Index: vuln.xml =================================================================== --- vuln.xml (revision 419498) +++ vuln.xml (working copy) @@ -58,6 +58,37 @@ * Do not forget port variants (linux-f10-libxml2, libxml2, etc.) --> + + Multiple vulnerabilities found in Lighttpd + + + lighttpd + 1.4.41 + + + + +

Lighttpd Project reports:

+
+

Security fixes for Lighttpd:

+
    +
  • security: encode quoting chars in HTML and XML

  • +
  • security: ensure gid != 0 if server.username is set, but not server.groupname

  • +
  • security: disable stat_cache if server.follow-symlink = “disable”

  • +
  • security: httpoxy defense: do not emit HTTP_PROXY to CGI env

  • +
+
+ +
+ + http://www.lighttpd.net/2016/7/31/1.4.41/ + + + 2016-07-31 + 2016-08-03 + +
+ xen-tools -- virtio: unbounded memory allocation issue