-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Sun, 18 Dec 2011 20:37:18 +0100 Source: lighttpd Binary: lighttpd lighttpd-doc lighttpd-mod-mysql-vhost lighttpd-mod-trigger-b4-dl lighttpd-mod-cml lighttpd-mod-magnet lighttpd-mod-webdav Architecture: powerpc Version: 1.4.28-2+squeeze1 Distribution: squeeze-security Urgency: high Maintainer: powerpc Build Daemon (praetorius) Changed-By: Arno Töll Description: lighttpd - A fast webserver with minimal memory footprint lighttpd-doc - Documentation for lighttpd lighttpd-mod-cml - Cache meta language module for lighttpd lighttpd-mod-magnet - Control the request handling module for lighttpd lighttpd-mod-mysql-vhost - MySQL-based virtual host configuration for lighttpd lighttpd-mod-trigger-b4-dl - Anti-deep-linking module for lighttpd lighttpd-mod-webdav - WebDAV module for lighttpd Changes: lighttpd (1.4.28-2+squeeze1) stable-security; urgency=high . * Backport security issues from 1.4.30: + Fix integer overflow (CVE-2011-4362) + Fix attack vector as disclosed by the SSL BEAST attack (related: CVE-2011-3389). Note: If you are upgrading from an older version you need to change your configuration to mitigate effects of the attack. See the corresponding NEWS file for details. Checksums-Sha1: 751136012c06bcd33362b98e1b9917d6cc871177 291480 lighttpd_1.4.28-2+squeeze1_powerpc.deb 000d9388a0cc91df5c859e8a34f0945740ea54f2 18320 lighttpd-mod-mysql-vhost_1.4.28-2+squeeze1_powerpc.deb 5da4a979d5a343f9143ebd4cf18e37c6abf959c6 20038 lighttpd-mod-trigger-b4-dl_1.4.28-2+squeeze1_powerpc.deb fb29496c2cbd8ba01e090946599e118f07eaf47d 23172 lighttpd-mod-cml_1.4.28-2+squeeze1_powerpc.deb a0f3354ff2ea5c7ad21edfe2b45575c3c7d8497f 24358 lighttpd-mod-magnet_1.4.28-2+squeeze1_powerpc.deb 209a8e21cb218868accac3a25e7f01380846adc1 31258 lighttpd-mod-webdav_1.4.28-2+squeeze1_powerpc.deb Checksums-Sha256: 907931ff9c65b16bc483d0072902431834b54efd547802277713bdcb6734e59e 291480 lighttpd_1.4.28-2+squeeze1_powerpc.deb 0730a10750ff85e40358ffd07900e00fce84253b5bbe64067eaafc33dc5c932e 18320 lighttpd-mod-mysql-vhost_1.4.28-2+squeeze1_powerpc.deb a685e51c4cee27901b28f110a0bb2930ce3648f7401385b4621a7f5a32ab679f 20038 lighttpd-mod-trigger-b4-dl_1.4.28-2+squeeze1_powerpc.deb b36d813a2816b002ac06155f2c9971f6735169330349969fc0caa7660cdef363 23172 lighttpd-mod-cml_1.4.28-2+squeeze1_powerpc.deb 8566d1551229cde6c540a925addd50ce99687a8cb18c359d99c4cae341f89116 24358 lighttpd-mod-magnet_1.4.28-2+squeeze1_powerpc.deb 588b74630a5910228c472ec4cc1ab3c91f350d773cbbfa2c49a5715ccff2d86b 31258 lighttpd-mod-webdav_1.4.28-2+squeeze1_powerpc.deb Files: 3fff5b3c165ced842e349dc2a9504612 291480 httpd optional lighttpd_1.4.28-2+squeeze1_powerpc.deb a96b5740b7a4cd387a6e64295bf0ba19 18320 httpd optional lighttpd-mod-mysql-vhost_1.4.28-2+squeeze1_powerpc.deb 13c84e518678c243746879449c01d21e 20038 httpd optional lighttpd-mod-trigger-b4-dl_1.4.28-2+squeeze1_powerpc.deb 787cd35ccfa541259dc84413c592036b 23172 httpd optional lighttpd-mod-cml_1.4.28-2+squeeze1_powerpc.deb 3e1cf936cf9a6fccdb3190855720d21c 24358 httpd optional lighttpd-mod-magnet_1.4.28-2+squeeze1_powerpc.deb 208c4fa4758160bfb12a710ca6f2063d 31258 httpd optional lighttpd-mod-webdav_1.4.28-2+squeeze1_powerpc.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iQIcBAEBCAAGBQJO8P+AAAoJENwoKotIl26lY2YP/i/gDpEYTjvp0Xz3BHTX8q3e +lXAVSP6bE9JCLqZc5zmpItjwqRqDfR4+RsDSZFhIHOi/OuVgDksBu07vnnFtlhm OdFqoYFMehPHnr6OJIwoB/OppppGMlt2AUy44JJt82PxvuskN8K0EkiwOkmLbdcH 2DINJq4DF2D6rQrFhLFglJPX1DJ1yx/BUybaMKIZg6TnDU7tGAW+9N+Vht39fBSw NA2VU0TYSEJcqKjUosfVMbHIDjeokoF9CKataTLFCp33DSJOKXc6VXNKayyTEUMJ kq66u3P0rnvEcO181k1MstBtQ2jCQDwUu8X59zoDkpHWJLwMXczb5kBtQc758Vx8 bTjdj6FSV1CY3tzbi7qQpaeRiGu2tqeB6oWdQivfMyks8TfX+kovxvPTC3w0Gt7B 5h/x9vMK7wfjKtT63+gvO+m3GyrnbpM7rPWDh8pA79BHY675hYbr1MLTxMREOsPK qvSpq9uIVQRF/AUb7mfD7qW18MvSqd8RWPzmfLOP8jKmZahLh1f+JRrQWkVdEjof 0GM7TCyy2f2zIPXtlWrTOy7p4x8c/moBunzDjPN4BpBrvRo8Pu3uHZNbipJmww0Y JNbQeGg8DQ9QFjtolpcjU1642I87eZ64II4+f/eo6BeH5tIpxuYPDAW57aW2+fPw lvYQn2/fJV0PZWhSuNmC =P5TU -----END PGP SIGNATURE-----