch to have a better time bounds on execution.
    - CVE-2011-0419
    - debian/patches/029_fnmatch_CVE-2011-1928.dpatch: fix possible
      DoS introduced by patch for CVE-2011-0419.
    - CVE-2011-1928
  * debian/patches/030_thumb2.dpatch; backport disabling process shared
    mutexes on arm to fix build hang (LP: #599874)

Date: Mon, 23 May 2011 12:20:09 -0700
Changed-By: Steve Beattie <sbeattie at ubuntu.com>
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
https://launchpad.net/ubuntu/lucid/+source/apr/1.3.8-1ubuntu0.3
-------------- next part --------------
Format: 1.8
Date: Mon, 23 May 2011 12:20:09 -0700
Source: apr
Binary: libapr1 libapr1-dev libapr1-dbg
Architecture: source
Version: 1.3.8-1ubuntu0.3
Distribution: lucid-security
Urgency: low
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
Changed-By: Steve Beattie <sbeattie at ubuntu.com>
Description: 
 libapr1    - The Apache Portable Runtime Library
 libapr1-dbg - The Apache Portable Runtime Library - Debugging Symbols
 libapr1-dev - The Apache Portable Runtime Library - Development Headers
Launchpad-Bugs-Fixed: 599874
Changes: 
 apr (1.3.8-1ubuntu0.3) lucid-security; urgency=low
 .
   * SECURITY UPDATE: denial of service in apr_fnmatch exploitable via
     apache's mod_index
     - debian/patches/028_fnmatch_CVE-2011-0419.dpatch: rewrite
       apr_fnmatch to have a better time bounds on execution.
     - CVE-2011-0419
     - debian/patches/029_fnmatch_CVE-2011-1928.dpatch: fix possible
       DoS introduced by patch for CVE-2011-0419.
     - CVE-2011-1928
   * debian/patches/030_thumb2.dpatch; backport disabling process shared
     mutexes on arm to fix build hang (LP: #599874)
Checksums-Sha1: 
 4b1aeccbfe20950b69d7b19bf652c8cf57f39b06 2119 apr_1.3.8-1ubuntu0.3.dsc
 7ed1b93b0c3ead2049d29a124a7b9534de50b22a 27199 apr_1.3.8-1ubuntu0.3.diff.gz
Checksums-Sha256: 
 31ac3d3eb1be39b5724f7273c21452a4caee211cb6d8656b187a5efa1f89fb7a 2119 apr_1.3.8-1ubuntu0.3.dsc
 e893ce80588cd7223a40ca50879e35af028153469db0db63cd094fb3260134e4 27199 apr_1.3.8-1ubuntu0.3.diff.gz
Files: 
 6553c2d9cfc60fce1da81134492ab23f 2119 libs optional apr_1.3.8-1ubuntu0.3.dsc
 b4501e2acb5fb7a51ccbb986cff7dc34 27199 libs optional apr_1.3.8-1ubuntu0.3.diff.gz
Original-Maintainer: Debian Apache Maintainers <debian-apache at lists.debian.org>


More information about the Lucid-changes mailing list