Package : lighttpd
Vulnerability : denial of service
Problem-Type : local & remote
CVE ID : CVE-2007-1870 CVE-2007-1869
Debian Bug : 422254
Two problems were discovered with lighttpd, a fast webserver with
minimal memory footprint, which could allow denial of service.
The Common Vulnerabilities and Exposures project identifies the
Remote attackers could cause denial of service by disconnecting
partway through making a request.
A NULL pointer dereference could cause a crash when serving files
with a mtime of 0.
For the stable distribution (etch) these problems have been fixed in
For the unstable distribution (sid) these problems have been fixed in
We recommend that you upgrade your lighttpd package.
will fetch the file for you
dpkg -i file.deb
will install the referenced file.
If you are using the apt-get package manager, use the line for
sources.list as given below:
will update the internal database
will install corrected packages
You may use an automated update by adding the resources from the
footer to the proper configuration.