A fix won't be provided for Ubuntu 14.04 by the lighttpd team, the issue has also been closed invalid. Thus, I consider the usage of lighttpd on Ubuntu as highly discouraged.
However they have some backports at OpenSuSE, which can be used. See https://redmine.lighttpd.net/projects/lighttpd/wiki/GetLighttpd#Debian- based-systems -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1475266 Title: CVE-2014-2324 not patched in 1.4.33-1+nmu2ubuntu2 To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/lighttpd/+bug/1475266/+subscriptions -- ubuntu-bugs mailing list ubuntu-bugs@lists.ubuntu.com https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs