mod_proxy_html-1:2.4.37-65.module+el8.10.0+1840+b070a976.1 > 6 6_6 3!pQp)Tξ7]mtZ`fP ]mtZ`jLr}ƈ9p[Z r%bD[LEc 7% 60pt]a9ؑ`I"9: lm'01o'ln[@{uq<8QozV~#y4Q%9ZUCS0 >=cxSZF"  1ܭم#u8IYGh{Mtn 1U nr&{>upŶZ./?VN wsq!6 G%rG&ZTGU؈EJ{a\vW btsLL$Î䥀kptS(0 ?0]m`qթXwse #V:WqJn'{HdJC#d-2y8Jݚaξ[c1g$O-a z>i-t,ډKHAQluTY3Dt$;ψû458fdc5ebe0361f4061dec54ae9ee4ce7fe3abe0743ac1f97b95bc7db0491e292131e483ba7b4c327d6b7d518a57bbe60a870283C3!pQp)Tξ7]mtZ`fP ]mtZ`d(uMhZ`V,!& 9?W f\rו렟h~<+J$"ŔÆА΍v=:bV+GB)GIO@pMn?K "M3H,G˺~Ang2$?4P%5g&lw{X 2\[Ͼ Z`_ʭEo xnBU-v]1:8-WO~,p"pRhŐc=삖1Qk/DuߣiPʲh?'oˀ._ozT 9LιKsa3~yDo(r= UW[?@v| Ӟ֫B;5*y륕bW=A"=&F.Gsԡm ܢZx[M>kS3@{QmbOFɷ&7 uÄN #S x_rkvO!PuIP@:D4X# >pAk?[d< @ x %+3 Ql     (Fd8(p8x9 x:7wBGHIXY Z[\]^Cbdefltuv0wlxy04Cmod_proxy_html2.4.3765.module+el8.10.0+1840+b070a976.1HTML and XML content filters for the Apache HTTP ServerThe mod_proxy_html and mod_xml2enc modules provide filters which can transform and modify HTML and XML content.fJord1-prod-a64build001.svc.aws.rockylinux.orgwKojiRockyASL 2.0infrastructure@rockylinux.orgSystem Environment/Daemonshttps://httpd.apache.org/linuxaarch6452@Af|fGfFfFfFfFa2211995b7e55b781f68666664f0bcd84550ed9a16edee07121f63477dfaaffae02cfe2d4e0ad489d8e0a0cf84cacf7c3f274375113cf020a81957874ff2c85dc793758176dc4e18839ec9b65606b1a4e03b90ce357dd64e58d4e16735b53b56../../../../usr/lib64/httpd/modules/mod_proxy_html.so../../../../usr/lib64/httpd/modules/mod_xml2enc.sorootrootrootrootrootrootrootrootrootrootrootroothttpd-2.4.37-65.module+el8.10.0+1840+b070a976.1.src.rpmconfig(mod_proxy_html)mod_proxy_htmlmod_proxy_html(aarch-64)@@@@@@@@@    @config(mod_proxy_html)httpdhttpd-mmnld-linux-aarch64.so.1()(64bit)ld-linux-aarch64.so.1(GLIBC_2.17)(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.17)(64bit)libpthread.so.0()(64bit)libxml2.so.2()(64bit)libxml2.so.2(LIBXML2_2.4.30)(64bit)libxml2.so.2(LIBXML2_2.5.2)(64bit)libxml2.so.2(LIBXML2_2.6.0)(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)rtld(GNU_HASH)1:2.4.37-65.module+el8.10.0+1840+b070a976.10:2.4.37-65.module+el8.10.0+1840+b070a976.120120211aarch643.0.4-14.6.0-14.0-15.2-14.14.3f@fieN@e̫@d d\@d!d-@d-@d-@doMdJcdcck@cck@c(Ybޅbb2@b8haNaaaawaU`:@`f@`@`@_м@__@_:_^b^(@^@^]]@]߶]҇]@]g@]-@]]@\7\Z@\Yz\T4\\U@[@[[[@[H[u[[[ā@[ā@[ā@[@[@["@[YZ@Z@Z@Yp@Y{Y@Y@YéYéYéYéYX@YYYYx@Ym@YlYf@Ycl@YV=@YGY5GY@YXۡXP@X @X@XwoX[@X[@XEVX)@X@WW~D@W~D@W~D@WKW@VVVVn@VhV.VCV@UK@U@Ua@UF@UQUQTp@T=@T@T @TT_Tk@Tk@S0S@SGS@SS/SS@SSS"@SS5d@S4S&Sz@Sz@S(S@R@RRG@R@R@RsRrF@Ri Re@RVQ@QQޞ@QQo@Q@QQV@Q@Qo@Qm=@QQQ,Q,Q']QP @P6@P6@P{@PPl(PiPiPiPiPYPQPIP3x@P3x@PPO@OO@O@OЗOЗOF@OF@OF@O]@O"O"O@O@O@O@O@O@OOOOOOleOleO_6O_6O_6OU@O8@O8@O5OKO@ONNS@N{#@NoENdNBrN)f@N&@N@N MM>MMn1@MdMRMF@M(QM$]@M$]@M# L@L@LLMxL7@K@Luboš Uhliarik - 2.4.37-65.1Luboš Uhliarik - 2.4.37-65Joe Orton - 2.4.37-64Joe Orton - 2.4.37-63Johnny Hughes - 2.4.37-62Luboš Uhliarik - 2.4.37-62Tomas Korbar - 2.4.37-61Tomas Korbar - 2.4.37-60Tomas Korbar - 2.4.37-59Tomas Korbar - 2.4.37-58Luboš Uhliarik - 2.4.37-57Luboš Uhliarik - 2.4.37-56.5Luboš Uhliarik - 2.4.37-56.4Luboš Uhliarik - 2.4.37-56Luboš Uhliarik - 2.4.37-55Luboš Uhliarik - 2.4.37-54Luboš Uhliarik - 2.4.37-53Tomas Korbar - 2.4.37-52Luboš Uhliarik - 2.4.37-51Luboš Uhliarik - 2.4.37-50Luboš Uhliarik - 2.4.37-49Luboš Uhliarik - 2.4.37-48Luboš Uhliarik - 2.4.37-47Luboš Uhliarik - 2.4.37-46Luboš Uhliarik - 2.4.37-45Luboš Uhliarik - 2.4.37-44Luboš Uhliarik - 2.4.37-43Luboš Uhliarik - 2.4.37-42Luboš Uhliarik - 2.4.37-41Lubos Uhliarik - 2.4.37-40Artem Egorenkov - 2.4.37-39Lubos Uhliarik - 2.4.37-38Lubos Uhliarik - 2.4.37-37Lubos Uhliarik - 2.4.37-36Lubos Uhliarik - 2.4.37-35Lubos Uhliarik - 2.4.37-33Lubos Uhliarik - 2.4.37-31Joe Orton - 2.4.37-30Lubos Uhliarik - 2.4.37-29Lubos Uhliarik - 2.4.37-28Lubos Uhliarik - 2.4.37-27Lubos Uhliarik - 2.4.37-21Lubos Uhliarik - 2.4.37-20Joe Orton - 2.4.37-19Lubos Uhliarik - 2.4.37-18Lubos Uhliarik - 2.4.37-17Lubos Uhliarik - 2.4.37-16Lubos Uhliarik - 2.4.37-15Lubos Uhliarik - 2.4.37-14Lubos Uhliarik - 2.4.37-13Lubos Uhliarik - 2.4.37-11Lubos Uhliarik - 2.4.37-10Lubos Uhliarik - 2.4.37-9Joe Orton - 2.4.37-8Joe Orton - 2.4.37-7Joe Orton - 2.4.37-6Luboš Uhliarik - 2.4.37-5Luboš Uhliarik - 2.4.37-4Luboš Uhliarik - 2.4.37-3Joe Orton - 2.4.37-2Lubos Uhliarik - 2.4.37-1Luboš Uhliarik - 2.4.35-10Lubos Uhliarik - 2.4.35-9Joe Orton - 2.4.35-7Joe Orton - 2.4.35-5Lubos Uhliarik - 2.4.35-4Lubos Uhliarik - 2.4.35-3Lubos Uhliarik - 2.4.35-2Lubos Uhliarik - 2.4.35-1Lubos Uhliarik - 2.4.33-4Joe Orton - 2.4.33-3Luboš Uhliarik - 2.4.33-2Joe Orton - 2.4.28-8Luboš Uhliarik - 2.4.28-2Luboš Uhliarik - 2.4.28-1Joe Orton - 2.4.27-14Joe Orton - 2.4.27-13Joe Orton - 2.4.27-12Stephen Gallagher - 2.4.27-11Jeroen van Meeuwen - 2.4.27-10Joe Orton - 2.4.27-9Jeroen van Meeuwen - 2.4.27-8Stephen Gallagher - 2.4.27-8.1Joe Orton - 2.4.27-8.1Joe Orton - 2.4.27-7Fedora Release Engineering - 2.4.27-6Fedora Release Engineering - 2.4.27-5Joe Orton - 2.4.27-4Joe Orton - 2.4.27-3Luboš Uhliarik - 2.4.27-2Luboš Uhliarik - 2.4.27-1Joe Orton - 2.4.26-2Luboš Uhliarik - 2.4.26-1Joe Orton - 2.4.25-10Joe Orton - 2.4.25-9Joe Orton - 2.4.25-8Luboš Uhliarik - 2.4.25-7Luboš Uhliarik - 2.4.25-6Joe Orton - 2.4.25-5Fedora Release Engineering - 2.4.25-4Joe Orton - 2.4.25-3Luboš Uhliarik - 2.4.25-2Luboš Uhliarik - 2.4.25-1Luboš Uhliarik - 2.4.23-7Joe Orton - 2.4.23-6Joe Orton - 2.4.23-5Joe Orton - 2.4.23-4Joe Orton - 2.4.23-3Joe Orton - 2.4.23-2Joe Orton - 2.4.23-1Joe Orton - 2.4.18-6Joe Orton - 2.4.18-5Joe Orton - 2.4.18-4Joe Orton - 2.4.18-3Fedora Release Engineering - 2.4.18-2Jan Kaluza - 2.4.18-1Joe Orton - 2.4.17-4Jan Kaluza - 2.4.17-3Jan Kaluza - 2.4.17-2Joe Orton - 2.4.17-1Jan Kaluza - 2.4.12-4Joe Orton - 2.4.12-3Fedora Release Engineering - 2.4.12-2Jan Kaluza - 2.4.12-1Jan Kaluza - 2.4.10-17Jan Kaluza - 2.4.10-16Jan Kaluza - 2.4.10-15Joe Orton - 2.4.10-14Jan Kaluza - 2.4.10-13Jan Kaluza - 2.4.10-12Jan Kaluza - 2.4.10-11Jan Kaluza - 2.4.10-10Joe Orton - 2.4.10-9Joe Orton - 2.4.10-8Jan Kaluza - 2.4.10-7Joe Orton - 2.4.10-6Fedora Release Engineering - 2.4.10-5Jan Kaluza - 2.4.10-4Jan Kaluza - 2.4.10-3Joe Orton - 2.4.10-2Joe Orton - 2.4.10-1Jan Kaluza - 2.4.9-8Jan Kaluza - 2.4.9-7Jan Kaluza - 2.4.9-6Joe Orton - 2.4.9-5Fedora Release Engineering - 2.4.9-4Jan Kaluza - 2.4.9-3Jan Kaluza - 2.4.9-2Jan Kaluza - 2.4.9-1Joe Orton - 2.4.7-6Stephen Gallagher 2.4.7-5Jan Kaluza - 2.4.7-4Jan Kaluza - 2.4.7-3Joe Orton - 2.4.7-2Joe Orton - 2.4.7-1Joe Orton - 2.4.6-10Joe Orton - 2.4.6-9Joe Orton - 2.4.6-8Jan Kaluza - 2.4.6-7Joe Orton - 2.4.6-6Jan kaluza - 2.4.6-5Joe Orton - 2.4.6-4Jan Kaluza - 2.4.6-3Jan Kaluza - 2.4.6-2Joe Orton - 2.4.6-1Jan Kaluza - 2.4.4-12Joe Orton - 2.4.4-11Joe Orton - 2.4.4-10Joe Orton - 2.4.4-9Jan Kaluza - 2.4.4-8Jan Kaluza - 2.4.4-7Jan Kaluza - 2.4.4-6Jan Kaluza - 2.4.4-5Jan Kaluza - 2.4.4-4Jan Kaluza - 2.4.4-3Joe Orton - 2.4.4-2Joe Orton - 2.4.4-1Joe Orton - 2.4.3-17Fedora Release Engineering - 2.4.3-16Joe Orton - 2.4.3-15Joe Orton - 2.4.3-14Joe Orton - 2.4.3-13Joe Orton - 2.4.3-12Joe Orton - 2.4.3-11Joe Orton - 2.4.3-10Joe Orton - 2.4.3-9Joe Orton - 2.4.3-8Joe Orton - 2.4.3-7Jan Kaluza - 2.4.3-6Joe Orton - 2.4.3-5Joe Orton - 2.4.3-4Jan Kaluza - 2.4.3-3Joe Orton - 2.4.3-2Joe Orton - 2.4.3-1Joe Orton - 2.4.2-23Fedora Release Engineering - 2.4.2-22Joe Orton - 2.4.2-21Joe Orton - 2.4.2-20Joe Orton - 2.4.2-19Joe Orton - 2.4.2-18Joe Orton - 2.4.2-17Joe Orton - 2.4.2-16Joe Orton - 2.4.2-15Joe Orton - 2.4.2-14Joe Orton - 2.4.2-13Joe Orton - 2.4.2-12Joe Orton - 2.4.2-11Joe Orton - 2.4.2-10Joe Orton - 2.4.2-9Joe Orton - 2.4.2-8Joe Orton - 2.4.2-7Joe Orton - 2.4.2-6Joe Orton - 2.4.2-5Joe Orton - 2.4.2-4Joe Orton - 2.4.2-3Joe Orton - 2.4.2-2Jan Kaluza - 2.4.2-1Joe Orton - 2.4.1-6Joe Orton - 2.4.1-5Joe Orton - 2.4.1-4Joe Orton - 2.4.1-3Joe Orton - 2.4.1-2Joe Orton - 2.4.1-1Joe Orton - 2.2.22-2Joe Orton - 2.2.22-1Petr Pisar - 2.2.21-8Jan Kaluza - 2.2.21-7Joe Orton - 2.2.21-6Fedora Release Engineering - 2.2.21-5Jan Kaluza - 2.2.21-4Jan Kaluza - 2.2.21-3Ville Skyttä - 2.2.21-2Joe Orton - 2.2.21-1Joe Orton - 2.2.20-1Jan Kaluza - 2.2.19-5Iain Arnell 1:2.2.19-4Jan Kaluza - 2.2.19-3Jan Kaluza - 2.2.19-2Joe Orton - 2.2.19-1Joe Orton - 2.2.17-13Joe Orton - 2.2.17-12Joe Orton - 2.2.17-11Joe Orton - 2.2.17-10Joe Orton - 2.2.17-9Fedora Release Engineering - 2.2.17-8Joe Orton - 2.2.17-7Joe Orton - 2.2.17-6Joe Orton - 2.2.17-5Joe Orton - 2.2.17-4Joe Orton - 2.2.17-3Joe Orton - 2.2.17-2Joe Orton - 2.2.17-1Joe Orton - 2.2.16-2Joe Orton - 2.2.16-1Joe Orton - 2.2.15-3Robert Scheck - 2.2.15-1- Resolves: RHEL-45812 - httpd:2.4/httpd: Substitution encoding issue in mod_rewrite (CVE-2024-38474) - Resolves: RHEL-45785 - httpd:2.4/httpd: Encoding problem in mod_proxy (CVE-2024-38473) - Resolves: RHEL-45777 - httpd:2.4/httpd: Improper escaping of output in mod_rewrite (CVE-2024-38475) - Resolves: RHEL-45758 - httpd:2.4/httpd: null pointer dereference in mod_proxy (CVE-2024-38477) - Resolves: RHEL-45743 - httpd:2.4/httpd: Potential SSRF in mod_rewrite (CVE-2024-39573)- Resolves: RHEL-31857 - httpd:2.4/httpd: HTTP response splitting (CVE-2023-38709)- Resolves: RHEL-14448 - httpd: mod_macro: out-of-bounds read vulnerability (CVE-2023-31122)- mod_xml2enc: fix media type handling Resolves: RHEL-14321- change for CentOS Stream Branding- Resolves: #2221083 - Apache Bug 57087: mod_proxy_fcgi doesn't send cgi CONTENT_LENGTH variable when the client request used Transfer-Encoding:chunked- Fix issue found by covscan - Related: #2159603- Another rebuild because of mistake in workflow - Related: #2159603- Rebuild because of mistake in workflow - Related: #2159603- Resolves: #2159603 - mod_status lists BusyWorkers IdleWorkers keys twice- Resolves: #2176723 - CVE-2023-27522 httpd:2.4/httpd: mod_proxy_uwsgi HTTP response splitting- Resolves: #2190133 - mod_rewrite regression with CVE-2023-25690- Resolves: #2177748 - CVE-2023-25690 httpd:2.4/httpd: HTTP request splitting with mod_rewrite and mod_proxy- Resolves: #2162499 - CVE-2006-20001 httpd: mod_dav: out-of-bounds read/write of zero byte - Resolves: #2162485 - CVE-2022-37436 httpd: mod_proxy: HTTP response splitting - Resolves: #2162509 - CVE-2022-36760 httpd: mod_proxy_ajp: Possible request smuggling- Resolves: #2155961 - prevent sscg creating /dhparams.pem- Resolves: #2095650 - Dependency from mod_http2 on httpd broken- Resolves: #2050888 - httpd with SSL fails to start unless hostname command was installed- Add the SNI support in mod_proxy_wstunnel module for Apache httpd - Resolves: rhbz#2017543- Resolves: #2097015 - CVE-2022-28614 httpd:2.4/httpd: out-of-bounds read via ap_rwrite() - Resolves: #2097031 - CVE-2022-28615 httpd:2.4/httpd: out-of-bounds read in ap_strcmp_match() - Resolves: #2097458 - CVE-2022-30522 httpd:2.4/httpd: mod_sed: DoS vulnerability - Resolves: #2097480 - CVE-2022-30556 httpd:2.4/httpd: mod_lua: Information disclosure with websockets - Resolves: #2098247 - CVE-2022-31813 httpd:2.4/httpd: mod_proxy: X-Forwarded-For dropped by hop-by-hop mechanism - Resolves: #2097451 - CVE-2022-29404 httpd:2.4/httpd: mod_lua: DoS in r:parsebody - Resolves: #2096997 - CVE-2022-26377 httpd:2.4/httpd: mod_proxy_ajp: Possible request smuggling- Resolves: #2065237 - CVE-2022-22719 httpd:2.4/httpd: mod_lua: Use of uninitialized value of in r:parsebody - Resolves: #2065267 - CVE-2022-22721 httpd:2.4/httpd: core: Possible buffer overflow with very large or unlimited LimitXMLRequestBody - Resolves: #2065324 - CVE-2022-23943 httpd:2.4/httpd: mod_sed: Read/write beyond bounds- Resolves: #2090848 - CVE-2020-13950 httpd:2.4/httpd: mod_proxy NULL pointer dereference- Resolves: #2065249 - CVE-2022-22720 httpd:2.4/httpd: HTTP request smuggling vulnerability in Apache HTTP Server 2.4.52 and earlier- Resolves: #2035030 - CVE-2021-44224 httpd:2.4/httpd: possible NULL dereference or SSRF in forward proxy configurations- Resolves: #2035063 - CVE-2021-44790 httpd:2.4/httpd: mod_lua: possible buffer overflow when parsing multipart content- Resolves: #2007199 - CVE-2021-36160 httpd:2.4/httpd: mod_proxy_uwsgi: out-of-bounds read via a crafted request uri-path - Resolves: #1972491 - CVE-2021-33193 httpd:2.4/mod_http2: Request splitting via HTTP/2 method injection and mod_proxy- Resolves: #1968278 - CVE-2020-35452 httpd:2.4/httpd: Single zero byte stack overflow in mod_auth_digest - Resolves: #2001046 - Apache httpd OOME with mod_dav in RHEL 8 - Resolves: #2005128 (CVE-2021-34798) - CVE-2021-34798 httpd: NULL pointer dereference via malformed requests - Resolves: #1984828 - mod_proxy_hcheck piles up health checks leading to high memory consumption - Resolves: #2005119 - CVE-2021-39275 httpd: out-of-bounds write in ap_escape_quotes() via malicious input- Related: #2007236 - CVE-2021-40438 httpd:2.4/httpd: mod_proxy: SSRF via a crafted request uri-path- Resolves: #2007236 - CVE-2021-40438 httpd:2.4/httpd: mod_proxy: SSRF via a crafted request uri-path - Resolves: #1969229 - CVE-2021-26691 httpd:2.4/httpd: Heap overflow in mod_session- Resolves: #1680111 - httpd sends reply to HTTPS GET using two TLS records - Resolves: #1905613 - mod_ssl does not like valid certificate chain - Resolves: #1935742 - [RFE] backport samesite/httponly/secure flags for usertrack - Resolves: #1972500 - CVE-2021-30641 httpd:2.4/httpd: MergeSlashes regression - Resolves: #1968307 - CVE-2021-26690 httpd:2.4/httpd: mod_session NULL pointer dereference in parser - Resolves: #1934741 - Apache trademark update - new logo- Resolves: #1952557 - mod_proxy_wstunnel.html is a malformed XML - Resolves: #1937334 - SSLProtocol with based virtual hosts- prevent htcacheclean from while break when first file processed- Resolves: #1918741 - Thousands of /tmp/modproxy.tmp.* files created by apache- Resolves: #1883648 - [RFE] Update httpd directive SSLProxyMachineCertificateFile to be able to handle certs without matching private key- Resolves: #1896176 - [RFE] ProxyWebsocketIdleTimeout from httpd mod_proxy_wstunnel - Resolves: #1847585 - mod_ldap: High CPU usage at apr_ldap_rebind_remove()- Resolves: #1651376 - centralizing default index.html for httpd- Resolves: #1868608 - Intermittent Segfault in Apache httpd due to pool concurrency issues - Resolves: #1861380 - httpd/mod_proxy_http/mod_ssl aborted when sending a client cert to backend server - Resolves: #1680118 - unorderly connection close when client attempts renegotiation- Resolves: #1677590 - CVE-2018-17199 httpd:2.4/httpd: mod_session_cookie does not respect expiry time - Resolves: #1869075 - CVE-2020-11984 httpd:2.4/httpd: mod_proxy_uswgi buffer overflow - Resolves: #1872828 - httpd: typo in htpasswd, contained in httpd-tools package - Resolves: #1869576 - httpd : mod_proxy should allow to specify Proxy-Authorization in ProxyRemote directive - Resolves: #1875844 - mod_cgid takes CGIDScriptTimeout x 2 seconds for timeout - Resolves: #1891829 - mod_proxy_hcheck Doesn't perform checks when in a balancer- Resolves: #1209162 - support logging to journald from CustomLog- Resolves: #1823263 (CVE-2020-1934) - CVE-2020-1934 httpd: mod_proxy_ftp use of uninitialized value- Related: #1771847 - BalancerMember ping parameter for mod_proxy_http doesn't work- Resolves: #1823259 - CVE-2020-1927 httpd:2.4/httpd: mod_rewrite configurations vulnerable to open redirect - Resolves: #1747284 - CVE-2019-10098 httpd:2.4/httpd: mod_rewrite potential open redirect - Resolves: #1747281 - CVE-2019-10092 httpd:2.4/httpd: limited cross-site scripting in mod_proxy error page - Resolves: #1747291 - CVE-2019-10097 httpd:2.4/httpd: null-pointer dereference in mod_remoteip - Resolves: #1771847 - BalancerMember ping parameter for mod_proxy_http doesn't work - Resolves: #1794728 - Backport of SessionExpiryUpdateInterval directive- Resolves: #1775158 - POST request with TLS 1.3 PHA client auth fails: Re-negotiation handshake failed: Client certificate missing- Resolves: #1704317 - Add support for SSLKEYLOGFILE- mod_cgid: enable fd passing (#1633224)- Resolves: #1744121 - Unexpected OCSP in proxy SSL connection - Resolves: #1725031 - htpasswd: support SHA-x passwords for FIPS compatibility - Resolves: #1633224 - mod_cgid logging issues- remove bundled mod_md module - Related: #1747898 - add mod_md package- Resolves: #1744999 - CVE-2019-9511 httpd:2.4/mod_http2: HTTP/2: large amount of data request leads to denial of service - Resolves: #1745086 - CVE-2019-9516 httpd:2.4/mod_http2: HTTP/2: 0-length headers leads to denial of service - Resolves: #1745154 - CVE-2019-9517 httpd:2.4/mod_http2: HTTP/2: request for large response leads to denial of service- Resolves: #1730721 - absolute path used for default state and runtime dir by default- Resolves: #1724549 - httpd response contains garbage in Content-Type header- Resolves: #1696142 - CVE-2019-0217 httpd:2.4/httpd: mod_auth_digest: access control bypass due to race condition - Resolves: #1696097 - CVE-2019-0220 httpd:2.4/httpd: URL normalization inconsistency - Resolves: #1669221 - `ExtendedStatus Off` directive when using mod_systemd causes systemctl to hang - Resolves: #1673022 - httpd can not be started with mod_md enabled- Resolves: #1695432 - CVE-2019-0211 httpd: privilege escalation from modules scripts - Resolves: #1696091 - CVE-2019-0215 httpd:2.4/httpd: mod_ssl: access control bypass when using per-location client certification authentication- Resolves: #1672977 - state-dir corruption on reload- Resolves: #1670716 - Coredump when starting in FIPS mode- add security fix for CVE-2019-0190 (#1671282)- add DefaultStateDir/ap_state_dir_relative() (#1653009) - mod_dav_fs: use state dir for default DAVLockDB - mod_md: use state dir for default MDStoreDir- add httpd.conf(5) (#1611361)- Resolves: #1652966 - Missing RELEASE in http header- Resolves: #1641951 - No Documentation= line in htcacheclean.service files- Resolves: #1643713 - TLS connection allowed while all protocols are forbidden- mod_ssl: fix off-by-one causing crashes in CGI children (#1649428)- Resolves: #1644625 - httpd rebase to 2.4.37- Related: #1493510 - RFE: httpd, add IP_FREEBIND support for Listen- mod_ssl: allow sending multiple CA names which differ only in case- mod_ssl: drop SSLRandomSeed from default config (#1638730) - mod_ssl: follow OpenSSL protocol defaults if SSLProtocol is not configured (Rob Crittenden, #1638738)- mod_ssl: don't require SSLCryptoDevice to be set for PKCS#11 cert- Resolves: #1635681 - sync with Fedora 28/29 httpd - comment-out SSLProtocol, SSLProxyProtocol from ssl.conf in default configuration; now follow OpenSSL system default (#1468322) - dropped NPN support - mod_md: change hard-coded default MdStoreDir to state/md (#1563846) - don't block on service try-restart in posttrans scriptlet - build and load mod_brotli - mod_systemd: show bound ports in status and log to journal at startup - updated httpd.service.xml man page - tweak wording in privkey passphrase prompt - drop sslmultiproxy patch - apachectl: don't read /etc/sysconfig/httpd - drop irrelevant Obsoletes for devel subpackage - move instantiated httpd@.service to main httpd package- Resolves: #1602548 - various covscan fixes- apache httpd can work with TLS 1.3 (#1617997) - drop SSLv3 support patch- new version 2.4.35 (#1632754)- mod_ssl: enable SSLv3 and change behavior of "SSLProtocol All" configuration (#1622630)- mod_ssl: add PKCS#11 cert/key support (Anderson Sasaki, #1527084)- new version 2.4.33 - add mod_md subpackage; load mod_proxy_uwsgi by default- remove %ghosted /etc/sysconfig/httpd (#1572676)- Resolves: #1512563 - httpd: update welcome page branding - Resolves: #1511123 - RFE: httpd use event MPM by default - Resolves: #1493510 - RFE: httpd, add IP_FREEBIND support for Listen- new version 2.4.28- add notes on enabling httpd_graceful_shutdown boolean for prefork- drop Requires(post) for mod_ssl- better error handling in httpd-ssl-gencerts (#1494556)- Require sscg 2.2.0 for creating service and CA certificates together- Address CVE-2017-9798 by applying patch from upstream (#1490344)- use sscg defaults; append CA cert to generated cert - document httpd-init.service in httpd-init.service(8)- Address CVE-2017-9798 by applying patch from upstream (#1490344)- Generate SSL certificates on service start, not %posttrans- move httpd.service.d, httpd.socket.d dirs to -filesystem- add new content-length filter (upstream PR 61222)- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Binutils_Mass_Rebuild- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild- update mod_systemd (r1802251)- switch to event by default for Fedora 27 and later (#1471708)- Resolves: #1469959 - httpd update cleaned out /etc/sysconfig- new version 2.4.27- mod_proxy_fcgi: fix further regressions (PR 61202)- new version 2.4.26- move unit man pages to section 8, add as Documentation= in units- add httpd.service(5) and httpd.socket(5) man pages- require mod_http2, now packaged separately- Resolves: #1397243 - Backport Apache Bug 53098 - mod_proxy_ajp: patch to set worker secret passed to tomcat- Resolves: #1434916 - httpd.service: Failed with result timeout- link only httpd, not support/* against -lselinux -lsystemd- Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild- mod_watchdog: restrict thread lifetime (#1410883)- Resolves: #1358875 - require nghttp2 >= 1.5.0- new version 2.4.25- Resolves: #1401530 - CVE-2016-8740 httpd: Incomplete handling of LimitRequestFields directive in mod_http2- fix build with OpenSSL 1.1 (#1392900) - fix typos in ssl.conf (josef randinger, #1379407)- no longer package /etc/sysconfig/httpd - synch ssl.conf with upstream- add security fix for CVE-2016-5387- load mod_watchdog by default (#1353582)- restore build of mod_proxy_fdpass (#1325883) - improve check tests to catch configured-but-not-built modules- update to 2.4.23 (#1325883, #1353203) - load mod_proxy_hcheck - recommend use of "systemctl edit" in httpd.service- have "apachectl graceful" start httpd if not running, per man page- use redirects for lang-specific /manual/ URLs- fix welcome page HTML validity (Ville Skyttä)- remove httpd pre script (duplicate of httpd-filesystem's) - in httpd-filesystem pre script, create group/user iff non-existent- Rebuilt for https://fedoraproject.org/wiki/Fedora_24_Mass_Rebuild- update to new version 2.4.18- re-enable mod_asis due to popular demand (#1284315)- fix crash when using -X argument (#1272234)- rebase socket activation patch to 2.4.17- update to 2.4.17 (#1271224) - build, load mod_http2 - don't build mod_asis, mod_file_cache - load mod_cache_socache, mod_proxy_wstunnel by default - check every built mod_* is configured - synch ssl.conf with upstream; disable SSLv3 by default- update to 2.4.16- mod_ssl: use "localhost" in the dummy SSL cert if len(FQDN) > 59 chars- Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild- update to 2.4.12- fix compilation with lua-5.3- remove filter for auto-provides of httpd modules, it is not needed since F20- core: fix bypassing of mod_headers rules via chunked requests (CVE-2013-5704) - mod_cache: fix NULL pointer dereference on empty Content-Type (CVE-2014-3581) - mod_proxy_fcgi: fix a potential crash with long headers (CVE-2014-3583) - mod_lua: fix handling of the Require line when a LuaAuthzProvider is used in multiple Require directives with different arguments (CVE-2014-8109)- require apr-util 1.5.x- use NoDelay and DeferAcceptSec in httpd.socket- increase suexec minimum acceptable uid/gid to 1000 (#1136391)- fix hostname requirement and conflict with openssl-libs- use KillMode=mixed in httpd.service (#1135122)- set vstring based on /etc/os-release (Pat Riehecky, #1114539)- pull in httpd-filesystem as Requires(pre) (#1128328) - fix cipher selection in default ssl.conf, depend on new OpenSSL (#1134348) - require hostname for mod_ssl post script (#1135118)- mod_systemd: updated to the latest version - use -lsystemd instead of -lsystemd-daemon (#1125084) - fix possible crash in SIGINT handling (#958934)- mod_ssl: treat "SSLCipherSuite PROFILE=..." as special (#1109119) - switch default ssl.conf to use PROFILE=SYSTEM (#1109119)- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild- add /usr/bin/useradd dependency to -filesystem requires- fix creating apache user in pre script (#1128328)- enable mod_request by default for mod_auth_form - move disabled-by-default modules from 00-base.conf to 00-optional.conf- update to 2.4.10 - expand variables in docdir example configs- add support for systemd socket activation (#1111648)- remove conf.modules.d from httpd-filesystem subpackage (#1081453)- add httpd-filesystem subpackage (#1081453)- mod_ssl: don't use the default OpenSSL cipher suite in ssl.conf (#1109119)- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild- add support for SetHandler + proxy (#1078970)- move macros from /etc/rpm to macros.d (#1074277) - remove unused patches- update to 2.4.9- use 2048-bit RSA key with SHA-256 signature in dummy certificate- Create drop directory for systemd snippets- remove provides of old MMN, because it contained double-dash (#1068851)- fix graceful restart using legacy actions- conflict with pre-1.5.0 APR - fix sslsninotreq patch- update to 2.4.7 (#1034071)- switch to requiring system-logos-httpd (#1031288)- change mmnisa to drop "-" altogether- drop ambiguous invalid "-" in RHS of httpd-mmn Provide, keeping old Provide for transition- systemd: use {MAINPID} notation to ensure /bin/kill has always the second arg- mod_ssl: allow SSLEngine to override Listen-based default (r1537535)- systemd: send SIGWINCH signal without httpd -k in ExecStop- load mod_macro by default (#998452) - add README to conf.modules.d - mod_proxy_http: add possible fix for threading issues (r1534321) - core: add fix for truncated output with CGI scripts (r1530793)- require fedora-logos-httpd (#1009162)- revert fix for dumping vhosts twice- update to 2.4.6 - mod_ssl: use revised NPN API (r1487772)- mod_unique_id: replace use of hostname + pid with PRNG output (#976666) - apxs: mention -p option in manpage- add patch for aarch64 (Dennis Gilmore, #925558)- remove duplicate apxs man page from httpd-tools- remove zombie dbmmanage script- return 400 Bad Request on malformed Host header- ignore /etc/sysconfig/httpd and document systemd way of setting env variables in this file- htpasswd/htdbm: fix hash generation bug (#956344) - do not dump vhosts twice in httpd -S output (#928761) - mod_cache: fix potential crash caused by uninitialized variable (#954109)- execute systemctl reload as result of apachectl graceful - mod_ssl: ignore SNI hints unless required by config - mod_cache: forward-port CacheMaxExpire "hard" option - mod_ssl: fall back on another module's proxy hook if mod_ssl proxy is not configured.- fix service file to not send SIGTERM after ExecStop (#906321, #912288)- protect MIMEMagicFile with IfModule (#893949)- really package mod_auth_form in mod_session (#915438)- update to 2.4.4 - fix duplicate ownership of mod_session config (#914901)- add mod_session subpackage, move mod_auth_form there (#894500)- Rebuilt for https://fedoraproject.org/wiki/Fedora_19_Mass_Rebuild- add systemd service for htcacheclean- drop patch for r1344712- filter mod_*.so auto-provides (thanks to rcollet) - pull in syslog logging fix from upstream (r1344712)- rebuild to pick up new apr-util-ldap- rebuild- pull upstream patch r1392850 in addition to r1387633- define PLATFORM in os.h using vendor string- use systemd script unconditionally (#850149)- use systemd scriptlets if available (#850149) - don't run posttrans restart if /etc/sysconfig/httpd-disable-posttrans exists- use systemctl from apachectl (#842736)- fix some error log spam with graceful-stop (r1387633) - minor mod_systemd tweaks- use IncludeOptional for conf.d/*.conf inclusion- adding mod_systemd to integrate with systemd better- mod_ssl: add check for proxy keypair match (upstream r1374214)- update to 2.4.3 (#849883) - own the docroot (#848121)- add mod_proxy fixes from upstream (r1366693, r1365604)- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- drop explicit version requirement on initscripts- mod_ext_filter: fix error_log warnings- support "configtest" and "graceful" as initscripts "legacy actions"- avoid use of "core" GIF for a "core" directory (#168776) - drop use of "syslog.target" in systemd unit file- use _unitdir for systemd unit file - use /run in unit file, ssl.conf- mod_ssl: fix NPN patch merge- move tmpfiles.d fragment into /usr/lib per new guidelines - package /run/httpd not /var/run/httpd - set runtimedir to /run/httpd likewise- fix htdbm/htpasswd crash on crypt() failure (#818684)- pull fix for NPN patch from upstream (r1345599)- update suexec patch to use LOG_AUTHPRIV facility- really fix autoindex.conf (thanks to remi@)- fix autoindex.conf to allow symlink to poweredby.png- suexec: use upstream version of patch for capability bit support- suexec: use syslog rather than suexec.log, drop dac_override capability- mod_ssl: add TLS NPN support (r1332643, #809599)- add BR on APR >= 1.4.0- use systemctl from logrotate (#221073)- pull from upstream: * use TLS close_notify alert for dummy_connection (r1326980+) * cleanup symbol exports (r1327036+)- really fix restart- tweak default ssl.conf - fix restart handling (#814645) - use graceful restart by default- update to 2.4.2- fix macros- add _httpd_moddir to macros- fix symlink for poweredby.png - fix manual.conf- add mod_proxy_html subpackage (w/mod_proxy_html + mod_xml2enc) - move mod_ldap, mod_authnz_ldap to mod_ldap subpackage- clean docroot better - ship proxy, ssl directories within /var/cache/httpd - default config: * unrestricted access to (only) /var/www * remove (commented) Mutex, MaxRanges, ScriptSock * split autoindex config to conf.d/autoindex.conf - ship additional example configs in docdir- update to 2.4.1 - adopt upstream default httpd.conf (almost verbatim) - split all LoadModules to conf.modules.d/*.conf - include conf.d/*.conf at end of httpd.conf - trim %changelog- fix build against PCRE 8.30- update to 2.2.22- Rebuild against PCRE 8.30- fix #783629 - start httpd after named- complete conversion to systemd, drop init script (#770311) - fix comments in /etc/sysconfig/httpd (#771024) - enable PrivateTmp in service file (#781440) - set LANG=C in /etc/sysconfig/httpd- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- fix #751591 - start httpd after remote-fs- allow change state of BalancerMember in mod_proxy_balancer web interface- Make mmn available as %{_httpd_mmn}. - Add .svgz to AddEncoding x-gzip example in httpd.conf.- update to 2.2.21- update to 2.2.20 - fix MPM stub man page generation- fix #707917 - add httpd-ssl-pass-dialog to ask for SSL password using systemd- rebuild while rpm-4.9.1 is untagged to remove trailing slash in provided directory names- fix #716621 - suexec now works without setuid bit- fix #689091 - backported patch from 2.3 branch to support IPv6 in logresolve- update to 2.2.19 - enable dbd, authn_dbd in default config- fix path expansion in service files- add systemd service files (#684175, thanks to Jóhann B. Guðmundsson)- minor updates to httpd.conf - drop old patches- rebuild- use arch-specific mmn- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- generate dummy mod_ssl cert with CA:FALSE constraint (#667841) - add man page stubs for httpd.event, httpd.worker - drop distcache support - add STOP_TIMEOUT support to init script- update default SSLCipherSuite per upstream trunk- fix requires (#667397)- de-ghost /var/run/httpd- add tmpfiles.d configuration, ghost /var/run/httpd (#656600)- drop setuid bit, use capabilities for suexec binary- update to 2.2.17- link everything using -z relro and -z now- update to 2.2.16- default config tweaks: * harden httpd.conf w.r.t. .htaccess restriction (#591293) * load mod_substitute, mod_version by default * drop proxy_ajp.conf, load mod_proxy_ajp in httpd.conf * add commented list of shipped-but-unloaded modules * bump up worker defaults a little * drop KeepAliveTimeout to 5 secs per upstream - fix LSB compliance in init script (#522074) - bundle NOTICE in -tools - use init script in logrotate postrotate to pick up PIDFILE - drop some old Obsoletes/Conflicts- update to 2.2.15 (#572404, #579311)mod_proxy_html1:2.4.37-65.module+el8.10.0+1840+b070a976.11:2.4.37-65.module+el8.10.0+1840+b070a976.11:2.4.37-65.module+el8.10.0+1840+b070a976.11:2.4.1-200-proxyhtml.conf.build-id0e935891f0baa3c5d4e7ef38a2e1cd7aa1c1319ed99151d9e4f9a45dd54f5726394aae108a32mod_proxy_html.somod_xml2enc.so/etc/httpd/conf.modules.d//usr/lib//usr/lib/.build-id/36//usr/lib/.build-id/a8//usr/lib64/httpd/modules/-O2 -g -pipe -Wall -Werror=format-security -Wp,-D_FORTIFY_SOURCE=2 -Wp,-D_GLIBCXX_ASSERTIONS -fexceptions -fstack-protector-strong -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -specs=/usr/lib/rpm/redhat/redhat-annobin-cc1 -fasynchronous-unwind-tables -fstack-clash-protectioncpioxz2aarch64-redhat-linux-gnuASCII textdirectoryELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=360e935891f0baa3c5d4e7ef38a2e1cd7aa1c131, strippedELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=a89ed99151d9e4f9a45dd54f5726394aae108a32, stripped RR R R RRRRRRRR RRRRRRutf-8c4286341f5c5d719bad8dc11b9a04a756dda49ead335e40275464957bf5385afhttpd:2.4:8100020240723155411:e155f54d?7zXZ !#,# Q_] b2u Q{LY8ZS$T' k9p>0FEAǞ){!1zHXZ ]q#  9_3޹@QC kBҁDWsub㑅r4Oa 魳l]v_{,LPZµ88*nmzr{A|w _K'Å oc}:{ _;F,%j#FxܦO7-^Ekiy] !aήRKᜉK_0J#P\thb"k|4SW9WG#9+%\WG $e{h01n,Pg'/ \toЎZ@S 9B]fte[8?@cZ+eͅ0 Ob HaUWt&No3NYTCyd  Fs¥Z*{vA9rbOS}/6Km~Ě6):|˶XEN٤bV3ro8% s8{|'Ս_6B*zقZQ[t8-u=!4ڸ=X/JI@==s~7JeI*#;\숸ޮp]Nj?pJ[6tƩ5[$MQxl=ղòD2wNd# svHÝf݄| ?`c&|̾F [ZSoS_ykgCfNn4!"4GiN^Chlm7ܤ~Lg*!2]J!k܏9 G~Zs*<\KMz/Ԗ@- '{q -Dh?NN0/!7Q~QhJQ]Da,]x`> } qFK{wOev|cA1g5[YTm.iѦwj5,h/b0zcRA}3h 6Wx8RQoʆ3N nN_ݮss^`nc lZ5@')ꀺ0F֪`2~2gzA*i+ʉ\C !ZXCNXVUt..l](E>!Q%a:>c(}OTT-:6{*[za׽t Qۼ\,ݬʻ ޞ=zp$fm\H\Rh+jO$;I<> \Ln5AFݼݖđdT3ZDOQMG-^Adc~*=:v4knՅt.uObDKkhoz1O|j8Y"&I;EC?$[kfn![;v}ެ2O :!p!:wXVZKAD܎Y ,X#w}Yu޸ElU:.)[pu>皨qhڔcGb=n@Y:"tKZ: q1`=tEl(|<%#teM]`~Onݣ<-ujSq3Bi #_yik=Ng 0*ʖif7x-aB utxqTkvQ8=yfmtGN8,ӕX ',U$>H X%S49Ь [A;ma-f/HP0{hiϏtd()ȉ5*دu.U 촧P/z^=<.߃Q.:7mq-tVJhfS;G2x ĶS<839ZaA} &GbtSţajlxyȣhc.fЪp\K5D̡_\YR62/I߭( It&`g:@5jIGQ\Eb#,YXekY:< Y\,G*/S%8MgeK8qb[Rf5B@-gbDWM!/S#W*N+|ԃx ={Rp+d *!_ Niq$vp"F"U =Vq|^ d"5#yZ,{qxMCA9 ?x0e, 5;OVOY%z L1+NGz>19; skUPN~)E(|z[w@D5~lɢ-oll%՚^zy) H09N^)&1hx95v?)Ց<ڃLS5pQ@NntM4BI۠Oro7@]UM7a5_uKP},X #tmoRQL٦OYc 5vP &uP şS':7GaL!/WY򹾴@$#Vhii|7Gv$<@5+WQ[*jy a1>3]=8x=pH6rT "QANlih;e½P8Z ,c%gÉCH418O|OCl`/s井,>ߋOL`*_Y6ozYz9cPyˇ'Y-J-JÛ#$/;@S[ZH@Z! v5lP31c]6>·U(N$׌wi׼trjĖ2ZI{Dͯp-7Ӡ@"KCżkޥłL4&4";:4_,ȏȪ}LNKkpn]<2 8Uų3VZ\GWVpt=9k{?J.^VNp=6x$6ysMҮއ=ڜ"b0(`UQvd_g "!fp*-"rg2a֩Mំt qjnοʵ xN)65צ񻥁XWdd)}ReȉhVY;yiooa88}sɳ-_vi`*v/R]{%58{.թڍD9!zz(/qf''Q4foU]M{n{)O~%300`s)gn[(0(/FJm{fꝗQ¤,VkϮWI"z8H ~Q; E@Xa+:O':st&\`吁>Ǻpl8Fh 0-b$AE+|? ̔R,4/ zyG_-%̍G"[KbǸ /"})to> wpcW]MX>]\~_ ܠH UKn-si!BMIK~t4*'}ū.Ԉw;aj_n婇#/>w sBQN:S\k4dӌ iN刼c$ԋ<-zPUoȋl{cS ^Rq݈b1 A}=v]_QW[K E7H9&dxկ}@YY<;&?dZY#-Q!kH-{ՄlO7`ƺ`*"+Om{W{ו5ۤ]3O߬ tMUT*9C[c V2H52NWȉR! JBUJfv \PEd`) Xc /v#ثXBN * #9]6(hQ!~J?_%arKI9^5٥|/fr#a;|:AY(H -'Z g8to=߾3@潩#bBP0I'JK1n"x=;5zU>;,EL=]JOXP+I\9o,V(yWHZ\d%EJR}^?Ƣ,섾C#Oà%wS]`ª$kÕNflnT:wrE8naZJ7&%9p[N2y }bSo ߰`-k*JD&9ll1rަ%z]({s&Sjn]~Jkeb[%\x"Rޟ1qAq %}㫽TJ5Y}YZmYw̯k,UWN4kt/!Q=&ruN)o> 6$M[~XEo an/>uުl ES5׍cdZJuX2ҀL0" 6({|uy4e+,_Yʁrd{%X Wf>?L5e UO¿|"sV&'0~m܂}vSjcn>Gpa悃RdlMlbxJ {.֏̭zzU: 3b{Yp賀;:%(uyV2/& _i&GtO;њ{4$#[KY0{Nwe(¢j*\.9} ?T 'r(Iv4Oy}Sܶڭ2`棌WjdZJÑQNoȷV ޝ\*GNcyb# V׊j9J^0(E ":y_t"|> LӰҏoN+{ EOOj}-xt%=T镧m$s Z*rɸi8C7%D"/b% DW3tn&=i)O+y%J^{멆L`~ZhiQxL(EgU O;98fXx\1Jr ,ҀYR2MLf^wE=Iן=?I-a/Pq Xe^D$=kRU !{Wӷu.&3<%/KW!$j3` W=@=`q 02xU4TO,x[,"?O7.= Vuᅱ(֤pG󆳀)TOX QԀt ̈yo0\F14`TzY-1URzۭL U.K9N,3 O$;N^ۇ]ā:(n87a<+fjgU(rYru2yj,Do{E@.6y,BIK~wI4W|O%5z8LUX1xtżTSAf!!lX_RGGN,EPbx9q7i)tdc'*Vp?Xd> ZQg3o2;$bn(V測%W)<x1*㮄= $<+rxz3qYpа;'7t;B6=YCoe"`&*wJz%WΣ uv1Djxl4f"vDRkQ!dgXp f 2i87sLHSΠe: aG:Rn!&+lH;ETQ2+iByn AWvB+se9>}\| ð&Kk%u=*K,*M] eN04öWj#:w6iʀT+o\D OV3ch7 #\1BJsQmp_sɔ{V,<8(Zsʲ0U(\9ᤎ27}®y#~ c&;ޥ <9Fg Crs diI>~]!n"KHԛ_D[`5mc⓫:ЛNuyz` d6{h顶WM}p.UxyR:vPkW߽#xߘ; 4&6+̄3ڄbwTտmoC!VČ9M2;JvB=I|" 0Rl5hl9oWsl& sh/?.v9 h72ŃcAy :ߡ=p>-:qXŝv3l<_&=@Rhhd ~bt{y(*҈32 b+j 6yxHjdf)|Җ (Ħ#KV(w9Ҡ.8zsP2aMqkH).#Fސ;o%a/ Y4Y@d7՜+A3YDK2YN($; Tx?&. 8]xZYdZKBLk22TXʕ=I Sb}en5st>%A0yj*i.Š+d_>< C\K|SH,\~^^gnZLšJ4Tc9kFz@kH:/r?E!C4rf3%%kAڔndr fHvgzϺP[zKm=;lZGj[o9q1t'UAH!H^pZH lXi$떬)O1CQ򽻳Cu=|X'G_u:<KɄ{`lokͺN%skQMwSWAo2[[&J3Zl:Nk-k &!C S85tVF} |d)!C`ƭ\n~M4_2&v)ǹCX4ͱ G~)cװ0RvsJ}vj#ICVֲNX )a! FG]nma7-PJNlD@=m&ZUȤ?`U`&%?ŗfeh@0# o\_JߵSg !s/ 3$ٟvEyzP\ i<4ڭªPvNDҫ'r5^ͷeUTJ6)o ]FrJP'1> |8Xd3m +E[5~ =ջSh=r&rr_BWEpˇssQ]HqUviy>Ȉ5eݳ uLBA7$l(/K.p퍯VL S<$Fj- AWQ8G#*+EXz E$rCI{WC5={Mta gMkVtv_jb/P눘鿖F824}1 D KnOO@̏K¿Nbn;l_ErerE:;ҡ3Ri:7`ߙG12WĺUFÒZRobn;PMjk}#2̫?ׯr8c*2,zV]N@ƧzKe&=Mԫ=PQsxӼs;pOMl ư*yFdQZ\˽42=ZNáaswoOFYVBUGImI;_0C:!ӃݙZ:_{9z9) x|y#+oŰkX陣I OKSv#*XɄ+ϒP/;whCP0} ~t$a*q,@D''6-hf!on%<*ʌђ(CmoJiςHS,v-"ށ3rwbDBwf-fKgP⩭y- f\*(Tq O/hXTxVOk0ZCRtrg#+jcc~/_w.CJ^4ԏvC Ӷ}Q P{$4Lyb#a]bث0eą]&'h(] ^(vK ]3 /M.WK3HU^ճӺwVr# ZE*qk0ݜ6WnX?Әw-Ea3}GCe*XvbPT:~,t92U`\4?E@?)IKq>{fkI9֜AEІMUpL2"("5p(om g˲.Yu': e+4i ~s1i^)^qu*'Mj*%`@%p@_6F[)^d?&,pdTm\ :YDj";qAsi=R)>G ͱ:ϣP=$놕}[&*T(#by!ɤU* ְPzذs 4>i#2Eqas#R:Y]H@Vχ u8k%RQ2G`2v٤I#>"rNȞa _;k 2eN{+řLsh ڢ:,)DONaK J :m,OCPW)X ؞WG| }ۛ"q6a2 sِzC-nh5YeinI3⦕sJ xu9t a)݋_o16/w 6n?ΩSn,jjk[u#h$?r0 $0~z*kC uN+VR$}gc֫3S5J;E`s=Uj*0k2\H#wp7[cGɜ%! ǝy\Đ +gR(oƐg&-1ӿnpw9L?:Zu!Xjn\̡}mXdnF__;#k,vw^9V7d5 rSqϥ3Oxp.6k/DHɋ; fJ KM6<[]nZ!! S Z Ci)ҽpvy}S/7c'8V+H~caYʩwM{bm ,ydb}h$21V͔~@%rӫ`rBu r`3nie.i#/Qݪ LUpԽl1 _:LG<I=5<6JXϯ-` D|m;$V Œ#vVjHeOf>Wr0 _^:p hٚ3T[=XUSޥBLC6lH8ܳxkisSe Mwy3{ʷƚUl\PթȿTM; e_;严 D1,0[Y=̓J<Ŭ_2qKGW+>÷3kg֐K^ȳ/w(ʛ0=[|s6}cRBxkruעo~$xpxЏ2}BM @;ͰlW !ܘ}lѪ+Z S:}q_]GkC|t)}ĥte`fxjUHċ}l) V5L=$[=P/2*U|m2z߱ fSV1E5pH?9-ioQ0gWݡ@{!]v2#QʖXax bYD)N?Cl8~0sCrUגX$fa?dFǙgTQmb14J÷67b;e`:_>.z=-CV/=̪xҏYRW3n+ Bmٟ6T'[xj 4&%jz eT%a&He~㲉w>gȎ /x7TN"Rk?3,)?[sR.#OG1>x(,F_YSdSvzT0b.tqb?>BDk :SrL ]"`#|F-0kqin*aEk`u$K'bO`-v3X'k׍.G3|/C?"#:qpGݬ(%H ^Xl*̋LB5'"ȱfuwuX[ ȟ%fʔK6b52^}5q'zr51ɏUrt街| 2<SSe`8:>m>䠩(?_>:!L5=2cGE78G:vJvൕK^Bm`u/61jkT+glv'Iޙ d< >c^ďAHV~Q[㞫ʽ4i OC 6rVeg|pplfxCqP`A'h$+}$>hpNYX0#": |`: #Ǽᨠd+P dᱥxn:(vmѼj1i#jk(ρ!wp 3waWnp?\|P؆,=目Y31~/#8._{HMaÁ'Kw*yX$]" ^P! 8_ZNN5_~=)'n.a0mӦX~TֻB.W/#, A✚jXPUcD'1Ё.}=pBK1f:/lr*Jj˭c<^z&yg#HymƊz(xkr=haרxJY,mgp$)ϱe)=( 7G>W7b9cJnAڐ 4o?sx!iW ž3^$E=Av%mH-dymGK^$#€/v^& .>=,ɂ燘hlnE-Z: 3l;-!ԙAL>$52"4ZͳQb!%mSό?~̝*ġ-[9Kb? ЉK6a"Xx[bBg/9^|^'! f6ܪ X/( pwue~lm5:nWD=%f$,x2d(aY- m߇hO-.7 ۂ0k#–E91ֹqڹ/hzft| Z0‹'E?5hO˰y3NN4ʏYp[|JmUX+6(!* {(K &wwL'w@) O=^TM,[jcBc~w/_RvǑ\ [7}M8&s"\W伂*N=>VIe9NMuZOÛPleK""Ρ5?$b$x6l)^=OưT>.3bc9|=}orw 0S}տ;7C^|Y25_,P+>8H>!i9h$s'%I r] E_~q ġ0 !e2A‚ )=̲>[1B3RqV+4C 14mϠ4nd$ub"N'c*XFҶ1r!moM8i-a ^dsuRR;]rV-) 4T*I68Hͱ!l5f͗n#h.9(T:Ct|P3l7*=Zg C$ck6ƚ-l(D=YNXAmlGvqyQ+4ܮ'>0M\'vٷVBoi R *)Hh+`!*yxHf]wH*Z~R?5Q`E)C PR&^r}b9,UE·YkׇQµcbfgWC1V  |9kJ.C3%JBH:pe=ەAU&c#{`0ss@0(Z ӰgUO0B݈ڢPV? ɡeGkz{MϪI|g@ˈZb_dJ:Ԕ 38TᬖuaWHsWeMԗl- Sf\%:LjE/BT}ЂdQ: 3$6Na95CPe>_vӹ]福1[w/w-\bƌ9ngHM.aUI\]Ird:HbkwbjFV~H9&T V h0 j# e!p[~̳+PqK UHn9B/ի.Bz h&9($2f^[-z~oa7WЅja&?2Q4s+TPSkba=[V3E9y}VKF{6mdLC@^T%;h~V=p{y[ojkűwBNÓ:/2,ORMd "cO⥊..i(*;*c ܔ3he.Z ;`GD$X/D(K#lFEX(YN|x–Ex- >)j&)(&{w]"fKW&,@mWO;_b$u/ Jld#vev' Xy`v)O8ј;Tb-ysA$ WZ.a^cќ4Z z_ϩxs8% | ft!S'( S'KA]Btx4uL)1GC>=HqQrIy h,<`qOsE6vbP_M=)|) 4p[0aɍyRES)05iQLKgHOUÝ Q1Ӫy[*"UTR eCtH0&@]h6}x܆ GJ9UyW0O'U|TfHӓbzbOLoW=KB1Iq?3ʼ9oɾ&I' o+ZiuDYb'ì|u$[QI_R{DG7rգc`rp1CH_ռRh yK"Yk 7qx*qHw>_JGp&hj`>4 z']sB#ʗD-1l 'cQ_-~[bq%'y#k`a3A^Uϗ!vgৼ,.I.Cu\gYݧ6Roc2BdweXz,:1l]>9i z3 !]c"3/fK7TgsP#xC|=xTL]-}v*DҪ,.i㯲۝#5c5Z"R2KU3S@3Wm-'Ч#SP'՝iU_Ǝ LpWWR.k`ˋ处./*"{`N+}5 Z8$2jρݓ7 lt+ݕC,<{3KSyA꼔B}.l\+(pDWKz4CZq&.Ev&St+&ZZlVUsB$G0ċ6#t`uS Ci}9@=,K&[nxk1 wq/NF )? 7W(BE;Aj" [ѵ\LqvPD^(`^i~)Y; <%# ?Krs$̈́-^@?dAGŧWvnlLzqHZu%vl3eC 3cz0Gyrj78B(8d4&+/ o銸ѧfB;oIjE-<2!3WyL~s}"_溱f/:;o491T_{@*$h:3YeBD.hWp`KF7loI5:|@ޢC5Sf_}F_fc;Ņ*U,JO1dkl?_%ЈJp`9۫c9,WZ(`h}~2:dï\q>\Ęwɖ;%_A<&ʿ 8.M%w,#o xs!n4|F % MpH 4.Ԛ .t`N&,tP=R2Id~V wasI+: ^,2?ajχ,oˁ,["G#c/v'% y >7sr+;#w΋;Ed8b/(x纷9[8ң޳7 k&Xxf`"rocI]Fva{(_{eNJ.# ֜,C٪@mY|A U*ADw:>vqR)=Ǭ)3baCEGD;ZQuV^UC4љ3 ,OSĨ!˛ݐޢ:DqKf8@WKK3̳~>*R }(T/G.[A&dá@DκJ0h ZMpl^#F]@ql(&|}YP~F`Ę pdh;QB VbrDh!v΄` abZ-d$k-F)\j}Q/t%yR6YK+V%MM|V1  kG:IBےcWJ:oĀȄUw!oq {deia4'Rs`\GA+e wIՌg悚k80d$"K(|[sr/Yp^i(7 d[kׄcgTxd]g洿lv4&' KyOC脟nmQٵB]Pe$պ9 'T&y]P>[2>Rk4 #9wGEL뺏& ;Xxk EXzM+Nx^6z|pAt|/eUp 2Gj<v|Okq4Bg.Y\BS/)޹$͠AFXrlrR/RC|wsK6'2%%) ;&p#< N)wrnS5M/PirY 54DV-B1\S&LՓYTq',Y@&VFGFb:4\Iu~B>u;՛_Suw;;D, 5kVk4v~A(to.16,aDPIW?(C2+a9V! }壭6#oA]?5Wq *{-_z4M;/*BiW:Q}IWw0LBL}i 8< 虚+x-j_hw;aQ.]9f^z'zn$)@vЈ09`q%*,č'EJnLUC~h"f?~O3 y:TEPI%ٓeg IpXCЖ9 ATt| Z SHVJ{9q Twy9rjUbp1 U˜U-X'ӒtZY؟*;AQgYP>cݐծV(DA~rd:Wwz`i;tkɉ3Qf6\rԕ7#p{y+ɡCRb| 3gAP=41'¸(["OAi,ފ涃kF0iCȇ`,k`G@5nss7)/U-[%ǒ.H Y8Z.'zmV^0=´5C!hb҇ Hwx@f)%{Ij\܈Dz8i<˷>>wp䐅Ѯ&WSڟ Hh#5=k`69$a\$eWk[nVK'6mJbB ra8ʙ0TdQ1wi!paYq#bPnVq^NjC^ACި^/km1dn~hdk`.hcи<0\!6$?7THY=hwhJ}-KpaZ?:aD2)eZG1/nuIzJb (Ȭ YZ