[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Bug#639825: marked as done (Apache2 seek broken)



Your message dated Sun, 04 Sep 2011 21:02:36 +0000
with message-id <E1R0Jps-0007LE-9E@franck.debian.org>
and subject line Bug#639825: fixed in apache2 2.2.20-1
has caused the Debian Bug report #639825,
regarding Apache2 seek broken
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact owner@bugs.debian.org
immediately.)


-- 
639825: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=639825
Debian Bug Tracking System
Contact owner@bugs.debian.org with problems
--- Begin Message ---
Package: apache2.2-common
Version: 2.2.9-10+lenny10

Yesterday evenings update broke our Apache server setup, which is
serving video files. Our application uses partial GET's (Range:
byte=...) to implement seeking in the video. Seeking stopped working
this morning, I haven't figured out yet what exactly is going wrong,
but reverting to 2.2.9-10+lenny9 fixed the issue for me.

The patch fixing CVE-2011-3192 involves ranges, which gave me the
impression that this might have caused our seeking issues:
http://anonscm.debian.org/viewvc/pkg-apache/trunk/apache2/patches/083_CVE-2011-3192.dpatch?revision=1341&view=co
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3192

I am using an up-to-date Debian Lenny, with Linux kernel 2.6.26-2-686 #1 SMP.

I can provide strace output or any other useful information.

With friendly regards,
Takis



--- End Message ---
--- Begin Message ---
Source: apache2
Source-Version: 2.2.20-1

We believe that the bug you reported is fixed in the latest version of
apache2, which is due to be installed in the Debian FTP archive:

apache2-dbg_2.2.20-1_i386.deb
  to main/a/apache2/apache2-dbg_2.2.20-1_i386.deb
apache2-doc_2.2.20-1_all.deb
  to main/a/apache2/apache2-doc_2.2.20-1_all.deb
apache2-mpm-event_2.2.20-1_i386.deb
  to main/a/apache2/apache2-mpm-event_2.2.20-1_i386.deb
apache2-mpm-itk_2.2.20-1_i386.deb
  to main/a/apache2/apache2-mpm-itk_2.2.20-1_i386.deb
apache2-mpm-prefork_2.2.20-1_i386.deb
  to main/a/apache2/apache2-mpm-prefork_2.2.20-1_i386.deb
apache2-mpm-worker_2.2.20-1_i386.deb
  to main/a/apache2/apache2-mpm-worker_2.2.20-1_i386.deb
apache2-prefork-dev_2.2.20-1_i386.deb
  to main/a/apache2/apache2-prefork-dev_2.2.20-1_i386.deb
apache2-suexec-custom_2.2.20-1_i386.deb
  to main/a/apache2/apache2-suexec-custom_2.2.20-1_i386.deb
apache2-suexec_2.2.20-1_i386.deb
  to main/a/apache2/apache2-suexec_2.2.20-1_i386.deb
apache2-threaded-dev_2.2.20-1_i386.deb
  to main/a/apache2/apache2-threaded-dev_2.2.20-1_i386.deb
apache2-utils_2.2.20-1_i386.deb
  to main/a/apache2/apache2-utils_2.2.20-1_i386.deb
apache2.2-bin_2.2.20-1_i386.deb
  to main/a/apache2/apache2.2-bin_2.2.20-1_i386.deb
apache2.2-common_2.2.20-1_i386.deb
  to main/a/apache2/apache2.2-common_2.2.20-1_i386.deb
apache2_2.2.20-1.diff.gz
  to main/a/apache2/apache2_2.2.20-1.diff.gz
apache2_2.2.20-1.dsc
  to main/a/apache2/apache2_2.2.20-1.dsc
apache2_2.2.20-1_i386.deb
  to main/a/apache2/apache2_2.2.20-1_i386.deb
apache2_2.2.20.orig.tar.gz
  to main/a/apache2/apache2_2.2.20.orig.tar.gz



A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 639825@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Stefan Fritsch <sf@debian.org> (supplier of updated apache2 package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@debian.org)


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Format: 1.8
Date: Sun, 04 Sep 2011 21:50:22 +0200
Source: apache2
Binary: apache2.2-common apache2.2-bin apache2-mpm-worker apache2-mpm-prefork apache2-mpm-event apache2-mpm-itk apache2-utils apache2-suexec apache2-suexec-custom apache2 apache2-doc apache2-prefork-dev apache2-threaded-dev apache2-dbg
Architecture: source all i386
Version: 2.2.20-1
Distribution: unstable
Urgency: low
Maintainer: Debian Apache Maintainers <debian-apache@lists.debian.org>
Changed-By: Stefan Fritsch <sf@debian.org>
Description: 
 apache2    - Apache HTTP Server metapackage
 apache2-dbg - Apache debugging symbols
 apache2-doc - Apache HTTP Server documentation
 apache2-mpm-event - Apache HTTP Server - event driven model
 apache2-mpm-itk - multiuser MPM for Apache 2.2
 apache2-mpm-prefork - Apache HTTP Server - traditional non-threaded model
 apache2-mpm-worker - Apache HTTP Server - high speed threaded model
 apache2-prefork-dev - Apache development headers - non-threaded MPM
 apache2-suexec - Standard suexec program for Apache 2 mod_suexec
 apache2-suexec-custom - Configurable suexec program for Apache 2 mod_suexec
 apache2-threaded-dev - Apache development headers - threaded MPM
 apache2-utils - utility programs for webservers
 apache2.2-bin - Apache HTTP Server common binary files
 apache2.2-common - Apache HTTP Server common files
Closes: 639825
Changes: 
 apache2 (2.2.20-1) unstable; urgency=low
 .
   * New upstream release.
   * Fix some regressions related to Range requests caused by the CVE-2011-3192
     fix. Closes: #639825
   * Add build-arch and build-indep rules targets to make Lintian happy.
   * Bump Standards-Version (no changes).
Checksums-Sha1: 
 f48f99ed66e137c6bbe1f1ebd9ce5e8f9c16940b 1751 apache2_2.2.20-1.dsc
 5e670636e17286b7ae5ade5b7f5e21e686559e5a 6834233 apache2_2.2.20.orig.tar.gz
 a54692749d14c49e672299309544a70dac1bba7c 205609 apache2_2.2.20-1.diff.gz
 b36865ea1e64ebb2bf462385d25ecd4d3c116cb6 2661502 apache2-doc_2.2.20-1_all.deb
 ead58e9d016fa365aa727e0bb201efbcd02cca92 313156 apache2.2-common_2.2.20-1_i386.deb
 6e0b8d33dd51adc137d97f8281cd0ed6f4378361 1451664 apache2.2-bin_2.2.20-1_i386.deb
 3f8189021c276085ebf13c8f4f7d5b53581d7c0f 2186 apache2-mpm-worker_2.2.20-1_i386.deb
 9ed4866c709755dd534eeba03e0ad886d8e57226 2294 apache2-mpm-prefork_2.2.20-1_i386.deb
 626ce02b71def192c30bc008fd66f19e51ee1d5d 2254 apache2-mpm-event_2.2.20-1_i386.deb
 0b7eb8d9104009fe61daf1e724b37cb128805797 2282 apache2-mpm-itk_2.2.20-1_i386.deb
 d4a7289bfd391477d74f073c757fae65a4f3b8e2 168460 apache2-utils_2.2.20-1_i386.deb
 0256c45bd5dbf0446ad22f413a7942452f53a901 102458 apache2-suexec_2.2.20-1_i386.deb
 7719133133f6f2e672fe75d5e45fd787ba6e2dea 104086 apache2-suexec-custom_2.2.20-1_i386.deb
 a7ece7ce13767c849bde41922a3e9a296c341445 1380 apache2_2.2.20-1_i386.deb
 1264542ed9fa7d41bd675e2c655917a7bdb492ae 137754 apache2-prefork-dev_2.2.20-1_i386.deb
 aadebf4c1e10b2dfe88fac692bd84e14b93360af 138930 apache2-threaded-dev_2.2.20-1_i386.deb
 e76198242ae6cacf99a8005d339158ba68224ebc 2799846 apache2-dbg_2.2.20-1_i386.deb
Checksums-Sha256: 
 8583fb5d6fe74511497dc3ded90792b16ef5434855f1352ae00381a7f3ee74d4 1751 apache2_2.2.20-1.dsc
 0abb59689664ae4db5d1ee1ab4140715b87f889e81de2b4d9581c235594e2868 6834233 apache2_2.2.20.orig.tar.gz
 b12f770564aaf8b7aeb875fccbf45717b8e82cd5aaac2236b312e9979f0f80b4 205609 apache2_2.2.20-1.diff.gz
 e080b93ce22d357a637d3cb47ea19a355c260fdc81062f5c88ef5e21a47265df 2661502 apache2-doc_2.2.20-1_all.deb
 b79920bd522901c189ff9a4a1483061b87c390902ffeaf6f73950c6c92e41504 313156 apache2.2-common_2.2.20-1_i386.deb
 6f675a51fbac60d35285e2c80e14d620d5f75fdc46ae2ef68847ab0907b95677 1451664 apache2.2-bin_2.2.20-1_i386.deb
 2463cf57fe0a9ef244bad524f39d4eab4c76a99d3e097b84958c8b3bae4e8bc4 2186 apache2-mpm-worker_2.2.20-1_i386.deb
 62158d40dbbb51f3c62ff3b30ba70711413326b21b139f762d0bb6a8e30d54a5 2294 apache2-mpm-prefork_2.2.20-1_i386.deb
 12bb4b586b98e11a4727df0c00cd00457e4e31fc3e53c9e36cf311edb66f93fa 2254 apache2-mpm-event_2.2.20-1_i386.deb
 a9736d7a39c78f596cdc9fa487f584f5508641416c7ec246ca05441de2a2b02e 2282 apache2-mpm-itk_2.2.20-1_i386.deb
 c50dac7d56f8a240e6f326b80ac61ff792bc7b6d12c29a886ef2edcf7f28f629 168460 apache2-utils_2.2.20-1_i386.deb
 c4e8e85228c81cfedf88b83e79163503a94a69209304c9a3fdc9f6e2b5daabfe 102458 apache2-suexec_2.2.20-1_i386.deb
 3b8e226997a1ba9da8a8f28f5164a1f05db305323eb2a3ff1c35059994166ff1 104086 apache2-suexec-custom_2.2.20-1_i386.deb
 bc458bfea03327afaa58643dd2436a4b120ff83fc0d3ca19797662d8297c8842 1380 apache2_2.2.20-1_i386.deb
 b9267b0ce3bb00f752712abf1280b40bda8a510b8f362ed702c7bbc3a4d2abf5 137754 apache2-prefork-dev_2.2.20-1_i386.deb
 dd05031828d521a2a2b3b37cd7f96a23b72eb672dc021bfda381c22418b3fe3a 138930 apache2-threaded-dev_2.2.20-1_i386.deb
 5a6dcd05543c806d198a0a7ea3a7cfba3c14809ab2b0a708df7e24d94a249bd9 2799846 apache2-dbg_2.2.20-1_i386.deb
Files: 
 ea1a718b7a768fc7a4141e7d3ad60a99 1751 httpd optional apache2_2.2.20-1.dsc
 4504934464c5ee51018dbafa6d99810d 6834233 httpd optional apache2_2.2.20.orig.tar.gz
 3909f2c13c8ad11fbb75945c92d315bc 205609 httpd optional apache2_2.2.20-1.diff.gz
 b054928220d8c157fa7887083d592d3e 2661502 doc optional apache2-doc_2.2.20-1_all.deb
 6839f0930360331d6ea44c420ebeddb3 313156 httpd optional apache2.2-common_2.2.20-1_i386.deb
 6debfff1356cd121c4c9516292585cb3 1451664 httpd optional apache2.2-bin_2.2.20-1_i386.deb
 76f4dd71d959fd4de97e575f0d82a08b 2186 httpd optional apache2-mpm-worker_2.2.20-1_i386.deb
 f6627109e6af81ebb8f11cc0b611d79f 2294 httpd optional apache2-mpm-prefork_2.2.20-1_i386.deb
 7f58153d11ce4d732a7a47e344b8f211 2254 httpd optional apache2-mpm-event_2.2.20-1_i386.deb
 df74895728ef5a8f9e8d1c1d0e5a721c 2282 httpd extra apache2-mpm-itk_2.2.20-1_i386.deb
 0685c1c3c3b2c7021b432aac37d30b3f 168460 httpd optional apache2-utils_2.2.20-1_i386.deb
 bb0b305eab128be80e61a059f0795cec 102458 httpd optional apache2-suexec_2.2.20-1_i386.deb
 c3cc82a416d8d995e0720fae56abac1e 104086 httpd extra apache2-suexec-custom_2.2.20-1_i386.deb
 88fd5b969e1755b71145f3fc69dcb84c 1380 httpd optional apache2_2.2.20-1_i386.deb
 52548e7c67e59627f5ef5bdc71eb2d6c 137754 httpd extra apache2-prefork-dev_2.2.20-1_i386.deb
 69eb97c87e3c961c7d8cee6d132918bf 138930 httpd extra apache2-threaded-dev_2.2.20-1_i386.deb
 cc1d7f48acf3197f95cc9ccdedf180b4 2799846 debug extra apache2-dbg_2.2.20-1_i386.deb

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.11 (GNU/Linux)

iD8DBQFOY9eHbxelr8HyTqQRAr4sAKDKqdip3bLNo9d9+d88UqUxbezKVQCg3OQ3
yuu8bG6P+5I5R41PGEO0gAA=
=L7EE
-----END PGP SIGNATURE-----



--- End Message ---

Reply to: