Hello community, here is the log from the commit of package apache2 for openSUSE:Factory checked in at 2019-08-24 18:43:03 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Comparing /work/SRC/openSUSE:Factory/apache2 (Old) and /work/SRC/openSUSE:Factory/.apache2.new.7948 (New) ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "apache2" Sat Aug 24 18:43:03 2019 rev:158 rq:724999 version:2.4.41 Changes: -------- --- /work/SRC/openSUSE:Factory/apache2/apache2.changes 2019-07-08 15:01:46.518602624 +0200 +++ /work/SRC/openSUSE:Factory/.apache2.new.7948/apache2.changes 2019-08-24 18:43:04.805776548 +0200 @@ -1,0 +2,16 @@ +Thu Aug 15 09:05:22 UTC 2019 - Michael Ströder <[email protected]> + +- version update to 2.4.41 with security fixes: + * low: Limited cross-site scripting in mod_proxy + error page (CVE-2019-10092) + * low: mod_rewrite potential open redirect (CVE-2019-10098) + * moderate: mod_http2, read-after-free in h2 + connection shutdown (CVE-2019-10082) + * moderate: mod_http2, memory corruption on + early pushes (CVE-2019-10081) + * moderate: mod_http2, DoS attack by exhausting + h2 workers. (CVE-2019-9517) + * moderate: mod_remoteip: Stack buffer overflow and + NULL pointer dereference (CVE-2019-10097) + +------------------------------------------------------------------- Old: ---- httpd-2.4.39.tar.bz2 httpd-2.4.39.tar.bz2.asc New: ---- httpd-2.4.41.tar.bz2 httpd-2.4.41.tar.bz2.asc ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Other differences: ------------------ ++++++ apache2.spec ++++++ --- /var/tmp/diff_new_pack.MTNKtj/_old 2019-08-24 18:43:07.677776272 +0200 +++ /var/tmp/diff_new_pack.MTNKtj/_new 2019-08-24 18:43:07.681776272 +0200 @@ -65,7 +65,7 @@ %define build_http2 0 %endif Name: apache2 -Version: 2.4.39 +Version: 2.4.41 Release: 0 Summary: The Apache Web Server Version 2.4 License: Apache-2.0 ++++++ httpd-2.4.39.tar.bz2 -> httpd-2.4.41.tar.bz2 ++++++ /work/SRC/openSUSE:Factory/apache2/httpd-2.4.39.tar.bz2 /work/SRC/openSUSE:Factory/.apache2.new.7948/httpd-2.4.41.tar.bz2 differ: char 11, line 1
