-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Sun, 18 Dec 2011 20:37:18 +0100 Source: lighttpd Binary: lighttpd lighttpd-doc lighttpd-mod-mysql-vhost lighttpd-mod-trigger-b4-dl lighttpd-mod-cml lighttpd-mod-magnet lighttpd-mod-webdav Architecture: ia64 Version: 1.4.28-2+squeeze1 Distribution: squeeze-security Urgency: high Maintainer: ia64 Build Daemon (alkman) Changed-By: Arno Töll Description: lighttpd - A fast webserver with minimal memory footprint lighttpd-doc - Documentation for lighttpd lighttpd-mod-cml - Cache meta language module for lighttpd lighttpd-mod-magnet - Control the request handling module for lighttpd lighttpd-mod-mysql-vhost - MySQL-based virtual host configuration for lighttpd lighttpd-mod-trigger-b4-dl - Anti-deep-linking module for lighttpd lighttpd-mod-webdav - WebDAV module for lighttpd Changes: lighttpd (1.4.28-2+squeeze1) stable-security; urgency=high . * Backport security issues from 1.4.30: + Fix integer overflow (CVE-2011-4362) + Fix attack vector as disclosed by the SSL BEAST attack (related: CVE-2011-3389). Note: If you are upgrading from an older version you need to change your configuration to mitigate effects of the attack. See the corresponding NEWS file for details. Checksums-Sha1: 909b31a36616a09a89119eaf41a5f96bc90d614d 403192 lighttpd_1.4.28-2+squeeze1_ia64.deb 367c3ec8acf076cc85924e818f76d04924354f95 20194 lighttpd-mod-mysql-vhost_1.4.28-2+squeeze1_ia64.deb 38e91a0ee47bc1bbdc11310c10b61f493c2f436f 22402 lighttpd-mod-trigger-b4-dl_1.4.28-2+squeeze1_ia64.deb 195646e299d456fea226c4b1bc2d03047e4c23f0 26394 lighttpd-mod-cml_1.4.28-2+squeeze1_ia64.deb ff468887a0fb5bfc209e581a02fed3455821b404 28288 lighttpd-mod-magnet_1.4.28-2+squeeze1_ia64.deb 3c1ece8f7284b0483da22ec8ae2384a7d78861c7 36412 lighttpd-mod-webdav_1.4.28-2+squeeze1_ia64.deb Checksums-Sha256: a1c09463b968ddcb934f594aa26cb8a4fc633aa2ae23035899712cdc4e443c4d 403192 lighttpd_1.4.28-2+squeeze1_ia64.deb ffb3f25f69adc4bfa913a89e2a9bb95b358ce6e6b51790ffd10005a0bd28ff94 20194 lighttpd-mod-mysql-vhost_1.4.28-2+squeeze1_ia64.deb 2e7ae606353c9e2b75ddf14f8602585c65d9daa63a19cca440e93fe2bae13de3 22402 lighttpd-mod-trigger-b4-dl_1.4.28-2+squeeze1_ia64.deb 605c7c2d2b257a3af1ac825ea380c86988967532cba11022243ed92d72dd349e 26394 lighttpd-mod-cml_1.4.28-2+squeeze1_ia64.deb cc882ac029db26a322f34c34a1a2dfaac0e1dadd7ea78e86f28e8af86edcd406 28288 lighttpd-mod-magnet_1.4.28-2+squeeze1_ia64.deb 68c6459872ba65e1a015a238e87fc450672000576f6822ee8f63d77cc7849d58 36412 lighttpd-mod-webdav_1.4.28-2+squeeze1_ia64.deb Files: 21997133e749478e09a3c8e208a4ed74 403192 httpd optional lighttpd_1.4.28-2+squeeze1_ia64.deb cfc2476db1296359d3745e38f04a02f3 20194 httpd optional lighttpd-mod-mysql-vhost_1.4.28-2+squeeze1_ia64.deb 2a731af783544228af383b4487a58c47 22402 httpd optional lighttpd-mod-trigger-b4-dl_1.4.28-2+squeeze1_ia64.deb c25405fe842527fa37f44dd2bf1b49ae 26394 httpd optional lighttpd-mod-cml_1.4.28-2+squeeze1_ia64.deb e0a590cd9b36b8e94edc29738b45bf48 28288 httpd optional lighttpd-mod-magnet_1.4.28-2+squeeze1_ia64.deb bb0274711c0aa248eaed0d63c9dccf46 36412 httpd optional lighttpd-mod-webdav_1.4.28-2+squeeze1_ia64.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iQIcBAEBCAAGBQJO8QBdAAoJEEvpbjz8HoZoWQQP/A26EIOhB0lRMu4FoxUA4EXk 7McV6mEjkR48B4qQmwe8frAuQugJfs+rxCVyg+V/aO2P1Awdf0Y+0fdaKOecd15W egDQ9qvjNXS81Zlj5zKZdib2x8kzm0O3pWDBAZYw0RmvAnDb60RZRZPM2wausuzh Lu4G4JBhILwPlPa1niCVltJZMwr5lqqoMu8SqHga7yo7iD6kvRNsyskayehnn2C4 5R3u9eHGTZVVQDPutcwV1ecTz7DzKcCELl3rS7mtmHrJfikJ072PyqM1OGE31AF+ bkFLxApJZIGPewLPaNfptiAR4Hln7XptWh1M3dJ3BvgLnWSm7PyI5IBQvU66rXYY 3cpEl5IORke1YzF/b0oTApv6tu0yhAgxsHkp8F/ikRq3MZ8zXvwQIfDU0p0bupbQ 33RfeRW3gLVIwAOu5ufG+eDeA7qePVSCx6DGn5PdTFkHkVH+39Vjxleo2kTv8a1E 2KowYY3THBolal2fezrIjof11msPYsIWvst+FqAA4RfD81iIboBUQ+ttxoXY0ba1 cTRy8SZEYdaMV5S6QDI8fQYP85ZMDu+i2VY7xlfyGtgFolxNy/3uhvO09rZPRUTv Nz/H0xj2ZgmTwj+/9TIQyjgDvmv5HUWBs3ImQmFlblPwenbFWnh2gL3eovZlzKzU dk+i0GGq16cdiX6eIBUx =5fkA -----END PGP SIGNATURE-----