Description: | Description:
The remote host is missing an update to lighttpd announced via advisory FEDORA-2008-2278.
Secure, fast, compliant and very flexible web-server which has been optimized for high-performance environments. It has a very low memory footprint compared to other webservers and takes care of cpu-load. Its advanced feature-set (FastCGI, CGI, Auth, Output-Compression, URL-Rewriting and many more) make it the perfect webserver-software for every server that is suffering load problems.
Available rpmbuild rebuild options : --with : gamin webdavprops webdavlocks memcache --without : ldap gdbm lua (cml)
ChangeLog:
* Tue Mar 4 2008 Matthias Saou 1.4.18-6 - Include patch for CVE-2008-0983 (crash when low on file descriptors). - Include patch for CVE-2008-1111 (cgi source disclosure).
References:
[ 1 ] Bug #435805 - CVE-2008-1111 lighttpd CGI source disclosure https://bugzilla.redhat.com/show_bug.cgi?id=435805 [ 2 ] Bug #434163 - CVE-2008-0983 lighttpd crashes when it's low on file descriptors https://bugzilla.redhat.com/show_bug.cgi?id=434163
Solution: Apply the appropriate updates.
This update can be installed with the yum update program. Use su -c 'yum update lighttpd' at the command line. For more information, refer to Managing Software with yum, available at http://docs.fedoraproject.org/yum/.
http://www.securityspace.com/smysecure/catid.html?in=FEDORA-2008-2278
Risk factor : Medium
CVSS Score: 5.0
|