[Bug 236489] CVE-2007-1869, CVE-2007-1870: lighttpd < 1.4.14 DoS vulnerabilities

bugzilla at redhat.com bugzilla at redhat.com
Mon Apr 16 11:24:19 UTC 2007


Please do not reply directly to this email. All additional
comments should be made in the comments box of this bug report.

Summary: CVE-2007-1869, CVE-2007-1870: lighttpd < 1.4.14 DoS vulnerabilities


https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=236489


matthias at rpmforge.net changed:

           What    |Removed                     |Added
----------------------------------------------------------------------------
             Status|NEW                         |ASSIGNED




------- Additional Comments From matthias at rpmforge.net  2007-04-16 07:24 EST -------
Since 1.4.15 doesn't seem to break any configuration syntax (I've tested an
update on a few servers, some with complex setups), I've decided to update all
currently supported branches to 1.4.15, which contains these fixes.

Note that the CVE-2007-1869 bug was already fixed in the devel and EL-5
branches, but they hadn't yet been rebuilt.

-- 
Configure bugmail: https://bugzilla.redhat.com/bugzilla/userprefs.cgi?tab=email
------- You are receiving this mail because: -------
You are on the CC list for the bug, or are watching someone who is.




More information about the Fedora-security-list mailing list