Bug 249162 (CVE-2007-3950) - CVE-2007-394{6-9} lighttpd 1.4.15 multiple vulnerabilities
Summary: CVE-2007-394{6-9} lighttpd 1.4.15 multiple vulnerabilities
Status: CLOSED ERRATA
Alias: CVE-2007-3950
Product: Fedora
Classification: Fedora
Component: lighttpd   
(Show other bugs)
Version: 7
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Matthias Saou
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard:
Keywords: Security
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2007-07-21 19:21 UTC by Ville Skyttä
Modified: 2007-11-30 22:12 UTC (History)
1 user (show)

Fixed In Version: 1.4.16-1.fc7
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2007-07-27 05:54:27 UTC
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)

Description Ville Skyttä 2007-07-21 19:21:01 UTC
http://www.vuxml.org/freebsd/fc9c217e-3791-11dc-bb1a-000fea449b8a.html

"Some vulnerabilities have been reported in lighttpd, which can be exploited by
malicious people to bypass certain security restrictions or cause a DoS (Denial
of Service)."

Comment 1 Lubomir Kundrak 2007-07-25 13:07:52 UTC
CVE-2007-3946 Lighttpd SA 2007:04-07
CVE-2007-3947 Lighttpd SA 2007:03
CVE-2007-3948 ?
CVE-2007-3949 Lighttpd SA 2007:08 (patch: 
CVE-2007-3950 ?
?             Lighttpd SA 2007:09

Comment 2 Matthias Saou 2007-07-26 08:37:58 UTC
Lighttpd 1.4.16 has just been released, and rebuilt for all current Fedora and
EPEL branches. Packages are waiting to be pushed.

Comment 3 Fedora Update System 2007-07-27 05:54:24 UTC
lighttpd-1.4.16-1.fc7 has been pushed to the Fedora 7 stable repository.  If problems still persist, please make note of it in this bug report.


Note You need to log in before you can comment on or make changes to this bug.