Bug#1068412: apache2: CVE-2024-27316 CVE-2024-24795 CVE-2023-38709

2024-04-05 Thread Yadd
On 4/5/24 15:58, Moritz Muehlenhoff wrote: On Fri, Apr 05, 2024 at 08:16:43AM +0400, Yadd wrote: On 4/4/24 22:51, Moritz Mühlenhoff wrote: Source: apache2 X-Debbugs-CC: t...@security.debian.org Severity: grave Tags: security Hi, The following vulnerabilities were published for apache2. CVE

Re: Need Some Help

2024-03-07 Thread Yadd
contain important CVE fixes, only minor/medium. So it will be updated during a Debian point release and not in security branch. Cheers, Yadd

Bug#1018718: marked as pending in apache2

2023-04-03 Thread Yadd
saw in this issue that you were a little frustrated by the lack of responsiveness in apache2 maintenance. But apache2 is "RFH" and I'm not C expert neither apache user so I try to do my best until someone more qualified takes over. Best regards, Yadd

Bug#1033770: bullseye-pu: package apache2/2.4.56-1~deb11u2

2023-03-31 Thread Yadd
against the package in (old)stable [X] the issue is verified as fixed in unstable [ Changes ] Drop apache2-doc.postinst [ Other ] Fixed in testing/Bookworm in version 2.4.54-3. Cheers, Yadd diff --git a/debian/NEWS b/debian/NEWS new file mode 100644 index ..c048ae45 --- /dev/null +++ b

Bug#1032476: apache2: CVE-2023-25690 CVE-2023-27522

2023-03-08 Thread Yadd
On 3/8/23 22:39, Moritz Muehlenhoff wrote: On Wed, Mar 08, 2023 at 07:09:20AM +0400, Yadd wrote: On 3/7/23 23:46, Salvatore Bonaccorso wrote: Source: apache2 Version: 2.4.55-1 Severity: grave Tags: security upstream X-Debbugs-Cc: car...@debian.org, Debian Security Team Hi, The following

Bug#967010: apache2: Did not reporoduce

2022-11-08 Thread Yadd
Le Mardi, Novembre 08, 2022 16:01 CET, Shai Berger a écrit: > Package: apache2 > Followup-For: Bug #967010 > > Dear Maintainer, > > I just installed Apache2 and did not encounter the problem > as reported in this bug. > > It is an old bug, and for some reason full of spam. > > Please close and/or

Bug#1014056: apache2: /var/run/apache2 permissions too narrow for cgid

2022-07-05 Thread Yadd
On 29/06/2022 16:51, MK wrote: Package: apache2 Version: 2.4.53-1~deb11u1 Severity: minor Dear Maintainer, *** Reporter, please consider answering these questions, where appropriate *** Enabling cgid in apache2 (with a2enmod cgid) results in an error when using  mpm_event:    

Bug#1012513: apache2: CVE-2022-31813 CVE-2022-26377 CVE-2022-28614 CVE-2022-28615 CVE-2022-29404 CVE-2022-30522 CVE-2022-30556

2022-06-08 Thread Yadd
Hi, those CVEs are tagged low/moderate by upstream, why did you tag this bug as grave ? Cheers, Yadd Le Mercredi, Juin 08, 2022 17:49 CEST, Moritz Mühlenhoff a écrit: > Source: apache2 > X-Debbugs-CC: t...@security.debian.org > Severity: grave > Tags: security > > Hi,

Re: Dependancy broken on apache2-dev with libldap-2.4-2 (libaprutil1-dev)

2022-05-30 Thread Yadd
1 - problem is in openldap only (fixed dependency between 2 openldap packages) 2 - this will be automatically fixed when package will be published: libldap-2.4 will be updated in the same time than libldap2-dev Cheers, Yadd > I don't know who must be warn so i warn on > debian-apache@

Bug#1000114: apache2: depends on obsolete pcre3 library

2021-12-28 Thread Yadd
On 28/12/2021 19:40, Yadd wrote: On 28/12/2021 08:25, Sebastiaan Couwenberg wrote: On Sun, 21 Nov 2021 17:17:32 + Matthew Vernon wrote: On 19/11/2021 21:46, Yadd wrote: > Sadly pcre2 does not provide /usr/bin/pcre-config, I'm unable to do this > change Well, there is pcre2-

Bug#1000114: apache2: depends on obsolete pcre3 library

2021-12-28 Thread Yadd
On 28/12/2021 08:25, Sebastiaan Couwenberg wrote: On Sun, 21 Nov 2021 17:17:32 + Matthew Vernon wrote: On 19/11/2021 21:46, Yadd wrote: > Sadly pcre2 does not provide /usr/bin/pcre-config, I'm unable to do this > change Well, there is pcre2-config, but that's a little beside the

Re: Fix for CVE-2021-40438 in bullseye missing?

2021-11-26 Thread Yadd
h. > Holger Hi, Apache2 in Bullseye follows upstream changes, so no need to produce a patch. See https://security-tracker.debian.org/tracker/CVE-2021-40438 Cheers, Yadd

Bug#1000627: apache2: missing dependency setting

2021-11-25 Thread Yadd
Le 26/11/2021 à 03:03, westlake a écrit : > Package: apache2 > Version: 2.4.48-3.1+deb11u1 > Severity: important > > apache2 can fail to start if the user defines a specific interface. > > the workaround meanwhile is to add "network-online.target" to the > systemd unit. > > The issue noticeably

Bug#1000114: apache2: depends on obsolete pcre3 library

2021-11-19 Thread Yadd
Control: tags -1 + moreinfo Le 18/11/2021 à 12:49, Matthew Vernon a écrit : > Source: apache2 > Severity: important > User: matthew-pcre...@debian.org > Usertags: obsolete-pcre3 > > Dear maintainer, > > Your package still depends on the old, obsolete PCRE3[0] libraries > (i.e. libpcre3-dev).

Bug#868861: Mitigation

2021-09-22 Thread Yadd
ln -s with @ instead of -)! > 1: After every apache upgrade the /usr/sbin/apache2ctl mod needs to be > performed again! > > On Tue, 6 Jul 2021 09:47:09 +0200 Michiel Hazelhof > wrote: > >> Made two small tweaks to hopefully mitigate this behaviour: > ... Do not follow this post anymore! Hi, could you push a merge request ? Cheers, Yadd

Bug#967010: apache2: last debian 10.4 , last apache avail from repo hangs on install (and start phase)

2021-09-22 Thread Yadd
Control: tags -1 + moreinfo Hi, I'm unable to reproduce this issue, package apache 2 contains default-ssl.conf and autopkgtest succeeded to start apache2.

Bug#990853: Problem with Directory directive

2021-07-09 Thread Yadd
Le 09/07/2021 à 13:12, Stadtsholte, Ingo a écrit : > Package: apache2 > > Version: 2.4.38-3+deb10u4 > >   > > After minor updating my Apache Installation to the above Version, > AuthType in Directory directive only affects to DirectoryIndex, not to > all other files/subdirectories > >   > >

Bug#990580: apache2: [regression] daily cron mails from logrotate: Reloading Apache httpd web server: apache2., caused by #979813

2021-07-08 Thread Yadd
Le 09/07/2021 à 05:04, Thorsten Glaser a écrit : > Thanks Adam for the analysis! > >> To stop the mails from logrotate, could you please change back: >> - invoke-rc.d apache2 reload >> + invoke-rc.d apache2 reload > /dev/null 2>&1 >> >> otherwise, people running Bullseye will

Bug#989562: apache2: CVE-2021-31618: NULL pointer dereference on specially crafted HTTP/2 request

2021-06-08 Thread Yadd
Le 08/06/2021 à 10:51, Yadd a écrit : > Le 08/06/2021 à 08:25, Yadd a écrit : >> Le 08/06/2021 à 07:58, Yadd a écrit : >>> Le 07/06/2021 à 17:34, Salvatore Bonaccorso a écrit : >>>> Source: apache2 >>>> Version: 2.4.47-1 >>>> Severity: grave

Bug#989562: apache2: CVE-2021-31618: NULL pointer dereference on specially crafted HTTP/2 request

2021-06-08 Thread Yadd
d.apache.org/security/vulnerabilities_24.html#CVE-2021-31618 > > Please adjust the affected versions in the BTS as needed. > > Regards, > Salvatore Hi all, I can't import the whole patch for Bullseye since it is written for 2.4.47. I think the best solution is to import the w

Re: CVE-2010-1452: apache2 fix version issue

2021-05-14 Thread Yadd
ce (updated in real time), it uses information from cve.mitre.org: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1452 This issue is fixed in 2.2.16-1. 2.2.* versions are so old that some information are missing, but 2.2.19-3 wasn't a Debian version (see http://snapshot.debian.org/package/apache2/). So there is probably a typo in criterion. Cheers, Yadd

Bug#988029: apache2: Non-unique IDs being generated by mod_unique_id - Fix available

2021-05-03 Thread Yadd
ckports for Bullseye * maybe Debian backports for Buster (buster-backports-sloppy) Cheers, Yadd

Bug#980137: apache2: multi-instance support, APACHE_CONFDIR and ServerRoot

2021-04-12 Thread Yadd
would also have the benefit that people could use APACHE_CONFDIR > in their configs if they want to make paths relative to it, where the > directive doens't use non-absolute paths per default relative to > ServerRoot. Hi, could you propose a patch? Cheers, Yadd