Alerts This Week
Warning Icon 1 677
Alerts This Week
Warning Icon 1 677

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -2 articles for you...
89

Fedora 32: 2021-444e38face Critical: Jetty 9.4.40 DoS Threat

Update to Jetty 9.4.40 (fixes multiple CVEs). --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-444e38face 2021-04-29 01:21:37.105103 --------------------------------------------------------------------------------Name : jetty Product : Fedora 32 Version : 9.4.40 Release : 1.fc32 URL : https://jetty.org/ Summary : Java Webserver and Servlet Container Description : Jetty is a 100% Java HTTP Server and Servlet Container. This means that you do not need to configure and run a separate web server (like Apache) in order to use Java, servlets and JSPs to generate dynamic content. Jetty is a fully featured web server for static and dynamic content. Unlike separate server/container solutions, this means that your web server and web application run in the same process, without interconnection overheads and complications. Furthermore, as a pure java component, Jetty can be simply included in your application for demonstration, distribution or deployment. Jetty is available on all Java supported platforms. --------------------------------------------------------------------------------Update Information: Update to Jetty 9.4.40 (fixes multiple CVEs) --------------------------------------------------------------------------------ChangeLog: * Wed Apr 21 2021 Alexander Kurtakov 9.4.40-1 - Update to Jetty 9.4.40 (fixes multiple CVEs) * Mon Mar 29 2021 Alexander Kurtakov 9.4.38-1 - Update to Jetty 9.4.38 * Tue Jan 26 2021 Fedora Release Engineering - 9.4.36-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_34_Mass_Rebuild * Mon Jan 18 2021 Mat Booth - 9.4.36-1 - Update to latest upstream release * Wed Oct 28 2020 Mat Booth - 9.4.33-1 - Update to latest upstream release * Wed Aug 19 2020 Mat Booth - 9.4.31-3 - Rebuild to regenerate OSGi metadata for dependency on servlet-api - Add patch to build against new APIs in servlet4 --------------------------------------------------------------------------------References: [ 1 ] Bug #1945710 - CVE-2021-28163 jetty: Symlink directory exposes webapp directory contents https://bugzilla.redhat.com/show_bug.cgi?id=1945710 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-444e38face' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure . The latest Jetty patch for Fedora 32 resolves vulnerabilities present in version 9.4.40, bolstering the security and efficiency of web applications.. Fedora 32 Jetty Security Update Java. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Apr 28, 2021 Critical Fedora
89

Fedora 32: FEDORA-2020-cf8ef2f333 Critical: Jetty Information Disclosure

Updates to the latest upstream release of Eclipse. See the upstream release notes for details: https://eclipseide.org/release/noteworthy/ Also contains security fixes for CVE-2019-17566 and CVE-2019-17638.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2020-cf8ef2f333 2020-08-31 15:48:37.485399 --------------------------------------------------------------------------------Name : jetty Product : Fedora 32 Version : 9.4.31 Release : 2.fc32 URL : https://jetty.org/ Summary : Java Webserver and Servlet Container Description : Jetty is a 100% Java HTTP Server and Servlet Container. This means that you do not need to configure and run a separate web server (like Apache) in order to use Java, servlets and JSPs to generate dynamic content. Jetty is a fully featured web server for static and dynamic content. Unlike separate server/container solutions, this means that your web server and web application run in the same process, without interconnection overheads and complications. Furthermore, as a pure java component, Jetty can be simply included in your application for demonstration, distribution or deployment. Jetty is available on all Java supported platforms. --------------------------------------------------------------------------------Update Information: Updates to the latest upstream release of Eclipse. See the upstream release notes for details: https://eclipseide.org/release/noteworthy/ Also contains security fixes for CVE-2019-17566 and CVE-2019-17638. --------------------------------------------------------------------------------ChangeLog: * Thu Aug 13 2020 Mat Booth - 9.4.31-2 - Reflective use of classes that might not be present in the JDK should be optional when expressed as OSGi dependencies * Wed Aug 12 2020 Mat Booth - 9.4.31-1 - Update to latest upstream release * Tue Jul 28 2020 Fedora Release Engineering - 9.4.30-3.v20200611 - Rebuilt forhttps://fedoraproject.org/wiki/Fedora_33_Mass_Rebuild * Fri Jul 10 2020 Jiri Vanek - 9.4.30-2.v20200611 - Rebuilt for JDK-11, see https://fedoraproject.org/wiki/Changes/Java11 * Thu Jun 18 2020 Mat Booth - 9.4.30-1.v20200611 - Update to latest upstream release * Fri Mar 20 2020 Mat Booth - 9.4.27-1.v20200227 - Update to latest upstream release --------------------------------------------------------------------------------References: [ 1 ] Bug #1848617 - CVE-2019-17566 batik: SSRF via "xlink:href" https://bugzilla.redhat.com/show_bug.cgi?id=1848617 [ 2 ] Bug #1864680 - CVE-2019-17638 jetty: double release of resource can lead to information disclosure https://bugzilla.redhat.com/show_bug.cgi?id=1864680 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2020-cf8ef2f333' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ . Stay informed about the newest security patches and upgrades for Jetty on Fedora 32. Critical for ensuring system safety.. Fedora Security, Jetty Updates, Information Disclosure, Security Enhancements. . Severity: Critical.LinuxSecurity.com Team

Calendar 2 Aug 31, 2020 Critical Fedora
89

Fedora 28: FEDORA-2018-a31054181a Critical: Lighttpd Denial Of Service

https://www.lighttpd.net/2018/10/14/1.4.51/. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2018-a31054181a 2018-10-23 21:06:54.129070 --------------------------------------------------------------------------------Name : lighttpd Product : Fedora 28 Version : 1.4.51 Release : 1.fc28 URL : http://www.lighttpd.net/ Summary : Lightning fast webserver with light system requirements Description : Secure, fast, compliant and very flexible web-server which has been optimized for high-performance environments. It has a very low memory footprint compared to other webservers and takes care of cpu-load. Its advanced feature-set (FastCGI, CGI, Auth, Output-Compression, URL-Rewriting and many more) make it the perfect webserver-software for every server that is suffering load problems. --------------------------------------------------------------------------------Update Information: https://www.lighttpd.net/2018/10/14/1.4.51/ --------------------------------------------------------------------------------ChangeLog: * Mon Oct 15 2018 Gwyn Ciesla - 1.4.51-1 - 1.4.51. * Mon Aug 13 2018 Gwyn Ciesla - 1.4.50-1 - 1.4.50. * Fri Jul 13 2018 Fedora Release Engineering - 1.4.49-5 - Rebuilt for https://fedoraproject.org/wiki/Fedora_29_Mass_Rebuild --------------------------------------------------------------------------------References: [ 1 ] Bug #1639043 - update of lighttpd package from 1.4.49 to 1.4.50 causes pi-hole admin console to fail at startup. https://bugzilla.redhat.com/show_bug.cgi?id=1639043 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2018-a31054181a' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the FedoraProject GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ . The recent security patch for Lighttpd resolves significant vulnerabilities in Fedora 28, providing users with a dependable and safe web server setup.. Lighttpd Security, Fedora Update, Denial of Service, Webserver Management. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Oct 23, 2018 Critical Fedora
89

Fedora 22: 2016-f59b94c349 Moderate: Lighttpd Crash Fix

Bugfix release: http://www.lighttpd.net/2016/1/2/1.4.39/. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2016-f59b94c349 2016-01-12 04:14:59.559109 -------------------------------------------------------------------------------- Name : lighttpd Product : Fedora 22 Version : 1.4.39 Release : 1.fc22 URL : http://www.lighttpd.net/ Summary : Lightning fast webserver with light system requirements Description : Secure, fast, compliant and very flexible web-server which has been optimized for high-performance environments. It has a very low memory footprint compared to other webservers and takes care of cpu-load. Its advanced feature-set (FastCGI, CGI, Auth, Output-Compression, URL-Rewriting and many more) make it the perfect webserver-software for every server that is suffering load problems. -------------------------------------------------------------------------------- Update Information: Bugfix release: http://www.lighttpd.net/2016/1/2/1.4.39/ -------------------------------------------------------------------------------- References: [ 1 ] Bug #1295149 - lighttpd-1.4.39 is available https://bugzilla.redhat.com/show_bug.cgi?id=1295149 [ 2 ] Bug #1296487 - lighttpd: crash after use-after-free [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1296487 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update lighttpd' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailinglist This email address is being protected from spambots. You need JavaScript enabled to view it. https://lists.fedoraproject.org/admin/lists/package-announce.lists.fedoraproject.org/ . Investigate the most recent security patch released for the lighttpd webserver on Fedora 22, aiming for enhanced security measures and peak performance.. Lighttpd Update,Fedora 22 Bugfix,Webserver Security,Performance Fix. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Jan 12, 2016 Important Fedora
202

openSUSE 11.4: Security Update openSUSE-SU-2011:1217-1 Important Apache DoS

An update that solves one vulnerability and has two fixes An update that solves one vulnerability and has two fixes An update that solves one vulnerability and has two fixes is now available. is now available.. openSUSE Security Update: apache2: Fixed several security issues ______________________________________________________________________________ Announcement ID: openSUSE-SU-2011:1217-1 Rating: important References: #713966 #719236 #722545 Cross-References: CVE-2011-3192 Affected Products: openSUSE 11.4 openSUSE 11.3 ______________________________________________________________________________ An update that solves one vulnerability and has two fixes is now available. Description: This update fixes several security issues in the Apache webserver. The patch for the ByteRange remote denial of service attack (CVE-2011-3192) was refined and the configuration options used by upstream were added. Introduce new config option: Allow MaxRanges Number of ranges requested, if exceeded, the complete content is served. default: 200 0|unlimited: unlimited none: Range headers are ignored. This option is a backport from 2.2.21. Also fixed: CVE-2011-3348: Denial of service in proxy_ajp when using a undefined method. CVE-2011-3368: Exposure of internal servers via reverse proxy methods with mod_proxy enabled and incorrect Rewrite or Proxy Rules. Patch Instructions: To install this openSUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - openSUSE 11.4: zypper in -t patch apache2-5347 - openSUSE 11.3: zypper in -t patch apache2-5347 To bring your system up-to-date, use "zypper patch". Package List: - openSUSE 11.4 (i586 x86_64): apache2-2.2.17-4.9.1 apache2-devel-2.2.17-4.9.1 apache2-example-certificates-2.2.17-4.9.1 apache2-example-pages-2.2.17-4.9.1 apache2-itk-2.2.17-4.9.1 apache2-prefork-2.2.17-4.9.1 apache2-utils-2.2.17-4.9.1 apache2-worker-2.2.17-4.9.1 - openSUSE 11.4 (noarch): apache2-doc-2.2.17-4.9.1 - openSUSE 11.3 (i586 x86_64): apache2-2.2.15-4.7.1 apache2-devel-2.2.15-4.7.1 apache2-example-certificates-2.2.15-4.7.1 apache2-example-pages-2.2.15-4.7.1 apache2-itk-2.2.15-4.7.1 apache2-prefork-2.2.15-4.7.1 apache2-utils-2.2.15-4.7.1 apache2-worker-2.2.15-4.7.1 - openSUSE 11.3 (noarch): apache2-doc-2.2.15-4.7.1 References: https://www.suse.com/security/cve/CVE-2011-3192.html . Important update for openSUSE users on Apache security vulnerabilities; please apply patches to enhance server protection and monitor site activities. apache security, openSUSE update, denial of service fix, important security patch, webserver vulnerability. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Nov 04, 2011 Important OpenSUSE
87

Debian: DSA-1513-1 Critical CGI Source Exposure in Lighttpd

It was discovered that lighttpd, a fast webserver with minimal memory footprint, would display the source to CGI scripts if their execution failed in some circumstances.. - ------------------------------------------------------------------------Debian Security Advisory DSA-1513-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Steve Kemp March 06, 2008 http://www.debian.org/security/faq - ------------------------------------------------------------------------Package : lighttpd Vulnerability : information disclosure Problem type : remote Debian-specific: no CVE Id(s) : CVE-2008-1111 It was discovered that lighttpd, a fast webserver with minimal memory footprint, would display the source to CGI scripts if their execution failed in some circumstances. For the stable distribution (etch), this problem has been fixed in version 1.4.13-4etch5. For the unstable distribution, this problem will be fixed soon. We recommend that you upgrade your lighttpd package. Upgrade instructions - --------------------wget url will fetch the file for you dpkg -i file.deb will install the referenced file. If you are using the apt-get package manager, use the line for sources.list as given below: apt-get update will update the internal database apt-get upgrade will install corrected packages You may use an automated update by adding the resources from the footer to the proper configuration. Debian GNU/Linux 4.0 alias etch - -------------------------------Source archives: Size/MD5 checksum: 36835 fa55bbf4bf1b9a555cc4b7b368a059f6 Size/MD5 checksum: 793309 3a64323b8482b0e8a6246dbfdb4c39dc Size/MD5 checksum: 1098 52f5881ec943188d8276c600902c84f5 Architecture independent packages: Size/MD5 checksum: 99430 b13f37c0c8b55e145e6f823d5dd82dee alpha architecture (DEC Alpha) Size/MD5 checksum: 716463d0308407b0b089bb8d8a215503f20d8 Size/MD5 checksum: 59412 cf3dc4218076b66d5fb04e40cb6e6a03 Size/MD5 checksum: 64832 c58a1cfc4a506351ef2425f4e4018113 Size/MD5 checksum: 61170 0a2a5196ed776076f29fb8a85976387e Size/MD5 checksum: 64402 58268f6c0dc00b8e0fe16f5cf93a6d86 Size/MD5 checksum: 318776 55890a8afec6ff4fba50ff2e8ac4df6c amd64 architecture (AMD x86_64 (AMD64)) Size/MD5 checksum: 69738 92677861a76629b9a3361c2c338d5bb0 Size/MD5 checksum: 63434 98b26e827bb4c8a023239a90bfdb45a2 Size/MD5 checksum: 60586 a3c573b8d1f921fb93fd28e33ee86d4f Size/MD5 checksum: 58994 de8951a3316888b5874f3b3ee0abe755 Size/MD5 checksum: 63726 0ca9bf4df2ca8260495146011e6d3a53 Size/MD5 checksum: 297048 a12c33257671acdd291f41b7b7f8c64d arm architecture (ARM) Size/MD5 checksum: 286092 3821f3f07c614ccf1a98cdec79301a18 Size/MD5 checksum: 58528 1e3e7f75c172bb082c7b083110194c9f Size/MD5 checksum: 60664 489518ec1610f510562a1d0a2dfcb940 Size/MD5 checksum: 69414 41096405646828e7a63a6e4b208d5497 Size/MD5 checksum: 62916 e74d042125f02400c48f2763d34e6d9a Size/MD5 checksum: 62718 3d19c37366365f0e7f3ee06da00df623 hppa architecture (HP PA RISC) Size/MD5 checksum: 324114 f8cc861ec3e948179387ee31f6f9f3b4 Size/MD5 checksum: 61616 fe5f56af17823da3ef58b9a0b8e6d298 Size/MD5 checksum: 72826 517acc9044c0d82adea99c3d1ca1f0cc Size/MD5 checksum: 64824 81bd6d5482ce8a3c5179edeecfd08346 Size/MD5 checksum: 59764 5d3f99e779ef096348b6749e4c809ba4 Size/MD5 checksum: 65288 bdd83e24259d7f2922c3a95b8293b36c i386 architecture (Intel ia32) Size/MD5 checksum: 58916 caed74881673974288bbc290b3ba3479 Size/MD5 checksum: 63722 5363ca45b9753e937fa011b163e2f376 Size/MD5 checksum: 63530 dda93744e3b76dd8f9e4a3dba20ca07a Size/MD5 checksum: 60684 fb1d5f0bcbabae22f148425b4c42fae5 Size/MD5 checksum: 70772 73b0ecdcafb617bf8e2e442f1886d9b0 Size/MD5 checksum: 288902 30283b07cea3f0a26dc1a38b839f2807 ia64 architecture (Intel ia64) Size/MD5 checksum: 403296 6c366b8fed9ff23f19aaf50a66931a69 Size/MD5 checksum: 62884 0ccb5f79ae50fbc9967b7af053ff0e76 Size/MD5 checksum: 61006 84f8efd4a34a05253e02aae4ad9e666a Size/MD5 checksum: 67184 3bd3cb49438d49c70436d106f97de40d Size/MD5 checksum: 76888 b5d4d899efb03134815b04b570bb8174 Size/MD5 checksum: 67326 c3301e3405ea81adbcbfdb25e9175df6 mips architecture (MIPS (Big Endian)) Size/MD5 checksum: 295944 7f5edffb4a6fa10cf0d57353d04939bc Size/MD5 checksum: 58380 8f124d373348b24428af69b411966c31 Size/MD5 checksum: 59762 63dbb566d233a7ca46f646e6f31db643 Size/MD5 checksum: 69048 a3002e94627fbe13a92f3750767ff833 Size/MD5 checksum: 62456 4b933ff37574e18d94b518d2dd1ddce1 Size/MD5 checksum: 62340 c62744ec6d7a84e13cda39089fc2cc40 mipsel architecture (MIPS (Little Endian)) Size/MD5 checksum: 69848 b01bc2ff253e183ccf000765acb86f81 Size/MD5 checksum: 60592 5aa70a480157629fc6caa35309371236 Size/MD5 checksum: 63194 a7d0666adf203cfc8a3089b7b27e7d27 Size/MD5 checksum: 59104 1d57b007782bbb3116113b418aa4d7c7 Size/MD5 checksum: 297028 96a183bd09c3ecee7899fa322a3d249f Size/MD5 checksum: 63370 b1f2124c09cfce63f77814bdfaf89ec6 powerpc architecture (PowerPC) Size/MD5 checksum: 65218 22aa056a61b992c613453c4e42a18931 Size/MD5 checksum: 64942 0a52051cdf863e7f4d07a784e9b999a6 Size/MD5 checksum: 71590 497c515d7d21d17b47938bb3ca62c98a Size/MD5 checksum: 323626 5d902bf2d0dad086610eed1a3ef399ff Size/MD5 checksum: 62298 5a6077d928a46f5412041586a79979a9 Size/MD5 checksum: 60480 e6b803329d925e756ebae8f3b8a25f61 s390 architecture (IBM S/390) Size/MD5 checksum: 64456 652df202c4877e31a189fdab5d73c429 Size/MD5 checksum: 711846a27ce3f4965c2f45063fc6a12fc95a1 Size/MD5 checksum: 64062 a1916058ca6929ba5ede58cd6df1c9fd Size/MD5 checksum: 59412 34187112fc60034864b8d7e4ad058010 Size/MD5 checksum: 60908 f457bf75d0034e57a2b037e091f1e8bc Size/MD5 checksum: 307020 9eaba4e65073194a68936c9957051597 sparc architecture (Sun SPARC/UltraSPARC) Size/MD5 checksum: 63234 c488f5fd992c2e1bc594614259a81c6d Size/MD5 checksum: 60348 643d00ff129a367c2f3f944ec3e9085d Size/MD5 checksum: 58700 32e6ed5c3bec41941466a4929d1e25ab Size/MD5 checksum: 283968 973579db2fff4ba527bbcfb8a78b4fb5 Size/MD5 checksum: 69712 a5b419803f4c7fb418291327c45ce442 Size/MD5 checksum: 63262 1748dc5be4967ff3fab5b94863e2be74 These files will probably be moved into the stable distribution on its next update. - ---------------------------------------------------------------------------------For apt-get: deb https://www.debian.org/security/ stable/updates main For dpkg-ftp: dists/stable/updates/main Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Enhance Debian lighttpd installations to resolve severe CGI vulnerabilities, protecting against unauthorized data disclosures.. lighttpd packages, Debian advisory, CGI exposure. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Mar 06, 2008 Critical Debian
91

Gentoo: 200402-03 Normal: Monkeyd Denial of Service Attack

A bug in get_real_string() function allows for a Denial of Service attack to be launched against the webserver.. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200402-03 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - ~ https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - ~ Severity: Normal ~ Title: Monkeyd Denial of Service vulnerability ~ Date: February 11, 2004 ~ Bugs: #41156 ~ ID: 200402-03 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= A bug in get_real_string() function allows for a Denial of Service attack to be launched against the webserver. Background ========= The Monkey HTTP daemon is a Web server written in C that works under Linux and is based on the HTTP/1.1 protocol. It aims to develop a fast, efficient and small web server. Description ========== A bug in the URI processing of incoming requests allows for a Denial of Service to be launched against the webserver, which may cause the server to crash or behave sporadically. Impact ===== Although there are no public exploits known for bug, users are recommended to upgrade to ensure the security of their infrastructure. Workaround ========= There is no immediate workaround; a software upgrade is required. The vulnerable function in the code has been rewritten. Resolution ========= All users are recommended to upgrade monkeyd to 0.8.2: ~ # emerge sync ~ # emerge -pv "> =net-www/monkeyd-0.8.2" ~ # emerge "> =net-www/monkeyd-0.8.2" Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bugat https://bugs.gentoo.org/. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.2.1 (GNU/Linux) Comment: Using GnuPG with Mozilla - iD8DBQFAKpaGMMXbAy2b2EIRAr1LAKC9dKoISy2eQelG1+Q71ZWgka7inwCgul7Z +naU63THPiXqAHQxweaTuR0=wRuH -----END PGP SIGNATURE----- . Uncover the security risk posed by Denial of Service in Monkeyd and find out how to protect your Gentoo system from potential dangers.. Monkeyd Denial of Service,Gentoo Security Advisory,Web Server Threats. . LinuxSecurity.com Team

Calendar 2 Feb 11, 2004 Gentoo
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here