[ubuntu/raring-proposed] lighttpd 1.4.31-3ubuntu2 (Accepted)

Lorenzo De Liso blackz at ubuntu.com
Mon Mar 25 13:50:15 UTC 2013


lighttpd (1.4.31-3ubuntu2) raring; urgency=low

  * Import change from debian version 1.4.31-4:
    - CVE-2013-1427: Switch the socket path for PHP when using FASTCGI. /tmp
      is world-writable which may cause security implications if an attacker
      manages to control /tmp/php.socket before the web server (re-)starts.

Date: Mon, 25 Mar 2013 11:55:53 +0100
Changed-By: Lorenzo De Liso <blackz at ubuntu.com>
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
https://launchpad.net/ubuntu/raring/+source/lighttpd/1.4.31-3ubuntu2
-------------- next part --------------
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Format: 1.8
Date: Mon, 25 Mar 2013 11:55:53 +0100
Source: lighttpd
Binary: lighttpd lighttpd-doc lighttpd-mod-mysql-vhost lighttpd-mod-trigger-b4-dl lighttpd-mod-cml lighttpd-mod-magnet lighttpd-mod-webdav lighttpd-dev
Architecture: source
Version: 1.4.31-3ubuntu2
Distribution: raring
Urgency: low
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
Changed-By: Lorenzo De Liso <blackz at ubuntu.com>
Description: 
 lighttpd   - fast webserver with minimal memory footprint
 lighttpd-dev - Development files for lighttpd
 lighttpd-doc - documentation for lighttpd
 lighttpd-mod-cml - cache meta language module for lighttpd
 lighttpd-mod-magnet - control the request handling module for lighttpd
 lighttpd-mod-mysql-vhost - MySQL-based virtual host configuration for lighttpd
 lighttpd-mod-trigger-b4-dl - anti-deep-linking module for lighttpd
 lighttpd-mod-webdav - WebDAV module for lighttpd
Changes: 
 lighttpd (1.4.31-3ubuntu2) raring; urgency=low
 .
   * Import change from debian version 1.4.31-4:
     - CVE-2013-1427: Switch the socket path for PHP when using FASTCGI. /tmp
       is world-writable which may cause security implications if an attacker
       manages to control /tmp/php.socket before the web server (re-)starts.
Checksums-Sha1: 
 8e4790d951e79a5d19d79129283c723ec16eb6c8 2487 lighttpd_1.4.31-3ubuntu2.dsc
 6b3babc9df173cea5ae4756c2fd6b0e85e015f2a 840123 lighttpd_1.4.31.orig.tar.gz
 416035d76b6de0f560c8fff916e96e289719d9e7 34635 lighttpd_1.4.31-3ubuntu2.debian.tar.gz
Checksums-Sha256: 
 81a1d4d8de80e60511c42e34a8227315e89c3f3eb0fe4a4f31e51f41949f523b 2487 lighttpd_1.4.31-3ubuntu2.dsc
 848a15604bf358d9355bd7a48c01f448c286734dbb5f4dc1cd16acb8b05a9b52 840123 lighttpd_1.4.31.orig.tar.gz
 62e58c161efd3897769309dbd22e9c5dd703185147c201dd919bb8620aefefd0 34635 lighttpd_1.4.31-3ubuntu2.debian.tar.gz
Files: 
 692d0c73e0d2568967145119695e90e6 2487 httpd optional lighttpd_1.4.31-3ubuntu2.dsc
 7907b7167d639b8a8daab97e223249d5 840123 httpd optional lighttpd_1.4.31.orig.tar.gz
 ba3011e0e38062370c1eb38981a1b9d3 34635 httpd optional lighttpd_1.4.31-3ubuntu2.debian.tar.gz
Original-Maintainer: Debian lighttpd maintainers <pkg-lighttpd-maintainers at lists.alioth.debian.org>

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iQEcBAEBAgAGBQJRUC8CAAoJECG2nyCsu/UVhukH/R1aMXpuhEvTbSTaNJF4DmW+
CmKKAk6oekKNh/84DZghM2CR/n1lpAKahiBs4btAJ1Zi1rQ75QF/IidBRVBqYMVq
5Ghdb4OY4Pe2t9/ZQqMu6kn/WUo8aQ0r50e2+yz9sexIh5hZ1xtQ2QiUPgiy60sb
7tCa+6zfl3coOXNYZGIZPsSj7WJENQpwiAJ9H8O1Ujp8AATtZB7PDhvC0HPAuCho
OF6kSXLRLFGWvS0zrqT6+7qE4PXzhLa1mDMdVYn6RvnQ0zeOCkRTQu64NVfv4LBY
SricO2eR7DR9VWA32T+VFAhQm5O6tZ39OHy29AGah57sC+99mrw1Vq2CIcL2gZE=
=JPUb
-----END PGP SIGNATURE-----


More information about the Raring-changes mailing list