Comment 13 for bug 200987

Revision history for this message
Jamie Strandboge (jdstrand) wrote :

lighttpd (1.4.11-3ubuntu3.8) dapper-security; urgency=low

  * SECURITY UPDATE: (LP: #200987)
   + debian/patches/91_CVE-2008-1270.dpatch
    - mod_userdir in lighttpd 1.4.18 and earlier, when userdir.path is not set,
      uses a default of $HOME, which might allow remote attackers to read arbitrary
      files, as demonstrated by accessing the ~nobody directory.
  * References
   + http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-1270
   + http://trac.lighttpd.net/trac/ticket/1587
   + http://trac.lighttpd.net/trac/changeset/2120

 -- Emanuele Gentili <email address hidden> Tue, 11 Mar 2008 15:03:17 +0100