-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Format: 1.8 Date: Mon, 05 Oct 2009 19:07:08 +0200 Source: apache2 Binary: apache2.2-common apache2-mpm-worker apache2-mpm-prefork apache2-mpm-event apache2-utils apache2-suexec apache2-suexec-custom apache2 apache2-doc apache2-prefork-dev apache2-threaded-dev apache2-src apache2-dbg Architecture: mipsel Version: 2.2.9-10+lenny5 Distribution: stable Urgency: low Maintainer: mipsel Build Daemon (rem) Changed-By: Stefan Fritsch Description: apache2 - Apache HTTP Server metapackage apache2-dbg - Apache debugging symbols apache2-doc - Apache HTTP Server documentation apache2-mpm-event - Apache HTTP Server - event driven model apache2-mpm-prefork - Apache HTTP Server - traditional non-threaded model apache2-mpm-worker - Apache HTTP Server - high speed threaded model apache2-prefork-dev - Apache development headers - non-threaded MPM apache2-src - Apache source code apache2-suexec - Standard suexec program for Apache 2 mod_suexec apache2-suexec-custom - Configurable suexec program for Apache 2 mod_suexec apache2-threaded-dev - Apache development headers - threaded MPM apache2-utils - utility programs for webservers apache2.2-common - Apache HTTP Server common files Closes: 517089 524268 528951 537665 545951 Changes: apache2 (2.2.9-10+lenny5) stable; urgency=low . * Minor security fixes in mod_proxy_ftp (closes: #545951): - DoS by malicious ftp server (CVE-2009-3094) - missing input sanitization: a user could execute arbitrary ftp commands on the backend ftp server (CVE-2009-3095) * Fix segfault in legacy ap_r* API which is triggered more often since the fix for CVE-2009-1891 was applied (closes: #537665). * Take care to not override existing index.shtml files when upgrading from before 2.2.8-1 (closes: #517089). * mod_deflate: Fix invalid etag to be emitted for on-the-fly gzip content-encoding. This prevented apache from sending "304 NOT MODIFIED" responses for compressed content. * mod_rewrite: Fix "B" flag breakage (closes: #524268) * Properly declare that apache2-suexec* replace files in old versions of apache2.2-common (closes: #528951). * Remove other_vhosts_access.log on package purge. Checksums-Sha1: 1a71da600da4434009ad5d482db6a71dc3e12576 778730 apache2.2-common_2.2.9-10+lenny5_mipsel.deb 238fe79ca664c0050f21737e5213cf79b2d6e107 232016 apache2-mpm-worker_2.2.9-10+lenny5_mipsel.deb d1dc0961f5ad5a85cdde54299409487f18697db7 227978 apache2-mpm-prefork_2.2.9-10+lenny5_mipsel.deb 3ef3fd47e376f7539158cbab5eeb929b4edd585c 232678 apache2-mpm-event_2.2.9-10+lenny5_mipsel.deb a8a13bc7c11dec497633f75aca7318fa40c8e3f1 149906 apache2-utils_2.2.9-10+lenny5_mipsel.deb f243d83d9b02836398bd8ab07dacf469e72f4025 82012 apache2-suexec_2.2.9-10+lenny5_mipsel.deb 14af64ea91a0de395446b78f57a966cd4aebcee2 83594 apache2-suexec-custom_2.2.9-10+lenny5_mipsel.deb 092c90e4f1900f419c2b545ab810dfe957269c75 208582 apache2-prefork-dev_2.2.9-10+lenny5_mipsel.deb cfd676d8311cf7e59dafc71f4f42732ca1f208c7 209610 apache2-threaded-dev_2.2.9-10+lenny5_mipsel.deb 4027e536466b9d3b06265e03b854e5f85c7162f8 2419014 apache2-dbg_2.2.9-10+lenny5_mipsel.deb Checksums-Sha256: 9925f8af590ae630d221e5c7d0ea3dba9643e3fd245fb690c219a7d24749938a 778730 apache2.2-common_2.2.9-10+lenny5_mipsel.deb 2fbb2d05b5040e171e91a04adcf39be6e0ab6aa151db9c92200c12a4f820f501 232016 apache2-mpm-worker_2.2.9-10+lenny5_mipsel.deb a73a1b42e2111f75ca2e883c001ec4d3331a74235c1359b1149952d6282bb304 227978 apache2-mpm-prefork_2.2.9-10+lenny5_mipsel.deb 94747a80617611a5c410293a4c5018b8064764f10354e58356bb1828332e739e 232678 apache2-mpm-event_2.2.9-10+lenny5_mipsel.deb 61fa1b3d6aa045f1067d5a7c272d7238c9f4d811cd8d43c2163056e0b09c2fd2 149906 apache2-utils_2.2.9-10+lenny5_mipsel.deb ec9531ff03d92027839f7aec7f6ef92ff068af583ac83173dec77f455f048db3 82012 apache2-suexec_2.2.9-10+lenny5_mipsel.deb c9651f1d15f8b618017d305f6c17f354bd1dafc8218c38571a16a9fb2f59abf1 83594 apache2-suexec-custom_2.2.9-10+lenny5_mipsel.deb 283635e92c23b7175e48adcce6d3b9721c1812b793b6a103b6673fa3ae413c7c 208582 apache2-prefork-dev_2.2.9-10+lenny5_mipsel.deb 5159778068bee629ec0131762138d145d1397f2d7d05038f85e0559e47d81c88 209610 apache2-threaded-dev_2.2.9-10+lenny5_mipsel.deb 4080be382436ba6c0e48dd22ed5b4511e4eb0b91c3e90f8476ed90dd07bbc079 2419014 apache2-dbg_2.2.9-10+lenny5_mipsel.deb Files: eb2f6882655821d2d896622269eae87d 778730 web optional apache2.2-common_2.2.9-10+lenny5_mipsel.deb 74c81dd8c8fe1c2a9fff9924005e2308 232016 web optional apache2-mpm-worker_2.2.9-10+lenny5_mipsel.deb f1cf8dcc6e5b79dff963e2cdbbdf0cd5 227978 web optional apache2-mpm-prefork_2.2.9-10+lenny5_mipsel.deb 9a4aa237562c35c19f11431f9e070605 232678 web optional apache2-mpm-event_2.2.9-10+lenny5_mipsel.deb 4df1767637b3a35ccb930bbc98786105 149906 web optional apache2-utils_2.2.9-10+lenny5_mipsel.deb a72ba9fd6118d5bca3a2d90eda0f4cfe 82012 web optional apache2-suexec_2.2.9-10+lenny5_mipsel.deb f4aa0287dec91233dd41d65ed113c9f7 83594 web extra apache2-suexec-custom_2.2.9-10+lenny5_mipsel.deb b74b4caa21242ce14ff96e8bd7804d65 208582 devel extra apache2-prefork-dev_2.2.9-10+lenny5_mipsel.deb 0bc5c083a7396041609248e0a0553ced 209610 devel extra apache2-threaded-dev_2.2.9-10+lenny5_mipsel.deb 67e58a44d4e8af0aef376119f0dfddfc 2419014 libdevel extra apache2-dbg_2.2.9-10+lenny5_mipsel.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.9 (GNU/Linux) iEUEARECAAYFAkrZVS0ACgkQmdOZoew2oYU5sgCYmEEf57KLXUv+B1qv4FdawrNo PACeP68mOsvZCiRmhVVrnunQ/3tknmc= =HETI -----END PGP SIGNATURE-----