openSUSE-SU-2022:10140-1
Dashboard / Vulnerabilities / openSUSE-SU-2022:10140-1
openSUSE-SU-2022:10140-1
Summary: Security update for lighttpd
Details: This update for lighttpd fixes the following issues: lighttpd was updated to 1.4.67: * Update comment about TCP_INFO on OpenBSD * [mod_ajp13] fix crash with bad response headers (fixes #3170) * [core] handle RDHUP when collecting chunked body CVE-2022-41556 (boo#1203872) * [core] tweak streaming request body to backends * [core] handle ENOSPC with pwritev() (#3171) * [core] manually calculate off_t max (fixes #3171) * [autoconf] force large file support (#3171) * [multiple] quiet coverity warnings using casts * [meson] add license keyword to project declaration
References: https://lists.opensuse.org/archives/list/[email protected]/thread/T6C6UOQL3XPIYN6MAYXR6H6PCUA7Q4N4/, https://bugzilla.suse.com/1203872, https://www.suse.com/security/cve/CVE-2022-41556
Affected packages
Package
Name: lighttpd
Purl: pkg:rpm/suse/lighttpd&distro=SUSE%20Package%20Hub%2015%20SP3
Affected ranges
Type: ECOSYSTEM
Events:
