[Git][security-tracker-team/security-tracker][master] apache2 fixed in sid
Moritz Muehlenhoff (@jmm)
jmm at debian.org
Fri Jun 12 10:26:17 BST 2026
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
f01d476a by Moritz Muehlenhoff at 2026-06-12T11:25:58+02:00
apache2 fixed in sid
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -3082,7 +3082,7 @@ CVE-2026-49233 (Routinator does not properly check the module component of rsync
CVE-2026-49232 (Routinator exits on any error when accepting incoming HTTP or RTR conn ...)
- routinator <itp> (bug #929024)
CVE-2026-48913 (Use After Free vulnerability in Apache HTTP Server module mod_http2 wh ...)
- - apache2 <unfixed> (bug #1139340)
+ - apache2 2.4.68-1 (bug #1139340)
[trixie] - apache2 <no-dsa> (Minor issue)
[bookworm] - apache2 <no-dsa> (Minor issue)
NOTE: https://httpd.apache.org/security/vulnerabilities_24.html#CVE-2026-48913
@@ -3128,25 +3128,25 @@ CVE-2026-46440 (Flowise is a drag & drop user interface to build a customized la
CVE-2026-45581 (fabric-chaincode-java is a Java based implementation of Hyperledger Fa ...)
NOT-FOR-US: fabric-chaincode-java
CVE-2026-44631 (Buffer Underwrite vulnerability in Apache HTTP Server on crafted regul ...)
- - apache2 <unfixed> (bug #1139340)
+ - apache2 2.4.68-1 (bug #1139340)
[trixie] - apache2 <no-dsa> (Minor issue)
[bookworm] - apache2 <no-dsa> (Minor issue)
NOTE: https://httpd.apache.org/security/vulnerabilities_24.html#CVE-2026-44631
NOTE: Fixed by: https://github.com/apache/httpd/commit/7d9f3cfb10b0fe70df7358d26d7b1f374ea1a0cb (2.4.68-rc1-candidate)
CVE-2026-44186 (Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability i ...)
- - apache2 <unfixed> (bug #1139340)
+ - apache2 2.4.68-1 (bug #1139340)
[trixie] - apache2 <no-dsa> (Minor issue)
[bookworm] - apache2 <no-dsa> (Minor issue)
NOTE: https://httpd.apache.org/security/vulnerabilities_24.html#CVE-2026-44186
NOTE: Fixed by: https://github.com/apache/httpd/commit/414de374a06549b2c6710cbcff81c3821379f75c (2.4.68-rc1-candidate)
CVE-2026-44185 (Buffer Over-read vulnerability in Apache HTTP Server via outbound OCSP ...)
- - apache2 <unfixed> (bug #1139340)
+ - apache2 2.4.68-1 (bug #1139340)
[trixie] - apache2 <no-dsa> (Minor issue)
[bookworm] - apache2 <no-dsa> (Minor issue)
NOTE: https://httpd.apache.org/security/vulnerabilities_24.html#CVE-2026-44185
NOTE: Fixed by: https://github.com/apache/httpd/commit/32b7e2e66477020ba75b78ab43fb8890ec292ad2 (2.4.68-rc1-candidate)
CVE-2026-44119 (Improper Privilege Management vulnerability in Apache HTTP Server 2.4. ...)
- - apache2 <unfixed> (bug #1139340)
+ - apache2 2.4.68-1 (bug #1139340)
[trixie] - apache2 <no-dsa> (Minor issue)
[bookworm] - apache2 <no-dsa> (Minor issue)
NOTE: https://httpd.apache.org/security/vulnerabilities_24.html#CVE-2026-44119
@@ -3160,7 +3160,7 @@ CVE-2026-43972 (Origin Validation Error vulnerability in ninenines gun (gun_http
CVE-2026-43966 (Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Reque ...)
TODO: check
CVE-2026-43951 (Out-of-bounds Read vulnerability in Apache HTTP Server with mod_header ...)
- - apache2 <unfixed> (bug #1139340)
+ - apache2 2.4.68-1 (bug #1139340)
[trixie] - apache2 <no-dsa> (Minor issue)
[bookworm] - apache2 <no-dsa> (Minor issue)
NOTE: https://httpd.apache.org/security/vulnerabilities_24.html#CVE-2026-43951
@@ -3172,14 +3172,14 @@ CVE-2026-42862 (Flowise is a drag & drop user interface to build a customized la
CVE-2026-42861 (Flowise is a drag & drop user interface to build a customized large la ...)
NOT-FOR-US: Flowise
CVE-2026-42536 (Heap-based Buffer Overflow vulnerability in Apache HTTP Server withmod ...)
- - apache2 <unfixed> (bug #1139340)
+ - apache2 2.4.68-1 (bug #1139340)
[trixie] - apache2 <no-dsa> (Minor issue)
[bookworm] - apache2 <no-dsa> (Minor issue)
NOTE: https://httpd.apache.org/security/vulnerabilities_24.html#CVE-2026-42536
NOTE: Fixed by: https://github.com/apache/httpd/commit/fa5d85bbc832a587c3c5bca7c19fb21df96b5df0 (trunk)
NOTE: Fixed by: https://github.com/apache/httpd/commit/cb1f79c0ce66393c48657b19df754f16b79af543 (2.4.68-rc1-candidate)
CVE-2026-42535 (A path handling issue in mod_dav_fs in Apache 2.4.67 and earlierallows ...)
- - apache2 <unfixed> (bug #1139340)
+ - apache2 2.4.68-1 (bug #1139340)
[trixie] - apache2 <no-dsa> (Minor issue)
[bookworm] - apache2 <no-dsa> (Minor issue)
NOTE: https://httpd.apache.org/security/vulnerabilities_24.html#CVE-2026-42535
@@ -3204,14 +3204,14 @@ CVE-2026-36789 (Shenzhen Tenda Technology Co., Ltd Tenda AC1206 v15.03.06.23 was
CVE-2026-36786 (Shenzhen Tenda Technology Co., Ltd Tenda FH451 V1.0.0.9 was discovered ...)
NOT-FOR-US: Tenda
CVE-2026-34356 (Heap-based Buffer Overflow vulnerability in Apache HTTP Server with ma ...)
- - apache2 <unfixed> (bug #1139340)
+ - apache2 2.4.68-1 (bug #1139340)
[trixie] - apache2 <no-dsa> (Minor issue)
[bookworm] - apache2 <no-dsa> (Minor issue)
NOTE: https://httpd.apache.org/security/vulnerabilities_24.html#CVE-2026-34356
NOTE: Fixed by: https://github.com/apache/httpd/commit/403269396d24404e2576a9b20f96cd0b10574048 (2.4.68-rc1-candidate)
NOTE: Fixed by: https://github.com/apache/httpd/commit/a70753d294292e8c9f68758cfe3550d83f812129 (trunk)
CVE-2026-34355 (A buffer overflow in mod_proxy_html in Apache HTTP Server 2.4.67 and e ...)
- - apache2 <unfixed> (bug #1139340)
+ - apache2 2.4.68-1 (bug #1139340)
[trixie] - apache2 <no-dsa> (Minor issue)
[bookworm] - apache2 <no-dsa> (Minor issue)
NOTE: https://httpd.apache.org/security/vulnerabilities_24.html#CVE-2026-34355
@@ -3219,14 +3219,14 @@ CVE-2026-34355 (A buffer overflow in mod_proxy_html in Apache HTTP Server 2.4.67
CVE-2026-34194 (Software installed and run as a non-privileged user may conduct improp ...)
NOT-FOR-US: Imagination Technologies
CVE-2026-29170 (A cross-site scripting vulnerability exists in mod_proxy_ftp's HTML di ...)
- - apache2 <unfixed> (bug #1139340)
+ - apache2 2.4.68-1 (bug #1139340)
[trixie] - apache2 <no-dsa> (Minor issue)
[bookworm] - apache2 <no-dsa> (Minor issue)
NOTE: https://httpd.apache.org/security/vulnerabilities_24.html#CVE-2026-29170
NOTE: Fixed by: https://github.com/apache/httpd/commit/e86bf540f166b3a322f7e7f9cd4aad4cd44deee6 (trunk)
NOTE: Fixed by: https://github.com/apache/httpd/commit/04641bce75a2734ad8150f9a6bc84fc5205e852b (2.4.68-rc1-candidate)
CVE-2026-29167 (Use After Free vulnerability in Apache HTTP Server with mod_ldap in pe ...)
- - apache2 <unfixed> (bug #1139340)
+ - apache2 2.4.68-1 (bug #1139340)
[trixie] - apache2 <no-dsa> (Minor issue)
[bookworm] - apache2 <no-dsa> (Minor issue)
NOTE: https://httpd.apache.org/security/vulnerabilities_24.html#CVE-2026-29167
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/f01d476a975691888c6e7378157087ec588dc8cd
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/f01d476a975691888c6e7378157087ec588dc8cd
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260612/c791c22e/attachment.htm>
More information about the debian-security-tracker-commits
mailing list