|
|||||||||||
|
[ GLSA 200708-11 ] Lighttpd: Multiple vulnerabilities
From: Raphael Marichez <falco(at)gentoo.org>
Date: Thu Aug 16 2007 - 15:44:13 EDT
Severity: Normal
Title: Lighttpd: Multiple vulnerabilities
Date: August 16, 2007
Bugs: #185442
ID: 200708-11
Synopsis Several vulnerabilities were reported in Lighttpd, most of them allowing a Denial of Service and potentially the remote execution of arbitrary code. Background Lighttpd is a lightweight HTTP web server. Affected packages
Package / Vulnerable / Unaffected
-------------------------------------------------------------------
1 www-servers/lighttpd < 1.4.16 >= 1.4.16
Description Stefan Esser discovered errors with evidence of memory corruption in the code parsing the headers. Several independent researchers also reported errors involving the handling of HTTP headers, the mod_auth and mod_scgi modules, and the limitation of active connections. Impact A remote attacker can trigger any of these vulnerabilities by sending malicious data to the server, which may lead to a crash or memory exhaustion, and potentially the execution of arbitrary code. Additionally, access-deny settings can be evaded by appending a final / to a URL. Workaround There is no known workaround at this time. Resolution All Lighttpd users should upgrade to the latest version:
# emerge --sync
References [ 1 ] CVE-2007-3946
Availability This GLSA and any updates to it are available for viewing at the Gentoo Security Website: http://security.gentoo.org/glsa/glsa-200708-11.xml Concerns? Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to security@gentoo.org or alternatively, you may file a bug at http://bugs.gentoo.org. License Copyright 2007 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. http://creativecommons.org/licenses/by-sa/2.5
This archive was generated by hypermail 2.1.8 : Sun Oct 28 2007 - 06:12:21 EDT |
||||||||||
|
|||||||||||