-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Fri, 08 Jan 2016 10:33:26 +0100 Source: prosody Binary: prosody Architecture: source amd64 Version: 0.9.7-2+deb8u2 Distribution: jessie-security Urgency: high Maintainer: Matthew James Wild <mwild1@gmail.com> Changed-By: Enrico Tassi <gareuselesinge@debian.org> Description: prosody - Lightweight Jabber/XMPP server Changes: prosody (0.9.7-2+deb8u2) jessie-security; urgency=high . * CVE-2016-1231: path traversal in http built-in server * CVE-2016-1232: weak PRNG for dialback on S2S Checksums-Sha1: 0ed2675b3b09ea1530161446e92ed9559baef4d9 1996 prosody_0.9.7-2+deb8u2.dsc 5515e15077ea0e8e26b83614a02ad632374a256b 266638 prosody_0.9.7.orig.tar.gz 5c7bd3afae548f373a864b0c074cf04a559b4a04 14912 prosody_0.9.7-2+deb8u2.debian.tar.xz 9dd9a4a1b3de2df41fa3f87986ac05bd21d2664f 204038 prosody_0.9.7-2+deb8u2_amd64.deb Checksums-Sha256: a6abb0396ec713f216d54e3f73ba4546df0d6fa8df995155668d843871b21216 1996 prosody_0.9.7-2+deb8u2.dsc dd4b99b39976442055898c933c013598e558beed11d7795d76ffc0f1a87e2e00 266638 prosody_0.9.7.orig.tar.gz 5f022630ac61924d98cd063de1ff589ed0ea1834eae5d5daf8ade3d0accee3dc 14912 prosody_0.9.7-2+deb8u2.debian.tar.xz 6ea64ce807941a214fd5cdb5da93f9e6438e5a47fbf8979b3437f7ad6bfca1da 204038 prosody_0.9.7-2+deb8u2_amd64.deb Files: 293cc8fe1f109cddf9652bf6c574c27c 1996 net extra prosody_0.9.7-2+deb8u2.dsc 47de7f593279e327792df78cfa93e8a7 266638 net extra prosody_0.9.7.orig.tar.gz f8035084ff7b7991b349b3a23a94d0ce 14912 net extra prosody_0.9.7-2+deb8u2.debian.tar.xz dc141bfaaa869c0a6c7105f0c03c0b28 204038 net extra prosody_0.9.7-2+deb8u2_amd64.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIcBAEBCAAGBQJWj/inAAoJECUFM8yim3ZPm0IQAIpxc4pjyVB5BDnsCuaKi47d kNh9EuOMdZhS1bUU8JbCs+vN5JdB69vafMr2lkNuiaWFbWu9IMNOKHXp0E7hlVTh 0caKmjVoF4spvMutWn8qHLG1o9FEg1/FyZ8vA/Dz2O39uMVzTq2tuDW7xo4OLOad akIXGmQRLhR6cfLBrfxuuoaAy1v8OyBDbUKXwmdwFUMrwo2rfrgzaWjWR4JNttbL 7aUPHocg65PVUOxQ5FUdcCu8cu0OkmlyJO0eTzlikQ3NhDCqxUsO0dUIFz+UOc4Q coTkgVDPZKoB39h1vN9TYWhLUTz22BNxnFQOn8LrU+k8f0/TBsUogf7YbJybcO9W hINRjtVzXN8j6uXDFeM6Ws5Tq0ex9KeSQ7XX9kszlfQjYTyOJ/xE4kFd63u+VFGS SSbO0/GOubqsJvoRcIRo+RPDyuI+plJAJGUtQavU878HWed28JQnyGjijeYP3X/w sk2PiQguNKSgLadqIEW7jKoZvEiY7u9HVF7rVRH9OE0O17otzaLx7wtxkbSW9QIl g6JTNr2drGpx69MJ2FxnJk6jmRffFZYL1t5na4KsbbbKQ6M///YeNAzdhUaM9wcn NTwAnOYyEL8kOJZwZ1uvcniFlLZc/2GBcGQyre3xLTYRx61etAUawdDkqnlKbZa3 +BFLDqahDKGv9BdKgk7U =NX+S -----END PGP SIGNATURE-----