openSUSE-SU-2019:2347-1
Dashboard / Vulnerabilities / openSUSE-SU-2019:2347-1
openSUSE-SU-2019:2347-1
Summary: Security update for lighttpd
Details: This update for lighttpd to version 1.4.54 fixes the following issues: Security issues fixed: - CVE-2018-19052: Fixed a path traversal in mod_alias (boo#1115016). - Changed the default TLS configuration of lighttpd for better security out-of-the-box (boo#1087369).
References: https://lists.opensuse.org/archives/list/[email protected]/thread/VOBJZNTYGCVJJSLH5SFMUWQQJH3XPGJW/#VOBJZNTYGCVJJSLH5SFMUWQQJH3XPGJW, https://bugzilla.suse.com/1087369, https://bugzilla.suse.com/1111733, https://bugzilla.suse.com/1115016, https://bugzilla.suse.com/1153722, https://www.suse.com/security/cve/CVE-2018-19052
Affected packages
Package
Name: lighttpd
Purl: pkg:rpm/suse/lighttpd&distro=SUSE%20Package%20Hub%2015
Affected ranges
Type: ECOSYSTEM
Events:
