-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Format: 1.7 Date: Wed, 03 Jun 2009 23:12:43 +0200 Source: apr-util Binary: libaprutil1 libaprutil1-dbg libaprutil1-dev Architecture: amd64 Version: 1.2.7+dfsg-2+etch2 Distribution: oldstable-security Urgency: high Maintainer: Debian amd64 Build Daemon Changed-By: Stefan Fritsch Description: libaprutil1 - The Apache Portable Runtime Utility Library libaprutil1-dbg - The Apache Portable Runtime Utility Library - Development Headers libaprutil1-dev - The Apache Portable Runtime Utility Library - Development Headers Changes: apr-util (1.2.7+dfsg-2+etch2) oldstable-security; urgency=high . * CVE-2009-0023: Fix underflow in apr_strmatch_precompile() which causes remotely exploitable DoS vulnerabilities in mod_dav_svn and libapreq2. * Fix DoS vulnerability (memory consumption) in handling of internal xml entities. Files: 4fc0d12955c259cf26aab065b174ccf3 72828 libs optional libaprutil1_1.2.7+dfsg-2+etch2_amd64.deb 6097da9f80f44b379f1b1d46aa13867a 124516 libdevel optional libaprutil1-dev_1.2.7+dfsg-2+etch2_amd64.deb fec6f28c19ad170d97e431a8657d6d3b 127854 libdevel optional libaprutil1-dbg_1.2.7+dfsg-2+etch2_amd64.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.9 (GNU/Linux) iD8DBQFKJvEPbxelr8HyTqQRAsu4AJ0XJwXJ1IpDT7RXNBu25cW0F/EYgwCgp6v/ xhnKkt7dUKBhF8dJJ6ZtJhw= =QiQ+ -----END PGP SIGNATURE-----