Bug#881725: apache2: reload fails inside (libvirt) lxc container

2018-04-16 Thread Moritz Mühlenhoff
On Mon, Apr 16, 2018 at 02:34:00PM -0400, Matthew Gabeler-Lee wrote: > On Sat, 14 Apr 2018, Stefan Fritsch wrote: > > > This seems to be a systemd bug. Changing PrivateTmp from true to false in > > apache2.service fixes the issue. But even with PrivateTmp it works for > > some time. It would be in

Bug#995368: libapache2-mod-proxy-uwsgi 2.0.14+20161117-3+deb9u4 - duplicated request path

2021-10-05 Thread Moritz Mühlenhoff
reassign 995368 uwsgi thanks Am Fri, Oct 01, 2021 at 04:16:05PM +0200 schrieb Josef Kejzlar, wpj s.r.o.: > I can confirm this regression. > After unattended security upgrades got applied during the night, all > our applications stopped working. > > There is wrong request path sent to uwsgi server

Bug#1012513: apache2: CVE-2022-31813 CVE-2022-26377 CVE-2022-28614 CVE-2022-28615 CVE-2022-29404 CVE-2022-30522 CVE-2022-30556

2022-06-08 Thread Moritz Mühlenhoff
Source: apache2 X-Debbugs-CC: t...@security.debian.org Severity: grave Tags: security Hi, The following vulnerabilities were published for apache2. CVE-2022-31813[0]: | Apache HTTP Server 2.4.53 and earlier may not send the X-Forwarded-* | headers to the origin server based on client side Connec

Bug#1068412: apache2: CVE-2024-27316 CVE-2024-24795 CVE-2023-38709

2024-04-04 Thread Moritz Mühlenhoff
Source: apache2 X-Debbugs-CC: t...@security.debian.org Severity: grave Tags: security Hi, The following vulnerabilities were published for apache2. CVE-2024-27316[0]: https://www.kb.cert.org/vuls/id/421644 https://www.openwall.com/lists/oss-security/2024/04/04/4 CVE-2024-24795[1]: https://www.o

Re: Passing LDFLAGS to Apache modules for hardened build flags

2012-04-14 Thread Moritz Mühlenhoff
On Mon, Apr 09, 2012 at 10:15:23PM +0200, Arno Töll wrote: > Hi Moritz, > > On 08.04.2012 22:10, Moritz Muehlenhoff wrote: > > Hi, > > I'm working on hardened build flags for Squeeze and I'm looking into > > how to pass hardened build flags to Apache modules. > > Perhaps we should add hardening

Re: Passing LDFLAGS to Apache modules for hardened build flags

2012-04-16 Thread Moritz Mühlenhoff
On Sat, Apr 14, 2012 at 04:50:44PM +0200, Arno Töll wrote: > On 14.04.2012 16:42, Moritz Mühlenhoff wrote: > > I can rebuild the Apache modules in the archive with test builds if that > > helps. > > I committed a fix to apxs in our VCS yesterday [1]. This will allow you >

Re: Passing LDFLAGS to Apache modules for hardened build flags

2012-05-27 Thread Moritz Mühlenhoff
On Mon, Apr 16, 2012 at 05:37:24PM +0200, Moritz Mühlenhoff wrote: > On Sat, Apr 14, 2012 at 04:50:44PM +0200, Arno Töll wrote: > > On 14.04.2012 16:42, Moritz Mühlenhoff wrote: > > > I can rebuild the Apache modules in the archive with test builds if that > > > helps.