apache2 2.2.4-3ubuntu0.2 source package in Ubuntu

Changelog

apache2 (2.2.4-3ubuntu0.2) gutsy-security; urgency=low

  [ Emanuele Gentili ]
  * SECURITY UPDATE:
   + debian/patches/111_CVE-2008-2364.dpatch (LP: #239894)
    - The ap_proxy_http_process_response function in mod_proxy_http.c
      in the mod_proxy module does not limit the number of forwarded
      interim responses, which allows remote HTTP servers to cause a
      denial of service (memory consumption) via a large number of
      interim responses.
   + References
    - http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-2364

  [ Marc Deslauriers ]
  * SECURITY UPDATE: Cross-site scripting (XSS) vulnerability in "413 Request
    Entity Too Large" error message
    - debian/patches/107_CVE-2007-6203.dpatch: properly escape some error
      messages in modules/http/http_protocol.c.
    - CVE-2007-6203
  * SECURITY UPDATE: Cross-site request forgery (CSRF) in balancer-manager in
    mod_proxy_balancer
    - debian/patches/108_CVE-2007-6420.dpatch: generate and validate a nonce in
      modules/proxy/mod_proxy_balancer.c.
    - CVE-2007-6420
  * SECURITY UPDATE: Denial of service via memory leak in the zlib_stateful_init
    function (LP: #224945)
    - debian/patches/109_CVE-2008-1678.dpatch: don't call
      CRYPTO_cleanup_all_ex_data in modules/ssl/mod_ssl.c.
    - CVE-2008-1678
  * SECURITY UPDATE: Cross-site scripting (XSS) vulnerability via UTF-7 encoded
    URLs
    - debian/patches/110_CVE-2008-2168.dpatch: specify a default charset in
      modules/dav/main/mod_dav.c, modules/generators/mod_info.c and
      modules/proxy/mod_proxy_balancer.c.
    - CVE-2008-2168
  * SECURITY UPDATE: Denial of service via large number of interim responses in
    mod_proxy module (LP: #239894)
    - debian/patches/111_CVE-2008-2364.dpatch: updated patch to newer version.
    - CVE-2008-2364
  * SECURITY UPDATE: Cross-site scripting (XSS) vulnerability in the
    mod_proxy_ftp module
    - debian/patches/112_CVE-2008-2939.dpatch: escape the html
      contained in the wildcard value in modules/proxy/mod_proxy_ftp.c.
    - CVE-2008-2939

 -- Marc Deslauriers <email address hidden>   Thu, 05 Mar 2009 15:54:32 -0500

Upload details

Uploaded by:
Marc Deslauriers
Uploaded to:
Gutsy
Original maintainer:
Ubuntu Development Team
Architectures:
any
Section:
web
Urgency:
Low Urgency

See full publishing history Publishing

Series Pocket Published Component Section

Downloads

File Size SHA-256 Checksum
apache2_2.2.4.orig.tar.gz 6.1 MiB daca1379b456e0139cd15ef90c876ed92638cd8620799f011d361065761da97a
apache2_2.2.4-3ubuntu0.2.diff.gz 122.1 KiB fc5799b44804759c2b5026196d58943ede700eb3fb8fd01886ed0eb2a22fd8f9
apache2_2.2.4-3ubuntu0.2.dsc 1.3 KiB 5dc0bd021ad60b1d86d5e89c48d629912f56d34ace685753f2ec489d62886ecf

View changes file

Binary packages built by this source

apache2: No summary available for apache2 in ubuntu gutsy.

No description available for apache2 in ubuntu gutsy.

apache2-doc: No summary available for apache2-doc in ubuntu gutsy.

No description available for apache2-doc in ubuntu gutsy.

apache2-mpm-event: No summary available for apache2-mpm-event in ubuntu gutsy.

No description available for apache2-mpm-event in ubuntu gutsy.

apache2-mpm-perchild: No summary available for apache2-mpm-perchild in ubuntu gutsy.

No description available for apache2-mpm-perchild in ubuntu gutsy.

apache2-mpm-prefork: No summary available for apache2-mpm-prefork in ubuntu gutsy.

No description available for apache2-mpm-prefork in ubuntu gutsy.

apache2-mpm-worker: No summary available for apache2-mpm-worker in ubuntu gutsy.

No description available for apache2-mpm-worker in ubuntu gutsy.

apache2-prefork-dev: No summary available for apache2-prefork-dev in ubuntu gutsy.

No description available for apache2-prefork-dev in ubuntu gutsy.

apache2-src: No summary available for apache2-src in ubuntu gutsy.

No description available for apache2-src in ubuntu gutsy.

apache2-threaded-dev: No summary available for apache2-threaded-dev in ubuntu gutsy.

No description available for apache2-threaded-dev in ubuntu gutsy.

apache2-utils: No summary available for apache2-utils in ubuntu gutsy.

No description available for apache2-utils in ubuntu gutsy.

apache2.2-common: No summary available for apache2.2-common in ubuntu gutsy.

No description available for apache2.2-common in ubuntu gutsy.