Gentoo Archives: gentoo-announce

From: Pierre-Yves Rofes <py@g.o>
To: gentoo-announce@l.g.o
Cc: full-disclosure@××××××××××××××.uk, bugtraq@×××××××××××××.com, security-alerts@×××××××××××××.com
Subject: [gentoo-announce] [ GLSA 200803-10 ] lighttpd: Multiple vulnerabilities
Date: Wed, 05 Mar 2008 21:22:14
Message-Id: 47CF13CC.4040909@gentoo.org
1 -----BEGIN PGP SIGNED MESSAGE-----
2 Hash: SHA1
3
4 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
5 Gentoo Linux Security Advisory GLSA 200803-10
6 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
7 http://security.gentoo.org/
8 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
9
10 Severity: Normal
11 Title: lighttpd: Multiple vulnerabilities
12 Date: March 05, 2008
13 Bugs: #211230, #211956
14 ID: 200803-10
15
16 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
17
18 Synopsis
19 ========
20
21 Multiple vulnerabilities have been discovered in lighttpd.
22
23 Background
24 ==========
25
26 lighttpd is a lightweight high-performance web server.
27
28 Affected packages
29 =================
30
31 -------------------------------------------------------------------
32 Package / Vulnerable / Unaffected
33 -------------------------------------------------------------------
34 1 www-servers/lighttpd < 1.4.18-r2 >= 1.4.18-r2
35
36 Description
37 ===========
38
39 lighttpd contains a calculation error when allocating the global file
40 descriptor array (CVE-2008-0983). Furthermore, it sends the source of a
41 CGI script instead of returning a 500 error (Internal Server Error)
42 when the fork() system call fails (CVE-2008-1111).
43
44 Impact
45 ======
46
47 A remote attacker could exploit these vulnerabilities to cause a Denial
48 of Service or gain the source of a CGI script.
49
50 Workaround
51 ==========
52
53 There is no known workaround at this time.
54
55 Resolution
56 ==========
57
58 All lighttpd users should upgrade to the latest version:
59
60 # emerge --sync
61 # emerge --ask --oneshot --verbose ">=www-servers/lighttpd-1.4.18-r2"
62
63 References
64 ==========
65
66 [ 1 ] CVE-2008-0983
67 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0983
68 [ 2 ] CVE-2008-1111
69 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1111
70
71 Availability
72 ============
73
74 This GLSA and any updates to it are available for viewing at
75 the Gentoo Security Website:
76
77 http://security.gentoo.org/glsa/glsa-200803-10.xml
78
79 Concerns?
80 =========
81
82 Security is a primary focus of Gentoo Linux and ensuring the
83 confidentiality and security of our users machines is of utmost
84 importance to us. Any security concerns should be addressed to
85 security@g.o or alternatively, you may file a bug at
86 http://bugs.gentoo.org.
87
88 License
89 =======
90
91 Copyright 2008 Gentoo Foundation, Inc; referenced text
92 belongs to its owner(s).
93
94 The contents of this document are licensed under the
95 Creative Commons - Attribution / Share Alike license.
96
97 http://creativecommons.org/licenses/by-sa/2.5
98 -----BEGIN PGP SIGNATURE-----
99 Version: GnuPG v2.0.7 (GNU/Linux)
100 Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org
101
102 iD8DBQFHzxPMuhJ+ozIKI5gRAungAJwINfZC2FZ4iEIxlamiBUjwmlflUgCfXXCM
103 LORr9FwlLB0pZuIR6aJJFGE=
104 =uoUo
105 -----END PGP SIGNATURE-----
106 --
107 gentoo-announce@l.g.o mailing list