SHA256
1
0
forked from pool/apache2
apache2/httpd-2.4.56.tar.bz2.asc
David Anes b0646b6a0e Accepting request 1070261 from home:david.anes:branches:Apache
- This update fixes the following security issues:
  * CVE-2023-27522 [bsc#1209049]: mod_proxy_uwsgi HTTP response splitting 
  * CVE-2023-25690 [bsc#1209047]: HTTP request splitting with mod_rewrite and mod_proxy  
- Update to 2.4.56: 
    *) rotatelogs: Add -T flag to allow subsequent rotated logfiles to be
      truncated without the initial logfile being truncated.  [Eric Covener]
    *) mod_ldap: LDAPConnectionPoolTTL should accept negative values in order to
      allow connections of any age to be reused. Up to now, a negative value
      was handled as an error when parsing the configuration file.  PR 66421.
      [nailyk <bzapache nailyk.fr>, Christophe Jaillet]
    *) mod_proxy_ajp: Report an error if the AJP backend sends an invalid number
      of headers. [Ruediger Pluem]
    *) mod_md:
      - Enabling ED25519 support and certificate transparency information when
        building with libressl v3.5.0 and newer. Thanks to Giovanni Bechis.
      - MDChallengeDns01 can now be configured for individual domains.
        Thanks to Jérôme Billiras (@bilhackmac) for the initial PR.
      - Fixed a bug found by Jérôme Billiras (@bilhackmac) that caused the challenge
        teardown not being invoked as it should.
      [Stefan Eissing]
    *) mod_http2: client resets of HTTP/2 streams led to unwanted 500 errors
      reported in access logs and error documents. The processing of the
      reset was correct, only unneccesary reporting was caused.
      [Stefan Eissing]
    *) mod_proxy_uwsgi: Stricter backend HTTP response parsing/validation.
      [Yann Ylavic]

  * CVE-2022-37436 [bsc#1207251], mod_proxy backend HTTP response splitting
  * CVE-2022-36760 [bsc#1207250], mod_proxy_ajp Possible request smuggling
  * CVE-2006-20001 [bsc#1207247], mod_dav out of bounds read, or write of zero byte

OBS-URL: https://build.opensuse.org/request/show/1070261
OBS-URL: https://build.opensuse.org/package/show/Apache/apache2?expand=0&rev=688
2023-03-08 20:52:02 +00:00

17 lines
833 B
Plaintext

-----BEGIN PGP SIGNATURE-----
iQIzBAABCgAdFiEEZbLUT+dL1ePeOsPwgngd5G1ZVPoFAmQFCgEACgkQgngd5G1Z
VPr0HhAAho+G5ExeMUPh7N8rDRJNswryTarzrphSO9kcll9cOcwPFxAsrp06aeaX
PEnRh3iVIncHXy8i+Jgj4U+srnSNWoU6x0RbmUju4kv2xXYHXNJieOGRanmE03Hu
hHq7Nv7KKb3GtYneof9pGboCR32LklJGSqEe8tpaW4f9y+HGOMflxpCLMqOAukyD
i8buHUvQ9OEC5TKbefq+eSkL0ndi8993pNP8k2fw+AQi5oHZe4gcEeUXCh4Eo9Bj
+bfPnIjS2A9znQ3IkWk1zz5WAUJIz1FfokDFrIZvEFf7+Vv48Fg0h7YfwgtT3sAs
Bz4ndUeG4DFKb0XwZ5uqnjeHkmRBn65FS+aXemhT1ilr3dx28O178BQ8gOv4FCYW
ijrefUxyz0WJYeD1qxhvWewXCEyzwSdiNCItfkKAl0g0b2VJnWjhx302QSjwaRT/
Qeh+bxGneDigyTy9eq2gdluUH/QoxwS+KVz+kp8xPoXJAkNT+2YOjpijOtnTMqQ0
zTpTWS6f9WLXVBX38oOF3EM915RQcGmGWVp3RRaxh6WPmR1rlf/zIih4XqZn68NH
qCjmRjE1ctG87ant/immcCrJ5GiSR9gHXhKMf7KLCUP3582fFuwvh0K9uO8z/Yfw
j/Ppae3Y/4CPd8Yk6tB90eFFHWusMHtcUD/mMKMOnSdVWxR7IGA=
=wk6o
-----END PGP SIGNATURE-----