SECURITY UPDATE: Memory exhaustion due to excessive HTTP/2 incoming headers
buffering
debian/patches/CVE-2024-27316.patch: Fix to bail after too many failed
reads, increment count on request headers failed to add
CVE-2024-27316
SECURITY UPDATE: Faulty input validation in the core of Apache allows
malicious or exploitable backend/content generators to split HTTP responses
debian/patches/CVE-2023-38709.patch: header validation after content-*
are eval'ed
CVE-2023-38709
SECURITY UPDATE: HTTP response splitting in multiple modules in Apache HTTP
Server allows an attacker that can inject malicious response headers into
backend applications to cause an HTTP desynchronization attack
debian/patches/CVE-2024-24795.patch: let httpd handle CL/TE for non-http
handlers