Re: Apache 2.4.39 in Buster ?

2019-04-04 Thread Stefan Fritsch
Hi, On Tuesday, 2 April 2019 22:21:31 CEST Xavier wrote: > New Apache 2.4.39 fixes many bugs (including 5 CVEs [1]) with only 2 > minor new features. Do you think it is a good idea to upgrade Apache > version in Buster or do you prefer a 2.4.38 with 2.4.39 fixes (means > 2.4.39 without ~2 commits)

apache2_2.4.25-3+deb9u7_amd64.changes ACCEPTED into proposed-updates->stable-new, proposed-updates

2019-04-04 Thread Debian FTP Masters
Accepted: -BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Format: 1.8 Date: Tue, 02 Apr 2019 21:05:13 +0200 Source: apache2 Binary: apache2 apache2-data apache2-bin apache2-utils apache2-suexec-pristine apache2-suexec-custom apache2-doc apache2-dev apache2-ssl-dev apache2-dbg Architecture: so

Bug#920302: marked as done (apache2: CVE-2018-17189: mod_http2, DoS via slow, unneeded request bodies)

2019-04-04 Thread Debian Bug Tracking System
Your message dated Fri, 05 Apr 2019 05:32:08 + with message-id and subject line Bug#920302: fixed in apache2 2.4.25-3+deb9u7 has caused the Debian Bug report #920302, regarding apache2: CVE-2018-17189: mod_http2, DoS via slow, unneeded request bodies to be marked as done. This means that you

Bug#920303: marked as done (apache2: CVE-2018-17199: mod_session_cookie does not respect expiry time)

2019-04-04 Thread Debian Bug Tracking System
Your message dated Fri, 05 Apr 2019 05:32:09 + with message-id and subject line Bug#920303: fixed in apache2 2.4.25-3+deb9u7 has caused the Debian Bug report #920303, regarding apache2: CVE-2018-17199: mod_session_cookie does not respect expiry time to be marked as done. This means that you

Bug#915103: marked as done (Apache2 HTTP/2 connection problems with Safari clients)

2019-04-04 Thread Debian Bug Tracking System
Your message dated Fri, 05 Apr 2019 05:32:08 + with message-id and subject line Bug#915103: fixed in apache2 2.4.25-3+deb9u7 has caused the Debian Bug report #915103, regarding Apache2 HTTP/2 connection problems with Safari clients to be marked as done. This means that you claim that the prob

Bug#904150: marked as done (apache2: typo in maintainer script)

2019-04-04 Thread Debian Bug Tracking System
Your message dated Fri, 05 Apr 2019 05:32:08 + with message-id and subject line Bug#904150: fixed in apache2 2.4.25-3+deb9u7 has caused the Debian Bug report #904150, regarding apache2: typo in maintainer script to be marked as done. This means that you claim that the problem has been dealt w

Bug#926432: apache2: Internal error: error fetching from cache 'dbm:/var/cache/apache2/gnutls_cache'

2019-04-04 Thread Xavier
Le 03/04/2019 à 14:40, Damir R. Islamov a écrit : > Package: apache2 > Version: 2.4.38-2 > Severity: normal > > Dear Maintainer, > > After update to aapche 2.4.38-1 /var/log/apache2/error.log has a lot of > errors like > > [gnutls:warn] [pid 6466:tid 140230002730752] (20014)Internal error (spec

Bug#915103: Apache2 HTTP/2 connection problems with Safari clients

2019-04-04 Thread Manu
Looks like this is fixed in 2.4.25-3+deb9u7. Safari is not dropping http2 requests any more. > This update also contains bug fixes that were scheduled for inclusion in the > next stable point release. This includes a fix for a regression caused by a > security fix in version 2.4.25-3+deb9u6. h

Bug#926432: apache2: Internal error: error fetching from cache 'dbm:/var/cache/apache2/gnutls_cache'

2019-04-04 Thread Damir R. Islamov
Package: apache2 Version: 2.4.38-2 Severity: normal Dear Maintainer, After update to aapche 2.4.38-1 /var/log/apache2/error.log has a lot of errors like [gnutls:warn] [pid 6466:tid 140230002730752] (20014)Internal error (specific information not available): error fetching from cache 'dbm:/var

Bug#926433: apache2: Invalid HTTP request to ocsp.int-x3.letsencrypt.org

2019-04-04 Thread Damir R. Islamov
Package: apache2 Version: 2.4.38-2 Severity: normal Dear Maintainer, After apache update to 2.4.38-1 /var/log/apache2/error.log has a lot of errors on each vhost like: [gnutls:error] [pid 6466:tid 140231699207936] Invalid HTTP response status from ocsp.int-x3.letsencrypt.org: HTTP/1.0 400 Bad R

Bug#926400: libapr1-dbd-mysql: apache fails to start if dbd with mysql is used

2019-04-04 Thread cstamas
Package: libaprutil1-dbd-mysql Version: 1.6.1-3+b2 Severity: important Hi, apache2ctl start leads to this error message: AH00526: Syntax error on line 19 of /etc/apache2/sites-enabled/mydomain.conf: Can't load driver file apr_dbd_mysql.so Action 'start' failed. The Apache error log may have more