|
|
| |
|
| |
lighttpd: multiple vulnerabilities
| Package(s): | lighttpd |
CVE #(s): | CVE-2008-4298
CVE-2008-4359
CVE-2008-4360
|
| Created: | October 6, 2008 |
Updated: | January 12, 2010 |
| Description: |
From the Debian advisory:
CVE-2008-4298:
A memory leak in the http_request_parse function could be used by
remote attackers to cause lighttpd to consume memory, and cause a
denial of service attack.
CVE-2008-4359:
Inconsistent handling of URL patterns could lead to the disclosure
of resources a server administrator did not anticipate when using
rewritten URLs.
CVE-2008-4360:
Upon file systems which don't handle case-insensitive paths differently
it might be possible that unanticipated resources could be made available
by mod_userdir.
|
| Alerts: |
|
( Log in to post comments)
|
|
|