~ubuntu-branches/ubuntu/gutsy/lighttpd/gutsy-security

Viewing all changes in revision 32.

  • Committer: Bazaar Package Importer
  • Author(s): Emanuele Gentili
  • Date: 2008-04-06 03:39:14 UTC
  • Revision ID: james.westby@ubuntu.com-20080406033914-kbrvw3kc104ooo8u
Tags: 1.4.18-1ubuntu1.4
* SECURITY UPDATE: (LP: #209627)
 + debian/patches/91_CVE-2008-1531.dpatch
  - lighttpd 1.4.19 and earlier allows remote attackers to cause a denial 
    of service (active SSL connection loss) by triggering an SSL error, 
    such as disconnecting before a download has finished, which causes 
    all active SSL connections to be lost.
* References
 + http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-1531
 + http://trac.lighttpd.net/trac/changeset/2136
 + http://trac.lighttpd.net/trac/changeset/2139

expand all expand all

Show diffs side-by-side

added added

removed removed

Lines of Context: