DSA-1934-1

NameDSA-1934-1
SourceDebian
Descriptionapache2 - several issues
ReferencesCVE-2009-3094, CVE-2009-3095, CVE-2009-3555
Debian/oldstablepackage apache2 is fixed in oldstable-security.
Debian/stablenot vulnerable
Debian/testingnot known to be vulnerable
Debian/unstablenot known to be vulnerable.

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
apache2 (PTS)etch2.2.3-4+etch6vulnerable
etch (security)2.2.3-4+etch11fixed
lenny, lenny (security)2.2.9-10+lenny6fixed

The next table lists affected binary packages.

Binary PackageReleaseVersionStatusArchitecures
apache2, apache2-doc, apache2-mpm-perchild, apache2-srcetch2.2.3-4+etch6vulnerableall
etch (security)2.2.3-4+etch11fixedall
apache2, apache2-doc, apache2-srclenny, lenny (security)2.2.9-10+lenny6fixedall
apache2-dbg, apache2-mpm-event, apache2-mpm-prefork, apache2-mpm-worker, apache2-prefork-dev, apache2-suexec, apache2-suexec-custom, apache2-threaded-dev, apache2-utils, apache2.2-commonlenny, lenny (security)2.2.9-10+lenny6fixedalpha, amd64, arm, armel, hppa, i386, ia64, mips, mipsel, powerpc, s390, sparc
apache2-mpm-event, apache2-mpm-prefork, apache2-mpm-worker, apache2-prefork-dev, apache2-threaded-dev, apache2-utils, apache2.2-commonetch2.2.3-4+etch6vulnerablealpha, amd64, arm, hppa, i386, ia64, mips, mipsel, powerpc, s390, sparc
etch (security)2.2.3-4+etch11fixedalpha, amd64, arm, hppa, i386, ia64, mips, mipsel, powerpc, s390, sparc

The information above is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
apache2sourceetch2.2.3-4+etch11unknown
apache2sourcelenny2.2.9-10+lenny6unknown

Search for package or bug name: Reporting problems

Home - Testing Security Team - Debian Security - Imprint