-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Sun, 22 Apr 2018 10:49:38 +0200 Source: gunicorn Binary: gunicorn Architecture: source all Version: 0.14.5-3+deb7u2 Distribution: wheezy-security Urgency: high Maintainer: Chris Lamb <lamby@debian.org> Changed-By: Chris Lamb <lamby@debian.org> Description: gunicorn - Event-based HTTP/WSGI server Closes: 896548 Changes: gunicorn (0.14.5-3+deb7u2) wheezy-security; urgency=high . * CVE-2018-1000164: Fix an issue where CRLF sequences in HTTP headers could result in an attacker tricking the server into returning arbitrary HTTP headers. (Closes: #896548) Checksums-Sha1: 5221dbb3ac6ee296562b44e32c99e568bbd0bd34 1890 gunicorn_0.14.5-3+deb7u2.dsc 24d4ea2afef8a05fc68c932f9ffc0a053098ac6b 219304 gunicorn_0.14.5.orig.tar.gz ebc4663a5e1ec82e325c8f61d8bd2fa17b0bd639 10634 gunicorn_0.14.5-3+deb7u2.debian.tar.gz 834354e9cf3e5a45d6411c271636bd14180233a7 113068 gunicorn_0.14.5-3+deb7u2_all.deb Checksums-Sha256: 9c61092380a21660856914413fe0ee22dc35d219473b5225c89048e2045f9fc4 1890 gunicorn_0.14.5-3+deb7u2.dsc c047af6fa69f97135aa9380d746f2cf1fc011196dd71a050701d4454fddd12e6 219304 gunicorn_0.14.5.orig.tar.gz f3f4a8370221a68bb04a9c18f84994e6a59670de5af6fb1ebf4a253653acb0c1 10634 gunicorn_0.14.5-3+deb7u2.debian.tar.gz fd25ffeaad80aeb475319aa2706364bf6a39307253115d0aa3d1a4c39e9e4aed 113068 gunicorn_0.14.5-3+deb7u2_all.deb Files: 5decc27cf574eab33e94814246111009 1890 python optional gunicorn_0.14.5-3+deb7u2.dsc c09bc8e0336a902a73a3c587a5b1440d 219304 python optional gunicorn_0.14.5.orig.tar.gz 0c347c7160af67b3d69737525943bc61 10634 python optional gunicorn_0.14.5-3+deb7u2.debian.tar.gz ceb01fbefe60b159310cfea3495c99da 113068 python optional gunicorn_0.14.5-3+deb7u2_all.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFiEEwv5L0nHBObhsUz5GHpU+J9QxHlgFAlrcTwQACgkQHpU+J9Qx Hli+OA/9ETS6KAB/WI3BjK5P/HkaFNLHqvr9keDiDMvcNcSNG/EmoE433Rng6mnb 2mbyIHavf++SmbRkkSqYRka3XzY/Zq12h5mFiskjjaxTsCiX5dmN+qCqkgLp62Wh Kp0EwzLAW1lpwDJEFtCInVrmHLlXdFOL0IdNdrgxbbctF6ooakk9UcniZS2ljg7R uWXk3WWvsRSUu28R4irU0rwWMQoJcAYj2m5sdq5DBkYnhs3kkqrZ2F4dxGMKlYiB syj8aiBcbwONi0kW8aT2oucKIzHShTsJGzrTWuDmJLiXrCGdd9VdUp/FYKN9v0kc BUNmteyc124NTMe+hDt0HmWcEivJNjzltETA5TXWJLneJULWS0QCEA/63nufqxs3 5OAA+CrDn33iIPBqzwFwN9VPEuup9cfdtnZ+8JOUusF4+kNZ8ywQN55AR7xHHLza icTUxUa5PE08GixZMaspWd2C3YnZf4tX2G8Xi3Nus3q0rDACrYxE92QKfN/jnLYb RBycAwnfsnEu1Ere8LMKXeT7xxiKHtLApIW9F8AkZMGNf7eBIRI/cld4MUtPCBOY 2PGXQzia0MTha/D9HifJgLLyZuaGwRXWpztf/htQMmrhs5qpV+X2207D6y+TCm39 WZA6RNHaBIwKjntqcSU7vJwdvzCvYoIkSDMcn4Lz7UviCjIg0s0= =YkWz -----END PGP SIGNATURE-----