Bug 1063 - [SECURITY] Update lighttpd to 1.4.26
Summary: [SECURITY] Update lighttpd to 1.4.26
Status: RESOLVED FIXED
Alias: None
Product: buildroot
Classification: Unclassified
Component: Outdated package (show other bugs)
Version: unspecified
Hardware: PC Linux
: P5 normal
Target Milestone: ---
Assignee: unassigned
URL:
Keywords:
Depends on:
Blocks:
 
Reported: 2010-02-09 14:32 UTC by Gustavo Zacarias
Modified: 2010-02-09 15:23 UTC (History)
1 user (show)

See Also:
Host: i686-linux
Target: arm-softfloat-linux-uclibcgnueabi
Build:


Attachments
Bump lighttpd to 1.4.26 (883 bytes, patch)
2010-02-09 14:32 UTC, Gustavo Zacarias
Details

Note You need to log in before you can comment on or make changes to this bug.
Description Gustavo Zacarias 2010-02-09 14:32:14 UTC
Created attachment 1081 [details]
Bump lighttpd to 1.4.26

lighttpd 1.4.26 fixes:

* Request parser handling for splitted header data
* FD leak in mod_cgi
* Segfault with broken configs in mod_rewrite/mod_redirect
* An OOM/DoS vulnerability (CVE-2010-0295)
Comment 1 Peter Korsgaard 2010-02-09 15:23:50 UTC
Committed, thanks