LWN.net Logo

lighttpd: multiple vulnerabilities

Package(s):lighttpd CVE #(s):CVE-2008-4298 CVE-2008-4359 CVE-2008-4360
Created:October 6, 2008 Updated:January 12, 2010
Description:

From the Debian advisory:

CVE-2008-4298: A memory leak in the http_request_parse function could be used by remote attackers to cause lighttpd to consume memory, and cause a denial of service attack.

CVE-2008-4359: Inconsistent handling of URL patterns could lead to the disclosure of resources a server administrator did not anticipate when using rewritten URLs.

CVE-2008-4360: Upon file systems which don't handle case-insensitive paths differently it might be possible that unanticipated resources could be made available by mod_userdir.

Alerts:
SuSE SUSE-SR:2009:020 2010-01-12
Fedora FEDORA-2008-11923 2008-12-30
Gentoo 200812-04 2008-12-02
SuSE SUSE-SR:2008:026 2008-11-24
rPath rPSA-2008-0309-1 2008-10-30
Debian DSA-1645-1 2008-10-06

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds