DSA-1740-1 yaws -- denial of serviceID: oval:org.secpod.oval:def:600441 | Date: (C)2011-05-13 (M)2022-10-10 |
Class: PATCH | Family: unix |
It was discovered that yaws, a high performance HTTP 1.1 webserver, is prone to a denial of service attack via a request with a large HTTP header. For the stable distribution , this problem has been fixed in version 1.77-3+lenny1. For the oldstable distribution , this problem has been fixed in version 1.65-4etch1. For the testing distribution and the unstable distribution , this problem has been fixed in version 1.80-1. We recommend that you upgrade your yaws package.
Platform: |
Debian 5.0 |
Debian 4.0 |