Bug 994444

Summary: 1.4.31 contains a severe DOS attack point
Product: [Fedora] Fedora EPEL Reporter: Andras Kemeny <pdx>
Component: lighttpdAssignee: Matthias Saou <matthias>
Status: CLOSED ERRATA QA Contact: Fedora Extras Quality Assurance <extras-qa>
Severity: high Docs Contact:
Priority: unspecified    
Version: el6CC: matthias, rhbugs
Target Milestone: ---   
Target Release: ---   
Hardware: Unspecified   
OS: Linux   
Whiteboard:
Fixed In Version: lighttpd-1.4.34-3.fc20 Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2014-02-22 01:47:44 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Andras Kemeny 2013-08-07 10:10:08 UTC
Description of problem:
Version 1.4.31 is known to have a severe security hole allowing remote attackers push lighttpd into an infinity loop. 1.4.32 is out since last November with a fix for this vulnerability.

Version-Release number of selected component (if applicable):
1.4.31-1.el6

How reproducible:
Look at the version number in the repo.

Steps to Reproduce:
1. add the EPEL repo.
2. yum list lighttpd.

Actual results:
Installing a web server with a known security hole.

Expected results:
Installing a web server withOUT a known security hole. That is, lighttpd 1.4.32.

Additional info:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5533
http://www.lighttpd.net/

Comment 1 Anssi Johansson 2013-08-07 13:11:13 UTC
Confirmed on:
lighttpd-1.4.31-1.el5
lighttpd-1.4.31-1.el6

Duplicate of bug 878915.

Bug 878213 is related.

Comment 2 Andras Kemeny 2013-08-07 13:48:00 UTC
(In reply to Anssi Johansson from comment #1)
> Confirmed on:
> lighttpd-1.4.31-1.el5
> lighttpd-1.4.31-1.el6
> 
> Duplicate of bug 878915.
> 
> Bug 878213 is related.

indeed. moved my whining over to bug 878915. but what happened? matthias saou disappeared without a trace, and no one took up maintaining this package?

Comment 3 Fedora Update System 2014-02-06 14:52:45 UTC
lighttpd-1.4.34-1.el6 has been submitted as an update for Fedora EPEL 6.
https://admin.fedoraproject.org/updates/lighttpd-1.4.34-1.el6

Comment 4 Fedora Update System 2014-02-06 14:53:21 UTC
lighttpd-1.4.34-1.fc19 has been submitted as an update for Fedora 19.
https://admin.fedoraproject.org/updates/lighttpd-1.4.34-1.fc19

Comment 5 Fedora Update System 2014-02-06 14:54:20 UTC
lighttpd-1.4.34-1.el5.1 has been submitted as an update for Fedora EPEL 5.
https://admin.fedoraproject.org/updates/lighttpd-1.4.34-1.el5.1

Comment 6 Fedora Update System 2014-02-06 14:54:58 UTC
lighttpd-1.4.34-1.fc20 has been submitted as an update for Fedora 20.
https://admin.fedoraproject.org/updates/lighttpd-1.4.34-1.fc20

Comment 7 Fedora Update System 2014-02-06 21:07:35 UTC
Package lighttpd-1.4.34-1.el6:
* should fix your issue,
* was pushed to the Fedora EPEL 6 testing repository,
* should be available at your local mirror within two days.
Update it with:
# su -c 'yum update --enablerepo=epel-testing lighttpd-1.4.34-1.el6'
as soon as you are able to.
Please go to the following url:
https://admin.fedoraproject.org/updates/FEDORA-EPEL-2014-0465/lighttpd-1.4.34-1.el6
then log in and leave karma (feedback).

Comment 8 Fedora Update System 2014-02-12 20:50:01 UTC
lighttpd-1.4.34-3.fc20 has been submitted as an update for Fedora 20.
https://admin.fedoraproject.org/updates/lighttpd-1.4.34-3.fc20

Comment 9 Fedora Update System 2014-02-12 20:50:35 UTC
lighttpd-1.4.34-3.fc19 has been submitted as an update for Fedora 19.
https://admin.fedoraproject.org/updates/lighttpd-1.4.34-3.fc19

Comment 10 Fedora Update System 2014-02-22 01:47:44 UTC
lighttpd-1.4.34-1.el5.1 has been pushed to the Fedora EPEL 5 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 11 Fedora Update System 2014-02-22 01:48:30 UTC
lighttpd-1.4.34-1.el6 has been pushed to the Fedora EPEL 6 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 12 Fedora Update System 2014-02-22 18:18:25 UTC
lighttpd-1.4.34-3.fc19 has been pushed to the Fedora 19 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 13 Fedora Update System 2014-02-22 18:21:54 UTC
lighttpd-1.4.34-3.fc20 has been pushed to the Fedora 20 stable repository.  If problems still persist, please make note of it in this bug report.