public inbox for cygwin-apps@cygwin.com
 help / color / mirror / Atom feed
* SECURITY: lighttpd
@ 2007-05-08  4:01 Yaakov (Cygwin Ports)
  2007-05-08  9:06 ` Lapo Luchini
  0 siblings, 1 reply; 3+ messages in thread
From: Yaakov (Cygwin Ports) @ 2007-05-08  4:01 UTC (permalink / raw)
  To: cygwin-apps

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

Two vulnerabilities have been discovered in Lighttpd, each allowing for
a Denial of Service.

Solution: upgrade to >= 1.4.14 (current is 1.4.9)

More information:
http://security.gentoo.org/glsa/glsa-200705-07.xml
http://bugs.gentoo.org/show_bug.cgi?id=174043
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1869
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1870

Yaakov

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.5 (Cygwin)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org

iD8DBQFGP/YgpiWmPGlmQSMRCOI3AKCOjsZ0fLtQ1GnqAB+G4r+fUrt0swCfQmS0
5I5vf8ZmoC5s+ufh8pKEi5o=
=e02T
-----END PGP SIGNATURE-----

^ permalink raw reply	[flat|nested] 3+ messages in thread

* Re: SECURITY: lighttpd
  2007-05-08  4:01 SECURITY: lighttpd Yaakov (Cygwin Ports)
@ 2007-05-08  9:06 ` Lapo Luchini
  2007-05-26 15:16   ` Lapo Luchini
  0 siblings, 1 reply; 3+ messages in thread
From: Lapo Luchini @ 2007-05-08  9:06 UTC (permalink / raw)
  To: cygwin-apps

Yaakov (Cygwin Ports) wrote:
> Two vulnerabilities have been discovered in Lighttpd, each allowing for
> a Denial of Service.
>
> Solution: upgrade to >= 1.4.14 (current is 1.4.9)
Uh... whoooops.
Is that mine?
AFAIR yes, I'll update it ASAP, thanks for the prod.

-- 
Lapo Luchini
lapo@lapo.it (OpenPGP & X.509)
www.lapo.it (Jabber, ICQ, MSN)

^ permalink raw reply	[flat|nested] 3+ messages in thread

* Re: SECURITY: lighttpd
  2007-05-08  9:06 ` Lapo Luchini
@ 2007-05-26 15:16   ` Lapo Luchini
  0 siblings, 0 replies; 3+ messages in thread
From: Lapo Luchini @ 2007-05-26 15:16 UTC (permalink / raw)
  To: [ML] CygWin-Apps

Lapo Luchini wrote:
> I'll update it ASAP, thanks for the prod.
BTW: the Windows partition of my laptop kinda died, so I can't use the
spare time on the bus. I'll have to finish it on my main box, competing
for free time with paid jobs...

PS: anyway who is using lighttpd for anything other than a local-only
installation (for which security issues are a bit moot) feel very free
to send me personal emails and tell me to be faster, it will help :-P

-- 
Lapo Luchini
lapo@lapo.it (OpenPGP & X.509)
www.lapo.it (Jabber, ICQ, MSN)

^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2007-05-26 15:16 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2007-05-08  4:01 SECURITY: lighttpd Yaakov (Cygwin Ports)
2007-05-08  9:06 ` Lapo Luchini
2007-05-26 15:16   ` Lapo Luchini

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for read-only IMAP folder(s) and NNTP newsgroup(s).