Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 304065 - www-servers/lighttpd-1.4.26 version bump
Summary: www-servers/lighttpd-1.4.26 version bump
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High enhancement (vote)
Assignee: Christian Hoffmann (RETIRED)
URL: http://www.lighttpd.net/2010/2/7/1-4-...
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2010-02-08 20:53 UTC by Nikhil Sethi
Modified: 2010-02-09 23:20 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments
lighttpd-1.4.26.ebuild (lighttpd-1.4.26.ebuild,5.52 KB, text/plain)
2010-02-08 20:54 UTC, Nikhil Sethi
no flags Details

Note You need to log in before you can comment on or make changes to this bug.
Description Nikhil Sethi 2010-02-08 20:53:16 UTC
This is my first submission.

I tested this by running 

ebuild /usr/local/portage/www-servers/lighttpd/lighttpd-1.4.26.ebuild test

And Installed on my x86 system using my overlay tree

PORTDIR_OVERLAY=/usr/local/portage emerge -av lighttpd


Changes in this build according to URL (the OOM/DoS was patched in gentoo by lighttpd-1.2.25-r1.ebuild):

There have been some important bug fixes (request parser handling for splitted header data, a fd leak in mod_cgi, a segfault with broken configs in mod_rewrite/mod_redirect, HUP detection and an OOM/DoS vulnerability).
Comment 1 Nikhil Sethi 2010-02-08 20:54:47 UTC
Created attachment 218927 [details]
lighttpd-1.4.26.ebuild
Comment 2 Jeroen Roovers (RETIRED) gentoo-dev 2010-02-08 21:22:31 UTC
* Append to previous buffer in con read, fix DoS/OOM vulnerability (fixes
  #2147, found by liming, CVE-2010-0295)
Comment 3 Nikhil Sethi 2010-02-08 23:51:58 UTC
The vulnerability was fixed for gentoo in lighttpd-1.4.25-r1 via a patch (not lighttpd-1.2.25-r1 as I mistyped before).
Comment 4 Christian Hoffmann (RETIRED) gentoo-dev 2010-02-09 23:20:37 UTC
Security issue (fixed in 1.4.25-r1 in Gentoo, as noted above) is being tracked in bug 303213, so this is just an ordinary version bump.