-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Format: 1.8 Date: Thu, 14 Mar 2013 02:20:07 +0100 Source: lighttpd Binary: lighttpd lighttpd-doc lighttpd-mod-mysql-vhost lighttpd-mod-trigger-b4-dl lighttpd-mod-cml lighttpd-mod-magnet lighttpd-mod-webdav Architecture: source amd64 all Version: 1.4.31-4 Distribution: unstable Urgency: high Maintainer: Debian lighttpd maintainers <pkg-lighttpd-maintainers@lists.alioth.debian.org> Changed-By: Arno Töll <arno@debian.org> Description: lighttpd - fast webserver with minimal memory footprint lighttpd-doc - documentation for lighttpd lighttpd-mod-cml - cache meta language module for lighttpd lighttpd-mod-magnet - control the request handling module for lighttpd lighttpd-mod-mysql-vhost - MySQL-based virtual host configuration for lighttpd lighttpd-mod-trigger-b4-dl - anti-deep-linking module for lighttpd lighttpd-mod-webdav - WebDAV module for lighttpd Changes: lighttpd (1.4.31-4) unstable; urgency=high . * CVE-2013-1427: Switch the socket path for PHP when using FastCGI. /tmp is world-writable which may cause security implications if an attacker manages to control /tmp/php.socket before the web server (re-)starts. * Switch VCS to git * Push standards version (no changes) Checksums-Sha1: e4e1bb92f4df94edd7323fc3df3245a0ea6e6786 2658 lighttpd_1.4.31-4.dsc 3289035b1273ca000ef513fc73b7e5a02fd54093 28416 lighttpd_1.4.31-4.debian.tar.gz 9825d99553e6c643aa9af9d1907a49fe6520d40a 302440 lighttpd_1.4.31-4_amd64.deb 4704cee5acebe6d6e587f5ad09181292b416068a 64024 lighttpd-doc_1.4.31-4_all.deb b147267d577eae72aded2c8554353897177a8459 20050 lighttpd-mod-mysql-vhost_1.4.31-4_amd64.deb e91ed4851356524305c73e089c36f0f11862a011 21568 lighttpd-mod-trigger-b4-dl_1.4.31-4_amd64.deb 50d99b580ff5e9eb72b9fab76d7178ac9d06ea69 24864 lighttpd-mod-cml_1.4.31-4_amd64.deb c5b0305d587c441002fd39cbbf07d2ade38de5f2 26012 lighttpd-mod-magnet_1.4.31-4_amd64.deb bdaf3c638cca945017ae64ecf9ca7ef00a121bb9 32280 lighttpd-mod-webdav_1.4.31-4_amd64.deb Checksums-Sha256: fa9f9be0eceedef29c347632a4f6e0ce7bf786a3e95dda9943a9dd3b626ab731 2658 lighttpd_1.4.31-4.dsc 1ad2198c78b5d6903a4d71ec682cd1ef313e937d0a7dd656890afdb204213299 28416 lighttpd_1.4.31-4.debian.tar.gz 16dbca8833546f301d1a22fc1b5d384cc3f4b693fe3f51928246079c526b922f 302440 lighttpd_1.4.31-4_amd64.deb 52f4814fb75c08fb52e5edb40909202d5c2ca5f22bed67621d7673cf9dcefa57 64024 lighttpd-doc_1.4.31-4_all.deb eff56d0aecba8adb93a0e00d8f71f9d4dfca0ebd06edd973815e5c59eebef10b 20050 lighttpd-mod-mysql-vhost_1.4.31-4_amd64.deb 3265b7b6f873c80ec81edde6664d4be821a910c9db8c970fc6511fe738ffa48a 21568 lighttpd-mod-trigger-b4-dl_1.4.31-4_amd64.deb 195b723421117dede917889f1fa8a4b4aa1d3200c510e3ce2d1bfa0d9403064b 24864 lighttpd-mod-cml_1.4.31-4_amd64.deb 139f13d0428f4b6d3e32a1af69d779bbf4e81bbf464382ab8cfa46961dbcf8c1 26012 lighttpd-mod-magnet_1.4.31-4_amd64.deb 747a4baf96fa15698cc9d7b8a4c4e632ed52df19fd0a09f05269146a2cebe045 32280 lighttpd-mod-webdav_1.4.31-4_amd64.deb Files: a323321da8c7e7e549ce8a2a92767818 2658 httpd optional lighttpd_1.4.31-4.dsc 81bb537f06258ad53482d4dd831fc6e6 28416 httpd optional lighttpd_1.4.31-4.debian.tar.gz 9a96559b3237e502ee651b438cebb396 302440 httpd optional lighttpd_1.4.31-4_amd64.deb 46acba59d2b5143fb5c7e51d75cd2e17 64024 doc optional lighttpd-doc_1.4.31-4_all.deb 93119503745ca6f3282c3786b04847a4 20050 httpd optional lighttpd-mod-mysql-vhost_1.4.31-4_amd64.deb 829bad42608f2257b5255185991f99b6 21568 httpd optional lighttpd-mod-trigger-b4-dl_1.4.31-4_amd64.deb da00043ef0df93bdf8e1c8e7825c0018 24864 httpd optional lighttpd-mod-cml_1.4.31-4_amd64.deb 5e0c39dae50dc76fa15f2b05e550dce0 26012 httpd optional lighttpd-mod-magnet_1.4.31-4_amd64.deb a290b89be74308ef314ada04ef60f6b0 32280 httpd optional lighttpd-mod-webdav_1.4.31-4_amd64.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQIcBAEBAgAGBQJRQ3yFAAoJEMcrUe6dgPNtQCQP/35HmnSbS83zp7aXUjcV63ab m8iMGhouCiMBbiKS4S6hNmZ7hqvwQ07UI7ZugZ4VYsetfe8CJWtiOo55e52xwLq5 AUC0iPF+vkM0YAcmBP8Zc8Xwnxsz1wejxOL/6Z4d3msAIscE2JhAMZMgf5TAwujl K4C+Ng7fgA4YMTkYqNLPGS5RA4vuS3ZW9qn1qKo4UDcGdW52N8hICdrWFjpBBPnE ybfyYRABYyU/U/YC9fFE83GVAhnwUH1EDnDyTD+gnSoRdxtryvfDuEkuVCk10ckH 9jGNJEWQY/gGnDjl88MFhDzWqozkaS6EyNmLlviYgFtMnsiqiEs9XC+T7oTT3Uqh SsD348Q98QAVx4nOBKMrzEucF44qPszWCV0qqMoxHuEjigVPpYAAtZI2b6fluLWH g3zO/Rk0eXXsLTW3mPr6GKjmitqeixDRu5gNhclMIdLewfHyoK0cyCS6op/GpylY UJNGPtcIAqvA61DFqMCxOWsq3eIQexPyIzaPP1cNePw19fiQXDiFdzGLSSDj00OK Bgr4BE9OJtaPF+ewrH7aIyCiQPFmUdyemdDJq/lJJFbJc0yyjr3ObFjEGpb41uoU Lw2un6jZZ1GS0wPiGJ3wHnjtEvnv/pe7TJvjz5EGyeizweG00AMD+kvsTCUk8imU FUGSgCsSEvA54To+yNm/ =FVDS -----END PGP SIGNATURE-----