[Bug 506862] [NEW] Please merge apache2 2.2.14-5(main) from debian squeeze(main)

Bhavani Shankar right2bhavi at gmail.com
Wed Jan 13 09:07:10 GMT 2010


Public bug reported:

Binary package hint: apache2

Debian Changelog:

 apache2  (2.2.14-5) unstable; urgency=low

   * Security: Further mitigation for the TLS renegotation attack
     (CVE-2009-3555): Disable keep-alive if parts of the next request have
     already been received when doing a renegotiation. This defends against
     some request splicing attacks.
   * Print a useful error message if 'apache2ctl status' fails. Add a comment
     to /etc/apache2/envvars on how to change the options for www-browser.
     Closes: #561496, #272069
   * Improve function to detect apache2 pid in init-script (closes: #562583).
   * Add hint README.Debian on how to pass auth info to CGI scripts.
     Closes: #483219
   * Re-introduce objcopy magic to avoid dangling symlinks to the debug info
     in the mpm packages. Closes: #563278
   * Make apxs2 use a2enmod and /etc/apache2/mods-available. Closes: #470178,
     LP: #500703
   * Point to README.backtrace in apache2-dbg's description.
   * Use more debhelper functions to simplify debian/rules.
   * Add misc-depends to various packages to make lintian happy.
   * Change build-dep from libcap2-dev to libcap-dev because of package rename.

 -- Stefan Fritsch <sf at debian.org>  Sat, 02 Jan 2010 22:44:15 +0100

** Affects: apache2 (Ubuntu)
     Importance: Undecided
         Status: Confirmed

-- 
Please merge apache2 2.2.14-5(main) from debian squeeze(main)
https://bugs.launchpad.net/bugs/506862
You received this bug notification because you are a member of Ubuntu
Server Team, which is subscribed to apache2 in ubuntu.



More information about the Ubuntu-server-bugs mailing list