Bugzilla – Bug 850469
VUL-0: CVE-2013-4560: lighttpd: possible remote DoS
Last modified: 2015-02-19 01:34:33 UTC
CVE-2013-4560 If FAMMonitorDirectory fails, the memory intended to store the context is released; some lines below the "version" compoment of that context is read. Reading invalid data doesn't matter, but the memory access could trigger a segfault. References: http://download.lighttpd.net/lighttpd/security/lighttpd_sa_2013_03.txt http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2013-4560 https://bugzilla.redhat.com/show_bug.cgi?id=1029664
The SWAMPID for this issue is 55104. This issue was rated as moderate. Please submit fixed packages until 2013-11-28. When done, please reassign the bug to security-team@suse.de. Patchinfo will be handled by security team.
bugbot adjusting priority
ping?
submitted for all distros.
only opensuse left to release. closing
Update released for: lighttpd, lighttpd-debuginfo, lighttpd-debugsource, lighttpd-mod_cml, lighttpd-mod_magnet, lighttpd-mod_mysql_vhost, lighttpd-mod_rrdtool, lighttpd-mod_trigger_b4_dl, lighttpd-mod_webdav Products: SLE-DEBUGINFO 11-SP2 (i386, ia64, ppc64, s390x, x86_64) SLE-HAE 11-SP2 (i386, ia64, ppc64, s390x, x86_64) SLE-SDK 11-SP2 (i386, ia64, ppc64, s390x, x86_64)
Update released for: lighttpd, lighttpd-debuginfo, lighttpd-debugsource, lighttpd-mod_cml, lighttpd-mod_magnet, lighttpd-mod_mysql_vhost, lighttpd-mod_rrdtool, lighttpd-mod_trigger_b4_dl, lighttpd-mod_webdav Products: SLE-DEBUGINFO 11-SP3 (i386, ia64, ppc64, s390x, x86_64) SLE-HAE 11-SP3 (i386, ia64, ppc64, s390x, x86_64) SLE-SDK 11-SP3 (i386, ia64, ppc64, s390x, x86_64)
openSUSE-SU-2014:0072-1: An update that fixes three vulnerabilities is now available. Category: security (moderate) Bug References: 849059,850468,850469 CVE References: CVE-2013-4508,CVE-2013-4559,CVE-2013-4560 Sources used: openSUSE 13.1 (src): lighttpd-1.4.32-2.5.1 openSUSE 12.3 (src): lighttpd-1.4.31-6.5.1 openSUSE 12.2 (src): lighttpd-1.4.31-4.13.1
openSUSE-SU-2014:0074-1: An update that solves one vulnerability and has three fixes is now available. Category: security (moderate) Bug References: 790258,849059,850468,850469 CVE References: CVE-2012-5533 Sources used: openSUSE 11.4 (src): lighttpd-1.4.32-37.1