-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Format: 1.8 Date: Sun, 18 Dec 2011 20:37:18 +0100 Source: lighttpd Binary: lighttpd lighttpd-doc lighttpd-mod-mysql-vhost lighttpd-mod-trigger-b4-dl lighttpd-mod-cml lighttpd-mod-magnet lighttpd-mod-webdav Architecture: source amd64 all Version: 1.4.28-2+squeeze1 Distribution: stable-security Urgency: high Maintainer: Debian lighttpd maintainers Changed-By: Arno Töll Description: lighttpd - A fast webserver with minimal memory footprint lighttpd-doc - Documentation for lighttpd lighttpd-mod-cml - Cache meta language module for lighttpd lighttpd-mod-magnet - Control the request handling module for lighttpd lighttpd-mod-mysql-vhost - MySQL-based virtual host configuration for lighttpd lighttpd-mod-trigger-b4-dl - Anti-deep-linking module for lighttpd lighttpd-mod-webdav - WebDAV module for lighttpd Changes: lighttpd (1.4.28-2+squeeze1) stable-security; urgency=high . * Backport security issues from 1.4.30: + Fix integer overflow (CVE-2011-4362) + Fix attack vector as disclosed by the SSL BEAST attack (related: CVE-2011-3389). Note: If you are upgrading from an older version you need to change your configuration to mitigate effects of the attack. See the corresponding NEWS file for details. Checksums-Sha1: 5bd11a63e6f0f2d8bb8655f637bb5818b31b933c 1676 lighttpd_1.4.28-2+squeeze1.dsc 24d614f75b3aba18f3cff5e52a27ec9fdcf853b5 808352 lighttpd_1.4.28.orig.tar.gz fe8ea40eb56fd0edd53be5bf28c0b82fb41d321d 28608 lighttpd_1.4.28-2+squeeze1.debian.tar.gz 86c1da3eafb0693e0355b8ba09ac04b7680e9e81 289116 lighttpd_1.4.28-2+squeeze1_amd64.deb 7b62991554bc5f64ab94840d9e7a7919a5b91f35 18330 lighttpd-mod-mysql-vhost_1.4.28-2+squeeze1_amd64.deb 91a327266af86a9d01b8ae81a34fee5b73068155 19962 lighttpd-mod-trigger-b4-dl_1.4.28-2+squeeze1_amd64.deb 18f9e54f0f34c6e925400a2c187473a628905958 23118 lighttpd-mod-cml_1.4.28-2+squeeze1_amd64.deb d6afafe5e5f494bcacc0b81468555fc13b7a0d2e 24318 lighttpd-mod-magnet_1.4.28-2+squeeze1_amd64.deb 00365b3c8cf15605c12e0f023845d08419c354c5 30336 lighttpd-mod-webdav_1.4.28-2+squeeze1_amd64.deb bf9432230bcb8e24890dddba9d32046eb3357dde 62854 lighttpd-doc_1.4.28-2+squeeze1_all.deb Checksums-Sha256: fb0761695df6bbdda1c3c033df8f38fe5d3fb2a9f3d39bdf63f77ddfb7f87c72 1676 lighttpd_1.4.28-2+squeeze1.dsc efd7623f43182723b99c51d57a24158e22a207cd90dca35aaf3b2e3bac115712 808352 lighttpd_1.4.28.orig.tar.gz e6cbe71759adea6da626575cdf866ed4a91e9a206328d16c8b52637bb4de5504 28608 lighttpd_1.4.28-2+squeeze1.debian.tar.gz 5cd3c95ca92ab6fdb391a42352a9a205000d3fd945a12c6177097bb3be895866 289116 lighttpd_1.4.28-2+squeeze1_amd64.deb 01df14d8ff2ce62552b181cb29fe764fcd7000adee449fe58b0fd0dbfcec85fa 18330 lighttpd-mod-mysql-vhost_1.4.28-2+squeeze1_amd64.deb 6c699274553102b25059647be19f9af9c814be9a05fb148e2e274ac18bd831a4 19962 lighttpd-mod-trigger-b4-dl_1.4.28-2+squeeze1_amd64.deb db4ab1654fe0dbc33cddf4fe10e1e7a4910cbef9e102e16b424603e336872e21 23118 lighttpd-mod-cml_1.4.28-2+squeeze1_amd64.deb 2e0258ddbd736ac1914af078dfe8b50ad6691719f90d0db4561fc7ea377cba2d 24318 lighttpd-mod-magnet_1.4.28-2+squeeze1_amd64.deb 9782bf61996a8319a10cb77ff950a8e7fd76967a17872f74fe4d4bdc5d5a7f9d 30336 lighttpd-mod-webdav_1.4.28-2+squeeze1_amd64.deb c55d37d645253beaeaa9712b190b8bafe90a34b5b501338102bfd66d072bf084 62854 lighttpd-doc_1.4.28-2+squeeze1_all.deb Files: 20354dd90f51cc6621d634442b1b0fef 1676 httpd optional lighttpd_1.4.28-2+squeeze1.dsc 202d36efc6324adb95a3600d2826ec6a 808352 httpd optional lighttpd_1.4.28.orig.tar.gz 851d03a66c6ca3d9393bdf4f74d129d6 28608 httpd optional lighttpd_1.4.28-2+squeeze1.debian.tar.gz 3967207abf498ddf948c5e90a3eadda5 289116 httpd optional lighttpd_1.4.28-2+squeeze1_amd64.deb 6d4073fc8e397e04bdb6e86300bc6700 18330 httpd optional lighttpd-mod-mysql-vhost_1.4.28-2+squeeze1_amd64.deb 54b8501cd4c71eda3ed941ebb3c8fe31 19962 httpd optional lighttpd-mod-trigger-b4-dl_1.4.28-2+squeeze1_amd64.deb ac0f3e2ed7c7e0643a3aa142d81a46bd 23118 httpd optional lighttpd-mod-cml_1.4.28-2+squeeze1_amd64.deb 32d721e3e4e3668a2e8885004b7551ee 24318 httpd optional lighttpd-mod-magnet_1.4.28-2+squeeze1_amd64.deb 6ba2b4b9be0002ac85c7da0c7877bbe4 30336 httpd optional lighttpd-mod-webdav_1.4.28-2+squeeze1_amd64.deb 3af8f4718e6c3c68a18fb963fa1fc294 62854 doc optional lighttpd-doc_1.4.28-2+squeeze1_all.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.11 (GNU/Linux) iEYEARECAAYFAk7w9fwACgkQHYflSXNkfP9KLACeKzqZ26soFrAwC7VcGlZKy3po IYEAn3c8908mr2FEhL7LNvyTGQkYLoJI =90U/ -----END PGP SIGNATURE-----