-
Committer:
Bazaar Package Importer
-
Author(s):
Emanuele Gentili
-
Date:
2008-04-06 00:09:12 UTC
-
Revision ID:
james.westby@ubuntu.com-20080406000912-8fch5qc1ahziv5zi
Tags: 1.4.19-0ubuntu3
* SECURITY UPDATE: (LP: #209627)
+ debian/patches/92_CVE-2008-1531.dpatch
- lighttpd 1.4.19 and earlier allows remote attackers to cause a denial
of service (active SSL connection loss) by triggering an SSL error,
such as disconnecting before a download has finished, which causes
all active SSL connections to be lost.
* References
+ http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-1531
+ http://trac.lighttpd.net/trac/changeset/2136
+ http://trac.lighttpd.net/trac/changeset/2139