-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Format: 1.8 Date: Mon, 05 Oct 2009 19:07:08 +0200 Source: apache2 Binary: apache2.2-common apache2-mpm-worker apache2-mpm-prefork apache2-mpm-event apache2-utils apache2-suexec apache2-suexec-custom apache2 apache2-doc apache2-prefork-dev apache2-threaded-dev apache2-src apache2-dbg Architecture: s390 Version: 2.2.9-10+lenny5 Distribution: stable Urgency: low Maintainer: s390 Build Daemon Changed-By: Stefan Fritsch Description: apache2 - Apache HTTP Server metapackage apache2-dbg - Apache debugging symbols apache2-doc - Apache HTTP Server documentation apache2-mpm-event - Apache HTTP Server - event driven model apache2-mpm-prefork - Apache HTTP Server - traditional non-threaded model apache2-mpm-worker - Apache HTTP Server - high speed threaded model apache2-prefork-dev - Apache development headers - non-threaded MPM apache2-src - Apache source code apache2-suexec - Standard suexec program for Apache 2 mod_suexec apache2-suexec-custom - Configurable suexec program for Apache 2 mod_suexec apache2-threaded-dev - Apache development headers - threaded MPM apache2-utils - utility programs for webservers apache2.2-common - Apache HTTP Server common files Closes: 517089 524268 528951 537665 545951 Changes: apache2 (2.2.9-10+lenny5) stable; urgency=low . * Minor security fixes in mod_proxy_ftp (closes: #545951): - DoS by malicious ftp server (CVE-2009-3094) - missing input sanitization: a user could execute arbitrary ftp commands on the backend ftp server (CVE-2009-3095) * Fix segfault in legacy ap_r* API which is triggered more often since the fix for CVE-2009-1891 was applied (closes: #537665). * Take care to not override existing index.shtml files when upgrading from before 2.2.8-1 (closes: #517089). * mod_deflate: Fix invalid etag to be emitted for on-the-fly gzip content-encoding. This prevented apache from sending "304 NOT MODIFIED" responses for compressed content. * mod_rewrite: Fix "B" flag breakage (closes: #524268) * Properly declare that apache2-suexec* replace files in old versions of apache2.2-common (closes: #528951). * Remove other_vhosts_access.log on package purge. Checksums-Sha1: 6e273a82dda81a1d39a16938f73b78c44587583b 824282 apache2.2-common_2.2.9-10+lenny5_s390.deb 77602ca9056266925e8e4f676efaa9e9c9505d29 259832 apache2-mpm-worker_2.2.9-10+lenny5_s390.deb 0156727c3fb7efcb18ed2314ea1235d29a23e965 255850 apache2-mpm-prefork_2.2.9-10+lenny5_s390.deb cbfef720c50cc94b38a65d21da4ba8fff2c8cc42 260474 apache2-mpm-event_2.2.9-10+lenny5_s390.deb 936b98268bb2c9c692781f2685a71863d892812b 150790 apache2-utils_2.2.9-10+lenny5_s390.deb 15f46b4c4638ae6fcb95c1ca2649faa1aee72004 82424 apache2-suexec_2.2.9-10+lenny5_s390.deb dd58c0f81fcf961510f2a847590b448a0db183a7 84186 apache2-suexec-custom_2.2.9-10+lenny5_s390.deb 9ae68080caeda50685244fe362a7c59fb99db64f 208572 apache2-prefork-dev_2.2.9-10+lenny5_s390.deb b40e6dc3f9736fc6b4b0b0cd4cbe5299c26955f6 209600 apache2-threaded-dev_2.2.9-10+lenny5_s390.deb cda08c885ec108500d8ae436d15db7c1db05b432 2408656 apache2-dbg_2.2.9-10+lenny5_s390.deb Checksums-Sha256: a25b2d8dcd5a6789a2dac9ec2ccbe482363f44b92bde82e931ffbbb4c2d2fd05 824282 apache2.2-common_2.2.9-10+lenny5_s390.deb acd89bb0ba53cd3acc8ccc90a78c7231865e9f97981e11b2038565334a3ed81b 259832 apache2-mpm-worker_2.2.9-10+lenny5_s390.deb 40f16980c3e030a99244770df5b1a865dc10e9249b796683a89561762dde4355 255850 apache2-mpm-prefork_2.2.9-10+lenny5_s390.deb 20b25ac7964b55436f9f4cad626f0d4e0b0edc54d0514bd1229c3bbc17539444 260474 apache2-mpm-event_2.2.9-10+lenny5_s390.deb f93519e1545f45a26d40381fd9f8f773275210178418a8d5b9a57072131465d2 150790 apache2-utils_2.2.9-10+lenny5_s390.deb 01f17367310814270c5869bbe996ded5cb903379c173ba19b38684fa27e4b8e8 82424 apache2-suexec_2.2.9-10+lenny5_s390.deb a904e6d3be78d17f6b9e0a73a65862f84283460c23fda44f9f083d7b2bb40f94 84186 apache2-suexec-custom_2.2.9-10+lenny5_s390.deb 634758126b92d64dfde3d37b8f5c708696b895ac9fd9169204eee444fc37ac6d 208572 apache2-prefork-dev_2.2.9-10+lenny5_s390.deb efa7c2adc95076cccc6faff0e1e8a1c836dfa460a1023641a1f1df67d9f30dae 209600 apache2-threaded-dev_2.2.9-10+lenny5_s390.deb 570ad9a12efaaf003799044e0c8aaee058d95ec94165fbf983671f58631f71b7 2408656 apache2-dbg_2.2.9-10+lenny5_s390.deb Files: 5c1bbca08daba912d99f2fad53bc4a37 824282 web optional apache2.2-common_2.2.9-10+lenny5_s390.deb 1ff1001a4cc5e98134f3347cd116ea7e 259832 web optional apache2-mpm-worker_2.2.9-10+lenny5_s390.deb 8ac8b6ec352fee709e376bf38f012a90 255850 web optional apache2-mpm-prefork_2.2.9-10+lenny5_s390.deb dc767bb6f7904fdcfa338469187db25b 260474 web optional apache2-mpm-event_2.2.9-10+lenny5_s390.deb 796377b780173e2e152248f79a2bd14b 150790 web optional apache2-utils_2.2.9-10+lenny5_s390.deb 513807c6559c2bf86d4f91a85e9e7261 82424 web optional apache2-suexec_2.2.9-10+lenny5_s390.deb d74e56e92405e5e3a857d18e1eea29b7 84186 web extra apache2-suexec-custom_2.2.9-10+lenny5_s390.deb c713a538b5f1c2cdd49de0b4c179192d 208572 devel extra apache2-prefork-dev_2.2.9-10+lenny5_s390.deb 701a1a8ae4cdceb837bfdebd30cb62cf 209600 devel extra apache2-threaded-dev_2.2.9-10+lenny5_s390.deb a116c0ef08b88f601ad1e41a9168bb7d 2408656 libdevel extra apache2-dbg_2.2.9-10+lenny5_s390.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.9 (GNU/Linux) iEYEARECAAYFAkreDmEACgkQLkAIIn9ODhFEPwCgkA3D7zCMzpzORPsc2tSMn1mt F3EAoNJhLs5Wt4axlRkzT51Uwpa/jJPL =TSIi -----END PGP SIGNATURE-----