apache2 2.2.9-7ubuntu3.5 source package in Ubuntu

Changelog

apache2 (2.2.9-7ubuntu3.5) intrepid-security; urgency=low

  * SECURITY UPDATE: Reject client-initiated SSL/TLS renegotiations.
    Partial fix for CVE-2009-3555. Configurations requiring renegotiation
    of per-directory/location access controls are still affected until
    OpenSSL is updated.
    - debian/patches/904_CVE-2009-3555.dpatch: disable all client
      renegotiations
    - CVE-2009-3555
  * SECURITY UPDATE: fix NULL pointer dereference in mod_proxy_ftp module
    - debian/patches/905-CVE-2009-3094.dpatch: fix NULL pointer dereference
      in mod_proxy_ftp.c/apr_socket_close() and potential buffer overread
      in EPSV response parser
    - CVE-2009-3094
  * SECURITY UPDATE: fix access control bypass in mod_proxy_ftp when
    configured as a reverse proxy
    - debian/patches/906-CVE-2009-3095.dpatch: adjust proxy_ftp_handler()
      in mod_proxy_ftp.c to fail if the decoded Basic credentials contain
      special characters.
    - CVE-2009-3095
 -- Jamie Strandboge <email address hidden>   Thu, 12 Nov 2009 14:02:27 -0600

Upload details

Uploaded by:
Jamie Strandboge
Uploaded to:
Intrepid
Original maintainer:
Ubuntu Development Team
Architectures:
any
Section:
web
Urgency:
Low Urgency

See full publishing history Publishing

Series Pocket Published Component Section

Downloads

File Size SHA-256 Checksum
apache2_2.2.9.orig.tar.gz 6.1 MiB 74c92f9905a809fb18822f0d98e45712bb17495cefaf2b5315c2ce15840a04a2
apache2_2.2.9-7ubuntu3.5.diff.gz 134.5 KiB 810d601094e616db1ce47cb0d5c4058c6e8c3627b300f49e8db58d6adc8dec21
apache2_2.2.9-7ubuntu3.5.dsc 1.7 KiB 1d48990093cd1c6650c2656fff3cfbd3edb47b22243e6df8f1317aaa4726f542

View changes file

Binary packages built by this source

apache2: No summary available for apache2 in ubuntu intrepid.

No description available for apache2 in ubuntu intrepid.

apache2-doc: No summary available for apache2-doc in ubuntu intrepid.

No description available for apache2-doc in ubuntu intrepid.

apache2-mpm-event: No summary available for apache2-mpm-event in ubuntu intrepid.

No description available for apache2-mpm-event in ubuntu intrepid.

apache2-mpm-prefork: No summary available for apache2-mpm-prefork in ubuntu intrepid.

No description available for apache2-mpm-prefork in ubuntu intrepid.

apache2-mpm-worker: No summary available for apache2-mpm-worker in ubuntu intrepid.

No description available for apache2-mpm-worker in ubuntu intrepid.

apache2-prefork-dev: No summary available for apache2-prefork-dev in ubuntu intrepid.

No description available for apache2-prefork-dev in ubuntu intrepid.

apache2-src: No summary available for apache2-src in ubuntu intrepid.

No description available for apache2-src in ubuntu intrepid.

apache2-suexec: No summary available for apache2-suexec in ubuntu intrepid.

No description available for apache2-suexec in ubuntu intrepid.

apache2-suexec-custom: No summary available for apache2-suexec-custom in ubuntu intrepid.

No description available for apache2-suexec-custom in ubuntu intrepid.

apache2-threaded-dev: No summary available for apache2-threaded-dev in ubuntu intrepid.

No description available for apache2-threaded-dev in ubuntu intrepid.

apache2-utils: No summary available for apache2-utils in ubuntu intrepid.

No description available for apache2-utils in ubuntu intrepid.

apache2.2-common: No summary available for apache2.2-common in ubuntu intrepid.

No description available for apache2.2-common in ubuntu intrepid.