-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Format: 1.7 Date: Tue, 1 Apr 2008 08:00:05 +0000 Source: mapserver Binary: mapserver-doc perl-mapscript mapserver-bin cgi-mapserver php5-mapscript python-mapscript php4-mapscript Architecture: source all amd64 Version: 4.10.0-5.1+etch2 Distribution: stable-security Urgency: high Maintainer: Debian GIS Project <pkg-grass-devel@lists.alioth.debian.org> Changed-By: Devin Carraway <devin@debian.org> Description: cgi-mapserver - cgi module of mapserver mapserver-bin - mapserver binary utilities mapserver-doc - documentation for mapserver perl-mapscript - perl mapserver library php4-mapscript - module for php4-cgi to use mapserver php5-mapscript - module for php5-cgi to use mapserver python-mapscript - python mapserver lib Changes: mapserver (4.10.0-5.1+etch2) stable-security; urgency=high . * Non-maintainer upload by the Security Team. * Apply upstream patches fixing two vulnerabilities: - CVE-2007-4542: Cross-site scripting (XSS) vulnerabilities using mapserver's writeError function (upstream fix also addresses a potential buffer overflow) - CVE-2007-4629: Multiple stack buffer overflow vulnerabilities in template handlers, potentially allowing the execution of arbitrary code via a maliciously crafted map file Files: 19c7e595b5f855246bdda2cb64dfbba6 1315 devel extra mapserver_4.10.0-5.1+etch2.dsc 4668bbd017c20c251e962a5cd09c8f31 1782838 devel extra mapserver_4.10.0.orig.tar.gz d424dba068ade923260400584ccc41c9 21156 devel extra mapserver_4.10.0-5.1+etch2.diff.gz 228d80f159c068f2f2dbcaabdc5f0142 98096 doc extra mapserver-doc_4.10.0-5.1+etch2_all.deb 792b68c551f4bb850cc2e3fb6dc6a4fd 546404 web extra php4-mapscript_4.10.0-5.1+etch2_amd64.deb ca7def85a6cbe91d04b27b111b4c9ab5 545634 web extra php5-mapscript_4.10.0-5.1+etch2_amd64.deb 32bb9470760e29a552b809073a9acc7d 698078 perl extra perl-mapscript_4.10.0-5.1+etch2_amd64.deb 67f97111943841cfcc3cbed8ce38d637 447180 web extra cgi-mapserver_4.10.0-5.1+etch2_amd64.deb 664d2194141c0d80ad8ba4c4cde7879c 577372 python extra python-mapscript_4.10.0-5.1+etch2_amd64.deb 43e559a538f7bf03fdbf9997f69ca50c 3269920 misc extra mapserver-bin_4.10.0-5.1+etch2_amd64.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.6 (GNU/Linux) iD8DBQFH9du8U5XKDemr/NIRAmNQAKDxDSm1lGxFuH63sDapCaf4EOGYxACbBmsX 1NrNxdcg8sBxePP85LVyYRw= =LISs -----END PGP SIGNATURE----- Accepted: cgi-mapserver_4.10.0-5.1+etch2_amd64.deb to pool/main/m/mapserver/cgi-mapserver_4.10.0-5.1+etch2_amd64.deb mapserver-bin_4.10.0-5.1+etch2_amd64.deb to pool/main/m/mapserver/mapserver-bin_4.10.0-5.1+etch2_amd64.deb mapserver-doc_4.10.0-5.1+etch2_all.deb to pool/main/m/mapserver/mapserver-doc_4.10.0-5.1+etch2_all.deb mapserver_4.10.0-5.1+etch2.diff.gz to pool/main/m/mapserver/mapserver_4.10.0-5.1+etch2.diff.gz mapserver_4.10.0-5.1+etch2.dsc to pool/main/m/mapserver/mapserver_4.10.0-5.1+etch2.dsc perl-mapscript_4.10.0-5.1+etch2_amd64.deb to pool/main/m/mapserver/perl-mapscript_4.10.0-5.1+etch2_amd64.deb php4-mapscript_4.10.0-5.1+etch2_amd64.deb to pool/main/m/mapserver/php4-mapscript_4.10.0-5.1+etch2_amd64.deb php5-mapscript_4.10.0-5.1+etch2_amd64.deb to pool/main/m/mapserver/php5-mapscript_4.10.0-5.1+etch2_amd64.deb python-mapscript_4.10.0-5.1+etch2_amd64.deb to pool/main/m/mapserver/python-mapscript_4.10.0-5.1+etch2_amd64.deb