New Debian apache2 2.4.59-1~deb10u4A~5.0.9.202411181233 fixes: This update addresses the following issue: 2.4.59-1~deb10u4 (Sat, 19 Oct 2024 12:44:34 +0000) * Team upload by ELTS team * Fix CVE-2024-38473: Encoding problem in mod_proxy allowed request URLs with incorrect encoding to be sent to backend services, potentially bypassing authentication via crafted requests * Fix a regression for CVE-2024-38473: Log error: AH01059: error parsing URL //: Invalid host/port that broke sympa and configuration line SetHandler "proxy:unix:/run/sympa/wwsympa.socket|fcgi://" * Fix a regression for CVE-2024-38473: After the update "アダプタ/index.php" is encoded to "%E3%82%A2%E3%83%80%E3%83%97%E3%82%BF/index.php" in the filesystem.
--- mirror/ftp/pool/main/a/apache2/apache2_2.4.59-1~deb10u3A~5.0.9.202409251402.dsc +++ apt/ucs_5.0-0-errata5.0-9/source/apache2_2.4.59-1~deb10u4A~5.0.9.202411181233.dsc @@ -1,7 +1,24 @@ -2.4.59-1~deb10u3A~5.0.9.202409251402 [Wed, 25 Sep 2024 14:03:40 -0000] Univention builddaemon <buildd@univention.de>: +2.4.59-1~deb10u4A~5.0.9.202411181233 [Mon, 18 Nov 2024 12:33:51 -0000] Univention builddaemon <buildd@univention.de>: * UCS auto build. The following patches have been applied to the original source package 20-no-proxy.patch + +2.4.59-1~deb10u4 [Sat, 19 Oct 2024 12:44:34 +0000] Bastien Roucariès <rouca@debian.org>: + + * Team upload by ELTS team + * Fix CVE-2024-38473: + Encoding problem in mod_proxy allowed request URLs with + incorrect encoding to be sent to backend services, + potentially bypassing authentication via crafted requests + * Fix a regression for CVE-2024-38473 (Closes: #1076554): + Log error: AH01059: error parsing URL //: Invalid host/port + that broke sympa and configuration line + SetHandler "proxy:unix:/run/sympa/wwsympa.socket|fcgi://" + * Fix a regression for CVE-2024-38473 (Closes: #1079171): + After the update "アダプタ/index.php" + is encoded to + "%E3%82%A2%E3%83%80%E3%83%97%E3%82%BF/index.php" + in the filesystem. 2.4.59-1~deb10u3 [Mon, 16 Sep 2024 20:34:52 +0000] Bastien Roucariès <rouca@debian.org>: <http://piuparts.knut.univention.de/5.0-9/#3021770430856611411>
OK: bug OK: yaml OK: announce_errata OK: patch OK: piuparts [5.0-9] c1e0633572 Bug #57752: apache2 2.4.59-1~deb10u4A~5.0.9.202411181233 doc/errata/staging/apache2.yaml | 13 +++++++++++++ 1 file changed, 13 insertions(+)
<https://errata.software-univention.de/#/?erratum=5.0x1175>