Vulnerability Bulletins |
DSA-3642 lighttpd - security update |
|
| Affected software | Debian |
|
Dominic Scheirlinck and Scott Geary of Vend reported insecure behaviorin the lighttpd web server. Lighttpd assigned Proxy header values fromclient requests to internal HTTP_PROXY environment variables, allowingremote attackers to carry out Man in the Middle (MITM) attacks orinitiate connections to arbitrary hosts. More info: https://www.debian.org/security/2016/dsa-3642 |
|






