-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sat, 25 Sep 2021 20:19:04 +0200 Source: uwsgi Binary: uwsgi uwsgi-dbg uwsgi-src uwsgi-core uwsgi-emperor uwsgi-plugins-all uwsgi-infrastructure-plugins uwsgi-app-integration-plugins uwsgi-mongodb-plugins uwsgi-plugin-alarm-curl uwsgi-plugin-alarm-xmpp uwsgi-plugin-curl-cron uwsgi-plugin-emperor-pg uwsgi-plugin-glusterfs uwsgi-plugin-rados uwsgi-plugin-rbthreads uwsgi-plugin-fiber uwsgi-plugin-geoip uwsgi-plugin-graylog2 uwsgi-plugin-gevent-python uwsgi-plugin-greenlet-python uwsgi-plugin-asyncio-python uwsgi-plugin-asyncio-python3 uwsgi-plugin-tornado-python uwsgi-plugin-gccgo uwsgi-plugin-jvm-openjdk-8 uwsgi-plugin-jwsgi-openjdk-8 uwsgi-plugin-ring-openjdk-8 uwsgi-plugin-servlet-openjdk-8 uwsgi-plugin-ldap uwsgi-plugin-lua5.1 uwsgi-plugin-lua5.2 uwsgi-plugin-luajit uwsgi-plugin-mono uwsgi-plugin-psgi uwsgi-plugin-python uwsgi-plugin-python3 uwsgi-plugin-rack-ruby2.3 uwsgi-plugin-router-access uwsgi-plugin-sqlite3 uwsgi-plugin-v8 uwsgi-plugin-php uwsgi-plugin-xslt libapache2-mod-proxy-uwsgi libapache2-mod-proxy-uwsgi-dbg libapache2-mod-uwsgi libapache2-mod-uwsgi-dbg libapache2-mod-ruwsgi libapache2-mod-ruwsgi-dbg python-uwsgidecorators python3-uwsgidecorators uwsgi-extra Architecture: source Version: 2.0.14+20161117-3+deb9u4 Distribution: stretch-security Urgency: high Maintainer: uWSGI packaging team <pkg-uwsgi-devel@lists.alioth.debian.org> Changed-By: Sylvain Beucler <beuc@debian.org> Description: libapache2-mod-proxy-uwsgi - uwsgi proxy module for Apache2 (mod_uwsgi) libapache2-mod-proxy-uwsgi-dbg - debugging symbols for Apache2 mod_proxy_uwsgi libapache2-mod-ruwsgi - uwsgi module for Apache2 (mod_Ruwsgi) libapache2-mod-ruwsgi-dbg - debugging symbols for Apache2 mod_Ruwsgi libapache2-mod-uwsgi - uwsgi module for Apache2 (mod_uwsgi) libapache2-mod-uwsgi-dbg - debugging symbols for Apache2 mod_uwsgi python-uwsgidecorators - module of decorators for elegant access to uWSGI API (Python 2) python3-uwsgidecorators - module of decorators for elegant access to uWSGI API (Python 3) uwsgi - fast, self-healing application container server uwsgi-app-integration-plugins - plugins for integration of uWSGI and application uwsgi-core - fast, self-healing application container server (core) uwsgi-dbg - debugging symbols for uWSGI server and it's plugins uwsgi-emperor - fast, self-healing application container server (emperor scripts) uwsgi-extra - fast, self-healing application container server (extra files) uwsgi-infrastructure-plugins - infrastructure plugins for uWSGI uwsgi-mongodb-plugins - MongoDB/GridFS plugins for uWSGI uwsgi-plugin-alarm-curl - cURL alarm plugin for uWSGI uwsgi-plugin-alarm-xmpp - XMPP alarm plugin for uWSGI uwsgi-plugin-asyncio-python - asyncio plugin for uWSGI (Python 2) uwsgi-plugin-asyncio-python3 - asyncio plugin for uWSGI (Python 3) uwsgi-plugin-curl-cron - cron cURL plugin for uWSGI uwsgi-plugin-emperor-pg - Emperor PostgreSQL plugin for uWSGI uwsgi-plugin-fiber - Fiber plugin for uWSGI uwsgi-plugin-gccgo - GNU Go plugin for uWSGI uwsgi-plugin-geoip - GeoIP plugin for uWSGI uwsgi-plugin-gevent-python - gevent plugin for uWSGI (Python 2) uwsgi-plugin-glusterfs - GlusterFS storage plugin for uWSGI uwsgi-plugin-graylog2 - graylog2 plugin for uWSGI uwsgi-plugin-greenlet-python - greenlet plugin for uWSGI (Python 2) uwsgi-plugin-jvm-openjdk-8 - Java plugin for uWSGI (OpenJDK 8) uwsgi-plugin-jwsgi-openjdk-8 - JWSGI plugin for uWSGI (OpenJDK 8) uwsgi-plugin-ldap - LDAP plugin for uWSGI uwsgi-plugin-lua5.1 - Lua WSAPI plugin for uWSGI (Lua 5.1) uwsgi-plugin-lua5.2 - Lua WSAPI plugin for uWSGI (Lua 5.2) uwsgi-plugin-luajit - Lua WSAPI plugin for uWSGI (LuaJIT) uwsgi-plugin-mono - Mono/ASP.NET plugin for uWSGI uwsgi-plugin-php - PHP plugin for uWSGI uwsgi-plugin-psgi - Perl PSGI plugin for uWSGI uwsgi-plugin-python - WSGI plugin for uWSGI (Python 2) uwsgi-plugin-python3 - WSGI plugin for uWSGI (Python 3) uwsgi-plugin-rack-ruby2.3 - Rack plugin for uWSGI (${uwsgi:RubyKind}) uwsgi-plugin-rados - Ceph/RADOS storage plugin for uWSGI uwsgi-plugin-rbthreads - Ruby native threads plugin for uWSGI (${uwsgi:RubyDefaultkind}) uwsgi-plugin-ring-openjdk-8 - Closure/Ring plugin for uWSGI (OpenJDK 8) uwsgi-plugin-router-access - Access router plugin for uWSGI uwsgi-plugin-servlet-openjdk-8 - JWSGI plugin for uWSGI (OpenJDK 8) uwsgi-plugin-sqlite3 - SQLite 3 configurations plugin for uWSGI uwsgi-plugin-tornado-python - tornado plugin for uWSGI (Python 2) uwsgi-plugin-v8 - JavaScript V8 plugin for uWSGI uwsgi-plugin-xslt - XSLT request plugin for uWSGI uwsgi-plugins-all - all available plugins for uWSGI uwsgi-src - sources for uWSGI plugins Changes: uwsgi (2.0.14+20161117-3+deb9u4) stretch-security; urgency=high . * Non-maintainer upload by the LTS Security Team. * CVE-2021-36160: a carefully crafted request uri-path can cause mod_proxy_uwsgi to read above the allocated memory and crash (DoS). Checksums-Sha1: c02f1baa5f4a7e79706fdcdec551f11009c859fc 9015 uwsgi_2.0.14+20161117-3+deb9u4.dsc 5bd848db51881b4fd2422444fbcbbf309c18f50d 54392 uwsgi_2.0.14+20161117-3+deb9u4.debian.tar.xz f7b6c075d4cb6ba897ea56dc6233891cd846b832 45091 uwsgi_2.0.14+20161117-3+deb9u4_amd64.buildinfo Checksums-Sha256: fbb9fb06a49d35ad106b1b338855ebb6a322f7b558c0707f556fe1dbdf36434c 9015 uwsgi_2.0.14+20161117-3+deb9u4.dsc 0568fcdda0861624ea3e8a53ece6343a75d6211329b3fe36605161c8c20a0ad5 54392 uwsgi_2.0.14+20161117-3+deb9u4.debian.tar.xz b60181ea5008c28851625d6a064fa1ccf0a4250958b65b329eef81e115a51fdc 45091 uwsgi_2.0.14+20161117-3+deb9u4_amd64.buildinfo Files: 3e613560693f2a969f5ed3ca860a679a 9015 web extra uwsgi_2.0.14+20161117-3+deb9u4.dsc b68628ff7cad97ab6ae18b76975a0de0 54392 web extra uwsgi_2.0.14+20161117-3+deb9u4.debian.tar.xz 7ee6dc62f155b6653a63060cfdc434ea 45091 web extra uwsgi_2.0.14+20161117-3+deb9u4_amd64.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE1vEOfV7HXWKqBieIDTl9HeUlXjAFAmFUrpMACgkQDTl9HeUl XjAX0g//YQgYodphBnMssCccnRodST/Obi0z8aPxYsLJ+7TztgR1qUbL7j5cNgTP TODwmJ45YzcgczpNjnJNmsPZPw/CQuZM3O7Eo1cDvivZW2X3uP2JI4Q7BaoFAnsv Z/FP1MvcceYQn+j1Y0NkG59x026Wma7Be7JxXzKbtGeslvxpKaboQ3P1pivdDBvV 6cnLG3BYEepRmPV3NGfxfIPYfSCxkPIACkLaHbnr+Ucpx5FVf256Eypo6wCsGHFa CnLJD7zIvzM7h2PTR8WXByMTErxnd8F43joJ0BivvGVvG1vXx+l9m1Z8leT3HZ9M TyC6trZxAh1KOv/WcrAttOTrXmc5QQhzNy6PSnyO02/Q+iXlYtD8TY16/se//dwL W+gBVp2iBvoKsdoEUfBb4IyJdaoZorPSyaMN5Bk4QZ7Gh9Kp5OxNAszqX55x800b V7pqq1XqtmppgQR7+m+2jIWmB5sl/460/GFYNHV7fNLzN3xCB5Tifc41v5Z4hDFm b2lj9y25dbN+6pzLuwHHYzp3F0oDG9sDF2YlTH/qiYbUpQl0St8fysbXsjWVRf5G KtJyT3hsOIul3hfJ+8UX8ZM+P2czMqwub2hO8X+3bYhzFzblx6Dpuihj2sEacBU6 3dmP/aSGlW3fC32eoX2s6hZZw0jVmGln1Qx63AKD16I64ojZDdk= =jsX6 -----END PGP SIGNATURE-----