apache2 2.2.22-4 source package in Debian

Changelog

apache2 (2.2.22-4) unstable; urgency=high


  * CVE-2012-0216: Remove "Alias /doc /usr/share/doc" from the default virtual
    hosts' config files.
    If scripting modules like mod_php or mod_rivet are enabled on systems
    where either 1) some frontend server forwards connections to an apache2
    backend server on the localhost address, or 2) the machine running
    apache2 is also used for web browsing, this could allow a remote
    attacker to execute example scripts stored under /usr/share/doc.
    Depending on the installed packages, this could lead to issues like cross
    site scripting, code execution, or leakage of sensitive data.

 -- Stefan Fritsch <email address hidden>  Sun, 15 Apr 2012 23:41:43 +0200

Upload details

Uploaded by:
Debian Apache Maintainers
Uploaded to:
Sid
Original maintainer:
Debian Apache Maintainers
Architectures:
any all
Section:
httpd
Urgency:
Very Urgent

See full publishing history Publishing

Series Pocket Published Component Section

Builds

Downloads

File Size SHA-256 Checksum
apache2_2.2.22-4.dsc 2.2 KiB d0645b6fbd93f2cda656c2bee3c145d9a452025eaa493f8c6e210a2bec1b184b
apache2_2.2.22.orig.tar.gz 6.9 MiB 74c1ffffefe1a502339b004ad6488fbd858eb425a05968cd67c05695dbc0fe7c
apache2_2.2.22-4.debian.tar.gz 204.8 KiB 44f75f56885ea53d2101e98c7332b26d8be0f8563884977a9e7d3bad46ce01b4

No changes file available.

Binary packages built by this source