Your message dated Thu, 10 Dec 2020 19:18:33 +0000
with message-id <[email protected]>
and subject line Bug#970833: fixed in modsecurity-apache 2.9.3-3
has caused the Debian Bug report #970833,
regarding libapache2-mod-security2: Segfault when using SecRemoteRules
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
970833: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=970833
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Package: libapache2-mod-security2
Version: 2.9.3-2
Severity: normal

Dear Maintainer,

When SecRemoteRules are configured, Apache segfaults.

Removing the SecRemoteRules configuration lines resolves the problem.

This appears to be a known issue in modsecurity 2.9.3 - 
https://github.com/SpiderLabs/ModSecurity/issues/1982 with an available patch 
there to fix this.

https://github.com/SpiderLabs/ModSecurity/commit/52532a1bce0b705c0aa4365fecf727b836d37f00

-- System Information:
Debian Release: 10.5
  APT prefers stable-updates
  APT policy: (500, 'stable-updates'), (500, 'stable'), (500, 'oldstable')
Architecture: amd64 (x86_64)

Kernel: Linux 4.19.0-9-amd64 (SMP w/4 CPU cores)
Locale: LANG=en_NZ.UTF-8, LC_CTYPE=en_NZ.UTF-8 (charmap=UTF-8), 
LANGUAGE=en_NZ:en (charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash
Init: systemd (via /run/systemd/system)
LSM: AppArmor: enabled

Versions of packages libapache2-mod-security2 depends on:
ii  apache2-bin [apache2-api-20120211]  2.4.46-1~bpo10+1
ii  libapr1                             1.6.5-1+b1
ii  libaprutil1                         1.6.1-4
ii  libc6                               2.28-10
ii  libcurl3-gnutls                     7.64.0-4+deb10u1
ii  liblua5.1-0                         5.1.5-8.1+b2
ii  libpcre3                            2:8.39-12
ii  libxml2                             2.9.4+dfsg1-7+b3
ii  libyajl2                            2.1.0-3

Versions of packages libapache2-mod-security2 recommends:
ii  modsecurity-crs  3.1.0-1+deb10u1

libapache2-mod-security2 suggests no packages.

-- no debconf information

--- End Message ---
--- Begin Message ---
Source: modsecurity-apache
Source-Version: 2.9.3-3
Done: Alberto Gonzalez Iniesta <[email protected]>

We believe that the bug you reported is fixed in the latest version of
modsecurity-apache, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Alberto Gonzalez Iniesta <[email protected]> (supplier of updated 
modsecurity-apache package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

Format: 1.8
Date: Thu, 10 Dec 2020 19:14:15 +0100
Source: modsecurity-apache
Architecture: source
Version: 2.9.3-3
Distribution: unstable
Urgency: medium
Maintainer: Alberto Gonzalez Iniesta <[email protected]>
Changed-By: Alberto Gonzalez Iniesta <[email protected]>
Closes: 970833
Changes:
 modsecurity-apache (2.9.3-3) unstable; urgency=medium
 .
   * Add upstream patch to fix Segfault when using SecRemoteRules.
     (Closes: #970833)
Checksums-Sha1:
 656e392414ae1b9bb398c5af2cdeac58f45cdfad 1958 modsecurity-apache_2.9.3-3.dsc
 6b716e5655ca30385c4bfaa8fee1a55266129907 8828 
modsecurity-apache_2.9.3-3.debian.tar.xz
 cd3f412a90726f234de2b2374dc74cc34e8ff942 7752 
modsecurity-apache_2.9.3-3_amd64.buildinfo
Checksums-Sha256:
 18bb427411d9d419b27b7c6808bd7892e15f44799350485c5abe64b211569c89 1958 
modsecurity-apache_2.9.3-3.dsc
 a3bfbfb69cb2b6156990ac9d9a38b42461d5dd73af862985ff2b8cb7e938338a 8828 
modsecurity-apache_2.9.3-3.debian.tar.xz
 e7c38f63ca69eda1fdacca2c3ce721c50786b50bb439038a0dcd6afe68391b4a 7752 
modsecurity-apache_2.9.3-3_amd64.buildinfo
Files:
 f8ebabf1586540ff170334bb109824a7 1958 httpd optional 
modsecurity-apache_2.9.3-3.dsc
 8a3ac6aa5e6dbb1d61fbc0b1cced5d19 8828 httpd optional 
modsecurity-apache_2.9.3-3.debian.tar.xz
 105d216500224388d01d51cfc0a45df8 7752 httpd optional 
modsecurity-apache_2.9.3-3_amd64.buildinfo

-----BEGIN PGP SIGNATURE-----

iQJEBAEBCAAuFiEEU0fL2D4wqetNfUvyAJszdWuaqlUFAl/Sbe8QHGFnaUBpbml0
dGFiLm9yZwAKCRAAmzN1a5qqVYeDD/9FaSjvHk3x6e8or7E2m/zSKHXZx+qYwVkz
kUUDdsiEvg1t0W776+2mp1xWo8Xa/zGNe6uSMuTtaQIjn6JWAOaON3zVUyrZRuGf
ipeI8MTlTZg7QZBWzBynxCqjKxaFmnfq991Ccyxn6yIsCu694RiHI6hTEdUwvrkU
LVypM06TF8T0y9f7n40qHkatT4aJ27dMjTm/VDI03KHutNNn08OCBnc40Skf6d3j
EEKsvjaaw2jly1/UvN76tAov6P9TQ+Xz5Mb48q4bm5HAACIQ7CUw64ruagA68EIU
j57msYpGhp2EicwzBEdCbvj4lEFpXCtLGjSRt0N+Un95Jgp0s8Iv4BRr89dPuCHG
dYOJVGwQ+t0CxhIuNrSFwlUOcQ4kyKdE5KXerowdyxs+k4ANJ8MaNI1pemQREM5x
jmbe2U8xwpX3APCPqzBqtM8FFmPKGxhcqfoi+z3ObLcJo154f46ZI9VHSwnD5wZH
WK1VrDsU0xx3IbbQRRCSRTWqzEdJNviMcsVr57mPvnijgNDE5Fpjl4yW1FFRPVeu
rPLNKtzyoUZAQwKHfPrWMjAs5i3qstdorn95B5WkT6NxTNIvyNfw6ewLDO5Xn8Ux
TO/mwCbgjsm2qrpOr5oOP+9XJUeLRxijt8PSLx7bJgLt/Rrjj2LT+lAhGPxgrovO
7fLmumiTOw==
=fgYY
-----END PGP SIGNATURE-----

--- End Message ---

Reply via email to