Information on source package lighttpd

Available versions

ReleaseVersion
squeeze, squeeze1.4.28-2+squeeze1
wheezy, sid1.4.30-1

Open issues

Open unimportant issues

Resolved issues

BugDescription
CVE-2007-1869lighttpd 1.4.12 and 1.4.13 allows remote attackers to cause a denial ...
CVE-2007-1870lighttpd before 1.4.14 allows attackers to cause a denial of service ...
CVE-2007-2841lighttpd DoS
CVE-2007-3946mod_auth (http_auth.c) in lighttpd before 1.4.16 allows remote ...
CVE-2007-3947request.c in lighttpd 1.4.15 allows remote attackers to cause a denial ...
CVE-2007-3948connections.c in lighttpd before 1.4.16 might accept more connections ...
CVE-2007-3949mod_access.c in lighttpd 1.4.15 ignores trailing / (slash) characters ...
CVE-2007-3950lighttpd 1.4.15, when run on 32 bit platforms, allows remote attackers ...
CVE-2007-4727Buffer overflow in the fcgi_env_add function in ...
CVE-2008-0983lighttpd 1.4.18, and possibly other versions before 1.5.0, does not ...
CVE-2008-1111mod_cgi in lighttpd 1.4.18 sends the source code of CGI scripts ...
CVE-2008-1270mod_userdir in lighttpd 1.4.18 and earlier, when userdir.path is not ...
CVE-2008-1531The connection_state_machine function (connections.c) in lighttpd ...
CVE-2008-4298Memory leak in the http_request_parse function in request.c in ...
CVE-2008-4359lighttpd before 1.4.20 compares URIs to patterns in the (1) ...
CVE-2008-4360mod_userdir in lighttpd before 1.4.20, when a case-insensitive ...
CVE-2010-0295lighttpd before 1.4.26, and 1.5.x, allocates a buffer for each read ...
CVE-2011-3389The SSL protocol, as used in certain configurations in Microsoft ...
CVE-2011-4362Integer signedness error in the base64_decode function in the HTTP ...
TEMP-0000000-589A35"slowloris" denial-of-service vulnerabilty in webservers

Security announcements

DSADescription
DSA-2368-1lighttpd - several
DSA-2368-1lighttpd - several
DSA-1987-1lighttpd - denial of service
DSA-1987-1lighttpd - denial of service
DSA-1645-1lighttpd - various problems
DSA-1609-1lighttpd - multiple DOS issues
DSA-1540-1lighttpd
DSA-1521-1lighttpd - arbitrary file disclosure
DSA-1513-1lighttpd - information disclosure
DSA-1362-1lighttpd - several vulnerabilities
DSA-1303-1lighttpd - denial of service

Search for package or bug name: Reporting problems

Home - Testing Security Team - Debian Security - Source (SVN)