Oval Definition:oval:org.cisecurity:def:1007
Revision Date:2016-09-16Version:6
Title:DSA-3642-1 -- lighttpd -- security update
Description:Dominic Scheirlinck and Scott Geary of Vend reported insecure behavior in the lighttpd web server. Lighttpd assigned Proxy header values from client requests to internal HTTP_PROXY environment variables, allowing remote attackers to carry out Man in the Middle (MITM) attacks or initiate connections to arbitrary hosts.
Family:unixClass:patch
Status:ACCEPTEDReference(s):CVE-2016-1000212
DSA-3642-1
Platform(s):Debian 8
Product(s):lighttpd
Definition Synopsis
  • Debian 8 is installed
  • AND lighttpd is earlier than 0:1.4.35-4+deb8u1
  • BACK