-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 3.0 (quilt) Source: squid3 Binary: squid3, squid3-dbg, squid3-common, squidclient, squid-cgi, squid-purge Architecture: any all Version: 3.4.8-1 Maintainer: Luigi Gangitano <[email protected]> Homepage: http://www.squid-cache.org Standards-Version: 3.9.6 Vcs-Git: git://git.debian.org/git/pkg-squid/pkg-squid3.git/ Build-Depends: libldap2-dev, libpam0g-dev, libdb-dev, cdbs, libsasl2-dev, debhelper (>= 5), libcppunit-dev, libkrb5-dev, comerr-dev, libcap2-dev [linux-any], libecap2-dev (= 0.2.0-1), libexpat1-dev, libxml2-dev, autotools-dev, libltdl-dev, dpkg-dev (>= 1.16.1~), pkg-config, libnetfilter-conntrack-dev [linux-any], nettle-dev Package-List: squid-cgi deb web optional arch=any squid-purge deb web optional arch=any squid3 deb web optional arch=any squid3-common deb web optional arch=all squid3-dbg deb debug extra arch=any squidclient deb web optional arch=any Checksums-Sha1: 4a5fec155d91f3d9eedf16ea474970e293699cc9 3042254 squid3_3.4.8.orig.tar.bz2 eb20e5fcf3d365455b80bcf3e5aa901e8d292042 22864 squid3_3.4.8-1.debian.tar.xz Checksums-Sha256: d0534c1cb6ad7de9e2c9f3fc192df92d4c454e3e4c5e00c5086997709153c455 3042254 squid3_3.4.8.orig.tar.bz2 7da43831936b9ab317555530276bd27dc0b86a1d1e26c2eeb6b209323fe6a3e3 22864 squid3_3.4.8-1.debian.tar.xz Files: 094bd5f974d13485d51d02e93ec6027b 3042254 squid3_3.4.8.orig.tar.bz2 f348f67256e38ebdf379d8dbeaba95be 22864 squid3_3.4.8-1.debian.tar.xz -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIcBAEBCgAGBQJUQEQDAAoJEAKE8gwrqXztiUAP/1ApMrrgYXp21c702IV//GiJ LU3VKul0fxp+MJgGcLJ6KzHnM+duSvF3dtr/LTs487L1V6o26LY2wZhuEZhNPRcO 0eeH2kDvAhMocf2YZabcucCO1FnZHZxAugu8o6sjWHLtV8LB2Nl7Se6Bb8Logrt1 tiixtvIHCabi2YP5l7tFQsQEq/qOWnOWOABz7Urdzg9IUI2MvnVzUXMGoY4/EkSs yZ46G5VV9oGgGliHISB7W36q2DhL5+uLsdzl2Q1Q3jXj4OVW7ryj0UqWtxhT+DEe GCciXEoD0nAdQRLGcqdCLT8Y+sD6qeyum8Y6LvJ1FW7G/PHzrLVFB58hDUVNpai3 Uv6NgroCIC2ByL/IfLKpMtLszVromRo0Nw6Yldkv8v9W6iB85p+UTa0SsNWTw6rZ Qw5P1LMH6G9UGjxLbSAW8ErulZ33VR//MSzDcoU/JGn6MxB0Wygm9jHkAKJmj/in rhEcOiGeS49fsUu+N1HodH0bRAPi3iRWJSvA6cUdIUGMz5rk8B7XlTvTR2twncyV bTkF8TtXTDz5YwmW7Jebd0502/lam/ZOZirkjoRQoT/jmSCbkD5eQb0/q5KG6ugv 2FRlyeuxzgkeV655zHSA8oeeTA8OLQlyYDHp+y46lY8+hBtPUZ3M/9RlkTCbKSPr ojb+Rwfkv/ii64EV4pEX =PHD7 -----END PGP SIGNATURE----- Changes: squid3 (3.4.8-1) unstable; urgency=high * Urgency high due to security fixes [ Amos Jeffries <[email protected]> ] * New upstream release (Closes: #737008) - Fixes CVE-2014-6270: off by one in snmp subsystem (Closes: #761002) - Fixes CVE-2014-CVE-2014-7141 and CVE-214-7142 (Closes: #760999) + pinger remote DoS vulnerabilities - Fixes CVE-2014-0128: Denial of Service in SSL-Bump (Closes: #741312) * debian/patches/ - remove CVE-2014-3609.patch included upstream - remove 17-pod2man-check.patch obsoleted by new version - add upstream patch 21-squid-3.4-13176-memoryleak.patch: memory leak in external_acl_type helper with cache=0 or ttl=0 * debian/rules - add --disable-arch-native to build with portable CPU support * debian/control - libecap API support is specific to version 0.2.0 - use nettle for crypto library * debian/watch - updated watch pattern for upstream major series * debian/rules - Remove obsolete --enable-underscores (Closes: #693905) [ Luigi Gangitano <[email protected]> ] * debian/patches/ - refreshed all patches to match 3.4.8 * debian/control - Added dependency for missing intepreter ksh - Bumped Standard-Version to 3.9.6, no change needed - Added XS-Vcs-Git Header pointing to Alioth repository -- Luigi Gangitano <[email protected]> Fri, 17 Oct 2014 00:10:00 +1300