Summary
The remote host is missing an update to lighttpd
announced via advisory FEDORA-2008-11923.
Solution
Apply the appropriate updates.
This update can be installed with the yum update program. Use su -c 'yum update lighttpd' at the command line.
For more information, refer to Managing Software with yum, available at http://docs.fedoraproject.org/yum/.
https://secure1.securityspace.com/smysecure/catid.html?in=FEDORA-2008-11923
Insight
This update fixes some moderate security issues and includes a few enhancements.
ChangeLog:
* Wed Dec 24 2008 Matthias Saou 1.4.20-6
- Partially revert last change by creating a spawn-fastcgi symlink, so that nothing breaks currently (especially for EL).
- Install empty poweredby image on RHEL since the symlink's target is missing.
- Split spawn-fcgi off in its own sub-package, have fastcgi package require it to provide backwards compatibility.
* Mon Dec 22 2008 Matthias Saou 1.4.20-3
- Rename spawn-fastcgi to lighttpd-spawn-fastcgi to avoid clash with other packages providing it for their own needs (#472749). It's not used as-is by lighttpd, so it shouldn't be a problem... at worst, some custom scripts will need to be updated.
* Mon Dec 22 2008 Matthias Saou 1.4.20-2
- Include conf.d/*.conf configuration snippets (#444953).
- Mark the default index.html in order to not loose changes upon upgrade if it was edited or replaced with a different file (#438564).
- Include patch to add the INIT INFO block to the init script (#246973).
References
Severity
Classification
-
CVE CVE-2008-4298, CVE-2008-4359, CVE-2008-4360 -
CVSS Base Score: 7.8
AV:N/AC:L/Au:N/C:C/I:N/A:N
Related Vulnerabilities