-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 13 Nov 2013 02:42:03 +0000 Source: lighttpd Binary: lighttpd lighttpd-doc lighttpd-mod-mysql-vhost lighttpd-mod-trigger-b4-dl lighttpd-mod-cml lighttpd-mod-magnet lighttpd-mod-webdav Architecture: source amd64 all Version: 1.4.31-4+deb7u1 Distribution: stable-security Urgency: high Maintainer: Debian lighttpd maintainers <pkg-lighttpd-maintainers@lists.alioth.debian.org> Changed-By: Michael Gilbert <mgilbert@debian.org> Description: lighttpd - fast webserver with minimal memory footprint lighttpd-doc - documentation for lighttpd lighttpd-mod-cml - cache meta language module for lighttpd lighttpd-mod-magnet - control the request handling module for lighttpd lighttpd-mod-mysql-vhost - MySQL-based virtual host configuration for lighttpd lighttpd-mod-trigger-b4-dl - anti-deep-linking module for lighttpd lighttpd-mod-webdav - WebDAV module for lighttpd Changes: lighttpd (1.4.31-4+deb7u1) stable-security; urgency=high . * Non-maintainer upload by the Security Team. * Fix cve-2013-4508: ssl cipher suites issue. * Fix cve-2013-4559: setuid privilege escalation issue. * Fix cve-2013-4560: use-after-free in fam. Checksums-Sha1: bec77c20c139a19444da517d2a38ccb6d2074adb 3382 lighttpd_1.4.31-4+deb7u1.dsc 6b3babc9df173cea5ae4756c2fd6b0e85e015f2a 840123 lighttpd_1.4.31.orig.tar.gz b26128b04f165cf3d7f36c52b4c9597f9f2a8739 32766 lighttpd_1.4.31-4+deb7u1.debian.tar.gz edf2c831b1a98b50e9565e0ced11f5302aacbef4 306442 lighttpd_1.4.31-4+deb7u1_amd64.deb a5cda093ab3222259af22f85610cc89a19146bfc 63852 lighttpd-doc_1.4.31-4+deb7u1_all.deb aa05230c91dc517f36d5c978fc8d0943654e6811 20312 lighttpd-mod-mysql-vhost_1.4.31-4+deb7u1_amd64.deb 0fec4b3fa8a8813c5300d71909fef5bc7e069b1b 21932 lighttpd-mod-trigger-b4-dl_1.4.31-4+deb7u1_amd64.deb 9cdbf307b1c1e80dd04120be44341bf07a1eef47 25252 lighttpd-mod-cml_1.4.31-4+deb7u1_amd64.deb 1537da0486bb33d7f0007bc9ed32897421efb9fb 26438 lighttpd-mod-magnet_1.4.31-4+deb7u1_amd64.deb 0108964b50407bbe546569468bb83024b2414a76 32684 lighttpd-mod-webdav_1.4.31-4+deb7u1_amd64.deb Checksums-Sha256: 7176c786ca6ec4f9982b71e75c0d6a6412b15a0f4091cbe84ffd2f1a8d902e01 3382 lighttpd_1.4.31-4+deb7u1.dsc 848a15604bf358d9355bd7a48c01f448c286734dbb5f4dc1cd16acb8b05a9b52 840123 lighttpd_1.4.31.orig.tar.gz 453983e57ffe4e2199a25b91ee9386b6b64623e03b84521725d8a57e2dfeb8df 32766 lighttpd_1.4.31-4+deb7u1.debian.tar.gz bdf2f21116dded90e4a0d216178bb1d12a6339d080e55d2880d065bff9917613 306442 lighttpd_1.4.31-4+deb7u1_amd64.deb f2f57154773dff93e90e46d8653d3ae5b400775a78e366565d9849dfb440e125 63852 lighttpd-doc_1.4.31-4+deb7u1_all.deb b5e4a5483d6951185a09feb1daa047cdd4f80ac0d833727c6a248c35edaed1eb 20312 lighttpd-mod-mysql-vhost_1.4.31-4+deb7u1_amd64.deb 51b1733555c1d6db400251ffd4138af5650a2a23c6bca5a112aa2b7a245e6ee0 21932 lighttpd-mod-trigger-b4-dl_1.4.31-4+deb7u1_amd64.deb fb7e010add9272ff5a9714cff12ac6a5e15ab3f635a60fd328b045a073c80005 25252 lighttpd-mod-cml_1.4.31-4+deb7u1_amd64.deb d450c3c7abfc4877678b8ef75a5f000fc5911fe470a8bc838c7f05a91459903d 26438 lighttpd-mod-magnet_1.4.31-4+deb7u1_amd64.deb 81fd621ee1af4777ca2b1dda9da69cd8c554662b093ae24f758e8c6945f44be6 32684 lighttpd-mod-webdav_1.4.31-4+deb7u1_amd64.deb Files: 55d7b2078205e61a32ca91e2e91e8b8b 3382 httpd optional lighttpd_1.4.31-4+deb7u1.dsc 7907b7167d639b8a8daab97e223249d5 840123 httpd optional lighttpd_1.4.31.orig.tar.gz 895cb89bb77cc6be1464b69846780929 32766 httpd optional lighttpd_1.4.31-4+deb7u1.debian.tar.gz 85210730db966ccca683332da8a87642 306442 httpd optional lighttpd_1.4.31-4+deb7u1_amd64.deb e019f1feaa975a660c79e285c701db1f 63852 doc optional lighttpd-doc_1.4.31-4+deb7u1_all.deb c96d0f475fe101276edc90d6da113488 20312 httpd optional lighttpd-mod-mysql-vhost_1.4.31-4+deb7u1_amd64.deb 887490d3bf5e536ea1ad40ff9215d133 21932 httpd optional lighttpd-mod-trigger-b4-dl_1.4.31-4+deb7u1_amd64.deb 355febe58521d37c4c5d0482df53c2e3 25252 httpd optional lighttpd-mod-cml_1.4.31-4+deb7u1_amd64.deb 6b7ff78b798ff5fcfdeb467b428d8f23 26438 httpd optional lighttpd-mod-magnet_1.4.31-4+deb7u1_amd64.deb f98c881557c2c469c58f3559838036b2 32684 httpd optional lighttpd-mod-webdav_1.4.31-4+deb7u1_amd64.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.15 (GNU/Linux) iQQcBAEBCgAGBQJSgwTdAAoJELjWss0C1vRzn9sf/0jIaneLsPpDxFkrCVo+d40A U4ZlBYxbByBoKkMbgLB1CXGSyQxTdgDriCiH91tl6kGS+WAyqzdJb4Ii5vCBCyEH taNOIZ28rqF5E4hFVpttn3Ddi8dCeFYvXl3YMsUwEP3Wy1XO9wfOD2WOYnzfxDK9 69vY89nbilNiEi5FnMwYu9u1UxZNK4aol7HAvLA+L6UGGHj8KDp5kvzeJTAKxxj1 Cskzibn7rBzxsmeh0/dcclT1Te/sCYYQ/HKIQkMxyUVusFZ4vY+W3csugilzTLM7 pI6wI5fqdzrcvXT1pMde3gb5F5N5R3W3smcUDccai61q5j/QAvQid8KgeGWXoAu2 TfjlHSJ+O2t3mY4Pa1Imxz0t9tRwJ97M95JWoN/aS/gG4eDJg40nCJEaSn3SS+/D 56VcCjh9Es7URfpCM1b+RMEJdw0M3iHGZMaNeFhNVU7mzxwGEEA7Vid3dr0yDayq aXpURK+ZV5vTAsw0dhscj0/jEWasrDs86CnI1lMDsXaMrzSX60jKzFI2G3NQv4RP VpSHoM4NFkwHDZ3OYoSYH6a0EXaRtgmhJGWyFJqrjdkwnP9xxXJ5hjo/EPxbO4kQ NPQcjOXC0Fnvn70tD8J5/8D9fp9Y2Y4pp4I459CU4Svf0/vKvjqIgmViZryNBsLg NvPu+eV2kXPDuQ1F4JX323NDQ0Yy9+TLIAUiSxzusHSmZ01L8B+7Jv+3WTLKBxs9 z12G8W44WcoqgsfLd/mLdPeu5348COxclS78z+6NQUohlpkoy78gHDylyiixN1Sb LxsVSDOD/c+ZLxBvJ6OKAlmlPOLf7ihE3ytCheRpt5fP4Wis9+Rng/f1PdKlEOm7 oVHifM3wCwKHOwuk9krwqpzK1tluMV976jPaGDdys8oPG/5MxQARKN4EpNDIHM0P Nz24y1npqZuNkA0NFcEnF6pUkXjorACaHOjLkbSQp/yKi/f7UGYd8cQq5RRpZAxH nt6Qls4hPuktLPQIEvkgIPEvOjTDaw8r7nyKxz5dmobDYPVsIdhZrEObG/A8NG1S mCGJ6dJ3vWCTDO6m4DvYcC0TE2koD+0YcvEH+oDgbzAzakWe+7Whv/ES2DOtT3qG OYNmgXA13T7wERQohzobWCx7utu57Nz6g55+lCj3gOmmNZM1aY0lLU5rQVoT0qKn 9qBugv4pGuPrR7OAtKjlUZKdbFsFfkmXBb2zCBYcp/1kVpHSWGcS2nJjy9GWKfxX VD3XEqbeJYJDNyTKVpxnnqz85+TAWiAy0Jwbmjn0jbGxTulsroArACX/JmuVNDtl Lcj2czKQMA5TNtJ/O3tVEbB8eKMjSEc3l5IzCJo/QSEQXCenCKj5zNIfKyjwy1A= =3ipg -----END PGP SIGNATURE-----