-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Format: 1.7 Date: Thu, 24 May 2007 21:59:15 +0200 Source: php4 Binary: php4-sybase php4-recode php4-pspell php4-cgi libapache-mod-php4 php4-interbase php4-mcrypt php4-cli php4-dev php4-snmp libapache2-mod-php4 php4-odbc php4-xslt php4-mysql php4-domxml php4-gd php4-ldap php4-imap php4-common php4 php4-curl php4-pear php4-mcal php4-pgsql php4-mhash Architecture: source i386 all Version: 6:4.4.4-9+lenny1 Distribution: testing-security Urgency: high Maintainer: Debian PHP Maintainers <pkg-php-maint@lists.alioth.debian.org> Changed-By: Stefan Fritsch <sf@debian.org> Description: libapache-mod-php4 - server-side, HTML-embedded scripting language (apache 1.3 module) libapache2-mod-php4 - server-side, HTML-embedded scripting language (apache 2 module) php4 - server-side, HTML-embedded scripting language (meta-package) php4-cgi - server-side, HTML-embedded scripting language (CGI binary) php4-cli - command-line interpreter for the php4 scripting language php4-common - Common files for packages built from the php4 source php4-curl - CURL module for php4 php4-dev - Files for PHP4 module development php4-domxml - XMLv2 module for php4 php4-gd - GD module for php4 php4-imap - IMAP module for php4 php4-interbase - interbase/firebird module for php4 php4-ldap - LDAP module for php4 php4-mcal - MCAL calendar module for php4 php4-mcrypt - MCrypt module for php4 php4-mhash - MHASH module for php4 php4-mysql - MySQL module for php4 php4-odbc - ODBC module for php4 php4-pear - PHP Extension and Application Repository (transitional package) php4-pgsql - PostgreSQL module for php4 php4-pspell - pspell module for php4 php4-recode - Character recoding module for php4 php4-snmp - SNMP module for php4 php4-sybase - Sybase / MS SQL Server module for php4 php4-xslt - XSLT module for php4 Changes: php4 (6:4.4.4-9+lenny1) testing-security; urgency=high . * Non-maintainer upload by the Security Team * Port security fixes from 6:4.4.4-8+etch3 to testing * The following security issue is addressed with this update: - CVE-2007-2509: CRLF injection in the ftp module - MOPB 04/CVE-2007-1286: ZVAL reference counter overflow - MOPB 10/CVE-2007-1380: Session extention heap information leak - MOPB 22/CVE-2007-1521: Session identifier double free - MOPB 32/CVE-2007-0910: Updated patch, fixes double free regression - MOPB 34/CVE-2007-1718: mail() header injection - MOPB 35/CVE-2007-1777: zip parsing integer overflow Files: 0cf5796a44faad41e67774ee6253b8de 2003 web optional php4_4.4.4-9+lenny1.dsc a3af087b73ed03036d5d0f9abbe03a0a 99858 web optional php4_4.4.4-9+lenny1.diff.gz 3dc33407048edda59d965535cb1bf170 206152 web optional php4-common_4.4.4-9+lenny1_i386.deb 5642aeed76d4a973f454dbb53bc4f19c 1595784 web optional libapache-mod-php4_4.4.4-9+lenny1_i386.deb dda64463ff717cc2bfb4fde5a3201573 1597360 web optional libapache2-mod-php4_4.4.4-9+lenny1_i386.deb ba457c8789895fa8a78d6e3a79812cc6 3176318 web optional php4-cgi_4.4.4-9+lenny1_i386.deb 4a1d0b1aba0748f07c349eb22a38d982 1597170 web optional php4-cli_4.4.4-9+lenny1_i386.deb b64d549e162bc13bc56d992d08a6c7ab 202364 devel optional php4-dev_4.4.4-9+lenny1_i386.deb 70cd313520ec268d1ce0b9f14ebc87fc 15912 web optional php4-curl_4.4.4-9+lenny1_i386.deb 66d87d7f118218ef9a277af139a17a99 35034 web optional php4-domxml_4.4.4-9+lenny1_i386.deb 2c8584e6b075fd63862315f461c86490 29662 web optional php4-gd_4.4.4-9+lenny1_i386.deb 184deb541e1d811c912ad6c11719b702 33232 web optional php4-imap_4.4.4-9+lenny1_i386.deb 07f834ba5df5a36b43db93777b5279b8 23148 web optional php4-interbase_4.4.4-9+lenny1_i386.deb dfc67d961d2c0baa42ded2bbba10c48f 17050 web optional php4-ldap_4.4.4-9+lenny1_i386.deb 5ca47a3d4c42117d6a309c73475efa69 14056 web optional php4-mcal_4.4.4-9+lenny1_i386.deb 3b519c2983b03ecadc3a71f42bfa0fb4 13144 web optional php4-mcrypt_4.4.4-9+lenny1_i386.deb 3a352e87774a424422947503e1db5ca1 5036 web optional php4-mhash_4.4.4-9+lenny1_i386.deb 239780fd8498dbcfc1e0d48538257d39 18538 web optional php4-mysql_4.4.4-9+lenny1_i386.deb b5e528e7c8fb2491ac554e3fb84188ed 24542 web optional php4-odbc_4.4.4-9+lenny1_i386.deb 0f50fff48117d9fa1586714b2d0b2e7d 33844 web optional php4-pgsql_4.4.4-9+lenny1_i386.deb 09637defcd10287ab41ad8fabb649802 8428 web optional php4-pspell_4.4.4-9+lenny1_i386.deb 3fde73dee70216a6372d8c6a7fe0e1ea 4750 web optional php4-recode_4.4.4-9+lenny1_i386.deb d77d90abef617132827b08b2f8123c6a 10262 web optional php4-snmp_4.4.4-9+lenny1_i386.deb 3237b7750e8cbf50ed3c16be5fbd3f31 18038 web optional php4-sybase_4.4.4-9+lenny1_i386.deb 058e4ca31d9d0ecd8687e5aa0bae5236 13190 web optional php4-xslt_4.4.4-9+lenny1_i386.deb 5962de774a18fd3c0f11b43b22b0e4bb 1162 web optional php4_4.4.4-9+lenny1_all.deb af6a4b0daa3e70d41f93a4d07b132922 1180 web optional php4-pear_4.4.4-9+lenny1_all.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.6 (GNU/Linux) iD8DBQFGVfbBbxelr8HyTqQRAr9oAJ9NcmCidHoMCeO3FkuuxxIqVdZHzQCgyzW1 t8QsKb2yuJdfdFWEfhH4PJM= =XjVN -----END PGP SIGNATURE----- Accepted: libapache-mod-php4_4.4.4-9+lenny1_i386.deb to pool/main/p/php4/libapache-mod-php4_4.4.4-9+lenny1_i386.deb libapache2-mod-php4_4.4.4-9+lenny1_i386.deb to pool/main/p/php4/libapache2-mod-php4_4.4.4-9+lenny1_i386.deb php4-cgi_4.4.4-9+lenny1_i386.deb to pool/main/p/php4/php4-cgi_4.4.4-9+lenny1_i386.deb php4-cli_4.4.4-9+lenny1_i386.deb to pool/main/p/php4/php4-cli_4.4.4-9+lenny1_i386.deb php4-common_4.4.4-9+lenny1_i386.deb to pool/main/p/php4/php4-common_4.4.4-9+lenny1_i386.deb php4-curl_4.4.4-9+lenny1_i386.deb to pool/main/p/php4/php4-curl_4.4.4-9+lenny1_i386.deb php4-dev_4.4.4-9+lenny1_i386.deb to pool/main/p/php4/php4-dev_4.4.4-9+lenny1_i386.deb php4-domxml_4.4.4-9+lenny1_i386.deb to pool/main/p/php4/php4-domxml_4.4.4-9+lenny1_i386.deb php4-gd_4.4.4-9+lenny1_i386.deb to pool/main/p/php4/php4-gd_4.4.4-9+lenny1_i386.deb php4-imap_4.4.4-9+lenny1_i386.deb to pool/main/p/php4/php4-imap_4.4.4-9+lenny1_i386.deb php4-interbase_4.4.4-9+lenny1_i386.deb to pool/main/p/php4/php4-interbase_4.4.4-9+lenny1_i386.deb php4-ldap_4.4.4-9+lenny1_i386.deb to pool/main/p/php4/php4-ldap_4.4.4-9+lenny1_i386.deb php4-mcal_4.4.4-9+lenny1_i386.deb to pool/main/p/php4/php4-mcal_4.4.4-9+lenny1_i386.deb php4-mcrypt_4.4.4-9+lenny1_i386.deb to pool/main/p/php4/php4-mcrypt_4.4.4-9+lenny1_i386.deb php4-mhash_4.4.4-9+lenny1_i386.deb to pool/main/p/php4/php4-mhash_4.4.4-9+lenny1_i386.deb php4-mysql_4.4.4-9+lenny1_i386.deb to pool/main/p/php4/php4-mysql_4.4.4-9+lenny1_i386.deb php4-odbc_4.4.4-9+lenny1_i386.deb to pool/main/p/php4/php4-odbc_4.4.4-9+lenny1_i386.deb php4-pear_4.4.4-9+lenny1_all.deb to pool/main/p/php4/php4-pear_4.4.4-9+lenny1_all.deb php4-pgsql_4.4.4-9+lenny1_i386.deb to pool/main/p/php4/php4-pgsql_4.4.4-9+lenny1_i386.deb php4-pspell_4.4.4-9+lenny1_i386.deb to pool/main/p/php4/php4-pspell_4.4.4-9+lenny1_i386.deb php4-recode_4.4.4-9+lenny1_i386.deb to pool/main/p/php4/php4-recode_4.4.4-9+lenny1_i386.deb php4-snmp_4.4.4-9+lenny1_i386.deb to pool/main/p/php4/php4-snmp_4.4.4-9+lenny1_i386.deb php4-sybase_4.4.4-9+lenny1_i386.deb to pool/main/p/php4/php4-sybase_4.4.4-9+lenny1_i386.deb php4-xslt_4.4.4-9+lenny1_i386.deb to pool/main/p/php4/php4-xslt_4.4.4-9+lenny1_i386.deb php4_4.4.4-9+lenny1.diff.gz to pool/main/p/php4/php4_4.4.4-9+lenny1.diff.gz php4_4.4.4-9+lenny1.dsc to pool/main/p/php4/php4_4.4.4-9+lenny1.dsc php4_4.4.4-9+lenny1_all.deb to pool/main/p/php4/php4_4.4.4-9+lenny1_all.deb