-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Mon, 12 Oct 2020 11:47:49 +0200 Source: yaws Architecture: source Version: 2.0.6+dfsg-1+deb10u1 Distribution: buster-security Urgency: high Maintainer: Debian Erlang Packagers <pkg-erlang-devel@lists.alioth.debian.org> Changed-By: Salvatore Bonaccorso <carnil@debian.org> Changes: yaws (2.0.6+dfsg-1+deb10u1) buster-security; urgency=high . * Non-maintainer upload by the Security Team. * Reject external entities in DAV requests (CVE-2020-24379) * Fix unused variable warning * Sanitize CGI requests (CVE-2020-24916) Checksums-Sha1: 884d819a909fee7eeabb90f32ecf754fc619c335 2686 yaws_2.0.6+dfsg-1+deb10u1.dsc 233fc3b258cb7c9c87cc7e861a835d7d742ade1e 1126388 yaws_2.0.6+dfsg.orig.tar.xz d3fa078b1a526c3b74632c0bebb7c35dcaa4ff3f 29108 yaws_2.0.6+dfsg-1+deb10u1.debian.tar.xz Checksums-Sha256: f34cce76841d7d7c9da4d86076e6c22dd7598bf6b761dfce8f0c885ee8443833 2686 yaws_2.0.6+dfsg-1+deb10u1.dsc 4466cee9bd7f7d60363e9bffbf442aee95d69b523bda2e45a2c3549284ed8b41 1126388 yaws_2.0.6+dfsg.orig.tar.xz 6a6b1fa3126807a24ae3e099f58af7502f97f593b11ae964d4333d2f50634289 29108 yaws_2.0.6+dfsg-1+deb10u1.debian.tar.xz Files: fffb8973c54201e30eba334d07222fb8 2686 httpd optional yaws_2.0.6+dfsg-1+deb10u1.dsc 2017141d97d8ffdd816d7acfccca5e4b 1126388 httpd optional yaws_2.0.6+dfsg.orig.tar.xz 9092d6b724c6c7de2e8fa25e6ebd4569 29108 httpd optional yaws_2.0.6+dfsg-1+deb10u1.debian.tar.xz -----BEGIN PGP SIGNATURE----- iQKmBAEBCgCQFiEERkRAmAjBceBVMd3uBUy48xNDz0QFAl+EJ8dfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2 NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQSHGNhcm5pbEBk ZWJpYW4ub3JnAAoJEAVMuPMTQ89EViAP/2N75CE3e2kDmGTApaVwxu21njGUe5Rb fveZRH27NElH1K2ymqW/Ey5q93mL5GWtZS3TdAbAA87NrHM1QRaVpCVfjl4AoLg6 wCIKCkHBNWsyC8VPfgGZz2RGM+PF8mxyBUct7cSmi2BCChbgxI816ifjhTD/pB3S Auis7kjVhwleP7h9G81TJMpEQAWej8CsyfZtWsgXoZKvr/gOFArJ20l9uT7ur4o3 zb6Nl40lvZLhDTrUgpp/Lym5TsODaiVA2Wc1HcAycyLc1UvLQorUOZSvL1s4VvXY q/YmAkYGum1/Ca34SYmFuGbtf6WpFyGFeVL1uSxZOixOOsKULqqdGqOO7hO/N5CZ yCVbNDIzSKfIWECqrbR7lgPiUFy/lymz1RgJDRTsXMauBQIB+vsT6otdF3js26kD WXA4sfxCDT8wvRLDhAqS/Y2pDgKiK2ibi+9Ng00rWbPZ2asLVPLOFMiMIeqFj4NB 3EwsZyf61zSsBqJhJ1aNkaqCq87xCIwJ9SaYkmf6/Fm4/IYZ8tb0FBCwrlXTYERP 2KpsiV/GYY27IC1n3NlmLPTzA3sSDwwIJdPl3Utpmvil8JjabJsxErAf5zO6DLAH 5KpuiCduZg8KnPaCrSMMzzkqIvkrRfPx0oxG+DEN+bhHxvyLiecC7x6fESeBFNY4 cJdNZCMs7Xg9 =Sp6c -----END PGP SIGNATURE-----