Debian-LTS has issued an advisory today (January 26): https://www.debian.org/lts/security/2023/dla-3283 The issues are fixed upstream in 2.9.7. Mageia 8 is also affected.
Whiteboard: (none) => MGA8TOOSee Also: (none) => https://bugs.mageia.org/show_bug.cgi?id=30977Status comment: (none) => Fixed upstream in 2.9.7
Assigning to all packagers collectively, because there is no registered maintainer for this package.
CC: (none) => marja11Assignee: bugsquad => pkg-bugs
Fedora has issued an advisory for this on April 22: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/SYRTXTOQQI6SB2TLI5QXU76DURSLS4XI/ It also switches to pcre2, fixing other issues (see Bug 31791).
Already done for cauldron. $ mgarepo rpmlog apache-mod_security * Sun Apr 16 2023 daviddavid <daviddavid> 1:2.9.7-1.mga9 + Revision: 1953094 - new version: 2.9.7 - switch to pcre2 (mga#31791)
CC: (none) => geiger.david68210
Done now for mga8.
mlogc-2.9.7-1.mga8 apache-mod_security-2.9.7-1.mga8 from apache-mod_security-2.9.7-1.mga8.src.rpm
Source RPM: apache-mod_security-2.9.5-2.mga9.src.rpm => apache-mod_security-2.9.5-1.mga8.src.rpmVersion: Cauldron => 8Assignee: pkg-bugs => qa-bugsWhiteboard: MGA8TOO => (none)Status comment: Fixed upstream in 2.9.7 => (none)
CC: (none) => mageia
MGA8-64 MATE on Acer Aspire 5253 No installation issues Test as in bug 29787 # httpd -M 2>/dev/null |grep security security2_module (shared) is OK.
Whiteboard: (none) => MGA8-64-OKCC: (none) => herman.viaene
Validating.
CC: (none) => andrewsfarm, sysadmin-bugsKeywords: (none) => validated_update
CC: (none) => davidwhodginsKeywords: (none) => advisory
An update for this issue has been pushed to the Mageia Updates repository. https://advisories.mageia.org/MGASA-2023-0175.html
Status: NEW => RESOLVEDResolution: (none) => FIXED