Alerts This Week
Warning Icon 1 626
Alerts This Week
Warning Icon 1 626

Debian: DSA-1521-2 Severe: Lighttpd Information Leak Vulnerability

debian
Calendar Grey March 16, 2008
Debian Logo
Enhance lighttpd to address a severe file exposure vulnerability impacting Debian environments caused by unconventional setups.
Julien Cayzac discovered that under certain circumstances lighttpd, a fast webserver with minimal memory footprint, might allow the reading of arbitrary files from the system

Summary


We recommend that you upgrade your lighttpd package.


Upgrade instructions
- --------------------wget url
will fetch the file for you
dpkg -i file.deb
will install the referenced file.

If you are using the apt-get package manager, use the line for
sources.list as given below:

apt-get update
will update the internal database
apt-get upgrade
will install corrected packages

You may use an automated update by adding the resources from the
footer to the proper configuration.


Debian GNU/Linux 4.0 alias etch

Size/MD5 checksum: 1098 3e5a62a7162734998177e8707d2dba02
Size/MD5 checksum: 37066 853e653e4b56e0065b7d072bfdb038b9

Architecture independent packages:

Size/MD5 checksum: 99510 38af003d4b49531a371c58eec8c92797

alpha architecture (DEC Alpha)

Size/MD5 checksum: 61252 f9a572ac4ece6cda80883e9ece59cf99
Size/MD5 checksum: 64492 6d0802043b33391abf217b605ade53c6
Size/MD5 checksum: 318848 64225fd5e10...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here