Advisories ยป MGASA-2018-0430

Updated lighttpd packages fix security vulnerabilities

Publication date: 03 Nov 2018
Modification date: 03 Nov 2018
Type: security
Affected Mageia releases : 6

Description

Updated lighttpd package fixes security vulnerabilities:

Potential path traversal with specific configs or in some use cases
in mod_alias.

use-after-free invalid Range requests in core.

Process headers after combining folded headers in core.

Skip username "." and ".." in mod_userdir.
                

References

SRPMS

6/core