This bug was fixed in the package lighttpd - 1.4.18-1ubuntu1.4 --------------- lighttpd (1.4.18-1ubuntu1.4) gutsy-security; urgency=low
* SECURITY UPDATE: (LP: #209627) + debian/patches/91_CVE-2008-1531.dpatch - lighttpd 1.4.19 and earlier allows remote attackers to cause a denial of service (active SSL connection loss) by triggering an SSL error, such as disconnecting before a download has finished, which causes all active SSL connections to be lost. * References + http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-1531 + http://trac.lighttpd.net/trac/changeset/2136 + http://trac.lighttpd.net/trac/changeset/2139 -- Emanuele Gentili <[EMAIL PROTECTED]> Sun, 06 Apr 2008 03:39:14 +0200 ** Changed in: lighttpd (Ubuntu Gutsy) Status: Fix Committed => Fix Released ** Changed in: lighttpd (Ubuntu Feisty) Status: Fix Committed => Fix Released -- lighttpd (security) ssl fix https://bugs.launchpad.net/bugs/209627 You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. -- ubuntu-bugs mailing list ubuntu-bugs@lists.ubuntu.com https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs