-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 13 Nov 2013 03:11:40 +0000 Source: lighttpd Binary: lighttpd lighttpd-doc lighttpd-mod-mysql-vhost lighttpd-mod-trigger-b4-dl lighttpd-mod-cml lighttpd-mod-magnet lighttpd-mod-webdav Architecture: source amd64 all Version: 1.4.28-2+squeeze1.4 Distribution: oldstable-security Urgency: high Maintainer: Debian lighttpd maintainers <pkg-lighttpd-maintainers@lists.alioth.debian.org> Changed-By: Michael Gilbert <mgilbert@debian.org> Description: lighttpd - A fast webserver with minimal memory footprint lighttpd-doc - Documentation for lighttpd lighttpd-mod-cml - Cache meta language module for lighttpd lighttpd-mod-magnet - Control the request handling module for lighttpd lighttpd-mod-mysql-vhost - MySQL-based virtual host configuration for lighttpd lighttpd-mod-trigger-b4-dl - Anti-deep-linking module for lighttpd lighttpd-mod-webdav - WebDAV module for lighttpd Changes: lighttpd (1.4.28-2+squeeze1.4) oldstable-security; urgency=high . * Non-maintainer upload by the Security Team. * Fix cve-2013-4508: ssl cipher suites issue. * Fix cve-2013-4559: setuid privilege escalation issue. * Fix cve-2013-4560: use-after-free in fam. Checksums-Sha1: 0030684f5cf3abe703d87438a302887c2a403358 3018 lighttpd_1.4.28-2+squeeze1.4.dsc 24d614f75b3aba18f3cff5e52a27ec9fdcf853b5 808352 lighttpd_1.4.28.orig.tar.gz a5efb24425438a9922dc6febe89194095fae7f16 35080 lighttpd_1.4.28-2+squeeze1.4.debian.tar.gz bc017c280257a541f1906a332f9baa9530c5223a 290872 lighttpd_1.4.28-2+squeeze1.4_amd64.deb a44dbdfd297a6e5587ce2e8ee95ef421cccf8382 19426 lighttpd-mod-mysql-vhost_1.4.28-2+squeeze1.4_amd64.deb 0c26f193378e282e5f679844ef57217ea3753f23 21092 lighttpd-mod-trigger-b4-dl_1.4.28-2+squeeze1.4_amd64.deb 6d2055c32e4e5056c40abe55807c3166899e5e18 24226 lighttpd-mod-cml_1.4.28-2+squeeze1.4_amd64.deb ed1c585de5a13ba5c3174fad02e47c7577d8c94b 25460 lighttpd-mod-magnet_1.4.28-2+squeeze1.4_amd64.deb 6362c1e53542c1265eb396b876f34fb678575cbe 31708 lighttpd-mod-webdav_1.4.28-2+squeeze1.4_amd64.deb 5eb6ba194b7aebece3b96aa97fd4ace763462b45 63654 lighttpd-doc_1.4.28-2+squeeze1.4_all.deb Checksums-Sha256: dce363e687cb3fae0cd03c1ed58ebee5551dd904d503ce4da213017684fd543b 3018 lighttpd_1.4.28-2+squeeze1.4.dsc efd7623f43182723b99c51d57a24158e22a207cd90dca35aaf3b2e3bac115712 808352 lighttpd_1.4.28.orig.tar.gz f2a47ae0f8955ac5c9c338c2419554480f204c0a3ca498ae525d9aea9a3648cd 35080 lighttpd_1.4.28-2+squeeze1.4.debian.tar.gz e3db53bd59bb1250deabbaa5e06c8b02933ba559ea705ca78642a99dea6e9fc2 290872 lighttpd_1.4.28-2+squeeze1.4_amd64.deb 94c2a2b7b669116d59ab0e8c6b2251589b20e843f2d468be56e565985dd4bce6 19426 lighttpd-mod-mysql-vhost_1.4.28-2+squeeze1.4_amd64.deb d7de49e5c0214fbb9ce0e56bad54a7ee523b7a57b9ec0b6b372f7f558ccfacb9 21092 lighttpd-mod-trigger-b4-dl_1.4.28-2+squeeze1.4_amd64.deb 944f0c56fdc619be8a63c3e3b33a20ec0f1c836238d0c387e86183e73565cea0 24226 lighttpd-mod-cml_1.4.28-2+squeeze1.4_amd64.deb 03d92195115437da0611165b0bbf712e186260e848f2c0357d677b282408185a 25460 lighttpd-mod-magnet_1.4.28-2+squeeze1.4_amd64.deb ca5747c36e241f8ab96b5996f0a547c286697a2cc17c9b4f830ee3fe81460a67 31708 lighttpd-mod-webdav_1.4.28-2+squeeze1.4_amd64.deb f2143fe5a1441aa674fcb78ff8ad0dff60b888f91bc36c0c01b2efad50364899 63654 lighttpd-doc_1.4.28-2+squeeze1.4_all.deb Files: 56d060cd3c450e69574807acc46bac14 3018 httpd optional lighttpd_1.4.28-2+squeeze1.4.dsc 202d36efc6324adb95a3600d2826ec6a 808352 httpd optional lighttpd_1.4.28.orig.tar.gz e6013454406bf470d5d7bbb39c16078d 35080 httpd optional lighttpd_1.4.28-2+squeeze1.4.debian.tar.gz bc156cd016eb32180809e31439f1be5a 290872 httpd optional lighttpd_1.4.28-2+squeeze1.4_amd64.deb 801fa6f457553440967003788370726a 19426 httpd optional lighttpd-mod-mysql-vhost_1.4.28-2+squeeze1.4_amd64.deb 0198023f0278deeec56be03b65944076 21092 httpd optional lighttpd-mod-trigger-b4-dl_1.4.28-2+squeeze1.4_amd64.deb 410b82d285fe6d02eede1fdc737b5ffb 24226 httpd optional lighttpd-mod-cml_1.4.28-2+squeeze1.4_amd64.deb 62d2c21b865e8086d72af86ed77c1ad0 25460 httpd optional lighttpd-mod-magnet_1.4.28-2+squeeze1.4_amd64.deb 10783b8c9a12c4be79cab5db400f3efb 31708 httpd optional lighttpd-mod-webdav_1.4.28-2+squeeze1.4_amd64.deb 89c4b652ebd4c70c96560ed8a611b718 63654 doc optional lighttpd-doc_1.4.28-2+squeeze1.4_all.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.15 (GNU/Linux) iQQcBAEBCgAGBQJSgwTUAAoJELjWss0C1vRzvIkf+wRRqJhwc4b7UE0SJ17U6tPX VbNkyvWh9zmk0ic6qLqcWEj88kJKi4YipA00kbfGOeNponF58Y5m/JO3nlUZco0m dkhconPc8J7yX+TkybZeCeIR8x/4qdmZoRZvAagN7bTzZhKJ2Zq/l0B60xdj1s8Q 3V2iVhOo/cn5q0KM1wO38trO3I4yJajg9ALzO0yByONYEyOK/+sn5nh0No+jIpWZ IgELHLRSZCSFViG7fnVlA1r+FpYrx6H6shvMEmPEq0iYfZiduxaeTzLeSX7svjcT fbpeX89zu4VOPR1nqdTPczpC4TVD5ro+NpFE8mmy/saHUAcwipnxncCRwOKKi28K sUKApGhexSl1MFQZZGKYGN9i0p3y9AnMvIboAosxSz9t0cwy6jhnca6EPHef5w/A PMRE2pXzMY+VprfMYLzXxDK9WQMN4jdoLcQJ5ePU0wDtM/EAOQt0+cNHVkN2A316 fiiwuM9ukm/vVpyvq4TZJaS0qkJwGY2uelx2oG3+zw4Y+YKtngIJgt7AhJOenQwt yyAkq6+UDnv90xN/YDeK1vXQ9TK/soG/kHIaw93kokQvUNJKX91/ZWYOQnlOdTL9 k3AruCPFaVeXqYES4zq4F53aWO+2ICxLmSszrYoqh/KM6NKq43TzLNCk03SJ78iF QmX4YYerLM7/tbRdkMjpqExejeqSH+XX2eiDPmr0c7fnrtNmZRkT56andeuSBZVw bSzgJawqWjOmhhPQsjBhRxLp/pIXAjLFiUo+0NO5J5W606f+adX+9MxVn4MaBIRq LV+aaVK3sC0F+9XFZOFZnPmrvUP0BI7AJqAmJwFKyB9sH4Wdf+pvvr+4TyEjSXrN FzpEESk1URv5XF01DNyGjn3LX5NABQSOLJLoNXvki/COT7b+rFQ6sA5DVx9J4l1U hR5AVuQhJq2nmbRJPGCTJfj0uEciI0zOXm/SqLBmQxJRVo1JTXPT6nqAC8m95zu9 Qs/lyXCuxhF1IBzV1Trvs6wwgrAZJyIdyZSF4fPgA5pVPl8kbBVz0TtkMv4RnxiE VQnnhWrwwWYEtapbxvhT3WDvMgPuazJxYjQthIz+BaEFBvNOhCNanWnGB5i1P5yn G/CYOYYnSuX1W8+tlI3E9VlRHRiQgis02hFPYWWKM8u4moE7L4A6cUPLL5EcujNa NUFAHD4gFZye0KmusHOuB1Le3NwabOdcqpZmutNw61D/7VHQoSAvys1ujV+fgXZq 3vwTSNE0AVWRZp6TrstRUihddp7NtVongJ61iNzqXfSaVE4c6uxBff94MZwqVSSY 8AAwiMtDDxUjy5YvM3rBum9QFEyuN/Zqbq+9GRozxgm5mm+E1HOHt/43+RglUiE= =H2SS -----END PGP SIGNATURE-----