[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248268

 
 

909

 
 

195051

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-2795-1 lighttpd -- several

ID: oval:org.secpod.oval:def:601146Date: (C)2014-01-08   (M)2022-10-10
Class: PATCHFamily: unix




Several vulnerabilities have been discovered in the lighttpd web server. CVE-2013-4508 It was discovered that lighttpd uses weak ssl ciphers when SNI is enabled. This issue was solved by ensuring that stronger ssl ciphers are used when SNI is selected. CVE-2013-4559 The clang static analyzer was used to discover privilege escalation issues due to missing checks around lighttpd"s setuid, setgid, and setgroups calls. Those are now appropriately checked. CVE-2013-4560 The clang static analyzer was used to discover a use-after-free issue when the FAM stat cache engine is enabled, which is now fixed.

Platform:
Debian 7.0
Debian 6.0
Product:
lighttpd
Reference:
DSA-2795-1
CVE-2013-4508
CVE-2013-4559
CVE-2013-4560
CVE    3
CVE-2013-4559
CVE-2013-4560
CVE-2013-4508
CPE    35
cpe:/a:lighttpd:lighttpd:1.4.31
cpe:/a:lighttpd:lighttpd:1.4.30
cpe:/a:lighttpd:lighttpd:1.4.13
cpe:/a:lighttpd:lighttpd:1.4.12
...

© SecPod Technologies