-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Thu, 13 Apr 2017 18:11:17 +0200 Source: apt-cacher-ng Binary: apt-cacher-ng Architecture: source Version: 2-2 Distribution: testing Urgency: high Maintainer: Eduard Bloch <blade@debian.org> Changed-By: Eduard Bloch <blade@debian.org> Description: apt-cacher-ng - caching proxy server for software repositories Closes: 856635 Changes: apt-cacher-ng (2-2) testing; urgency=high . * Special version only for Debian Stretch, solving moderate security issues: + hardening against HTTP header splitting attack (no user input printed in the HTTP headers anymore; backport from Sid, related to CVE-2017-7443) + hardening against unintended or malicious triggering of hidden space allocation, by disabling the fallocate completely. This is ultima ratio, trading code simplicity for fragmentation avoiding efforts; a smarter solution is found in upstream version 3; closes: #856635) + handle a corner case of bad TLS handshake with invalid certificate (related to #839751) Checksums-Sha1: bd56a74d034ecdb95b46af7ad5eb4ffa7c6fea48 2197 apt-cacher-ng_2-2.dsc 29c5fb3e2df9762ec68601e163993cbee8d805bc 48508 apt-cacher-ng_2-2.debian.tar.xz 74e9cd4806021ee899846cee64bcd14b2c2e9015 8500 apt-cacher-ng_2-2_source.buildinfo Checksums-Sha256: c418ffc4f2223acaca0733c2deabef529b0f56e67e0efd98e8cfdfd05fa7ddc9 2197 apt-cacher-ng_2-2.dsc e68b4e670d05ec818639bc4e0813d24a42f224429beca9f2ec5ac36dbaa5e7e1 48508 apt-cacher-ng_2-2.debian.tar.xz 27630ddd510f87eacd9f2c654b0b7c937f8b9f3a43208d3e8e469fd4c5fcdb63 8500 apt-cacher-ng_2-2_source.buildinfo Files: 01c4b06e2fc5180313d62dbcea0f35db 2197 net optional apt-cacher-ng_2-2.dsc 08455c1e92375784e57bf934f9580843 48508 net optional apt-cacher-ng_2-2.debian.tar.xz 8bcdb0f365b29efe337d6bf63e87763c 8500 net optional apt-cacher-ng_2-2_source.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFiEEZI3Zj0vEgpAXyw40aXQOXLNf7DwFAlkQ2RUACgkQaXQOXLNf 7Dw2yw//aK0xlMtx36TkdalZSqmIdjp3RL0fpZrU1qQRa36LwUcu1zWt9sVvT12Y pMLONgofUfbbD/KxpOgJvS7JNC/cJ/9mJ896CtIqXC380mmCJP3C3sFI9HEW30on oteD0fdSmd+q6uUH1NeckBu3pic1hT7e9K0I3Cj+uL5wiu4GihF2QhbM+lMMbLJV OGjIaUtNUxpZDMMfiYUDUOsvKKtF04Qsk6SQ6pQ8onR6RPp/d4o/UFP6UlBZu3pG OTr2CKVcdpWSAxRRO/3v0kjlyxfV7zRJS2gi2sz1KFvrAZBu7fOdVTMj2Ghc5d/q i1oyTTwXb+H5zsp/xfsutt4qNIyOyfvlcZ19BKrIPbGJBkSRPdve+srzHNSJaR/V f+ymRGMT6PeHaXOoUl95Ib1TgLjz9dW3Kju9zlGf3263cF38M8Xeh3wLrrbjo5zh g3OjBXsQGl7BOMcDjOZCpIo1dUkhig5rDCuWIiBIdubYarbNqbnTyKy0w7ndHGf5 uv5UAQEzr3FCoxt3nNoLLKcSpJl/aVx8XTBii8qq4HxSb57H1Pg4RgTzdiNqMqBa RgLdskUYaWnvzQex1dhmXSy/Fq0Mu+EHz2Tc2rRT7HodVxtlCHfo28IfrCu44RMA p/WY44sVjYFkGYs0Gvy6CZObwN61y2JQsNp3UqLOLEw/hT3VTag= =ypO4 -----END PGP SIGNATURE-----