Re: Apache2 CVE-2016-4975

2018-08-16 Thread Markus Koschany
Hi Stefan, Am 16.08.2018 um 21:13 schrieb Stefan Fritsch: [...] > In jessie this has been included in 2.4.10-10+deb8u8 and Antoine did the > heroic backport to wheezy. So, there should not be anything to to fix in > Debian. Excellent. Thank you very much for your confirmation. Best, Markus

Re: Apache2 CVE-2016-4975

2018-08-16 Thread Stefan Fritsch
Hi Markus, On Wednesday, 15 August 2018 21:22:40 CEST Markus Koschany wrote: > I am currently investigating CVE-2016-4975 for Apache2. The issue is > already two years old but was only made public yesterday. [1] I skimmed > through old commit messages but I could not isolate the fixing commit. > H

Re: Apache2 CVE-2016-4975

2018-08-16 Thread Jan Ingvoldstad
On 2018-08-16 10:12, Moritz Muehlenhoff wrote: On Thu, Aug 16, 2018 at 05:12:11PM +1000, Brian May wrote: Note: This is only being sent to debian-LTS. I am currently investigating CVE-2016-4975 for Apache2. The issue is already two years old but was only made public yesterday. [1] I skimmed th

Re: Apache2 CVE-2016-4975

2018-08-16 Thread Moritz Muehlenhoff
On Thu, Aug 16, 2018 at 05:12:11PM +1000, Brian May wrote: > Note: This is only being sent to debian-LTS. > > > I am currently investigating CVE-2016-4975 for Apache2. The issue is > > already two years old but was only made public yesterday. [1] I skimmed > > through old commit messages but I cou

Re: Apache2 CVE-2016-4975

2018-08-16 Thread Brian May
Note: This is only being sent to debian-LTS. > I am currently investigating CVE-2016-4975 for Apache2. The issue is > already two years old but was only made public yesterday. [1] I skimmed > through old commit messages but I could not isolate the fixing commit. > However I found this changelog en

Apache2 CVE-2016-4975

2018-08-15 Thread Markus Koschany
Hello Stefan, I am currently investigating CVE-2016-4975 for Apache2. The issue is already two years old but was only made public yesterday. [1] I skimmed through old commit messages but I could not isolate the fixing commit. However I found this changelog entry [2] from December 13th, 2016 and yo