Solution
Please Install the Updated Packages.
Insight
Boa is a single-tasking HTTP server. That means that unlike traditional web servers, it does not fork for each incoming connection, nor does it fork many copies of itself to handle multiple connections. It internally multiplexes all of the ongoing HTTP connections, and forks only for CGI programs (which must be separate processes), automatic directory generation, and automatic file gunzipping.
The primary design goals of Boa are speed and security. Security, in the sense of "
can't be subverted by a malicious user,"
not "
fine grained access control
and encrypted communications"
. Boa is not intended as a feature-packed server.
Available rpmbuild rebuild options :
--with : debug access poll
--without : gunzip sendfile
Affected
boa on Fedora 12
References
Updated on 2015-03-25
Severity
Classification
-
CVE CVE-2009-4496 -
CVSS Base Score: 5.0
AV:N/AC:L/Au:N/C:P/I:N/A:N
Related Vulnerabilities