Debian Security Advisory 3642-1

Discussion in 'News Aggregator' started by Packet Storm, 10 Aug 2016.

  1. Packet Storm

    Packet Storm Guest

    Debian Linux Security Advisory 3642-1 - Dominic Scheirlinck and Scott Geary of Vend reported insecure behavior in the lighttpd web server. Lighttpd assigned Proxy header values from client requests to internal HTTP_PROXY environment variables, allowing remote attackers to carry out Man in the Middle (MITM) attacks or initiate connections to arbitrary hosts.

    Continue reading...
     

Share This Page

Loading...