UbuntuUpdates.org

Package "lighttpd"

Name: lighttpd

Description:

fast webserver with minimal memory footprint

Latest version: 1.4.33-1+nmu2ubuntu2.1
Release: trusty (14.04)
Level: updates
Repository: universe
Homepage: http://lighttpd.net/

Links


Download "lighttpd"


Other versions of "lighttpd" in Trusty

Repository Area Version
base universe 1.4.33-1+nmu2ubuntu2
security universe 1.4.33-1+nmu2ubuntu2.1

Packages in group

Deleted packages are displayed in grey.


Changelog

Version: 1.4.33-1+nmu2ubuntu2.1 2019-01-31 20:07:08 UTC

  lighttpd (1.4.33-1+nmu2ubuntu2.1) trusty-security; urgency=medium

  * SECURITY UPDATE: Fix vulnerabilities in mod_sql and HTTPoxy.
    - debian/patches/CVE-2014-2323-CVE-2014-2324.patch: Fix SQL injection
      vulnerability in mod_mysql_vhost.c.
    - debian/patches/CVE-2016-1000212.patch: Mitigation for HTTPoxy
      vulnerability.
    - CVE-2014-2323
    - CVE-2014-2324
    - CVE-2016-1000212

 -- Paulo Flabiano Smorigo <email address hidden> Fri, 25 Jan 2019 10:08:11 -0200

CVE-2014-2323 SQL injection vulnerability in mod_mysql_vhost.c in lighttpd before 1.4.35 allows remote attackers to execute arbitrary SQL commands via the host nam
CVE-2014-2324 Multiple directory traversal vulnerabilities in (1) mod_evhost and (2) mod_simple_vhost in lighttpd before 1.4.35 allow remote attackers to read arbi
CVE-2016-1000212 Mitigation for HTTPoxy vulnerability



About   -   Send Feedback to @ubuntu_updates