-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Format: 1.8 Date: Fri, 15 Mar 2013 19:32:40 +0100 Source: lighttpd Binary: lighttpd lighttpd-doc lighttpd-mod-mysql-vhost lighttpd-mod-trigger-b4-dl lighttpd-mod-cml lighttpd-mod-magnet lighttpd-mod-webdav Architecture: source amd64 all Version: 1.4.28-2+squeeze1.3 Distribution: stable-security Urgency: high Maintainer: Debian lighttpd maintainers <pkg-lighttpd-maintainers@lists.alioth.debian.org> Changed-By: Arno Töll <arno@debian.org> Description: lighttpd - A fast webserver with minimal memory footprint lighttpd-doc - Documentation for lighttpd lighttpd-mod-cml - Cache meta language module for lighttpd lighttpd-mod-magnet - Control the request handling module for lighttpd lighttpd-mod-mysql-vhost - MySQL-based virtual host configuration for lighttpd lighttpd-mod-trigger-b4-dl - Anti-deep-linking module for lighttpd lighttpd-mod-webdav - WebDAV module for lighttpd Changes: lighttpd (1.4.28-2+squeeze1.3) stable-security; urgency=high . * CVE-2013-1427: Switch the socket path for PHP when using FastCGI. /tmp is world-writable which may cause security implications if an attacker manages to control /tmp/php.socket before the web server (re-)starts. Checksums-Sha1: 0aac4ffd1bf00effcaeeb026c393d1e689f62130 2322 lighttpd_1.4.28-2+squeeze1.3.dsc 2178dca954604c8cd99fbe099b5444f6feb6e194 31357 lighttpd_1.4.28-2+squeeze1.3.debian.tar.gz 8e35144483c149e220ec66edd56a44bcd44d8e9b 289246 lighttpd_1.4.28-2+squeeze1.3_amd64.deb 9b2b8ac677add1f317326e1151e50324a8b7ddc4 19324 lighttpd-mod-mysql-vhost_1.4.28-2+squeeze1.3_amd64.deb 74c70f1c453edc44606d16c014375cb3cc67db20 20880 lighttpd-mod-trigger-b4-dl_1.4.28-2+squeeze1.3_amd64.deb 835e26ef946d68e07e309f3ac21d138bdd1a3e2e 23994 lighttpd-mod-cml_1.4.28-2+squeeze1.3_amd64.deb 97eb30e09cba6bc06494a97b65d43619b6994fac 25202 lighttpd-mod-magnet_1.4.28-2+squeeze1.3_amd64.deb ec8eeeea5fb6e120992cb0559f57968f925a77ef 31422 lighttpd-mod-webdav_1.4.28-2+squeeze1.3_amd64.deb 8aa16050a97148839a469dd167a5725519434d72 63704 lighttpd-doc_1.4.28-2+squeeze1.3_all.deb Checksums-Sha256: 042c219708a4c096a3d5cf3f29224f4239f5fe340c71e60b132ca049a7ce6322 2322 lighttpd_1.4.28-2+squeeze1.3.dsc 1b681731e70f6d509d676c85c497820f2ee047ba24b0c7055dad66ea1e8d4f1e 31357 lighttpd_1.4.28-2+squeeze1.3.debian.tar.gz dbec77844188a4be3d7fea949ddf0e833cab82903962532f6017cab523d294f5 289246 lighttpd_1.4.28-2+squeeze1.3_amd64.deb 97238a82e6ac5eba60521094488d11ffeabf2ad9edced5a9fac748f9f629f0a2 19324 lighttpd-mod-mysql-vhost_1.4.28-2+squeeze1.3_amd64.deb 36be394b947820dba92b1c13d457c38f3f0aa36b61e15ed1daef6f778177ac94 20880 lighttpd-mod-trigger-b4-dl_1.4.28-2+squeeze1.3_amd64.deb 406d5baedf1a580ed9da815b5c079cb2aab085d6767d5140cec7f7adc4853921 23994 lighttpd-mod-cml_1.4.28-2+squeeze1.3_amd64.deb 2b594c2544608a16528b82a3078926cde9c2df4d3a306d553d0cb796deb040df 25202 lighttpd-mod-magnet_1.4.28-2+squeeze1.3_amd64.deb 82869bd36f33b40323f2ba80574301faa66f2d2f13ebffe30ef98bbc2cb87a66 31422 lighttpd-mod-webdav_1.4.28-2+squeeze1.3_amd64.deb e70c1574ffc7cf05ee3602f713c1614aed64d26c384098c199e26ade6f3c4feb 63704 lighttpd-doc_1.4.28-2+squeeze1.3_all.deb Files: 535633bfe5af671a37f2e10355c1197f 2322 httpd optional lighttpd_1.4.28-2+squeeze1.3.dsc 0f29cae27624cc30763261abcfcfecbd 31357 httpd optional lighttpd_1.4.28-2+squeeze1.3.debian.tar.gz 9e1a7a85caecbee01324d1468cc30bb3 289246 httpd optional lighttpd_1.4.28-2+squeeze1.3_amd64.deb 40915162a32f72675539084ea25321ef 19324 httpd optional lighttpd-mod-mysql-vhost_1.4.28-2+squeeze1.3_amd64.deb cf07aae69d986c1c14ad538161af324e 20880 httpd optional lighttpd-mod-trigger-b4-dl_1.4.28-2+squeeze1.3_amd64.deb 99c66bf4bc886baa8fa77b7f2ff4c320 23994 httpd optional lighttpd-mod-cml_1.4.28-2+squeeze1.3_amd64.deb c0f9c26a1a949de3fe59d69438bf8eb2 25202 httpd optional lighttpd-mod-magnet_1.4.28-2+squeeze1.3_amd64.deb 66ea1e69dd19b3942ce7cff393d094c8 31422 httpd optional lighttpd-mod-webdav_1.4.28-2+squeeze1.3_amd64.deb d7a727a03e59d805e456780110c75a6f 63704 doc optional lighttpd-doc_1.4.28-2+squeeze1.3_all.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQIcBAEBAgAGBQJRQ3yPAAoJEMcrUe6dgPNthFEQAMq2ZO08ZQh4YBtsxB8km425 J+vmZpOk+/fj40l/ABXzD0+3pjy0QpfiL2hv3x1RyOz/W633OdHguOb8LlzfqPQA y5zdklKLJWSuzPHgtemH7Ol3aZeOIZpm6DwdnMDypjYe94/yoysXaSz+UnNsSCM5 o5wNRywQQgNw0R+k5GUtz4JoW49JLdq8iFaaQ9Xx/Q0jATBVAyOnebQRo8NubuUy 10WN+4Q0aYGCkmbm07xrM1oWggK9l0qYXuLdu0vHd2Qd8FjzF1WnlWN6XiiCFDlU QhMIWrBkZ5FcIZvUTwrM1cdAPsRQNjhOF6ea1ID9dVwPOh6HJMuT7PdtTZfnHb+R GpTsjz7TuFkLscrqaMgVqoZz7uNNtI6FdFLozMGUs0HISRJtofJoKsO3clzl20KT k3Zb+41qe6ecAsiBfoNuy56A2kEVq/odJBr+GQSgwu9iNvrBcRcy2R2CcFDOkEDX dUV2UttQgto5t31SdTOW0lCV80ArWdObckOcsoF7o3s3uq9M3Y5bl4SxBgp145J7 txnePWnCnEmCMl4x7rniiPxcSVcBxyUNqyL+xzf0tpvwzfT6ZfQVuwx6I+8CGzyU qPHl8vN3djEcMM5cepnYZ7+Rav1OotJx6EKpq+OvWOMQQgCh4pCC+AHxtaTVxXoh ogprhVGpnyNx4VEFMuDJ =bEQk -----END PGP SIGNATURE-----