Alerts This Week
Warning Icon 1 626
Alerts This Week
Warning Icon 1 626

Debian: DSA-1362 A Moderate Advisory on Lighttpd DoS Vulnerabilities

debian
Calendar Grey August 29, 2007
Debian Logo
Ubuntu security bulletin announcing patches for nginx targeting various high-severity vulnerabilities. Discover strategies to safeguard your server.
Several vulnerabilities were discovered in lighttpd, a fast webserver with minimal memory footprint

Summary


The use of mod_auth could leave to a denial of service attack crashing
the webserver

CVE-2007-3947

The improper handling of repeated HTTP headers could cause a denial
of serve attack crashing the webserver.

CVE-2007-3949

A bug in mod_access potentially allows remote users to bypass
access restrictions via trailing slash characters.

CVE-2007-3950

On 32-bit platforms users may be able to create denial of service
attacks, crashing the webserver, via mod_webdav, mod_fastcgi, or
mod_scgi.


For the stable distribution (etch), these problems have been fixed in version
1.4.13-4etch3.

For the unstable distribution (sid), these problems have been fixed in
version 1.4.16-1.

We recommend that you upgrade your lighttpd package.

Upgrade instructions
- --------------------wget url
will fetch the file for you
dpkg -i file.deb
will install the referenced file.

If you are using the apt-get package manager, use the line for
sources.list a...

Read the Full Advisory

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here