-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Format: 1.8 Date: Mon, 05 Oct 2009 19:07:08 +0200 Source: apache2 Binary: apache2.2-common apache2-mpm-worker apache2-mpm-prefork apache2-mpm-event apache2-utils apache2-suexec apache2-suexec-custom apache2 apache2-doc apache2-prefork-dev apache2-threaded-dev apache2-src apache2-dbg Architecture: sparc Version: 2.2.9-10+lenny5 Distribution: stable Urgency: low Maintainer: sparc Build Daemon (schroeder) Changed-By: Stefan Fritsch Description: apache2 - Apache HTTP Server metapackage apache2-dbg - Apache debugging symbols apache2-doc - Apache HTTP Server documentation apache2-mpm-event - Apache HTTP Server - event driven model apache2-mpm-prefork - Apache HTTP Server - traditional non-threaded model apache2-mpm-worker - Apache HTTP Server - high speed threaded model apache2-prefork-dev - Apache development headers - non-threaded MPM apache2-src - Apache source code apache2-suexec - Standard suexec program for Apache 2 mod_suexec apache2-suexec-custom - Configurable suexec program for Apache 2 mod_suexec apache2-threaded-dev - Apache development headers - threaded MPM apache2-utils - utility programs for webservers apache2.2-common - Apache HTTP Server common files Closes: 517089 524268 528951 537665 545951 Changes: apache2 (2.2.9-10+lenny5) stable; urgency=low . * Minor security fixes in mod_proxy_ftp (closes: #545951): - DoS by malicious ftp server (CVE-2009-3094) - missing input sanitization: a user could execute arbitrary ftp commands on the backend ftp server (CVE-2009-3095) * Fix segfault in legacy ap_r* API which is triggered more often since the fix for CVE-2009-1891 was applied (closes: #537665). * Take care to not override existing index.shtml files when upgrading from before 2.2.8-1 (closes: #517089). * mod_deflate: Fix invalid etag to be emitted for on-the-fly gzip content-encoding. This prevented apache from sending "304 NOT MODIFIED" responses for compressed content. * mod_rewrite: Fix "B" flag breakage (closes: #524268) * Properly declare that apache2-suexec* replace files in old versions of apache2.2-common (closes: #528951). * Remove other_vhosts_access.log on package purge. Checksums-Sha1: fd8767468f84358332f8c5349e266bd9fb5f72d7 781510 apache2.2-common_2.2.9-10+lenny5_sparc.deb 7f5f88b9cab7b5fb79cbd3bc3116515b058b7df4 240886 apache2-mpm-worker_2.2.9-10+lenny5_sparc.deb c48345013c56690f5445ba7a64c298a55865ceff 237048 apache2-mpm-prefork_2.2.9-10+lenny5_sparc.deb e29da9f25f52c89f15ca148918a1bf5230018f9b 241350 apache2-mpm-event_2.2.9-10+lenny5_sparc.deb 1446e88c3a57392b234dea82ed36a90af64eae89 146464 apache2-utils_2.2.9-10+lenny5_sparc.deb 62293a8966f7693d609e50e8efaf9b9ce373633e 82740 apache2-suexec_2.2.9-10+lenny5_sparc.deb 6735c9fea1b8ee13ebd812fa6daaa4c5348d2b56 84430 apache2-suexec-custom_2.2.9-10+lenny5_sparc.deb 4942873d84e939593731c4b67b14c8ac473aee1e 212666 apache2-prefork-dev_2.2.9-10+lenny5_sparc.deb 7e33229f018aee483107f403f190b0c3c7d4da03 213828 apache2-threaded-dev_2.2.9-10+lenny5_sparc.deb 9132e9ceab4674fa98038e954fd638b6fee1b27e 2226186 apache2-dbg_2.2.9-10+lenny5_sparc.deb Checksums-Sha256: 5f6764c82927edb01278765924755d1b92625cb93f44024725554db01b8dbc8b 781510 apache2.2-common_2.2.9-10+lenny5_sparc.deb 29837868c786e78ec91e1ff6fc41107e502016469c3ee694aae4e3b29a1cc1aa 240886 apache2-mpm-worker_2.2.9-10+lenny5_sparc.deb a479de4a06701752ee5421959ef4de77c3d158d2782e5189d90dde9f8a03bc44 237048 apache2-mpm-prefork_2.2.9-10+lenny5_sparc.deb a144a63018a1eee2f95010214f0cd426461860deba90cbbc07c9f65988995cdb 241350 apache2-mpm-event_2.2.9-10+lenny5_sparc.deb e3c4f9a503380d00092f400d6540ff42fbe0771a7565e0d57c74a3a10cabbe5f 146464 apache2-utils_2.2.9-10+lenny5_sparc.deb bb610b366391b28e42377b97fd35da9b553d3eddad4dab42ac05c1e4a6c76bac 82740 apache2-suexec_2.2.9-10+lenny5_sparc.deb 794a5dbd02133e5b64c359bb0d6f9ce02138bdc1b0fae96996545e98503aabd5 84430 apache2-suexec-custom_2.2.9-10+lenny5_sparc.deb d169751fad9fb9c2c912111cc0bfb6b0e99c49a76a7f4a5c0bd6a2800206b8a5 212666 apache2-prefork-dev_2.2.9-10+lenny5_sparc.deb ac34300e715a940649f04f7636116e5860a03fac23f44f23a48be1be3c40becb 213828 apache2-threaded-dev_2.2.9-10+lenny5_sparc.deb 3872cd7889965b633ab4cdc5d36bb3ec0ee5fa71a2689ca84689497b233ee6c1 2226186 apache2-dbg_2.2.9-10+lenny5_sparc.deb Files: 6fbeea95bc04aaa3df0f1d11e7cd394d 781510 web optional apache2.2-common_2.2.9-10+lenny5_sparc.deb d0db58f09f548d7fe3eb08ec8529e7f7 240886 web optional apache2-mpm-worker_2.2.9-10+lenny5_sparc.deb 1f4923f79edf5182afb11210b2c99c30 237048 web optional apache2-mpm-prefork_2.2.9-10+lenny5_sparc.deb 5112ddaa8a7d42f0fb081d8010477147 241350 web optional apache2-mpm-event_2.2.9-10+lenny5_sparc.deb 013c54bf00160a12e4b5f956453f4665 146464 web optional apache2-utils_2.2.9-10+lenny5_sparc.deb 464fc4d22221c36cbe5a3e513fef8d30 82740 web optional apache2-suexec_2.2.9-10+lenny5_sparc.deb e0698af4130f67eb836f1af7ec4c2922 84430 web extra apache2-suexec-custom_2.2.9-10+lenny5_sparc.deb ea4368208db2fcfa437efd4718c95946 212666 devel extra apache2-prefork-dev_2.2.9-10+lenny5_sparc.deb 21a7331de22ed2820c20cac7fdbf87a3 213828 devel extra apache2-threaded-dev_2.2.9-10+lenny5_sparc.deb fb37fd1a58e4538e9fc59ed76ef13d73 2226186 libdevel extra apache2-dbg_2.2.9-10+lenny5_sparc.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.9 (GNU/Linux) iEYEARECAAYFAkrZVSsACgkQmdOZoew2oYWqPQCeNYQMEtvurwMB4QtYaoD2va7E wAkAnjz/tFACytVjb6kEhtp7zh5r2VHA =DD2q -----END PGP SIGNATURE-----