-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Format: 1.6 Date: Thu, 12 Sep 2002 17:37:54 -0400 Source: php4 Binary: php4-cgi-snmp php4-cgi-mysql php4-snmp php4-mysql php4-dev php4-cgi-pgsql php4-cgi-imap php4-pgsql php4-imap php4-cgi-xml php4-cgi-mhash php4-cgi-ldap php4-xml php4-mhash php4-ldap php4-cgi-gd php4-cgi php4-gd php4 Architecture: sparc Version: 4.0.3pl1-0potato4 Distribution: oldstable-security Urgency: high Maintainer: Debian/SPARC Build Daemon Description: php4 - A server-side, HTML-embedded scripting language php4-cgi - A server-side, HTML-embedded scripting language php4-cgi-gd - GD module for php4-cgi php4-cgi-imap - IMAP module for php4-cgi php4-cgi-ldap - LDAP module for php4-cgi php4-cgi-mhash - MHASH module for php4-cgi php4-cgi-mysql - MySQL module for php4-cgi php4-cgi-pgsql - PostgreSQL module for php4-cgi php4-cgi-snmp - SNMP module for php4-cgi php4-cgi-xml - XML module for php4-cgi php4-gd - GD module for php4 php4-imap - IMAP module for php4 php4-ldap - LDAP module for php4 php4-mhash - MHASH module for php4 php4-mysql - MySQL module for php4 php4-pgsql - PostgreSQL module for php4 php4-snmp - SNMP module for php4 php4-xml - XML module for php4 Changes: php4 (4.0.3pl1-0potato4) oldstable-security; urgency=high . * Non-maintainer upload by Security Team * Backport security fixes from 4.2.3+ to prevent CR/LF injection - Filter control characters from To and Subject in mail() - Filter control characters from URLs passed to fopen() * Was never vulnerable to safe_mode/extra_cmd problem in mail() because extra_cmd doesn't exist yet in this version Files: be65d0d8c66e0bdcf5aa3a337a019ea6 435060 web optional php4_4.0.3pl1-0potato4_sparc.deb 4c30e39b0b41c257b6799be7ba1049d6 24640 web optional php4-gd_4.0.3pl1-0potato4_sparc.deb 1c549583a976b31a470d99084e90debe 27882 web optional php4-imap_4.0.3pl1-0potato4_sparc.deb 2e450b42984d51fff11d047e76b2b010 11408 web optional php4-ldap_4.0.3pl1-0potato4_sparc.deb 6b839eb92043d7141cb55ed50f65305e 4302 web optional php4-mhash_4.0.3pl1-0potato4_sparc.deb 0e785646230878a503bfc9337805c232 13426 web optional php4-mysql_4.0.3pl1-0potato4_sparc.deb 65ac791d544f5d2bba73c9f7fd6883fc 13814 web optional php4-pgsql_4.0.3pl1-0potato4_sparc.deb fd0cfad8da3867e6299cad6650bc2ba6 6448 web optional php4-snmp_4.0.3pl1-0potato4_sparc.deb e98ff68b971213999ca3f997ed4b12a8 11982 web optional php4-xml_4.0.3pl1-0potato4_sparc.deb 2670abfe8104e7b93ce3eb82f82783ef 665368 web optional php4-cgi_4.0.3pl1-0potato4_sparc.deb bb8e61d4d8e1327cd7e482068c874170 24646 web optional php4-cgi-gd_4.0.3pl1-0potato4_sparc.deb 062a92643d80f5290e1becea2d3be39f 27884 web optional php4-cgi-imap_4.0.3pl1-0potato4_sparc.deb dfbb3b0b85309c6fe58a73084824f661 11416 web optional php4-cgi-ldap_4.0.3pl1-0potato4_sparc.deb f612f9825e60799ad0083f8f8740158b 4298 web optional php4-cgi-mhash_4.0.3pl1-0potato4_sparc.deb 54e9b490f54c7cd68008f7aa3b29468d 13418 web optional php4-cgi-mysql_4.0.3pl1-0potato4_sparc.deb 2e6ced4a93def735d2a9acf27ae36218 13820 web optional php4-cgi-pgsql_4.0.3pl1-0potato4_sparc.deb a654cb5937d6912191e92a8c2b9628d4 6444 web optional php4-cgi-snmp_4.0.3pl1-0potato4_sparc.deb 46e69e7b24e5ddc5f3aaa3c27a78cc52 11992 web optional php4-cgi-xml_4.0.3pl1-0potato4_sparc.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.0.7 (GNU/Linux) iD8DBQE9gbQRW5ql+IAeqTIRAg8EAJwMW8sttAaBlR4mt66AkUI0r9IZ8wCfVPwY 75cS/jjaVAnOpwqMcGFWkj4= =JAsH -----END PGP SIGNATURE-----