-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Sun, 18 Dec 2011 20:37:18 +0100 Source: lighttpd Binary: lighttpd lighttpd-doc lighttpd-mod-mysql-vhost lighttpd-mod-trigger-b4-dl lighttpd-mod-cml lighttpd-mod-magnet lighttpd-mod-webdav Architecture: s390 Version: 1.4.28-2+squeeze1 Distribution: squeeze-security Urgency: high Maintainer: s390/s390x Build Daemon (zandonai) Changed-By: Arno Töll Description: lighttpd - A fast webserver with minimal memory footprint lighttpd-doc - Documentation for lighttpd lighttpd-mod-cml - Cache meta language module for lighttpd lighttpd-mod-magnet - Control the request handling module for lighttpd lighttpd-mod-mysql-vhost - MySQL-based virtual host configuration for lighttpd lighttpd-mod-trigger-b4-dl - Anti-deep-linking module for lighttpd lighttpd-mod-webdav - WebDAV module for lighttpd Changes: lighttpd (1.4.28-2+squeeze1) stable-security; urgency=high . * Backport security issues from 1.4.30: + Fix integer overflow (CVE-2011-4362) + Fix attack vector as disclosed by the SSL BEAST attack (related: CVE-2011-3389). Note: If you are upgrading from an older version you need to change your configuration to mitigate effects of the attack. See the corresponding NEWS file for details. Checksums-Sha1: 1a57b8cf2dd7139f6f8e679df68f1cc5081848cf 296076 lighttpd_1.4.28-2+squeeze1_s390.deb 01f4c43711b1cb30afac3f2410f81ac3484473fe 18550 lighttpd-mod-mysql-vhost_1.4.28-2+squeeze1_s390.deb 6fa5ac9bd4fe3d7ae6c48d18d14dedfed0494836 20146 lighttpd-mod-trigger-b4-dl_1.4.28-2+squeeze1_s390.deb 103a5569fade232ee6acbc272a0286c11c6b76f5 23390 lighttpd-mod-cml_1.4.28-2+squeeze1_s390.deb 5c1f337cebd01050363f7e4a67b821792e10b675 24606 lighttpd-mod-magnet_1.4.28-2+squeeze1_s390.deb 275d39df1dbe166f136c779fd48f296120bf93bc 31068 lighttpd-mod-webdav_1.4.28-2+squeeze1_s390.deb Checksums-Sha256: 8092e298d2ad74140b9c323129494687a7e0d1ba3196481b06543adc5ba85f0f 296076 lighttpd_1.4.28-2+squeeze1_s390.deb 5d881dc62c4ab59ddb5b00fc0eb65e6fbfe69ff80440debd1eed1c6137d4a70e 18550 lighttpd-mod-mysql-vhost_1.4.28-2+squeeze1_s390.deb 7ca8beb9359e3013adb0ec01c0f173cb64df2f374747b82dcbcdd97fc655d973 20146 lighttpd-mod-trigger-b4-dl_1.4.28-2+squeeze1_s390.deb 3f2a840309075dda4287afe8ec50561e28f5a4317205a0037927dd57cc7dcd9f 23390 lighttpd-mod-cml_1.4.28-2+squeeze1_s390.deb 168348b7f28b79dd8cc04ef6ddf198ba173d8dc06bc8830b3baa28ef419c77c5 24606 lighttpd-mod-magnet_1.4.28-2+squeeze1_s390.deb 0a1becbf9c2d77861642e055e84c5f89373bcaef97520b238293412b6bf463f1 31068 lighttpd-mod-webdav_1.4.28-2+squeeze1_s390.deb Files: 0a7a7343d6f517d037c295896e653c69 296076 httpd optional lighttpd_1.4.28-2+squeeze1_s390.deb 4169d75663e81c5b4a3928ae0f1a99a5 18550 httpd optional lighttpd-mod-mysql-vhost_1.4.28-2+squeeze1_s390.deb 616a045f0c40ad39092533500d62cdcd 20146 httpd optional lighttpd-mod-trigger-b4-dl_1.4.28-2+squeeze1_s390.deb cd9134ad9149baf85789f5899e7c8ba6 23390 httpd optional lighttpd-mod-cml_1.4.28-2+squeeze1_s390.deb da640ae065137a3002a7a52e73c0537a 24606 httpd optional lighttpd-mod-magnet_1.4.28-2+squeeze1_s390.deb 59ac95abfd1690ac73d720088ec9ca41 31068 httpd optional lighttpd-mod-webdav_1.4.28-2+squeeze1_s390.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iQIcBAEBCAAGBQJO8P9IAAoJELWkVFx3JxH3xSQP/0Jx0igbxpfbL1GAlDdC2YML Eq37UcdITpWV/SksBiDCLuR1qnm1DbbMNJ86bXknFWny7KvtcGIHT6BissvL6miw IYb2R5/94UUJO1O/TuF+5Ei0Il8jeORGhkQdrNSLUOP6X5xJku41oaK1g+RGbueu CfbKcYzPipa7o4nwWYK+z74vIK6mnWpCbmz+q68Cd/BhSXXNFf4gz4seIRYYc1BL QK+42I2KyPxFyXJQJKt7hySg+BFZ4kZQJX4Ec5SpCFJ5j46iTLpjeamtYPwEb2+W /py1iCgbfMpmaR48e34xig1nqYh+GLGg0EC62Xf4fPupmTlBdeG0AVnZJ6X7K/sv DPEU48TvtAhwfw2aYRMNdVXXfki20HwKtpGKskQLri8h9f9DcBU4NfeqlIwpOH22 pmxcbjN0L2rj/MxPZbYOeiNqZpJt5G8q2H5+VAckvbVS4umrjNIywrXP7xzFDNGJ 4itGgh2ms4XzEyEcOMqe+TAAVE+CyEFnw63bjWrPAuT1oERIRWtld1LzjcYJ8ZHa RrDnLFaflHJi/JUatHv+pgTYRUyTnGp5jmgG47PHTGxR2zaJZjpvu+YepXHN+8on UtN8IinJHwEw4c6FRDC7RVIAcq+X/2gSYhioAls/gzzsQakwul4f3OnFZQsm0ulF ReSlkbgRh1ZX4Iwpb3uR =4+J+ -----END PGP SIGNATURE-----