Alerts This Week
Warning Icon 1 770
Alerts This Week
Warning Icon 1 770

Fedora 21 lighttpd Update FEDORA-2015-12250 Moderate Log Injection

fedora
Calendar Grey August 7, 2015
Dist Fedora Esm H88
New Lighttpd Release for Fedora 21 Fixes Log Injection Vulnerabilities and Boosts Performance
Latest upstream security release: http://www.lighttpd.net/2015/7/26/1.4.36/

Summary

Secure, fast, compliant and very flexible web-server which has been optimized

for high-performance environments. It has a very low memory footprint compared

to other webservers and takes care of cpu-load. Its advanced feature-set

(FastCGI, CGI, Auth, Output-Compression, URL-Rewriting and many more) make

it the perfect webserver-software for every server that is suffering load

problems.

Update Information:

Latest upstream security release:

http://www.lighttpd.net/2015/7/26/1.4.36/

Change Log

* Mon Jul 27 2015 Jon Ciesla - 1.4.36-1 - 1.4.36 1246857, 1224910, 1224911. * Wed Jun 17 2015 Fedora Release Engineering - 1.4.35-5 - Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild

References


[ 1 ] Bug #1224911 - CVE-2015-3200 lighttpd: log injection via malformed base64 string in Authentication header [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=1224911 [ 2 ] Bug #1224910 - CVE-2015-3200 lighttpd: log injection via malformed base64 string in Authentication header [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1224910 [ 3 ] Bug #1246857 - lighttpd-1.4.36 is available https://bugzilla.redhat.com/show_bug.cgi?id=1246857

Update Instructions

This update can be installed with the "yum" update program. Use su -c 'yum update lighttpd' at the command line. For more information, refer to "Managing Software with yum", available at .

Name: lighttpd
Product: Fedora 21
Version: 1.4.36
Release: 1.fc21
Summary: Lightning fast webserver with light system requirements

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here