Debian alert DLA-2706-1 (apache2)
From: | Emilio Pozuelo Monfort <pochu@debian.org> | |
To: | <debian-lts-announce@lists.debian.org> | |
Subject: | [SECURITY] [DLA 2706-1] apache2 security update | |
Date: | Fri, 09 Jul 2021 10:50:21 +0200 | |
Message-ID: | <20210709085021.7D4672A01EB@andromeda> |
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 - ------------------------------------------------------------------------- Debian LTS Advisory DLA-2706-1 debian-lts@lists.debian.org https://www.debian.org/lts/security/ Emilio Pozuelo Monfort July 09, 2021 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : apache2 Version : 2.4.25-3+deb9u10 CVE ID : CVE-2020-1927 CVE-2020-1934 CVE-2020-35452 CVE-2021-26690 CVE-2021-26691 CVE-2021-30641 CVE-2021-31618 Several vulnerabilities have been found in the Apache HTTP server, which could result in denial of service. In addition the implementation of the MergeSlashes option could result in unexpected behaviour. For Debian 9 stretch, these problems have been fixed in version 2.4.25-3+deb9u10. We recommend that you upgrade your apache2 packages. For the detailed security status of apache2 please refer to its security tracker page at: https://security-tracker.debian.org/tracker/apache2 Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS -----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFiEEcJymx+vmJZxd92Q+nUbEiOQ2gwIFAmDoDc0ACgkQnUbEiOQ2 gwIbPQ/8DJNz+cq+k5zyEGb1j6yq63G4gQIKuK9AwKNl3QV8j6f7EXdHRke50Lqn 2wFUF94WlPnx0IPdK5gAxNDR2RRh9sOz8MxwVmRqWrPZVvlC2E0yZzCpaN7kQmLQ deealB/doRpA16gNUTJWXNx22lQTwbgaHK3rLorMUM2C7PUMrS0HJBZ4jlBRoWU3 ZmpDrppPdGmn0IuDdS96SW0GmaqkbXwjqocP1RUmZgdVLK6XakCwvZrq2srj1CQn yqiLYvzZhfzNR0ZC2f99uXabfjIQyEYGQUjnOOsNO0ziJAxFfqdnY+ibv2EK8F07 Da0z8etvmZfdq7mii2d+YHouCZAXWCXn56hZt4uQ8kf3QMmSRRy9nYbcKu8SMlcO djMn+vcusQK7U8nkLcMqj/jm32FKWruxm22RmDdDeZhp4zbFcR4hcRqRwr/egtoP XTXBrvGyIJwHaIaQsN0mrTnF60kXZtexQqBA3H8r0296AOClqyw0a2eBorTf2SbA lHZ2eBli+ZYKcZOdxRPedGhVDcoXq8+niEbRJovD8Ka5U4t2X5M1u7ZP4M/ZubHg sTrecRViPY+y0wvaxBKp6P54Ap38iBPsR/g4FJpjOI+kXc8cy8VWnM3Xg3qPNmHk 2bddQdLTvC3L3YBt1IAUXYSLXKa49A57u/vpV5zlC16Dica36ps= =WUI2 -----END PGP SIGNATURE-----