Fedora alert FEDORA-2008-3376 (lighttpd)
From: | updates@fedoraproject.org | |
To: | fedora-package-announce@redhat.com | |
Subject: | [SECURITY] Fedora 8 Update: lighttpd-1.4.19-4.fc8 | |
Date: | Tue, 29 Apr 2008 20:57:25 +0000 | |
Message-ID: | <200804292112.m3TLCX57031009@bastion.fedora.phx.redhat.com> |
-------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2008-3376 2008-04-29 20:27:05 -------------------------------------------------------------------------------- Name : lighttpd Product : Fedora 8 Version : 1.4.19 Release : 4.fc8 URL : http://www.lighttpd.net/ Summary : Lightning fast webserver with light system requirements Description : Secure, fast, compliant and very flexible web-server which has been optimized for high-performance environments. It has a very low memory footprint compared to other webservers and takes care of cpu-load. Its advanced feature-set (FastCGI, CGI, Auth, Output-Compression, URL-Rewriting and many more) make it the perfect webserver-software for every server that is suffering load problems. Available rpmbuild rebuild options : --with : gamin webdavprops webdavlocks memcache --without : ldap gdbm lua (cml) -------------------------------------------------------------------------------- Update Information: This update fixes a bug where a user could kill another user's SSL connection by killing his own, because the SSL error queue wasn't cleared properly. -------------------------------------------------------------------------------- ChangeLog: * Thu Apr 24 2008 Matthias Saou <http://freshrpms.net/> 1.4.19-4 - Merge in second changest from upstream fix for upstream bug #285. * Thu Mar 27 2008 Matthias Saou <http://freshrpms.net/> 1.4.19-3 - Include sslshutdown patch, upstream fix to upstream bug #285 (#439066). * Sat Mar 22 2008 Matthias Saou <http://freshrpms.net/> 1.4.19-2 - Provide "webserver" (#437884). * Wed Mar 12 2008 Matthias Saou <http://freshrpms.net/> 1.4.19-1 - Update to 1.4.19, which includes all previous security fixes + bugfixes. * Tue Mar 4 2008 Matthias Saou <http://freshrpms.net/> 1.4.18-6 - Include patch for CVE-2008-0983 (crash when low on file descriptors). - Include patch for CVE-2008-1111 (cgi source disclosure). * Tue Feb 19 2008 Fedora Release Engineering <rel-eng@fedoraproject.org> - Autorebuild for GCC 4.3 * Wed Dec 5 2007 Release Engineering <rel-eng at fedoraproject dot org> - Rebuild for deps * Wed Oct 31 2007 Matthias Saou <http://freshrpms.net/> 1.4.18-3 - Update mod_geoip source to fix segfault upon stopping lighttpd. * Mon Oct 22 2007 Matthias Saou <http://freshrpms.net/> 1.4.18-2 - Include mod_geoip additional source, make it an optional sub-package. - Reorder sub-packages alphabetically in spec file. - Make sub-packages require exact release, just in case. - Change default webroot back from /srv to /var. -------------------------------------------------------------------------------- References: [ 1 ] Bug #439066 - CVE-2008-1531 lighttpd closes unrelated SSL connections on SSL error https://bugzilla.redhat.com/show_bug.cgi?id=439066 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update lighttpd' at the command line. For more information, refer to "Managing Software with yum", available at http://docs.fedoraproject.org/yum/. All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at http://fedoraproject.org/keys -------------------------------------------------------------------------------- _______________________________________________ Fedora-package-announce mailing list Fedora-package-announce@redhat.com http://www.redhat.com/mailman/listinfo/fedora-package-ann...