    Debian: New lighttpd packages fix regression

    It was discovered that lighttpd, a fast webserver with minimal memory footprint, was didn't correctly handle SSL errors. This could allow a remote attacker to disconnect all active SSL connections.
    Debian Security Advisory DSA-1540-3                  This email address is being protected from spambots. You need JavaScript enabled to view it.                          Thijs Kinkhorst
    July 23, 2008               
    Package        : lighttpd
    Vulnerability  : denial of service
    Problem type   : remote
    Debian-specific: no
    CVE Id(s)      : CVE-2008-1531
    This update fixes a regression in lighttpd introduced in DSA-1540,
    causing SSL failures. For reference the original advisory text is
    quoted below.
    It was discovered that lighttpd, a fast webserver with minimal memory
    footprint, was didn't correctly handle SSL errors.  This could allow
    a remote attacker to disconnect all active SSL connections.
    For the stable distribution (etch), this problem has been fixed in
    version 1.4.13-4etch10.
    We recommend that you upgrade your lighttpd package.
    Upgrade instructions
    wget url
            will fetch the file for you
    dpkg -i file.deb
            will install the referenced file.
    If you are using the apt-get package manager, use the line for
    sources.list as given below:
    apt-get update
            will update the internal database
    apt-get upgrade
            will install corrected packages
    You may use an automated update by adding the resources from the
    footer to the proper configuration.
    Debian GNU/Linux 4.0 alias etch
    Source archives:
      These files will probably be moved into the stable distribution on
      its next update.
    For apt-get: deb stable/updates main
    For dpkg-ftp: dists/stable/updates/main
    Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it.


