|
|
Log in / Subscribe / Register

lighttpd: denial of service and MITM vulnerabilities

Package(s):lighttpd CVE #(s):CVE-2011-4362 CVE-2011-3389
Created:December 21, 2011 Updated:September 10, 2012
Description: A signedness issue in the lighttpd base64 decoding routine can lead to an out-of-bounds read and a denial-of-service opportunity (CVE-2011-4362). Lighttpd can also be vulnerable to the SSL "BEAST" attack in certain configurations, enabling a possible man-in-the-middle attack (CVE-2011-3389).
Alerts:
Debian-LTS DLA-400-1 pound 2016-01-24
Gentoo 201406-10 lighttpd 2014-06-14
Gentoo 201301-01 firefox 2013-01-07
Mageia MGASA-2012-0259 fetchmail 2012-09-07
Fedora FEDORA-2012-9078 lighttpd 2012-06-26
Fedora FEDORA-2012-9040 lighttpd 2012-06-26
Red Hat RHSA-2012:0508-01 java-1.5.0-ibm 2012-04-23
Mandriva MDVSA-2012:058 curl 2012-04-13
Debian DSA-2398-2 curl 2012-03-31
SUSE SUSE-SU-2012:0114-2 IBM Java 1.6.0 2012-03-06
Gentoo 201203-02 curl 2012-03-05
openSUSE openSUSE-SU-2012:0240-1 lighttpd 2012-02-09
Debian DSA-2398-1 curl 2012-01-30
openSUSE openSUSE-SU-2012:0030-1 mozilla-nss 2012-01-05
Fedora FEDORA-2011-17400 thunderbird 2011-12-23
Fedora FEDORA-2011-17400 nss-util 2011-12-23
Debian DSA-2368-1 lighttpd 2011-12-20
Fedora FEDORA-2011-17400 nss-softokn 2011-12-23
Fedora FEDORA-2011-17400 nss 2011-12-23
Fedora FEDORA-2011-17400 firefox 2011-12-23

to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds