~ubuntu-branches/ubuntu/dapper/lighttpd/dapper-security

Viewing all changes in revision 16.

  • Committer: Bazaar Package Importer
  • Author(s): Emanuele Gentili
  • Date: 2008-03-11 15:03:17 UTC
  • Revision ID: james.westby@ubuntu.com-20080311150317-y2jhxou7h1soqat4
Tags: 1.4.11-3ubuntu3.8
* SECURITY UPDATE: (LP: #200987)
 + debian/patches/91_CVE-2008-1270.dpatch
  - mod_userdir in lighttpd 1.4.18 and earlier, when userdir.path is not set,
    uses a default of $HOME, which might allow remote attackers to read arbitrary
    files, as demonstrated by accessing the ~nobody directory.
* References
 + http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-1270
 + http://trac.lighttpd.net/trac/ticket/1587
 + http://trac.lighttpd.net/trac/changeset/2120

expand all expand all

Show diffs side-by-side

added added

removed removed

Lines of Context: