Home page logo
/

fulldisclosure logo Full Disclosure mailing list archives

[USN-241-1] Apache vulnerabilities
From: Adam Conrad <adconrad () ubuntu com>
Date: Thu, 12 Jan 2006 20:40:18 +1100 (EST)

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

===========================================================
Ubuntu Security Notice USN-241-1           January 12, 2006
apache2, apache vulnerabilities
CVE-2005-3352, CVE-2005-3357
===========================================================

A security issue affects the following Ubuntu releases:

Ubuntu 4.10 (Warty Warthog)
Ubuntu 5.04 (Hoary Hedgehog)
Ubuntu 5.10 (Breezy Badger)

The following packages are affected:

apache-common
apache2-common
apache2-mpm-worker

The problem can be corrected by upgrading the affected package to
following versions:

Ubuntu 4.10:
  apache-common 1.3.31-6ubuntu0.9
  apache2-common 2.0.50-12ubuntu4.10
  apache2-mpm-worker 2.0.50-12ubuntu4.10

Ubuntu 5.04:
  apache-common 1.3.33-4ubuntu2
  apache2-common 2.0.53-5ubuntu5.5
  apache2-mpm-worker 2.0.53-5ubuntu5.5

Ubuntu 5.10:
  apache-common 1.3.33-8ubuntu1
  apache2-common 2.0.54-5ubuntu4
  apache2-mpm-worker 2.0.54-5ubuntu4

In general, a standard system upgrade is sufficient to effect the
necessary changes.

Details follow:

The "mod_imap" module (which provides support for image maps) did not
properly escape the "referer" URL which rendered it vulnerable against
a cross-site scripting attack. A malicious web page (or HTML email)
could trick a user into visiting a site running the vulnerable mod_imap,
and employ cross-site-scripting techniques to gather sensitive user
information from that site. (CVE-2005-3352)

Hartmut Keil discovered a Denial of Service vulnerability in the SSL
module ("mod_ssl") that affects SSL-enabled virtual hosts with a
customized error page for error 400. By sending a specially crafted
request to the server, a remote attacker could crash the server. This
only affects Apache 2, and only if the "worker" implementation
(apache2-mpm-worker) is used. (CVE-2005-3357)


Updated packages for Ubuntu 4.10:

  Source archives:

    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2_2.0.50-12ubuntu4.10.diff.gz
      Size/MD5:   102697 b9ab5b9b329233515fefebd4eda8f414
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2_2.0.50-12ubuntu4.10.dsc
      Size/MD5:     1154 821a525974e6c5a860804b7ee161bcbb
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2_2.0.50.orig.tar.gz
      Size/MD5:  6321209 9d0767f8a1344229569fcd8272156f8b
    http://security.ubuntu.com/ubuntu/pool/main/a/apache/apache_1.3.31-6ubuntu0.9.diff.gz
      Size/MD5:   372917 40492f263fea26a723e7d5ae00aa5b4b
    http://security.ubuntu.com/ubuntu/pool/main/a/apache/apache_1.3.31-6ubuntu0.9.dsc
      Size/MD5:     1102 f1420705a37bbe22382bdac63bd0dd4a
    http://security.ubuntu.com/ubuntu/pool/main/a/apache/apache_1.3.31.orig.tar.gz
      Size/MD5:  3104170 ca475fbb40087eb157ec51334f260d1b

  Architecture independent packages:

    http://security.ubuntu.com/ubuntu/pool/main/a/apache/apache-dev_1.3.31-6ubuntu0.9_all.deb
      Size/MD5:   329946 4523d5d31291fd61527e4e6fe2647a58
    http://security.ubuntu.com/ubuntu/pool/universe/a/apache/apache-doc_1.3.31-6ubuntu0.9_all.deb
      Size/MD5:  1187018 c8445132ce6680a1bedf9777d3aa5dff
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-doc_2.0.50-12ubuntu4.10_all.deb
      Size/MD5:  3179114 9f8d1313218e9647e6d6922a3dd596aa
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-prefork-dev_2.0.50-12ubuntu4.10_all.deb
      Size/MD5:   164496 79203dac930d4f4cd2ef857f4a9a2e44
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-threaded-dev_2.0.50-12ubuntu4.10_all.deb
      Size/MD5:   165258 9ece4dde8a562fa1dff10234c56ad15a

  amd64 architecture (Athlon64, Opteron, EM64T Xeon)

    http://security.ubuntu.com/ubuntu/pool/main/a/apache/apache-common_1.3.31-6ubuntu0.9_amd64.deb
      Size/MD5:   873834 566017c0c221fae1d9630309f03a219e
    http://security.ubuntu.com/ubuntu/pool/universe/a/apache/apache-dbg_1.3.31-6ubuntu0.9_amd64.deb
      Size/MD5:  9131724 39b52912a2e31b2f83cd3018ffccd55c
    http://security.ubuntu.com/ubuntu/pool/universe/a/apache/apache-perl_1.3.31-6ubuntu0.9_amd64.deb
      Size/MD5:   520978 3ca778eb1c7b1dd41a3bf89bd6c216a8
    http://security.ubuntu.com/ubuntu/pool/universe/a/apache/apache-ssl_1.3.31-6ubuntu0.9_amd64.deb
      Size/MD5:   511078 1c621fb6db54097d4a97e07d07d9d0fd
    http://security.ubuntu.com/ubuntu/pool/main/a/apache/apache-utils_1.3.31-6ubuntu0.9_amd64.deb
      Size/MD5:   271744 2f09954e5578ca0e1050c6f2cfd0ec98
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-common_2.0.50-12ubuntu4.10_amd64.deb
      Size/MD5:   865442 b09ae2a626a4c7afa4bc009aff36e007
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-mpm-perchild_2.0.50-12ubuntu4.10_amd64.deb
      Size/MD5:   231190 149d647db36689c3983fb2d9b422b4cc
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-mpm-prefork_2.0.50-12ubuntu4.10_amd64.deb
      Size/MD5:   226334 9086722d2571d55f06d3db4fd0472742
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-mpm-threadpool_2.0.50-12ubuntu4.10_amd64.deb
      Size/MD5:   229686 d0a2121f37682dd5c4a7da183e7e9ac4
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-mpm-worker_2.0.50-12ubuntu4.10_amd64.deb
      Size/MD5:   230312 d991e4bd7994c29285c76ad600b62694
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2_2.0.50-12ubuntu4.10_amd64.deb
      Size/MD5:    30726 64fa0d53f98651122deb4688f5e74b9f
    http://security.ubuntu.com/ubuntu/pool/universe/a/apache/apache_1.3.31-6ubuntu0.9_amd64.deb
      Size/MD5:   398562 dc69c02fee09a9c4c74bde74cc020230
    http://security.ubuntu.com/ubuntu/pool/universe/a/apache/libapache-mod-perl_1.29.0.2.0-6ubuntu0.9_amd64.deb
      Size/MD5:   491918 fbafeec1e6cacf0dabde3a53e1e2ac6f
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/libapr0-dev_2.0.50-12ubuntu4.10_amd64.deb
      Size/MD5:   276242 e0fdda747b95fa35894a4d59110063af
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/libapr0_2.0.50-12ubuntu4.10_amd64.deb
      Size/MD5:   134180 af5cb5c7b9e0831946dc94a4961ecffe

  i386 architecture (x86 compatible Intel/AMD)

    http://security.ubuntu.com/ubuntu/pool/main/a/apache/apache-common_1.3.31-6ubuntu0.9_i386.deb
      Size/MD5:   838782 71df372da7a56281907c9d2046d20af2
    http://security.ubuntu.com/ubuntu/pool/universe/a/apache/apache-dbg_1.3.31-6ubuntu0.9_i386.deb
      Size/MD5:  9080910 e056b1e70bff49a076ac1bd5f046843e
    http://security.ubuntu.com/ubuntu/pool/universe/a/apache/apache-perl_1.3.31-6ubuntu0.9_i386.deb
      Size/MD5:   494588 c5f7d2f9cc0a4abf45710c862d8079d0
    http://security.ubuntu.com/ubuntu/pool/universe/a/apache/apache-ssl_1.3.31-6ubuntu0.9_i386.deb
      Size/MD5:   484412 41ad993bff379577eb51576107309bbc
    http://security.ubuntu.com/ubuntu/pool/main/a/apache/apache-utils_1.3.31-6ubuntu0.9_i386.deb
      Size/MD5:   265552 cf1a05ca41cf8c46e7223aa713b9ccb0
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-common_2.0.50-12ubuntu4.10_i386.deb
      Size/MD5:   826938 7e755cd6c6a1a4bbf7577e0295496655
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-mpm-perchild_2.0.50-12ubuntu4.10_i386.deb
      Size/MD5:   210112 6542e2360062cb0810b8e82fbb8dd5df
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-mpm-prefork_2.0.50-12ubuntu4.10_i386.deb
      Size/MD5:   206350 adbe6b4d6277c073de94dc8b212ed3f9
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-mpm-threadpool_2.0.50-12ubuntu4.10_i386.deb
      Size/MD5:   208988 0ef9291233dd6ff9ef301145574aeabf
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-mpm-worker_2.0.50-12ubuntu4.10_i386.deb
      Size/MD5:   209412 cda3b9da217412248974fbcd3fc8b769
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2_2.0.50-12ubuntu4.10_i386.deb
      Size/MD5:    30724 1c183a30096ae610e41c25586f814d8f
    http://security.ubuntu.com/ubuntu/pool/universe/a/apache/apache_1.3.31-6ubuntu0.9_i386.deb
      Size/MD5:   377780 a17065ef39cb3e6dec3a47fe124e78d3
    http://security.ubuntu.com/ubuntu/pool/universe/a/apache/libapache-mod-perl_1.29.0.2.0-6ubuntu0.9_i386.deb
      Size/MD5:   485268 174ae6f25ad9e6f91cd7867ae8735ba7
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/libapr0-dev_2.0.50-12ubuntu4.10_i386.deb
      Size/MD5:   254206 346225b4431eaf85bac9e81776fa08d2
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/libapr0_2.0.50-12ubuntu4.10_i386.deb
      Size/MD5:   124896 c3c18eb91ecb08130d5ed8aa22124153

  powerpc architecture (Apple Macintosh G3/G4/G5)

    http://security.ubuntu.com/ubuntu/pool/main/a/apache/apache-common_1.3.31-6ubuntu0.9_powerpc.deb
      Size/MD5:   917906 27b01c892c39f08625db8a73df0900fa
    http://security.ubuntu.com/ubuntu/pool/universe/a/apache/apache-dbg_1.3.31-6ubuntu0.9_powerpc.deb
      Size/MD5:  9226810 aa20edbb4d5263549ab229e20547e7aa
    http://security.ubuntu.com/ubuntu/pool/universe/a/apache/apache-perl_1.3.31-6ubuntu0.9_powerpc.deb
      Size/MD5:   511680 17c6ea33be64e4d8e0f733dac38af3dd
    http://security.ubuntu.com/ubuntu/pool/universe/a/apache/apache-ssl_1.3.31-6ubuntu0.9_powerpc.deb
      Size/MD5:   507512 f6b5cf1a74d18471789dd0183ecd3632
    http://security.ubuntu.com/ubuntu/pool/main/a/apache/apache-utils_1.3.31-6ubuntu0.9_powerpc.deb
      Size/MD5:   278880 234b19e362da6e927c4a4aaa63b0b90d
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-common_2.0.50-12ubuntu4.10_powerpc.deb
      Size/MD5:   904636 8302f88c861deead3efbb418c35c21ac
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-mpm-perchild_2.0.50-12ubuntu4.10_powerpc.deb
      Size/MD5:   223774 ae205ac9caa54978d009eb9cd8be3cad
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-mpm-prefork_2.0.50-12ubuntu4.10_powerpc.deb
      Size/MD5:   218758 64a004ab491a912a0f858753240a8a74
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-mpm-threadpool_2.0.50-12ubuntu4.10_powerpc.deb
      Size/MD5:   221784 2d03fcd4695951e4424cfaa571bfc34e
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-mpm-worker_2.0.50-12ubuntu4.10_powerpc.deb
      Size/MD5:   222596 f51529d830cdedd9dd7dcf2c7f1b4aa3
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2_2.0.50-12ubuntu4.10_powerpc.deb
      Size/MD5:    30728 7b1c3da7137d0ab863ccdc0ec6b23825
    http://security.ubuntu.com/ubuntu/pool/universe/a/apache/apache_1.3.31-6ubuntu0.9_powerpc.deb
      Size/MD5:   395914 b285ff09bb65bd3aa4b553c9f03454db
    http://security.ubuntu.com/ubuntu/pool/universe/a/apache/libapache-mod-perl_1.29.0.2.0-6ubuntu0.9_powerpc.deb
      Size/MD5:   489458 e44725465bf4369dacb1adf7f03828de
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/libapr0-dev_2.0.50-12ubuntu4.10_powerpc.deb
      Size/MD5:   269998 8589d6433af42e63a6431b028fd4bdf5
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/libapr0_2.0.50-12ubuntu4.10_powerpc.deb
      Size/MD5:   131506 c5cbcd6706d6d779487d598f577718b3


Updated packages for Ubuntu 5.04:

  Source archives:

    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2_2.0.53-5ubuntu5.5.diff.gz
      Size/MD5:   109374 000706d79d9c8b28e298fa52837627db
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2_2.0.53-5ubuntu5.5.dsc
      Size/MD5:     1159 59e8b14a9361f3418228276dd29ec528
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2_2.0.53.orig.tar.gz
      Size/MD5:  6925351 40507bf19919334f07355eda2df017e5
    http://security.ubuntu.com/ubuntu/pool/universe/a/apache/apache_1.3.33-4ubuntu2.diff.gz
      Size/MD5:   364909 889674cb6a424c468cfbc436b21b3295
    http://security.ubuntu.com/ubuntu/pool/universe/a/apache/apache_1.3.33-4ubuntu2.dsc
      Size/MD5:     1121 6c6dcd7fb566cc06ea8e803d25dfb597
    http://security.ubuntu.com/ubuntu/pool/universe/a/apache/apache_1.3.33.orig.tar.gz
      Size/MD5:  3105683 1a34f13302878a8713a2ac760d9b6da8

  Architecture independent packages:

    http://security.ubuntu.com/ubuntu/pool/universe/a/apache/apache-dev_1.3.33-4ubuntu2_all.deb
      Size/MD5:   331204 2bd939db8fe498fed1e832e0d96f1199
    http://security.ubuntu.com/ubuntu/pool/universe/a/apache/apache-doc_1.3.33-4ubuntu2_all.deb
      Size/MD5:  1189264 c2cd07389b6a594be7867aab821eee3a
    http://security.ubuntu.com/ubuntu/pool/universe/a/apache/apache-utils_1.3.33-4ubuntu2_all.deb
      Size/MD5:   211952 951b9a8b77f02798ce5830ff2f3835e7
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-doc_2.0.53-5ubuntu5.5_all.deb
      Size/MD5:  3578784 c660c224fcca24437abda1aa859abad6
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-mpm-threadpool_2.0.53-5ubuntu5.5_all.deb
      Size/MD5:    34266 847d992bd540a3344f196bfce3d95adb

  amd64 architecture (Athlon64, Opteron, EM64T Xeon)

    http://security.ubuntu.com/ubuntu/pool/universe/a/apache/apache-common_1.3.33-4ubuntu2_amd64.deb
      Size/MD5:   875210 c1a0de1cde030ecba1f0626f4b985b40
    http://security.ubuntu.com/ubuntu/pool/universe/a/apache/apache-dbg_1.3.33-4ubuntu2_amd64.deb
      Size/MD5:  9164038 1953a7036727e9f63740fec483d410e6
    http://security.ubuntu.com/ubuntu/pool/universe/a/apache/apache-perl_1.3.33-4ubuntu2_amd64.deb
      Size/MD5:   522296 b280d123d9292f5385403c36a22100b2
    http://security.ubuntu.com/ubuntu/pool/universe/a/apache/apache-ssl_1.3.33-4ubuntu2_amd64.deb
      Size/MD5:   512508 ca54187982e54d702fcf58d7c0878a92
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-common_2.0.53-5ubuntu5.5_amd64.deb
      Size/MD5:   826574 43fb7a070010ffbeb34c493fb6754685
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-mpm-perchild_2.0.53-5ubuntu5.5_amd64.deb
      Size/MD5:   221512 56710242a8a8b3f48a0a8f0f9e965daa
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-mpm-prefork_2.0.53-5ubuntu5.5_amd64.deb
      Size/MD5:   217158 0ee442a4b104efde575aa1979c51e7bc
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-mpm-worker_2.0.53-5ubuntu5.5_amd64.deb
      Size/MD5:   220574 2481ccb00b4bc5305049e31d00f3037a
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-prefork-dev_2.0.53-5ubuntu5.5_amd64.deb
      Size/MD5:   167932 9e15597c23c4eafae0cb77c33e81df1a
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-threaded-dev_2.0.53-5ubuntu5.5_amd64.deb
      Size/MD5:   168714 fbc84d1ac3119a8258bb3c5fbbff5941
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-utils_2.0.53-5ubuntu5.5_amd64.deb
      Size/MD5:    93366 4f29d17cfb3136d2374d7d93f1c84ed6
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2_2.0.53-5ubuntu5.5_amd64.deb
      Size/MD5:    34194 d9c2454c60fd8088bcf70d8953b2f7de
    http://security.ubuntu.com/ubuntu/pool/universe/a/apache/apache_1.3.33-4ubuntu2_amd64.deb
      Size/MD5:   399974 096267c728c4233d8aa55b34c907e507
    http://security.ubuntu.com/ubuntu/pool/universe/a/apache/libapache-mod-perl_1.29.0.3-4ubuntu2_amd64.deb
      Size/MD5:   492394 620dc00a36c0eaca91231c4c3cfdb71f
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/libapr0-dev_2.0.53-5ubuntu5.5_amd64.deb
      Size/MD5:   279554 d157e01efc5e8aabbf4eeb47945e2f21
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/libapr0_2.0.53-5ubuntu5.5_amd64.deb
      Size/MD5:   138040 ef5b1a9566b0677527d931c8c90dcecf

  i386 architecture (x86 compatible Intel/AMD)

    http://security.ubuntu.com/ubuntu/pool/universe/a/apache/apache-common_1.3.33-4ubuntu2_i386.deb
      Size/MD5:   839620 aaa564735f9dc7e71d14f91d5128399e
    http://security.ubuntu.com/ubuntu/pool/universe/a/apache/apache-dbg_1.3.33-4ubuntu2_i386.deb
      Size/MD5:  9104778 c4fff1962faeaab90cd63d91b8f1d1d7
    http://security.ubuntu.com/ubuntu/pool/universe/a/apache/apache-perl_1.3.33-4ubuntu2_i386.deb
      Size/MD5:   495262 d6a22c78a4783f8bf5e41c695f539474
    http://security.ubuntu.com/ubuntu/pool/universe/a/apache/apache-ssl_1.3.33-4ubuntu2_i386.deb
      Size/MD5:   485508 556697b210bd0266d1b1a7e35eb3f352
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-common_2.0.53-5ubuntu5.5_i386.deb
      Size/MD5:   789600 0eed4549ca3fb12996e71229bf0fd22d
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-mpm-perchild_2.0.53-5ubuntu5.5_i386.deb
      Size/MD5:   201830 dcb33f94fc60b2a8cf1ef9297c8ad0c4
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-mpm-prefork_2.0.53-5ubuntu5.5_i386.deb
      Size/MD5:   197578 4ec720ddc2cec8b772c44b6780b07ef0
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-mpm-worker_2.0.53-5ubuntu5.5_i386.deb
      Size/MD5:   201014 efac94b53861bc999db907163578b996
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-prefork-dev_2.0.53-5ubuntu5.5_i386.deb
      Size/MD5:   167944 4db2460ab3476b80e7858f90558245fe
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-threaded-dev_2.0.53-5ubuntu5.5_i386.deb
      Size/MD5:   168726 4b2d825987781e484a9681e0ef6996b9
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-utils_2.0.53-5ubuntu5.5_i386.deb
      Size/MD5:    91104 dcd06b7d3bfba28cd9b776f259e41023
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2_2.0.53-5ubuntu5.5_i386.deb
      Size/MD5:    34194 2a52039d42c4d4c7312730ddee388d12
    http://security.ubuntu.com/ubuntu/pool/universe/a/apache/apache_1.3.33-4ubuntu2_i386.deb
      Size/MD5:   378904 fa78ca4f2736fe9eeb04f196e2a4e53a
    http://security.ubuntu.com/ubuntu/pool/universe/a/apache/libapache-mod-perl_1.29.0.3-4ubuntu2_i386.deb
      Size/MD5:   485792 b2ab8ff4db993be297af3159a781ad76
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/libapr0-dev_2.0.53-5ubuntu5.5_i386.deb
      Size/MD5:   257488 4f15b3f3505f637a21c73b72668fa113
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/libapr0_2.0.53-5ubuntu5.5_i386.deb
      Size/MD5:   128738 f1e6e5632886a8fe33d225e5092e7c28

  powerpc architecture (Apple Macintosh G3/G4/G5)

    http://security.ubuntu.com/ubuntu/pool/universe/a/apache/apache-common_1.3.33-4ubuntu2_powerpc.deb
      Size/MD5:   919520 3470ca9b6836ed0c27b1c0e9b4f67e65
    http://security.ubuntu.com/ubuntu/pool/universe/a/apache/apache-dbg_1.3.33-4ubuntu2_powerpc.deb
      Size/MD5:  9253994 efebd79c8574a5a4c84e1edeca5d9ec9
    http://security.ubuntu.com/ubuntu/pool/universe/a/apache/apache-perl_1.3.33-4ubuntu2_powerpc.deb
      Size/MD5:   513232 15e5ca796f64e7bb9e1ce7e64fe780c3
    http://security.ubuntu.com/ubuntu/pool/universe/a/apache/apache-ssl_1.3.33-4ubuntu2_powerpc.deb
      Size/MD5:   509154 c569dd0a6a0a84bc386ef5eba1e4efe0
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-common_2.0.53-5ubuntu5.5_powerpc.deb
      Size/MD5:   855930 5ad12c9e970cbb34c54de2b4af98cad8
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-mpm-perchild_2.0.53-5ubuntu5.5_powerpc.deb
      Size/MD5:   214828 4aedb1d58f7393f3abbf79c248b32d5a
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-mpm-prefork_2.0.53-5ubuntu5.5_powerpc.deb
      Size/MD5:   209938 d45c90319b5383b99b6933e01ea1ab23
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-mpm-worker_2.0.53-5ubuntu5.5_powerpc.deb
      Size/MD5:   213858 68e163b074d6a68151b4bfb8cd544275
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-prefork-dev_2.0.53-5ubuntu5.5_powerpc.deb
      Size/MD5:   167942 6ecb3fcfd160baa3b84a574688d9bea4
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-threaded-dev_2.0.53-5ubuntu5.5_powerpc.deb
      Size/MD5:   168714 6b0705e15135a112bc6a1706913a6c4b
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-utils_2.0.53-5ubuntu5.5_powerpc.deb
      Size/MD5:   102790 b1967ad6269cda61b99c72c1e9d480e2
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2_2.0.53-5ubuntu5.5_powerpc.deb
      Size/MD5:    34196 ff6fb5ff24f6dc15b63172357371e1b7
    http://security.ubuntu.com/ubuntu/pool/universe/a/apache/apache_1.3.33-4ubuntu2_powerpc.deb
      Size/MD5:   397196 b55f344c51050420de8bd30ae1554a20
    http://security.ubuntu.com/ubuntu/pool/universe/a/apache/libapache-mod-perl_1.29.0.3-4ubuntu2_powerpc.deb
      Size/MD5:   490526 6dcafd0faa774ecf409f7ec37312749c
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/libapr0-dev_2.0.53-5ubuntu5.5_powerpc.deb
      Size/MD5:   272782 11651cfdb44f4ccceec53561839fdab2
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/libapr0_2.0.53-5ubuntu5.5_powerpc.deb
      Size/MD5:   135082 3824767a49fba2a329d08e31c50f5ac4


Updated packages for Ubuntu 5.10:

  Source archives:

    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2_2.0.54-5ubuntu4.diff.gz
      Size/MD5:   116790 df0ce6e09b794605bc72dbaa07c6ceac
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2_2.0.54-5ubuntu4.dsc
      Size/MD5:     1155 ab66b3bd03d3d0fe8eadda96408918a7
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2_2.0.54.orig.tar.gz
      Size/MD5:  7493636 37d0d0a3e25ad93d37f0483021e70409
    http://security.ubuntu.com/ubuntu/pool/universe/a/apache/apache_1.3.33-8ubuntu1.diff.gz
      Size/MD5:   370309 f018c73ed5af6d2a2acd74388b0cf3e5
    http://security.ubuntu.com/ubuntu/pool/universe/a/apache/apache_1.3.33-8ubuntu1.dsc
      Size/MD5:     1109 a8c73446fb0402a49a956721f0ce74f4
    http://security.ubuntu.com/ubuntu/pool/universe/a/apache/apache_1.3.33.orig.tar.gz
      Size/MD5:  3105683 1a34f13302878a8713a2ac760d9b6da8

  Architecture independent packages:

    http://security.ubuntu.com/ubuntu/pool/universe/a/apache/apache-dev_1.3.33-8ubuntu1_all.deb
      Size/MD5:   331756 f3d1cf41f4ec3ef158f52556959954cc
    http://security.ubuntu.com/ubuntu/pool/universe/a/apache/apache-doc_1.3.33-8ubuntu1_all.deb
      Size/MD5:  1189834 48a529a5626746107cc6da5071abe606
    http://security.ubuntu.com/ubuntu/pool/universe/a/apache/apache-utils_1.3.33-8ubuntu1_all.deb
      Size/MD5:   212548 251bc83b92f15cc87e48d9f533ef13d3
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-doc_2.0.54-5ubuntu4_all.deb
      Size/MD5:  3862902 6200801224d31a71c4cf1d44a50c4deb
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-mpm-threadpool_2.0.54-5ubuntu4_all.deb
      Size/MD5:    35080 77db9b00ac5e4bbabd3c0e8679dba171

  amd64 architecture (Athlon64, Opteron, EM64T Xeon)

    http://security.ubuntu.com/ubuntu/pool/universe/a/apache/apache-common_1.3.33-8ubuntu1_amd64.deb
      Size/MD5:   873236 a047157623a9c953d8aa0a33640372ec
    http://security.ubuntu.com/ubuntu/pool/universe/a/apache/apache-dbg_1.3.33-8ubuntu1_amd64.deb
      Size/MD5:  8626076 1392d88d117c3c648beca0b8bc760a3e
    http://security.ubuntu.com/ubuntu/pool/universe/a/apache/apache-perl_1.3.33-8ubuntu1_amd64.deb
      Size/MD5:   530612 6c607769117c9c74296bc438082603c3
    http://security.ubuntu.com/ubuntu/pool/universe/a/apache/apache-ssl_1.3.33-8ubuntu1_amd64.deb
      Size/MD5:   517802 1dd9562fd170cd44912f91d41ef4835d
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-common_2.0.54-5ubuntu4_amd64.deb
      Size/MD5:   826138 5e55831358d77900f2a2ceed8d9df0d7
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-mpm-perchild_2.0.54-5ubuntu4_amd64.deb
      Size/MD5:   226024 9c712624ed56fd721c27c4451e4ca074
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-mpm-prefork_2.0.54-5ubuntu4_amd64.deb
      Size/MD5:   220656 45476c34759a14b76c37eb746babd7af
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-mpm-worker_2.0.54-5ubuntu4_amd64.deb
      Size/MD5:   225232 e2e50763c1c5399706900eba0e87d95d
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-prefork-dev_2.0.54-5ubuntu4_amd64.deb
      Size/MD5:   169300 20f38605e4f3868ae56945ac27c6f388
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-threaded-dev_2.0.54-5ubuntu4_amd64.deb
      Size/MD5:   170044 76b38a3efbacbb52a47aef7c93d74d38
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-utils_2.0.54-5ubuntu4_amd64.deb
      Size/MD5:    93018 1ed9bae73f6dac81f565e379fadaa32a
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2_2.0.54-5ubuntu4_amd64.deb
      Size/MD5:    35010 4706a9d5b7db08ea9e9d646d55a707a8
    http://security.ubuntu.com/ubuntu/pool/universe/a/apache/apache_1.3.33-8ubuntu1_amd64.deb
      Size/MD5:   406560 6712638df37a9a6a35d4d0182dcf24ba
    http://security.ubuntu.com/ubuntu/pool/universe/a/apache/libapache-mod-perl_1.29.0.3-8ubuntu1_amd64.deb
      Size/MD5:   494446 2a61cfecdee26428792c7a674eec7ae6
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/libapr0-dev_2.0.54-5ubuntu4_amd64.deb
      Size/MD5:   283296 617b6b89b5f5fb7a1e02b5a4ed6d1819
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/libapr0_2.0.54-5ubuntu4_amd64.deb
      Size/MD5:   142696 2bddf9d1e0848a694297b6e0e1ef97c8

  i386 architecture (x86 compatible Intel/AMD)

    http://security.ubuntu.com/ubuntu/pool/universe/a/apache/apache-common_1.3.33-8ubuntu1_i386.deb
      Size/MD5:   836298 cb6786f3552029a16c7ca392f6f7c341
    http://security.ubuntu.com/ubuntu/pool/universe/a/apache/apache-dbg_1.3.33-8ubuntu1_i386.deb
      Size/MD5:  8392184 6e89f3b92ad5b6cfe55d1136991fbdf4
    http://security.ubuntu.com/ubuntu/pool/universe/a/apache/apache-perl_1.3.33-8ubuntu1_i386.deb
      Size/MD5:   499024 98c2e97c1b8dbfdda4a784fdd4275051
    http://security.ubuntu.com/ubuntu/pool/universe/a/apache/apache-ssl_1.3.33-8ubuntu1_i386.deb
      Size/MD5:   489228 304d88bdede64334a01ff65fe26c2223
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-common_2.0.54-5ubuntu4_i386.deb
      Size/MD5:   780750 60edcbe6f87ab9b9ef83c7f39db9f938
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-mpm-perchild_2.0.54-5ubuntu4_i386.deb
      Size/MD5:   201254 b1879d2b6424fd74ba9cc3ba2acaf583
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-mpm-prefork_2.0.54-5ubuntu4_i386.deb
      Size/MD5:   197158 8ae300065838a9a464bd4065a23d3eda
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-mpm-worker_2.0.54-5ubuntu4_i386.deb
      Size/MD5:   200710 285e9c4c914f5ecca01c2e10b67b33ea
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-prefork-dev_2.0.54-5ubuntu4_i386.deb
      Size/MD5:   169308 50cec1ff79575b208a72397dc8b7f7f3
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-threaded-dev_2.0.54-5ubuntu4_i386.deb
      Size/MD5:   170050 f87ac4324738b07aad1e98348c81c6b0
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-utils_2.0.54-5ubuntu4_i386.deb
      Size/MD5:    91312 47b5f83da69812066513000b0b41d2ac
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2_2.0.54-5ubuntu4_i386.deb
      Size/MD5:    35008 f609ef4c84ec1f2cc1b208ccd090b852
    http://security.ubuntu.com/ubuntu/pool/universe/a/apache/apache_1.3.33-8ubuntu1_i386.deb
      Size/MD5:   383510 6ea2eab8114d8b98ad92495e0bd6482e
    http://security.ubuntu.com/ubuntu/pool/universe/a/apache/libapache-mod-perl_1.29.0.3-8ubuntu1_i386.deb
      Size/MD5:   488900 c14399ebc205896ed564c25b5caf5140
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/libapr0-dev_2.0.54-5ubuntu4_i386.deb
      Size/MD5:   259618 6a4827f36c6ffc570d51acf07b6fce91
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/libapr0_2.0.54-5ubuntu4_i386.deb
      Size/MD5:   131098 9d7230a6c28716ed0312fd4aa329ff77

  powerpc architecture (Apple Macintosh G3/G4/G5)

    http://security.ubuntu.com/ubuntu/pool/universe/a/apache/apache-common_1.3.33-8ubuntu1_powerpc.deb
      Size/MD5:   916804 73b3193a58736eb9bcb0a5c80ecd8a93
    http://security.ubuntu.com/ubuntu/pool/universe/a/apache/apache-dbg_1.3.33-8ubuntu1_powerpc.deb
      Size/MD5:  8717248 94937cc19dbec615f5cd6044a2fa507a
    http://security.ubuntu.com/ubuntu/pool/universe/a/apache/apache-perl_1.3.33-8ubuntu1_powerpc.deb
      Size/MD5:   522470 bd55c7b338c4c4f73ebd8f04986ce2c1
    http://security.ubuntu.com/ubuntu/pool/universe/a/apache/apache-ssl_1.3.33-8ubuntu1_powerpc.deb
      Size/MD5:   514840 a58275590f4268ffdf0a4c886bf6bbad
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-common_2.0.54-5ubuntu4_powerpc.deb
      Size/MD5:   854038 c27922832b31bef8649cd7159625dd89
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-mpm-perchild_2.0.54-5ubuntu4_powerpc.deb
      Size/MD5:   218214 d020ea657485fb2bd2a290443bb6b8f5
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-mpm-prefork_2.0.54-5ubuntu4_powerpc.deb
      Size/MD5:   213860 375246f469c00900018061186aaa1e0c
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-mpm-worker_2.0.54-5ubuntu4_powerpc.deb
      Size/MD5:   217386 2c5b73c348aa1ae513dc40584d3e2789
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-prefork-dev_2.0.54-5ubuntu4_powerpc.deb
      Size/MD5:   169302 9060652d8386e05fb36bdf77ffebfe05
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-threaded-dev_2.0.54-5ubuntu4_powerpc.deb
      Size/MD5:   170042 2eca7805b3285db87db07ba8daa09c17
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-utils_2.0.54-5ubuntu4_powerpc.deb
      Size/MD5:   103298 2abd2af3fe90b06bcd3de996f9aeaa03
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2_2.0.54-5ubuntu4_powerpc.deb
      Size/MD5:    35012 57821d6ed956a238b5b13393411e4918
    http://security.ubuntu.com/ubuntu/pool/universe/a/apache/apache_1.3.33-8ubuntu1_powerpc.deb
      Size/MD5:   402864 e287ea1bc261db4b0bce941dd1c22b5e
    http://security.ubuntu.com/ubuntu/pool/universe/a/apache/libapache-mod-perl_1.29.0.3-8ubuntu1_powerpc.deb
      Size/MD5:   491414 d232929639d3a9636e574e8573c33179
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/libapr0-dev_2.0.54-5ubuntu4_powerpc.deb
      Size/MD5:   278878 6c3647225a81c8842dfd8927e650c10b
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/libapr0_2.0.54-5ubuntu4_powerpc.deb
      Size/MD5:   140150 33185bae3bf5a0a6c481316f2c599ae8

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.2 (GNU/Linux)

iD8DBQFDxiHVvjztR8bOoMkRAg8MAKChvXGqQJEvpIemLbBEuEgQP+MLdQCgt6OZ
o/Dx4HiQL3h4wh3koibkr2c=
=xB5i
-----END PGP SIGNATURE-----
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


  By Date           By Thread  

Current thread:
  • [USN-241-1] Apache vulnerabilities Adam Conrad (Jan 12)
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]