Vulnerability Bulletins

DSA-3642 lighttpd - security update

   
Affected software Debian
 
Dominic Scheirlinck and Scott Geary of Vend reported insecure behaviorin the lighttpd web server. Lighttpd assigned Proxy header values fromclient requests to internal HTTP_PROXY environment variables, allowingremote attackers to carry out Man in the Middle (MITM) attacks orinitiate connections to arbitrary hosts.

More info:

https://www.debian.org/security/2016/dsa-3642