LWN.net Logo

Fedora alert FEDORA-2008-4119 (lighttpd)

From:  updates@fedoraproject.org
To:  fedora-package-announce@redhat.com
Subject:  [SECURITY] Fedora 9 Update: lighttpd-1.4.19-4.fc9
Date:  Sat, 17 May 2008 22:28:22 +0000
Message-ID:  <200805172228.m4HMRumQ016877@bastion.fedora.phx.redhat.com>

-------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2008-4119 2008-05-17 19:21:43 -------------------------------------------------------------------------------- Name : lighttpd Product : Fedora 9 Version : 1.4.19 Release : 4.fc9 URL : http://www.lighttpd.net/ Summary : Lightning fast webserver with light system requirements Description : Secure, fast, compliant and very flexible web-server which has been optimized for high-performance environments. It has a very low memory footprint compared to other webservers and takes care of cpu-load. Its advanced feature-set (FastCGI, CGI, Auth, Output-Compression, URL-Rewriting and many more) make it the perfect webserver-software for every server that is suffering load problems. Available rpmbuild rebuild options : --with : gamin webdavprops webdavlocks memcache --without : ldap gdbm lua (cml) -------------------------------------------------------------------------------- Update Information: This update fixes a bug where a user could kill another user's SSL connection by killing his own, because the SSL error queue wasn't cleared properly. -------------------------------------------------------------------------------- ChangeLog: * Thu Apr 24 2008 Matthias Saou <http://freshrpms.net/> 1.4.19-4 - Merge in second changest from upstream fix for upstream bug #285. * Thu Mar 27 2008 Matthias Saou <http://freshrpms.net/> 1.4.19-3 - Include sslshutdown patch, upstream fix to upstream bug #285 (#439066). -------------------------------------------------------------------------------- References: [ 1 ] Bug #439066 - CVE-2008-1531 lighttpd closes unrelated SSL connections on SSL error https://bugzilla.redhat.com/show_bug.cgi?id=439066 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update lighttpd' at the command line. For more information, refer to "Managing Software with yum", available at http://docs.fedoraproject.org/yum/. All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at http://fedoraproject.org/keys -------------------------------------------------------------------------------- _______________________________________________ Fedora-package-announce mailing list Fedora-package-announce@redhat.com http://www.redhat.com/mailman/listinfo/fedora-package-ann...


(Log in to post comments)

Copyright © 2008, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds