This bug was fixed in the package apache2 - 2.4.62-1ubuntu1 --------------- apache2 (2.4.62-1ubuntu1) oracular; urgency=medium
* Merge with Debian unstable (LP: #2077060). Remaining changes: - d/index.html, d/icons/ubuntu-logo.png, d/apache2.postrm, d/source/include-binaries, d/t/check-ubuntu-branding: Replace Debian with Ubuntu on default homepage. (LP #1966004, LP #1947459) - d/apache2.py, d/apache2-bin.install: Add apport hook (LP #609177) - d/c/m/setenvif.conf, d/p/fix-dolphin-to-delete-webdav-dirs.patch: Add dolphin and Konqueror/5 careful redirection so that directories can be deleted via webdav. (LP #1927742) - d/debhelper/apache2-maintscript-helper: Allow execution when called from a postinst script through a trigger (i.e., postinst triggered). Thanks to Roel van Meer. (Closes: #1060450) (LP #2038912) - d/index.html, d/apache2.postrm: Fix https link to apache documentation. (LP #2045055) * Dropped: - d/control, d/apache2.install, d/apache2-utils.ufw.profile, d/apache2.dirs: Add ufw profiles (LP #261198) [Included in Debian 2.4.60-1] - d/control: Upgrade lua build dependency to 5.4 (LP #1910372) [Included in Debian 2.4.60-1] apache2 (2.4.62-1) unstable; urgency=medium * New upstream version 2.4.62 (Closes: CVE-2024-40725, CVE-2024-40898) apache2 (2.4.61-1) unstable; urgency=medium * New upstream version 2.4.61 (Closes: CVE-2024-39884) apache2 (2.4.60-1) unstable; urgency=medium [ Bastien Roucariès ] * Forward port CVE-2023-25690 uwsgi tests * Fix depends of uwsgi test * Use python3 uwsgi plugin * Encode bytes for uwsgi test [ Bryce Harrington ] * Add UFW profile integration (Closes: #1071705) [Chris Murray] * Use https instead of http in doc (LP: #2045055) [ Yadd ] * Bump liblua from liblua5.3-dev to liblua5.4-dev (Closes: #1071701) * Update test framework * releasing package apache2 version 2.4.59-1~deb12u1 * New upstream version (CLoses: CVE-2024-36387, CVE-2024-38472, CVE-2024-38473, CVE-2024-38474, CVE-2024-38475, CVE-2024-38476, CVE-2024-38477, CVE-2024-39573) * Unfuzz patches -- Bryce Harrington <br...@canonical.com> Thu, 15 Aug 2024 00:32:14 -0700 ** Changed in: apache2 (Ubuntu) Status: Fix Committed => Fix Released ** CVE added: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2023-25690 ** CVE added: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2024-36387 ** CVE added: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2024-38472 ** CVE added: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2024-38473 ** CVE added: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2024-38474 ** CVE added: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2024-38475 ** CVE added: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2024-38476 ** CVE added: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2024-38477 ** CVE added: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2024-39573 ** CVE added: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2024-39884 ** CVE added: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2024-40725 ** CVE added: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2024-40898 -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2077060 Title: Please re-merge apache2 (2.4.62-1) for oracular To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/apache2/+bug/2077060/+subscriptions -- ubuntu-bugs mailing list ubuntu-bugs@lists.ubuntu.com https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs