-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Fri, 24 Feb 2017 07:23:33 +0100 Source: cakephp Binary: cakephp cakephp-scripts Architecture: source all Version: 1.3.15-1+deb7u2 Distribution: wheezy-security Urgency: high Maintainer: Chris Lamb <lamby@debian.org> Changed-By: Markus Koschany <apo@debian.org> Description: cakephp - MVC rapid application development framework for PHP cakephp-scripts - MVC rapid application development framework for PHP (scripts) Changes: cakephp (1.3.15-1+deb7u2) wheezy-security; urgency=high . * Non-maintainer upload by the LTS team. * Fix CVE-2016-4793: The getClientIP function allowed remote attackers to spoof their IP address. This vulnerability could be used to bypass access control lists to get access to sensitive data, or lead to higher severity vulnerabilities if untrusted data returned by getClientIP() is treated as safe and used without appropriate sanitization within SQL queries, system command calls etc. Checksums-Sha1: 3863f15af4140edf8b29282baffd5e9c6607f056 2017 cakephp_1.3.15-1+deb7u2.dsc d29408bb6c6dceac7bf1fad24f7a34dcead671d5 8208 cakephp_1.3.15-1+deb7u2.debian.tar.gz 205530008602e302ef0092ca7d91aec8e24b90b9 905746 cakephp_1.3.15-1+deb7u2_all.deb 914391ea3145973b3ebcd519a586e3063033953c 113314 cakephp-scripts_1.3.15-1+deb7u2_all.deb Checksums-Sha256: d08d5ba2e22801681777f1763777a00b231a2b5c07f73b87fddb8f7cd7d1bc4b 2017 cakephp_1.3.15-1+deb7u2.dsc a14e36bcd6b44eba0a052677c4dd12f9a68deb2d771bb38a2df012ae3fe9fe56 8208 cakephp_1.3.15-1+deb7u2.debian.tar.gz 4986b5b4ce235c4c1218a20605361672d4cdf3d76830aa3ca2785d3194af0543 905746 cakephp_1.3.15-1+deb7u2_all.deb a5a94ad6b22b101548533de7fc4a2bbd829800b5f7e7cc97d87da4836aa2b2e7 113314 cakephp-scripts_1.3.15-1+deb7u2_all.deb Files: 37bc1d32ea60a29ba0fe71ed9dec78ef 2017 web optional cakephp_1.3.15-1+deb7u2.dsc 6760d7b46d36fd04ee0fc26167e2a02e 8208 web optional cakephp_1.3.15-1+deb7u2.debian.tar.gz fb1ce544a55ed83878f58bf74dd3f842 905746 web optional cakephp_1.3.15-1+deb7u2_all.deb eb04d79f8da63e7d7097f57c253b0e1c 113314 web optional cakephp-scripts_1.3.15-1+deb7u2_all.deb -----BEGIN PGP SIGNATURE----- iQKjBAEBCgCNFiEErPPQiO8y7e9qGoNf2a0UuVE7UeQFAliwgZRfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldEFD RjNEMDg4RUYzMkVERUY2QTFBODM1RkQ5QUQxNEI5NTEzQjUxRTQPHGFwb0BkZWJp YW4ub3JnAAoJENmtFLlRO1HkeyEQAM7GF8XL2PKtLiNdfsd7E+nUhd8DtdWn5Fg4 k9mySm6EneGuRA98lUhWpXWfX8cF2Qgf4BKCB9yVxRHEcamw2ltjMZncy3GDXzXK kWxGoj0Hk5Nq9FfSreXZDFQ1mnt2JIN0i+xPZRxvf8rFFzaKECzw3p0jB8hkc6ua RYh8FLspsS2HzWEzTpitn9G7vDr8OVussh4semcGfGOpaJj14W4hCdgzlWh2mAe8 ae9TTrRP5RbKX7jhu8PS5SB/FEbkFpCv0BOrtb6E/PtjASXYC5z196dHj12cw6MF fs9WPOJCQnupBB+PrtgAFh0kPEkMOpPXtQXthhelaorz+4QES7mZt4Kwj16dkayd MWAB23XZnq9YNWmhg2tinJogpsObd0vriCqWFKq4LazThlj0vmRajAAqMe5++Mms 8CdEPPORyBV4QhTm9RzE9So8H2+l6XoTmoLg28PtnvpPc16d2+N/yLXYWSZ/reBg eODifzx6eaL/Wi2M90Ppv/+lDcQRLiPsv3Id32cnttzuq8vtamJDcjvbjjBHPXYm nY+at+6ELmi7+L1pF62lj+LBUE6EW6Wx2ywO7MciD1deWmoRgoXpQ0GJ3Dz7VoOi 8Bg1TPyV/FKRvAbDvkCiQybrKDKSIs1wk5P9fA3P7US3pCQNwG5F1Wh5gqAJM89Q CyrdFABj =fHfN -----END PGP SIGNATURE-----