Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Lighthttpd vulnerability CVE-2011-4362

    Scheduled Pinned Locked Moved General pfSense Questions
    9 Posts 3 Posters 2.9k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • L
      Lee Sharp
      last edited by

      One of the hotels I support was just a part of a PCI scan, and CVE-2011-4362 came up.  http://security-tracker.debian.org/tracker/CVE-2011-4362  I do not think it applies to FreeBSD but I can not find any documentation to that effect.  But is there any way to get a patched rolled out?  Convincing reality to PCI compliance scanners is a serious challenge.

      PS:  Oh, and Hi.  I am the Lee Sharp from the M0n0wall project.  Been using pfSense in a few places where dual WAN is a nice thing. :)

      1 Reply Last reply Reply Quote 0
      • D
        dhatz
        last edited by

        If you're going to touch lighttpd, please consider adding:

        1. mod_evasive
        2. url.redirect-code support (to be able to specify http code 302 instead of 301 for redirects). Last time I checked (~9 months ago) it required either lighttpd 1.5.0 or a patch for 1.4.x to work …

        1 Reply Last reply Reply Quote 0
        • jimpJ
          jimp Rebel Alliance Developer Netgate
          last edited by

          Bumping lighty's version for a CVE is probably in the cards, but adding features is not something that would be done during a security update.

          Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

          Need help fast? Netgate Global Support!

          Do not Chat/PM for help!

          1 Reply Last reply Reply Quote 0
          • jimpJ
            jimp Rebel Alliance Developer Netgate
            last edited by

            Just bumped lighty to 1.4.31, will be in the next round of snapshots (2.0.2 and 2.1)

            Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

            Need help fast? Netgate Global Support!

            Do not Chat/PM for help!

            1 Reply Last reply Reply Quote 0
            • D
              dhatz
              last edited by

              Apparently (according to http://redmine.lighttpd.net/issues/2247) the latter feature is now part of 1.4.31 so I'm good.

              1 Reply Last reply Reply Quote 0
              • L
                Lee Sharp
                last edited by

                Any eta on 2.0.2?

                I have MasterCard breathing down my neck…  ;D

                1 Reply Last reply Reply Quote 0
                • D
                  dhatz
                  last edited by

                  @dhatz:

                  Apparently (according to http://redmine.lighttpd.net/issues/2247) the latter feature is now part of 1.4.31 so I'm good.

                  Hmm, seems to be missing mod_setenv (http://redmine.lighttpd.net/projects/lighttpd/wiki/Docs:ModSetEnv). Any chance to add mod_setenv to the default install ?

                  PS: The reason for asking is because last year I did some testing for possible CP bottlenecks, and one idea I tried was to do the CP http -> https redirect using only lighttpd, rather than php. In that setup I used mod_setenv to set the various no-cache headers.

                  1 Reply Last reply Reply Quote 0
                  • jimpJ
                    jimp Rebel Alliance Developer Netgate
                    last edited by

                    2.0.2 will be any time now… every time I think it's ready someone finds another thing to fix (like a lighty cve ;-)

                    As for setenv open a feature req ticket. Not sure.

                    Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

                    Need help fast? Netgate Global Support!

                    Do not Chat/PM for help!

                    1 Reply Last reply Reply Quote 0
                    • jimpJ
                      jimp Rebel Alliance Developer Netgate
                      last edited by

                      Looks like lighttpd 1.4.31 is working fine in the 2.0.2 and 2.1 snapshots, so this should be resolved unless someone else finds a problem with it.

                      Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

                      Need help fast? Netgate Global Support!

                      Do not Chat/PM for help!

                      1 Reply Last reply Reply Quote 0
                      • First post
                        Last post
                      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.