-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Format: 1.7 Date: Wed, 14 Mar 2007 09:39:56 +0100 Source: php5 Binary: php5-gd php5-ldap php5 php5-xmlrpc php5-pspell libapache2-mod-php5 php5-xsl php5-cgi php-pear php5-tidy php5-pgsql php5-cli php5-recode php5-mhash php5-sybase php5-curl php5-odbc php5-mcrypt php5-mysql php5-common php5-imap php5-snmp php5-dev php5-sqlite libapache-mod-php5 php5-interbase Architecture: source i386 all Version: 5.2.0-8+etch1~bpo.1 Distribution: sarge-backports Urgency: high Maintainer: Debian PHP Maintainers Changed-By: Jan Wagner Description: libapache-mod-php5 - server-side, HTML-embedded scripting language (apache 1.3 module) libapache2-mod-php5 - server-side, HTML-embedded scripting language (apache 2 module) php-pear - PEAR - PHP Extension and Application Repository php5 - server-side, HTML-embedded scripting language (meta-package) php5-cgi - server-side, HTML-embedded scripting language (CGI binary) php5-cli - command-line interpreter for the php5 scripting language php5-common - Common files for packages built from the php5 source php5-curl - CURL module for php5 php5-dev - Files for PHP5 module development php5-gd - GD module for php5 php5-imap - IMAP module for php5 php5-interbase - interbase/firebird module for php5 php5-ldap - LDAP module for php5 php5-mcrypt - MCrypt module for php5 php5-mhash - MHASH module for php5 php5-mysql - MySQL module for php5 php5-odbc - ODBC module for php5 php5-pgsql - PostgreSQL module for php5 php5-pspell - pspell module for php5 php5-recode - recode module for php5 php5-snmp - SNMP module for php5 php5-sqlite - SQLite module for php5 php5-sybase - Sybase / MS SQL Server module for php5 php5-tidy - tidy module for php5 php5-xmlrpc - XML-RPC module for php5 php5-xsl - XSL module for php5 Changes: php5 (5.2.0-8+etch1~bpo.1) sarge-backports; urgency=low . * rebuild for sarge * Removed libcurl3-openssl-dev and libpq-dev from build-dependencies. * changed depencies for libapache2-mod-php5 to apache2-common * changed build depency from libsnmp9-dev to libsnmp5-dev * removed build depency for libmysqlclient15-dev and linked against libmysqlclient12-dev * changed build depency from libapr1-dev to libapr0-dev * changed build depency from libdb4.4-dev to libdb4.2-dev * added build depency for libsqlite3-dev * set build depency version for firebird2-dev to (>=1.5.3.4870-1) * disabled LFSs, caused segfaults on sarge: - modified rules - modified 053-extension_api.patch and 006-debian_quirks.patch - removed 019-z_off_t_as_long.patch * leave a hint in README.Debian of php5-common about mysql . php5 (5.2.0-8+etch1) testing-proposed-updates; urgency=high . [ sean finney ] * Rebuild of 5.2.0-10 targeted at etch. * The following security issues are addressed with this update: - CVE-2007-0906: Multiple buffer overflows in various code: * session (116-CVE-2007-0906_session.patch) * streams (116-CVE-2007-0906_streams.patch) * imap (116-CVE-2007-0906_imap.patch) * str_replace: (116-CVE-2007-0906_string.patch) * interbase: (116-CVE-2007-0906_interbase.patch) * zip: (116-CVE-2007-0906_zip.patch) * the sqlite and mail related vulnerabilities in this CVE do not affect the php5 source packages. - CVE-2007-0907: sapi_header_op buffer underflow (116-CVE-2007-0907.patch) - CVE-2007-0908: wddx information disclosure (116-CVE-2007-0908.patch) - CVE-2007-0909: More buffer overflows: * the odbc_result_all function (116-CVE-2007-0909_odbc.patch) * various formatted print functions (116-CVE-2007-0909_print.patch) - CVE-2007-0910: Clobbering of super-globals (116-CVE-2007-0910.patch) - CVE-2007-0988: 64bit unserialize DoS (116-CVE-2007-0988.patch) * The package maintainers would like to thank Joe Orton from redhat and Martin Pitt from ubuntu for their help in preparation of this update. * backport upstream fix for AUTH PLAIN support in imap extension Files: 06605fa55d181985f9826ab168f63269 1993 web optional php5_5.2.0-8+etch1~bpo.1.dsc 52d7e8b3d8d7573e75c97340f131f988 8583491 web optional php5_5.2.0.orig.tar.gz 58f855357e34f35886151b022c9c4d08 83496 web optional php5_5.2.0-8+etch1~bpo.1.diff.gz 58e06a24f0827827b135b1ba63b0a1a5 214102 web optional php5-common_5.2.0-8+etch1~bpo.1_i386.deb d1961a8e15e4a2ae6dc913485b0755a3 2405218 web optional libapache-mod-php5_5.2.0-8+etch1~bpo.1_i386.deb e6c3301d3bebc534e38b4e0e721f640d 2405578 web optional libapache2-mod-php5_5.2.0-8+etch1~bpo.1_i386.deb 401cb326d0be31b008be076004525bb7 4743990 web optional php5-cgi_5.2.0-8+etch1~bpo.1_i386.deb 673563d75a6e6cb634f8d7b0683c57e9 2389064 web optional php5-cli_5.2.0-8+etch1~bpo.1_i386.deb 33ef15fcebcc2831f23326cdfabd16e3 342052 devel optional php5-dev_5.2.0-8+etch1~bpo.1_i386.deb 6bf1cb95aab685326279965600189882 24200 web optional php5-curl_5.2.0-8+etch1~bpo.1_i386.deb 094c5c6c60deb3a9a5086e6af23c954b 32978 web optional php5-gd_5.2.0-8+etch1~bpo.1_i386.deb 4ad9e9ef1b5871dc6ca53fbf89ec31e5 35310 web optional php5-imap_5.2.0-8+etch1~bpo.1_i386.deb 3765060281dca08be868b6eff4e576a8 43598 web optional php5-interbase_5.2.0-8+etch1~bpo.1_i386.deb 2d65d1bfbf3bdf4b08ee03fe881077b7 17202 web optional php5-ldap_5.2.0-8+etch1~bpo.1_i386.deb 4a7d9649c4031f78450099cbbc7b3d63 13030 web optional php5-mcrypt_5.2.0-8+etch1~bpo.1_i386.deb 8f107cf923c703f0dcd8631f5093fcb5 5256 web optional php5-mhash_5.2.0-8+etch1~bpo.1_i386.deb 726e82daeebdbada38e4ba0621badf69 27168 web optional php5-mysql_5.2.0-8+etch1~bpo.1_i386.deb cf8502e602a2eebc08ce9bcca1814fb4 33542 web optional php5-odbc_5.2.0-8+etch1~bpo.1_i386.deb 8d5aee23cc25389dece39b87d66bb354 48972 web optional php5-pgsql_5.2.0-8+etch1~bpo.1_i386.deb 7e8796153f8e5bf59f62e1c3a1aed723 8652 web optional php5-pspell_5.2.0-8+etch1~bpo.1_i386.deb 03b2ff4f4a9efaaf47c0a3ba6148de3d 4922 web optional php5-recode_5.2.0-8+etch1~bpo.1_i386.deb 1966124657f68d75101bddb7197f7af4 11402 web optional php5-snmp_5.2.0-8+etch1~bpo.1_i386.deb 93ccb931e5da90e540ae220162cd6206 34684 web optional php5-sqlite_5.2.0-8+etch1~bpo.1_i386.deb f7d3d8ae134e61fbc83c2bd6a9fa562c 18676 web optional php5-sybase_5.2.0-8+etch1~bpo.1_i386.deb bb0bcd59f86103b511cad13f20f095f3 16920 web optional php5-tidy_5.2.0-8+etch1~bpo.1_i386.deb d34ecd11130fb12ac656db8e329893d4 36460 web optional php5-xmlrpc_5.2.0-8+etch1~bpo.1_i386.deb ed780c8848c64adb0bb72bf25e5b7ab7 12522 web optional php5-xsl_5.2.0-8+etch1~bpo.1_i386.deb 68300d5c63207b0e7657933687ed85c1 1048 web optional php5_5.2.0-8+etch1~bpo.1_all.deb 36e2605d1e2c798fc9b5fa56ee8f8d8d 307016 web optional php-pear_5.2.0-8+etch1~bpo.1_all.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.6 (GNU/Linux) iD8DBQFF+RAI9u6Dud+QFyQRAm26AKC6Ipslalm0StZAvnuD5X+jVk/8dwCdFCHc 6Tl+yI5PfQVP0+c26bygFYA= =BqX4 -----END PGP SIGNATURE-----