Re: [SRM] Please review apache2 2.2.3-4+etch3

2007-09-20 Thread Martin Schulze
Martin Zobel-Helas wrote: Hi, Considering that there is already an update pending for etch r2, and that CVE-2007-3847 is of similar severity as the issues fixed in 2.2.3-4+etch2, I think it makes sense to upload +etch3 to s-p-u, too. Martin Schulze agreed to this. Security team,

[SRM] Please review apache2 2.2.3-4+etch3

2007-09-19 Thread Stefan Fritsch
Hi SRM, please review apache2 2.2.3-4+etch3 for inclusion in etch r2: apache2 (2.2.3-4+etch3) stable; urgency=low * fix CVE-2007-3847: DoS in mod_proxy (for threaded MPMs) (Closes: #441845) * Don't eat all memory on graceful restart when config has changed from many listening