Affected by security bug quite significant, lighttpd is still be vulnerable to Ubuntu repositories.

Lighttpd 1.4.19 and earlier allows remote attackers to cause a denial of service (active SSL connection loss) by triggering an SSL error, such as disconnecting before a download has finished, which causes all active SSL connections to be lost.

Vulnerable Version:

  • Hardy (upgraded)
  • Gutsy
  • Feisty
  • Edgy

CVE

Debdiffs:

Upgrade by .deb packages:

 

Upgrade by Repository:

  • Gutsy
deb http://ppa.launchpad.net/emgent/ubuntu gutsy main
deb-src http://ppa.launchpad.net/emgent/ubuntu gutsy main

apt-get update

apt-get upgrade

 

  •  Feisty
deb http://ppa.launchpad.net/emgent/ubuntu feisty main
deb-src http://ppa.launchpad.net/emgent/ubuntu feisty main

 apt-get update

 apt-get upgrade

 

  • Edgy
deb http://ppa.launchpad.net/emgent/ubuntu edgy main
deb-src http://ppa.launchpad.net/emgent/ubuntu edgy main

 apt-get update

 apt-get upgrade

This post has no comment. Add your own.