-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Format: 1.8 Date: Mon, 05 Oct 2009 19:07:08 +0200 Source: apache2 Binary: apache2.2-common apache2-mpm-worker apache2-mpm-prefork apache2-mpm-event apache2-utils apache2-suexec apache2-suexec-custom apache2 apache2-doc apache2-prefork-dev apache2-threaded-dev apache2-src apache2-dbg Architecture: armel Version: 2.2.9-10+lenny5 Distribution: stable Urgency: low Maintainer: armel Build Daemon (argento) Changed-By: Stefan Fritsch Description: apache2 - Apache HTTP Server metapackage apache2-dbg - Apache debugging symbols apache2-doc - Apache HTTP Server documentation apache2-mpm-event - Apache HTTP Server - event driven model apache2-mpm-prefork - Apache HTTP Server - traditional non-threaded model apache2-mpm-worker - Apache HTTP Server - high speed threaded model apache2-prefork-dev - Apache development headers - non-threaded MPM apache2-src - Apache source code apache2-suexec - Standard suexec program for Apache 2 mod_suexec apache2-suexec-custom - Configurable suexec program for Apache 2 mod_suexec apache2-threaded-dev - Apache development headers - threaded MPM apache2-utils - utility programs for webservers apache2.2-common - Apache HTTP Server common files Closes: 517089 524268 528951 537665 545951 Changes: apache2 (2.2.9-10+lenny5) stable; urgency=low . * Minor security fixes in mod_proxy_ftp (closes: #545951): - DoS by malicious ftp server (CVE-2009-3094) - missing input sanitization: a user could execute arbitrary ftp commands on the backend ftp server (CVE-2009-3095) * Fix segfault in legacy ap_r* API which is triggered more often since the fix for CVE-2009-1891 was applied (closes: #537665). * Take care to not override existing index.shtml files when upgrading from before 2.2.8-1 (closes: #517089). * mod_deflate: Fix invalid etag to be emitted for on-the-fly gzip content-encoding. This prevented apache from sending "304 NOT MODIFIED" responses for compressed content. * mod_rewrite: Fix "B" flag breakage (closes: #524268) * Properly declare that apache2-suexec* replace files in old versions of apache2.2-common (closes: #528951). * Remove other_vhosts_access.log on package purge. Checksums-Sha1: 2f8e1b2c2eca9004cd87d2a9fecd44f88e907c80 802502 apache2.2-common_2.2.9-10+lenny5_armel.deb 782b661cf211757c05a0b247226f6b8bc28ab1a9 225958 apache2-mpm-worker_2.2.9-10+lenny5_armel.deb d030282a1d341001c8cc96dd501f5168d5d1c600 221780 apache2-mpm-prefork_2.2.9-10+lenny5_armel.deb d7059ca8b00ee723dd24e10c856e820309dcabfc 226242 apache2-mpm-event_2.2.9-10+lenny5_armel.deb 62fc685f3366c4dd691a917c5c65d59c6256fbc9 151096 apache2-utils_2.2.9-10+lenny5_armel.deb ff63b132c7908f4cd96cf6b3f792f2ad02ca8179 82184 apache2-suexec_2.2.9-10+lenny5_armel.deb 59d46c994af356a20631841f6745feacddbf3414 83832 apache2-suexec-custom_2.2.9-10+lenny5_armel.deb 88d2d331b2a97fac86152f2e61ec4af2e95a3a52 212456 apache2-prefork-dev_2.2.9-10+lenny5_armel.deb d91282ce9374aa2fbdb69f2cdcc43842c1b401bb 213602 apache2-threaded-dev_2.2.9-10+lenny5_armel.deb 1c8a0cac952def4f02d78ef360d1200d34a51c33 2339602 apache2-dbg_2.2.9-10+lenny5_armel.deb Checksums-Sha256: 2dabd30f6669595f75ba75a92a226e2e033891b2ddebc3b19a86babc48f9a2b4 802502 apache2.2-common_2.2.9-10+lenny5_armel.deb 9640d025061f98d39562395a61423d4cd62bba963b47131f549f545e8fab49d8 225958 apache2-mpm-worker_2.2.9-10+lenny5_armel.deb f6aff7e057de2c4e2ec5b9d6c6747a411fce198552d7523a7e31eeb9d8825640 221780 apache2-mpm-prefork_2.2.9-10+lenny5_armel.deb 33e862fc52bc4665c01a56a2ec0f70e329c3a73e5ab01815f6295309c652e622 226242 apache2-mpm-event_2.2.9-10+lenny5_armel.deb 8f28f1d3a2a7a60a3e85e8f2f6d181e62f2f3fc129d6fd8434ca69abab56b805 151096 apache2-utils_2.2.9-10+lenny5_armel.deb 8cb222c89a73fae3fc0691cb02c226c0e7ac1d802787cef0e29776a3aef9b7d5 82184 apache2-suexec_2.2.9-10+lenny5_armel.deb a9d16bcddcf88f780b243a95e23303b9a13b89428d7ba6a51204a7c9a38f86f6 83832 apache2-suexec-custom_2.2.9-10+lenny5_armel.deb aa360afd83a581e2c7cef3890d63f81359bd6132d586fdd8e4a785340e056995 212456 apache2-prefork-dev_2.2.9-10+lenny5_armel.deb 647dc9e451a814c0f322c5d57ae2b670abc83b8b1bfe56f011a96abb557dfee5 213602 apache2-threaded-dev_2.2.9-10+lenny5_armel.deb de21c618e33cea54095fe2ee359e32d97da485f0f7d8102e6eeab70c4485d682 2339602 apache2-dbg_2.2.9-10+lenny5_armel.deb Files: 825e57f658ada2a6a21367823130737a 802502 web optional apache2.2-common_2.2.9-10+lenny5_armel.deb 49c55dd6224234ba37b44ee42dce5a18 225958 web optional apache2-mpm-worker_2.2.9-10+lenny5_armel.deb 8bf8e1982c9e5a420d901583ae47c847 221780 web optional apache2-mpm-prefork_2.2.9-10+lenny5_armel.deb bf2dc7da57cf38c0a7f6ca6762fac28e 226242 web optional apache2-mpm-event_2.2.9-10+lenny5_armel.deb 5b98bb83572e4c203c1d6b523838eca9 151096 web optional apache2-utils_2.2.9-10+lenny5_armel.deb 1ad6dbef06d60d843acdfc1b978de8dd 82184 web optional apache2-suexec_2.2.9-10+lenny5_armel.deb b6981066664c2f67a21ec250b0cd0fd7 83832 web extra apache2-suexec-custom_2.2.9-10+lenny5_armel.deb 07f1325f955efc7975b464a567585e3f 212456 devel extra apache2-prefork-dev_2.2.9-10+lenny5_armel.deb b515e46dd8d90139ffc8801b87b8066d 213602 devel extra apache2-threaded-dev_2.2.9-10+lenny5_armel.deb b61e00d91e9bf1d51fa6035d4cf62470 2339602 libdevel extra apache2-dbg_2.2.9-10+lenny5_armel.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.9 (GNU/Linux) iD8DBQFK2V8ZibPvMsrqrwMRAlskAJ9BgN81AixH0kF3OAFlPbGKrLP2FQCgr5sI 6DAgixGf/4R89eItBgc6zt4= =MCdd -----END PGP SIGNATURE-----