-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Sun, 18 Dec 2011 20:37:18 +0100 Source: lighttpd Binary: lighttpd lighttpd-doc lighttpd-mod-mysql-vhost lighttpd-mod-trigger-b4-dl lighttpd-mod-cml lighttpd-mod-magnet lighttpd-mod-webdav Architecture: armel Version: 1.4.28-2+squeeze1 Distribution: squeeze-security Urgency: high Maintainer: armel Build Daemon (antheil) Changed-By: Arno Töll Description: lighttpd - A fast webserver with minimal memory footprint lighttpd-doc - Documentation for lighttpd lighttpd-mod-cml - Cache meta language module for lighttpd lighttpd-mod-magnet - Control the request handling module for lighttpd lighttpd-mod-mysql-vhost - MySQL-based virtual host configuration for lighttpd lighttpd-mod-trigger-b4-dl - Anti-deep-linking module for lighttpd lighttpd-mod-webdav - WebDAV module for lighttpd Changes: lighttpd (1.4.28-2+squeeze1) stable-security; urgency=high . * Backport security issues from 1.4.30: + Fix integer overflow (CVE-2011-4362) + Fix attack vector as disclosed by the SSL BEAST attack (related: CVE-2011-3389). Note: If you are upgrading from an older version you need to change your configuration to mitigate effects of the attack. See the corresponding NEWS file for details. Checksums-Sha1: f85bbb45c80d2378cca2f2f9234fdc3b65446b1c 283954 lighttpd_1.4.28-2+squeeze1_armel.deb 3bc83392fefb6a04ea25f127fe04cdec841b5f3e 17800 lighttpd-mod-mysql-vhost_1.4.28-2+squeeze1_armel.deb 81044a93a75d2849f4e3cb7c0eea4ec156159f06 19574 lighttpd-mod-trigger-b4-dl_1.4.28-2+squeeze1_armel.deb b651545e23300fc24d10af8ecfade020759fa5dd 23100 lighttpd-mod-cml_1.4.28-2+squeeze1_armel.deb 0650efadae41c7c16297c09b8912080b3adc2fd6 24952 lighttpd-mod-magnet_1.4.28-2+squeeze1_armel.deb 3cb1a3ba6dcfe3240ffb67c07a91668d306c2366 29880 lighttpd-mod-webdav_1.4.28-2+squeeze1_armel.deb Checksums-Sha256: 599d874d444d16943b20a307334d8ab9e89959384ce3963810c03a0a44383540 283954 lighttpd_1.4.28-2+squeeze1_armel.deb 90f5c580ed10eabe74d4198666eba3516b3515c9951d0f234b3844bdc8f8f615 17800 lighttpd-mod-mysql-vhost_1.4.28-2+squeeze1_armel.deb 850fdabe2e89b6d4fc080f1602d5fc20ac9d57dced1219c3f65bbc072d91a1e4 19574 lighttpd-mod-trigger-b4-dl_1.4.28-2+squeeze1_armel.deb 216a992b6725c3c37ba1c14828f9bc36a28e1c846296f287b566f3ef84f33388 23100 lighttpd-mod-cml_1.4.28-2+squeeze1_armel.deb 6c933e5085b5c4ab4cf0e3a829c1234865c97c33886ba4201d48650ed332152d 24952 lighttpd-mod-magnet_1.4.28-2+squeeze1_armel.deb b05dfed6b51e1f213eeb2e0223816c480465e72a7d3013488b87b2646895c954 29880 lighttpd-mod-webdav_1.4.28-2+squeeze1_armel.deb Files: 6e8a54d36e590fbae0764b0031b49550 283954 httpd optional lighttpd_1.4.28-2+squeeze1_armel.deb f5e730d3b834e02d975d299eb80623d0 17800 httpd optional lighttpd-mod-mysql-vhost_1.4.28-2+squeeze1_armel.deb f313500e26014c03093ef4236e11b316 19574 httpd optional lighttpd-mod-trigger-b4-dl_1.4.28-2+squeeze1_armel.deb ac41b1f3263c7a7c55672310c26c537e 23100 httpd optional lighttpd-mod-cml_1.4.28-2+squeeze1_armel.deb 6a83acf4e749895cecefb62a42d12534 24952 httpd optional lighttpd-mod-magnet_1.4.28-2+squeeze1_armel.deb a2a14bd69f5ab046412e02a40bcd5940 29880 httpd optional lighttpd-mod-webdav_1.4.28-2+squeeze1_armel.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iQIcBAEBCAAGBQJO8QHWAAoJENw5e+lerrJ2ZCoP/Au74xjyErozYfe0hVildWeF FvAwB5OK6HIDjt/BWbIH6xHDX5751pCCTyWNo3DHJw+Qr8jiruF5QzO0VQrJ4kTy pi8cd7KPeByHdmX+Fw+zYKHG83KyGtGuRM5Rh2R8IidsMV07vNw1FfWR6xc6Bo5K tPolj5XY+7h5PnQGBbz7RXekp8LfOp2WDjLDHjMRiRBSpPde8QWFvmehPH8LYKNm z8I8A67jv2zS9N6wY/9TqmvqAMDpcmuzFGh83mK/QZG+1TByCQpvE1y0kuY0PBKO xbmrRGOWnbAXk8EhuanMNt6KOJVjhT4LSP4jap49C182qMRSEU860bsCSgmzjOTL J0FhLTNEXvyTXhoJ6y7YtoRYmOBG90JsryYhiKE5PLdJVrN8m7tXbK0Mk5wJ4E33 HbuGhDMoDra2dCfwOsRE3j6M/Rkndv627IkzR0kqnJz1P1Qqzt+zh5hbZ9/NKFC1 7AP8kVFGMoVXSmV1Gl8Vh8mtWlRMIdPWl/tuc6IruDNdmpTAuTqTtkhct2z5fto4 FifgDn9jDJbEexYvVM+oINfehDsPDgnGgkibvj7rq2807ZzMOa16rtoe/gGsWDsv ws+YkdfiFIh+jEQxt2H7GkJPbk5/INnuPr7pfseW6c+Q7gRp8K9FgbxEXu1bEivc 0zWnBym45Zo+JlNR3XOp =0Nby -----END PGP SIGNATURE-----