-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Format: 1.8 Date: Mon, 05 Oct 2009 19:07:08 +0200 Source: apache2 Binary: apache2.2-common apache2-mpm-worker apache2-mpm-prefork apache2-mpm-event apache2-utils apache2-suexec apache2-suexec-custom apache2 apache2-doc apache2-prefork-dev apache2-threaded-dev apache2-src apache2-dbg Architecture: ia64 Version: 2.2.9-10+lenny5 Distribution: stable Urgency: low Maintainer: Debian/IA64 Build Daemon Changed-By: Stefan Fritsch Description: apache2 - Apache HTTP Server metapackage apache2-dbg - Apache debugging symbols apache2-doc - Apache HTTP Server documentation apache2-mpm-event - Apache HTTP Server - event driven model apache2-mpm-prefork - Apache HTTP Server - traditional non-threaded model apache2-mpm-worker - Apache HTTP Server - high speed threaded model apache2-prefork-dev - Apache development headers - non-threaded MPM apache2-src - Apache source code apache2-suexec - Standard suexec program for Apache 2 mod_suexec apache2-suexec-custom - Configurable suexec program for Apache 2 mod_suexec apache2-threaded-dev - Apache development headers - threaded MPM apache2-utils - utility programs for webservers apache2.2-common - Apache HTTP Server common files Closes: 517089 524268 528951 537665 545951 Changes: apache2 (2.2.9-10+lenny5) stable; urgency=low . * Minor security fixes in mod_proxy_ftp (closes: #545951): - DoS by malicious ftp server (CVE-2009-3094) - missing input sanitization: a user could execute arbitrary ftp commands on the backend ftp server (CVE-2009-3095) * Fix segfault in legacy ap_r* API which is triggered more often since the fix for CVE-2009-1891 was applied (closes: #537665). * Take care to not override existing index.shtml files when upgrading from before 2.2.8-1 (closes: #517089). * mod_deflate: Fix invalid etag to be emitted for on-the-fly gzip content-encoding. This prevented apache from sending "304 NOT MODIFIED" responses for compressed content. * mod_rewrite: Fix "B" flag breakage (closes: #524268) * Properly declare that apache2-suexec* replace files in old versions of apache2.2-common (closes: #528951). * Remove other_vhosts_access.log on package purge. Checksums-Sha1: bc6bcb05221838645acc5213e2e702eabb36d61b 1036364 apache2.2-common_2.2.9-10+lenny5_ia64.deb 03f220191566cee32480050879adca6967c6b72b 311564 apache2-mpm-worker_2.2.9-10+lenny5_ia64.deb 7ef8ed10e6ae346dbefef5e129ec749f86a8c332 304556 apache2-mpm-prefork_2.2.9-10+lenny5_ia64.deb 7ca04b6d338b9161b7b1948e2882570690d50e29 312498 apache2-mpm-event_2.2.9-10+lenny5_ia64.deb 7893003bf3f350c0546b2f5fd13f4a32c9949c36 162626 apache2-utils_2.2.9-10+lenny5_ia64.deb b7f798f7ee8066f0370735726a7913fd2f2111ab 83800 apache2-suexec_2.2.9-10+lenny5_ia64.deb 98ae65ec59c0d9aebdf7e3af70ed139d846b022b 85694 apache2-suexec-custom_2.2.9-10+lenny5_ia64.deb c2ce49eb57620ed1d6994c45c39bd89e85a9bb83 208552 apache2-prefork-dev_2.2.9-10+lenny5_ia64.deb d5350e3278747c9fca0239c50addc1416bb08a89 209586 apache2-threaded-dev_2.2.9-10+lenny5_ia64.deb 585974ad63d15cc04f1b8a919daa4ad47b7a05fa 2317384 apache2-dbg_2.2.9-10+lenny5_ia64.deb Checksums-Sha256: 12bf82bec8ac0e0f90823cd57417a57b3756021ce1eb1ff0a8953e2845226d17 1036364 apache2.2-common_2.2.9-10+lenny5_ia64.deb 4b54225e8f7c7a0a737630ff614d94cfcc6605ab0498f327fc569983b23059e7 311564 apache2-mpm-worker_2.2.9-10+lenny5_ia64.deb 5519b968a835fdc8d0ad699a078060d19d98fb0c21ed20a7659844e44b54c611 304556 apache2-mpm-prefork_2.2.9-10+lenny5_ia64.deb 3b92b14e9a6c99f2398b4e3e65a147ae545afee1ee7feb6f5fe8a6f1fa40df62 312498 apache2-mpm-event_2.2.9-10+lenny5_ia64.deb 33156a0ccbb60d341df8158bfa05d3f1cbbfb9a8475b07ed846531aca2ae01d9 162626 apache2-utils_2.2.9-10+lenny5_ia64.deb 4da58586bf6690921c7e77a6bc3700ff58ccba8e667e21aa8e3e8f82264eb525 83800 apache2-suexec_2.2.9-10+lenny5_ia64.deb a1258a98330edacee85027d4baa4278190fb591661649c4dc509f92ec9a1ed45 85694 apache2-suexec-custom_2.2.9-10+lenny5_ia64.deb 9d416f5220bca838819826c8101c520fef4cf34c4346c965353f7842a7b5b82d 208552 apache2-prefork-dev_2.2.9-10+lenny5_ia64.deb 118c3e5ce7071cada18f235c480a6c02e8caf6a855cf1071d06787237c76db5c 209586 apache2-threaded-dev_2.2.9-10+lenny5_ia64.deb 18d7f0e5e5f30b2d0564b5f2b2826f05b6726a4fac6468d63d85c471953b194f 2317384 apache2-dbg_2.2.9-10+lenny5_ia64.deb Files: 247713c5a1c40a1eaab3ad61d312f98e 1036364 web optional apache2.2-common_2.2.9-10+lenny5_ia64.deb d3aef33c13e72d04e8d8b99fc68188eb 311564 web optional apache2-mpm-worker_2.2.9-10+lenny5_ia64.deb 3e72f99d6ccf726e8c162fb4d1207689 304556 web optional apache2-mpm-prefork_2.2.9-10+lenny5_ia64.deb f8186b6f2f85863eb8b904dd8e4e297b 312498 web optional apache2-mpm-event_2.2.9-10+lenny5_ia64.deb acda9d4964610f00933c901dc9ff6bb7 162626 web optional apache2-utils_2.2.9-10+lenny5_ia64.deb cf910c9db1b3b7495c75aa7971bdb38f 83800 web optional apache2-suexec_2.2.9-10+lenny5_ia64.deb 9d16ca12e3846ee16cb09cdf66443b0a 85694 web extra apache2-suexec-custom_2.2.9-10+lenny5_ia64.deb ba761ab86f1941030420369091774cd8 208552 devel extra apache2-prefork-dev_2.2.9-10+lenny5_ia64.deb 51ec8b350cb7f5aff699586e5033b6ab 209586 devel extra apache2-threaded-dev_2.2.9-10+lenny5_ia64.deb 00fac2d8d8cc9351603c5206a34aac3b 2317384 libdevel extra apache2-dbg_2.2.9-10+lenny5_ia64.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.9 (GNU/Linux) iD8DBQFK3vGjzN/kmwoKyScRApOzAJ4xqGgIntJA7hVXY/mw6DtvcjiPoQCeObF2 hzWPrQCsMlfwWX1rX0HzMk8= =01v/ -----END PGP SIGNATURE-----