|
|
Subscribe / Log in / New account

Debian alert DLA-2768-2 (uwsgi)

From:  Sylvain Beucler <beuc@beuc.net>
To:  debian-lts-announce@lists.debian.org
Subject:  [SECURITY] [DLA 2768-2] uwsgi regression update
Date:  Wed, 20 Oct 2021 20:04:40 +0200
Message-ID:  <20211020180440.GA633@mail.beuc.net>

-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian LTS Advisory DLA-2768-2 debian-lts@lists.debian.org https://www.debian.org/lts/security/ Sylvain Beucler October 20, 2021 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : uwsgi Version : 2.0.14+20161117-3+deb9u5 CVE ID : CVE-2021-36160 Debian Bug : 995368 A regression was introduced in DLA-2768-1, where the uwsgi proxy module for Apache2 (mod_proxy_uwsgi) interprets incorrect Apache configurations in a less forgiving way, causing existing setups to fail after upgrade. For Debian 9 stretch, this problem has been fixed in version 2.0.14+20161117-3+deb9u5. We recommend that you upgrade your uwsgi packages. For the detailed security status of uwsgi please refer to its security tracker page at: https://security-tracker.debian.org/tracker/uwsgi Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE1vEOfV7HXWKqBieIDTl9HeUlXjAFAmFwTIoACgkQDTl9HeUl XjDToQ/9GKnnExwbanMX5YK/hWo8YEoxr91u0H6OO+Sb7UCn+LMzbmbWDkR06G6K 1ziHGm2IKk3U/RakJ0hL4+az2iizKqtE5N9pRC8EGGeT2vly5cCiCFOacc+6oB8l pnnA7QGHlgiL5XzFRYx8UQs/7jv0FGjTQbEMdY0kCJe7OodsfiD2PLA8s7dRKaAh IrvS2xuT3uNQtT7a3kUg8ug1TxTxeYNwEkUqRUz5UYJFe2tdnHlNDm/q9I0xPfHp dH8hBBsVxArJ2ACOOvxcVMJww0wL2fnE4QbTcehhdiNFrMHvjmcmIQln5jPvXJQc J2k8XwBMXEkGgUY7EuC8A7hF/GenYAjSwTvsaT/pY2VxsSr0RoJyUAI5M2s6VHZk FRGjpytx89I6orinfBRdo4lAYvq/WVtkvFV3oVgpDs5oeh3iKsH/DAO3XG1BtdeL 5lHdM2MYAwPYYN8by9XfhcBklBLOTlOEcAWNrWqokErkpCtdZ7D1VnxiOzPxryPy NT73j7S3jlM3JSTRu2/+LOlDJ3Sp5Qh1dsKePRSNSbIrnmzmD22UeLZOohn5wO1s k+yf+VIidDnjdILtiOfDLETwFYFPHh6krzIasFEwbkHkv/X+tfACEdoheKxQAKox fqLKuhjMfje408vB159R65TO6fdJgWQ3io9IJ5fxzIKnVFRZEIw= =onVk -----END PGP SIGNATURE-----


to post comments


Copyright © 2025, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds