* SECURITY UPDATE: (LP: #200987)
+ debian/patches/91_CVE-2008-1270.dpatch
- mod_userdir in lighttpd 1.4.18 and earlier, when userdir.path is not set,
uses a default of $HOME, which might allow remote attackers to read arbitrary
files, as demonstrated by accessing the ~nobody directory.
* References
+ CVE-2008-1270
+ http://trac.lighttpd.net/trac/ticket/1587
+ http://trac.lighttpd.net/trac/changeset/2120
This bug was fixed in the package lighttpd - 1.4.18-1ubuntu6
---------------
lighttpd (1.4.18-1ubuntu6) hardy; urgency=low
* SECURITY UPDATE: (LP: #200987) patches/ 91_CVE- 2008-1270. dpatch trac.lighttpd. net/trac/ ticket/ 1587 trac.lighttpd. net/trac/ changeset/ 2120
+ debian/
- mod_userdir in lighttpd 1.4.18 and earlier, when userdir.path is not set,
uses a default of $HOME, which might allow remote attackers to read arbitrary
files, as demonstrated by accessing the ~nobody directory.
* References
+ CVE-2008-1270
+ http://
+ http://
-- Emanuele Gentili <email address hidden> Tue, 11 Mar 2008 14:16:48 +0100