Updated lighttpd packages fix security vulnerabilities
Publication date: 03 Nov 2018Modification date: 03 Nov 2018
Type: security
Affected Mageia releases : 6
Description
Updated lighttpd package fixes security vulnerabilities:
Potential path traversal with specific configs or in some use cases
in mod_alias.
use-after-free invalid Range requests in core.
Process headers after combining folded headers in core.
Skip username "." and ".." in mod_userdir.
References
SRPMS
6/core
- lighttpd-1.4.51-1.mga6