Commit Graph

  • d05b619e34 Accepting request 1325323 from Apache factory Ana Guerrero 2026-01-06 16:41:57 +00:00
  • 38a6772ea1 Accepting request 1325322 from home:mschreiner:branches:Apache Martin Schreiner 2026-01-04 21:20:48 +00:00
  • 356bfd0a6f Fix 4 bugs/CVEs. slfo-main slfo-1.2 Martin Jungblut Schreiner 2025-12-16 21:14:50 +01:00
  • 8c09fbb5b1 Accepting request 1321637 from Apache Ana Guerrero 2025-12-10 14:29:37 +00:00
  • 180093ea5d Accepting request 1321598 from home:adkorte:branches:Apache Martin Schreiner 2025-12-08 20:36:56 +00:00
  • c42e1ec449 Accepting request 1317188 from Apache Ana Guerrero 2025-11-13 16:25:57 +00:00
  • 7f28caabda - Make /usr/sbin/httpd a dedicated script again, this fixes building modules while still making Apache free of update-alternatives, relying entirely on sysconfig to dispatch the appropriate MPM. Martin Schreiner 2025-11-04 20:43:03 +00:00
  • 369b30c142 Accepting request 1314641 from home:dimstar:Factory Martin Schreiner 2025-11-04 18:42:23 +00:00
  • bafe23b2d9 Accepting request 1314067 from Apache Ana Guerrero 2025-10-30 16:09:35 +00:00
  • d069dfd19f - Re-introduce /usr/sbin/httpd - Links to start_apache2, which now contains the logic to dispatch to the appropriate MPM respecting sysconfig's decision. Martin Schreiner 2025-10-21 11:32:54 +00:00
  • 2cd34b5fd0 Accepting request 1311136 from home:mschreiner:branches:Apache Martin Schreiner 2025-10-13 20:58:48 +00:00
  • 0beaa8512c Accepting request 1308207 from Apache Ana Guerrero 2025-10-02 17:19:19 +00:00
  • 6c4ed74764 Accepting request 1306753 from home:pgajdos:libxml2 Martin Schreiner 2025-09-23 14:02:23 +00:00
  • 1aaedef3aa Sync changes to SLFO-1.2 branch Adrian Schröter 2025-08-20 09:03:01 +02:00
  • f2841a47a6 Accepting request 1295323 from Apache Dominique Leuenberger 2025-07-25 15:03:56 +00:00
  • 5e2a6b06f3 Accepting request 1295323 from Apache Dominique Leuenberger 2025-07-25 15:03:56 +00:00
  • fe73fa2fe5 Accepting request 1295320 from home:pgajdos Kristyna Streitova 2025-07-23 12:56:49 +00:00
  • 1177533e53 - version update to 2.4.65 *) SECURITY: CVE-2025-54090: Apache HTTP Server: 'RewriteCond expr' always evaluates to true in 2.4.64 (cve.mitre.org) A bug in Apache HTTP Server 2.4.64 results in all "RewriteCond expr ..." tests evaluating as "true". Users are recommended to upgrade to version 2.4.65, which fixes the issue. Kristyna Streitova 2025-07-23 12:56:49 +00:00
  • e6d41f1323 Accepting request 1294249 from Apache Ana Guerrero 2025-07-20 13:28:01 +00:00
  • 3a0ed9cf2d Accepting request 1294249 from Apache Ana Guerrero 2025-07-20 13:28:01 +00:00
  • 4300bba466 Accepting request 1294247 from home:mschreiner:branches:Apache Martin Schreiner 2025-07-18 03:49:15 +00:00
  • e4531db3a3 * Refresh patches: - apache-test-application-xml-type.patch - apache-test-turn-off-variables-in-ssl-var-lookup.patch - apache2-HttpContentLengthHeadZero-HttpExpectStrict.patch - apache2-LimitRequestFieldSize-limits-headers.patch * Update to 2.4.64. * CVE-2025-53020: Apache HTTP Server: HTTP/2 DoS by Memory Increase * CVE-2025-49812: Apache HTTP Server: mod_ssl TLS upgrade attack * CVE-2025-49630: Apache HTTP Server: mod_proxy_http2 denial of service * CVE-2025-23048: Apache HTTP Server: mod_ssl access control bypass with session resumption * CVE-2024-47252: Apache HTTP Server: mod_ssl error log variable escaping * CVE-2024-43394: Apache HTTP Server: SSRF on Windows due to UNC paths * CVE-2024-43204: Apache HTTP Server: SSRF with mod_headers setting Content-Type header * CVE-2024-42516: Apache HTTP Server: HTTP response splitting * mod_proxy_ajp: Use iobuffersize set on worker level for the IO buffer size. * mod_ssl: Drop $SSLKEYLOGFILE handling internally for OpenSSL 3.5 builds which enable it in libssl natively. * mod_asis: Fix the log level of the message AH01236. * mod_session_dbd: ensure format used with SessionDBDCookieName and SessionDBDCookieName2 are correct. * mod_headers: 'RequestHeader set|edit|edit_r Content-Type X' could inadvertently modify the Content-Type _response_ header. Applies to Content-Type only and likely to only affect static file responses. * mod_ssl: Remove warning over potential uninitialised value for ssl protocol prior to protocol selection. * mod_proxy: Reuse ProxyRemote connections when possible, like prior to 2.4.59. * mod_systemd: Add systemd socket activation support. * mod_systemd: Log the SELinux context at startup if available and Martin Schreiner 2025-07-18 03:49:15 +00:00
  • a354411418 Accepting request 1251625 from Apache Ana Guerrero 2025-03-11 19:43:41 +00:00
  • 26adddb99d Accepting request 1251625 from Apache Ana Guerrero 2025-03-11 19:43:41 +00:00
  • d2fe688ea4 Accepting request 1251624 from home:mschreiner:branches:Apache Martin Schreiner 2025-03-10 05:09:18 +00:00
  • 285b0fe9bf - Update to 2.4.63: * mod_dav: Update redirect-carefully example BrowserMatch config to match more recent client versions. * mod_cache_socache: Fix possible crash on error path. * mod_ssl: Fail cleanly at startup if OpenSSL initialization fails. * mod_md: update to version 2.4.31 - Improved error reporting when waiting for ACME server to verify domains or finalizing the order fails, e.g. times out. - Increasing the timeouts to wait for ACME server to verify domain names and issue the certificate from 30 seconds to 5 minutes. - Change a log level from error to debug when Stapling is enabled but a certificate carries no OCSP responder URL. * mod_proxy_balancer: Fix the handling of the stickysession configuration parameter by the balancer manager. * Add the ldap-search option to mod_authnz_ldap, allowing authorization to be based on arbitrary expressions that do not include the username. Make sure that when ldap searches are too long, we explicitly log the error. * mod_proxy: Honor parameters of ProxyPassMatch workers with substitution in the host name or port. * mod_log_config: Fix merging for the "LogFormat" directive. * mod_lua: Make r.ap_auth_type writable. * mod_md: update to version 2.4.29 - Fixed HTTP-01 challenges to not carry a final newline, as some ACME server fail to ignore it. - Fixed missing label+newline in server-status plain text output when MDStapling is enabled. * mod_ssl: Restore support for loading PKCS#11 keys via ENGINE without "SSLCryptoDevice" configured. * mod_authnz_ldap: Fix possible memory corruption if the Martin Schreiner 2025-03-10 05:09:18 +00:00
  • 267a22e544 Accepting request 1251234 from Apache Dominique Leuenberger 2025-03-08 16:51:31 +00:00
  • 4f979fbc59 Accepting request 1251234 from Apache Dominique Leuenberger 2025-03-08 16:51:31 +00:00
  • 6010246e4c Accepting request 1180997 from home:crameleon:branches:Apache Martin Schreiner 2025-03-07 15:18:26 +00:00
  • 0299bc148b - Require main apache2 package in MPM packages (boo#1226379) Martin Schreiner 2025-03-07 15:18:26 +00:00
  • 73364b9416 Accepting request 1237712 from Apache Ana Guerrero 2025-01-15 16:42:06 +00:00
  • 2bde2c8dc7 Accepting request 1237712 from Apache Ana Guerrero 2025-01-15 16:42:06 +00:00
  • 6e2193fc73 Accepting request 1237660 from home:dimstar:Factory Petr Gajdos 2025-01-14 10:27:27 +00:00
  • 7e57f4d1e3 - Fix builds of test package with RPM 4.20: + noarch packages cannot rely on libdir, which is an arch-dependent variable. Rely on apxs -q libdir to extract the correct information instead. Petr Gajdos 2025-01-14 10:27:27 +00:00
  • eda135f780 Accepting request 1221591 from Apache Ana Guerrero 2024-11-06 15:49:13 +00:00
  • ff8f362dac Accepting request 1221591 from Apache Ana Guerrero 2024-11-06 15:49:13 +00:00
  • 0bdd99d90d Accepting request 1221590 from home:mschreiner:branches:Apache Martin Schreiner 2024-11-05 18:24:44 +00:00
  • e7ac9d37d9 - Update httpd-framework to svn1921782. - Fixes Apache's impact on bsc#1218342. Martin Schreiner 2024-11-05 18:24:44 +00:00
  • 2062e48982 Accepting request 1221258 from home:jengelh:branches:Apache Martin Schreiner 2024-11-05 18:14:23 +00:00
  • 62e3b1fe7e - Explicitly mark start_apache2 as bash-dependent. Martin Schreiner 2024-11-05 18:14:23 +00:00
  • 5f337498c4 Accepting request 1205314 from Apache Ana Guerrero 2024-10-03 15:59:19 +00:00
  • 9695f91e0b Accepting request 1205314 from Apache Ana Guerrero 2024-10-03 15:59:19 +00:00
  • 30a638bdc2 Accepting request 1204794 from home:kukuk:cleanup Martin Schreiner 2024-10-02 19:42:36 +00:00
  • 3684930e1f - Add /srv/www directories to filelist [bsc#1231027] (apache2 will not start since default config uses this directory) Martin Schreiner 2024-10-02 19:42:36 +00:00
  • fc65467d3d Accepting request 1192286 from Apache Dominique Leuenberger 2024-08-08 08:57:11 +00:00
  • 56b3280607 Accepting request 1192286 from Apache Dominique Leuenberger 2024-08-08 08:57:11 +00:00
  • 129fff1b8c Accepting request 1191452 from home:adkorte:branches:Apache David Anes 2024-08-07 12:48:58 +00:00
  • 9ac936a203 - Update to 2.4.62 *) SECURITY: CVE-2024-40898: Apache HTTP Server: SSRF with mod_rewrite in server/vhost context on Windows (cve.mitre.org) [boo#1228098] SSRF in Apache HTTP Server on Windows with mod_rewrite in server/vhost context, allows to potentially leak NTML hashes to a malicious server via SSRF and malicious requests. Users are recommended to upgrade to version 2.4.62 which fixes this issue. Credits: Smi1e (DBAPPSecurity Ltd.) *) SECURITY: CVE-2024-40725: Apache HTTP Server: source code disclosure with handlers configured via AddType (cve.mitre.org) [boo#1228097] A partial fix for CVE-2024-39884 in the core of Apache HTTP Server 2.4.61 ignores some use of the legacy content-type based configuration of handlers. "AddType" and similar configuration, under some circumstances where files are requested indirectly, result in source code disclosure of local content. For example, PHP scripts may be served instead of interpreted. Users are recommended to upgrade to version 2.4.62, which fixes this issue. *) mod_proxy: Fix canonicalisation and FCGI env (PATH_INFO, SCRIPT_NAME) for "balancer:" URLs set via SetHandler, also allowing for "unix:" sockets with BalancerMember(s). PR 69168. [Yann Ylavic] *) mod_proxy: Avoid AH01059 parsing error for SetHandler "unix:" URLs. PR 69160 [Yann Ylavic] *) mod_ssl: Fix crashes in PKCS#11 ENGINE support with OpenSSL 3.2. [Joe Orton] *) mod_ssl: Add support for loading certs/keys from pkcs11: URIs via OpenSSL 3.x providers. [Ingo Franzki <ifranzki linux.ibm.com>] *) mod_ssl: Restore SSL dumping on trace7 loglevel with OpenSSL >= 3.0. [Ruediger Pluem, Yann Ylavic] *) mpm_worker: Fix possible warning (AH00045) about children processes not terminating timely. [Yann Ylavic] David Anes 2024-08-07 12:48:58 +00:00
  • acb851bd41 Accepting request 1186139 from Apache Ana Guerrero 2024-07-09 18:03:17 +00:00
  • 222bf624be Accepting request 1186139 from Apache Ana Guerrero 2024-07-09 18:03:17 +00:00
  • 39f20e4cff Accepting request 1185778 from home:adkorte:branches:Apache David Anes 2024-07-08 10:21:09 +00:00
  • 7a70b52ac1 Accepting request 1185778 from home:adkorte:branches:Apache David Anes 2024-07-08 10:21:09 +00:00
  • 26e8bb1d7a Accepting request 1181737 from Apache Ana Guerrero 2024-06-20 14:46:51 +00:00
  • 5f6583c75b Accepting request 1181737 from Apache Ana Guerrero 2024-06-20 14:46:51 +00:00
  • d9afb9cfb7 Accepting request 1180827 from home:pgajdos David Anes 2024-06-19 11:52:27 +00:00
  • 06c2e29428 - added patches [bsc#1226217] c2fffd29b0 + apache2-issue-444.patch David Anes 2024-06-19 11:52:27 +00:00
  • 5e33742259 Accepting request 1166934 from Apache Ana Guerrero 2024-04-12 15:33:53 +00:00
  • 1c7ff42df1 Accepting request 1166934 from Apache Ana Guerrero 2024-04-12 15:33:53 +00:00
  • ef55205e3e Accepting request 1165100 from home:adkorte:branches:Apache David Anes 2024-04-11 19:35:33 +00:00
  • 7ef8ed17b4 Accepting request 1165100 from home:adkorte:branches:Apache David Anes 2024-04-11 19:35:33 +00:00
  • 271a2160c2 Accepting request 1152028 from Apache Ana Guerrero 2024-02-28 18:44:55 +00:00
  • d93fe72faa Accepting request 1152028 from Apache Ana Guerrero 2024-02-28 18:44:55 +00:00
  • 73ea51886f Accepting request 1147806 from home:dimstar:rpm4.20:a David Anes 2024-02-27 07:42:18 +00:00
  • 7270596621 Accepting request 1147806 from home:dimstar:rpm4.20:a David Anes 2024-02-27 07:42:18 +00:00
  • f5797818b3 Accepting request 1142753 from Apache Ana Guerrero 2024-01-30 17:24:56 +00:00
  • 4ce22f1d2e Accepting request 1142753 from Apache Ana Guerrero 2024-01-30 17:24:56 +00:00
  • e45d401fd5 Accepting request 1142224 from home:dirkmueller:Factory David Anes 2024-01-30 11:32:13 +00:00
  • 539b1e985d Accepting request 1142224 from home:dirkmueller:Factory David Anes 2024-01-30 11:32:13 +00:00
  • 73db9223a4 Accepting request 1118995 from Apache Ana Guerrero 2023-10-22 19:01:19 +00:00
  • 18f945721f Accepting request 1118995 from Apache Ana Guerrero 2023-10-22 19:01:19 +00:00
  • 975c19666b Accepting request 1118994 from home:david.anes:branches:Apache David Anes 2023-10-19 14:44:15 +00:00
  • c49461adb0 Accepting request 1118994 from home:david.anes:branches:Apache David Anes 2023-10-19 14:44:15 +00:00
  • 0c70389cd7 Accepting request 1104179 from Apache Ana Guerrero 2023-08-17 17:42:46 +00:00
  • d56320887e Accepting request 1104179 from Apache Ana Guerrero 2023-08-17 17:42:46 +00:00
  • d5678a9092 Accepting request 1102468 from home:dstoecker David Anes 2023-08-16 13:09:50 +00:00
  • 98cd467f8f Accepting request 1102468 from home:dstoecker David Anes 2023-08-16 13:09:50 +00:00
  • 6839c91cdd Accepting request 1078453 from Apache Dominique Leuenberger 2023-04-12 10:51:03 +00:00
  • ce7cd40dd3 Accepting request 1078453 from Apache Dominique Leuenberger 2023-04-12 10:51:03 +00:00
  • a69275ec6d Accepting request 1077884 from home:adkorte:branches:Apache David Anes 2023-04-11 13:32:57 +00:00
  • 28fa74dd09 Accepting request 1077884 from home:adkorte:branches:Apache David Anes 2023-04-11 13:32:57 +00:00
  • 51873aee52 Accepting request 1070268 from Apache Dominique Leuenberger 2023-03-11 17:22:05 +00:00
  • 3350d002e4 Accepting request 1070268 from Apache Dominique Leuenberger 2023-03-11 17:22:05 +00:00
  • 0016f66e00 Accepting request 1070261 from home:david.anes:branches:Apache David Anes 2023-03-08 20:52:02 +00:00
  • b0646b6a0e Accepting request 1070261 from home:david.anes:branches:Apache David Anes 2023-03-08 20:52:02 +00:00
  • eec4791b49 Accepting request 1060992 from Apache Dominique Leuenberger 2023-01-26 13:23:47 +00:00
  • c17f45f66c Accepting request 1060992 from Apache Dominique Leuenberger 2023-01-26 13:23:47 +00:00
  • b3efde70d7 Accepting request 1060991 from home:david.anes:branches:Apache David Anes 2023-01-25 16:45:25 +00:00
  • 05ed3ad0b8 Accepting request 1060991 from home:david.anes:branches:Apache David Anes 2023-01-25 16:45:25 +00:00
  • 093f7348a7 Accepting request 1060983 from home:david.anes:branches:Apache David Anes 2023-01-25 16:37:03 +00:00
  • 208a7dc602 Accepting request 1060983 from home:david.anes:branches:Apache David Anes 2023-01-25 16:37:03 +00:00
  • 2ab5f3ec98 Accepting request 1060451 from Apache Dominique Leuenberger 2023-01-24 18:42:19 +00:00
  • a0a3cc81be Accepting request 1060451 from Apache Dominique Leuenberger 2023-01-24 18:42:19 +00:00
  • 7eb34fb33d Accepting request 1060450 from home:david.anes:branches:Apache David Anes 2023-01-23 15:33:33 +00:00
  • 0415ee3d0e Accepting request 1060450 from home:david.anes:branches:Apache David Anes 2023-01-23 15:33:33 +00:00
  • 4c2a2dab1e Accepting request 1059452 from home:david.anes:branches:Apache David Anes 2023-01-19 09:33:48 +00:00
  • 7daefa5b80 Accepting request 1059452 from home:david.anes:branches:Apache David Anes 2023-01-19 09:33:48 +00:00
  • 79e2788acd Accepting request 1043275 from Apache Dominique Leuenberger 2022-12-17 19:36:09 +00:00
  • 51daf9244c Accepting request 1043275 from Apache Dominique Leuenberger 2022-12-17 19:36:09 +00:00
  • 466a98bde2 Accepting request 1043175 from home:dirkmueller:Factory David Anes 2022-12-16 07:31:14 +00:00
  • 5c0c75bfa3 Accepting request 1043175 from home:dirkmueller:Factory David Anes 2022-12-16 07:31:14 +00:00