-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Format: 1.7 Date: Tue, 5 Apr 2005 09:21:20 +0000 Source: php3 Binary: php3-cgi php3-cgi-mysql php3-cgi-imap php3-gd php3-cgi-mhash php3-magick php3-cgi-xml php3-cgi-snmp php3 php3-mysql php3-imap php3-dev php3-doc php3-xml php3-mhash php3-snmp php3-cgi-ldap php3-cgi-gd php3-ldap php3-cgi-magick Architecture: source arm all Version: 3:3.0.18-23.1woody3 Distribution: stable-security Urgency: high Maintainer: Martin Schulze <joey@debian.org> Changed-By: Adam Conrad <adconrad@0c3.net> Description: php3 - A server-side, HTML-embedded scripting language php3-cgi - A server-side, HTML-embedded scripting language php3-cgi-gd - GD (graphic creation) module for PHP3 (cgi) php3-cgi-imap - IMAP module for PHP3 (cgi) php3-cgi-ldap - LDAP module for PHP3 (cgi) php3-cgi-magick - ImageMagick module for PHP3 (cgi) php3-cgi-mhash - mhash module for PHP3 (cgi) php3-cgi-mysql - Mysql module for PHP3 (cgi) php3-cgi-snmp - SNMP module for PHP3 (cgi) php3-cgi-xml - XML module for PHP3 (cgi) php3-dev - Header files for PHP3 module development php3-doc - Documentation for PHP3 php3-gd - GD (graphic creation) module for PHP3 (apache) php3-imap - IMAP module for PHP3 (apache) php3-ldap - LDAP module for PHP3 (apache) php3-magick - ImageMagick module for PHP3 (apache) php3-mhash - mhash module for PHP3 (apache) php3-mysql - Mysql module for PHP3 (apache) php3-snmp - SNMP module for PHP3 (apache) php3-xml - XML module for PHP3 (apache) Changes: php3 (3:3.0.18-23.1woody3) stable-security; urgency=high . * Backport fixes to functions/image.c from the 4.3 branch: - Avoid infinite loops in the php3_skip_variable() function and the php3_read_APP() function which were being called indirectly by getimagesize() function. As this function is commonly called with untrusted data, this becomes a remote DoS. [functions/image.c] - Addresses CAN-2005-0525 (for refrence, PHP 3.0.18 is not vulnerable to CAN-2005-0524, the sister bug to this one) Files: 9883ae8db978fc385a7b7f4e28e80b21 1116 web extra php3_3.0.18-23.1woody3.dsc 6792e26a0ea655b6123aa5773a36b868 57405 web extra php3_3.0.18-23.1woody3.diff.gz 81f4654a85ba8915e074ad9c1d38fae2 817804 web extra php3-doc_3.0.18-23.1woody3_all.deb c0d2e82d9fde3f535e1638bc0d07e089 372290 web extra php3_3.0.18-23.1woody3_arm.deb 2199512c2863c0e26345f752d6daed2e 495542 web extra php3-cgi_3.0.18-23.1woody3_arm.deb df2da0c655604d257de96c43f4a1c8b3 12884 web extra php3-mysql_3.0.18-23.1woody3_arm.deb b65bb764f7b10f23f7fd96d8c0f5a9ef 13556 web extra php3-cgi-mysql_3.0.18-23.1woody3_arm.deb 1bf42890cc804b5980e942c3279e3dfb 20346 web extra php3-gd_3.0.18-23.1woody3_arm.deb f207f71ad8d3f12de9aaadba13781851 20708 web extra php3-cgi-gd_3.0.18-23.1woody3_arm.deb 0483cbadb5b6a5e4c83c85f81d374a7c 25708 web extra php3-imap_3.0.18-23.1woody3_arm.deb d202de328a2913fcf3ebdc870cc11a45 26406 web extra php3-cgi-imap_3.0.18-23.1woody3_arm.deb 3a2079cec513a6352a798e5dfcbf07f4 10580 web extra php3-xml_3.0.18-23.1woody3_arm.deb 5fa8687a46ede5a69b8468ce36a3c5ac 11002 web extra php3-cgi-xml_3.0.18-23.1woody3_arm.deb 0e6025660d79987eb7d1c477ce18303e 9066 web extra php3-ldap_3.0.18-23.1woody3_arm.deb 6c605246eddf005c236a9437ad35866e 9312 web extra php3-cgi-ldap_3.0.18-23.1woody3_arm.deb 1ef6e018e71dea3d690c034404c50c3c 5604 web extra php3-snmp_3.0.18-23.1woody3_arm.deb 0d711125ded55df940ea9beb562104cb 5418 web extra php3-cgi-snmp_3.0.18-23.1woody3_arm.deb 5a7a15c14ecea059256675133b5366cc 7620 web extra php3-magick_3.0.18-23.1woody3_arm.deb 43e17349d1b58a87778bdaf0de3373e5 7876 web extra php3-cgi-magick_3.0.18-23.1woody3_arm.deb 914693d35393245c4c463372c41f8da9 3642 web extra php3-mhash_3.0.18-23.1woody3_arm.deb 6256a16940ea479ca6649bea5c723d0c 3742 web extra php3-cgi-mhash_3.0.18-23.1woody3_arm.deb 090bb3cf3b32ec0a245a36e8af33eb65 51346 web extra php3-dev_3.0.18-23.1woody3_arm.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.0 (GNU/Linux) iD8DBQFCVSQWW5ql+IAeqTIRAu7rAJ42Q8pC9qdOQpNtEJNTgLwMX3aDrQCdEzyI Cj42yuh0w4Yfl/9Gkzl2THY= =JKAs -----END PGP SIGNATURE----- Accepted: php3-cgi-gd_3.0.18-23.1woody3_arm.deb to pool/main/p/php3/php3-cgi-gd_3.0.18-23.1woody3_arm.deb php3-cgi-imap_3.0.18-23.1woody3_arm.deb to pool/main/p/php3/php3-cgi-imap_3.0.18-23.1woody3_arm.deb php3-cgi-ldap_3.0.18-23.1woody3_arm.deb to pool/main/p/php3/php3-cgi-ldap_3.0.18-23.1woody3_arm.deb php3-cgi-magick_3.0.18-23.1woody3_arm.deb to pool/main/p/php3/php3-cgi-magick_3.0.18-23.1woody3_arm.deb php3-cgi-mhash_3.0.18-23.1woody3_arm.deb to pool/main/p/php3/php3-cgi-mhash_3.0.18-23.1woody3_arm.deb php3-cgi-mysql_3.0.18-23.1woody3_arm.deb to pool/main/p/php3/php3-cgi-mysql_3.0.18-23.1woody3_arm.deb php3-cgi-snmp_3.0.18-23.1woody3_arm.deb to pool/main/p/php3/php3-cgi-snmp_3.0.18-23.1woody3_arm.deb php3-cgi-xml_3.0.18-23.1woody3_arm.deb to pool/main/p/php3/php3-cgi-xml_3.0.18-23.1woody3_arm.deb php3-cgi_3.0.18-23.1woody3_arm.deb to pool/main/p/php3/php3-cgi_3.0.18-23.1woody3_arm.deb php3-dev_3.0.18-23.1woody3_arm.deb to pool/main/p/php3/php3-dev_3.0.18-23.1woody3_arm.deb php3-doc_3.0.18-23.1woody3_all.deb to pool/main/p/php3/php3-doc_3.0.18-23.1woody3_all.deb php3-gd_3.0.18-23.1woody3_arm.deb to pool/main/p/php3/php3-gd_3.0.18-23.1woody3_arm.deb php3-imap_3.0.18-23.1woody3_arm.deb to pool/main/p/php3/php3-imap_3.0.18-23.1woody3_arm.deb php3-ldap_3.0.18-23.1woody3_arm.deb to pool/main/p/php3/php3-ldap_3.0.18-23.1woody3_arm.deb php3-magick_3.0.18-23.1woody3_arm.deb to pool/main/p/php3/php3-magick_3.0.18-23.1woody3_arm.deb php3-mhash_3.0.18-23.1woody3_arm.deb to pool/main/p/php3/php3-mhash_3.0.18-23.1woody3_arm.deb php3-mysql_3.0.18-23.1woody3_arm.deb to pool/main/p/php3/php3-mysql_3.0.18-23.1woody3_arm.deb php3-snmp_3.0.18-23.1woody3_arm.deb to pool/main/p/php3/php3-snmp_3.0.18-23.1woody3_arm.deb php3-xml_3.0.18-23.1woody3_arm.deb to pool/main/p/php3/php3-xml_3.0.18-23.1woody3_arm.deb php3_3.0.18-23.1woody3.diff.gz to pool/main/p/php3/php3_3.0.18-23.1woody3.diff.gz php3_3.0.18-23.1woody3.dsc to pool/main/p/php3/php3_3.0.18-23.1woody3.dsc php3_3.0.18-23.1woody3_arm.deb to pool/main/p/php3/php3_3.0.18-23.1woody3_arm.deb -- To UNSUBSCRIBE, email to debian-changes-REQUEST@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.org