Summary
The remote host is missing an update to lighttpd
announced via advisory DSA 1362-1.
Solution
https://secure1.securityspace.com/smysecure/catid.html?in=DSA%201362-1
Insight
Several vulnerabilities were discovered in lighttpd, a fast webserver with minimal memory footprint. The Common Vulnerabilities and Exposures project identifies the following problems:
CVE-2007-3946
The use of mod_auth could leave to a denial of service attack crashing the webserver
CVE-2007-3947
The improper handling of repeated HTTP headers could cause a denial of serve attack crashing the webserver.
CVE-2007-3949
A bug in mod_access potentially allows remote users to bypass access restrictions via trailing slash characters.
CVE-2007-3950
On 32-bit platforms users may be able to create denial of service attacks, crashing the webserver, via mod_webdav, mod_fastcgi, or mod_scgi.
For the stable distribution (etch), these problems have been fixed in version 1.4.13-4etch3.
For the unstable distribution (sid), these problems have been fixed in version 1.4.16-1.
We recommend that you upgrade your lighttpd package.
Severity
Classification
-
CVE CVE-2007-3946, CVE-2007-3947, CVE-2007-3949, CVE-2007-3950 -
CVSS Base Score: 8.3
AV:N/AC:M/Au:N/C:P/I:P/A:C
Related Vulnerabilities