apache2 2.2.4-3ubuntu0.1 source package in Ubuntu
Changelog
apache2 (2.2.4-3ubuntu0.1) gutsy-security; urgency=low * SECURITY UPDATE: denial of service (application crash) when using mod_proxy in threaded MPM via crafted date headers. * debian/patches/100_CVE-2007-3847.dpatch: fix proxy_util.c to use apr_date_parse_http() and apr_rfc822_date() * SECURITY UPDATE: cross-site scripting vulnerability in mod_autoindex.c when charset not defined * debian/patches/101_CVE-2007-4465.dpatch: fix mod_autoindex.c to properly check for and use charset * SECURITY UPDATE: cross-site scripting vulnerability in mod_imagemap * debian/patches/102_CVE-2007-5000.dpatch: fix for mod_imagemap.c to use ap_escape_html() * SECURITY UPDATE: cross-site scripting vulnerability in mod_status when server-status is enabled * debian/patches/103_CVE-2007-6388.dpatch: fix for mod_status.c to properly setup table * SECURITY UPDATE: cross-site scripting vulnerability in mod_proxy_balancer * debian/patches/104_CVE-2007-6421.dpatch: fix for mod_proxy_balancer.c to use ap_escape_html() * SECURITY UPDATE: denial of service (application crash) in mod_proxy_balancer when MPM is used * debian/patches/105_CVE-2007-6422.dpatch: fix for /mod_proxy_balancer.c to check bsel is non-NULL * SECURITY UPDATE: cross-site scripting vulnerability in mod_proxy_ftp when charset is not defined * debian/patches/106_CVE-2008-0005.dpatch: fix for mod_proxy_ftp.c to define a charset * References CVE-2007-3847 CVE-2007-4465 CVE-2007-5000 CVE-2007-6388 CVE-2007-6421 CVE-2007-6422 CVE-2008-0005 -- Jamie Strandboge <email address hidden> Tue, 22 Jan 2008 18:28:27 +0000
Upload details
- Uploaded by:
- Jamie Strandboge
- Uploaded to:
- Gutsy
- Original maintainer:
- Debian Apache Maintainers
- Architectures:
- any
- Section:
- web
- Urgency:
- Low Urgency
See full publishing history Publishing
Series | Published | Component | Section |
---|
Downloads
File | Size | SHA-256 Checksum |
---|---|---|
apache2_2.2.4.orig.tar.gz | 6.1 MiB | daca1379b456e0139cd15ef90c876ed92638cd8620799f011d361065761da97a |
apache2_2.2.4-3ubuntu0.1.diff.gz | 118.8 KiB | 5efb5fa0ff60c50ab40d5e8d335380ad1a0e7ca000ecfc1dc1a72f2eb1db74b2 |
apache2_2.2.4-3ubuntu0.1.dsc | 1.2 KiB | ae6e739133060bd17c130f7b9e37003f40a74bb1ca311340e99b9366a74a1cb1 |
Binary packages built by this source
- apache2: No summary available for apache2 in ubuntu gutsy.
No description available for apache2 in ubuntu gutsy.
- apache2-doc: No summary available for apache2-doc in ubuntu gutsy.
No description available for apache2-doc in ubuntu gutsy.
- apache2-mpm-event: No summary available for apache2-mpm-event in ubuntu gutsy.
No description available for apache2-mpm-event in ubuntu gutsy.
- apache2-mpm-perchild: No summary available for apache2-mpm-perchild in ubuntu gutsy.
No description available for apache2-
mpm-perchild in ubuntu gutsy.
- apache2-mpm-prefork: No summary available for apache2-mpm-prefork in ubuntu gutsy.
No description available for apache2-mpm-prefork in ubuntu gutsy.
- apache2-mpm-worker: No summary available for apache2-mpm-worker in ubuntu gutsy.
No description available for apache2-mpm-worker in ubuntu gutsy.
- apache2-prefork-dev: No summary available for apache2-prefork-dev in ubuntu gutsy.
No description available for apache2-prefork-dev in ubuntu gutsy.
- apache2-src: No summary available for apache2-src in ubuntu gutsy.
No description available for apache2-src in ubuntu gutsy.
- apache2-threaded-dev: No summary available for apache2-threaded-dev in ubuntu gutsy.
No description available for apache2-
threaded- dev in ubuntu gutsy.
- apache2-utils: No summary available for apache2-utils in ubuntu gutsy.
No description available for apache2-utils in ubuntu gutsy.
- apache2.2-common: No summary available for apache2.2-common in ubuntu gutsy.
No description available for apache2.2-common in ubuntu gutsy.