-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Fri, 23 Oct 2015 11:38:38 +0100 Source: cakephp Binary: cakephp cakephp-scripts Architecture: source all Version: 1.3.2-1.1+deb6u11 Distribution: squeeze-lts Urgency: high Maintainer: Chris Lamb <lamby@debian.org> Changed-By: Chris Lamb <lamby@debian.org> Description: cakephp - MVC rapid application development framework for PHP cakephp-scripts - MVC rapid application development framework for PHP (scripts) Changes: cakephp (1.3.2-1.1+deb6u11) squeeze-lts; urgency=high . * [TEMP-0000000-698CF7] Address SSRF (Server Side Request Forgery) attack by ensuring included files are "regular" (eg. `./foo.xml`) rather than merely existing (eg. `/dev/urandom`, etc.). Checksums-Sha1: eedb8049b1e26aba7b6f618117cf0de6f461f7ee 1810 cakephp_1.3.2-1.1+deb6u11.dsc 0989f1842e369e0e88b5b6ba1341332831b635ff 8539 cakephp_1.3.2-1.1+deb6u11.debian.tar.gz 065fc8af47d0c79ae22e0c042ae4d7a8123d9aee 873352 cakephp_1.3.2-1.1+deb6u11_all.deb 7ed3add8f8563a445a8f61658ba3f92812fe4037 98506 cakephp-scripts_1.3.2-1.1+deb6u11_all.deb Checksums-Sha256: d41779da1e6a4cdc65923d59649563cf638d3cd10ff4d1d1456d6cb9172e0f9b 1810 cakephp_1.3.2-1.1+deb6u11.dsc 6aa16eedecf154a8ac6645366e4ea4ee80d8c8f8dccc5bcd844e40c96a97f5af 8539 cakephp_1.3.2-1.1+deb6u11.debian.tar.gz d911d734da505f0ed8a5883d108a5cc389ca5354f9e285b01eeaf92859053014 873352 cakephp_1.3.2-1.1+deb6u11_all.deb 43aee61f724624e664b88c273eec79a4c50f11a725e645ca82070a53d01a74ce 98506 cakephp-scripts_1.3.2-1.1+deb6u11_all.deb Files: cbe7cf934753f24cb2df1bc7e768598b 1810 web optional cakephp_1.3.2-1.1+deb6u11.dsc bcf04d05046ff7c4cec745daee55765a 8539 web optional cakephp_1.3.2-1.1+deb6u11.debian.tar.gz 33e76e02d4140fcdcf54dae8e5158528 873352 web optional cakephp_1.3.2-1.1+deb6u11_all.deb 518e36937e238713ccf5a18b6efe6622 98506 web optional cakephp-scripts_1.3.2-1.1+deb6u11_all.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIcBAEBCAAGBQJWKg8QAAoJEB6VPifUMR5YFMUQAIWnAaQo833bjc43nfjn9rBz HMiw+lqDt8vnJgOZCBTyBH/eYHQR3Iip4XRPTOXeKpiTqf8VeJ9qKET09dENLdbR yNhzLM1zvQwtmj1wYJarQFW9zcEyUXAo6Q32FEsAdY+jMgqOEgjU1gEXlGdxlxvH j9H2MD7d0aKnI8AYRUMHu6QtrGMiP6wNNVDgn+EdEnKqUh8DQz14s9falUySjhDM 896V9ziWN2I2sQ0dsCXJG6ikyIUyQeBWt0B0FQ8FpPCycVCBfNOap/Rwq5d9z2+/ mejTLHytUY0CF6U94D93icUCdRGhkHZE0o5aJj4KoxFBjei+ss3cxdie1dkhQkgs 4XdoyBxEgP1cHTuB9555BPDBM5WnNz3OzqiGFh0O8pAnID9HBj4t9pkoU00Jfwgb 0YdakxNlmZMaMyeePSxfLAfPIpxbCP5LvW1qW3oBvhodnSLMf7hmGP+H4qXt//tl SckPUotH5RDKdkN9qVK8GnCS+qm04pHvlXJR+CxKwvOOkNnn+Vdo1WOctZ94c9Gy ru3xNrRD2VdxYmLiWHWo2+3EoRDJ0+n4aBxFaYaAjAk/qJg/SczvBTKRkF8i8e7n 91kA0ZrjTE1sf+3zRu9jmNtYb297fNfr2uKJ6J9eZ4juieHvmaNaDP4rfL3jAveP 1QTpG7ssG+FmTPufCBNz =MZMV -----END PGP SIGNATURE-----