-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Format: 1.8 Date: Sun, 18 Dec 2011 23:41:49 +0100 Source: lighttpd Binary: lighttpd lighttpd-doc lighttpd-mod-mysql-vhost lighttpd-mod-trigger-b4-dl lighttpd-mod-cml lighttpd-mod-magnet lighttpd-mod-webdav Architecture: source all amd64 Version: 1.4.19-5+lenny3 Distribution: oldstable-security Urgency: high Maintainer: Debian lighttpd maintainers <pkg-lighttpd-maintainers@lists.alioth.debian.org> Changed-By: Arno Töll <debian@toell.net> Description: lighttpd - A fast webserver with minimal memory footprint lighttpd-doc - Documentation for lighttpd lighttpd-mod-cml - Cache meta language module for lighttpd lighttpd-mod-magnet - Control the request handling module for lighttpd lighttpd-mod-mysql-vhost - MySQL-based virtual host configuration for lighttpd lighttpd-mod-trigger-b4-dl - Anti-deep-linking module for lighttpd lighttpd-mod-webdav - WebDAV module for lighttpd Changes: lighttpd (1.4.19-5+lenny3) oldstable-security; urgency=high . * Backport security issues from 1.4.30: + Fix integer overflow (CVE-2011-4362) + Fix attack vector as disclosed by the SSL BEAST attack (related: CVE-2011-3389). Note: If you are upgrading from an older version you need to change your configuration to mitigate effects of the attack. See the corresponding NEWS file for details. Checksums-Sha1: ade40ae06509dc09ab65060c5c023c41c484bd73 1708 lighttpd_1.4.19-5+lenny3.dsc 67eea3090d57a5f4a07eeac0aeefa266b9efcd73 29971 lighttpd_1.4.19-5+lenny3.diff.gz 1696c2c6721c5cea281cdd4b792eb8d68a119a94 110462 lighttpd-doc_1.4.19-5+lenny3_all.deb 34c20dabf817f124610b954daaa08ca320c39d82 325014 lighttpd_1.4.19-5+lenny3_amd64.deb de8107010851a932462acd54a4187cfa6305204b 67716 lighttpd-mod-mysql-vhost_1.4.19-5+lenny3_amd64.deb aa91b3e9b9e4e5877e996020e7b981db5961230a 69382 lighttpd-mod-trigger-b4-dl_1.4.19-5+lenny3_amd64.deb 6f31da8456c7e89505d2949bfa8edd91a7a8f29d 72774 lighttpd-mod-cml_1.4.19-5+lenny3_amd64.deb 1c3d74072c04907535e1bc8305a10b54b42035bc 72434 lighttpd-mod-magnet_1.4.19-5+lenny3_amd64.deb 39fda4b106268c4d97f786ad185ae0bfe54e1baf 79386 lighttpd-mod-webdav_1.4.19-5+lenny3_amd64.deb Checksums-Sha256: 38c31f5f032362aba0e24d32a6af9b5b9b4bf499ffc9b32ea871fce95320e47b 1708 lighttpd_1.4.19-5+lenny3.dsc 9990315c36c747d9b9eb0c77f268fede0881289f7f17a145a693674a330385de 29971 lighttpd_1.4.19-5+lenny3.diff.gz 3cc05b16c1a1538de2ae444012d60b8ee3f52015ddd1be1d655d932a1708e9d1 110462 lighttpd-doc_1.4.19-5+lenny3_all.deb d342fbfe59cfb842d5bb416f60034bd066a46ef30b1c37f4fba0f628f96ddd97 325014 lighttpd_1.4.19-5+lenny3_amd64.deb 1285217db2e68e2d54e1724e348a0efa181051c313f59fb0e338793b2725316b 67716 lighttpd-mod-mysql-vhost_1.4.19-5+lenny3_amd64.deb 2ace9a9a1804cd31d6924389b416210905c5e95c19c5a3d8e6df237aab8772d5 69382 lighttpd-mod-trigger-b4-dl_1.4.19-5+lenny3_amd64.deb 22e912043257d3a752612dedc67e675d7a33bad2087b000b7d9ee0094c2e2d54 72774 lighttpd-mod-cml_1.4.19-5+lenny3_amd64.deb 8b0e140f9b5c1eefffc57378cbd338881ab86c7f86415510c257a6364508ac68 72434 lighttpd-mod-magnet_1.4.19-5+lenny3_amd64.deb 9782f38537405a9f717ee56831cbf419f75d2004b6d5e4eeaa34337bf36e9c3d 79386 lighttpd-mod-webdav_1.4.19-5+lenny3_amd64.deb Files: aa843bce3a8e03dc4a66d45b1414af98 1708 web optional lighttpd_1.4.19-5+lenny3.dsc 42d07c1caf75c19f018abc30896a3771 29971 web optional lighttpd_1.4.19-5+lenny3.diff.gz 14ddcdd50a655e1c6e1fa88b657d60c6 110462 doc optional lighttpd-doc_1.4.19-5+lenny3_all.deb ecfe596fde9c09ac15f07825a053618b 325014 web optional lighttpd_1.4.19-5+lenny3_amd64.deb 04c2f26f4b907f156799a89d800fd150 67716 web optional lighttpd-mod-mysql-vhost_1.4.19-5+lenny3_amd64.deb 1373061a4b18a8fb93587236ee849ced 69382 web optional lighttpd-mod-trigger-b4-dl_1.4.19-5+lenny3_amd64.deb ae68e33d1ff53aab3e3079f2ac70b221 72774 web optional lighttpd-mod-cml_1.4.19-5+lenny3_amd64.deb 217185bc0d26aad9b551d87cb45d8d65 72434 web optional lighttpd-mod-magnet_1.4.19-5+lenny3_amd64.deb a5a29b84f461f053ce64ff889ebf82e2 79386 web optional lighttpd-mod-webdav_1.4.19-5+lenny3_amd64.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.11 (GNU/Linux) iEYEARECAAYFAk7w9XAACgkQHYflSXNkfP90ngCfWviRxy4qA37qvk+X2aWSNzuU BMoAoLlU7KM+rmWVI9Zao1sOgPWA1EG2 =qgr2 -----END PGP SIGNATURE----- Accepted: lighttpd-doc_1.4.19-5+lenny3_all.deb to main/l/lighttpd/lighttpd-doc_1.4.19-5+lenny3_all.deb lighttpd-mod-cml_1.4.19-5+lenny3_amd64.deb to main/l/lighttpd/lighttpd-mod-cml_1.4.19-5+lenny3_amd64.deb lighttpd-mod-magnet_1.4.19-5+lenny3_amd64.deb to main/l/lighttpd/lighttpd-mod-magnet_1.4.19-5+lenny3_amd64.deb lighttpd-mod-mysql-vhost_1.4.19-5+lenny3_amd64.deb to main/l/lighttpd/lighttpd-mod-mysql-vhost_1.4.19-5+lenny3_amd64.deb lighttpd-mod-trigger-b4-dl_1.4.19-5+lenny3_amd64.deb to main/l/lighttpd/lighttpd-mod-trigger-b4-dl_1.4.19-5+lenny3_amd64.deb lighttpd-mod-webdav_1.4.19-5+lenny3_amd64.deb to main/l/lighttpd/lighttpd-mod-webdav_1.4.19-5+lenny3_amd64.deb lighttpd_1.4.19-5+lenny3.diff.gz to main/l/lighttpd/lighttpd_1.4.19-5+lenny3.diff.gz lighttpd_1.4.19-5+lenny3.dsc to main/l/lighttpd/lighttpd_1.4.19-5+lenny3.dsc lighttpd_1.4.19-5+lenny3_amd64.deb to main/l/lighttpd/lighttpd_1.4.19-5+lenny3_amd64.deb