Package: apache2
Version: 2.4.61-1~deb12u1
Severity: important

Dear Maintainer,

Following DSA 5729-1 (2.4.61-1~deb12u1), access to Sympa broke.
User error: Bad Request
Log error: AH01059: error parsing URL //: Invalid host/port

I believe the issue is related to this line:
  SetHandler "proxy:unix:/run/sympa/wwsympa.socket|fcgi://"
This is the default configuration from the sympa Debian package.

I get the same result when compiling the debdiff from:
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1076531
(2.4.62)

I can work-around the issue by appending 'localhost':
  SetHandler "proxy:unix:/run/sympa/wwsympa.socket|fcgi://localhost"
(but this is still a regression in the stable release :))

-- Package-specific info:

-- System Information:
Debian Release: 12.6
  APT prefers stable
  APT policy: (500, 'stable')
Architecture: amd64 (x86_64)

Kernel: Linux 6.1.0-23-cloud-amd64 (SMP w/1 CPU thread; PREEMPT)
Locale: LANG=fr_FR.UTF-8, LC_CTYPE=fr_FR.UTF-8 (charmap=UTF-8), LANGUAGE not set
Shell: /bin/sh linked to /usr/bin/dash
Init: systemd (via /run/systemd/system)
LSM: AppArmor: enabled

Versions of packages apache2 depends on:
ii  apache2-bin                2.4.62-1~deb12u1~local
ii  apache2-data               2.4.62-1~deb12u1~local
ii  apache2-utils              2.4.62-1~deb12u1~local
ii  init-system-helpers        1.65.2
ii  lsb-base                   11.6
ii  media-types                10.0.0
ii  perl                       5.36.0-7+deb12u1
ii  procps                     2:4.0.2-3
ii  sysvinit-utils [lsb-base]  3.06-4

Versions of packages apache2 recommends:
ii  ssl-cert  1.1.2

Versions of packages apache2 suggests:
pn  apache2-doc              <none>
ii  apache2-suexec-pristine  2.4.62-1~deb12u1~local
pn  www-browser              <none>

Versions of packages apache2-bin depends on:
ii  libapr1                  1.7.2-3
ii  libaprutil1              1.6.3-1
ii  libaprutil1-dbd-sqlite3  1.6.3-1
ii  libaprutil1-ldap         1.6.3-1
ii  libbrotli1               1.0.9-2+b6
ii  libc6                    2.36-9+deb12u7
ii  libcrypt1                1:4.4.33-2
ii  libcurl4                 7.88.1-10+deb12u6
ii  libjansson4              2.14-2
ii  libldap-2.5-0            2.5.13+dfsg-5
ii  liblua5.3-0              5.3.6-2
ii  libnghttp2-14            1.52.0-1+deb12u1
ii  libpcre2-8-0             10.42-1
ii  libssl3                  3.0.13-1~deb12u1
ii  libxml2                  2.9.14+dfsg-1.3~deb12u1
ii  perl                     5.36.0-7+deb12u1
ii  zlib1g                   1:1.2.13.dfsg-1

Versions of packages apache2-bin suggests:
pn  apache2-doc              <none>
ii  apache2-suexec-pristine  2.4.62-1~deb12u1~local
pn  www-browser              <none>

Versions of packages apache2 is related to:
ii  apache2      2.4.62-1~deb12u1~local
ii  apache2-bin  2.4.62-1~deb12u1~local

-- no debconf information

Reply via email to