oval:org.mitre.oval:def:15241
Definition Id: oval:org.mitre.oval:def:15241 | |||
Oval ID: | oval:org.mitre.oval:def:15241 | ||
Title: | DSA-2368-1 lighttpd -- multiple | ||
Description: | Several vulnerabilities have been discovered in lighttpd, a small and fast webserver with minimal memory footprint. CVE-2011-4362 Xi Wang discovered that the base64 decoding routine which is used to decode user input during an HTTP authentication, suffers of a signedness issue when processing user input. As a result it is possible to force lighttpd to perform an out-of-bounds read which results in Denial of Service conditions. CVE-2011-3389 When using CBC ciphers on an SSL enabled virtual host to communicate with certain client, a so called "BEAST" attack allows man-in-the-middle attackers to obtain plaintext HTTP traffic via a blockwise chosen-boundary attack on an HTTPS session. Technically this is no lighttpd vulnerability. However, lighttpd offers a workaround to mitigate this problem by providing a possibility to disable CBC ciphers. This updates includes this option by default. System administrators are advised to read the NEWS file of this update. | ||
Family: | unix | Class: | patch |
Reference(s): | DSA-2368-1 CVE-2011-4362 CVE-2011-3389 | Version: | 7 |
Platform(s): | Debian GNU/Linux 5.0 Debian GNU/Linux 6.0 Debian GNU/kFreeBSD 6.0 | Product(s): | lighttpd |
Definition Synopsis: | |||
|
Definition Id: oval:org.mitre.oval:def:6513 | |||
Oval ID: | oval:org.mitre.oval:def:6513 | ||
Title: | Debian GNU/Linux 5.0 is installed | ||
Description: | Debian GNU/Linux 5.0 (lenny) is installed | ||
Family: | unix | Class: | inventory |
Reference(s): | cpe:/o:debian:debian_gnu/linux:5.0 | Version: | 7 |
Platform(s): | Debian GNU/Linux 5.0 | Product(s): | |
Definition Synopsis: | |||
Referenced By: | |||
oval:org.mitre.oval:def:15241 |
Definition Id: oval:org.mitre.oval:def:12959 | |||
Oval ID: | oval:org.mitre.oval:def:12959 | ||
Title: | Debian 6.0 is installed | ||
Description: | Debian 6.0 (squeeze) is installed | ||
Family: | unix | Class: | inventory |
Reference(s): | cpe:/o:debian:debian:6.0 | Version: | 6 |
Platform(s): | Debian 6.0 | Product(s): | |
Definition Synopsis: | |||
Referenced By: | |||
oval:org.mitre.oval:def:15241 |
Definition Id: oval:org.mitre.oval:def:24698 | |||
Oval ID: | oval:org.mitre.oval:def:24698 | ||
Title: | Debian GNU/kFreeBSD is installed | ||
Description: | Debian GNU/kFreeBSD is installed | ||
Family: | unix | Class: | inventory |
Reference(s): | cpe:/o:debian:debian_gnu/kfreebsd | Version: | 3 |
Platform(s): | Debian GNU/kFreeBSD | Product(s): | |
Definition Synopsis: | |||
Referenced By: | |||
oval:org.mitre.oval:def:15241 |
Definition Id: oval:org.mitre.oval:def:24894 | |||
Oval ID: | oval:org.mitre.oval:def:24894 | ||
Title: | Debian GNU/Linux is installed | ||
Description: | Debian GNU/Linux is installed | ||
Family: | unix | Class: | inventory |
Reference(s): | cpe:/o:debian:debian_gnu/linux | Version: | 3 |
Platform(s): | Debian GNU/Linux | Product(s): | |
Definition Synopsis: | |||
Referenced By: | |||
oval:org.mitre.oval:def:15241 |