-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Format: 1.8 Date: Mon, 05 Oct 2009 19:07:08 +0200 Source: apache2 Binary: apache2.2-common apache2-mpm-worker apache2-mpm-prefork apache2-mpm-event apache2-utils apache2-suexec apache2-suexec-custom apache2 apache2-doc apache2-prefork-dev apache2-threaded-dev apache2-src apache2-dbg Architecture: mips Version: 2.2.9-10+lenny5 Distribution: stable Urgency: low Maintainer: Debian Build Daemon Changed-By: Stefan Fritsch Description: apache2 - Apache HTTP Server metapackage apache2-dbg - Apache debugging symbols apache2-doc - Apache HTTP Server documentation apache2-mpm-event - Apache HTTP Server - event driven model apache2-mpm-prefork - Apache HTTP Server - traditional non-threaded model apache2-mpm-worker - Apache HTTP Server - high speed threaded model apache2-prefork-dev - Apache development headers - non-threaded MPM apache2-src - Apache source code apache2-suexec - Standard suexec program for Apache 2 mod_suexec apache2-suexec-custom - Configurable suexec program for Apache 2 mod_suexec apache2-threaded-dev - Apache development headers - threaded MPM apache2-utils - utility programs for webservers apache2.2-common - Apache HTTP Server common files Closes: 517089 524268 528951 537665 545951 Changes: apache2 (2.2.9-10+lenny5) stable; urgency=low . * Minor security fixes in mod_proxy_ftp (closes: #545951): - DoS by malicious ftp server (CVE-2009-3094) - missing input sanitization: a user could execute arbitrary ftp commands on the backend ftp server (CVE-2009-3095) * Fix segfault in legacy ap_r* API which is triggered more often since the fix for CVE-2009-1891 was applied (closes: #537665). * Take care to not override existing index.shtml files when upgrading from before 2.2.8-1 (closes: #517089). * mod_deflate: Fix invalid etag to be emitted for on-the-fly gzip content-encoding. This prevented apache from sending "304 NOT MODIFIED" responses for compressed content. * mod_rewrite: Fix "B" flag breakage (closes: #524268) * Properly declare that apache2-suexec* replace files in old versions of apache2.2-common (closes: #528951). * Remove other_vhosts_access.log on package purge. Checksums-Sha1: f2b0acb1f7b762e0bb18d6ac5444fb2a3f83a2d5 780162 apache2.2-common_2.2.9-10+lenny5_mips.deb 79f7193b2a43334a3ab020be6b8b42a78afd7cf5 233286 apache2-mpm-worker_2.2.9-10+lenny5_mips.deb c748f3313fb73d0f798336d5015dda2def7e22bd 229356 apache2-mpm-prefork_2.2.9-10+lenny5_mips.deb 9519e3e449552ebc6517b0a549cacd64fee83a71 233846 apache2-mpm-event_2.2.9-10+lenny5_mips.deb 81935657361730819ec673ef321ecb53c307fe78 149600 apache2-utils_2.2.9-10+lenny5_mips.deb 39091e438dc0ad942b506983e1167e9b70ca4d8a 81954 apache2-suexec_2.2.9-10+lenny5_mips.deb ab19b2d2bb438324afa02920e1dc258bb27c962e 83574 apache2-suexec-custom_2.2.9-10+lenny5_mips.deb 2b2733d95d9f639a842bb3406b9b078b441545cd 208570 apache2-prefork-dev_2.2.9-10+lenny5_mips.deb 5cce866b560c2e12faaa53d861a81a0ee667015c 209598 apache2-threaded-dev_2.2.9-10+lenny5_mips.deb a2fe71419018d8c9870ae864e6ce82d558e7972d 2463898 apache2-dbg_2.2.9-10+lenny5_mips.deb Checksums-Sha256: 145f8bd40fa98a3aebdbbb90adc2c9fbb3738c1ad79cfbb44211ee11b655a6d2 780162 apache2.2-common_2.2.9-10+lenny5_mips.deb 330246b749c782590bb76a4b78f5855683cf16e7d8c0c9934f2260e8dac48eb8 233286 apache2-mpm-worker_2.2.9-10+lenny5_mips.deb b8f2551555a380fa5b0df4fe59bbfe21bb9cd388baaaf634a7569da4d0e23e3b 229356 apache2-mpm-prefork_2.2.9-10+lenny5_mips.deb 4ed55a3c084384dc270d6efc4c8931652cce74b545ee71a068459e3494753c7a 233846 apache2-mpm-event_2.2.9-10+lenny5_mips.deb a4ab1e743c656532376780d74f230f36aae2a3f731fcde27a2c282a471432b5f 149600 apache2-utils_2.2.9-10+lenny5_mips.deb 79e9d4ac9d9575e5489a4082d73003fcf6047f2b3b233469ac4e163424957375 81954 apache2-suexec_2.2.9-10+lenny5_mips.deb b38bffb701d4a57392386e5bc87e2088d61bc51aba707516169c5efd6d1ed599 83574 apache2-suexec-custom_2.2.9-10+lenny5_mips.deb f30c8eaa9ef318de9686b03f5e4cf2145f51efb316ef1f384bc70e27a876e66e 208570 apache2-prefork-dev_2.2.9-10+lenny5_mips.deb b1e25a88a082c1fb429abeb140f986de295cd5c7e9698c3ec753d71cfda5735c 209598 apache2-threaded-dev_2.2.9-10+lenny5_mips.deb 1d50ef9cb7fba4e0c667779fa66a31316f794952b15712a2a49dfd2d9dc0223d 2463898 apache2-dbg_2.2.9-10+lenny5_mips.deb Files: ddc07f6c4cebe28c083127d33ccf561f 780162 web optional apache2.2-common_2.2.9-10+lenny5_mips.deb ad2a4bc31022212ce87f8a63e816e4a7 233286 web optional apache2-mpm-worker_2.2.9-10+lenny5_mips.deb 78eedb46533effb49a5500b0a539c717 229356 web optional apache2-mpm-prefork_2.2.9-10+lenny5_mips.deb 6cd75194e5d7dafbe8d90cee53370331 233846 web optional apache2-mpm-event_2.2.9-10+lenny5_mips.deb d23a5278bef85937016d9f908bcabd77 149600 web optional apache2-utils_2.2.9-10+lenny5_mips.deb fe7f9a9fedd141d1d39a40d36444ccd1 81954 web optional apache2-suexec_2.2.9-10+lenny5_mips.deb 86b28ba724cba170f2225c7ab771975f 83574 web extra apache2-suexec-custom_2.2.9-10+lenny5_mips.deb 31b14729b86e22d42b36e237f1d3075a 208570 devel extra apache2-prefork-dev_2.2.9-10+lenny5_mips.deb a9f72440faf7586b475b3f2482eaa0cf 209598 devel extra apache2-threaded-dev_2.2.9-10+lenny5_mips.deb 34407ef4f49c41a94ebe8ed6516f02ad 2463898 libdevel extra apache2-dbg_2.2.9-10+lenny5_mips.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.9 (GNU/Linux) iEYEARECAAYFAkrZjbAACgkQKLKVw/RurbuJDwCbBpIDq742KhKRg1U3ca1R2kqL kFwAoJHhtKLpmJOp4tFedLRa2mOq7NDZ =dkch -----END PGP SIGNATURE-----