[Bug 872000] Re: /etc/apache2/mods-available/suexec.load has group read

Launchpad Bug Tracker 872000 at bugs.launchpad.net
Mon Oct 17 14:00:11 UTC 2011


This bug was fixed in the package apache2 - 2.2.21-2ubuntu1

---------------
apache2 (2.2.21-2ubuntu1) precise; urgency=low

  * Merge from debian unstable.  Remaining changes:
    - debian/{control, rules}: Enable PIE hardening.
    - debian/{control, rules, apache2.2-common.ufw.profile}: Add ufw profiles.
    - debian/control: Add bzr tag and point it to our tree
    - debian/apache2.py, debian/apache2.2-common.install: Add apport hook.
    - debian/control, debian/ask-for-passphrase, debian/config-dir/mods-available/ssl.conf:
      Plymouth aware passphrase dialog program ask-for-passphrase.

apache2 (2.2.21-2) unstable; urgency=high

  * Fix CVE-2011-3368: Prevent unintended pattern expansion in some
    reverse proxy configurations by strictly validating the request-URI.
  * Correctly set permissions of suexec.load even if umask is 0002 during
    build. LP: #872000

apache2 (2.2.21-1) unstable; urgency=low

  * New upstream release.
    - Fixes CVE-2011-3348: Possible denial of service in mod_proxy_ajp
      if combined with mod_proxy_balancer
 -- Chuck Short <zulcss at ubuntu.com>   Fri, 14 Oct 2011 16:01:29 +0000

** Changed in: apache2 (Ubuntu)
       Status: New => Fix Released

** CVE added: http://www.cve.mitre.org/cgi-
bin/cvename.cgi?name=2011-3348

** CVE added: http://www.cve.mitre.org/cgi-
bin/cvename.cgi?name=2011-3368

-- 
You received this bug notification because you are a member of Ubuntu
Server Team, which is subscribed to apache2 in Ubuntu.
https://bugs.launchpad.net/bugs/872000

Title:
  /etc/apache2/mods-available/suexec.load has group read

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/apache2/+bug/872000/+subscriptions



More information about the Ubuntu-server-bugs mailing list