Debian Linux Security Update: Lighttpd DoS and Gaim Package Remote Security Issues
Debian Linux project released today bug fixes for lighttpd and gaim package.
Gaim packages fix execution of arbitrary code
It was discovered that gaim, an multi-protocol instant messaging client, was vulnerable to several integer overflows in its MSN protocol handlers. These could allow a remote attacker to execute arbitrary code.
lighttpd packages fix multiple DOS issues
Several local/remote vulnerabilities have been discovered in lighttpd, a fast webserver with minimal memory footprint.
a) lighttpd 1.4.18, and possibly other versions before 1.5.0, does not properly calculate the size of a file descriptor array, which allows remote attackers to cause a denial of service (crash) via a large number of connections, which triggers an out-of-bounds access.
b) connections.c in lighttpd before 1.4.16 might accept more connections than the configured maximum, which allows remote attackers to cause a denial of service (failed assertion) via a large number of connection attempts.
How do I fix lighttpd and gaim security issues?
First, update the internal database, enter:
# apt-get update
Install corrected packages, enter:
# apt-get upgrade
E-mail this to a friend
Printable version
You may also be interested in other helpful articles:
- Security Warning: Serious flaw in Debian Linux OpenSSL Package
- Download of the day: pidgin instant messaging for Linux, BSD, MacOS X, and Windows
- CVE-2008-0595: Linux dbus packages fix privilege escalation
- Download of the day: Lighttpd web server 1.4.17
- How to upgrade lighttpd tar ball (source code) installation
Leave a Reply
We encourage your comments, and suggestions. But please stay on topic, be polite, and avoid spam. Thank you very much for stopping by our site!
Tags: arbitrary code, attacker, attackers, CVE-2007-3948, CVE-2008-0983, CVE-2008-2927, denial of service, internal database, lighttpd, linux security, memory footprint, minimal memory, msn protocol, overflows, protocol handlers, security issues, vulnerabilities



Recent Comments
Today ~ 6 Comments
Today ~ 10 Comments
Today ~ 5 Comments
Yesterday ~ 22 Comments
Yesterday ~ 11 Comments