-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Format: 1.8 Date: Mon, 05 Oct 2009 19:07:08 +0200 Source: apache2 Binary: apache2.2-common apache2-mpm-worker apache2-mpm-prefork apache2-mpm-event apache2-utils apache2-suexec apache2-suexec-custom apache2 apache2-doc apache2-prefork-dev apache2-threaded-dev apache2-src apache2-dbg Architecture: powerpc Version: 2.2.9-10+lenny5 Distribution: stable Urgency: low Maintainer: Debian Build Daemon Changed-By: Stefan Fritsch Description: apache2 - Apache HTTP Server metapackage apache2-dbg - Apache debugging symbols apache2-doc - Apache HTTP Server documentation apache2-mpm-event - Apache HTTP Server - event driven model apache2-mpm-prefork - Apache HTTP Server - traditional non-threaded model apache2-mpm-worker - Apache HTTP Server - high speed threaded model apache2-prefork-dev - Apache development headers - non-threaded MPM apache2-src - Apache source code apache2-suexec - Standard suexec program for Apache 2 mod_suexec apache2-suexec-custom - Configurable suexec program for Apache 2 mod_suexec apache2-threaded-dev - Apache development headers - threaded MPM apache2-utils - utility programs for webservers apache2.2-common - Apache HTTP Server common files Closes: 517089 524268 528951 537665 545951 Changes: apache2 (2.2.9-10+lenny5) stable; urgency=low . * Minor security fixes in mod_proxy_ftp (closes: #545951): - DoS by malicious ftp server (CVE-2009-3094) - missing input sanitization: a user could execute arbitrary ftp commands on the backend ftp server (CVE-2009-3095) * Fix segfault in legacy ap_r* API which is triggered more often since the fix for CVE-2009-1891 was applied (closes: #537665). * Take care to not override existing index.shtml files when upgrading from before 2.2.8-1 (closes: #517089). * mod_deflate: Fix invalid etag to be emitted for on-the-fly gzip content-encoding. This prevented apache from sending "304 NOT MODIFIED" responses for compressed content. * mod_rewrite: Fix "B" flag breakage (closes: #524268) * Properly declare that apache2-suexec* replace files in old versions of apache2.2-common (closes: #528951). * Remove other_vhosts_access.log on package purge. Checksums-Sha1: e4004527962af81c9882b38fd5418a0448a94bc1 916272 apache2.2-common_2.2.9-10+lenny5_powerpc.deb 7303c5809d50c1b46297d5541d7febe26a77e51a 257440 apache2-mpm-worker_2.2.9-10+lenny5_powerpc.deb f29a661d3363bfc2dd02c3f9f824a2614fe1774f 253384 apache2-mpm-prefork_2.2.9-10+lenny5_powerpc.deb 0f00c8f6fb279e857dbd4f453dc0ef7b975c1f3f 258206 apache2-mpm-event_2.2.9-10+lenny5_powerpc.deb eddbdc6901889003090cd5c2e25108915a67e7be 160848 apache2-utils_2.2.9-10+lenny5_powerpc.deb 7c068d7c8ff586b7fc51fd62f25b14020590e0e0 82792 apache2-suexec_2.2.9-10+lenny5_powerpc.deb 70b65f61ef4a62a0425a687e42294a27a62c5c99 84446 apache2-suexec-custom_2.2.9-10+lenny5_powerpc.deb 5f3c881f364c598c62a1800537fcf85d9766e01c 208584 apache2-prefork-dev_2.2.9-10+lenny5_powerpc.deb bc89f67c93fad56f56fa22a77de358191f27ffc1 209618 apache2-threaded-dev_2.2.9-10+lenny5_powerpc.deb 313a742e66da5e4bf15282a5da4c16d6e5e3ce4c 2496048 apache2-dbg_2.2.9-10+lenny5_powerpc.deb Checksums-Sha256: 8cfc9e170a0116f3dbdd8c68e55c7ad30f688f073bfc87b71c7dc970507d1038 916272 apache2.2-common_2.2.9-10+lenny5_powerpc.deb 71f1b00f14ea3f69081f4c7d2f473761cf2affe1b4cbc24b83386a68d154958f 257440 apache2-mpm-worker_2.2.9-10+lenny5_powerpc.deb 977c1ddac49dfe2527d72ffec0a885a37be276e572373ae6f12b83d6627a04cd 253384 apache2-mpm-prefork_2.2.9-10+lenny5_powerpc.deb 889f90c4505a722f8a36b57db089ac531dc2e7985e34603aff8c982c3f6690bb 258206 apache2-mpm-event_2.2.9-10+lenny5_powerpc.deb 8dda691453df83250aacb9b377854a74252169f7258189f6d69cd35e08e638f9 160848 apache2-utils_2.2.9-10+lenny5_powerpc.deb 4441aaf9b97fd89286c821e57594da543731d31b782a6f3ae704c240fcfd4d96 82792 apache2-suexec_2.2.9-10+lenny5_powerpc.deb f4d3b6911b9a52a0626d0d5b036c794a8e85edbd32a74c08c1e43913a7138a83 84446 apache2-suexec-custom_2.2.9-10+lenny5_powerpc.deb ef3ff8e7490c9564531646d8bff58f1f87943009cf8d4eba4047858d1c28e92b 208584 apache2-prefork-dev_2.2.9-10+lenny5_powerpc.deb d8f46f2c252cfa6cd9078f08d303af062c7cb33305b64eb706c5512efbbebefe 209618 apache2-threaded-dev_2.2.9-10+lenny5_powerpc.deb ac1c95176170fe94ff16f805f6a99e0fa684a4f10efacab25d969c86de44b17a 2496048 apache2-dbg_2.2.9-10+lenny5_powerpc.deb Files: a3ad08ed693bf3f514a91ba410f25eea 916272 web optional apache2.2-common_2.2.9-10+lenny5_powerpc.deb b55b67df1ae077b25fdc97002542bb39 257440 web optional apache2-mpm-worker_2.2.9-10+lenny5_powerpc.deb b440a3c74d9a2875fc43f8f6c3ecb222 253384 web optional apache2-mpm-prefork_2.2.9-10+lenny5_powerpc.deb 07502882f1dde176e2ae3fd1b8187881 258206 web optional apache2-mpm-event_2.2.9-10+lenny5_powerpc.deb 4169df24c6ba07f9522b3ce08d9c2ab5 160848 web optional apache2-utils_2.2.9-10+lenny5_powerpc.deb 2681b9b5030f55b47fc449a603adb439 82792 web optional apache2-suexec_2.2.9-10+lenny5_powerpc.deb 888fecbd23cfe65174c0796ff1351eff 84446 web extra apache2-suexec-custom_2.2.9-10+lenny5_powerpc.deb 5bf7523d09ddbd02101070efcd5cd0a6 208584 devel extra apache2-prefork-dev_2.2.9-10+lenny5_powerpc.deb 4ed05a46325bfe6e0eb20e8f8de4a466 209618 devel extra apache2-threaded-dev_2.2.9-10+lenny5_powerpc.deb a5588a867cd82a7b5e60896b1950d012 2496048 libdevel extra apache2-dbg_2.2.9-10+lenny5_powerpc.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iEYEARECAAYFAkraBVMACgkQhbxvHru886yIUgCfY0u7osfJ61cCvWgozhEkiCTE KCoAniuEFOErbFiZuWwx31PLhO+F3ezH =0hkT -----END PGP SIGNATURE-----