Apache 2.2.15 / OpenSSL v1

Asked by RefernReward

Chaps, what is the release status of 2.2.15 apache for Ubuntu? It seems that the 2.2.15 version is urgently required for all apache users but yet I dont really find much in the forums and in the news about what is being done about it.

Its a MUST HAVE especially OpenSSL v 1.0 instead of 0.9.8h etc

Im sure that are 1000's of servers out there running un secure SSL connections!!

I've managed to compile Apache 2.2.15 and OpenSSL latest versions in the meantime but for the countless people out there Im sure they need to get these updates.

Please can somebody update me on the present status - I have some colleagues who arent as technical needing some help


Question information

English Edit question
Ubuntu apache2 Edit question
No assignee Edit question
Solved by:
Last query:
Last reply:
Revision history for this message
Micah Gersten (micahg) said :

Apache 2.2.15 will be in Ubuntu Maverick. Ubuntu Lucid is shipping with 2.2.14 with the appropriate security patches applied.

Revision history for this message
RefernReward (adnexius) said :

Ok, thanks but does this cover SECURITY: CVE-2009-3555, CVE-2010-0408, 2010-0425, 2010-0434?

Revision history for this message
Micah Gersten (micahg) said :

CVE-2010-0408 and CVE-2010-0434 in 2.2.14-5ubuntu3
CVE-2009-3555 in 2.2.14-5
CVE 2010-0425 is Windows only: https://bugs.launchpad.net/bugs/cve/2010-0425

Revision history for this message
RefernReward (adnexius) said :

Thanks everso much.

PS. Ive got to say Im very happy with Lucid - my Rails application and env is running sooooooooooo much faster its mind blowing. Its like its on steroids, everything system wide is tons faster, and the apt-get "tab to complete" for available pacakges is just pefect! Thanks again